Techstrong TV – July 13, 2023
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
Transcript
Hello everyone and welcome to Techstrong tv. Today is Thursday, July 13th, and I hope you'll have it. A wonderful day so far.
I'm your host, Willie Willis, and in today's show, we're gonna bring you some fantastic interviews with incredible guests from around the world. So stay tuned. As always, I'm gonna start off with our tech Strong news recap, filling you in on the biggest tech headlines that are making waves.
Then we will head over to Alan, where he will sit down with Shawn Ahmed, chief Product Officer at Cloud BS to talk about DevOps world 2023. Alan will then speak to Mosh Millman, co-founder and COO of Apple Tools about its acquisition of pre-flight. We then go to Mitch, where he meets with Craig Box Istio Steering Committee member and vice president of the open source community at ARM to announce tios graduation as an open source project in the C N C F.
Micen speaks to Eve Mailer, forge Rock, CTO O to discuss why decentralized digital IDs are gaining traction. Next, we will air an episode of Text Strong Research Review. In this week's review, they discussed the critical topic of how to find a position in in the innovative areas we cover, like Cloud Native DevOps, cybersecurity, and ai.
Then Amanda Ani speaks with Brian, land Vice President of Sales Engineering at Lucidworks about implementing AI technology. We then go to Mike Ard, where he speaks with Pascal Weinberger, CEO of barine about integrating web applications using ai. And to wrap up this broadcast, Mike Ard interviews Animo CEO o Shiva, Nathan as Shiva explains why updates to operating systems for mobile devices continue to represent a major challenge for DevOps teams.
And that what we have coming up for you on this episode of Text Drawing tv. So without further ado, let's get the show started. com is the number one online destination for DevOps education and community building.
com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com where the world meets DevOps. Hi again, everyone hear the headlines for July 13th. First up, the European Union in the United States have reached a new agreement called the EU US Data Privacy Framework to address concerns about the privacy of personal data transferred across the Atlantic.
This allows companies to transfer information from Europe to the US without additional security measures. The framework infected from Tuesday includes strengthened safeguards against data collection abuses, and offers avenues for a redress. Business.
Groups have welcomed the decision as it provides a legal pathway for cross-border data flows to continue the deal implemented through an executive order signed by the US President Joe Biden aims to resolve the longstanding clash between eus strict data privacy rules and the less comprehensive US ones. The European Commission has deemed the framework to provide an adequate level of protection for personal data comparable to the eus own stringent data protection standards. Zooming out tech giants like Google and Meta have faced uncertainty regarding the handling of European data user for targeted advertising.
However, privacy groups are criticizing the new agreement stating that it failed to address core issues of data transfers. Next, the European Union has approved Broadcom's proposed 61 billion acquisition of CL the cloud technology company. VMware after the chip and software maker made concessions to address competition concerns.
Broadcom aims to strengthen its presence in the cloud computing market by acquiring VMware, which offers tech technology that enables the integration of public cloud access with internal networks. Broadcom has committed to providing access and system connections to its only existing rival Marvell, as well as potential future competitors satisfying European commission's, antitrust enforcers. This being said, the approval is conditional on Broadcom fulfilling its commitments for a period of 10 years with compliance being monitored by an independent trustee.
However, the deal still faces scrutiny from the UK's competition regulator too. In other news, China has dismissed Microsoft's report about a China based hacking group, reaching government linked email accounts as disinformation aimed at diverting attention from US cyber activities. Microsoft has identified the group as Storm 0 5 5 8, and stated that it gained access to email accounts associated with 25 organizations, including Western European government agencies.
The Chinese foreign ministry spokesman called the accusation false and claimed that the US is the world's largest hacker empire engaging in cyber theft. Microsoft has collaborated with relevant US agencies to prevent further breaches, and it is monitoring the activities of the storm 0 5 5 8 hackers. This comes after our previous reports of suspected state backed Chinese hackers targeting critical infrastructure and utilizing security vulnerabilities to infiltrate networks.
Next, HCA Healthcare, a major medical provider operating hospitals in the US and Britain has reported a data breach that HA may have compromised the personal information of approximately 11 million patients across 20 states. A hacker attempted to sell samples of the stolen data, including addresses, phone numbers, emails, and birth dates on an online forum frequented by cyber les. This being said, the stolen data did not include social security numbers, payment details, or clinical information.
However, it did contain information about scheduled appointments and medical departments involved. HCA Healthcare has not disclosed the exact date of the breach or when it became aware of the incident. HCA Healthcare has stated that it will provide credit monitoring and identity theft protection to affected individuals and advises patients to be cautious of suspicious phone calls, emails, and text messages.
Zooming out, healthcare providers are considered prime targets for hackers as the sector is classified as critical infrastructure. ai, we have an article looking at how to use AI to fuel experimentation in music. AI is giving new artists new ways to create and innovate by changing the way music is made and consumed.
This article looks at some of the ways that AI is fueling artistic experimentation. com. We have an article looking at how jfr has added a curation capability for open source software components.
The, the tool called j Froog curation will address cybersecurity and compliance issues before any open source component gets added to the mix to create a frictionless experience. com. Finally, on Security Boulevard, we have an article looking at a survey showing concerns about the rise of info Steeler malware.
The survey looked at responses from 320 IT security professionals, and found that 53% are extremely concerned about their ability to stop attacks that exfiltrate authentication data. Additionally, 36% stated that they didn't reset passwords for exo exposed applications. com, and that's today's Tech strong news recap.
This is Textron tv. Hi everyone. Welcome back to Textron tv.
You know, I'm really happy to have this next guest on. He's, he's, he's been on here many, many times, but we haven't had him on in a while. com, uh, November of 2013, so almost 10 years.
And I will tell you our, I think it was our first or our second, maybe our second sponsor was CloudBees. And, uh, so CloudBees is always to me synonymous with DevOps, right? And, and through the years, look, it's been a, a long strange trip in 10 years, right?
And we've seen a lot of things happen in the market, but DevOps is still here and so is Cloud vs. And, and the fact is that when they, um, started, what, what, what was Jenkins days and then Jenkins world, then cloud these days, cloud, and then they changed the name to DevOps world. I don't know, it had to be seven years ago, six years ago.
It, to me, it defined the DevOps community, right? That was one of the pillars of, of what, you know, when you got together with that DevOps community was. And we had some great ones that I think the last really big one was in the US was at the Moscone Center in San Francisco.
And the last big one in Europe, I wanna say was nice France, which was an amazing event. Anyway, I reminisce cuz I'm an old man and I do that, but, uh, or perhaps it was Lisbon even as I'm thinking about it, I think Lisbon was after Nece even, and that was maybe right before I think Covid Kaboshed everything. But anyway, this next guest is a good friend of mine.
His name's Shawn. Ed Shawn, of course, is the chief product officer. And he wear, he wears a lot of hats and he's worn a lot of hats at Cloud BS over the years.
Sean, welcome back to techstrong tv. Thanks, Alan. Thanks for having me.
I appreciate it. It's great being back home again. It's been a while.
Yeah, I, I'm sorry for the long-winded intro, but I was reminiscing there for a while. No. Anyway, I was reminiscing right there with you Uhhuh.
It's, it's been, it's been a bit. Um, anyway, Sean, you know what, let's start off with you. For people who aren't familiar with Sean and Med, why don't you give 'em a little bit of your background?
Yeah, sure. Absolutely. Happy to do that.
I, um, you know, have been with CloudBees now for the last, uh, I would say five years, a little bit more than five years. Um, and in various product roles here. Uh, for a little while there, I also had the opportunity to, uh, run marketing here.
Uh, prior to this I've been with companies like Splunk and sap, where I've also been in different types of, of, uh, product leadership roles. And, and, and, uh, it's been a tremendous ride and, uh, you know, I am, uh, getting old myself, but, you know, have had the opportunity to be a, be a part of, of, of a number of sort of transformations in the market, like Big Data. And then there was ML and now it's full G P T and, uh, and DevOps.
I mean, that's, uh, yeah, last 10 years have been exciting for DevOps. It's a fast moving industry. So to be a part of something that, you know, is fundamentally changing the way that people work and do things to generate, uh, mass value for customers is, is a great place to be in DevOps is is right there at the center of it.
So it's been a great ride so far. Absolutely. And, and I think, Sean, you're being modest.
You were also c e o of companies you've done Yes, that's true. You've been Acquired, did some acquiring, you Know, you've, You've capped in this ship. You've, you've dealt swabbed the deck and everything in between, right?
Alan, you're right. I have been, uh, CEO a couple of times before. You're right, I don't talk about it as much, but, uh, but yeah, a couple of times, you know, I had the opportunity to be founder, um, build companies and, uh, Bucky for me, I've had an opportunity to, uh, get the companies acquired as well.
So, uh, it was quite the experience. Um, but I did tell myself that the rest of my, uh, career, I'm gonna stick with what I love doing that's building product. So, uh, don't, don't, no, uh, no, no, no.
Uh, no plans to go back into that chair for any time soon. Never say never my friend. You never know.
Um, but that being said, a absolutely, and, and you know what? For, for younger people out there who look at someone like Sean and over the course of his career, it, it helps make you a well-rounded individual cause you don't know what you like and particularly what you may not like until you actually do those things. So it's great experience and my, my advice to you all out there is, look, if you, if you feel the urge to go start a company or build something like that, go do it.
If you don't, you know, you don't like it, you can always go back. Um, and there's, you know, the, the great thing about, especially in the tech world is there's so many paths to a successful career and to, and quite frankly to a happy career, right? Anyway, Sean, I want to talk about cloud vs a little bit.
Yeah, let's do it. com, but you know, when we first came in, Jenkins was DevOps, forget cloud vs. Jenkins was DevOps, right?
There was chef puppet and maybe Ansible for deploying stuff and then continuous integration. I don't know, it had to be 95% of the market. I betcha was, was Jenkins, right?
And, and KK who, you know, chief scientist, chief science officer at club, he's at the time, he, he started Jenkins, right? And, and CloudBees though, there was always a very clear delineation between the open source Jenkins and Jenkins community and a commercial company called CloudBees. CloudBees was a very benevolent custodian, if you will, in some ways, or guardian, better is a good word of, of Jenkins and the Jenkins community.
And then over time, right? And this is the natural course of things, right? Cloudy's concentrated on Cloudy's Enterprise and Cloud Cloudy's.
You know, you've got investors, you gotta make a return on your investment and so forth. But Jenkins was always closely entwined there with Cloud V. If you don't mind give our audience an update on, on what's happening with Cloud vs.
From, you know, maybe a product and market point of where you are in the market and vis-a-vis, uh, the Jenkins community and, and, you know, developments in Jenkins. Yeah. Well, well look, Jenkins is, has been, I would say foundational and a pillar for DevOps, like you said, right?
And, and, uh, synonymous with continuous integration, continuous deployment, delivery. Um, and despite what mon many folks might say in the market, it still is a fact of the matter is it's still growing. You know, you go, you look at the Jenkins IO stats and you look at, you know, the usage of Jenkins.
And what's astonishing is that, you know, 10 year o 10 years on, and it's still growing and it's growing at a rapid pace and the, the, the usage. And I think that the core fundamentals that made, you know, uh, Jenkins the first choice for C I C D, for most developers, fundamentally, those principles still hold true. And that is that it's open, it's extensible, it's flexible, and then there's plug-ins you can connect, you can build your software development lifecycle on this platform, and you have the most flexibility to sort of accommodate all the users that you have and all the methods of building software and delivering software that you have.
So that those core principles are still there. And what's really exciting for us this year is that, uh, we are here at CloudBees, you know, kind of, we're absolutely, uh, full on continuing to expand our investment in Jenkins as well for our existing customers and new customers and prospects that are building and using, um, you know, uh, Jenkins. Um, and we made some massive investments in the product this year as well.
And, uh, uh, bringing this back a little bit to DevOps world that you were talking about, which is now coming up here in September, we'll start our series. We are going to be releasing, uh, something we call the greatest, biggest probably performance and scalability enhancement to Jenkins in over a decade. And, uh, oh, you tease, I'm not, now we know Sean a teaser.
Now you got a reason to come back on right before September. Um, but so we're, we're very excited about DevOps world and, and, and, and you know, this year, you know, we're live, we're back in person as you know, the no thanks to, uh, Ian and, uh, uh, if a hurricane in Florida last year. Uh, so we're really excited about being the in person and being able to go on the road and share this exciting news.
And, uh, of course, uh, we always, as we do have, uh, as, as the great Steve Jobs would say. One more thing and one more. We do have one more thing this year as well, that's, uh, going to be super exciting.
So, so yeah, That's, that's exciting stuff. Let, let's focus in on DevOps world. Yep.
So, you know, you mentioned Hurricane Ian. For those maybe who don't know the, the reference there, uh, Cloudy's was hoping to go back to a kind of a single big DevOps world event moving, I think actually going before Ian, Sean, if you don't mind. Yeah.
I think the, the next DevOps world was scheduled to be a big one in Vegas, and then Covid Covid, just Absolutely. Yeah, absolutely. Then last year everybody was kind of dipping their toes in the water, and we said, okay, let's do a DevOps web, but we're gonna do it in Orlando.
And Hurricane Ian comes outta nowhere. We, you know, we, it was a late storm, I remember. And, and, and kind of puts the kibosh on that.
So this year, sort of following a strategy of not putting all our eggs in one basket, right? Yeah. We we're, we're, we're, we're a distributed DevOps world platform, right?
And we're doing a, a series of DevOps world, truly global DevOps world with the emphasis on world. That's right. And let's talk about some of the places that DevOps world's coming to.
Oh, yeah. Um, so, so we are gonna have, uh, DevOps world, uh, kickoff. Uh, we're gonna have it in the first kickoff on, uh, September.
In September, mid-September. Uh, it's gonna hit the road, and we are gonna be in the New York metro area. We're going to be in Chicago, we're gonna be in Silicon Valley.
Uh, we're gonna be in Singapore as well. And, uh, we're gonna bring it to London. Uh, excellent.
And so as we go to these various location, we're, we're really excited about bringing this event to our constituencies and to the audiences that we know wanna be there. And you're right, I mean, um, you know, uh, COVID was definitely just decimated, uh, oh, most of the industry's plans and the whole world's plans in so many ways. And, and the founding, you know, sort of the, the, the, the, the, the changes that we are now observing from that, uh, some of them are permanent changes to markets and economies and things like that.
Travel has sort of come back again, and some of these events are, are also coming back and, and we're seeing sort of some of these, you know, events come back in person as a a, a again, and it's phenomenal. We love it. And, and, and it's great to see that these types of events are still mainstays.
People love our attending them. Um, there's a networking effect that comes from them, um, coming there and learning be part of workshops, you know, kind of like, you know, in our, in our Santa Clara and New York, uh, you know, events, we're, we're actually gonna have a conference day, but proceeded by a workshop day. So it gives people a ability to come and learn Jenkins, how to use it, cloud BCI products, be certified, meet new people, make those types of connections that are so important to, to sort of the career path that you take.
Um, and, and it's great. I I'm so excited to just say that. No, those things have not changed.
Yeah. Even though many other things changed, I, um, I, I don't, you know what, I want to comment on that, but before we do, I just wanna reemphasize. So we have three in the us.
We've got New York, Chicago and Silicon Valley. We've got APAC region is Singapore, EMEA is London. com is functional.
com. But you can go there and get all this information. Now, Sean, I will tell you, I've spent the last, uh, well, I guess starting with Amsterdam for CubeCon in March.
So you're the last two, three months going back to in-person. And, and you're right, that, that networking track, and I don't mean Cisco or that kind of network, right? The human, the human networking, the, the water cooler, the hallway track, whatever you want to call it, is the most exciting thing.
I think we forgot. I mean, this Zoom stuff is great, but it's not, it's not the same as being able to shake someone's hand, share a beer, talk about stuff, have other people. I mean, it's just, it's amazing.
And I saw this in Amsterdam and qan, Hey man, they had 10,000 people with a 2000 person waiting list. I went right from there to San Francisco to the R S A conference. And you know what?
San Francisco has issues right now. I, we all know, but there were over 40,000 people in RSA conference, uh, CubeCon Chicago, which we'll be in, I think in November. They expect to sell out crowd.
Maybe 14,000 or more. 15,000 in person is back. People wanted come in person.
I think this is a great time to bring DevOps world to, to the people again. Um, you mentioned some of them, which was it, New York and Silicon Valley will have workshops the day before. That's right.
That's right. You know, for those of you who have not been to a, a DevOps world or a Jenkins world before, those workshops are great, right? It was hands-on training, there was certifications, I think you mentioned there's gonna be That's Right.
Certifications. And then, quite frankly, usually at night there's a community get together and, and stuff like that. You guys doing anything like that?
Yes, absolutely. We'll have, uh, we'll have some get togethers there for, for, for folks that are attending in our live. And, and we'll, we'll, we'll, we'll, we'll have some fun as well.
There'll be lots of learning. You know, uh, there's some great speakers that we have lined up. There's, they're, they're as always right experts on every topic that, uh, relative to Jenkins, relative to DevOps this year is no different than previous years.
Um, so we're excited, uh, about the line of, of speakers that we have. And, you know, as you go to the website and you check out the agenda, you'll see the powerful set of speakers that are there and the topics that we're covering. Everything from, uh, you know, really exciting topics in, uh, and John Jenkins to things about digital transformations and journeys to how DevOps is being applied to digital twins and, you know, yeah.
And so on and so forth. So we have this little industrial flavor going on in, in each one of these different locations that I think is gonna be real exciting for the audience. Sean, is it the same kind of set of speakers from location and location, or is each Luca location sort of bespoke, bespoke in Terms of it's a little bit bespoke speakers?
Yeah, it's a little bit bespoke, but, you know, there are some core sessions that, you know, we'll repeat in every single one of them that, you know, you're, you're going to have, you're gonna have a Jenkins sessions, uh, that will be the same in every location, but each location has a little bit of, of, of flavor associated with that particular region and industries that are very popular there. Um, so we've tried to sort of give a mix of content that's gonna be a little bit specific to the location, but at the same time a core of content that will always be the same no matter which part, uh, which kind of city we're in. Let me ask you a question.
For our big Jenkins users, our big Cloud V customers out there, does it pay to maybe hit New York and Chicago or New York and London, or do you think just getting one of these is, it might be too much overlap? I think, I think for us, I think, um, you know, we tried to keep the core of the sessions such that, you know, it'd be most valuable to hit up one session, but we always welcome people to come to any one of them if you wanna go to multiple ones and see some of the other adjunct. But you know what, we'll always have all of the sessions on syndication runs and things like that afterwards, that true, as well as presentations, right?
So, uh, you know, you'll have that available, uh, if you're a registered user, uh, you know, you'll be able to go back and take a look at those sessions if you want to. But, but generally speaking, I'd say the core sessions are all the same. And, and, and so if you're attended one, you'll get, you know, tremendous amount of value out of those ones, that's for sure.
Sure. Yeah. Last question, and then I had some other comments, is, okay, so DevOps world is back.
Do you think we'll see sort of a mega DevOps world? Not this year. Obviously we got five DevOps worlds this year, but maybe in the, in the near next year or the year after, it's back to this kinda mega event.
You know what, those mega events, they are still popular, aren't they? Yeah. And we might go back to that.
We might go back to that next year as well. We might, we might do that. I mean, this year we really wanted to test and try taking, you know, the events to, you know, our constituents and, and attendees and really try that out.
You know, last three years, we, we haven't had a live event and we tried last year and, you know, got really slammed because of the hurricane prior to that covid. So our approach was let's make it easy for folks. Um, yeah, and, and let's try to bring the event there.
Um, but next year we might just be back in, in one big event again, or we'll see how this one goes. Um, maybe we do a combination, well, hybrid, we're, DevOps is always changing. It's hybrid.
So the principle underneath us of DevOps applies. We, we apply it to DevOps world as well. So, you know, we'll see how this goes and, and if we want to go back, we, we can do that.
I, excellent. com. You, as Sean mentioned, you could get speaker info, uh, agendas, um, venue and everything else, dates and registrations.
Um, also just a quick plug. com. And we're gonna have a lot of pre pre-show kind of coverage, kind of highlighting some of the speakers in sessions, so you could catch it there.
We'll be doing a bunch of text drunk tv, uh, interviews on to them as well with some of the speakers and the coming weeks. So stay tuned for that. But hey, the big news DevOps world is back.
If you're in a DevOps, don't miss it. Sean, thanks for coming on today and, and, and telling us all about this. Very exciting.
We are gonna hold your feet to the fire on these product announcements, though, so. Oh, It's gotta be exciting. We'll, we'll have You back here.
Okay. All right. Thanks for having me, Alan.
I appreciate it. And, uh, to everybody, see you at DevOps world. Absolutely.
Shammed, chief Product officer at Cloud vs. Here on Textron tv. We're gonna take a break.
We'll be right back in a moment. This is Textron tv. Hi everyone, welcome back to Textron tv.
I'm really happy to do this next interview and bring you this, uh, news, um, exciting stuff. Let me introduce you to Mosha Millman. Mosha is co-founder and cto, is it Mosha of, of Apple, apple Tools.
C O O C O O, chief Operating Officer of Apple, apple Tools. For those of you who watch Techstrong TV often, you know, apple Tools is not a stranger to our, to our show and to our audience. We're usually lucky to have Gil ever the CEO of Apple, apple Tools on with us, and we've never, as a result, had a chance to interview Mosha here.
So we're really happy to have him join us. Mosha, welcome to techstrong tv and thanks for being here with us today. Yeah, thanks for having me on.
I'm a big fan, and, uh, it's a pleasure to be here. Pleasure. So, Mosha, before we jump into today's news, let's talk a little bit about, as I mentioned, you haven't been on, we usually have Gil who is co-founder, ceo, but you're co-founder too.
Why don't we get a little bit of your background, a little bit of your story? Yeah, sure. Um, happy to share.
So again, I've been with Apto. I mean, we started Aptos more than, uh, 10 years ago now. And, um, I've been working with Gil and Adam with, are my other two co-founders for the last almost 20 years now.
Uh, we've been working before the previous startup company that got acquired. It was called, uh, safe. And, uh, then we started aptos, and then we started the company in Tel Aviv.
Spent a few first few years building the product and testing the market, finding product market fit, and I moved to the us uh, around 2016 to help build a US part of the business, sales marketing go to market. And this has been my main focus over the past, uh, the past few years. Absolutely.
Um, and Moshi, you know what, not everyone out here, of course, will be familiar with, uh, with Apple Tools. I think most, most of our audiences we're, you know, pretty focused audience. But for those who maybe are not familiar or not sure, why don't you give them a little bit of the Apli tools story?
Sure, a hundred percent. So, um, yeah, so apli tools, uh, maybe just to start with a brief intro, like why we started APLI Tools and how we started it. So in previous companies, we always had challenges with testing and testing.
Always was kind of like left behind and was, uh, running late and was causing delays in, uh, uh, in releases and we're trying to find tools or solutions to solve it. And we spoke with all the vendors out there and no had a good solution that could actually solve this problem. And we felt that there has to be a better way to solve it.
And, uh, with the advancement of, uh, machine learning and ai, which again, was in its infantry, but back then, we felt that there has to be better ways to solve this problem. And our mission is to, um, improve testing processes, um, make testing better with ai. The first solution that we launched to the market, which was called Apto Eyes, was focused on the visual and functional testing through visual ai, which looks at the application screens and compare them between different versions and on different environments.
And, uh, we have now hundreds of enterprise customers across the globe that are using this, uh, uh, this technology. And our focus now is to continue to expand it organically as well as through acquisitions to be able to help solve problems in each and every step of the testing, uh, life cycle and modernize testing with with ai. Sure.
And, and, you know, for many of us Apple tools sort of define the, the visual testing, if you will, uh, category, right, and, and look testing today and always, frankly, but more so I think even today, testing has such a, there's a wide range of kinds of tests of the things you test. Is it unit testing, load testing, code testing, security testing is, is, you know, part and parcel of that now. Uh, UI and visual testing and, and all of user experience testing.
Th there's so many different aspects to testing and, and of course in a DevOps world where the, we're continuously deploying, we're also continuously testing, right? And we gotta get those feedback loops and taking the test results and, and, you know, working the next and iterations and so forth. Um, so testing is, I mean, there's a lot in there, right?
There's, there's a lot to it. Now you mentioned Apple Tools sort of expanding. Its, its, uh, portfolio, if you will, of solutions within testing.
And look, I, I've been an entrepreneur, you know, serial entrepreneur doing tech, uh, VC backed startups for years. There's basically two ways of doing it. You could organically develop or via acquisition.
My experience is as companies get older and bigger and more mature, sometimes it's harder for them to organically develop not what they started with, right? They're going to continue developing that, but analogists or adjacent categories, it's actually a faster time to market right? To, to some acquisitions.
And if you have the wherewithal and, um, apple Tools has some news on this. Yeah. Yes.
Yeah, definitely. Yeah. And I think you describe it correctly.
I mean, we constantly look for ways to expand. And we recently launched a couple new products organically with our self-cleaning execution cloud, but we also looking for ways to, uh, expand and accelerate our growth. And one of the ways to do it, like you mentioned it, through acquisitions and, uh, with APPLI tools in the last few years, we had a really good solution that can serve companies that already have test automation in place.
So if the companies already have a test automation with open source tools like Selenium or Cypress or playwright, and they have developers maintaining these tests, we had a perfect solution for them. They can, within a few lines of code, they layer visual AI and start enjoying all the benefits of apli tools for validation, for execution of the test, self fitting capabilities, et cetera. But we didn't have a solution for companies that didn't yet have test automation in place, or that didn't have the developer skills or developer resources available to, uh, write and maintain their automated test.
And we're looking for ways to, uh, offer solutions in the no-code, low-code, uh, space. And again, in the last two years, I think we looked at probably 20 different companies in that space. There is, this space has been evolving, uh, pretty heavily in the last few years, and there are lots of companies that are playing in that, uh, field.
And, um, we look for a company with like really strong technology based on AI that can fit well with our vision, with our, uh, technology stack and preflight, we decided to acquire preflight. That's the, that's the news. And, uh, preflight really impressed us with their, uh, technology and with their modern, um, application that they build, which is really user friendly, which makes it easy for any user in the organization to generate automated tests really easily without writing any code, without requiring any, um, significant, uh, uh, customizations or, uh, integrations.
So, uh, so this was the main reason for that, uh, uh, for that acquisition. Excellent, excellent. And, and you're right there.
Ha, low, low-code. No, this whole low-code, no-code area has been, uh, I mean, just exploding through co I think Covid helped accelerate it, right? Because, uh, you know, we had to get stuff done quickly, we had to get stuff done remotely and, and so forth.
But also, I, I think it's just the state of, of where we are, right? Um, so, so it happens, so pre-flight is, is is the acquisition. Can you give us kind of a pre-acquisition, pre-flight, who it is, people, places, products, and then how does that, how is that going to, what's the plan?
Cuz this just happened, obviously. What's the plan to integrate this into aply tools? Yeah, sure.
Uh, a hundred percent. So preflight their, um, uh, their, their founder, um, was based in Chicago. His name is, uh, Mustafa.
And, uh, he built this company from the ground up. He was a Y Combinator, um, uh, in the Y Combinator plan. And he worked with a lot of the YC companies to test and evolve the product and work until you get to the market, uh, to the product market fit.
And, uh, they built a really unique, uh, product. Um, like you mentioned, like, you know, there's a lot of solutions in that space, but although there are many solutions in a low-code, low-code space, when you look at the market landscape today company, a lot of companies are still doing manual testing. And there is a tremendous amount of manual testing that's been done.
And we're still seeing companies spend tens and hundreds of millions every year on manual testing resources and manual testing processes. And this really limits the ability of companies to get to continuous delivery, to continuous testing. Uh, you know, all these process advanced processes that you mentioned, which we're seeing more and more companies do it, but still the majority of the market is not, uh, is not there.
So preflight really focused on to, on solving these, uh, problems. They have, um, uh, distributed team, they're like a fully remote company, so they have engineers, um, in different regions, uh, uh, of the, of the world. And, um, our goal with this acquisition is to bring this to, uh, be part of the Aptos platform, bring the preflight team to be part of the, uh, of the atos team and work together with them to continue expanding this, uh, uh, product.
I mean, now they have tens of customers. We have hundreds of customers. We believe that many of our customers can enjoy, uh, the benefits of, uh, uh, pre-flight.
And of course there are many more customers out there which can enjoy these benefits of the combined, uh, pre-flight and alto's, uh, uh, solution. And what makes preflight unique? I mean, maybe just to, um, may answer your question a bit more directly.
So my, what makes it unique is that you can really easily generate automated tests in multiple ways. I mean, one way is you have a recorder, so you can go, like, again, many other, uh, solutions. You can go open your browser, interact with the application, and as you're doing it, it records and generates automated tests.
But what's unique about it is as you're recording these tests, it helps you make these tests scalable so you don't have to later, like, you know, deal with the data parameterization as you're recording the test. Every time it recognizes a place with data input, it immediately helps you parameterize this data and get test data generated to, uh, you know, to support running these tests at scale. It helps you deal with email validation, file downloads, all the things that usually happens when you interact with an application and you need to deal with, which used to be really painful with all their tools, which had to write custom JavaScript and a lot of things to make it work.
Now we can do it instantly, and also it allows you to just record what your users are doing in the application. So there is also an option to just put a snippet on your application, on staging or, um, on test environment. And as your users are playing with the application, it can generate tests based on this activity.
So there is multiple ways to create these tests without writing code, as well as really sophisticated editor that allows you to edit the test without a lot of maintenance efforts, which makes it really easy to, um, to scale automated testing. Great. Um, you know, I've done a lot of acquisitions over my years.
I've been acquired, also did a lot of acquisitions for a company I, I helped, uh, put together. Um, you know, the, the stan, the standard thing is, look, you gotta let it, you know, you don't come in and start patching, I don't know if you know what the word patching means, but you don't come in and start patching with, you gotta kinda let it sit for six months and acclimate and, and all of that. Um, what, what's the plan here for integration into Apple Tools or the, you know, broader offering?
Yeah, so, uh, so, so like you mentioned, we, we don't wanna just, you know, like kind of like, uh, tear it apart or, uh, replace everything. I mean, we definitely really appreciate the technology and the, uh, innovation that the pre-flight team built. And we believe there's a lot out there that the market can enjoy right now without any, uh, changes or, uh, or modifications.
So the plan is to release the product, like to the products already out in the market, but like we release the product to the market and allow companies to buy it as a standalone solution even without Aptos right now. And companies will be able to, uh, start using it and enjoy it and, uh, uh, use it as it is. And over the course of the next few months, we'll start integrating it with the Aptos, uh, platform.
Our vision at the end of the day is to help infuse AI into each and every step in the testing, uh, life cycle. And like you mentioned, there is many different types of testing activities. And traditionally we've been very focused on, or like, not traditionally, historically, we've been very focused on the valid test validation test, maintenance, test execution parts.
Now, we would like to also help tackle the test creation part and infuse AI into this, uh, phase of the product. So initially companies will be able to do it with pre-flight, uh, uh, standalone, and over time we'll integrate into the atos platform and you'll be able to, uh, create the test with, uh, pre-flight, but still enjoy the visual AI benefits from Apli tools. As you, uh, create these tests, you'll be able to execute, execute this test on the appli tools, uh, uh, test cloud and get all the benefits of the automated maintenance.
And at the end of the day, get to like fully autonomous testing platform, which can serve companies with existing automated tests using open source tool like Selenium and Cyrus and playwright and others, as well as companies which don't yet have automated tests and would like to start from scratch or would like to build it without, uh, developer, uh, involved. So again, I realize it's early, but a timeframe for this is, is there any sort of working timeframe at this point when we might see that? Yeah, sure.
So, um, the, um, uh, the integration is tend to be launched in the, um, in, in the last quarter of this, uh, of this year. So this, this is where the integrated product will, uh, will be released with Apple eyes and the preflight kind of like running together. Uh, we're planning to launch our kind of like next generation of the product during next year.
And there's like lots of exciting things coming, uh, coming up over there. This is probably a topic for a separate, uh, a separate interview, but we believe that this will really change the game of how, uh, companies do, uh, how companies do testing. And one thing that's interesting to mention here, it's interesting to also hear your perspective about it, but when I look at the overall software development life cycle, I mean, when you look at design and development and testing, I mean, the areas of design and development went through a tremendous disruption in the last few years.
I mean, when you look at design, almost every company now use Figma and other modern solutions. And these tools, I mean, changed dramatically from what happened like 10 years ago. And we look at development with Kubernetes and cloud platforms and all the modern, uh, frontend development stack that's available now for companies.
Again, almost every company is now using completely different tools than what they used 10 years ago. And these processes also advanced, and the velocity is much faster. Companies are trying to do continuous delivery release multiple times per day.
But when you look at testing, testing hasn't really gone through that disruption. I mean, a lot of companies are still using the same tools and processes that they used five and 10 years ago, and it's the same vendors that's been involved in that space for many years. And we believe that this area is really up for disruption, up for innovation, especially with the recent progress of, uh, generative AI and all these other things that are happening in the market.
So we would like to try to, um, to tackle this program and help this market, uh, evolve, help companies with better, uh, better solutions in that space. So that's our main goal with the new platform that we're, uh, that we're working on. I think you're dead on with that.
I, I think for whatever reason, testing was a bit of a redheaded stepchild compared to design and development where those areas were constantly evolving and improving. Testing was testing, right? It, it was, and then with the advent of DevOps and automated and the idea, anyway, the concept of automated continuous testing, scripting out your tests so that they run automatically, the, the, the focus moved from a tester to a person who could script for automated testing.
The guy who, or the per, not just a guy, a gal, a person who who sets up the automated testing right, became more important than the actual maybe person doing the testing. Cuz with the automated testing, we could build it into the pipeline, the developer could kick it off, right? And, and that was state of the art 10 years ago, let's say.
Right? That's, that was the big change. But you're right, we, we haven't, now we've added, as I said at the top, we've added security to the testing stuff.
We've added different kinds of test testing for what, but the, the, the, the Tools and concept there has been rather static. I think AI's a complete game changer for this because now the same way we move the focus from the person doing the test, to the person scripting the test, I think AI takes that person's place perhaps, right? And now, okay, so now where's the focus?
Right? Where's the person now and, you know, find the person and what can we and what does that mean? It's gonna be interesting.
We're actually, um, I haven't announced it yet, but we're doing something not just around testing, but around how generative and large language module in AI is going to affect this whole DevOps, uh, way of doing things. And we're, we're gonna do something in August here in our offices in Boca with like a, I don't want to, we're gonna announce it soon. Stay tuned.
Um, yeah, but I, I think you're right Mo we're outta time though, but for people who wanna get more information both about Apple Tools and Flight Pat, where, where can they go? Yeah, sure. So in the Apple Tools, uh, website, you can get all the information about Apple Tools and we now have, like after the acquisition, we have a banner kind of like referring, announcing the acquisition and referring people to the pre-flight side.
So with one click they can go into, uh, into pre-flight and enjoy, uh, bright. And we would love to get feedback and, uh, um, get people using it. Great.
Mosha, thank you for coming on today. It's, appreciate it. I've, and, uh, you did great on your First Techstrong tv.
We hope to see you back here soon. Thanks, guys. It's been a pleasure.
Appreciate It. All right. Mosha Melman, see O Apple Tools acquisition of pre-flight.
com. We'll be right back here in just a moment. com is the leading resource for news and analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network, This is Textron tv. Well, the great pleasure of being joined by Craig Box, and we're talking about some very cool news, great things that are happening in the Istio community.
Welcome, Craig. Good to be talking with you. Well, thank you, Mitch.
Well, let's, let's, uh, before we get to the kind of great news and the cool things that are happening, if you're in the cloud native, you know, microservices service mesh world, you know what STO is. If you're not, it may not be something familiar. So give folks maybe a little bit what it of, what it is in the history of it and, and then we'll talk about kind of the news that's happening.
Of course, Kubernetes was founded at Google in 2014, looking at the state of the internal systems at Google and how they operated and then what was available in the market at the time. And so the engineering team at Google where I was working at the time, looked at Docker, which was popular out there in the world, and look how they could solve container scheduling problems. 0 afterwards.
The SDO project is a very similar thing that that started at Google. It was looking at how it could manage microservices and, and help with some of the networking concerns for them in the same way that Kubernetes could deal with the deployment concerns in a similar fashion to how Kubernetes built on top of Docker. We looked out to see what was available in the ecosystem and came across Envoy, which was a proxy server that had just been released, was in the process of being released by Lyft, very high performance modern proxy server.
And we were looking to how we could solve some of the challenges we saw with operating applications, the things that we knew we faced internally at Google, and that people were going to have to face as they went forward building on top of meeting people where they were working also with partners in the community. So IBM very early on, we joined forces with them and put together a project that was very similar. We decided not to do that work in the Kubernetes project itself, to keep that very core and have that deal with containers, but we wanted to look at how we could build out an ecosystem of all of the tools that were required.
And so STO was the tool that Google developed in order to deal with the networking challenges that came up when running a distributed system, broadly speaking, we have pieces that need to speak to one another that are no longer guaranteed to be able to connect. They're not necessarily just processes on the same machine or threads in the same process, but now what happens if you call a service and it's not available? What happens if you need to retry connections to it a certain set of times?
What happens if someone else has taken over the endpoint for that service and there's no longer the endpoint that you expected it to be? So we looked to security observability and network functions and how we could adapt that and to do that in a way that was transparent to applications so that we didn't have to change the application, that we were just able to add a little something in front that handled all of those things for you. Using, of course, the Envoy proxy that I mentioned.
And then the SDO project was launched in, in 2017 to solve those problems. Pretty amazing how far it's come in five, six years from where it is. I remember seeing the TIO book, well, let me check that out.
Let's, let's go look at that, the O'Reilly book. Well, tell us about the news. Um, what, what's, we have some kind of graduation or, or moving along in the maturity of, of the project at C N C.
Yes. Yeah. SIO today has announced the graduation within the Cloud Native Computing Foundation.
The project was donated or contributed to the C N C F last year and joined at the incubation phase, which basically was a reflection of the process that needed to go through at the time to move through those steps. It is a very mature project that joined after five years. And so we have obviously many production users and many different ecosystem and many different industries, sorry.
And this graduation today is sort of a reflection that the project is recommended for use in, in all use cases in the same way that things like Envoy and Kubernetes that it builds on, it joins those projects now with the top level of recommendation from CNCF f And one, one of the, uh, aspects of this, and I know you had a lot of contributors and, and companies involved, but the, the companies that are contributing, supporting, engaged in the leadership at the working level, you know, it's a kind of a who's who of, of technology companies. Not everybody in the world is there, but it's the IBM Red Hat, Intel, uh, VMware, la la la you know, the list goes on and on. People who are part of the, uh, team as well as contributing.
Yes. That's something that's perhaps a bit different with SDO than many other open source project. It is very corporate led unashamedly, so it was founded by Google and ibm.
Many other vendors you joined, uh, many Chinese vendors as well. Hui have a great deal of contribution and service mm-hmm. As to, uh, Tencent and Alibaba and other providers there.
Then there's also networking vendors, people like Cisco, there are people like Salesforce who use it internally and have done a lot of contribution to it. And then there are companies like Tetra and Solo who were founded to offer SDO services, and that's on top of all of the other people who run Kubernetes environments and have offered SDO on top of that. We've gone back with them now many, many years.
But since joining C N C F last year, we've also managed to broaden the horizon a little bit as a neutral project openly governed. We've now welcomed Microsoft on board as well, who had been working on a, a different service mesh product, and they decided on balance that the right thing to do was to be part of this open ecosystem, and they archived that project and have now joined the STO community as well. So now, now that you've, uh, kinda moved up in status or maturity, um, from this C N C S perspective, what does, what does that let you do as a project and what does that mean to the people who are using Istio, uh, open source software If you separate the software and the project for a little bit.
So it doesn't make a huge difference to the software itself. Like we have a very mature process for it delivering the software. It does, of course bring more people on board.
As I mentioned, Microsoft for example, they've brought their engineering team onto this. So we are able to drive that forward. And it also helps with contribution that we're all doing as a community to bring service mesh to the broader Kubernetes ecosystem.
And we started a project last year with Microsoft and with some of the other service mesh vendors and with the Kubernetes team to use the new gateway APIs in Kubernetes, which are designed to handle ingress use cases to replace the Kubernetes ingress and expand them to support ingress to services, to support service mesh use cases. Those APIs were largely built based on SDO implementations from the past. But now what we're doing is building out an api which is available to everybody, and you can say, here's how I want to define traffic within a cluster.
And you can use the SDO implementation or you could use a different mesh implementation that also uses that same api. So that does help in terms of collaboration as well. When we come to the software and its use cases and so on, it is very mature and we have a good engineering team working on it from, from many different vendors.
I don't think we expect to see a, a huge change in how the project is, is run or managed, but one thing that we see when people evaluate whether or not to choose software is they look for that seal of approval. They sort of see it as a shortcut to say it is vetted by somebody else. It is guaranteed that the, the trademark and the processes and so on meet a minimum bar.
And that is something people were obviously very happy to use STO production beforehand, but this just helps them stop needing to do that analysis themselves and say, Hey, it's in this category, it's graduated in the C ncf, therefore I know that I can trust that it meets this bar. But it's not like, um, you attain this level and then you put it on the shelf. It's, it's, you attain this level because you have a, a certain level of engagement and activity.
Mm-hmm. And support and commitment behind it. Yes.
And we will need to maintain that as well. So there's, there's no formal process by which project, uh, sort of reevaluated over time, but we do encourage people to look at the, the number of contributors to a project and how active a project is when they choose to decide which software that they want to bring on board. Mm-hmm.
Yeah. Uh, one of the great things I was excited to talk with you about is in, in a very simplistic way, one of the things I described, um, cloud native architecture, particularly around service mesh to non-software developers. So it may be security people, network engineers, folks like that is, think about it this way, the network essentially has gone into the application and it's all kind of woven together.
It's not a, a hard exterior that's controlled through APIs or, or rigid protocols. Um, I mean, I'm curious, the folks that are involved from network companies like F five and Cisco, et cetera, uh, are, are they contributing, uh, largely from a network perspective, or is it still thinking about it as a Kubernetes world and, and, uh, cloud, cloud native kind of architecture? Uh, or is this a bridge to the networking people?
That's kind of what I'm asking. Curious your perspective On that. It, it can be both.
So there are vendors, uh, TRICS comes to mind who are building modern networking stacks, and they're realizing that simply dealing at layer three and saying, this traffic is going to, this IP address on this port isn't enough to, to deal with security and, and application identity and so on. So they are using it to move further up the stack in terms of application networking. You get people like Intel who are saying, we want to be able to support acceleration of those kind of network use cases with Intel hardware and network cards.
And you get people who are dealing at how they can make that faster. And you also get people who are looking from the Kubernetes perspective and saying, here is something that I wasn't able to do without making changes to my application. So we do really see across the board in terms of contribution, at least people who are looking to say, this is how we want to define things.
And you mentioned there differences between security and platform teams and developers. This is something we can offload from developers that they don't need to worry about. They don't necessarily need to change their code to say, I'm gonna deal with identity and validation.
This is something I can trust that my network does for me. And have a platform team provide that underneath and know that any connection you make will be bound by those things. And then of course, you can apply that across your clusters, across one or many clusters.
And from the security team's perspective, you can say, well, I, I know that as long as this thing is running, then this isn't a policy that's enforced everywhere, and I don't need to worry about people forgetting to add that or audit the code in order to know that the traffic will be secure When we think about it in terms of distributed applications, even applications to the edge as well as mm-hmm. Cloud, multi-cloud, all that kind of thing. It's all, it's a networking fabric that it's obviously operating on.
But now in a cloud native world, that's, uh, And the zero trust world as well. Environment, pardon? Go ahead.
Sorry. And the zero trust world as well. The zero trust.
There is a, a lot of, uh, emphasis, especially from the US government on, on operating in a zero trust environment. We're effectively, we say we, we don't want to have any guarantees provided to us by the network that we're communicating across, but we do need to do that ourselves. And again, not to have to build that into the application and say, I, I know that I can speak to an endpoint and I'm going to validate that endpoint.
I'm going to cryptographically verify that I'm speaking to someone who I trust, rather than just simply saying it's at this endpoint end point and I've seen them before, and therefore I, I'm willing to send my data to them. Very cool. I'm curious your perspective on this too.
Obviously, software, supply chain security is a big topic. Mm-hmm. Um, as it relates not only to open source, but all software in general.
Uh, given obviously your experience coming, bringing this through Google and maturity of the other organizations contributing to it, what are the some of the best practices you may already be doing around software supply chain security that others could take away or benefit from by using sto? I don't know that I associate the two things that there are many different aspects to security. In fact, I, I left Google, I now work at a security vendor called ama.
So I, I'm very engaged in the space. But the software supply chain, I would say we factor all that in, in terms of the building of STO and how we take open source components and, and make our components available to other people as well, and verify the pieces that we're running. We really think about that in terms of the build time and when an application is being built, when an application is being operated and run.
It's not so much that any recompilation is happening at that point or anything. So they are two different parts of the security ecosystem, but I don't really feel that there's a connection, a strong connection between the two when SDO is operating. Okay.
Very good. Um, how about where, where, where's SIO going? Where, what's sort of the next, uh, you foresee the next six to 12 months of things that are at least on the horizon that you might work on?
Yes. We launched in 2017 with, uh, a, a new architecture. We've talked about sidecar before.
So it was a, I think it was enabled easily by Kubernetes to say, when you deploy an application, deploy the proxy server alongside it and know that those two things will be tightly coupled throughout the lifecycle of your application. In large part, that was the right choice at the time, but we've looked at how we can improve that and make it possible to deliver all the same functionality without needing to deploy that extra component with every workload without having to manage the overhead of that. And last year we released an architecture, which we call ambient mesh, which allows us to deploy a very lightweight component on each node, which handles just the layer three, layer four networking of sending things to the right place.
And then per secure environment or per namespace within a cluster, we deploy the full layer seven proxy survey and we're able to do the higher level network functions through that for workloads that want to opt into that. So the security can be provided at layer four, the network application stuff can be provided at layer seven. We decouple that in a way that allows it to be deployed by the platform team.
So you don't have to think, I'm deploying my application, I'm, my sidecar comes along with it as a developer, but we, we call it ambient because we want it to be part of the environment. It's just there. And that also means you can opt into those functions and, and opt into doing traffic routing and circuit braking and so on if you want to.
But you don't have to say, right, I'm gonna have to redeploy my application and deploy a sidecar along with it to make it possible. We launched that Bit more efficient approach also. Absolutely.
So we see a huge amount of resource saving Yeah. On that. We launched that in, in preview last year.
It's, uh, alpha in the last release of STO one 18, and our goal is to get that to production readiness within the next 12 months. Yeah. Very exciting.
Well, congratulations on the accomplishments. Thank you. To date and of course more in the future.
io. What kinds of things will they find out by visiting the project site? Yeah.
We have, uh, information there on why you might want to use a service mesh and why you might want, might want to choose STO as that we have the full documentation for the project. We have our blogs where we talked about a lot of the newer stuff. A lot of the ambient content as that's being built out has been through blog posts.
And then of course we have a link to today's announcement and the supporting vendors behind that. The people who have contributed to SDO in the past and, uh, moved on to other things. One thing we think is, is great about our community is people come and go and move to different vendors.
Some stay involved with the project, some move on to some other things. Some go away and work on something else for a while and, and come back to the project. So one thing we wanted to highlight with this was the people in the past who worked on it and, and their congratulations and their best wishes to us for finally making graduation.
Very good. Congratulations to you and all the supporting companies. And thank you individual contributors.
Well to speak to you again soon. Good luck on the next, uh, set of releases. Thank we look forward to ambient ash.
Talk to you again soon. Craig. Thank you.
This is Techstrong tv. Uh, the great pleasure being joined by Eve Mailer. Eve is C t o with for Rock.
Welcome Eve. Great to be here. Thanks.
Great to have you here. You know, it's, it's uh, TA Talk for Rock and talking about, uh, digital identities. We were both just chatting a little bit earlier about, uh, you know, identity's not a new thing and digital certificates of something.
We both have had our hands in to varying degrees and been around for a long time, but things are kinda changing and evolving. Right. We still, of course have digital certificates in use soon.
Yes. You Know, I don't think they're going away anytime soon. Right.
Not anytime soon. Yeah, for sure. But I think maybe the thinking around identity is starting to evolve.
And I know you, one of the things that you are focused on is around this idea of, of, uh, distributed identities. Is that the right term? Correct, Yeah.
Distributed, decentralized. It's got some other decentralized names, which we can get into. Um, but yeah, I mean, you know, certificates obviously have formed a substrate, a very important substrate for things that have been built up over the last couple of decades.
You know, centralized identity and access management, having a repository and recording people's kind of profiles. And then we entered into the era of federated identity. So thinking about cross domain, single sign-on, which was a major innovation 23 years ago.
I was actually first chair of the SAML group, if you know, who were you, right? Security assertion. Oh, yes, yes.
Markup language. Oh my. And I always joke that the funny thing is stale doesn't have an eye in it cuz we didn't really talk about identity.
We talked about security and directory and certificates and things like that. And, and all that's really important to the ultimate solutions. We've taken things far enough that we can now kind of outsource authentication through this notion of single sign-on and federated identity.
And that's taken us pretty far. It's a very centralized approach. And as people have gotten more and more privacy sensitive, um, and more kind of cottoning onto, oh, I don't know, cryptocurrency, when people say crypto now you have to ask which one they mean.
Mm-hmm. Um, it's, it's brought together some new opportunities for solutions which are able to put identity information. So maybe username, maybe email address, maybe lots more information on the edge, like for example, on a smart mobile device.
Um, and then have it be free attested to by somebody who actually knows real information about you. And then you can kind of be in charge of handing that to services when you go and visit them. Almost putting more power back into the end user or the individual's hands.
It's not just on some, you know, a certificate authority somewhere, said somewhere that this is a valid device, person, server, et cetera. Mm-hmm. More thinking about it from whose data it is and then Attached.
That's right. Yeah. And I've, we've certainly seen the number of privacy regulations, you know, the world over GDPR and all of its cousins, things like that, that have influenced the thinking.
Um, and, and this really started actually even a little bit before GDPR in the era where people are just sort of fed up with filling in web forms over and over mm-hmm. And then people running the services going, you know, what kind of data did I just get? Is this person really at, you know, 1 23, Mickey Mouse Lane?
That sort of thing. Mm-hmm. So there might be a nice confluence of interest here with services able to get good quality data and people being able to choose when to actually share it and actually when to unshare it as well.
Yeah. There, there's also of course the big, um, how do we get away from passwords and Oh yeah. As well as our, you know, our own identity.
And at one point we're all supposed to get a digital certificate for ourself and Mm-hmm. Mm-hmm. You know, that kinda knew about that far towards solving the problem.
It's, it's easy to hate passwords and it's been easy to hate passwords since pretty much they were invented. Um, and, and there's good reason not to like passwords. Right.
You know, I was just mentioning to you, we, we publish a, an annual identity breach report and, you know, passwords are this huge vector for a lot of these breaches. And unauthorized access writ large is, is the major cause of a lot of these breaches. And so if you can find a way to use the other factors and use things cleverly and use multiple other factors, you can get to a passwordless world, that's becoming more, an more possible today.
Um, and we actually see this decentralized identity world possibly playing a really big role in getting us to, to next gen passwordless, if you will, because where you put the data, when I said you put it on the edge, you know, here's where I wave my phone. Um, if you can put it somewhere on the edge, then, um, you have the opportunity to have people unlock their phones, unlock a special app, which is getting to be called a digital identity wallet. And that wallet is what holds the information.
And the wallet can actually be in charge of logging you in with a, with, with a much better experience without compromising security and, and hopefully privacy as well as, as we've started to discuss. Mm-hmm. You know, I I, I'm still kind of getting over, when you said federated identities, I remember trying to explain that to my lawyer team that, oh no, this is not an antitrust issue.
This is like identity. Totally different kinda federation Than No, I mean, it's interesting because, you know, federating identity, where you've got, you know, we call it a relying party and that's some service that relies on an identity provider. The big question is, can I actually outsource liability?
What does that look like? So, you know, there's the technology which we've had available for a long time, and then there's the business trust questions, which mm-hmm. You know, have sometimes prevented us from doing more, like transferring attributes that the identity provider knows about me.
So decentralized identity is actually sort of making another run at it, doing it a different way by using the user as the kind of conduit for that information. I'm, I'm really curious, tell me a little bit about the, for rock perspective of what, what brings customers to you? Usually there's a two or three sets of problems that commonly come to a, you know, a technology provider and, you know, and lot.
And oftentimes it's a very common one that people run into. Yeah, yeah. Sort of those use cases that you see most often.
So enterprises, um, and, and particularly large enterprises have challenges when they have, um, either consumer populations or they might have their workforce population where they've just collected too many applications for which they've implemented user management. Mm-hmm. And they've got silos.
And it's either preventing business, preventing upsell, preventing engaging with customers better, or it's preventing a really hard look at security for their workforce and for their partners. And so they're trying to get away from that. What I think of is application by application user management, and get onto, um, kind of a higher maturity basis for, uh, registering users, onboarding employees, um, authenticating those users strongly and in a way that they can kind of swallow and we can talk more about password list.
Mm-hmm. Cause that's something that really is here now. Um, and looking at the entire cost risk, value equation and, and kind of injecting digital identity into all of it.
People think of identity as kind of a login box these days. Right. And it's easy when you have a lot of passwords in your life.
I'm starting to think of it as the cardiovascular system for any connected enterprise, for the connected world. Uh, so that, that's the kind of problems that we're solving for customers is, is, um, unifying these silos, making it efficient to get people using their systems and to identify those users to make the experience not just pleasant, but kind of really make it sing. Um, and, and really to, uh, provide the backing.
Uh, for example, there's new standards in authentication like the Fido standards mm-hmm. Fast identity online where you can really start to implement these things in a, in a lot easier way if you have an expert IAM solution behind you. Cuz it's what we do all day long Ex Exactly.
I think as much of as we've gone digital in all parts of our work, essentially all parts, um mm-hmm. Yes. There's internal systems, so many more external systems and SaaS and single sign up clearly helps with that.
But one of the big complaints I hear from end users is athe authenticator apps and texting codes and backup codes and what is all this stuff, right? I I'm just trying, oh gosh. Get my job done in accounting.
Right. That's the Yeah, totally. I'm trying To enable work, but, And, and what we do to workers is really often not very nice.
Like, you know, we, we sort of enable poorer experiences to be shown in front of employees than that we can get away with for, for consumers. Right. Um, and so that's really why I think the Phi IDO standards have become so important.
Um, and this is where they, they leverage something you have and something you are typically, so you can do like a local phone unlocked to start that experience. Um, and it really gives you a multifactor strong authentication and increasingly in a passwordless way, and increasingly in a way that doesn't even mind so much if you lose your phone. Because if you've heard of pass keys, very popular topic these days, that comes from Fido and it's this approach that can really bring multi-device credentials.
So for web and mobile, we're starting to get some solutions locked in as long as the implementation sort of can be trusted. Um, now when it comes to employees, they interact with VPNs and remote desktop software and all kinds of environments, legacy mainframes, databases where it's not so easy. It's not just sort of a web mobile, Hey, let's stick Fido in here.
Uh, we actually have a solution, um, that we call Enterprise Connect passwordless for that as well to kind of like take the pain and the toil out of, um, you can't necessarily eliminate the passwords, but you can give a fully passwordless experience. So these, these things are definitely possible. Yeah.
Almost like a, I'm in my enterprise session now, I can go use the tools and applications mm-hmm. Normally would use without feeling like I'm in living in a world of SAS applications that are all you Yeah. Independently secure.
Yeah, exactly. SaaS applications that, you know, none of which know about each other. That's, that's the sad part.
So speaking about passkey, do you think, I mean, apple just announced in next version of their os they're gonna be supporting that on both iOS and MAC os, I believe. Um, do, do you see that as being sort of a big thing that if people will be adopting it sounds like a much better User Experience? I really see people adopting it.
In fact, I've had consumer experiences apart from any work conversations or work interactions where they've offered me pass keys. I use a password manager that offers, that is a passkey provider. So if you think mm-hmm.
I was talking about identity providers, being a passkey provider is kind of the same level of seriousness. And we know Apple is, we know Google is, um, and, and we're starting to see these, I'll call them third party, uh, passkey providers. And I think that's exciting for the, you know, an ecosystem of, um, making passwordless attractive so that people adopt it on their own.
Like, can you imagine rolling out a new IT program where you don't have to do any convincing, you don't have to sort of buy off any user groups. They just want it. This is where I think we're, we're really going.
And, um, that's, it's, it's enabled and I mean, we already support paske, uh, iOS PAs keys in the for Rock platform. So it's, it's, they've made it that easy. And, and having Fido support, um, be before you show up, uh, to the Paske conversation definitely helps.
I don't know how often security people get standing ovations when they're rolling out new stuff, but maybe Paske is that that event, right? I think so. I mean, I, it's, it's been 20 years that I've sat next to people on a plane who are not technical and they say, so what do you do?
And I'm like, Hmm. Yeah. And the conversation always still goes to passwords and just how much people hate them.
And I, I, I don't blame them. I do too. Well, Eve, it's been a great pleasure.
Uh, tell us a little bit more about the report, um, and then also where we can get ahold of that. Absolutely. com, forge Rock.
Sounds like two words. The rock in the name is not an accident. I see those guitars on the wall.
Yeah. And, uh, it's the Identity Breach Report and it's our 2023 edition, our fifth annual. Very nice.
And, uh, we hope that'll help people out. It's nice. Always nice having some continuity of multiple reports cuz you can see some trends and what's changing, what's Exactly, et Cetera, so.
Exactly right. Excited To check that out. So folks, be sure to check out, uh, that report and also Forge Rock and the great things, uh, that you have to offer working with enterprises and identity, uh, whether it's centralized or, or it's decentralized Or decentralized, Et cetera.
All of the above. Well, thank you so much, Eve. Great.
It's a great pleasure talking with you. I look forward to you coming back again. It was a pleasure.
Mitch. Hey everybody. Mike Rothman here, general manager of Text Run Research with another episode of Text Run Research Review.
I am joined as always by Mitch Ashley. Mitch, how are you? Good.
Always good. We've had a lot of great events here recently and looking forward to some more. We have some great projects on the books, so happy to do doing this work.
You know, Aren aren't, you're supposed to slow down over the summer, right? Take a little bit of a break, a little bit of a holiday, do this, and it, it seems that, you know, we've kind of been a little bit on the pile on, you know, kind of of thing. And again, this is a first world problem for sure.
Yeah. I am certainly not complaining about it. No.
Right. But it just, it does seem that, that this summer is, uh, uh, you know, pretty intense in terms of, of what we see coming down the pike. It just, the number of events that we have and, you know, for me, getting ready for Black Hat and, and getting ready to teach, uh, uh, the cloud security course that, that I'm gonna be teaching once again, probably my seventh or eighth year doing that, uh, at this point.
Um, so what do we wanna talk about today? So what you'll see by the time this hits Textron tv and you guys can all see it, we will have had the Cloud Native Now show. And one of the things that we did in the Cloud native virtual conference was go through our cloud native trends and, you know, have some accountability and really talk about what worked, what didn't work, you know, where were we off, where were we on, and what made sense moving forward from a change standpoint.
And one of the things that we kept getting around to was the skills gap, right? You know, we've got all these new technologies, obviously Techstrong is focused around a lot of these new innovative technologies, starting with DevOps and then went into security and then what was containers. And now we've red redo cloud native now to, you know, really talk about the much broader cloud native migration and, and where folks are moving from that standpoint.
We recently launched a ai, right? ai is really focused on where artificial intelligence is playing in, in all of these things. And every so often, you know, I'd say it's probably once or twice a month I'll have somebody reach out who has more of a traditional IT background and says, you know, I listened to your thing, whether it's the research review or one of your, you know, virtual conference presentations or saw me speak somewhere.
Uh, and I would love to break into this business and this business could be secured. Right? That's where I get most of my questions.
Mitch, I would imagine a bunch of folks approach you on cloud native and, and DevOps and a lot of these things. So I thought this week we really wanna dig into, if you are a practitioner, if you are really trying to refresh your skills and try to move to where the puck is gonna be, right in the old Gretzky Gretzky mm-hmm. Um, you know, skate to where the puck is gonna be, not to where it is, um, how do we do that, right?
How do we get towards it? Uh, and and really put yourself on a trajectory to take advantage of some of these new technologies and new capabilities where we do have such a huge skills gap. You know, I think it's sometimes it's hard to pull out of the lane that you're in, right?
You're you because that's the world you're working in and then, you know, so well, and also it pulls you back cuz you've got day-to-day and big responsibilities and things like that. One of the things that has always helped me is, yes, I have to do my day-to-day job, but think about, so what is changing and why in our world, whether I it's in security or not, right? So to me it starts with software is now part of the business strategy.
Matter of fact, the business strategy is built on the organization's ability to deliver, operate in the cloud, uh, evolve, um, maybe even be more resilient around the software experiment with new products and ideas and features. And a lot of the business just wants to be more agile and software is there because it's just not a back office function anymore. It's part of the strategy.
Now, whether you're doing it all yourself, probably not, you're doing it with a lot of partners and such. So if you're a security person, um, your world's already changed that way, right? How many, how many software do adds appliances are using in a cloud provider, even in our own data centers, right?
There aren't as many rack and stack boxes, uh, as there used to be had software modules that get turned on with orchestration. So kinda think about what is so, so what's gonna happen in my world? I see this happening elsewhere, is that that gonna happen in ours too?
And what would sort of set me up to be ready for that? Or maybe I can help make that change even better, be one of the people to help help that happen. No, that that's right.
So, so I think part of it is really understanding how these new technologies are impacting the business strategy and therefore the technology strategy. So there's part of it, which is just an understanding of your business, uh, and where things are going. But I I, you know, I I also, again, you know, a lot of folks just are trying to say, do I take a bootcamp, right?
Is that how I learned to DevOps? Do I open up a cloud account, just start playing around and doing, you know, some of this online workshopping, you know, type stuff? Do I try to volunteer with an organization and, and, you know, do some app dev, uh, on, on that front or, you know, try to help folks, you know, get a Kubernetes, uh, environment started up or, or spun up, right?
So that's kind of where I, I wanna poke a little bit too. Okay. Which is, you know, where do you develop these technical skills?
Again, you, you assume that you've got at least a little bit of a background. We're not talking about somebody coming out of, um, y you know, a totally non-technical positioning going, okay, I want to be a DevOps sir. Right?
You know, this is somebody who's been, they're a traditional app dev, maybe they're a networking person, OnPrem, maybe they're a security admin, uh, maybe there's some type of IT ops person and, and they wanna start getting immersed in some of these new technologies, uh, that their business may not necessarily have embraced quite yet, or maybe has done it as part of a skunkworks, but they see that it's gonna become more general purpose over time. Mm-hmm. Yeah.
We're sort of, you, you, you've been, you've been to the, uh, you've logged onto the console before you've been to the dashboard. That's right. You know, you've used some of those tools somewhere in your, in your history, if not today.
Uh, this is just, just for me. I'm, I am a tactile learner doing it. I learned so much more about, okay, I can theorize about it, talk about it, you know, pontificate about it, but I'd learn so much more just doing it.
That's why I've got Docker and Kubernetes and 80 other things running on my laptop, and it's so dang slow. I have to stop everything to do videos. Right?
And some of it is like real things that I'm working on for, for our business, but other is like, okay, what is this? How does it work? Um, I think I've told this story before, and probably about 2002 11 or so, I had my network.
I took over an IT group. I had my network engineer, senior most guy, excellent, awesome network engineer, come to me and say, what should I be learning? I'm getting ready to go to Cisco now and kind think about what should I, what should I be looking for?
And, and I told him, well, I don't know that you're gonna need to do this as your job every day, but you need to learn Python. Mean, like, gave me the four eye look. Of course I had my glasses on, so I had four eyes, but, but I said, because everything's moving to software, I think you're knowing a little bit about software, not, you may never write any code.
Just kind get an idea of what this writing code is about. And so you kind of relate to the software you're trying to manage and the, the scripts and all the stuff that you may be putting together in the future. And he came back from Cisco now, and he goes, yeah, that's exactly right.
They just told us they're starting this bootcamp thing on, on Python. So that, that's, again, it's, I don't think it's to learn Python for example, or go or Node or whatever you wanna learn. Yep.
I think it's just understanding that world, right? It's kind of putting someone else's shoes on for a little bit and just saying, okay, I see what this is about. Yeah.
Agreed. And, and I think one of the things that's been so, um, democratizing about the cloud is that you can get a free account, right? And, and you know, Azure, if you do, if you sign for Microsoft thing, they'll give you $200 worth of credits that you get to use over six months or something like that.
Um, a w s has a free tier that you can use for y you know, at least a year to do a, a, a lot of different things and, and remember it. And one of the things that came out of a, uh, recent pulse meter that we did, I don't know if it's launched yet, but it will be soon. Um, I think it was the one we did on backup and recovery, but we asked how many and what platform are they using for Kubernetes?
And the leading two platforms were, and I got, this is gonna shock everybody, right? Um, elastic Kubernetes service, that's an a w s service and, uh, Azure Kubernetes service, which is obviously the Microsoft Azure service. So, and again, if folks are doing Kubernetes in a lot of cases, they're using the managed environment on the part of the cloud providers and you can get a free account and start playing around with these technologies ahead of time.
Yeah. Each of these cloud providers has a number of different workshops that they provide as part of their training, things. You can find a lot of cool stuff on the internet.
So I, I, I agree. I mean, I think that that, you know, kind of the tactile piece of this is, is important. And obviously if it's part of your day job, they're going to make sure that you are trained in order to do that.
But remember, they're looking at a whole mess of people and they're gonna go, well, which one do we wanna send through training? Which one do we wanna put down and, and have walked this path towards a cloud native future or towards a DevOps, you know, type of future if you've done a little bit of work ahead of time, right? If you've started that process and you're, again, you're not gonna be a hundred percent there, but if you're 15%, 20, 25% of the way there, understanding these technologies starting to played with them, you look like a lot better candidate.
You are showing that initiative to go and start to build out, you know, your personal skill sets and employers take note of that, right? And if you were in a situation, I know, and it's, it's, it's been very tough for some folks, especially coming out of high tech, um, where there have been just a ton of layoffs. And if you're looking to, um, get into a new position and really kind of change the trajectory of your career that way, it becomes all the more important that you have that hands-on skill.
Now, folks are gonna be willing to train you if you have, you know, kind of the right outlook and, and kind of a learning mindset, but having some of that experience in, Hey, I've been playing around with this stuff. Look at what I built. I I made this, you know, kind of again, demo application, whatever it is that again, gives them, gives an employer a sense that, one, you're a serious person and you're making an investment in yourself, right?
And two, the learning curve's not gonna be as steep as it's gonna be with some folks because again, you know, we just don't have enough folks that have these kind of capabilities that can step in and be productive on day one. Organizations know they're gonna have to train up, uh, a number of folks. But a again, if you're starting from zero, that's one type of training.
If you're starting from 25 or 30%, that's a different kinda training. And I think that ladder is, is far more attractive to, uh, a number of employers. You know, one of the questions I I used to ask security and network engineers when hiring folks for those teams is tell me about your home network and the, the folks that would say, oh man, I've got four racks and I've got this and that and Cisco, that and, uh, you know, whatever, uh, Palo Alto this and this firewall, and I'm trying this right now and I'm old working with, uh, Linux a little bit more trying to figure it out.
That's who I want to talk to right now. It's like you, those answers are, well, actually I'm in Azure and I just started using Kubernetes and I'm not, I'm not sure about that. Kind of figuring out the, the, I got the container thing down and I downloaded a whole bunch of open source and I know how to build packages through the package manager and set up new, uh, containers.
And okay, great. That's not gonna be your job, but that is what you're working in that I love that answer. Yes.
Right. And, uh, you know, the folks that say, I have a router and a laptop, I, okay, and so what do you do in the cloud? And if it's not those things, then Probably I'm here, you know, show up at the front door of the cloud provider.
I'm here, you know, with the router. Yep. I can't tell you how.
And, And your, and your serial cable Yes. Your console cable, your nine pin cable, go in the back of the, I'm here, let's go the blue. Hold on, I got the time machine in the back.
So we'll, we'll be happy to send you, you know, to 1992. Uh, and you'll, you'll be relevant, uh, at that point, right? Maybe even in into the eighties.
Uh, but, but you know, I think that whole learning mindset is really critical. Right. And that's always been how I've hired too.
Right? And, and, you know, for all positions, it's really not just about what you know now, it's about what you do to develop your own personal skillset. Mm-hmm.
What are you doing to invest in yourself, right? What are your interests? Uh, what kind of stuff do you read?
And, and listen, I mean, the reality is I don't necessarily expect everybody to read, you know, kind of wily textbooks, you know, all day that again, that'll make you old, uh, to begin with and your eyes will start bleeding. Right? But, you know, it's just to find well-rounded individuals, you know, find folks with, with varied interest, find folks that wanna, you know, gain and, and build up their knowledge, uh, over time.
Um, I think that's really y you know, kind of the important stuff. And, and listen, that's not to say that there's not a position for folks that like to, I'll kind of say it, and this really isn't meant in a derogatory way, right? But they wanna punch the clock, right?
They come in, they wanna come in at 9 0 1, right? They want to be out at 5 0 1 and take their one hour lunch break. And that's okay, right?
And, and when we went through this, right, you remember, you, y you know, back when we had y you know, in, at the turn of the century, you know, we had a whole bunch of folks that were trained up on mainframes, and we could, everybody could see, yeah, we're gonna get through this Y2K thing, and then these big irons are, y you know, they're, they're going to not go away, right? But they're gonna reduce in terms of, you know, kind of their importance with within, you know, kind of the systems, uh, environment. But those folks didn't wanna change, right?
They didn't wanna learn new stuff. They didn't, they knew what they knew. They, they did it very, very well.
And, and they could be very consistent and predictable about what it was they're to do what they're doing. And that's fine until it's not right. And you as an organization, you, you know, have to decide.
Yeah. You know, as long as we have those positions, that's great. You, you, you do, you, I'm not gonna tell you, you gotta grow.
I'm not gonna tell you. You need to, you know, go and learn new skills, but the minute I decommission that big iron, or I outsource it, or I do something else, then I've got an issue, right? Because you're either gonna move forward with where we're going or you're not.
And again, that's a choice. And I'm cool with whatever that choice is, right? There's not the point to say that you, you, you know, that's not a great choice, but that kind of resistance, you know, is there, and, and you know, we still see it.
And as more folks move towards DevOps, and as more folks move towards cloud native infrastructure, y you know, there's going to be that group of folks that again, do it ops for data center looking things, and their world is, is going to contract. It has to, right? That's just where the trends are going.
It, it, it's almost like it becomes its own, um, specialty, but very narrowly, right? If, if you enjoy what you're doing, you like what you're doing, you know, like, Hey, I wanna sink in five years learning blah, right? I, I like what I'm doing.
Maybe it's, maybe it's continued to stay down the lane, but how do you work with the people that are doing the new stuff? Is there things that you can help? Cuz guess what, you know, we all said the mainframes are going away.
No technology in my career has ever gone away. There's a website. It's, it's hard to find PDP elevens or Wangs at this point, right?
Well, well, but I, there's a website you can run every version of the Mac operating system from the very first version of it, an emulated version on this website and every as, every, every release that they did. Yeah. And you can, it's like, yeah, that's what it was.
Like, you know, that's going back to 19, uh, what was it, 85? Yeah, that's right. Something like that.
Somewhere in that range for 84. Yeah. 84 cause of it.
Um, so, but that stuff doesn't go away, but it's role. Well, we still need people that work on that stuff. Um, we still need new apps, still need to talk to the mainframe or the data or transactions coordinated across those.
It's not that they're, it's not that they're dead, it's just the investment in new apps and functionality is obviously gonna be in other environments along with what you need to do to keep, you know, what you have in an older environment. Current, right? I think the worst thing is, worst thing is being in an environment where there's zero funding to do zero with it, and all it is doing is getting older and more out of date and, you know, ready to fall over and you're keeping, you're keeping the alive with, you know, soldering irons, whatever you No, That's right.
That's Right. That's the hard part. I mean, I've had, I've had that situation before where it's time to, we have to upgrade and, uh, people were thankful for it.
But your point, I think your point's valid. Not everybody is on the hard right end of the learning curve. Learner curve, right?
We all do it differently. So lever choice people, And, and again, we're not coming from a play of, I don't speak for you, I'm not coming from a place of judgment from that standpoint. But the reality is that is a choice, right?
And, and, and managers and folks that run it shops have to look at the resource allocations that they have, where their technology's going and staff up accordingly. Yeah. So, great.
You know, we went, went, went through a bunch of that stuff. Are there good resources, Mitch, that you know of that folks should, you know, kind of pay attention to if they're interested in learning about DevOps, learning about cloud native infrastructure, where, where would you join them? I, I think a great place to start is whatever cloud that you're in, if it's Azure, if it's, um, you know, Google or, you know, pick your favorite, maybe it's Oracle or it's, um, Akamai, even all of those, all of those, uh, organizations have great training resources for people both getting started and then more advanced things.
So the nice thing about that is they're training on you on how to use containers in an a w s environment so you're not having to kind of put all the pieces together yourself. Um, I would start there. I think that's a fantastic resource.
And, and of course I have to pitch, what we do is we share a lot of content, whether it's in video or in the written form. My third suggestion is find somebody to partner up. This week I had an interview.
No, actually I had, I had a call with somebody, uh, I was talking about, totally different subject. And I asked him, by the way, are you doing, are you doing i d e in the cloud instead of on your local machines and all that? Cuz this is getting crazy for me.
And he says, yeah, I am. So, so I asked him, I said, this guy's, you know, younger than I am. He said, would you mentor me on how to do that?
Cuz I've got some questions. I don't wanna, I don't wanna like burn cycles on problems I already solved. So find somebody either online, a friend, do it together with somebody, find somebody that, that you can ask questions of and they'll help you.
Guess what? Nobody says, no, I won't help you. Everybody says, sure, I'm happy to help.
Right? Yeah. On, on the security side, I would, I would echo that I think that you, you know, for key areas of, of understanding like identity and access management, like networking, um, you know, some cases, the, the Kubernetes, you know, services and those things, uh, a w s and, and Azure and Google to, to that degree also have real good, again, both documentation as well as, you know, kind of training materials that are hands-on in nature and run you through scenarios so that you're playing around in the environment.
Uh, I will plug, uh, if, if your organization, uh, will support that, uh, and you wanna learn about cloud security, we do our introduction to cloud security class called cloud security hands-on, uh, at black hat I I'm teaching that in, in August. That's a gram mean you basically, we build a WordPress stack in a w s and we have an Azure version of it too. So we'll do the same thing, uh, in Azure, uh, and secure it.
So you understand about how to set up I identity and access management policies. You understand how to set up, you know, kind of firewall rules. They're called security groups or, uh, network, uh, rules, uh, on, on that.
In, in Azure, y y you know, we, we kind of build out and, and encrypt data. So there's just a, there are a number of resources that are out there so that you can get HandsOn. And that's really the big difference.
Back in the old days, if you wanted to understand how to be a CIS admin on a Spark station y yeah, you're probably not buying a Spark station to sit, you know, in your basement, you know, back in the day, right? You just didn't do that. Nobody had the money to do that.
It made no sense. So you had to learn on the job. Now you've got these opportunities to learn, um, really, and, and get hands-on in a very inexpensive way.
Uh, and I think that's to the betterment of, of everybody. Now understand, there are also a bunch of organizations that I will, I don't wanna call them shysters, but you, you, you know, there's a lot of training stuff out there that's total crap. And they say it's, you know, hands on and all this, and you get somebody who really hasn't been there, done that, you know, they don't understand what they're doing, they're just following the manual, they're reading to you and, and they can charge you thousands of dollars for these courses.
So buyer beware on that front. Then again, I just don't think if you've got that hacker mentality, if you like to play around with stuff, just get in there, right? Start doing some stuff, start breaking things, uh, start figuring out how, how it works.
Uh, and I think ultimately, not only will you be better off in your career, I think, you know, you'll, you'll have a lot more fun because the, this stuff is just, again, it's really cool, right? It's just really cool that, you know, when we do our labs in the part of, uh, y you know, we've got our first, uh, instance going y you know, within the first two hours of class, right? And you've configured it and you've, you know, kind of locked it down, uh, and you just see people go, holy crap, you can like do that stuff.
So, uh, I would say definitely get hands-on, uh, look at your cloud providers as a great resource to, uh, really facilitate some of that training. Uh, but y you know, if you wanna be in this business for the next 10, 15 years, uh, that learner's mindset is, is going to be absolutely critical for you. I think I'm glad you mentioned the workshops and, and especially at, at events.
Like you're talking about going to conferences, you know, in even I'll say the old trusted sources, and I don't mean all derogatively, but you know, like Sand's Institute, guess what, you know, they're keeping up because this is where this is going too. And so, and then that's just one right? That you can go to for, for work workshops and training and, and uh, things like that.
So you can go to some very familiar and known places. Just start looking for things you weren't looking for and saying, you know, I'd like to know a little bit about this. What's this generative AI stuff?
How do I secure it? Is that on there? Maybe even be, I'll find something like that on there.
Exactly. Exactly. So good.
So good. So I think, you know, again, folks have their marching orders. You do, you you wanna stay in your box?
No, no problem with that. We're not judging anything you wanna start to expand. There are lots of different resources to do that.
Um, and you know, obviously at Techstrong we have a number of different opportunities for you to, you know, get hands on and do some workshops and, and just look for tech strong learning. Uh, we do have, uh, events that happen, you know, pretty frequently that do give you the opportunity to, uh, go a little bit deeper from the technology and those are some of our more popular mm-hmm. Events.
So, so definitely keep a lookout for that. Mitch, what do we have coming up? We've got cloud native now probably happened already.
So the next one would be Data ops. Data Ops Day. Yep.
Data Ops day, right? I'm not, you know, date Beverly who runs our events would just have my head if I expanded it to a Multiple day and, uh, just put a plug in, uh, November, I don't know if we've released details yet. We'll be doing a, uh, SecOps conference.
We, I wonder who would be driving that one? Um, I don't know. We better find somebody quick.
I think we know Too. We got SecOps. We might, we might have somebody that we could do that with.
com for up in September. And I wanted to offer, you know, maybe, you know, if if I, if get SED with requests, that's okay, anybody wants to reach out, I'm happy to connect them with something. If you're looking for a resource of where do I learn this, how to, I, I, I don't, there don't, there's a lot more I don't know, but I can certainly point you to some areas if I do know those.
com and happy to reply to you and see if, if I can help. Alright, good, good. So with that, we will wrap up.
We will see you next week on the Textron Research Review where I'll come up with some wacky topic that we can talk about, which I just no idea what it is quite yet, but we will figure it out between now. No, by the time we hit record. All right, thank you much.
Take care everybody. See you soon. C I S O talk to hear how real world CISOs are dealing with today's real world issues.
From enabling secure remote workers to accelerating secure cloud adoption, defending against a pandemic of security attacks and beyond. C I S O talk covers the cyber topics you want to learn about with your hosts, Unisys, C I o, Matt Newfield, and media ops c e o at Alan Shimmel featuring a revolving panel of C I S O cyber experts. This is where CISOs talk.
tv. This is Text Strong tv. Hello, I'm Amanda Ani and I'm excited to be here today with Brian Land.
He is the Vice President of Sales engineering for Lucidworks. How are you? Great, Amanda.
Great. Thanks for having me. Well, can you explain to our audience what is lucidworks and what services do you provide?
Sure. Yeah. Here at lucidworks we essentially help the search and discovery part of the journey.
Um, and you can think about that as three different markets, customer experience, customer service, and employee experience. So, um, on the customer experience, think about commerce, Lululemon, helping customers find things faster, using machine learning, customer service, helping customers, you know, solve their problem, get their question asked faster as well. So delight the customers and also help deflect those incoming chats or cases into the call center.
And finally, employee experience, making employees more productive. You know, a lot of, uh, big organizations have silos of data, sometimes petabytes, so they have a hard time finding documents and information, so making them more productive and finding that, that information faster. Wonderful.
So we're gonna talk a little bit about implementing technology, especially AI and business today. So what are some of the challenges faced by businesses when it comes to trying to leverage ai? Sure.
I think, um, you know, a lot of our customers, especially commerce on that customer experience, they have been experimenting with ai, right? Google, Amazon and Apple. They were early to market.
Now most retailers have some type of AI on their website, so finding things faster, even at the type ahead. So I'm aggregating user behavior and clicks. And so, um, I see the biggest challenge more on the employee experience.
So some customers, big enterprises are still having challenges of enabling ai, consolidating their data, but I will say a current challenge over the last couple of months is how do we, they're all asking about across all three of those markets about generative ai. You know, how do I leverage generative AI and large language models, you know, for the customers, customer service employees and all of that. So, do you have some solutions and can you give some use case examples of implementing generative AI into companies?
Sure. We do have examples. So I lead our solutions and engineering team.
We do demos, POCs, and so we talked to customers and prospects a lot and partners. And so that's what we've been hearing over the past six months. I would say six months was like once a week, and then it was like every day now.
Now it's like every day, every meeting customers are asking about this. And so our, our product fusion, it's always been open platform, so you can roll your own machine learning model. So Advanced Enterprises, they may have a data science team, all right, I wanna roll my own machine learning model.
But now with large language models and generative ai, I mean, it's amazing what's out there, right? With, uh, open ai, Chachi, BT, and Bard now with Palm two that came out from Google and, um, and yeah. And so, so Fusion is very, uh, you know, it's a perfect solution for that since to roll into Chache, bt in fact, I get these questions over the past months and weeks, you know, it was, uh, hey, my C-suites asking why do we need a search vendor when there's chache, BT I can get an answer.
So, but, but, but there are challenges around that, right? You don't now fast forward, you know, some of these enterprises are locking down chat G p t, they don't want to put their enterprise data in the consumer app. And so that's where Fusion comes on.
We order enterprise platform, we provide guardrails and, and control around their data and the, the input and the output. So I think that's the biggest benefit is like you need those really guardrails and control and still get the full value of these large language models. There's so much can be done.
We're still learning stuff every week when we can do these p especially my team and the POCs, cuz customers ask, this is what I want to do. And like, oh, well this is, this is a way to do it. So we solve a problem and show it to him in a poc.
Now live pilots are running on websites, so pretty interesting, pretty fun days actually. I've been a longtime search engineer for a very long time. So it's, it seems like a, like a new revolution over the past few months.
So do you think that this is gonna be a required technology that businesses will need to harness or is it not always a good solution for every company? For example, do they need to look at the cost benefit and how, how do they weigh if it's beneficial and if they're seeing success by implementing this technology? Yes, co Well, cost is a factor.
So, and I see our cost consumption on open ai, it gets very expensive very quickly. And, uh, there's a few ways of controlling costs. One is instead of executing a query, uh, uh, an API hit to OpenAI for every single query, think about all the employees, all the consumer shopping on these sites that can rack up very expensive, but there's a lot you can do at behind the scenes at index time.
You know, what are the top dresses in summer, you know, that, that have flora in it and then, uh, floral prints. And so you can get that information from a large language model, store it in a product like fusion or an index and use it for future use. So it's a, it's a one-time hit.
And we have a great wine demo as well. So our, our merchandisers, you know, you have merchandisers at these commerce sites and they're doing things like, all right, what wine pairs well or what food pairs well with this wine, it's a one-time, that's a prompt, really think about these chat chip d prompts. And so that's a prompt you put in our engine and then it populates the data one time and then customers can see that output, that really valuable data, you know, millions of times.
Um, yeah. And so, uh, it, so it's not really, it's not one size fits all. It's like all the different use cases.
What do you want to prove? Um, you know, some of the other questions I've heard from, from customers and prospects who are like, I, I don't want you to show my competitor's data on the output because you can get that in chate, bt like, what are the top, you know, what are the top cruises? What are the flight destinations, what are the hotels?
And so being able to control, that's also, you know, you can do a lot of configuration with the prompting of a large language model. And so you have these series of prompts and then you get the data and you refine it, you control it, enrich it, and then present it back to the user. So that's what I mean by the guardrails and control.
Same thing with employee experience. One of the questions I, I got, uh, probably about a month ago was like, I don't want, uh, an employee to ask who's getting rift next week, right? So it's, uh, so, um, you know, you, you don't want to, and you don't want to push all of your documents to a large language model.
All of your data of course, uh, be very sensitive to that. So, um, we are guiding our customers to this, you know, some of the data that can be pushed to a large language model, enriched and extracted, and then what cannot, but there's also level of what we call security training. So there's a sensitive document that employee a may not be able to see, filter that out, so they never see it.
So we're having to index not just the data, but also employee document entitlements and things like that, the role in the organization, geo location. So, you know, without guardrails and control, you really can't do that. So it's, it's another, another great thing we're working with customers.
Wonderful. So you addressed the security issue, but how do companies ensure the quality of the data being generated? Because I know that there are some concerns about the hallucinations and um, bias and things like this.
So how do they ensure quality in their implementation? Right, right, absolutely. So the quality is a big thing.
Hallucinations is a big thing and uh, with, with a lot of search engines, you can do what's called ground, uh, grounding in the truth. And so, you know, I've been a search engineer nerd for a long time, and um, so you can enter a search query, this is the old days before large language models get a set of results. And that is, you know, it's always scored and parameterized.
So it's like this is good quality relevancy and it is relevant to what the user's searching on. So what we're finding, this is again, like I said, like every week we're finding something new. My engineers in the field, so, you know, in the past, uh, we were you, we were sending prompts to g PT four, getting results enriching it, and then, uh, a query to the index.
That's the ground, you know, it's like grounding at the end. But now we're able, we're showing where we can do truth grounding at the very top of the pipeline query pipeline. It's a technical term, but ground the truth in the results and then constrain the large language model to that.
And then you can even do stuff after that. You can enrich the data, add new metadata, user intents and things like that. It's pretty, pretty interesting.
Awesome. And I wanted to rewind a little bit. You talked about the staff and employee experience.
Um, how do companies handle when they're trying to implement this technology, how do they handle kinda the buck back from employees who are not happy with the technology or not comfortable with it or not seeing the benefits? Well, it seems like the other way around, you know, well, since I've been working here at Loose Works, it was, it was, uh, hey, I want the Google experience because I'm trying to find an internal document and I have to go to Salesforce, confluence, windows Share, SharePoint, I can't find it. So they're always looking for that Google experience and even Siri, Alexa experience.
Like, I want to ask a question and get it in the first response. Um, so there's been a big push for that o over the years and, um, you know, those technologies like Siri and Alexa, they are neural networks, very large. You know, they've been trained and trained and so we've already been working with, uh, with that for about three years.
We have our own solution around that. But you know, for example, the power chatbot and uh, now added a large language model on top, like Jet GPT or GPT four, it, it, even the, the, the employees trust the data even more now. So it, it is always been, uh, you know, we're rioting, we need faster access to documents and data, and now they see it can be done.
So it's, uh, we're kind of seeing that, that kind of trend. So it's mostly positive feedback and um, really helping with efficiency and the searches. Right?
But, and it, but you know, the first challenge was consolidating all that data from the silos. That's been a long, um, age old problem in search technologies. So I have 12 data sources, like I mentioned, cofluent, Salesforce, Microsoft, all that.
So, you know, we have connectors and just the data, you know, so get it all into one index to make it findable across, you know, with a single search box or something like that. But then once it's in there, add the machine learning, the neural network now the larger language model on top to enrich it and even power a chat bot. So you know, you have employees ask things from a chat bot and uh, and using their data, get those ask in a natural language type of question, get really relevant results.
So we're, we're seeing a lot of positive, uh, results there. Wonderful. So looking toward the future and this technology is advancing so quickly, so when I say future, I mean a lot could happen in the next five years, but where do you see this technology going five years from now?
Yeah, five years. I mean, there's, uh, it, it, you know, I've used these, these new models now, these large language models, there's automation on top of it, so it's model on top of model, it's, it's improving itself. So that's where I'm seeing that level of automation.
I mean, I think Morgan Stanley, I believe said, you know, 20% of jobs may be impacted within five years in different sectors. And, um, you know, if, if you have models acting upon models and this automation just keep growing and growing and doing our jobs faster and, and, and easier and more automated fashion, I mean, that's where I kind of see it, you know, right now it's a big, big model, large language model. We're asking natural language questions, we're fining our prompts, and now we're getting better at asking two or three or five level prompts, but I'm still a human asking that.
And uh, and now we're mo we're, we're moving that methodology to our query pipeline so that now the pipeline takes care of it, but still, you know, I define those prompts or questions in a pipeline, that's step two. Now, you know, in three to five years you're not gonna need a human or engineer or team. This is going to keep improving, improving over time, all automated.
So I know, um, so that brings up one more question then that I have is there is a concern about this loss of jobs, but do you think that, um, likewise there's gonna be some jobs gained in other areas and can you go into that a little bit? Sure. I think so.
I think everyone's, every enterprise is gonna be more efficient and, you know, with efficiency comes, uh, you know, uh, more equity and so to grow the company. So, you know, it kind of floats all boats. That's my perception.
That's my, um, you know, that, you know, that's my opinion is that, you know, all these companies are gonna be a lot more efficient and they may have to constrain certain departments. I'm not sure if it's HR marketing or what, and that'll all come out in play, but they're gonna keep growing and grow in other areas. So it's, I I think it's gonna be good for the economy as a whole.
Well thank you Brian, for coming on today and sharing your insights about this technology that is just making waves across the globe, I feel like, and look forward to speaking with you again in the future. Awesome. Thank you Amanda.
Thanks for having me. It was a great conversation. Thank you.
Hello and welcome to techstrong Don ai. ai, and we're talking about how to better integrate all our web applications because, well right now it's a lot of work and our workflows are something of a mess. Pascal, welcome the show.
Thank you so much for having me. Super excited to be here today. So every organization I know these days has some number of web apps and they're usually built to automate some process somewhere, but then they're all siloed and nothing seems to work together, and I've yet to meet a process that didn't wind up spanning at least three or four applications.
And the integration is always somewhat, shall we say, tenuous at best. So how can this all get better and what role might AI play in it? Yeah, it's a, it's a great point.
So I think, like we all know this problem of having like, you know, 50 tabs open in the browser and like copy pasting data between different apps and services and as you mentioned, they're all kind of like doing a great job at like a certain part of what your daily workflows are like, but nothing really solves the whole thing end to end. So we, and we as the users end up being kind of the, you know, monkeys almost copy pasting data between them. And what we're trying to do with Badin is essentially allow you in a very easy and intuitive way to bridge those gaps and build automations that work in context across your different workforces.
So examples can be, you know, when you're doing your research for the podcast, you might want to like look at LinkedIn and Crunchbase and news from a certain company or a person that you're talking to and then pull all that data into some project management system like or notion or something like that. So traditionally you would end up like copy pasting a lot of information between different tabs and a lot of copy, copy pasting, context switching and so on. And with Badin you could build an automation that does that for you with a click of a button.
You just skip the name or the context of the person that you're looking for. And then we do the hard work for you all on the browser on the edge with privacy first by design. And we leverage like new generation AI technology to help make it very easy to build those automations.
But traditionally you would need to build it in like no code builders with us to just at this point just describe what you want to do and it interprets that for you. So that's kind of like a high level, happy to jump into more details wherever that makes sense. So it has a natural language interface that connects to some sort of generative AI platform.
Did you guys build that yourself and how does it know what my environment looks like? Yeah, it's a great question. So we built, the badin comes in a, a web extension, so it plugs right into your browser, which is today where most of us spend, you know, 80 plus percent of our time in workflows and like that web extension and all the interface and connections and connectivity between those apps and the abstractions layers are all things that we built ourselves.
The actual underlying language model, we utilize some of the advancements that have been made in the last, you know, six months of this nascent technologies by companies like Open AI and others where we basically plug into their language models to do some of the, the work. And we then have to kind of like pre process and post process, um, those, the the models output. I think that's something that with a lot of like AI companies these days, you see that, you know, some of, there's two ways it goes.
Like what some of them try to build their own large language models but gets prohibitively expensive and it's a very fast moving field, so it almost makes no sense to invest there unless you can invest like hundreds of millions of dollars versus the approach that we are taking where we say that like, okay, this technology is going to commoditize in some sense where there's enough players like open AI out there that they're building these large language models and we built on top of those with kind of a lift and shift approach, whereas the new models come out like GPT five at some point might come out. We then basically just take our platform, move it from GPT four to GPT five, and then like benefit from that, that advancement. So that's kind of the approach we took.
So, so, so yeah, everything around it we had to build ourselves. So, And over time it seems to me at least that there's gonna be multiple large language models that people build for different use cases, but I need something that stitches all that together, right? Because they all have APIs, but you know, not every one of them is best suited for every use case, especially if it's a general purpose, large language model.
Yeah, exactly. It's a great point. I think that, you know, you see that with large language models.
You also see that with like database technologies. You know, today you have 10 different task management tools, you know, from Notion Airtable, Trello and, and, and more that serve like a specific purpose. And like we in general run into this problem where we have many, many fit for purpose tools, but it's hard to kind of like orchestrate them and like pull them all together into like a coherent workflow that makes it easy for the end user to use.
Um, so that's kind of like the abstraction layer that we're building with budin where you can, you know, integrate with your SaaS tools like, you know, notion, Google sheets, uh, table, you name it. But you can also integrate with those AI technologies like a large language model from open ai, various different models that we have available there, um, or OCR technologies or text to speech technologies. All these things become building blocks in workflows that you as an end user want to build and orchestrate.
So that's kind of like the way we think about it is just like abstraction layer that really allows the end user to make it easy for them to build workflows for their various use cases. So yeah, We have been trying to create this category of folks called citizen developers with mixed success. We give them low-code tools and we hope for the best.
And generally speaking, they build apps that don't scale, they're not particularly pretty and they're generally insecure, but other than that it's great. So if we use your approach, can I actually get to the promise of citizen developers because they actually have the knowledge of how the workflow works, but I don't, they don't have to be as deep into the how to code model as they might otherwise be today. Yeah, I mean I think like there's been a lot of amazing progress in the no-code field as you mentioned.
In general, we are much more, we're not as focused on like the building and app approach. You know, we wouldn't want you to publish a website with, with Badin we are very much focused on helping you automate the workflows that you know best, like your own workflows, right? And everyone understands what they do in their day to day and they know the ins and outs of what they need, uh, to have done.
And we try to now make it like as easy as possible. Now, when we first launched the platform a bit more than a year ago, the language technology wasn't quite there yet where we, we actually tried to have something like what we're launching now, but the models were just not strong enough, so it didn't work. Most of the time we decided not to go with that and instead launched with like a easy to use no-code builder where you still have to kind of like dissect your workflow, like you end up with this and you can see all the imagery on our website, right?
You kind of like end up with this like a blank sheet of paper. And as a user, I now have to understand it like, oh, if I want to, for example, for my sales workflow, get LinkedIn data into my CM system, I have to first extract the data from LinkedIn, then I have to maybe modify it in some way and then add it to my CM system of sorts. And that itself is almost like programmatic thinking, which we actually saw that a lot of users struggle sometimes with like dissecting their workflows and they might get the orders wrong and so on.
So that kind of like the kind of like the pitfalls that as, as you say, like traditional no-code development still has, what we're trying to do now with this approach is take all that away and like leave that to our model to decide on how to structure the workflow where you have to only describe kind of the actual workflow that you're doing the same way that you would describe it to like your assistant, right? Like the analogy we're trying to build here is that virtually anyone should have, you know, like a mini assistant that you can talk to and just say like, Hey, you know, Michael, I want to get the current page as a PDF and I might wanna share that via Google Drive with the participants of the current meeting, right? That instructions I could give to my assistant and the same way I can describe this exact same workflow into badin and it then figures out like, okay, these are the specific steps that I need to do in that workflow.
Build the automation for me, let me preview it because I think that's a very important step here to make it like trustworthy and reliable for the end user. So I need to be able to like actually see what the model is gonna do before it does it, and then like, you know, when it gets everything right, I just hit the button and, and, and the magic happens. And that's really kind of the approach we're taking.
Yeah. In your experience, how unique are the different workflows that people are creating? Because I sometimes wonder if we're reinventing the same wheel in different companies and maybe it's not really a differentiated workflow, so maybe we just need to figure out, hey, this workflow already exists over here and you can use it and away you go.
Yeah, it's a great question. The way we, so I think like 2, 2, 2 comments to that. One is, turns out a lot of workflows are structurally the same but kind of unique.
So we might, you know, both of us might, when we do our research before interviews, we might look at the same data sources, but you might store the data into like a Google sheet and I might store it into a notion, right? So it's not exactly the same workflow, it's like kind of the same skeleton, but it has different modalities or destinations or something like that, right? So that's something that we found and, and, and then now you have the complexity explosion of all the, you know, hundreds of SAS apps that are out there and all the different combinations of those.
So that's something that makes us challenging where it's like kind of like pre-building out of the box, all possible combinations of those workloads becomes very challenging. In fact, we tried to do that with our current approach. We shipped the product with roughly 700, almost 800 prebuilt automations at this point that are exactly those, you know, from us, from our users, from our usage community, what we identified as the most common patterns in various situations.
But then you still have this very long tail of like, you know, we might have a, you know, pre-built automation for the example that you might have, but with a different tool it's, it doesn't drop for you. You still have to go into the build and like edit it. And that's exactly the part where now we want to like make that last mile, so to speak, very easy.
And that model that we have is in fact trained on all those pre-built automations from us and also from the user community to try to kind of leverage that collective knowledge to make it easier for people to do that. So I think like yes, there is some kind of power law distribution where like the skeletons of the workforce are similar, but you have a very, very long tail of very unique combinations and very unique kind of instances of workflows and it's, we found that it's very critical to be able to cover those like long tail distribution to make the platform actually useful for people. And that's what we're trying to do now with bringing like the usage barrier down, introducing a simple language interface and let people just actually describe what they wanna do and take it from there.
Mm-hmm. As you kind of think this through a little bit further, will we ever get to the point where maybe AI will surface workflows that are inefficient and some suggestions for optimizing them? How smart can smart get, It's an amazing question.
It's a kind of like, if you think about kind of like bringing automation to everyone, like all end users, there's a few different problems you have to solve, right? You have to first node that what you're doing is automatable, which, you know, most of the people in the audience probably kind of like technically minded, uh, folks that like we kind of like tend to see repeating patterns and tend to say that like, oh, this is something I can automate. Then like once you automated it, uh, once you identified that it's automatable, you need to like build or find the actual automation.
That's kind of the part we talked about before. I know what I want to automate now I have to actually build it and then you have to be able to use it, right? This, it's kinda like this three-step problem.
And the way we approach that is we kind of go backwards and we say like, okay, let us rebuild all the common workflows and then just make it easy for people to use. So you bring it right to, in the context where they are, make it about extension, make it super seamless to use, make it, you know, very accessible. Once you have an automation, then the next step of what we launched last year was the visual build out where it has to be now easy for people to build their unique workforce once they know they have something.
And it's also kind of in the direction of what we're launching now with MeBox. The, the language interface is, is like, once I know that I have something that's automatable, I can easily build it. But the last step that we is something that we're actively working on but we are not quite ready to release it yet, is what we call smart suggestions.
And it's essentially, uh, identifying that what I do is automateable. And the idea here is that if you are already in the browser, we already see what the user does and like we can do that in a privacy preserving way. There's no data sent to the server or anything, but we kind of identify repeating patterns of like, oh, the user is like copy pasting data from a LinkedIn to a Google sheet, and like he might be doing that for like whatever recruiting, building out a candidate list.
And in that se in that moment when you do that like, you know, two or three times, then we want to kind of like pop up right then the moment and say like, Hey, you know, Lon or Michael, like here's something that you can automate and like we already prebuilt that automation for you, so we kind of like take you all the way there and you just listening you to click the button verify again, very important step to build trust and make it reliable. Like verify that what we understood you want to automate is correct and then just run it with a click of the button. In fact, we have that like already like rolled out a very small percentage of users that get like a preview of this and we're starting to kind of train the, the, the instances of like identifying, repeating workforce and suggesting it to users.
So yeah, that's something that I think is a big, big, big opportunity here in the automation space. And I always like, it's a really cool story because the founders of Honey, the, the, you got, you guys might know like, honey, the Chrome extension, which helped you save money when you're shopping. I think it's almost like the most brilliant user experience from an end user point of view that you can get because you installed a Chrome extension, you might completely forget that they even exist and then you're on a checkout page and like when they can actually apply a coupon code for you, they pop up in your face and go like, hey, here's something, here's like, we can save you whatever, 10% on this purchase, just the key will apply the coupon code for you.
And I think what we want to get to with automation is a similar user experience, but obviously instead of saving your money, saving your time, which ends up being also, you know, money for most people and, and it's kind of this very proactive automation approach. So that's where a bit of this inspiration came from. But, but yeah, I think it's a, it's a very good idea and it's a very hard problem to solve, but I think like with the modern technology and the way we approach the abstraction there, as we build, we're pretty close to being able to release that to the public and we have some like demos and use cases ready already.
Do you think we need to revisit a lot of the so-called digital business transformation initiatives that we've done? Because seems to me they largely consist of somebody taking a paper-based process and shoving it on a mobile device and we're still entering data and copying, pasting stuff. So, you know, if, if we look back in time, will we say, Hey, you know, that first generation of digital transformation was maybe cute, but hardly the point.
I mean, it's a, it's a very philosophical question. I think there's always different iterations to any progress we have, you know, in anything humanity. I think it is a great first step to bring the paper-based process into digital and maybe just have the same, you know, workflow, whether it might be inefficient or not in the digital domain, and then think about like how you can take it to the next step.
I think very rarely we've seen that people go all the way from, you know, like having a very boring like, paper-based repetitive process to something that's, you know, fast and efficient in the digital domain, right? Like expecting people to make that leap I think is a tall ask. So, so, so I totally expect it to be like an evolution over time.
Having said that, it will become a big competitive advantage for companies or people who, who, who are ahead of this, right? Like ultimately most businesses succeed because they're more efficient in some way, shape or form than their competitors. More efficient in production, more efficient in sales, more efficient at scale, et cetera.
And, and, and being able to like be an early adopter of the technology, I think will become a big competitive advantage. So we will see that like the winners of tomorrow are going to be those companies that take a very kind of automation first approach in their digital transformation processes and maybe they, they rethink as you suggested, like the whole process entirely and think about like, oh, what are the steps that we can automate end to end? Or maybe what are the steps we can even completely get rid of that we might need in the old school paper domain that we might not even need in the digital domain.
And like we hope to play a role with that with Buddy to make that easier for companies and individuals to do that. All right folks, you heard it here. Maybe in a world where almost anything is gonna be possible, the biggest issue is gonna be our lack of imagination.
So we'll figure it out from there. Pascal, thanks for being on the show. Thank you so much.
All right. ai. You can find this episode and others on our website along with show notes.
We'll see you all next time. com is the leading online destination for centralized computing related content. com covers all aspects of software containers from container management, data management for containers, container security networking for containers to the entire container ecosystem.
Kubernetes, microservices, serverless and more. com has the largest selection of container related news featuring breaking news, blog posts, podcasts and more. com to learn more.
This is Text Strong tv. Hey guys, thanks for the thrill. We're here with Shiva Nathan, who's c e o for ais and we're talking about operating system upgrades and how they've gotten better, but they're still pretty disruptive at the end of the day.
So the question is, is how to make that simpler. Shiva, welcome to the show. Thanks Mike.
Thanks for having me. So let me start with uh, operating system updates for web applications and mobile applications and IOT applications in different, uh, realms. So when it comes to web applications, most companies have moved to using public, uh, cloud providers like a W s or Azure or G C P and we no longer have to worry about operating system updates in those runs because the cloud cloud providers are responsible and they take care of it for you.
Whereas when you move to the mobile world, it's still early stages, it's still infancy. Uh, it's as if we are still in the 1990s for uh, hardware OS upgrades and stuff. So Apple iOS brings out a one major upgrade, uh, every year around this timeframe.
We are in beta right now. The release itself will come out in September and then Android comes out in December. The iOS would, uh, the Android 14 will come out in December and bring the big upgrades every year.
There are at least like a dozen minor upgrades as well, which makes the problem even more cumbersome. So what is the impact of all this in terms of disruption? Do the applications break or they just run uh, less well if they're not on the latest upgrade cycle per se.
I mean are there penalties in that? Because it seems like a lot of folks take their sweet time actually upgrading to the various uh, new versions of an operating system. Yeah, the biggest problem of not upgrading immediately, like upgrading your application immediately to the, to support the latest and greatest uh, OS update from these mobile operating systems is security.
So if you actually go back and look at the iOS upgrades and Android upgrades, the big ones and more importantly the minor ones, that happens almost like every month or so. The minor ones are mostly filled with uh, security patches. So if your application is not upgraded to take care of those security fixes that come from iOS and Android, you are in fact exposing your app and your apps users to all the security vulnerabilities.
So in which case the imperative is for you to jump, make, uh, do the right thing for at least the security updates. That's one. If you remove the security thing out of the picture and then you start to look at other stuff, if you don't upgrade your app fast enough, your app will start to look stale.
So imagine when face ID came up into the picture and if your application only supports a touch ID or fingerprint, ID still, any person that downloads your app immediately know that hey, this is not a cool app. I can't use face ID anymore on iOS. And when they don't see your app to be the cool taking advantage of the cool features, your adoption goes down.
When your adoption goes down, your reviews and ratings goes down, it's like a vicious cycle down. You're basically getting flushed down the al. So that's what happens.
Um, to that end then, are security people driving the conversation more about ensuring those upgrade cycles? Cuz we hear more about DevSecOps and we hear more about software supply chain management, but has that become the primary reason to drive an upgrade? Uh, not necessarily.
You would want to believe that that happens, but not necessarily within an enterprise development organization. There is like a um, healthy and unhealthy strain of, uh, relationships between the engineering team that has to do the work and the security team and the product team. The product team wants the latest and greatest school application specific features.
They are not as, uh, vest in getting the engineering team focus on doing what is called grunt work or maintenance or getting the app to work on the latest thing. They want the latest cool business feature to be put in. That's what they want the engineering team to spend time on.
The security team on the other end wants all the security fixes to be taken care of. The engineering team itself wants to actually keep everything up to date, not just with iOS and Android, but your application depends on lot of other things. APIs from all the other service providers, let's say's TRI or PayPal or uh, Twilio or someone, the engineering team has its own backlog of things about keeping things updated.
So between this triad of security product team wanting cool new business features and the engineering teams own backlog is a healthy and health healthy discussion. And especially in this economy when there are very few engineering staff and questions being asked on what's gonna bring revenue security kind of falls to the lower pole, but the CEOs or the CTO should rather get the new feature out that brings some incremental revenue rather than fix something that'll actually make the app a little bit security robust. Mm-hmm.
How automated can all of this get going forward? Um, I understand in the past it was very manual, but it feels to me at least a lot of this is getting more automated and should become a little more turnkey. But what's your sense of how much have people embraced automation for operating system upgrades?
The development process itself is getting automated a lot more from the time that the developer checks in the code to testing happening, the build happening, the testing happening, the performance test and the labor test happening, and then the pushing at the gap store, that part of it is getting automated quite a bit, but unfortunately it still needs engineers or fortunately, uh, depending on where you set it still needs engineers to go look at what really changed with this new iOS 17. 5 and doing those changes in your particular application. And same story for Android as well.
Android 14 is gonna come out in December and you still need engineers to go look at what change within Android 14 and Android 13 and then make those changes to the app once you check in the changes things are automated almost all the way to the app store. What's your best advice then to the DevOps teams that are in charge of keeping track of those changes and understanding what they are? Because it's not like the operating system update just appeared overnight.
It seems like they get telegraphed in in advance, but how far in front of this should I get? So There are two ways to solve this problem, right? The one way to solve the problem is of course to have your team start to look at the alpha releases and beta releases.
Like right now we are in IO 17 beta, have your engineering team go look at IO 17 beta and find out what's happening. Will there be still something that gets surprised on you when the IO 17 gets production release? Of course, but at least you are caught up to 90, 95% of the changes and you're doing it in your own schedule rather than having to do all of that on the day that I 17 gets released, right?
Or use technologies like Aus, uh, where you are kind of like absolving your engineering team off the need to use, uh, the platform, uh, of features that are to be constantly upgraded, doing grunt work to keep your app updated to IY 17 and Android 14 and so on. So either one of these two charges, either do the work or absolve yourself for doing the work by using technologies economists. Those are currently your choices.
We hear a lot about artificial intelligence these days. Is that gonna get applied in this space and how so? Um, not yet is the answer that I want to give.
I'll tell you the main reason why artificial intelligence requires data to be trained on. So iOS 17 when I was 17 comes out in September and Android 14 comes out in December. It needs probably two or three months for all the generative AA and the intelligence to really learn what are the changes that's happened, what people have done with it, what are the core changes that they have done.
So if you go back to, uh, the artificial intelligence system in December after it has had three months of data and ask, uh, the artificial intelligence system, Hey, tell me what I need to do to upgrade my app from IOA 16 to I 17. It can spew out some stuff to help you, but unfortunately it takes three months for the artificial intelligence team to learn and those three months, your app is gonna be dated, your app is gonna have all the security vulnerabilities and stuff. So you actually need to unfortunately get ahead of the game and then do it yourself with engineers, with real human real intelligence or human intelligence than wait for artificial intelligence to come and help you.
Do the folks who make the operating systems really understand the implications of the upgrade or are they just kind of focused on the operating system and the features but they don't really think through what the downstream impact of that might all be? They do and they don't. Uh, the reason is if you go to Apple or if you go to Google and look at the iOS development teams and Android, android development teams, they're in a raise to get features out themselves.
Um, I'll talk about one particular feature. If you are on a iOS, uh, location for example, there, there are, um, you can actually give uh, precise location which tells you exactly where you are or a non-PC precise location, which just tells an application a general area that you are, we kind of know from the IAS 17 beta that Apple is gonna come up with a third thing, which is like give you a very, very precise location inside a mall or inside an airport to be able to navigate you to that store within the mall or the particular coffee shop within the airport. And that's coming out hopefully in I 17.
That's what the rumors say and I think that's what's uh, gonna be out in I 17, right? And when they're trying to do that, every application in the world, two or 3 million application developers in the world have to actually go back and look at that particular change and make their app either leverage it or make sure that their app does not break because of this particular change. Right?
So if you are an iOS engineer with an Apple, are you thinking about the impact that you're making to all these 2 million applications? Yes. But at the same time, what is driving you more is a cool new feature from Apple that you want to drive?
And what do you think wins? What wins essentially is that Apple development team saying, you know what, we only had two levels of location. We're gonna have three levels of location that's always seems to be winning.
Then the problem that it creates to all the 2 million application developers out there, it takes some time, it takes few years at least for the operating systems to mature to the point where Apple and Google will start thinking about, Hey, if I make this change, how much does it impact the people where Linux is today? Linux operating system upgrades when it happens? You understand that, hey, there's a huge install base of people using Linux.
I can't fundamentally go and break things immediately. iOS and Android only had like, what, like 15 years of uh, um, in the industry compared to 30 years or 40 years for unique operating systems. So it'll take, I'm not saying it'll take another 25 years for mobile operating system to catch up there, but it'll probably be another five to 10 years for it to catch up there to that level of maturity.
What is your best advice then to uh, say a DevOps team that's kind of managing this process? How do they kind of get their arms around it? What have you seen, you know, people who are successful in keeping pace with operating system updates and not losing ground every time there's an update?
So it's only a little of a plug off, uh, anonymous here, right? Our customers had the same problem that most engineer enterprise teams are facing, and our customers now are extremely happy because they chose to put their application on top of the anonymous platform and not just a platform, but it actually gives them the leverage to look at the source code. We are the only company in the world that licensed the source code.
It's as if your engineer slept work up and you got all the source code available to you. So look at not just Aus, but look at similar technologies out there that absolves you of this responsibility of your engineers having to update all of the basic or core basic features doing the grant work whenever an iOS 17 change, iOS upgrade happens, or a hundred upgrade happens, or any of the 12 different upgrades that happen within the year. So that's what I would point them to like, do you anymore worry about operating system changes in the web application world?
You don't. You give it to the cloud providers to do it. Why do you have to worry about the same thing when it comes to mobile operating system changes?
You need to use technologies like Aus to do it. All right, folks. Well, if it's non-differentiated value, it should be automated at the end of the day.
Hey Shiva, thanks for being on the show. Sure, thanks Mike. All right, back to you guys in the Hi again, everyone.
I hope y'all enjoyed today's episode of Techstrong tv. We had an amazing set of interviews with industry professionals to give you the inside scoop into the tech world. We'll be back again on Monday, so we hope to see you then.
In the meantime though, if you want more tech strong TV content, be sure to check out some of our podcasts or download our mobile app. Thank you so much for watching and I hope you have a wonderful rest of your day. As always, stay strong.
Text strong.