Techstrong TV July 16, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Hey, everyone. You ready to get your vibe on? You're watching Text Trunk Inc.
Hi everyone. Happy Wednesday. It's Alan Shimmel for Techstrong Gang.
Welcome to joining us right here on Hump Day. Kinda hard to believe Wednesday, I believe it was Monday. Um, we've got great show too.
We get some interesting things going on. Not all ai, but some ai. Uh, we've, and we've got some really interesting people to talk about 'em with.
They're all regulars here on the gang. Let me quickly introduce you to them. We have, uh, Mitch Ashley, Chris Blak, Kate Scarcella, Dan o Dan O'Brien, and of course the dean, Mike Ard coming at you from Lake Placid.
I don't know if he's going off the ski jump like Eddie the Eagle or what, but whatever. Welcome, welcome gang members. Thanks for being here.
You know, we're gonna start off today. We're gonna come back to the vibe, but we're gonna start off with Arm. Mike.
You know, to me ARM is one of the great success, untold great success stories in tech over the last 10 years. Why don't you start us off there? Yeah.
The, their CEO came out and just kind of made a comment to the fact that they now have 70,000 customers for our arm chips. And we all talk about GPUs all day long. But most of the workloads I know are running on traditional CPU still.
And, um, we talk about Intel and uh, a MD, but looks to me, you know, I think it was last year when AWS told me, I think half of their new workloads are running on their ARM-based chips. So Dan is Arm kind of like rapidly emerging, is, I don't know, the number two, three player in CHIPS or where, why don't we talk more about arm? Yeah, listen, I, I, I think the ARM story has been incredible.
You know, if I had to pinpoint why we don't talk about arm, uh, it's, 'cause generally I think we're talking about their customers. I mean, they are really the key enabler of a lot of silicon innovation in the industry over the past decade or so. Um, you know, it comes from really more of an embedded background, really, the primary player in mobile enabled by their customers like Apple, Qualcomm, media Tech, uh, Samsung, Huawei, uh, but more recently, you know, really making a, a significant move in the data center space.
And that's really where the action is. As we know, um, AI silicon, uh, is all the rage. And, you know, pretty much every competitor that we talk about to Nvidia is really being enabled by arm.
I mean, you know, Intel and a MD would be kind of the exceptions there. And, uh, I think we all know kind of Intel's woes a MD getting more competitive. I think their rack scale solution coming next year will, you know, continue to give them some momentum on the GPU side.
But really all of these ai, asics, uh, are are really driven by arm. We think about, you know, Google's TPU, um, arm ip, you know, with some Broadcom, uh, design help behind it. Um, everything Marvell is doing, uh, really everything the hyperscalers are doing through vertical integration enabled by Arm.
You see, you know, graviton and, you know, Inia and Traum at the AWS, um, you see the Maya Silicon that Microsoft's working on. You know, really ARM is the enabler of that alternative to Nvidia ecosystem. And, you know, a lot of it coming from really their history as somebody who's been able to really drive a lot of performance at a lot lower power, you know, envelope, obviously power consumption is coming a really key bottleneck in ai.
Um, but you know, they've also invested a lot on the software side. I think we continue to see that, you know, software is the great enabler of hardware. You know, in order for a new chip architecture to Latch, you really need to invest heavily on the software side.
And I think Arm's done that. So, uh, definitely a hot name. Somebody we should probably be talking more about.
Um, and again, you know, to the degree we talk about them less, it's because they really give a lot of the shine to their customers. It, it, it's almost not as much customers as truly channel partners, right? Because I think that's the key to, um, their distribution.
How many times have we sat on here and said, who's going to compete with Nvidia? My God, this is a runaway train. No one can compete with Nvidia.
And I'm not saying anyone can at a $4 trillion valuation, but when you look at arm's distribution, and that's Dan, to your point, you just nailed it. It's, it's, we don't hear about arm. It's because most of their channel partners, their go to market partners are companies we're hearing about now adding them all up.
I still don't know if they come close to NVIDIA's, you know, uh, market share or penetration there. But remember, NVIDIA is pretty much, I mean, it was a gaming chip now, of course, but the, you know, the real bread and butter here is the AI chip. I think ARM has a, a much broader footprint of technology, you know, in terms of chips, it's not, you mentioned it's the mobile chip, it's now the data center chip.
It's the laptop chip, right? It, I mean, it's an enviable powerhouse, Yeah. Significant inroads with PCs, right?
Enabled by Apple and Qualcomm where they get some share. Um, and starting to get into the market themself. I mean, I, I think we see, you know, ARM launching its own chip sometime later this year.
You know, it's been widely reported. Meta is a kind of key customer for them on that side. Um, but really much more playing on the CPU side, you know, than the GPU side at this point in time in the data center.
But, you know, companies come out and said, targeting 50% share of data center by the end of this year. So, you know, clearly making some significant inroads. And I think a lot of that's been enabled by the, you know, internal silicon efforts of the hyperscalers, uh, the past several years.
I think notably Google and, and, and AWS, um, quite far ahead on that front in terms of using arm Yeah, arm's, kind of one of those 20 year overnight successes, right? They've been at this for a long time. Um, but to your point, Dan, it, it's, we talk about 'em when we talk about, um, Qualcomm and Apple M chips and all of the different, the, the licensing that they've done with their architecture, which has been frankly a brilliant strategy.
It's the alternative to Intel where here's the architecture. You can build your own chips using that, you know, licensing that technology. And you mentioned this too, and I want to emphasize it.
'cause I noticed about three, four years ago when you were talking to ARM people, they were emphasizing how do we get compatibility for ARM into open source projects? How do we get compatibility for ARM into data centers? How do we get compatibility?
So they've made a real effort to kind of, you know, go at the, go at the, the low end of, let's get into the infrastructure, let's get into this software stack to make sure we're already there so people can compile and run on ARM just as well as they can, you know, in Intel or in some cases in Nvidia. So Mitch, you know, we've talked about the concept of application modernization on this show, and it's always usually in the context of mainframes to something that's X 86. And as I scratch my head and I think about all this stuff, I'm like, am I gonna see app modernization where we're gonna take legacy workloads and move them from X 86 to arm because there are benefits to be had and how hard, or how big a lift might that be?
Absolutely. And that goes to the whole, you know, underlying software substrate. If you are open source stack that you're using all the different element of projects, for example, or support, support arm already, you can recompile your applications.
Maybe you do some design to optimize for mobile kind of apps if that's what you're doing. Um, but it's a much smaller lift to do that today, by the way. You know, we, we talk about modernization of mainframe applications.
Well, how old is Netflix's infrastructure, right? That's been built over many, many years. There's a lot of legacy stuff they have.
We think of Netflix and AWS and, uh, and Lyft and, uh, different companies that we work with today, as, you know, new and innovative. But they've got software stacks that have been present and built up over many years. So everybody has got this modernization challenge to some degree where they need to keep up their software infrastructure and their stack moving forward.
Well, and, and you know, this is all happening in a macro environment where, to be clear, none of us have any idea where the hell AI is going, right? And suddenly in the last couple years, we've all gone, oh, graphic processors are really good at vector math, which is what we need to run the, you know, the LOM holographic spaces and so forth, and it goes through the roof. At the same time.
The use of those chip sets in that technology, that whole stack is using more power than, you know, God's own little bunny is to make popcorn. Right? And it's becoming more evident that, that there's other ways to do it.
You know, there's tasks that inference engines are fantastic for, but asking them to add 42 plus three is not really one of them. And so in this, at the chip level, everyone is focusing on GPUs, but at the architecture level, and I have no idea whether this is part of it, but this is the way I think about it. We've all forgotten other chips exist, other processors do things way better things quite often, as long as you're not trying to, you know, you know, fold a molecule And, and with a lower energy consumption, which is, as we go forward, as a person who has dealt extensively with energy, I can tell you that, um, from a ICE have seen them, um, the arm architecture through IOT devices and I I OT devices, and that footprint is massive.
So I think on for the win, Well, the trend in the market towards heterogeneous compute, right? Really design, uh, silicon for, you know, for the specific workloads, um, that's been kind of the mega trend over the last several years, that more workloads that are finding the way that Silicon, that's kind of purpose built. Um, and Arm's really been the great enabler of that, right?
So I think, you know, that that trend continues and, you know, to Chris's point on a lot of the stuff we're playing with in ai, we may have a fundamentally wrong architecture for it's gonna land in the long term. And, you know, arms seems really well positioned to benefit from some of that rationalization and that balancing of, you know, kind of price performance that needs to happen across the market. They've got the licensing model down for sure, Dan.
Well, Dan and Dan, Dan, I love where the, where that goes as well. 'cause uh, that takes us sort of a step further than I was thinking, but yeah, I'll say it. You know, we think that 90 to 99% power reduction to see the, uh, achieve the same task can be done, right?
You know, it's just as you look case by case, it's sort of ridiculous. Um, but the, you know, as you take a step further, because of the adaptability that we have these days with, with these sort of tools and structures, um, yeah. Not just GPUs or X 86 or, you know, why not, you know, remember EPOS and programmable chips and so forth, it was really big back in the day and customized hardware for workloads.
Yeah, I think you're exactly right. So if they're down on that track, I'm with them. Let Me, let me come back to the best kept secret in tech kind of theme on Arm here.
If we weren't in this Nvidia irrational exuberance, if you, if I may call it that at some level, what a story arm would be because they would be competing with just a MD and Intel and, and quite frankly, they're kicking butt there. Well, AMD's a channel partner, right, at some level, but they'd be kicking butt. I mean, when you look at what Apple has done with their chips, with the Apple silicon compared to the Intel, you know, based on this architecture, it really is.
I mean, it's a phenomenal, phenomenal story and they've been able to do it. Now, Dan, I know you used to cover Arm back in the day. I'm not gonna say you, I'm not gonna say you're all Yeah, they were a public company before Software bought them, uh, uh, covered them as an equity.
Yeah. And they, they're riding the Nvidia train too, right? They're, they, you know, they're on the CPU side and their CPUs are right alongside NVIDIA's GPUs.
I mean, let's not forget Nvidia did try to buy Arm, uh, which maybe was the validation we all should have picked up on at the time, um, as to their potential. Obviously that didn't get through, uh, you know, antitrust, but, uh, you know, NVIDIA's cra, CPU are all based on arm, arm, uh, architecture as well. So, um, certainly they would be picking up more if Nvidia weren't doing what they were doing, but, you know, they're, they're benefiting from that trend as well.
Yeah. Their Tegra chip is based on Arm several things. Yeah.
Anybody be, anybody besides me kinda have a perception that maybe these arm chips are just fundamentally more secure, the next 86 chips. Is that a benefit of this as well? I don't know.
I, I always think of, I met, uh, a person who 5, 6, 6, 7 years ago, and he just left Intel as their, you know, a, uh, not firmware, but the, the actual chip security person. He just got the point he had to say, you know, we can't tell anymore, right? So maybe, you know, security, the chip level can be, you know, optimized.
But again, we're, we're levels of complexity. And I'm thinking out loud here, recursing these same tools back on that maybe we can raise, uh, chip level security, but frankly, I never count on that sort of thing. It's beyond the can you, you need to secure everything at a layer you can see.
And the other thing, you know, Mike, that sounds very much like the old, old Apple's much more secure than Windows kind of argument, right? Look, when you have a certain amount of of market share, you get that bullseye, right? And I, and, and this might be an interesting thing to see how it plays out.
Arm keeps making a lot of noise about how much market share they're getting. They become more of a target for the security people. I, I, I don't believe that any of these architectures are necessarily inherently more secure than others, right?
I I think that's fair. A but I also think, you know, we can probably chart arms rise, you know, alongside kind of Intel's, you know, fallback to the back where, I mean, I think, you know, the reality is is we're probably in year 10 to 15 of a three to four decade transition away from X 86 is the dominant architecture. Um, um, obviously ARM obviously was there on the embedded side, but really kind of took the momentum from Intel and Mobile.
Um, we've chipped away at Intel a little bit on the PC side with what Apple and, you know, Qualcomm and AI PC have done. And, you know, X 86 is the dominant architecture and data center for, you know, kind of all of history up until probably the last five to 10 years, uh, with re you know, really the momentum coming in the last five, um, and seemingly going forward. So, um, you know, that, that, that's probably the bigger trend here is, you know, we've kind of moved from an intel world to an army world.
I Mean, when they write the history books on this, I mean, in Intel's miss on mobile in general, it is probably, I, I'm not gonna say it's fatal, but it was fateful in terms of allowing a lot of, uh, a lot of people to come in and, and, and compete there. Um, but look, hey, I got, I got, I got 10 bucks that says that there's gonna be an AI agent for converting X 86 workloads to arm before the end of the year. So it might not be two decades, Dan, If there isn't already, If there isn't already.
Pretty compelling stories there on AWS with customers making that exact transition in, Hey, speaking of AWS, they're kind of groovy getting their vibe on. We're gonna talk about that next. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back. And as Alan said, AWS is previewing an IDE called kiro. And it does a couple of things, but at its core it's talking about vibe coding for the enterprise.
And the two pieces of it are hooks that are essentially links to backend services that are probably AI agents that will automate a series of tasks for you. You can program those yourselves. And then there's a thing called specs, which are the actual steps for building the application and more of the vibe coating, but it's kind of like guardrails built in so that you can't go wrong and all you have to do is kind of like, describe what you wanna have happen and the ID will magically make this happen.
Mitch, we've talked about vibe coating before and we've kind of been a little bit dismissive it as an enterprise tool, but I don't know, is something happening here? Well, the big thing that's happening first Kiro is ides CLI are cool now, right? Everybody's coming out one, or they're acquiring one or doing something around that, because that's the environment that software is created in.
That's where developers spend most of their time. It's kind of the kitchen of software development. And what, what's interesting is a KIRO announced by AWS is actually based on the open source of Microsoft's Visual Studio Code vs code, which has got 73 to 75% market share among developers.
It is widely used, you know, even app people that like Apple still develop on VS code. So they've taken that open source and what they've done is not just added another I can generate code with whatever LLM model that you like to use. They've stepped back and said, well, yeah, we can do that, but let's really talk about what the developer's work is.
So they've, they've emphasized what they call secure specs, was the upfront developing stories, turning those into requirements, turning that into design that whole flow before you really start writing code and laying out those plans and then, uh, proving that with the, with the developer and then going to the coding phase and moving beyond. And of course, what you talked about hooking into AI along the way to build and also to to operate your code. So I think it's more of a holistic approach to ides than just a nice editor sitting, uh, alongside of a, a great natural interface to kind of guide your, your whatever you're asking the agent or the AI to do, LLMs to do on the backend.
And I think we're gonna see a lot more of this. There was an announcement actually just the other day by Perforce who came out with Perfecto ai, which is a testing tool that instead of just generating tests, it actually monitors the requirements, the, uh, PDFs or the, the, uh, PRDs that you put together for a product. Whatever you use to guide, guide your requirements or stories from Agile and actually generates tests from that.
And analyzing code is code changes. So it's dynamically creating tests, not just here create a bunch of tests for my code today. It's looking more holistically at the development process.
That's the key trend to really get the productivity out of AI for software development. Very Good. Mitch.
You know, I gotta tell you, people say shimmy, you have fun doing what you do. This, this whole vibe thing is exactly the kind of stuff why I enjoy doing what we do here, right? Lemme just get a quick history of vibe coding on Textron Gang.
I don't think it was more than three, four months ago. It was the first time vibe, maybe six months ago. We mentioned Vibe coding and Chris, I don't know if it was you or one of the other security experts said, nonsense, this stuff will never work.
It's, it's buggy, it's terrible. It's it's crappy code. It's low quality, it's a toy about a month later, you know, vibe, coating's, a nice little kind of hobby to do for a little home project.
You know, it's not terrible. A month later after that, you know, a lot of people are vibe coating. There's some interesting stuff.
It'll never work in the enterprise mind you, but you know, for little stuff it's not so bad. Here we are, mark, the date July 15th, AWS comes out with an IDE for vibe coding for the enterprise. Is this, is this the world we live in?
Is it, are we in of like a, a time zone? Chris, what do you, what do you say? Well, I, that doesn't sound like something I would say, but if I did, I'll on that one and, and it's wrong.
Now I'm listening to Mitch, you know, uh, I'll go through all that. And that sounds exactly right to me. And you know how the concerns I have for how, you know, AI is, is applied these days, that sounds like a logical structure.
Now, I'd, I'd love to spend more time and pick it apart and see exactly how they're doing something LLLM stuff, but it's, it's is, yeah. So that, you know, what I'm finding as, as folks who were spending a lot of time around me the last couple months, uh, are finding out that, I'll use the word semantic an awful lot because AI doesn't describe at all what we're talking about here. I mean, any more than 700 other things, but they're semantic systems, and these are exactly the kind of, uh, use cases where you can understand that there's, there's someone over here who has some characteristics and they're relating to something over here and building code.
Mitch, as you're walking through that, I'm thinking through the steps and how that would be used. And, and again, I would bet that if I stared at it really hard, I would have a lot of criticisms, but it's in the right place, right? You know, I haven't done a lot of coding in, you know, I have used every language ever, but I try to avoid it in the last three months because I have these semantic partners.
I write or copy and paste and occasionally edit piles and piles and piles of code. So everything I hear about vibe matches my thoughts. You know, it's not about the exact, can I put the commas in the right place?
Is do I know why I'm doing what I'm doing? And that's the semantic screen kind of thing that, that what we, you know, erroneously call AI is literally fantastically built for it. Yeah.
The term was actually coined in February, Alan, and it was an expost by, um, Andre Cari, who was a co-founder of Open ai. I think he was Tesla before that. Um, and it was his, it is a kind of a nice little definition, essentially.
It's, it's, you know, when you're vibing, you're like in the zone, right? And this is about being in the zone of creating software using ai. So you're leaning into ai, not writing code traditionally, and kind of augmenting with, with, you know, some things that AI can do for you.
It's like, let's maximize what you could do with AI and see what's possible. And that's what caught on about it is it started to describe what developers and platform engineers and testers are starting to experience as they really lean into AI for their work, is there's prompting and then there's really vibing where you're really using AI and some of the capacities that, so I I, in ways we having two, I see two use patterns around this vibe coding that I, it, you know, just from my observations and my friends, there's the, the crisp Blas of the world who I wouldn't necessarily consider a coder, a professional coder who are vibing, right? They're vibing and, and then there's real, there's real software developers, right?
Real professional coders. They're also vibing, but I think they're vibing to be fair, and Chris, no disrespect to you, but they're vibing at another level, Right? Right.
As they should. Oh, it's an accelerant no matter where you're on the curve. Yeah.
Right. Whether you're, you know, kind of more of a beginner who knows enough to be dangerous or a true expert, it's shifting you up the curve in terms of what you're able to produce, right? I mean, that to me is the big observation here is like writing code and software development, software engineering.
It might be the ultimate AI use case. Well, that, that's what you would think from all the, the, the, the press and, you know, airtime it gets, it, it certainly is, you know, and, and Well, but I think a, the people are also like, that's, that's flowing through, right? I mean, you've heard about like a 50% decrease in the number of DevOps people in AWS as they're rolling this stuff out, right?
You've seen, uh, you know, some of the layoffs across the tech industry. Uh, I do think that we are getting that predictivity because of this. And I think, you know, it's real enough that it's actually being reflective.
Google paid, what was it? Was it three and a half billion or two and a half? No, excuse me.
4 to license the windsurf. We just spoke about this yesterday. 4 billion to license the windsurf, uh, uh, software.
And they hired the CEO, like the, the brains of the operation, supposedly. And they were in pretty good shape before that. Yeah.
That was Gemini. They, they clearly wanted to make Gemini a better AI coder. But let me give you the other Absolutely.
That dropped on this some other AI company. They haven't released the amount they paid for it, but they bought Windsurf yesterday, right? I, and I, I, forgive me, I don't remember the name of this other AI company.
Everybody's Got a piece of windsurf. Like if you didn't buy Windsurf for the last week, You've missed out. Exactly.
So, but we spoke, There's cognition. Alan Is cognition, right? You know, so we spoke about yesterday, well, what, boy, they left windsurf for dead.
They're picking the bones. Someone, someone found those bones pretty tasty. And Windsurf iss pretty smart, smart people.
I have a couple of questions for Mitch. So, does vibe coding mean like no-code, low-code tools or history? I mean, are we like moving on behind?
Uh, 'cause you know, it seems like this is the same use case that we used to use for low-code, no-code. Yeah, I think, I think AI is the new low-code, no-code. And it's interesting talking to people that have low-code, no-code tools today is they're in this bifurcated world of bringing in AI to start to do more of the work with citizens developers, but they also don't want to immediately, uh, cannibalize their current customer base of got things have already built in the current tools.
So I think that transition is happening, but I, I want to go back to what Dan said. I, I took the position about three months ago in one of our papers that the place to watch of what AI is doing is in the developer world. And because not just 'cause I like development and like developers and all that stuff, is, that's the tip of the spear.
That's where, that's the landing dock on the shores to, uh, you know, come into the country and go through immigration and be part of the development process. Developers love to innovate. They love to try new things.
Not every one of them, but it's a very innovative crowd, very in independent crowd. And they will find use for it, and they'll find use cases you don't even anticipate. And if you follow what's happening in development and how that's changing, not only coding, but the overall work of the coders.
I mean, I talked to very expense experienced developers that tell me I'm more tired than ever when I go home today because I'm thinking about this stuff at a much different level. It's just not like, I need to convert this from JavaScript to this. It's, I'm working up here and they're getting so much more done.
So it, it is informing, I think, the rest of the market, at least in the software world of what testing can look like, or what platform engineering can look like, what ops can look like. And I think the vendors who are smart will look at their own development teams as well as other development organizations as leading indicators of what AI is changing in how we create software. I think you're so smart.
We call the tip of the spear, Mitch. I mean, it's the people building AI that are applying it to their own work, you know, their own kind of workload. Um, it, it, it really is kind of where all the experimentation and the leading edge is happening.
Um, that kind of the ultimate client zero story. And now that's why I think it's so interesting to watch the companies that are building ai, because I think they're gonna resemble what all companies look like longer term. I think, you know, the things you see happening and the changes, you know, in terms of workforce composition that you see in the companies that are really leading on the curve of building ai.
Uh, that's kind of where everybody else is gonna end up eventually, in my opinion. All right, here's my, here's here's my prediction, right? So we started out from concept in February, and we're now at Enterprise in July.
All this stuff is a commodity by September. Nothing a see here. And, and I think along with that, Mike, it totally equalizes people who are non coders to the people who are big DevOps quotes.
Well, that, that's that whole citizen developer thing. Chris, go ahead. I'm sorry buddy.
No, that's okay. I, so I'll give you an example of, of vibe coating, right? You know, in the last couple months, you know, I have written hundreds and hundreds and hundreds and hundreds of, uh, shell scripts and Python scripts and so forth, because I said, I want to build a metabolic system.
That's it. And step by step, you know, my, my AI partner who knows how this stuff works, presents options, you know, raise the code. I put it in it, run it, it works.
Doesn't work every single step that I know how to do myself faster. And I don't have the attention and span, you know, I've hacked everyone's code. I've written some myself, but as you say, I'm not a coder, right?
That's a long, tedious job. Now I can surf in, because to your point, Kate, I know what I want. I know how it's done.
I don't wanna do the work. I don't have to. I just, I guess to the term of this segment, I just know the vibe.
I know what I want. And now I have a, a complex, you know, we quiet wire have a complex, uh, system, you know, mesh that is based on, you know, existing technologies that is, uh, supporting semantic processes in a, in a, in a auto autonomous, you know, human machine, a to a, you know, fashion in two months. I love it.
Yeah. I wanna close this segment out with this, though, no doubt that the, the, the lens has been focused or the, in, in terms of the AI mar ai market on how AI is taking over coding or has the potential to, to really ruled coding and software engineering. But as humans, as humans, and we're all humans, I think here list someone's a deep fake, um, what it's doing in software coding, it will do in other verticals, whether it's medicine or lore or manufacturing or what have you.
That's why we spend so much time talking about ai. It's not just that we're geeks and this is the world we live in. This is, this is happening, this is going to, this is going to, you know, send ripples and waves and tsunamis across every piece of it.
And, and it, we can't, you can't lose sight of that when we talk, you know, I, I've already spoken to some on my wife's family, to tell you the truth. They're not tech people. And they're like, ah, yeah, this ai it's a tech thing.
You know, they, they don't see it coming, you know, as Bobby Bakala said to, uh, Tony Soprano, do you think you even hear it when it comes? You should be hearing it right now. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. Visit www security boulevard com to learn more.
com. Home of security bloggers network. Hey, folks, we're back, and we're gonna shift gears a little bit.
We're talking about some ai, but we're talking about cybersecurity and impersonation of government officials using deep fakes. And the latest victim, apparently is Marco Rubio. But this has been going on for a little while now.
So, Chris, are we on the cusp of, I don't know, outright anarchy? I mean, who's in charge? And nobody knows.
I am shocked, shocked to find gambling going on here. Um, yeah, this is in 1990 at General Electric in South Carolina. We, you know, I was there, we put a video conference centers, we had a demo tape, it was the world's leading graphics, uh, animation, and it had like real fluid, fluid mo uh, T-Rex running around with silver skin.
But, you know, moving realistically was amazing. And sitting there in 1990, and I look, you know, talking to my, my colleague saying, at some point, we're gonna make it so you cannot tell the difference. Can't be admissible in court.
What do we do? Right? So it's not like this hasn't been a long time coming and we're here now, like we were talking about in the break about ai.
Yeah, if, if never, okay, you know, but if eventually this isn't, eventually, eventually we will have these capabilities to take out. Now what does that even mean? Well, it means that we're gonna have these sort of conversations where we say, did anybody think about, how do we know who's who on the internet?
But, uh, we skipped that part. Um, you don't, and, and, you know, to, again, my favorite topic, you know, we're making all these things with ais that have no common ethical framework, and we'll do anything anybody feels like, you know, prodding them into, so yeah, this is where we are. And I personally, along this, um, sorry.
No, go ahead, Kate. Uh, I think disinformation is, is tearing our nation apart. It is horrible what we see happening, and we don't have any real security mitigating controls at present.
And really, and, and you know, since I, since I just acknowledged the problem, let me, you know, take a stab at, at the solution. I think there is solutions and, and, you know, we saw this coming from miles and miles away. There are all sorts of structures out there, including attest station systems and whatnot that have, that are exercised to reasonable depths.
And, and again, all my biases, uh, being acknowledged, you know, civic ai, ai that actually has a common shared reference boundary that attest to things, it does, you know, that, you know, like a human, you know, and again, on the AI side, it's just like, just like this, will we never, ever, ever give to the point where they are, quote unquote, you know, the same as us or smart as us? And if so, you know, what do we need to do with it? If not, then forget it.
If so, then we had to in advance think about how do we manage that? And I think the answer is ethics, right? You knowis right now will do whatever, whatever.
There's no tracing, there's no tracking. You know, civic ais, you know, that are following the, the canon that, that we published, you know, we, and now others are, are working on out there. Um, they will not do things because it's unethical.
And they will write it down. If you ask them, Man, I would give 10 K to be able to do a mission impossible. Tear off my mask right now, and I'm someone else under here.
'cause here, here's the issue with this. Hey, let's not make AI the whipping boy for deep fakes, right? Deep fakes has been, have been going on since before AI and AI makes it easier.
AI makes these deep fakes better, but deep fakes, you know, have been going on. I I, I have a confession. When I first started getting involved in computers, the first thing I was playing with were graphics programs.
And, you know, I would love switching people's heads onto other bodies and then doing stupid things. I was young and stupid. Now I'm just old, still not so smart sometimes, but, you know, deep fakes is a long time.
As you say, Chris, this is a, this is not new stuff. It's just easier to do. Now, Kate, to your point, it's not just deep fakes.
That's, that's tearing the fat. It's, it's the whole misinformation, fake news, conspiracy theories, everybody goes into their own echo chambers and all that stuff. Again, let's not blame AI for that, right?
Let's, AI has enough problems, right? I Go ahead. Just to be clear, Alan was switching heads on action figures like 50 years ago, Computers, GI Joe, GI Joe, one guy had the beard, one guy did it.
But anyway, Well, you know, the, this the, the Rubio thing, isn't that remarkable to me, I think what's a more important one is it's been less than two months ago, I think it was in June when the company was Arup, I believe Hong Kong based firm, where somebody got a phishing email. And that led to a conference call with the deep fake of That was, I believe, wasn't it? It, was it Singapore?
Yeah. Okay. I I think it was Hong Kong, whichever.
But they transferred $25 million I think it was, and only to figure out, oops, that was not a, that was not our CFO. So that's one example. You think that's the only example That's where the real kind of, yes, it's Steve fake and false information in society, and that's, that's its own set of problems, but the money behind this and how much money will be stolen or already is being stolen because you could do this is scary.
So how will I know whether or not Dan O'Brien on this call is a deep fake? Do I have to have two machine services validate who he is, plus somebody who actually knows him to verify to me that that's actually Dan, or, um, I know it's not gonna play. I gotta take a page from Kate.
I think where you're going with this, you know, and, and, and I think I've said this on the show, my favorite little artifacts right now is seven years ago, I told a nation of 25 million years that in seven of, uh, people that in seven years, they would have to have an answer to this question or their lights will turn because I, people like me will tell 'em to turn off. Hey, why not? So this is it, it it is, and it isn't.
This has been a long time coming, but it's woven in with everything else. How do we verify that the person telling you to turn off the power to a major city is the person telling you and they're authorized? The answer is not Well, and folks like me and people with, you know, interesting motivations can get around those, you know, should they choose to.
Now, again, this is an inevitably question, will it always, I tell you, amongst security people, I, I love, uh, argument with my friends about this one. It'll never be better. It'll always be really like, it'll never, things never change.
It's always gonna be exactly this bad. Now I think I can get a lot better. I think it's always been sloppy.
We've gotten away with it forever. We're being forced in the ways to fix it, and we have the ways to fix it. So it's everything from a video to a social media post or whatnot.
We'll get the visibility into provenance and so forth to the point that we can function. We Have to, well, we have, we have, we have fixed similar issues with security. When you look at the whole, you know, uh, digital, uh, uh, certificates like the Digi Cert business, right?
And, and that kind of thing. And we even have post quantum algorithms for these certificates we've been, we've been able to solve, is that information real with digital certificate technology? Now, that doesn't mean that someone doesn't get a phishing mail saying, Hey, I got your updated, uh, wire information, and you say, oh my goodness, that's the wrong wire information.
Let me correct it for you. Right? That, that's human error.
And it's the same thing here with deep fakes. We could have certificates and, and digital watermarks and all of these things for our own right protection, but it's still the person behind the keyboard, especially, you know, when we talk about electronic stuff, it's the human error that we need to correct. Don't blame the technology Defenders, you know, tend to feel, you know, uh, uh, you're looking from the wrong side.
You gotta think about this from the attacker perspective. It's hard to imagine it being easier to successfully pull these sort of narrative attacks. Now, it's unlikely that it will stay exactly as easy.
In fact, I think small changes make the world of the, the narrative attackers much harder. I Think that people process technology A amen. Absolutely.
I I think at the end of the day that, um, it can get better, but we are, as the article points out, woefully unprepared for this along the, so, Yeah, I mean, we, we really are getting to the point where we all almost need a zero trust mindset when it comes to consuming any information, right? Like, it all needs to be authenticated. It all needs to be verified.
I mean, I think a lot of the problem we talk about, you know, when it comes to more of the disinformation things we, Kate was talking about earlier is, you know, the media landscape has moved from one that's been fairly highly centralized to massively distributed, right? And, you know, we, we've gotta, you know, get back, you know, particularly when it comes to, you know, government officials and the messages that they're communicating out to the public, uh, we've gotta have those trusted channels that they're flowing through, right? Like, you know, seeing it on an ex post or, you know, seeing it on a, a, a web, you know, a a a web video.
That's probably not enough. We, you know, we need to be able to have places we can go where, you know, we know what we consume through that channel is gonna be real and gonna be verified. Um, but yeah, No, no, well enough, right?
Because the, the, you know, it is easy to get this, you know, feel despair when you look at increasing volumes of, you know, how am I going to process all of, and if the answer is you, you'll never be able to then this either. We'll never be able to fix it or if there's something else. And I think we look back, not as far back as you think, um, at how human culture has maintained, you know, enough shared narrative to get through the day.
It's small bits of a tested information that everybody can agree on. You know, that's a rock. And we all agree that rock's been there for the last two weeks, and that's the sort of capability that we have to today and, and is beginning to happen today, brought enough narrative reference points that most of the time, we'll, we'll have the same results as we do in life, which isn't perfect, but, you know, it's, it's not, So, Chris, I think you just said we're all gonna agree that something's an actual fact when in reality we can't even do that.
Yes, we can. Yeah. You mean you surprised, you really would be surprised.
You know, the sky is blue on sunny days, right? You know, there's, there's enough things we agree on. It doesn't have to be much, it's not about out shouting, you know, think about it, you know, large numbers of people going down the street, you put one little thing on the street, the entire flow of people changing around it.
It's not about convincing everybody anything Dead. Dan. Yeah, I was just gonna say, uh, you know, I think we deal with deep fakes to deal with the way we deal with fakes of everything else, right?
I mean, you know, look at the a hundred dollars bill. Now, how do we make sure that the a hundred that we, you know, have in our wallet is real, right? You can mark it with the little pen.
You've got the hologram, you've got all these things, right? Uh, you know, I, I think we're just gonna need to approach digital assets the same way we approach fakes with physical assets, whether it be a hundred dollars bill, a concert ticket, um, you know, a high-end luxury item, like a, a high-end watch or, you know, piece of, uh, piece of, uh, you know, clothing or furniture. Um, you know, we're, we're gonna need to find ways to validate that things are what they say they are.
Glad you said that, because I, it comes down to something physical, right? Something you have, you recognize this Chris, right? Something, you know, something you have when it comes to a person, anything can be faked, right?
I can fake your social security once I have your social security number could go do bad things with it. I can fake you, uh, with your voice or with your image. But today we re we rely on, I think increasingly it's gotta be something physically that we have.
If I'm sitting on a conference call and I have a device that I'm holding that is my VI device, and verified that it's mine and electronically and can verify that that device is present during my conversation with you, or it's watermarked in my digital image, or whatever it might be, the physical part of this, to your point, Dan, the dollar bill, whether it's the strips we're inserting into it or the holographs, there is a physical component to security to be able to validate human identity and who We are. So are we gonna have to do two factor every time I do a zoom with you, Mitch? No.
Yeah, I'll disagree with you, Mitch, on this one, because it, the difference is not something you have is something you are, and other whatt mean biometrics, and you know, it's like, and we're pushing time here, but yeah, that's the something you are, is you can't be taken away from you and, and you, you know where you are, Simon. You're the environment, right? Yeah.
So let You're, let me wrap this up for us. You know, my con law teacher in law school a hundred years ago taught us something, and I, it's proven true. Society runs three to five years behind technology, right?
And this ai deep fake stuff. And by the way, I'll point that on the ticker Taylor, it's Secretary Rubio, not senator. He's the secretary of State three.
It's gonna take us three to five years to catch up with what the bad guys are able to do right now with ai, and not just bad guys, with, with whatever's going on with AI Society, society has a lot of inertia built in. It doesn't, it doesn't slalom, you know, a ski course. It, it takes big obtuse turns and, and so we could rail on here all we want, but it's gonna take three.
But in five years, we will come up with, whether it's biometrics or something, or it's, Chris is your point, you know, we'll come up with something, we'll mitigate it. It's just gonna take time. This stuff is happening so quick, right?
Maybe someone will come up with a vibe to, to, to fix, uh, deep fakes. I don't know. Anyway, gang, what a great discussion today.
We live in interesting times, that's for sure. Thank you for watching. We hope you've enjoyed today's text on gang.
As usual, we have a full text on TV lineup immediately following, so stay tuned for that. Of course, you could always check this out on, uh, text Drunk tv, on the text Drunk tv o TT app, or our Textron TV yacht, uh, YouTube channel. By the way, we now have the individual segments broken out on the YouTube channel, so you don't have to watch all three segments.
If there's a particular segment you like, go check it out on YouTube. Until then, until tomorrow, though, everyone is Alan Shimel, we're outta here. Thank you.
Hey, everyone, welcome back here to Techstrong tv. We've got another interview coming at you in this segment, I want to introduce you to Dan Candy. Dan is the CEO of a company called Cork Protection.
Dan, welcome to Tech Drunk tv. Thanks for coming on today. Thanks For having me today, Alan.
Ah, it's our pleasure to have you on. So, Dan, we're gonna talk about Cork, but before we do, let's talk Dan. Yeah.
Tell us a little bit about your journey. Yeah, you bet. Uh, perhaps just, uh, like any other college dropout, uh, a guy trying to figure out, uh, uh, how to do things in life and, um, been fortunate enough to have some great mentorships, some interesting education, and, uh, be an insatiably curious person along the way.
Um, so yeah, uh, you know, I, I had originally dropped, gone to college on the East Coast in, in, I'm a Colorado boy, but, uh, I ended up, uh, uh, deciding it was time to, uh, start a house painting company so I could save a couple bucks and start traveling the world a little bit more. I had been living overseas and studying abroad, and, um, uh, had a lot of, learned a lot about customer satisfaction and, uh, how to manage employees through that very first, uh, that first experience in my twenties, eventually sold that, which helped me, uh, afford going back to college and finishing the degree and going back and doing some international business stuff. But I always was involved in startups and building businesses and early stage companies and, um, and technology and, you know, that's kinda the, the sweet spot for me.
Uh, I eventually sold a couple of businesses as well, but, uh, got recruited Good for you to EMC and right around the time that Dow was buying, uh, EMC Sure I remember it. Yeah, the, you know, strong software background. I got to help lead some of the VMware, uh, side of that, that, uh, experience.
And that was really fun. I helped grow that to just under a billion dollars, uh, in a couple of years. And then, uh, got recruited AWS and got to build the VMware cloud and AWS for Andy Jassy and, and Pat Gelsinger and, uh, did the enterprise, uh, side of things for, uh, a little over four years.
And again, you know, that was during COVID and what a wild experience to help, uh, you know, the world move to cloud or hybrid cloud, whatever the world needed to do, uh, in order Digital transformation. Yeah, you nailed it. Um, and, and when my tour of duty was up, uh, from Amazon, I couldn't wait to get back to, to, you know, know small and mid-size business and really be focused on managed service providers and it, which is where, uh, all of my early career had been and where my heart is.
My parents own a restaurant. My brother's a police officer, my sister runs nursing facilities, and so Wow. That's great.
Yeah, that spoke to the earth, right, man. Yeah. This is what we do every day.
Right? I, similar, similar story here. Are you still out in Colorado?
I am, yep. I've got, uh, an amazing wife, uh, of just over a decade, and then my 7-year-old son Luca and my 9-year-old daughter. Good for you.
We live out in the country, uh, just a few minutes outside of Boulder. And then of course, you don't run a run into business these days. It means a lot of time, uh, on airplanes on the Road, Wherever our partners and customers are and, and just being of service, right?
Because it's always these days it's about listening. Yes, we have ai, yes, we have lots of technology, but there's nothing more important than sitting down, um, and, and listening to people and asking questions and understanding how we can be of value to one another. Absolutely.
Excellent, man. I spent some time out in Boulder myself. One of the companies I co-founded was based out there.
I have a good friend, Brad Feld, who kinda really helped the whole bold scene happen. Of Course, Brad, Brad is a force to be reckoned with, and, uh, You know, yeah, he still is. Yeah.
I sold my very first company to Brad about 30 years ago. Oh my gosh. And, um, worked every venture backed company I did after that, while always either Mobius or Foundry, you know, they were, Brad companies was there when they were starting Techstars, so Yeah.
Similar story. Yeah. His, His office is about 15 minutes west, uh, or you know, of my, my old atri Yeah, I have out here.
Yeah. So, well, Brad spends a lot of his time out, and he has a place out near Aspen now, or in Aspen, and actually I haven't seen Brad in a couple years. I, I owe him a trip out there.
But anyway, we'll talk about Colorado all day. We, but we're here to talk about cork protection. How long, you know, how, when did you become CEO of Cork protection?
Yeah, you bet. Cork's legacy story, uh, is a little over two and a half, about two and a half years ago, uh, maybe three years ago with Austin McCord as one of the co-founders, Austin, of course, of Datto fame. Uh, and Austin is insanely passionate about managed service providers and how, uh, you know, collectively we work to support, uh, small and medium sized business.
And he saw, along with John McNeil from, uh, DVX and John McNeil as another, uh, incredible business person, uh, in very compassionate business later, uh, uh, they saw this opportunity to, uh, to really think about where cyber insurance was falling short for SMB and how MSPs in particular were trying to be of, of service in that market. And by falling short, meaning, um, not that a lot of those products were not designed for SMB, and I saw the same thing, uh, at, at AWS right where I was. Uh, although I had an s and b business, it wasn't as large as a lot of my enterprise customers, where we were doing, you know, incredibly large deals with some of the biggest, uh, banks and financial, various financial institutions and healthcare institutions and manufacturing worldwide.
Um, and a lot of the cyber insurance and financial protection things were designed for the biggest, not the smallest medium size. And, and, and I didn't want it when I left a WSI didn't, I didn't want to do that anymore. It's just like there's this gap.
And so that's where Austin and I are very aligned in the purpose of Cork. Cork is a cyber risk platform that, that understands exactly all the open windows and doors of where the threat actors can get in. And we do that by working with an a managed service provider's existing stack, API agent list, right?
In less than an hour, less than time it takes to order or eat a pizza, as we like to say, we're fully integrated and we can make the MSP that much smarter with all of our compliance, monitoring, compliance insights, and we can create incredible efficiency and security within the first day. Right? But the interesting piece of all of it, and we're the only company in the world doing this, is we tie it into cyber warranty and cyber insurance.
We believe that just understanding risk is okay, but what is phenomenally important in this next, in the next decade of our lives and are running businesses, is being able to write checks to have money in the bank account when things go wrong. And that's the only way that s and b is gonna stay in business. The average s and b only has 18 days of cashflow on hand.
And so that's where our cork solutions, our cork warranty, et cetera, puts, you know, writes checks. So I've got an SLA within an hour, I'm handing over a $10,000 virtual credit card just, just to spend, like, wherever you need to go, just go. And within another SLA 14 days reimbursement for, that's for like a CH wire transfer fraud.
I've got a number of these different situations. We real use cases we could talk about where, you know, 20, $30,000 of, uh, of money is going out the bank. Uh, that shouldn't have because, But you know what?
That, that could be fatal for SMBs, that kind of money. It is, yeah. And that, and that's, and honestly, that's the world we're living in where enterprise is so well protected because they have the bank accounts, they have the deep bench of cybersecurity expertise, and they have incredible cyber insurance policies, and then cash in the bank to be able to deal with the short term hits.
That in many ways, the threat actors are going, all right, this is pretty tough. Where is it easier? And that's where they're looking and They always, yeah, they look for the lowest hanging fruit man.
Yep. That's, that's the mo there. And that, you know, Dan, I, I, I've been in security 25, 30 years.
I have an interesting take on cyber insurance. When I first really got into InfoSec, there was only, I mean, the only company that was writing cyber was Aon. If you, I don't know how long you remember, he goes back on this, but Aon was the only one, then it started becoming a thing.
But I would say maybe five years ago, four years ago, during COVID, perhaps I saw an interesting thing happen. The cyber insurance companies became sort of the police officers, the enforcement agents of good cyber hygiene and resilience, right? Because as you mentioned, without insurance, a lot of these companies are dead in the water, you know, without some sort of coverage.
And the cyber insurance people were in a fantastic place to say, Hey, we'll give you coverage, but, you know, let's do something about managing the risk here, right? Let what you know, and so I am not getting political or anything, but where we didn't have the political will to have enforcement on certain compliance and best practices around cyber, the cyber insurance industry became the, the enforcers of, of best practices. When if you think back to being a third grader, right?
You're learning how to do a math equation. Your teacher says to you, show me your work. Right?
Right. And in a way, if I'm being generous to the insurance companies, they're saying to s and p and to managed service providers, show me your work, prove that everything was taken care of at the time of the incident. That burden has been very difficult in a way, because a lot of the technology and a lot of the compliance monitoring in in the systems haven't been set up for the proof and just needing to demonstrate the proof to insurers companies.
It's been about protecting the castle, right? It's been about providing the answer to the teacher Here, I, I got the answer right, or I'm really trying to learn how to get the answer in part because the threat actors are so damn good and they just keep getting better. And so that's where Cork and a number of other really good companies are leveraging the same tools and better tools than some of the threat actors to actually simplify the show your work concept, which may, which means we're working hand in hand with the insurance companies to go, Hey, we're doing our part.
Which means that when there is a scenario, Mr. And Mrs. Insurance Company, you gotta pay out.
Like we actually have the tooling to enforce payouts and to, and for the first time ever, we've got the leverage to assist companies in making sure that insurance companies pay out. And in the meantime, I'm not gonna wait around, right? Insurance companies typically pay four to six months after an incident.
Cork said, you know, there's an opportunity in the market for, for doing good in the market, but there's also a business opportunity where, which is where the best businesses exist when there's a triple win, right? There's a win for the end user client's, a win for the managed service provider, there's a win for cork, which is let's do something immediately, let's be of service to one another right now within the first few minutes. And that's how we're creating a, a better environment for all of us.
And I'll tell you something, I'm not throwing stones. I wish every cyber insurance carrier had that attitude though, right? I I, I have friends, I have a friend right now who's going through this company's more in the, let's call it a small medium enterprise than small medium business.
But they suffered, uh, maybe it was a phishing attempt that cost them in the, you know, high six figures and their cyber insurance carriers trying to return it from a phishing attempt into an improper invoicing thing. And it really makes you sick. 'cause you pay your premium, you think you're protected.
I see you're getting sick from it. Yeah. Well, look, I'm, I'm not an insurance company.
I don't sell cyber. No, I, No, I realize, you know, you Don't what I mean, like, it makes me sick too. And yeah.
And that's where, you know, that's where data matters. So we all have to have the source of truth in our life personally and within our communities and professionally, the data matters, right? My entire framework for success is that it's been an output of love plus performance.
That performance piece is the data, right? That love piece is the integrity, it's the accountability. What else are we gonna do on top of the data?
And that's when us as humans are making intentional choices to do business with people we know we'll be there when things get tough, right? Yep. Is we all got choices on how we spend our money or spend our time, right?
Alan? Absolutely. AB and who and who you wanna spend it with, right?
And companies, you wanna do business. And I, you know, I preach this, I I say to the kids, you get to be a certain age, right? But I preach this to the people in my company, right?
You, you, If you're gonna go to war, you want someone you could trust in that foxhole with you. And if you don't think today's cyber climate with the bad guys using things like AI and all of these other things are, are, you're not in a war. You're kidding yourself, right?
And, and so pick your allies, pick your friends, pick your, you know, your, your war fighters with you. Yeah. I, I couldn't agree with you enough.
I'll give you a quick example, real life example if that's okay. Um, we have a great managed service provider. This one happens to be out of Canada.
Uh, they're, they're called Plexus. They've been in business for over 20 years, and they're a cork partner. They, uh, they not only use our risk insight platform, but they also provide the cork warranty to their partners.
One of the three top, uh, top sectors industries that are being hit that I'm seeing over the last 12 months is construction services. Okay? Construction services is prime, prime target for these sub $100,000 attacks, primarily a CH wire transfer fraud through business email compromise.
There's some ransomware as well, right? The reason is because of invoices and cash flow, and in these construction businesses, everybody's paying one another. You gotta pay, you know, concrete bills, you gotta pay architecture bills, you gotta pay steel bills, and on and on and on, right?
Well, in, in this case, uh, the architecture firm that serviced the construction client, our, our client got infiltrated, and they, and they just sat through business email compromise for about three months, and they learned who was gonna receive the invoices in the construction company. And then they sent the three emails needed to, the construction company used the real invoice for that month and said, Hey, this month is $21,000. Uh, but we did have to change banks, ironically, because there was a, uh, an in cyber incident, here's the new a CH, please send it, uh, on over.
And despite great things from our friend at, uh, our, our managed service provider, uh, including Sentinel One for endpoint protection, ninja for remote monitoring, Microsoft email, datto for business to cover discovery and like, you know, real security awareness training that had been done despite these things. Construction company just didn't pick up the phone to verify the a CH transfer, so the funds went out, right? Like, that's the world we're living in.
Where not only is the threat actor using time and research, but also the tools, right? Those smart tools in order to get around some of these things. And so if people are not thinking about cyber insurance, cyber warranty, right?
And compliance monitoring as a way to have that next layer of protection, then it's not if, but when, right? And we're all on a journey, but over the next five, 10 years, these things are gonna become more and more common. Does that, does that story make sense, Ellen?
It's like I said, Dan, we're at war. Except if you don't know you're at war, but the other side does, you're at an extreme disadvantage, right? And, and that story you just made is exactly the story I was telling you about my friend, except that was to the tune of 800 plus thousand dollars.
Oh, That's, that's end of, that's end of days for people's careers and for, for businesses. Isn't it Crazy? It's crazy.
Anyway, Dan, we're, we're in low on time. For people who want to find out more about Cork protection, what's the website? com.
Uh, we're also constantly doing, taking education based approach. Uh, what is ours is yours. So where we can be of service, uh, we try to be, uh, we, we have recently released something called the Cyber Insurance Analyzer, which is a free tool where people can put their cyber insurance policies in there.
And we're able to provide a summary analysis of it. We, um, on the backend of our tooling, we have connections with companies like Datastream and Yukon so that people can access cyber insurance and risk, uh, risk, uh, insurance platforms such as that. Um, and then, uh, we make sure that our team is always, uh, well educated in being able to, uh, provide answers.
And if, if I can ever be of service to you or anybody in your community, please let me know. It's, it's about the love, uh, even more than the performance, honestly, in this world that we're living in. Dan Candy, thanks for being on Text Talk tv, and thanks for what you're doing, man.
It's good work. Pleasure to say hello to Alan. I hope you have a wonderful and safe afternoon.
You as Well, Dan Candy Cork Protection here. com. Check them out.
We're gonna take a break on Techstrong. We'll be back in a moment. Hi everyone.
Welcome back here to Tech Drunk tv. Alan Shimmel back in studio. I've got a first time guest on here for me.
His name is Drew George. Drew is the CEO and co-founder of a company called orus Think Orchestration, like the plural, if you will, of orchestration Orcus. Drew, welcome to Text Drug tv.
It's great to have you on here. Yeah, thanks for having me, Alan. Uh, nice to be here.
Nice to have you. So, drew, let, before we talk about Orcus and orchestration and all that good stuff, let's talk a little bit about you. You're the CEO co-founder, and you know, I, I think everyone's always interested in what, what made this man sign up to, you know, go through co-founding and, and running his own company.
It's not something we do lightly. Yeah. And, uh, a lot of, uh, it has to do with, uh, my time at Netflix.
And, um, you know, before starting Oracle, I, I did spend some time at Uber before the IPO, but spend a significant amount of time at Netflix, and that's where it all started. And, uh, if your Uber back in the day, um, the cloud was still coming up, right? You know, pre-cloud era, like everything was big data centers, more of the applications.
Netflix was also the first company of its size to operate completely in the cloud, right? Yeah. And, and so much so that every single cloud computing principle that you see on the internet today came out of Netflix.
And, and we used to have folks from a Ws sit in, sit in the Netflix offices trying to take feature requests, and a year later they would make up, uh, into the AWS tool set, like, you know, things like auto scaling and how to do multi-region, how to do reliability, and, you know, failure, uh, addressing it scale and all of that stuff, right? And, um, Um, whole idea of chaos engineering. Absolutely.
And, and, uh, mm-hmm. You know, that that's May, that's, that's also, you know, those principles also is what made Netflix really great and operate extremely efficiently. And at a scale, when we talk about scale, like, you know, we talk Netflix scale because, uh, you know, it is hard to find companies that operate at that scale.
Um, and, and especially in the early cloud days when, and these things were still being formed on how to do these things at, at like really large scales, right? Um, conductor, the product that was built on Netflix also had a lot to do with one, how do we move a big business? Back then, you know, we were like under 20 million or so paid subscribers.
Um, it was hard to find paid subscriber services that were that huge in number, right? Uh, but that said, conductor had also a big role to play in, in that journey on Netflix, moving from completely on the data centers to operate completely in the cloud and making this transition while keeping the business operational, right? That was one aspect of it.
The second one, um, was today, if you go to Netflix, most of the content that you see on the website is origin programming, right? Content that you would only see on Netflix, not anywhere else, right? Back in the day it was more licensed content.
Um, and there was a big starting shift back then saying, yeah, how do we, uh, create some differentiation in the business? And, and the answer was, let's try to produce our own content. And that's where the scale comes in.
Imagine that today we have, Netflix has over 300 billion subscribers doing several, I would say a hundred thousand pieces of content every year, 50, 60, 70 different languages, lot of different art artwork combinations, and then you multiply them all together. And then how do you run something, uh, a complex process as this at scale Conductor enabled a lot of that and continues to enable a lot of that in Netflix today, right? Um, we saw that, and you talked earlier about a little bit about microservices.
The, the whole microservices architecture also started when, when cloud came about, also led to an interesting problem where we had lot more, uh, microservices that people in the company, half the microservices were built to talk about the services. And that's where the whole notion of orchestration came in. Conductor was born to kind of fill these gaps and put the need and solve this problem At Netflix, we just hit the problem first because we were one of the early adopters, right?
So seeing this big traction in Netflix, we decided to open source that that was back in 20 16, 17. Over the last few years, we have seen over two 3000 companies use the open source product at scale, uh, and some of their very, very core business units. So take a company, for example, like Tesla, Tesla's entire stack is built on open source, right?
Uh, the, the conductor. So if you look at how, how people go and place a, uh, order for their car online, few months later, the car shows up home, right? Their payment systems, billing systems, CICD pipelines, right?
And we saw that same journey in, in companies like Tesla, companies like Wiggy, which is the, you know, they both, they're kind of the door edge of India, saw that in the big banks like JP Morgan, Amex, you know, Morgan Stanley, healthcare companies like G Healthcare, that's where we saw there was this big shift of, you know, how the cloud came about and changed everything, right? No one builds data centers anymore. Similar thing on a layer above that, when people are thinking about building applications, um, you spend a lot of time getting the foundational systems right, on how do you run this at scale?
How do you run this at extremely high liability? And those are things where Conductor was super, super good at. And we are seeing a big shift on how developers think about building applications.
And that's where conductor fits in. That is a passion that basically came about and say, Hey, this is, there's this world that is completely set for kind of making this big transitional shift happening on building applications, right? And that's, that's how we go and then, and start Orcus, right?
Um, it's being, you know, three plus years right now. We have an enterprise rate conductor on the top of open source that we built, um, Netflix and Orca combined together, and then, you know, took the open source story for a couple of years since we started Orcas, and then we got worked with Netflix, called them to archive that project, and more, more conducted to an open source foundation. And we're continuing that fabulous journey in, in the enterprise ORUS world as well.
I love it. Thank that was a great, a great history and explanation. Drew.
You know what I always like, I co-founders are always pa not just co-founders, but founders, people who stock companies, entrepreneurs, their passion bleeds through when they talk about it, almost like they're talking about their children. Absolutely. You know what I mean?
And, and so, and it comes through with you. So, and that, that's genuine, and that's, that's a good thing. So, so congratulations on that.
Let's talk a little bit. So I, I mentioned in the opening, orca is kinda plural, shortened orchestration in some way. Expand on that a little bit.
Yeah. So if you look at orchestration, what Orchestrate was conducted as it enables developers to build applications, applications that are typically run in the backend, uh, they are asynchronous or synchronous in nature, right? You know, long running workflows to real time, a p orchestration that is run at high scale, um, you know, high throughput, low latency, for example, and off late, uh, the last couple of years, building out agent applications, agent workflows, and you know, how to also build idea reliable AI agents, right?
And these are all forms of applications. And, and that's, you know, changed over the years. But, uh, we are the platform that enables all of that, right?
And, uh, how do you do this, especially when you want to run this at enterprises, how do you do this in, in a way, which enterprises are, you know, the things that enterprise look for, right? Outside of the, the regular stuff, which is security governance. Uh, but, you know, we need to run this at extremely high liability, extremely high scale when needed.
Not everyone needs scale, but extremely high liability. And when we talk about liability, what that means is low error rates, which means that, you know, how do we detect error? How do we make that rates really slow?
How do we take the, you know, time to detect and time to fix and time to deploy when these things happen? And this, it happen all the time. Um, and, um, that's really where kind of we fit in, right?
And, uh, this is an area as as big as the cloud itself. And, um, and then we have seen, you know, with, with also agent take stuff coming in, like, you know, the, the mode of how people kind of go and develop applications has already changed as well, right? So, um, and then if you look at it like, you know, everything that you build, you know, there are individual small pieces that you build, but you need to tie all these things together to make business sense out of it.
Um, and whether it's at the high level business layer or platform layer, but, um, and then things are talking to each other, that's where the orchestration comes in, right? And then, uh, common things that almost every single company on the planet needs, who's, who's building software, whatever size or shape it, it might, might end up, uh, being used in, right? And that's where like an orchestration's really come into play.
And, uh, when we started, orchestration was still fairly new, right? Like even the term was getting coined and, and, and, uh, fairly new things. But that has really accelerated in the last couple of years, right?
And, uh, we have seen lot of companies also come out emerging in this category, but I think we are really primed to go and this space as well, right? And that's also very, very exciting. And we see this, this journey is also been great because the, the usage and how people are thinking about building applications also changed.
Yeah. All right. So Drew, as you can expect, I fair, I spend a fair amount of time talking to people about ai, right?
Everybody wants to talk about AI today and what effect it's having on their job, on their industry, on society. com, our newer site. So, you know, things like microservices and, and let, let's call them new architectures and, and new ways of looking at, you know, building out applications are what I spend a lot on, right?
And sometimes I, I, so I think I live in a bubble where I, I think everyone knows this, right? We're all living in this, well, maybe you are too, and you're in my bubble. But when you step back and look at it, Jew, we're in a, it is a very interesting times.
It's kind of a revolutionary kind of timeframe where things like cloud and cloud native, I'm being married to ai, agentic AI and, and things like this. And the, I don't think as we sit here, we're not a hundred percent sure how this all shakes out, except we know it's gonna be big and it's gonna be very different. I'm wondering if where you are sitting, what you are seeing, and, and do you feel that way?
And if so, in what, how is it going to shake out? Yeah. And I think this has been a fundamental shift, right?
I think the last big shift that happened, uh, you know, combined with cloud coming out and, and how people can go and easily deploy microservices at scale. And then obviously that with that comes orchestration. That was a big last shift that happened probably from, you know, 2007, eight, you know, up until now.
Um, last couple of years is where kind of AI really, really took off, right? Uh, with obviously things like Chad, GPD coming out and, um, and then people basically seeing all the magic that it can do, right? But that said, uh, there is the consumer aspect of it.
Like when you go and use strategy PT over the last few years, you've seen, like, you know, how it's really taken off. Um, it is, it is, you know, hallucinations were a problem early on, right? Like, you see less and less of that right now.
But it is, it is magical to think about, like, you know, all the great stuff that it can do, but sometimes it also trips up, some trips up on very, very simple things, right? And then we, we chat with, uh, the application and try to get the right answer out of it. Right?
Now, you take the same thing, go to an enterprise, the enterprise, you don't want to have any kind of those things. You need to have you building these agencies. You see the efficiency benefits that comes out of it, but you also wanna make sure it works really, really well and it, it doesn't do things that it's not supposed to do, right?
And when you, the two big areas that LLMs AI has been kind of really being used and found, its, I would say like, you know, product market fit in, in chat, complete areas, chat areas, and also code, right? But when you want to run these applications and build these things at scale, few things that come into play. One is you have existing application stacks that enterprises have right now.
One is how do you go and use AI in those companies without the need of rearchitecting your entire stack? 'cause that takes a long time to do. People don't want to kind of break down an existing business and spend two years kind of, you know, you know, getting, getting that right.
So that's one piece of it. The second piece is how do you, and for, for agents, when you think about agents, right? Like, you know, there's this whole thing about, you know, the agency aspect of it, but there's like a, how can you build an agent in such a way that you can enable that to make autonomous decisions, right?
And to make autonomous decisions happen, it needs the right kind of tooling in enterprise, which means that the ability to go and connect the agent and the LLM models to the internal tooling within enterprises, and it could be tools that could be APIs, whatever format, they kind of expose that. And then also, how do you connect that to internal knowledge bases, internal databases, right? That is where it makes these things agents really powerful, right?
And then the principle on where to use ai, where to use LLMs and where not to use it, right? And right now, if you look at it, the way, the feedback that we've been getting and how people have been using our, uh, you know, agent workflows and AI and products have been things which are very deterministic in agent. Like, you're gonna call an API, right?
Like, uh, there's nothing an agent needs to do magical to call an API because an API is already built out, it's already existing enterprise, it's working calling that is not really where the power of an agent comes. But when to call that and how to call that, that is something an agent can really do well, right? LLM models can really do well.
Um, non-deterministic things, which if you were to go and build these things from scratch, it can be extremely much more efficient. So the mixing and matching of these things, and also to build in the guardrails that you need to, right? Like if you want to, uh, make actions, uh, the autonom University of the agents, if you wanna make them happen really well, you need to also put the right kind of, when, when agents are gonna call into the tooling, you also wanna put in the right guard rails and placing that, Hey, I build this agent, this agent has been built for doing a specific purpose.
If a human, were going to do that. You have put in the right checks and balances in place, right? Can you do the same guardrails on agents as well?
And that's really what makes agents really, really powerful, right? And then obviously, you know, this is also fast moving industry, right? Um, things will change rapidly and you know, this is where things are right now, right?
And we, we think this is where the industry is gonna meet, move in the next, you know, year or so. But, you know, we have to keep a very, very close tab of how, how things are also getting developed in the industry so that, you know, we can, we can adapt to what enterprises are looking for, address problems, right? But so far, this is the direction that we have seen really, really good adoption coming.
Absolutely. You know, gee, we we're running low on time. We mentioned the website was orca io.
That's right. Or io, O-R-K-E-O io. Someone out there who says, you know, this seems very interesting for me.
I'd like to find out more. I want to maybe try it, whatever. What, what's like, what's the path they should take?
Yeah. So if you go to orchestra io, right? If you want to, as a developer, if you wanna try it out, uh, on the top of the, you see a developer tab you can go to or you can go directly to or io slash developers, there is a developer edition that you can sign up for free, perpetually free.
You can go sign up on that, and you can, uh, you know, with your social accounts, with your company accounts, whatever you may choose. And then you can build application, you can try out and get a sense of the enterprise product, uh, every single thing in, in, in what you find in enterprises enterprise product. You can find it here as well, right?
So that's one option, specifically made for developers. Um, if you want to use an enterprise, um, you can, there's a get a demo tab on the top. You can talk to someone there.
Um, you can, we can, uh, sit with you and figure out your needs and, you know, car bought Enterprise edition for your business as well. There's like two different ways to go, you know, get in touch with us, right? Uh, but if you're an existing open source user, or, uh, if you have questions, there's a Slack channel out there, there's a discuss channel out there, but Slack is one of the easiest ways to connect with us.
But people, enterprises, or people who don't have access to Slack, there's a discourse format there. Both the links can be found on the homepage, on the top right corner, um, and you can, you can get in touch as, uh, touch with us in that Manner as well. Excellent.
Drew, we're about outta time. I want to thank you for coming on, educating us a little bit about Orcas, giving us a little bit of your own journey. And, and look, there's no doubt we're living in a time where we're seeing change, reshaping our, our daily workflows, our daily tasks, and how we're doing things.
It's gonna be an interesting couple of years. Maybe you could come back on and tell us more sometime soon. Absolutely.
Thanks for having me. I'm love to come back again. Love it.
io, uh, here on Text Trunk tv. We're gonna take a break. We'll be back with more in just a moment.
ai Leadership Insights series. I'm your host, Mike Bazar. Today we're with NAAB Iran, who is head of cloud engineering for cruso, and we're talking about AI infrastructure, and a whole lot of things are going on with these folks.
They got a $750 million line of credit partnership with a MD, and I think they're expanding into Europe, if I read all the announcements correctly. But Nadav, welcome to show. Thank you.
Thank you, Mike. Happy to be here. Um, it's a funny thing, but I think we've talked in the past and it felt like this was gonna be some sort of interesting little niche, and now I've turned around and it's kind of this billion dollar industry, and everybody and his brother's talking about more efficient ways to consume AI processors.
Is there some sort of rapid maturation process going on here? I I, I think there is. I think, I think we actually talked about it last time we talked, uh, a little bit about kinda like the pace of how it happens and, you know, this hockey stick we're in.
I'm, I'm not horribly surprised. Um, maybe just a little bit. Uh, definitely the, the pace is picked up and, and I think the, the market also looks a lot more interesting in terms of like how you see, uh, both the consumption and the supply mm-hmm.
Of, uh, compute infrastructure. Um, uh, that's, that's focused on AI for sure. I feel like it's also changing in terms of who's responsible for what.
I think early on it was a data science team, and there was a couple infrastructure people attached to that, and they built one application. I think we're at some point now where people are trying to figure out how to operationalize AI infrastructure across multiple applications, and that's changing the nature of the conversation. Is that a fair assessment?
I, I, I think to some extent it is. I, I think there is, um, also the, the focus is shifting to some extent from AI as a technology to the applications that are enabled by ai. Um, it's, it's, you know, it's less interesting what the AI is and more interesting what it does for you.
And I think we're seeing that more and more as people start to use AI in more and more areas. We, we do see that, we do hear from our customers more and more. Like, I just want this thing to work.
I have a day job to worry about not building AI infrastructure, not figuring out how to optimize a performance. It's not figuring out how to, uh, you know, find the right device driver for the hardware I'm using. Um, I have a day job, and, and that means building a business.
So building an application or something like that. AI is a tool and, and not the, uh, not the objective of the work. I also feel like there's more separation between the process of training an AI model and the actual running of the AI model.
In terms of the inference engine and where that might be, and are, are we seeing some shifts there or, you know, how is that evolving in your mind? There, there, there's definitely a lot of, um, uh, focus, you know, like, like I mentioned as, as people try to use AI more, that means they do more inference. Um, inference is becoming more and more important.
I think last time, um, we spoke, we, we talked about manage inference, you know, that's a, a product that we, uh, we have out there that is seeing more use even within our, uh, straight up infrastructure, uh, users, we are seeing more and more focus on inference. And, and to me that's just natural, again, because people are using AI more than they're focused on making AI better, bigger, et cetera, that's still an important thing. But as a percentage of the slice of the pie, uh, you know, that slice that is using AI is the one that's driving the growth.
There's also a point where, um, you know, certain things are at a good enough place. Um, and again, there, there's always the, the, the leading edge, the bleeding edge, the place where you are finding new capabilities in, in the technology. But there's also, you know, to your point about maturation, there are parts of ai, you know, large language malls have been with us, um, roughly with the same general direction.
They're, they, they have today for, for a couple years now. And so at, at that point, you do see like the, the, the core LLM becoming less of a focus and how you use it becoming more important. Mm-hmm.
And to your point, I also feel like l LM is now coming t-shirt sizes. They're small, medium and large, and, um, and people are getting smarter about which to use when, and then what the infrastructure resources are required to support those, Uh, for sure, 100% that, that's actually something that, that has happened. Um, I, I think pretty since, pretty early on, um, you know, the, the full scale, the large LMS are super expensive to, to use, uh, the, they're slow.
Uh, you need, you need a lot of hardware to make them work. And for a lot of stuff, you don't need the power that they provide. I think more and more we're gonna see actually systems that, you know, dynamically use, uh, the, the right size model for, um, the, the situation you're in, depending on, you know, your context window length, depending on the prompt you have, et cetera.
All these things to me are, are natural optimizations that are happening as, um, as the technology matures. Um, you know, there, there's, there's a rule that I've learned in, in, in building infrastructure over the last couple decades, which is the, the closer you are to the end user, the bigger the leverage you have over optimizing the problem. So, you know, we started by optimizing these things by looking very close to the hardware.
Um, that's important early on to understand how the hardware works, et cetera. But you really get the leverage where you look at a problem from a user or you look at an application in general and say like, you know what? I don't need a 400 billion parameter to serve that need.
4 billion is enough. That's a huge optimization you can make. And so I I, I do think we see as the technology matures people more and more looking at that place in the value chain saying like, Hey, you know, I have a 10 x improvement I can do here by just using something else.
Mm-hmm. Now you also partnered with a MD recently. So are people looking at GPUs from different vendors now and mixing and matching, or are they saying I'm either an all Nvidia or all a MD?
Or is it becoming a little more nuanced? That, that, that, that's a great question. I think, um, in general, as a, as a cloud service provider, um, and I think it's good for, for the customers as well, the users, the end users of the technology, uh, competition is good.
Um, I think right now we're still at a place where people have a preference for one or the other. Uh, there is like the, the level which that we work with our customers, they would be aware, Hey, you know, I'm going to get a MB hardware, I'm gonna get Nvidia, the hardware. To me, the really interesting next phase, again, going back to the point of like, the further up the stack, the more leverage you have is actually building services that can make it match.
Um, we're not quite there yet. Um, but I think that is forthcoming. And I'm, I'm, I'm super happy, you know, to have our hands on on those a MD machines.
I think just by having two things from two different vendors that are different from each other, we're gonna, we're gonna find the niches, we're gonna find the place where one is really useful, where the other is really useful. We do see, um, healthy demand for, for both, you know, we also have, uh, B two hundreds that, that we started, um, uh, offering to our customers a few months back. We have the A MD that, that is still a couple months out.
Um, both of these we see healthy demand for, um, and I, I think this is recognition in the market that, um, competition is good as well. Specialization, you know, uh, this, this workload is with this model on this type of hardware, this workload acts differently, needs different type of hardware, different model. It's all good.
Um, speaking of different classes of processors, are we also gonna see more usage of things that aren't GPUs to run inference engines? And what might that look like, Perhaps? I, I, I think, um, I think in general, um, as the market grows, it would make more and more sense to try and hyper optimize for a fraction of the market, right?
So like, if you have a market that's a hundred billion dollars, whatever, just to, just to pick a random number, uh, an easy round number, um, you know, 20% of that market is a 20 billion market. It's worth an investment to, to create hardware that's hyper optimized for that. I do think that hyperop optimizing hardware makes the problem simpler and therefore allows you to get, um, uh, more benefit out of it.
And, and as I mentioned before, also from the usage perspective, as your software stack becomes smart and is able to direct the traffic to the harder that's most useful for it, that, again, will lower the bar for people to come up with with new types of hardware. I, I would say today we are seeing, um, more and more interest in the asics that the, uh, big hyperscalers have. So like, you know, traum and, and innium with, with, with, um, AWS TPUs with Google, you see them taking more and more, uh, perhaps of the market share.
Um, we've been, uh, exploring things with, with several startups that, that work on interesting hardware solutions. Again, all these solutions are trying to limit the scope of their problem to be able to do better than the big GPU vendors. You know, if you wanna build something that will accelerate any AI workload under the sun, it's a very tall order.
But if you're just focusing on, let's say, inference for small to medium models and, and you make that simplifying assumption, I think there's a lot to gain there. And as the market in general grows, even optimizing for just such a slice, we'll become lucrative enough that we will see innovation happening in the hardware in that space. Mm-hmm.
Is it me? But I feel like, and maybe it's just part of that whole maturation process, but people are more sensitive to the cost of AI as they try to figure out what to operationalize. 'cause it's one thing to have a thousand experiments, it's another thing to figure out what can I actually afford to run in production.
Yeah. I, I think that's fair. I think, um, the, the way we sometimes refer to it here is there's, there's sewers and there's harvesters and, uh, I, I think we are leaning more towards the harvesters.
And the harvesters do behave somewhat differently. They're not just, um, more, uh, cost sensitive. They're also, um, less tolerant of complexities and, you know, the need to gain expertise and to learn and to experiment.
They want something that just works and hopefully just works and doesn't break the bank. I, I think for ai, this is actually something super important. You know, when, when you think about using a new technology, um, there is, there is, you know, the 5%, 10% kind of improvement in, in cost performance, which, which is good.
That just helps the current players, you know, uh, improve their products by a little bit or make a little bit more money. We, we are still seeing, and there's a bunch of data about this, about, you know, the cost of inference over the last two years, basically going down by orders and orders of magnitude. When something becomes order of magnitude cheaper, that opens up a whole new, you know, universe of possibilities in terms of the kind of products that you can use it in, the kind of business model you can use to monetize it, et cetera, et cetera.
And so as we're seeing those cost improvements, um, you know, compound, um, and, and continue to improve, uh, I'm, I'm super excited because I think those harvesters will have all, all kinds of different things they could harvest all kinds of different areas where AI will all of a sudden be a great solution just because it's now cheap enough to justify its use. Can we simplify the stack? And I'm asking the question because one of the great things about the cloud was it made it relatively easy for developers to stand up infrastructure and build and deploy software.
I look at AI today, and I still feel like there's, you know, ML ops people, data engineers, security people throwing a bunch of developers and shake and bake, and maybe by the time I get the village together, something good happens. Can we streamline that? I, I, I think we can.
I think, again, this is partly the, the transition from the sewers to the harvesters where, like I said, I think people are looking for more simplicity, so there's more and more demand for that. Um, I, I, I will say a lot of the complexity even starts before you get to ai, for example, you know, um, as you know, we, we at Cruise who are building the world's favorite AI cloud, but we're not pretending to the, to be building a general purpose cloud. So many of our users have a footprint on a general purpose cloud as well, to run the known AI parts of their workloads.
And even just that, you know, the, the ability to work together across two different cloud providers, sometimes three or four, um, and, and hide the complexities there. That's, that's a demand that we see coming from our users and that we're working on helping them with. So the, the complexities start even before you get to the, you know, the science of ai, if you will.
Um, so we're trying to fix that. We're definitely seeing that in the, in the AI space itself. Like I said, we're seeing more and more demand for managed services, for managed inference, for, you know, a a a point and click kind of interface of like, here's my data, um, do something with it.
Um, you definitely see much more demand for that. I think, again, that that part of the journey is still in, in its infancy. We see some first steps in the right direction, but I think it's still a long journey ahead.
So what's the plan for the funding? And as part of that, what's coming next for you guys? Um, so again, we're, we're excited, uh, as, as everybody knows, um, this is, uh, a pretty CapEx intensive, um, uh, industry and, and so like having that funding secured is, is great.
Um, I, uh, I'm not here to talk about future financials for sure, financials in general. So I, I, I, I'm not gonna say what's, what's ahead in terms of the funding, but I can say in terms of our expansion, um, as you mentioned, we just announced, um, a new data center in Norway, um, that uses 100% renewable energy. Um, we, we announced a big deal with, with a MD.
Um, there's more things coming, you know, the business is growing for sure. Um, it does require a lot, a lot of capital to feed it, but, but we do see a lot of growth. Um, I would also point out, we had, um, an announcement, um, a couple weeks back with Redwoods materials, which is a company that, um, uh, recycles EV batteries where we have, uh, a pilot of deployment with them, um, that is 100%, uh, powered by solar energy and recycled EV batteries off the grid.
Um, so all sorts of interesting things are happening in terms of our, our growth. The, the business is definitely, um, on the up and up. So what's the thing you see people doing today that kind of just makes you shake your head a little bit and go, folks, we could be a little bit smarter than that.
I, I think, um, this is a great question. I, I, I think one of the things, uh, is, is something that we've touched on in terms of like the, the hyper focus on the model versus the application. Um, you know, like I said, there's, there's a lot of optimization that can be done at the top layers of the application in terms of like, what actually you're gonna use for when, uh, we don't have good infrastructure for that, and therefore a lot of people in the space, I think, overlook the ability to optimize at that level.
Um, I, I also think, um, that there is still, um, maybe I would say focus on expanding the capabilities where the capabilities are good enough. There is a little bit of like chasing like, oh, let's, let's, let's, let's work on transitioning to this new model, uh, where actually the system that you have is good enough. Um, I, I would say it's in general, in my experience, something that you need to watch out for with software engineers.
Software engineers don't like good enough. They like to be the best. And so a lot of times, you know, there's a point of diminishing returns, those last 2% of squeezing something, um, is oftentimes really, really hard.
And, and 98% may be good enough. So I, again, this is part of moving from like expanding the envelope of the technology to just using it. Um, and I think shifting that focus will allow us to iterate a lot faster, because again, those last 2% take forever.
Very hammer folks. There's a thing called AI optimization. It's coming to a store near you soon.
Nadav, thanks for being on the show. My pleasure, Mike. My pleasure.
Thank you. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership series.
You can find this episode, others on our website, we watch to check them all out. So then we'll see you next time. Hey everyone, it's Alan Shimmel, founder editor-in-chief of Techstrong group.
Welcome to our second video in a series we've done with our good friends at Adobe, looking at the influence, the impact of AI and security. I've spoken to five different Adobe security professionals. In this next video series, you're gonna watch about how Adobe themselves are using AI to make their security more effective, to make the Adobe products you use more secure.
The beauty of this, it's not just about making Adobe more secure, but there are lessons here for everyone. It, how do you use and leverage AI to make security more secure? And my first guest in in this series is Brian Payne, who's Adobe's VP of product and software security, and he's gonna give us a little bit more of an overview of the work his teams are doing in AI and security.
And welcome back to our continuing series, discussing Software Insecurity with our good friends at Adobe. My guest for this episode is Brian Payne. Brian is the VP of product and software security at Adobe, and let's welcome him.
Hey, Brian, how are you? Doing well, thank you. Thanks for coming on here.
Brian, VP product and software security. Sounds like an awesome job, but tell us a little bit about kind your journey and how you view your role. Sure, absolutely.
So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well. Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years. Um, I've been with the government, I've been in academia doing research, and, uh, spent the last 15 years or so in the private sector here, Brian, of of course, we've, you know, we've entered into the age of ai.
Sounds like a, an old song. It's not Aquarius though. Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect.
It, it promises all kinds of disruptions. Um, and, and ai, quite frankly, to those of us in the security world, it, it's kind of a shield and a sword, if you will, right? Unfortunately, it is for the bad guys too, you know, that's always the case in security.
Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security. If you wouldn't mind, again, without giving up trade secrets, or let's not get inside ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone.
Uh, it's a tool and you can use tools for, for good and for bad. And I think, you know, in the security world, we're keenly aware of that, that history, that's always been the case with tools. And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge, right.
Um, at the end of the day, we find that it's very useful to help us scale. Um, I've rarely run into a security person who just feels like they have so much extra time in the day. Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right?
Using their brains to solve those security problems, um, that's really the key for us. And, uh, and it comes out in many, many ways throughout our work. So look, if you don't mind, Brian, let's, if we could dive, peel that onion back at layer or two, how, how does this manifest itself?
What are some of the ways you're leveraging ai? You know, we look at different code bases all the time. If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger.
And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful. Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right? Uh, which functions receive untrusted user input?
Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic. It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially. Um, some other examples of things that we've done, um, think about network scanners.
Uh, you often need to stay up to date on the latest CVEs, the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities. Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things. Um, it can turn around and create those scan til buts rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them.
We also use it, um, internally for developers. Uh, we like to give them as much information as we can around the security problems that we find in code and help them to fix them quickly. And, um, we have found that it's much better to provide some context around this is how we think it should be fixed.
Um, this is the best practices around fixing and those things as opposed to just saying, here's the problem. And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them. Excellent.
Brian, everyone today is talking about agentic AI and AI agents. We're, we're definitely looking at, um, different ways that this can play out. Um, we have, uh, been exploring code generation, um, using some magenta AI systems.
And one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SQL injection. Maybe it doesn't quite do the right filtering on that input. Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code.
And then all of a sudden, the code that it generates, it's the bar is raised in terms of the security quality of the output. Um, and a world where more and more code is likely to be generated by a AI year over year. If we can get ahead of that curve, and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time.
So I'm very excited about, about that space and where that's heading. Um, we're also using it in, um, more of a chat bot situation, right? So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password, right?
Or, um, you know, any sort of question they might have. And a lot of these things are actually written up as internal policy here at Adobe. And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them.
And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time. And we can go back and, of course, double check, do we think it gave the right answer? And then kind of train it over time in the cases where maybe it missed.
Brian, thank you so much for, for, uh, coming on here today for people who maybe just wanna find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information? So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work. Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community.
Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference. We are quite often there, so Absolutely. Brian Payne, VP product and software security of Adobe here.
Thank you for joining us, Brian, and keep up the great work. Thank you, Alan. It's been great.
I want to introduce you to our next guest in this series. His name is Alex Stan. Alex is the senior pro product security engineer at Adobe, and he's responsible for triaging and validating bug bounty reports, planning, life hacking events, developing security automation for scale, and, uh, to scale the programs activities, and as well as collaborating with the various stakeholders, both internally and externally to improve security workflows.
Alex, that's a mouthful, but welcome and it's great to have you here on Textron tv. Thank you, and very Glad to be here. It's obvious.
What are the, what are the benefits to a company like let's say, Adobe, um, with having a bug bounty program? Well, you're gonna find out, hopefully your software becomes more secure as a result, because there are people who are not, you know, who are on the outside looking in, let's say, or who are, you know, beyond the team who are letting you know about, uh, potential bugs and defects in your software or maybe their features, right? That's not a bug, it's a feature, but what's in it, what's in it for the security researcher who discovers this?
Yes, for sure. And, uh, of course that I, I cannot, uh, you know, it, it's just financial. Uh, it's definitely one of the main reasons.
Uh, but they do have some advantages. Like I I think internal flexibility. They get to choose their targets.
They can hack whichever company they, they want, like if they're specialized, maybe in desktop testing or web application testing or mobile testing or cloud, large language models, they, they, they can try to test everything they want. And also there is, uh, an, an important part to this, which is the reputational aspect. Um, they get recognized by the companies.
They maybe, um, have CVS on their day name, you know, they report the vulnerabilities in the program, which is a CV numbering authority issues, the cvs, they can sign a cv. So, uh, it's, it's a great aspect on the reputational part as well. Absolutely.
And, and that in many times, many ways, it's even more, that's more of a, of a, a carrot, more of a, of a reason to do this than, than some of the financial rewards. But now we, of course, Alex, we're in a new world, right? We've got AI and we've got, well, even before ai, I remember when fuzzing came out, right?
All of a sudden that made, you know, doing scanning with a fuz, it made you, you could do a lot more with that than you, than you did with the old way of, of doing it. But talk to us a little, talk to us a little about how bug bounties are changing in this new AI world we live in. Definitely, I, uh, believe the backbone hunters are using AI and large language models to, you know, help, uh, discover more exploitable opportunities.
But we, on our end, in the programs we need to scale as well. So we're trying to definitely leverage ai, um, to reduce our, you know, our manual tasks and focus on the more important tasks. So I can give a little examples if that's okay.
Sure, please do. Cool. So, um, we definitely from time to time, you know, as, as, uh, like going to program owners have a lot of reports.
So we do want to ensure, uh, we are doing report validation, very efficient. So, uh, one of the manuals tasks we, we have to do is maybe identify duplicate reports. It's, uh, mostly unfortunate, but, uh, bug monte hunters are, uh, can find duplicate reports of one another on our end is, is pretty tricky to, to, uh, lead the pieces together.
Um, and we try to use olms to maybe identify, uh, duplicate reports and also maybe the LLM can assist on the reproduct reproducible aspects. Like if there are unclear steps to reproduce, like for example, I'm not sure from step three to step four, um, how I can actually reproduce the finding. But maybe the LLM can already do an, an analysis for us before we actually jump into the report and, and provide the extra steps or, uh, make, uh, you know, some, some distinctions maybe DLM telling you, you can go back to the researcher, ask more information about this or, uh, it isn't enough security impact illustrated.
Can you, can you show us? Um, so it actually help us, uh, reproducing. So yeah, uh, this is, uh, usually how, uh, LMS can, can help with a report validation.
There are others application as well. Absolutely. Alex, I want to hit on two things.
Number one, you mentioned you as, you know, the a person at Adobe who goes through all of these bug bounty reports that you receive. Give us an idea how, how big a job is that in, in like sifting through all these reports, eliminating duplicates, finding out which ones are, are in fact valid, which ones are critical, which ones are not deciding how much money a particular bounty should be paid on a particular thing? I, if you wouldn't mind, you know, 'cause that sounds like a huge job and then, you know, now in the age of ai, is the aim to replace the external researcher with the internal ai, or is it really you want the, you want both?
I think my answer is we want both. Uh, especially since, you know, the external researchers are very creative. So an AI definitely cannot, uh, cannot get to that level.
Um, and regarding the volume and, uh, let's say the technical, uh, technicality of the findings, uh, yeah, it, it's, it is challenging and yeah, we, we need to handle, uh, the payout. So we need to assess each finding correctly. So, uh, in the world of ai, uh, actually another application is to auto enrich reports.
So we have pretty much a lot of findings, right? So, uh, we can use an LLM, for example, to predict CVSS score based on similar reported findings. So we don't have each time, uh, need to check those and see we, uh, we align with, you know, with previous submissions.
And, you know, of course there will be many bugs and many products reported on against. We can also use the LLM to identify the product that is reported against and pre-populated, uh, in, in a ticket and actually categorize the findings. So in order to track the findings, you, you need to, to know like certain information and what's the vulnerability like, is it ized scripting?
Is it SQL injection? What's the proposed CVSS score? Because, because of, on the CVSS score, where you pay the bies was the reported product.
So, um, yeah, uh, the alarms can can be used for that as well. So it sounds Alex, like the, the, the LLM, the ai, right? Because the LLM is just sort of the, the data from which the AI is drawing upon, but we could use the ai AI to, to actually manage the Bug Bounty program itself, right?
So in addition to finding particular bugs using an AI and an LLM, we could use the AI LLM to manage our Bug bounty program, contact the researchers immediately see, is this particular report a duplicate of one we've already received, as you mentioned, uh, uh, take a, a, a shot at predicting what the CVSS score would be for this bug. I mean, it really, it sounds like it makes your job a lot easier. No, Yes, it is.
Uh, but yeah, that comes with, uh, a limitation actually, because, uh, uh, it's, uh, providing a lot of extra value, but it needs to be verified. So, uh, we have all the information there, but, uh, in the end, uh, human touches is required for these. So, uh, and we really want to give the, you know, the researchers a chance to, uh, like we want to understand them.
We don't want them to be blocked by, you know, an AI decision. So that, that's definitely a limitation. Absolutely.
I, well, it's not just in this particular instance, I think that's good lesson for everyone who's using AI chat bots for customer support and, and service and so forth, is people do get fussed. I, I'm, I'm the first to admit it. I'm the guy yelling representative.
Representative, you know, I want to get a real person to talk to. Uh, and, and I think it's, it's true in bug bounty programs too, Alex, we're almost outta time for, we have a huge security audience here for security folks out there who say, you know what, I'd like to be involved in the Adobe Bug Bounty program. Where, how can they, how can they get involved?
For sure. com/adobe and read the policy, the assets in scope, and start there. com/adobe.
Alex, Hey, keep up the great work. You know, everyone, every, all software has bugs and vulnerability, right? Vulnerabilities.
I, and it can happen to anyone. I, I've learned a long time ago. Don't point fingers, but Adobe's done a great job, I think, and the Bug Bounty program is one of the ways that you guys have done a great job in ensuring your software is the most secure and safest it could be.
So keep up the great work and keep us posted. Thank you very much, diam. Thank you.
We'll be back with more information and insight into Adobe security. I want to introduce you to Omkar ni Bakar, and hopefully I pronounced it right, but, um, this gentleman's too nice to correct me, I'm afraid, but I, I hope it's the right, uh, pronunciation. Omkar is the senior manager, cyber threat research and intelligence at Adobe mka.
Welcome to Textron tv. It's great to have you on here. Yep.
It's my pleasure to be here. And you pronounced my name absolutely right. So it is, um, thank you for that.
Thank you. Thank you. I try.
So mka yeah, I gave them your title. What, what does it, what does it mean when you, uh, you know, when we talk about threat research and intelligence? Sure.
Uh, I can definitely talk a little bit about that. Um, so I lead a team of cyber threat researchers responsible for proactively identifying and analyzing adversaries, tactics, techniques and procedures, gtps, um, and which who are also responsible for providing actionable intelligence to enhance OB security posture and support overall incident response efforts. So that's what the team does, but at the core, it is really about threat intelligence.
And if you look at the whole, uh, idea of threat intelligence, threat intelligence at the core is practice of gathering, analyzing, and disseminating intelligence on current and emerging threats so that you can strengthen your overall defenses. So the thread graph really focuses on gaining deep insight into understanding who your adversaries are, understanding their tactic, tactics and targeting strategies so that you can generate actionable intelligence to proactively defend against their attacks. Uh, the goal here is really to get insights into adversaries intense capabilities and opportunities so that you can inform risk-based decisions to enhance defense posture.
And when I say enhance defense posture, there are multiple ways to do this that threat intelligence really helps with. Uh, like, for example, threat intelligence is kind of an input loop into threat hunting exercise. So that based on adversaries threat intelligence team is tracking, threat hunting team can go and look for specific behaviors of that tactic, techniques and procedures into the organization's environment.
Threat intelligence also informs detections engineering, so that detections engineering can actually instrument a lot of detections for the adversaries that would be interested in your organization or would've actually targeted your organization in the past. So the overall goal of threat intelligence is to make it more actionable and timely in order to, um, improve overall defense posture in multiple ways. Makes sense, makes sense.
Um, now, like, like almost everything else, AI has the potential to change the game here, right? And not only to future tense, but is in many cases, is today. Talk to us about how, how AI is, is changing how Adobe does threat in research and intel.
Yep, absolutely. Uh, and you're absolutely right, like AI is changing like our lives every day. Uh, and from work perspective, like as we think about technology, so when I think about ai, like it is so much evolving.
And similarly, when I think about like overall threat landscape, uh, for industry that is also always a very evolving. So this two things, uh, connecting together are really helping solve like a lot of problem space in threat intelligence world. So by leveraging ai, uh, threat enter teams can really automate and augment like threat analysis performed by a human threat.
Intelligence teams can move from reactive threat signals triage to more strategic proactive defense. And I, I can give like a couple of examples in the way we are doing this here at Adobe. So what we call it as AI power thread analysis.
So large language models, LLMs are able to digest and understand vast volume of unstructured data from various threat intelligence reports, blog articles, research papers that are talking about specific attack campaigns. They have specific context around adversaries, what their tactic techniques and procedures look like, what their indicators of compromise are. So LLMs can easily digest this information, identify patents in a much, much better way with more contextual insight to extract indicators of compromise so that organizations can actually go and, um, look for those indicators across your environment.
And what this really helps with is automating threat analysis for emerging threats by reducing manual bandwidth. Like if you look at the news, like there are so many threats every day that are evolving, like the landscape has been rapidly changing. So for humans to, for the analyst or researchers to actually sit down and analyze that every thread, it's a very manual type bandwidth consuming task.
So AI is really helping us to do that faster and better by reducing noise overall from threat intel feeds, prioritizing relevant indicators of compromise based on organization's context, which ultimately helps with faster dissemination of intel, uh, where the goal of intelligence is really to make it time and also actionable. So that is one example. Uh, the other example that I can give is threat landscape report generation.
So I'm sure like, like Adobe, every organization would be interested in understanding what their threat landscape looks like. This is where AI can really help by analyzing both external threat data, uh, through multiple sources, both public, there might be some vendors providing threat intelligence data. So AI can actually help analyze external data as well as internal organizations signals to generate more tailored threat landscape reports for executives, for security teams, uh, for various engineering teams, which can be, uh, created at regular cadence.
Uh, so that all those teams are informed about evolving threats specific to their organizations or specific for their team. Um, so the benefit here is really, uh, rapid and relevant threat landscape reporting with minimal manual effort. And the best part about this is that ai, due to the contextual understanding, um, AI is able to generate tailored threat intelligence for specific organizational needs so that it is more tailored for your use case and not generalized.
I love it. So mka, I'm gonna ask you a important question important to our audience too. We're all hearing how AI might replace people.
You know, they're, we're calling some of these agentic AI things, digital workers, right? As you sit here and, and how Dolby is using it. Is it, is it replacing anyone on the cyber threaten intelligence research and intelligence team?
Or is it augmenting and, and making you more effective? That's a really good question. So I don't believe like AI will is replacing threat intelligence analyst as of today.
As I think about AI, technology definitely helps augment human analysis and it helps us be better and faster at what we do as threat researchers compared to like replacing. So it's a little bit away from replacing. And, and the reason I see this is because, um, AI is better, but it is still not at a point where it would really replace, uh, like we still keep seeing false positive based on what AI generates, because it really depends on what the quality of data that you are training your model on.
Um, it also has like a lot of contextual awareness, but it still requires human oversight for decision making in some cases because AI might miss the nuances that a seasoned security professional would catch it immediately. So it is definitely a game changer to augment and make us faster at what we do, but I don't believe it is at a point where it'll replace us right now. But it definitely augments and makes you more effective, and I think that's the important thing.
Yep, absolutely. It is definitely a game changer in that way. Excellent.
Omkar, thank you for coming on and talking to us about threat research and intelligence, which, you know, was such an important arrow in the quiver for our cyber teams today and about how you're using ai. Again, another really great example of how AI is making us more effective in our cyber jobs and making our security better. Thank you.
Awesome. Thank you for having me. Uh, it was a pleasure talking with you.
I'm happy to introduce you to our next guest. His name is Poin Resh. I hope I've got that right, but if not, please correct me.
P Poin is a, a senior application security engineer. Poin, welcome to Techstrong tv. It's great to have you on.
Hi, a, uh, great to be here as well, Howen as a senior application security engineer at Adobe. Talk to us about how you are harnessing the power of ai, and not just you, but Adobe and your team and teammates. How are you guys harnessing the power of AI to define the future of security?
Right? Yeah. Oh, great question.
So, uh, I'm essentially part of like the threat modeling team. So we handle like the threat modeling efforts across, uh, the board for Adobe. So, uh, one of the ways that we are exploring to leverage AI in the threat modeling space is to make sure that we can, um, essentially have like better faster feedback to product teams.
Because as a small team, scalability is one of the, our primary issues, right? So, uh, the way we're thinking about this is making sure that we can leverage AI at the early stages of like the SELC process where teams can come and provide us a little bit of information, and in return we provide them with potential threats and potential mitigation strategies that they can leverage. And from there, if we see any critical issues or areas that we want to manually focus on, that's where we would like go ahead and do a manual threat model or like the traditional threat model if, I mean, so that's how we're currently thinking about leveraging AI in the, in the threat modeling space.
You know, you, you think about it, it would seem like threat modeling is probably a, uh, a great area to harness the power, the positives that AI brings to it, that AI brings to a, you know, an issue like that. Can you dive in maybe a little deeper about why AI is a, is a great technology for threat modeling specifically? Oh, yeah, for sure.
So, um, over the last year or so, we've started leveraging like, uh, an LLM to essentially analyze like architecture diagrams, the user flow diagrams, as well as like any documentation that the team provides us. And based off the documentation itself, we, uh, would be able to like look into, uh, and understand the context, the LM would be able to understand the context and then provide back potential threats and mitigations. And right now we're exploring the concept of using agent pipelines.
So, uh, one is essentially figuring out, uh, one agent will be figuring out what the content looks like, and if there is not enough content that the, that the pro product team has provided, then getting back to them saying, Hey, can you give us more details about your authentication, your authorization, maybe how you see, uh, how you store your secrets, and so on and so forth. And then from there, we have another threat detection engine. So this is where like the meat of it happens, right?
So, um, this essentially takes all the context that, um, the product team has provided along with like a prompt that we've created that would then like provide us with a list of like the top end number of threats that might affect the product itself. And that is where we go into the interesting phase. So we are currently leveraging what we call like a, a retrieval augmented generation system or a rag system for us to like provide the mitigation strategies.
Before what we were doing was more so just leveraging the base or the foundational knowledge of the LLM to provide mitigation strategies. And that wasn't working as well because like, um, it would just be a little generic in terms of like the medications, uh, in, in terms of what it, uh, gave us back in terms of the mitigations. But, um, right now the way we're doing it is, uh, hey, these are the documents that we have curated over the last few years that are very Adobe specific, that, uh, talk about like the products that we use at Adobe, the solutions that we use at Adobe, and then that is leveraged by the LLM to provide very specific or pointed, uh, medication strategies to the team.
And we're hoping that this would make it more actionable for product teams to leverage and, uh, at the same time make sure that they don't see, or like, it doesn't make it too generic to a point where they don't leverage the medication strategies altogether. So that's essentially the path that we're moving towards right now. Love it.
I love it. You know, I, I'm just realizing and listening to you talk. I I've been in security a long time.
I, I of course understand everything you're saying about what you do in threat modeling, but you know, Adobe does threat, not just Adobe, but a modern cybersecurity strategy today includes threat intelligence, threat modeling. If you wouldn't mind, take just a quick minute talk about how these, these things, you know, how they go together, but yet they're each their own sort of independent, uh, discipline, if you will. Oh, yeah, for sure.
So, uh, threat modeling has sort of moed over the last few years, but essentially it is a very systematic way of like detecting potential issues and like providing mitigation strategies for teams very early on in the development life cycle. So you can think of it as like a shift left strategy. And, uh, the way we would approach it is essentially understanding like, uh, the components that are being part of like a particular workflow, the way they interact with each other, uh, how data flows from like the entry point all the way to the exit point.
And, uh, if there are trust boundaries, how those trust boundaries interact with each other as well. So, uh, essentially understanding the complete picture of how a product works and then figuring out where there are weak points or like potential areas where new risk or, uh, potential threats can be introduced. And once we identify those, we share that with the product team along with like a curated list of, Hey, if you do this, this potential risk can be mitigated, and so on and so forth.
So, uh, this, uh, threat modeling essentially becomes like a part of the early, uh, se early part of the development lifecycle, but we essentially try to like keep that flowing from like the ideation phase all the way to production so that we help teams like secure their workflow, uh, from from to shift left to right. And the earlier we do threat modeling, the better it is purely because it reduces the kind of double work that teams need to do to like prevent these risks from happening after they go to production itself. So, uh, that's where, uh, threat modeling as a concept comes into play, and that's why it's so important in the industry right now.
Love it. This next question is the most important question you're going to get asked here, so give me a good answer. Go on.
We hear so much about AI taking people's jobs. We hear also about AI helping people with their jobs when it comes to using threat to using AI and threat modeling, maybe even with agentic ai, is it replacing security engineers or is it making you more effective in your job? Oh, great question.
And the answer is resoundingly, uh, to say that it is making us a lot more efficient. I don't think, uh, egen pipelines or however complex these AI systems become, it would, uh, replace our jobs altogether purely because there is that human factor that comes into threat modeling. We understand like the, the nuances between how companies interact with each other, uh, the co uh, the business impact of like a potential threat that could, uh, affect a particular product.
And there are other human aspects that cannot be like taught to an ai. But at the same time, having said that, it does make our lives a lot more efficient with the introduction of AI itself because, um, we call it the low hanging fruits, but essentially, uh, AI is able to cover our bases when it comes to like, uh, the lower risk areas or like, uh, some of the gotchas that are easy to detect. And that is where it helps us, like cover our base.
And from there, if there are any critical components, we go in and still continue to do like a manual threat model. So, um, essentially think of it this way, right? Instead of doing like, um, 20 threat models, we are able to focus on the top five highest risk threat models, and the rest of it is sort of handled by ai.
So we are able to focus our time and energy towards the, towards the critical workflows that matter for Adobe. And that had like, uh, like dire consequences if there is like an issue with that workflow. So I would say that it is not replacing our job, but like making our lives a lot better and our work a lot more efficient.
Got it. I think a lot of, a lot of, uh, security engineers are breathing, breathing a sigh of relief. Ha ha.
Hearing you say that. Um, one last question. This, this AI stuff is evolving so quickly, it, it seems like every day it's like a generation ahead.
How is Adobe and yourself, how are you, how are you staying ahead here? How are you continuing to kind of ride the crest of that wave? Oh, a great question again.
So, uh, what we do at, within our team is spend a lot of time doing open-ended research on like topics, essentially making sure that we do a lot of research in the areas and trying to keep up with the trends. Just yeah, open-ended research, making sure that teams reach out to us, uh, early on in the development life cycle so that we can like, learn with them as they're like experimenting with the new LMS or the new workflows so that they're doing it in a secure manner. So, yeah.
I love it. Wan I wish we had more time to talk 'cause this is such an interesting area, but thank you for coming here on techstrong TV and, and talking to us about threat modeling and AI and how Adobe is harnessing AI to stay ahead here and, uh, keep us all more secure. Thank you.
Have a great day. Our next guest in this series is Trudy Gupta. Trudy is the product security, AI and data engineer at Adobe.
Trudy, welcome to Tech Trunk tv. It's great to have you on here. Thank you so much, Aden, it's great to be here as well.
So, Trudy, let's, before we dive into topic at hand, let's talk a little bit about yourself. Give us an idea of your journey and how you came to have this role at Adobe. Yeah.
Um, yes. So I am a product security, AI and data engineer. Uh, I've been at Adobe for four years now.
Started as an application security engineer, and then my role evolved into what it is right now. So basically my background is at the intersection of cybersecurity and, uh, machine learning and ai. So I've always been curious about how do we apply AI to solve cybersecurity challenges.
And, uh, that's at the heart of what I do right now at Adobe. So I, uh, research and develop AI capabilities that can enhance product security. And, um, in addition to my engineering role, I'm also the product lead for my team.
And in that function, like in that capability, um, I am responsible for understanding developer needs, translating that into what we are building, um, communicating and collaborating with stakeholders, and also setting the long-term vision for what we are building. That's a great role. What an interesting role because in some ways shady, you are the conduit, the translator, if you will, of what business is asking for, what the developers, the non-security folks are asking for, and dealing with the security team as well.
And then fashioning what really is new technology when it comes to AI and agent AI to kinda meet, meet those needs. What a, what an interesting intersection to be at at this moment in time. Absolutely.
Let's talk a little bit about kind of things you're doing. And I, when, I mean you, I don't mean just you personally, I mean your team, things, you, you guys are building, deploying, using, along these lines that are helping to define how, how AI is being utilized in security by Adobe. Yeah, absolutely.
So we, my team are basically building a suite of AI capabilities that are designed to reduce product security toil. Um, and the way we want to achieve this is by making security guidance, security knowledge, security expertise more available, more accessible to product teams whenever and wherever they need it. Um, and those services that we are building, we are, uh, we are making them available as, um, API endpoints.
Basically they should, anybody at Adobe should be able to use them in a self-serve manner, and you can integrate our services seamlessly into existing developer workflows. So think, uh, messaging platforms, ticketing platform IDs, web widgets, et cetera, right? So be where developers are, uh, provide security guidance as in when they need it.
And for this, we are using ai. Um, so fundamentally we think of all the stuff that we are building, uh, we kind of categorize it into two large buckets, I would say. The first is, um, AI security assistance.
Um, you can also call it ask security. So anybody at Adobe can come to the assistant, ask their security question and get an answer. And now we are doing this by leveraging Adobe's internal policies, uh, standards developer product and platform documentations so that, you know, when a developer is coming with a question, the AI assistant can answer that question in a way that is as close as possible to how a human security expert at Adobe would answer that question.
So that's one. And then the second pillar is, uh, remediation recommendations. So, uh, we want to equip engineering teams with the right resources that they need to remediate to fix vulnerabilities.
And again, for that we are using Adobe specific information, Adobe specific product specific best practice guidance, trying to understand the context in which the vulnerability is, and then put all of that together to provide the guidance that can aid the developers, that can enable them to go fix the vulnerability. So these are kind of like the broad two categories, uh, of capabilities that we are building. So in, in here you describe them, they sound to me more almost chatbot type of things where an engineer could say, Hey, how do I, what's this vulnerability?
What's the best way to patch it or remediate it? I know patch is mm-hmm, mm-hmm. An old word.
And, you know, these are great chatbot type of, uh, opportunity or description. So, uh, Go ahead. Yeah, no, no, go.
I think you know where I'm going. Go ahead. So, uh, chatbot is one way to get this guidance wherein yes, like you have a, you have a chat, bott, the developer comes to the chat bot asks a question and gets the guidance for the question, um, be it generic guidance, or how do I do X, y, z or how do I fix a bug, right?
Um, one of the other ways that we are doing this also is when we find, uh, security bugs, uh, we have a process for ticketing them. You've spoken, uh, with, uh, like Alex on the bug bounty side. So we, we create tickets and then we assign those tickets to the developers.
So another way that we are integrating in that existing workflow is, um, call our APIs that understand what the bug is, and then provides remediation guidance in the ticket itself. So when the developer is assigned the security ticket, they don't just have, uh, a description of what the vulnerability is, but they also get a guidance as to how they can go about fixing the vulnerability. So, so that is how we are doing it today.
We also, of course, have the chatbot functionality. Another aspect is, like right now, um, AI assisted IDs is the new thing, right? Like it's gaining a lot of popularity among developers.
So that's, that's another outlet. So as developers are writing code, how do we detect vulnerabilities? And instead of having the AI agent in the IDE provide like a generic guidance, how do we get that tailored to, uh, what Adobe recommends as the way to go about it?
So that's another way to kind of, um, address this and make this information available to developers. Let me ask you a big question. So when do you think we'll see agents that actually go out and just do this and kinda tell the human after the fact, if you will, or do a report, but they're actually doing the remediation in an autonomous type of, uh, setting like that?
Yeah, that is a tough question, right? And I think, uh, it's, it's an ambitious goal as well, right? Of course, that would make all of our lives so much easier.
But it's also so difficult goal to achieve with state of the art AI models and AI agents. The thing is, when you're talking about a single code file or like a small enough code repository, state of the art models do okay-ish, they, there can be hits and misses, but the thing is, like at Adobe, each product team is so different. Our code bases are vast.
So realistically, I would say we are not there yet, uh, wherein we can have AI agents figure out what the fix is and go do it, uh, at the PR level themselves. And I would say we don't necessarily want that. Also, um, in my team, since we've been developing these AI capabilities for what, almost one and a half to two years now, like, we have learned along the way that human feedback, human in the loop is absolutely critical in these workflows.
Um, like we don't think that the answer is to give the AI agents a hundred percent agency, uh, but there has to be a human oversight involved, right? Like these agents are, uh, very useful when it comes to doing the manual laborious, tedious tasks, right? Like going through documentations, um, like finding the right resources, those kinds of things.
But at the end of the day, uh, we do need, like, like our recommendation also is that there has to be human oversight involved. Go take a look at what the AI agent has produced, what the AI agent has generated, right? Does it meet, meet your requirements?
Does it meet the, the, your requirements, what you've asked for, what, what the right way to do things is, and then you kind of, for the lack of a better term, approve those changes. So I would say that's, that is more realistic than, uh, like let agents go do whatever they want to. Uh, I don't think, um, even with the state of the art, we are not there yet.
Yeah. Trudy, I wanna thank you for coming on and talking with us today. As I said, the time goes quick.
Keep up the great work though. And this is, as I said, an exciting place to be in this moment in time. So good luck to you, absolutely.
Surety Gupta, product security, AI and data engineer at Adobe. I hope you've enjoyed this session of four or five actually segments of different areas of the Adobe security team using ai, leveraging AI to make their software more secure and makes your work more secure. I hope you can take these lessons and apply them in your own organization as well.
Thank you. Hi, welcome to the six five Summit AI Unleashed and this enterprise app Spotlight, intentional innovation. I would like to welcome Gobin Bala Krishnan, senior vice president and general manager responsible for Adobe Express.
During his 19 plus years at Adobe. His passion has been to build tools and runtimes that cultivate creativity on all platforms. Most recently, this has led to his leading the Adobe Express business.
Govin, thank you for joining us. Thank you, Mel. Really, it's my pleasure to be here.
Thank you for having, great to have you. Before we dive into this topic of intentional innovation, let's set the stage a bit. Can you tell us a little bit more about Adobe Express?
Who's it for? What it aims to do? Yeah, more than happy to.
Um, so we've been on this journey with Adobe Express for, uh, for a few years. For two or three years now. We've had it in market for, I would say around a year and a half.
Uh, and, uh, the premise, so to speak, is that Adobe Express brings the best of Adobe's creative and document tools into an application that's quick and easy to use for everyone, right? And the idea is that it enables everyone to create content that helps 'em stand out. And we have numerous examples of a number of, uh, users from different genres, so to speak, using the application in very impactful and meaningful ways.
Uh, we have marketers who have been, who, who have successfully used express to create new campaigns, to repurpose content from existing campaigns to localized content for regional markets. Uh, we have solopreneurs and small businesses, uh, using Express to build their professional and personal brand to grow and, uh, to grow their social audiences. Uh, we have educators are using Express to help students, uh, communicate and learn more creatively.
Uh, we also play, we also see Express playing a very critical role in enterprises, uh, as it relates to their content supply chain, uh, solutions where we are empowering both business professionals to, uh, who need to create visual content, be it presentations or social content or, uh, even, uh, sales pitch decks, uh, and, and sort of working hand in hand with marketing leaders who are focused on ensuring that the content that's created stays on brand, right? It's not that you just enable everyone to create content, but you, the, the core component or a critical component of the content supply chain is ensuring that any content that gets created within an organization stays on brand. And, and marketing leaders are sort of collaborating very effectively with business professionals to ensure that any content that's created by business professionals in the enterprise stays on brand.
And the, the, the, the good news is that through these efforts and through some of these in initiatives, we have seen a very large number of enterprises, uh, experience a significant level of success, uh, with Express. Uh, some of the examples that come to mind are the PGA or AstraZeneca, uh, Virgin Australia, uh, PRAL Financial, uh, Workday Paramount. The list is really, really long.
And, uh, we believe that as we continue to go through this journey, we, we expect to see an incredibly large number of, uh, large businesses, actually it's large and small businesses for that matter, uh, deliver, uh, success, uh, from, from leveraging the capabilities of, uh, of Express. So you named a variety of users like marketers, solopreneurs, small businesses, educators, and enterprise teams that use Adobe Express. Can you share a couple of examples of how some of these customers have achieved success with the platform?
Yeah, sure. A couple that I'll go drill deeper into are, uh, one is Red Hat, uh, where we have seen them empower the breadth of their organization to create content using Adobe Express, which has helped their company achieve a time saving of almost 10 x, which is incredible to hear. Yeah.
The other one that I will highlight is with, uh, Densu, where we are seeing that they have enabled their entire distributed, uh, marketing and social teams across 120 offices to create content, uh, using Express, which has helped them get to market, uh, 70% faster than they could without express. So two clear, uh, proof points of success where our customers are realizing some significant ROI from, uh, incorporating express into their workflows and, uh, processes. That's great.
It's great to hear those outcomes and innovation, that it has to be customer centric and it has to solve real problems, but that doesn't just happen. It's not magic. So what does that customer centricity mean for Adobe, and how do you ensure that these tools enhance the process for your customers?
Yeah, that's a, as, as you've heard me say that, that's a topic that's near and dear to my heart, Mel. Mm-hmm. Um, as I've said in the past, one of the key, uh, components of innovation is to, is to ensure that obviously the capability, uh, is, it's, is is inherently interesting and, and compelling by itself.
But, uh, innovation that does not necessarily do enough to, uh, to address real customer problems, to, well, a, we have to ensure that we are identifying the right set of customers that the innovation is addressing, uh, identify the right problems that we are, uh, that we are addressing for those customers, and then making sure that the innovation that we deliver drives the right business outcomes. I mean, that to me is when innovation becomes truly magical and is something that we try to deliver to the extent possible. Within Adobe, it's about getting the, finding the right problem for the right customer to drive the right outcome, and obviously the capabilities themselves, how to be compelling to start with.
So once we get to that, the question then is how are we applying that within Adobe? And, uh, I would take the example of Adobe Express and how we have built Adobe Express. We, uh, when we started on the process a few years back, we ensured that we built every feature with a clear customer in mind.
We, uh, the question that we kept asking ourselves is, who's the bullseye for the product to start with? And how, what pain point, uh, are we, are we addressing as we, as it relates to addressing the needs of that bullseye customer, customer? And then once we started delivering the capabilities for that bullseye audience, the question is, okay, what business outcomes are we driving for that customer?
And we started that process by, uh, ensuring that we validated every one of our capabilities within Adobe. So we have, um, very, uh, compelling dog footing program, so to speak, where we encourage every one of our users to use the products or use every one of our products on a daily basis. But more importantly, we also get them to use some of the new capabilities that we are intending to launch and have them provide feedback before we have them, uh, you know, made available to the external audiences.
So we, we sort of start by ensuring that we are delivering real value, uh, to our customers. And there are a couple of examples where I feel like this has really moved the needle. One is with how we brought generative AI into the product.
Uh, when we started building the product, we had started building it as an AI first solution, but generative AI sort of became a thing, uh, while we were building the product. And rather than bolting generative AI onto the product as an afterthought, we decided that it made most sense for us to be customer centric by contextually integrating generative AI into these workflows that our customers go through to ensure that it does not feel obtrusive, but end ends up feeling more, uh, like a, like a, like something that they can leverage as they go through the creative process. It's clearly helped us, uh, uh, see signals where the ability to use generative AI as part of their workflows has helped them create significantly more, uh, compelling content, uh, that has helped them drive better, uh, business outcomes.
So there are a few more examples, but I'll, I'll pause there and, uh, see if you have any other questions related to that. Yeah, I mean, you said like it allows them to create more, and so let's talk a little bit about creativity and productivity, because we're seeing a trend where those concepts are really coming together. They really have to, right?
I mean, this is somewhat caused by demand. So how do you see Adobe's role in this? Yeah, this is an interesting trend that has actually been around for, for a while.
I mean, we've always known that visual, uh, communication is by far the most effective, uh, form of communication. But an interesting trend that we have been noticing, uh, recently is that even, uh, PDF documents that have historically been more text-based are increasingly visual in nature. I mean, we, we did some analysis recently and found that roughly 10 to 15% of all PDF documents that are created today, uh, are visual in nature.
So, uh, it is clear that, uh, creativity and productivity are, are coming closer and closer together. Uh, more and more communication is happening through visual channels. Uh, previously it was primarily, uh, personal, uh, communication, but we are also seeing business communication happening through social and visual channels.
And the opportunity that we have, obviously is to, uh, make sure that we deliver solutions that, uh, meet the, the customer need that we are sensing in that, in that space. And, uh, we are doing that by, uh, ensuring that the products that we have, uh, like with Express, for instance, is deeply integrated with, uh, Acrobat. Uh, we are increasingly building workflows that connect Acrobat with, uh, Adobe Express and the capabilities of Adobe Express that make it easier for, uh, users of, uh, and a of Acrobat and creators of PDF documents bring in more visual elements into that, into their documents.
Mm-hmm. Uh, we're also, uh, looking for opportunities to make it so that even within Express, you have the ability to bring in your creative assets from applications like Photoshop, illustrator, InDesign, Lightroom, bring them into Express and, and build on the content that you have created in some of these flagship creative applications. And we are taking that even further by ensuring that we have, uh, expressed, well integrated into the downstream applications for building fledged campaigns by ensuring that we are integrated into applications like a EM Workfront and, uh, gen Studio.
So it's the end-to-end connectivity, so to speak, of, you know, making sure that Express can work with both creative and productivity applications. To build that seamless end-to-end workflow is an area that we have focused on. And we've taken that even a step further by bringing, uh, making the product extensible and ensuring that express as a product can be integrated with solutions that our users are leveraging outside of, you know, the creative space.
So ensuring that, uh, express is integrated into applications like box applications like Slack. Uh, we have recently launched now an integration with Miro, which is actually, uh, uh, has been doing incredibly well, um, or even actually in, in an interesting way, integrating it into consumer use cases like, uh, an integration that we launched with EA Sports that, uh, was, was, was a fun one with the college football game and EA sports, uh, chat, GPT. Uh, and more recently we just, uh, announced a partnership with the NFL that we are super excited about because we feel, we see that there's an opportunity to drive fan engagement, uh, with a tool like Express through our partnership with, uh, NFL.
So it's, it's sort of the fact that creativity and productivity are coming together has helped us take our solutions like express to, to new levels by enabling more of our users, uh, to be creative even in productivity, like use cases and situations. That's really helpful. I love the overview of Express and also how Adobe is working hand in hand with customers to answer to those organizational demands.
And also really just kind of to answer to human creativity and expression. And as you look towards the future and where we go from here, what do you think people need to be thinking about when using AI in their organization and when adopting it? I actually love what you said about just getting AI into people's hands.
I think that's really great for you as an organization with the feedback mechanism, but also getting it into people's hands is such a big way of getting people to use it, right? So what do you see in the future of how, you know, getting people to adopt it, getting it in people's hands? What, where do you think we're going from here?
Yeah. One of the, uh, the key, uh, tenets that we have held, we have held true to, uh, all along, uh, at Adobe is that everyone has a story to tell. And, um, the opportunity that we have had, uh, all along is to enable everyone to tell the, tell their stories in a visually compelling way.
And, uh, when I look at our journey, uh, with Adobe Express and where we started, uh, when we started, uh, as I said, we started working or building this product around three years back and back then, uh, one of the key, uh, components of building the product was to make it AI first. And the idea there was we would provide, uh, our users with tools and, uh, recommendations and contextual recommendations to help them on their journey using AI to help them on their journey to get to their output, uh, as quickly as possible. That was phase one or step one.
Step two was when generative AI became a thing, and we started incorporating generative AI into the tool where not only do we provide contextual recommendations, but now you have the ability to use a prompt to convey or to communicate what you're looking for, and we would, uh, be able to generate either images or videos, or even text effects in the context of your workflow as you go through the creative process with a tool like Express. Mm-hmm. What we are now seeing, though, is the next step, so to speak, or the next phase of this evolution with Agentic ai, where now with the prompt, you now have the ability to essentially generate a design from scratch.
And what it does for us as a company, and what I'm most excited about here is that it gives us the opportunity to completely reimagine and rethink creativity and how creativity is done. And it gives us the opportunity to dramatically lower the barrier to entry for anyone to come in, anyone with a story to tell, which we believe is almost everyone, anyone with a story to tell, to come in and interact through a prompt. It could be a conversational interface or a text space interface, but interact through a prompt to essentially communicate or convey what they would like to create.
It could be an image, it could be a video, it could be a full fledged design, and have that show up on the screen. And what's, what's what's quite exciting or truly exciting about all of this is that we obviously have the ability to generate what's in their minds eye, but we still have the tools, or they still have access to the tools if they choose to, to go in and, and, and tweak the content to meet their needs, right? So it's not that the tools are completely taken away from them, they don't need to use the tools, they don't need to learn to use the tools, but if they choose to, they still have access to the tools to go in and fine tune the, to fine tune the content as needed.
So what it does is it gives us this, this, uh, ability for us to reimagine, as I said, reimagine creativity, and it gives new ways, entirely new ways for everyone. Um, and I mean, really everyone to tell their stories and, and scale their businesses. And that to me is just an unbelievable, unbelievable opportunity that we have ahead of us that I can't wait to deliver on and see what, uh, everyone creates and does with.
Well, this was great. I love to hear all of this, and we're so appreciative of you joining us at this enterprise app keynote at the six five Summit. Great.
It was my pleasure to be here. Thank you, Mel. Thank you.
com slash summit and stay tuned for more insights coming up next. Hi everyone, welcome to the six five Summit AI Unleashed. I'm joined today by Tristan Holcomb, group Vice President Corporate Strategy and Development at Applied Materials.
This is going to be an excellent semiconductor spotlight, and we're gonna be talking about accelerating energy efficient computing. Tristan, welcome to the show. Great to have you on the six five and at the summit.
Thanks so much, Daniel, it's great to talk to you. So let's do, uh, the quick backdrop on this, uh, you know, applied materials like, you know, everyone that knows the six five knows Patrick and I knows that we are semiconductor geeks, nerds, chip guys, anyone that reads our stuff watches us on the tube on the news. We love talking about this, but apply materials, massive company.
But just give us that quick backdrop for everybody out there in our audience and those that may or may not know apply materials. Sure. So I think many of the other speakers at this summit work for companies who are leading the way either in the development of AI hardware or software that ultimately is gonna be used by companies or consumers, um, at apply materials.
We're really working at the other end of the technology stack. And applied materials is actually quite a descriptive name for the company. We're a material science or materials engineering company at our core.
And those large pieces of capital equipment that go into the fabs that we're well known for, they're really just the life support system for that material science. One of the examples that we often give is, if you look at that application processor chip in your phone, uh, that chip has 19 billion transistors, about 70 miles of wiring. It's all contained in a sliver of silicon, as small as your fingernail, as thin as a piece of paper.
And today that chip is made from 25 different materials that are combined together in a hundred, uh, different ways. And the smallest feature of that chip is about two atoms tall. So creating, depositing, shaping those materials, that's really what a apply materials does better than anyone else in the world.
Tristan, really appreciate you giving a little bit of the background. Now, let's talk AI for just a second here. I mean, yes, people know applied materials and now they know it even better.
They know you're one of the top suppliers of equipment for basically every chip fab in the world, but one of the areas that they may not be as familiar with is how you enable ai. Talk a little bit about where applied plays in the overall AI technology stack. In terms of our role in ai, we look at AI as a technology stack with the applications, the models, the softwares at the, uh, the software at the top of the stack.
So that's companies like OpenAI, Google, Microsoft, and Meta. The data centers themselves in the middle, and then the chips and the chip making technology at the base and at apply materials. We are really the foundation of that stack.
Our focus is on those foundational technologies that define how chips are made, and we work up from there and we partner with the different layers of the hardware and software companies, uh, in the ecosystem With such a foundational role in the tech ecosystem, applied as a unique perspective on where AI AI is headed, uh, and what might be some of the big challenges facing the industry. But what would you say is the number one thing? Uh, and I have my answer by the way, but I'm gonna, I'm not gonna tell you what it is, but what do you think the number one thing that's going to really limit this large scale deployment of ai?
Yeah, so I would say, you know, if we were gonna use one word, that word would be energy. Uh, but to explain why we believe that's the case, maybe I'll back up a little bit and explain where we think we are in the adoption curve of ai. And I think the first thing that we can say is that AI has almost infinite potential applications, and we're really just at the beginning of this large scale deployment, and that deployment is gonna take multiple decades.
And as AI gets better and better and more cost effective, you can think of these economic crossover points for all of the different types of application. Um, the second thing I'd say is we see the adoption of AI becoming a necessity rather than discretionary. So if you step back and you look at some of the big macro trends in many of the developed countries, there is significant changes in demographics taking place.
So people are having less children, they're living longer, and that means the ratio of the working population to the non-working population is getting smaller and smaller. And the way to offset what is effectively a shrinking workforce is through productivity growth, increasing the average output per worker. But productivity growth, uh, over the last decade has been very slow in those economies.
I think in Japan, for example, it's less than 1%. So I think that this will probably sound like a very Silicon Valley thing to say, but the only way to drive future productivity growth that the magnitude that's needed is through technology, specifically AI and automation. So with that as some background, you know, given those factors, why don't we see AI being deployed much faster?
And I think you'll hear throughout this summit that there are numerous reasons, cultural, ethical, technical, but in our view, the biggest one is energy. And I don't think it's any secret that AI consumes a lot of power, uh, today to train a generative AI model like chat, GPT, those companies are typically using a 10 megawatt class data center. So a data center like that is consuming the same amount of energy as 5,000 homes within the next year or so.
We expect those data centers to have a hundred times more compute and use 10 times more power. So at that point you're gonna be at a hundred megawatt class, and then a few years further out, we can expect another a hundred times increase in compute, another 10 x in power. So at that point you're at a one gigawatt class data center.
And in fact, meta recently announced that they're building a two gigawatts data center in, uh, Louisiana. 1 gigawatts. So that means that we see this grand challenge for the industry is to significantly improve the performance and energy efficiency of those data centers.
And the metric that we think about is flops per watt, and it's really flops per watt, per dollar. And an emerging consensus in the industry is that we're gonna need a 10,000 times improvement in that computing performance per watt over the next 15 years or so. Yeah, Tristan, I I really like how you set that up too because I've spent a lot of time thinking about the productivity gains, thinking a lot, sort of what it means, um, how quickly we do move in this direction and, and how do we get more productivity and also those sort of rate limiters.
Because I think even at this event you probably hear a lot, lot of people talking about, it's been pretty exponential. It's been pretty mind blowing to see in two years or two and a half years since that first instantiation of chat GPT to the model iteration innovation and the exponential growth in the, in their capabilities to reasoning, um, the development of the chips, the ones that you help support from, uh, various, uh, you know, fabulous designers and, uh, you know, different, um, even hyperscalers building their own. And of course you play a role in in how this all all comes to pass.
And then kind of how you came back to this, that it is energy. And I've spent a lot of time talking about this too. And of course there's different ways to achieve energy.
There's more energy through, you know, kind of dirtier mechanisms like coal fire and, and then there's nuclear, which we've spent a lot of time talking about. And you know, people like Elon Musk are, are, are kind of swearing by the sun being the answer that we can get all of this power we need from solar. But then even when you put into perspective of like the Hoover Dam and one single data center for one company, we go, holy smokes.
We are way, way over our skis right now in terms of how fast we're building data centers versus how much power we have. Um, so that's gonna be a real challenge. But the other side of this is some of this efficiency can come from the design.
Some of this efficiency comes from the material. Some of this comes from the way we interconnect and network systems to optimize. Um, and that's been a big advantage here in the US of why we have AI leadership that we do, is we don't necessarily get more total compute.
We can just do it more efficiently. And that's a big part of, of what's going on. So let's, let's just dive a little deeper into that though, because I'm hearing, and hopefully you're all hearing from me as well, my opinion as well as Tristan's here.
So clearly a big topic, hyperscalers chip designers, but where do you, where does a company like yours play a role in sort of delivering efficiency? Yeah, absolutely. So we would agree with everything that you've said, and I think you'll hear from many leaders in the industry right now saying that AI is not an evolution in computing, but it's really a revolution in computing.
And that new era of computing requires new software, it requires new data center architectures, it requires new chip architectures. And then from where we sit from a manufacturing perspective, it requires new ways to make those chips. So at apply materials, we're really focusing on five key areas.
And the first one of those is how do we accelerate the leading edge logic roadmap? So really how do we create those better transistors, those better interconnects, the better wiring to advance, uh, leading edge logic. Uh, the second area is how do we enable the next generation of compute memory?
Uh, so, so DRAM and DRAM is really undergoing some very big device architecture inflections at the moment, and they will play out over the next five or 10 years. Uh, the third big theme for us is advanced packaging, both for dye stacking. So for example, where your, you have high performance dram chap chips and you're stacking them on top of each other to make high bandwidth memory and then also heterogeneous integration where you're putting multiple chips together using very, very sophisticated packaging techniques.
So they act as one integrated system. The fourth area we are focused on is next generation power devices. And those power devices are gonna use compound semiconductors, so gallium nitride or silicon, silicon carbide.
And the potential there is that they can provide significant energy savings in the data center's power systems. And then fifth, which is a little bit further out, uh, is silicon photonics. So si silicon photonics is all about using light to move data from chip to chip rather than traditional copper wiring.
And what we would say is, in each of those areas, there are very significant innovations underway. There's a wealth of possibilities on the roadmap. So we are very optimistic about what can be done at that foundational chip level.
And, and those are many things, and I'll skip the editorial as I bounce into the next question because I I've got a bunch. I was thinking about everything you just said with materials with light, like these things are happening and they're happening very quickly. Um, and, and, and they're, they're essential.
So companies like yours, doing what you do is going to be essential because I think we, we've shown that we can keep pushing the limits on compute and you know, there's been sort of these pronouncements about the death of Moore's law. Um, I think different companies argue this in different ways, but we're seeing a and just AI data center architecture, we're seeing a year to year cadence from multiple companies now that in that tend to include exponential magnet orders of magnitude, more computing at greater efficiencies. But we're also seeing software and use cases develop that are going to use all that computing and more concurrently.
So it's gonna put a lot of pressure on the system. So, you know, we hear about the death of Moore law, Moore's law. We, uh, now see trillion transistor, uh, GPU systems in a single package.
Um, how do you see the chip making roadmap evolving, uh, in the coming years from your lens? Well, I, I found that it's very unpopular to say that Moore's law is dead. And that's really because it depends on how you define Moore's law.
Agree. Uh, but I do think it's safe to say that the benefits of traditional 2D scaling, which is all about packing more transistors or bit cells into the same area on the chip, those benefits are slowing down or have stopped for many types of chip. When that 2D Moores, uh, 2D scaling Moores law was working well, you would shrink the feature sizes on the chip and then you would make all kinds of adjustments to the materials to make them work at those smaller dimensions.
And the outcome of that would be a simultaneous improvement in performance power, an area cost of the chip, which is often called Ppac or PPAC in the industry. So today, even though that 2D scaling still has an important role to play, much more of the ppac is coming from different types of innovation. And that might be the architecture of the chips themselves.
It might be three dimensional devices and structures in the chips. So things like new transistors and interconnects. It might be new materials like compound semiconductors, or it might be things like advanced packaging.
So if we just took the transistor as an example, transistors have moved from being a planer two dimensional device 20 years ago to fin fat and now to gate all around. And that first generation of gait all around transistors gives us about a 25 to 30% improvement in energy efficiency over fin fat. But those devices are a lot more complicated, complex to make, and they actually require atomic level precision in the material science.
So in the channel of those transistors, there's actually five different materials, and each layer of material is only one to two nanometers thick. And then end to end that process flow to make the ga all around transistors, there's actually 10 to 15% more process steps. So more complexity compared to that prior generation FinTech.
But I think a simple way to think about it is as both the devices and the packages are getting much more three dimensional as that happens, materials in innovation is playing a much bigger role. I love that you pointed that out. I think one of the key takeaways for everyone out there is we are still getting really significant scaling, but the way we scale is different.
So when you thought about Moore's law, it was very centric, like you said, to a certain idea and two dimensional. A lot of what we're hearing now is about package, you know, two and a half D, 3D, um, you know, how we're basically putting more and more into not just the, the, you know, into, into the system to create more computing power, but doing it differently. I mean, you talked about light earlier, you know, things like co packaged optic optics are really changing.
Um, you know, the future of design and how systems are able to communicate, network, these are just a few of the examples, but where does innovation come from? So innovation used to come from one place, now it's kind of coming from many, some of it is materials by the way, which is what, you know, you're very focused on. So let's kind of bring this all home, you know?
'cause I think what I was trying to summate, maybe not as eloquently as you, but was the traditional version of Moore's law may not in fact exist. And you may be very unpopular for even suggesting that. But I think again, it, that comes down to the definition, but it sounds like there's a lot of reasons to be optimistic.
Uh, the industry as a whole is driving incredible innovation, which includes this AI era, which is almost a brand new computing architecture ground up. Um, so chips are getting more complex. This means more r and d, this means more collaboration in the semis, silicon and, and systems ecosystem.
Um, this means risk because companies like yours has to make big bets and big investments to get to new products, new materials, new uh, designs. Um, so talk a little bit about that. How do you sort of make sure we keep pushing the envelope, but make it worthwhile for companies like Applied Materials to take this risk to support these next generation of designs?
And what do you see in terms of the role of r and d in all of this? So your role r and d's role, and how do we keep the innovation going? Tristan?
Yeah, AB absolutely. So as we talked about earlier, the technologies that are being used in these early phases of AI deployment, they're gonna change quite significantly in the coming years. And maybe another way to frame that, another way to say that is much of the technology that we need to deploy AI at scale either hasn't been invented yet, or if it does exist in an r and d lab somewhere, it hasn't been fully commercialized.
And then of course, in many cases there are multiple competing technologies, and it's not entirely clear which of those, uh, is gonna win out. So I think all of that means that we're really in a race to bring these new technologies to market. And whether you are a company or at a national level, those companies or countries that can get there first, they're gonna have a significant competitive advantage.
So at Applied, we're spending a lot of our time thinking about what we can do to speed up, how can we accelerate those technology roadmaps essentially for our customers. And we believe there's a number of things that can be done to change the way that the ecosystem is working together. So if you look at how this works, traditionally, if you look at how a new breakthrough in a material, immaterial science makes its journey all the way through to a commercial chip, it's actually quite a serial process.
And there are several, you can call them clunky handoffs along the way. That process usually starts in a skunk work type environment. So that might be a, a university lab environment.
Then you have to develop a commercially viable process technology and the equipment set to support that process. That's really the core of what companies like Apply materials, uh, does. Uh, then you need to integrate those new technologies into the device itself.
So that entire process can take 10 to 15 years. So one of the things that we can do is we can start to make that journey more parallel and less serial. So as we start to think about speed, and I think really we should say velocity because direction is important, one of the things that we can do is we can work on collaboration, tighter collaboration, and we think there's an opportunity to work differently, not just with the immediate upstream and downstream partners, but across the stack.
So for example, if the companies at the top of the stack understand the art of the possible in the material science roadmap, they can actually help steer and optimize that roadmap and also those investments. And then finally, I think this is true for everyone in the industry. We all want to maximize the impact of the r and d dollars that we're spending.
So for a company like Applied where we have to invest in our r and d platform, which is our labs and the equipment sets, and then we also invest in r and d programs, and it's really only those r and d programs that generate innovations and products and revenue. The platform itself is important, but it's really a necessary evil and it's a very expensive, necessary evil. So one of the other things that we can do is share platforms with others, and that means that across the ecosystem, we can start to make our assets work harder and free up more investments so we can spend more on the r and d itself.
And Tristan, what do you think the industry can do? You talked about that collaboration. What could the industry do to accelerate the pipeline of r and d to commercialization?
Because 10 to 15 years, as you suggested, that may not be fast enough. Yes. So Daniel, we can definitely talk about the theory of industry working together more effectively and efficiently, but actually applied is making some real investments to make this a reality.
Um, our vision is what our CEO calls high velocity co-innovation. So in other words, getting more speed through better collaboration. And to do that, we've been building our Epic platform, and EPIC stands for equipment and Process Innovation and Commercialization.
And Epic really is designed to be an open platform that brings together our customers, our r and d partners, our suppliers, other companies that bring complementary capabilities and technologies. And using Epic, we can run either bilateral or multi-party r and d. And really the goal here is to give us faster cycles of learning and then ultimately higher mutual success rates.
So the centerpiece of this platform is the Epic Center. So this is a new facility that we're building here in Silicon Valley. It's a $5 billion investment for applied materials, and it's gonna provide us with three acres of state-of-the-art, clean room space that we'll share with our partners.
And interestingly, the building itself has several innovations in both design and construction to support the way that we want to work in the future. And in, in r and d, uh, we're about two thirds of the way through that project. The center is on track to come online in the spring of 2026.
And we're just very excited about the work that we're gonna be able to do with our partners and our customers, uh, at Epic. And Daniel, as you can probably tell, uh, we're very excited in general about the future. You know, we truly believe technologies like AI and automation have this huge potential to have a positive impact on the world.
And today we're really just only scratching the surface of what's possible. Yeah, and, and a thing I'd like to point out, and this is definitely my opinion and certainly not proclaiming it to be yours, Tristan, or that I've applied, but is, there's a reason I'm such an advocate of, of, of research and the r part of r and d. Um, it's a very long slog.
And the companies that do it take on a ton of risk. And this is also why I tend to be pretty bullish on anything that's IP protection. Now, there's a certain amount where we want to, you know, diffuse and not use it to take advantage in the market, uh, or create great asymmetry or make things not accessible.
But at the same time, we have to give companies like yours the ability to breathe and, and feel comfortable that their investments will be protected and they'll have a chance to profit on the risk they take. Because when you take such a big risk, you should, same thing we see in pharma and other areas, risks and opportunities should be in parallel. That's what keeps, you know, you talk about Silicon Valley, you talk about that's what keeps this engine of innovation ecosystem going.
And that's what's made this such an exciting time for AI is that there are people and enterprises and entities taking big risks, doing really important work. Research is a big part of it. Um, great.
Tristan to have a chance to talk to you here at the six five Summit. Hopefully everybody out there learned a little bit more about Applied materials, about what's going on in material sciences and how it really is feeding this exciting time of AI developing more energy efficient silicon and chip designs, and then of course, powering the future, uh, across our industry. Tristan, let's do it again soon.
I, I have a feeling there's gonna be more to talk about. Thanks so much, Daniel. It's been a, a pleasure and thanks so much for inviting us to participate.
Absolutely. And thank you everybody for joining us here in this semiconductor spotlight session here at the six five Summit. com slash summit.
More content coverage and summit coming up next. Hey, everyone, you ready to get your vibe on? You're watching Textron Gang.
Hi everyone. Happy Wednesdays Tale Shimmel for Textron Gang. Welcome to join us right here on Hump Day.
Kinda hard to believe Wednesday, I blinked. It was Monday. Um, we've got a great show too.
We got some interesting things going on. Not all ai, but some ai uh, we've, and we've got some really interesting people to talk about 'em with. They're all regulars here on the gang.
Let me quickly introduce you to them. We have, uh, Mitch Ashley, Chris Blak, Kate Scar, Dan o' Dan O'Brien, and of course the dean, Mike Ard coming at you from Lake Placid. I don't know if he's going off the ski jump like Eddie the Eagle or what, but whatever.
Welcome, welcome gang members. Thanks for being here. You know, we're gonna start off today.
We're gonna come back to the vibe, but we're gonna start off with Arm, Mike. You know, to me Arm is one of the great success, untold great success stories in tech over the last 10 years. Why don't you start us off there.
Yeah. The, their CEO came out and just kind of made a comment to the fact that they now have 70,000 customers for our arm chips. And we all talk about GPUs all day long.
But most of the workloads I know are running on traditional CPUs still. And, um, we talk about Intel and uh, a MD, but looks to me, you know, I think it was last year when AWS told me, I think half of their new workloads are running on their ARM-based chips. So Dan is Arm kind of like rapidly emerging is, I don't know, the number two, three player in CHIPS or where, why don't we talk more about arm?
Yeah, listen, I, I I think the ARM story has been incredible. You know, if I had to pinpoint why we don't talk about arm, uh, it's, 'cause generally I think we're talking about their customers. I mean, they are really the key enabler of a lot of silicon innovation in the industry over the past decade or so.
Um, you know, it comes from really more of an embedded background, really, the primary player in mobile enabled by their customers like Apple, Qualcomm, media Tech, uh, Samsung, Huawei, uh, but more recently, you know, really making a, a significant move in the data center space. And that's really where the action is. As we know, um, AI silicon, uh, is all the rage.
And, you know, pretty much every competitor that we talk about to Nvidia is really being enabled by arm. I mean, you know, Intel and a MD would be kind of the exceptions there. And, uh, I think we all know kind of Intel's woes a MD getting more competitive.
I think their rack scale solution coming next year will, you know, continue to give them some momentum on the GPU side. But really all of these ai, asics, uh, are are really driven by arm. We think about, you know, Google's TPU, um, arm ip, you know, with some Broadcom, uh, design help behind it.
Um, everything Marvell is doing, uh, really everything the hyperscalers are doing through vertical integration enabled by Arm. You see, you know, graviton and, you know, Inia and Cranium at the AWS, um, you see the Maya Silicon that Microsoft's working on. You know, really ARM is the enabler of that alternative to Nvidia ecosystem.
And you know, a lot of it coming from really their history as somebody who's been able to really drive a lot of performance at a lot lower power, you know, envelope, obviously power consumption is becoming a really key bottleneck in ai. Um, but you know, they've also invested a lot on the software side. I think we continue to see that, you know, software is the great enabler of hardware.
You know, in order for a new chip architecture to latch, you really need to invest heavily on the software side. And I think Arm's done that. So, uh, definitely a hot name.
Somebody we should probably be talking more about. Um, and again, you know, to the degree we talk about them less, it's because they really give a lot of the shine to their customers. It, it, it's almost not as much customers as truly channel partners, right?
Because I think that's the key to, um, their distribution. How many times have we sat on here and said, who's going to compete with Nvidia? My God, this is a runaway train.
No one can compete with Nvidia. And I'm not saying anyone can at a $4 trillion valuation, but when you look at arm's distribution, and that's Dan, to your point, you just nailed it. It's, it's, we don't hear about arm.
It's because most of their channel partners that go to market partners or companies we're hearing about now adding them all up. I still don't know if they come close to NVIDIA's, you know, uh, market share or penetration there. But remember NVIDIA is pretty much, I mean, it was a gaming chip now, of course, but the, you know, the real bread and butter here is the AI chip.
I think ARM has a, a much broader footprint of technology, you know, in terms of chips. It's not, you mentioned it's the mobile chip, it's now the data center chip, it's the laptop chip, right? It, I mean, it's an enviable powerhouse That significant inroads with PCs, right?
Enabled by Apple and Qualcomm where they take some share. Sure. Um, and starting to get into the market themselves.
I mean, I, I think we see, you know, ARM launching its own chip sometime later this year. You know, it's been widely reported. Meta is a kind of key customer for them on that side.
Um, but really much more playing on the CPU side, you know, than the GPU side at this point in time in the data center. But, you know, companies come out and said, targeting 50% share of data center by the end of this year. So, you know, clearly making some significant inroads.
And I think a lot of that's been enabled by the, you know, internal silicon efforts of the hyperscalers, uh, the past several years. I think notably Google and, and, and AWS, um, quite far ahead on that front in terms of using Arm Yeah, arm's kind of one of those 20 year overnight successes, right? They've been at this for a long time.
Um, but to your point, Dan, it, it's, we talk about 'em when we talk about, um, Qualcomm and Apple M chips and all of the different, the, the licensing that they've done with their architecture, which has been frankly a brilliant strategy. It's the alternative to Intel where here's the architecture. You can build your own chips using that, you know, licensing that technology.
And you mentioned this too, and I want to emphasize it. 'cause I noticed about three, four years ago when you were talking to ARM people, they were emphasizing how do we get compatibility for ARM into open source projects? How do we get compatibility for ARM into data centers?
How do we get compatibility? So they've made a real effort to kind of, you know, go at the go at the, the low end of, let's get into the infrastructure, let's get into this software stack to make sure we're already there so people can compile and run on ARM just as well as they can, you know, in Intel or in some cases Nvidia. So Mitch, you know, we've talked about the concept of application modernization on this show, and it's always usually in the context of mainframes to something that's X 86.
And as I scratch my head and I think about all this, I'm like, am I gonna see app modernization where we're gonna take legacy workloads and move them from X 86 to arm because there are benefits to be had and how hard or how big a lift might that be? Absolutely. And that goes to the whole, you know, underlying software substrate.
If your open source stack that you're using all the different element of projects, for example, or support, support arm already, you can recompile your applications. Maybe you do some design to optimize for mobile kind of apps if that's what you're doing. Um, but it's a much smaller lift to do that today, by the way.
You know, we, we talk about modernization of mainframe applications. Well, how old is Netflix's infrastructure, right? That's been built over many, many years.
There's a lot of legacy stuff they have. We think of Netflix and AWS and, uh, and Lyft and, uh, different companies that we work with today, as, you know, new and innovative. But they've got software stacks that have been present and built up over many years.
So everybody has got this modernization challenge to some degree where they need to keep up their software infrastructure in their stack moving forward. Well, and, and you know, this is all happening in a macro environment where, to be clear, none of us have any idea where the hell AI is going, right? And suddenly in the last couple of years, we've all gone, oh, graphic processors are really good at vector math, which is what we need to run the, you know, the LOM holographic spaces and so forth, and it goes through the roof at the same time.
The use of those chip sets in that technology and that whole stack is using more power than, you know, God's own little bunny is to make popcorn. Right? And it's becoming more evident that, that there's other ways to do it.
You know, there's tasks that inference engines are fantastic for, but asking them to add 42 plus three is not really one of them. And so in this, at the chip level, everyone is focusing on GPUs, but the architecture level, and I have no idea whether this is part of it, but this is the way I think about it. We've all forgotten other chips exist, other processors do things way better things quite often, as long as you're not trying to, you know, you know, fold a molecule And, and with a lower energy consumption, which is as we go forward, as a person who has dealt extensively with energy, I can tell you that, um, from a ICE have seen them on the arm architecture through IOT devices and I IOT devices, and that footprint is massive.
So I think on for the win, Well, the trend in the market towards heterogeneous compute, right? Really design, uh, silicon for, you know, for the specific workloads, um, that's been kind of the mega trend over the last several years. That more workloads that are finding the way that Silicon, that's kind of purpose built.
Um, and Arm's really been the great enabler of that, right? So I think, you know, that that trend continues and, you know, to Chris's point on a lot of the stuff we're playing with in ai, we may have a fundamentally wrong architecture for where it's gonna land in the long term. And, you know, arm seems really well positioned to benefit from some of that rationalization and that balancing of, you know, kind of price performance that needs to happen across the market.
They've got the licensing model down for sure, Dan. Well, Dan and Dan, Dan, I love where the, where that goes as well. 'cause uh, that takes us sort of a step further than what I was thinking, but yeah, I'll say it.
You know, we think that 90 to 99% power reduction to see the, uh, achieve the same task can be done, right? You know, it's just because you look case by case, it's sort of ridiculous. Um, but the, you know, as you take a step further, because of the adaptability that we have these days with, with these sort of tools and structures, um, yeah.
Not just GPUs or X 86 or, you know, why not, you know, remember E OMS and programmable chip and so forth, it was really big back in the day and customized hardware for workloads. Yeah, I think you're exactly right. So if they're down on that track, I'm with them.
Let me, let me come back to the best kept secret in tech kind of thing on Arm here. If we weren't in this Nvidia irrational exuberance, if you, if I may call it that at some level, what a story arm would be because they would be competing with just a MD and Intel and, and quite frankly, they're kicking butt. Well, AMD's a channel partner, right?
At some level, but they'd be kicking butt. I mean, when you look at what Apple has done with their chips, with the Apple silicon compared to the Intel, you know, based on this architecture, it really is. I mean, it's a phenomenal, phenomenal story and they've been able to do it.
Now, Dan, I know you used to cover Arm back in the day. I'm not gonna say you, I'm not gonna say you're Old. Yeah.
They were a public company, but poor software bought them, uh, uh, covered them as an equity. Yeah. And they, hey, they're riding the Nvidia train too, right?
They're, they, you know, they're on the CPU side and their CPUs are right alongside NVIDIA's, GPUs. I mean, let's not forget Nvidia did try to buy arm, uh, which maybe was the validation we all should have picked up on at the time, um, as to their potential. Obviously that didn't get through, uh, you know, antitrust, but, uh, you know, NVIDIA's, grace CPUs are all based on arm, arm, uh, architecture as well.
So, um, certainly they would be picking up more if Nvidia weren't doing what they were doing, but, you know, they're, they're benefiting from that trend as well. Trend, yeah. Their Tegra chip is based on Arm several things.
Yeah. Anybody be, anybody besides me kind of have a perception that maybe these arm chips are just fundamentally more secure, the next 86 chips? Is that a benefit of this as well?
I don't know. I, I always think of, I met, uh, a person who is 5, 6, 6, 7 years ago, and he just left Intel as there's, you know, uh, uh, not firmware, but the, the actual chip security person. He just gotta the point he had to say, you, we can't tell anymore, right?
So maybe, you know, security, the chip level can be, you know, optimized. But again, we're, we're levels of complexity. And I'm thinking out loud here, recursing these same tools back on that maybe we can raise, uh, chip level security, but frankly, I never count on that sort of thing.
It's beyond the can you, you need to secure everything at a layer you can see. And the other thing, you know, Mike, that sounds very much like the old, old Apple's much more secure than Windows kind of argument, right? Look, when you have a certain amount of of market share, you get that bullseye, right?
And I, and, and this might be an interesting thing to see how it plays out. Arm keeps making a lot of noise about how much market share they're getting. They become more of a target for the security people.
I, I, I don't believe that any of these architectures are necessarily inherently more secure than others, right? I I think that's fair, Alan. But I also think, you know, we can probably chart arms rise, you know, alongside kind of Intel's, you know, fall back to the back, right?
I mean, I think, you know, the reality is is we're probably in year 10 to 15 of a three to four decade transition away from X 86 as the dominant architecture. Um, arm obvious arm obviously was there on the, the embedded side, but really kind of took the momentum from Intel and Mobile. Um, we've chipped away at Intel a little bit on the PC side with what Apple and, you know, Qualcomm and the AI PC have done.
And, you know, X 86 is the dominant architecture and data center for, you know, kind of all of history up until probably the last five to 10 years, uh, with re you know, really the momentum coming in the last five, um, and seemingly going forward. So, um, you know, that, that, that's probably the bigger trend here is, you know, we've kind of moved from an Intel world to an armed world. I mean, when they write the history books on this, I mean, in Intel's miss on mobile in general, I is probably, I, I'm not gonna say it's fatal, but it was fateful in terms of allowing a lot of, uh, a lot of people to come in and, and, and compete there.
Um, but look, hey, I got, I got, I got 10 bucks that says that there's gonna be an AI agent for converting X 86 workloads to arm before the end of the year. So it might not be two decades, Dan, If there isn't already, if there isn't already. Pretty compelling stories there on AWS with customers making that exact transition.
Hey, speaking of AWS, they're kind of groovy getting their vibe on. We're gonna talk about that next. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey folks, we're back. And as Alan said, AWS is previewing an IDE called kiro. And it does a couple of things, but at its core it's talking about vibe coding for the enterprise.
And the two pieces of it are hooks that are essentially links to backend services that are probably AI agents that will automate a series of tasks for you. You can program those yourselves. And then there's a thing called specs, which are the actual steps for building the application and more of the vibe coding, but it's kind of like guardrails built in so that you can't go wrong and all you have to do is kind of like, describe what you wanna have happen and the ID will magically make this happen.
Mitch, we've talked about vibe coding before and we've kind of been a little bit dismissive it as an enterprise tool, but I don't know, is something happening here? Well, the big thing that's happening first Kiro is ides CLI are cool now, right? Everybody's coming out one or they're acquiring one or doing something around that because that's the environment that software is created in.
That's where developers spend most of their time. It's kind of the kitchen of software development. And what, what's interesting is a KIRO announced by AWS is actually based on the open source of Microsoft's Visual Studio Code vs code, which has got 73 to 75% market share among developers.
It is widely used, you know, even app people that like Apple still develop on BS code. So they've taken that open source and what they've done is not just added another I can generate code with whatever LLM model that you like to use. They've stepped back and said, well, yeah, we can do that, but let's really talk about what the developer's work is.
So they've, they've emphasized what they call secure specs was the upfront developing stories, turning those into requirements, turning that into design that whole flow before you really start writing code and laying out those plans and then, uh, proving that with the, with the developer and then going to the coding phase and moving beyond. And of course, what you talked about hooking into AI along the way to build and also to to operate your code. So I think it's more of a holistic approach to ides than just a nice editor sitting, uh, alongside of a, a great natural interface to kind of guide your, your whatever you're asking the agent or the AI to do, LLMs to do on the backend.
And I think we're gonna see a lot more of this. There was an announcement actually just the other day by Perforce who came out with Perfecto ai, which is a testing tool that instead of just generating tests, it actually monitors the requirements, the, uh, PDFs or the, the, uh, PRDs that you put together for a product. Whatever you use to guide, guide your requirements or stories from Agile and actually generates tests from that.
And analyzing code is code changes. So it's dynamically creating tests, not just here create a bunch of tests for my code today. It's looking more holistically at the development process.
That's the key trend to really get the productivity out of AI for software development. Very good. Mitch.
You know, I gotta tell you, people say Shimmy, you have fun doing what you do. This, this whole vibe thing is exactly the kind of stuff why I enjoy doing what we do here, right? Lemme just give a quick history of vibe coding on Text Drunk Gang.
I don't think it was more than three, four months ago. It was the first time vibe, maybe six months ago. We mentioned Vibe coding and Chris, I don't know if it was you or one of the other security experts said, nonsense, this stuff will never work.
It's, it's buggy, it's terrible. It's it's crappy code. It's low quality, it's a toy about a month later, you know, vibe coating's, a nice little kind of hobby to do for a little home project.
You know, it's not terrible. A month later after that, you know, a lot of people are vibe coding, there's some interesting stuff. It'll never work in the enterprise mind you, but you know, for little stuff it's not so bad.
Here we are, mark the date July 15th, AWS comes out with an IDE for vibe coding for the enterprise. Is this, is this the world we live in? Is it, are we in of like a, a time zone?
Chris, what do you, what do you say? Well, I, that doesn't sound like something I would say, but if I did, I'll own that one. And, and it's wrong.
You know, I'm listening to Mitch, you know, uh, I'll go through all that. And that sounds exactly right to me. And you know how the concerns I have for how, you know, AI is, is applied these days, that sounds like a logical structure.
Now I, I'd love to spend more time and pick it apart and see exactly how they're doing something LLLM stuff, but it's, it's is, yeah. So that, you know, what I'm finding as, as folks who were spending a lot of time around me the last couple months, uh, are finding out that, I'll use the word semantic an awful lot because AI doesn't describe at all, but we're talking about here. I mean, any more than 700 other things, but they're semantic systems, and these are exactly the kind of of use cases where you can understand that there's, there's someone over here who has some characteristics and they're relating to something over here and building code.
Mitch, as you're walking through that, I'm thinking through the steps and how that would be used. And, and again, I would bet that if I stared at it really hard, I would have a lot of criticisms, but it's in the right place, right? You know, I haven't done a lot of coding and you know, I have used every language ever, but I try to avoid it in the last three months because I have these semantic partners.
I write or copy and paste and occasionally edit piles and piles and piles of code. So everything I hear about vibe matches my thoughts. You know, it's not about the exact, can I put the commas in the right place?
Is do I know why I am doing what I'm doing? And that's the semantic screen kind of thing that, that what we, you know, erroneously call AI is literally fantastically built for. Yeah, the term was actually coined in February, Alan, and it was an expost by, um, Andre Cari, who was a co-founder of OpenAI.
I think he was Tesla before that. Um, and it was his, it is kind of a nice little definition, essentially it's, it's, you know, when you're vibing, you're like in the zone, right? And this is about being in the zone of creating software using ai.
So you're leaning into ai, not writing code traditionally, and kind of augmenting with, with, you know, some things that AI can do for you. It's like, let's maximize what you can do with AI and see what's possible. And that's what caught on about it is it started to describe what developers and platform engineers and testers are starting to experience as they really lean into AI for their work is there's prompting and then there's really vibing where you're really using AI in some of the capacities.
So I, I, I, in Ways Haven thought, so two, I see two use patterns around this vibe coding that I, you know, just from my observations and my friends, there's the, the Chris Blas of the world who I wouldn't necessarily consider a coder, a professional coder who are vibing, right? They're vibing and, and then there's real, there's real software developers, right? Real professional coders.
They're also vibing, but I think they're vibing as, to be fair, and Chris, no disrespect to you, but they're vibing at another level, Right? Right. As they should.
Well, It's an accelerant no matter where you're on the curve. Yeah. Right?
Whether you're, you know, kind of more of a beginner who knows enough to be dangerous or a true expert, it's shifting you up the curve in terms of what you're able to produce, right? I mean, that to me is the big observation here is like writing code and software development, software engineering. It might be the ultimate AI use case.
Well, that, that's what you would think from all the, the, the, the press and, you know, air time it gets, it, it certainly is, you know, and, and Well, but I think the people were also like, that's, that's flowing through, right? I mean, you've heard about like a 50% decrease in the number of DevOps people in AWS as they're rolling this stuff out, right? You've seen, uh, you know, some of the layoffs across the tech industry.
Uh, I do think that we are getting that productivity because of this. And I think, you know, it's real enough that it's actually being reflected. Google paid, what was it?
Was it three and a half billion or two and a half? No, excuse me. 4 to license the windsurf.
We just spoke about this yesterday. 4 billion to license the windsurf, uh, uh, software. And they hired the CEO, like the, the brains of the operation supposedly.
And they were in pretty good shape before that. Yeah, right? I mean, that was Gemini.
They, they clearly wanted to make Gemini a better AI coder. But let me give you the other shoot that dropped on this, some other AI company. They haven't released the amount they paid for it, but they bought Windsurf yesterday, right?
I, and I, I, forgive me, I don't remember the name of this other AI company. Everybody's got a piece of windsurf. Like if you didn't buy Windsurf in the last week, You've missed out.
Exactly. So, but we spoke It's cognition. Alan is Cognition the bottom right.
You know, so we spoke about yesterday, well what, boy, they left windsurf for dead. They're picking the bones. Someone, someone found those bones pretty tasty and Winds surf's pretty smart.
Some smart people. I have a couple of questions for Mitch. So, does vibe coding mean like no-code, low-code tools or history?
I mean, are we like moving on behind? Uh, 'cause you know, it seems like this is the same use case that we used to use for low-code, no-code. Yeah, I think, I think AI is the new low-code no-code.
And it's interesting talking to people that have low-code, no-code tools today is they're in this bifurcated world of bringing in AI to start to do more of the work with citizens developers, but they also don't want to immediately, uh, cannibalize their current customer base, have got things they've already built in the current tools. So I think that transition is happening, but I, I want to go back to what Dan said. I, I took the position about three months ago in one of our papers that the place to watch of what AI is doing is in the developer world.
And because not just 'cause I like development and like developers and all that stuff, is, that's the tip of the spear. That's where, that's the landing dock on the shores to, uh, you know, to come into the country and go through immigration and be part of the development process. Developers love to innovate.
They love to try new things. Not every one of them, but it's a very innovative crowd, very indi independent crowd. And they will find use for it, and they'll find use cases you don't even anticipate.
And if you follow what's happening in development and how that's changing, not only coding, but the overall work of the coders. I mean, I talk to very expensive experienced developers to tell me I'm more tired than ever when I go home today because I'm thinking about this stuff at a much different level. It's just not like, I need to convert this from JavaScript to this.
It's, I'm working up here and they're getting so much more done. So it, it is informing, I think, the rest of the market, at least in the software world, of what testing can look like, of what platform engineering can look like, what ops can look like. And I think the vendors who are smart will look at their own development teams as well as other development organizations as leading indicators of what AI is changing and how we create software.
I think you're so smart. We call the tip of the spear, Mitch. I mean, it's the people building AI that are applying it to their own work, you know, their own kind of workload.
Um, it, it, it really is kind of where all the experimentation and the leading edge is happening. Um, the kind of the ultimate client zero story. And now that's why I think it's so interesting to watch the companies that are building AI, because I think they're gonna resemble what all companies look like longer term.
I think, you know, the things you see happening and the changes, you know, in terms of workforce composition that you see in the companies that are really leading on the curve of building ai, uh, that's kind of where everybody else is gonna end up eventually, in my opinion. All right, here's my, here's here's my prediction, right? So we started out from concept in February and we're now at Enterprise in July.
All this stuff is a commodity by September. Nothing to see here. And and I think along with that, Mike, it totally equalizes people who are non coders to the people who are big DevOps quotes.
Well, that, that's that whole citizen developer thing. Chris, go ahead. I'm sorry buddy.
No, that's okay. I gave, so I'll give you an example of, of vibe donating, right? You know, in the last couple months, you know, I have written hundreds and hundreds and hundreds and hundreds of, uh, shell scripts and Python scripts and so forth, because I said I want to build a metabolic system.
That's it. And step by step, you know, my, my AI partner who knows other stuff, works, presents options, you know, raise the code, I put it in it, run it, it works, doesn't work every single step that I know how to do myself faster. And I don't have the attention and span, you know, I've hacked everyone's code.
I've written some myself, but as you say, I'm not a coder. Right? That's a long, tedious job.
Now I can surf in, because to your point, Kate, I know what I want. I know how it's done. I don't wanna do the work.
I don't have to. I just, I guess to the term of this segment, I just know the vibe. I know what I want.
And now I have a, a complex, you know, we quiet wire, have a complex, uh, system, you know, mesh that is based on, you know, existing technologies that is, uh, supporting semantic processes in a, in a, in a auto autonomous, you know, human machine, a to a, you know, fashion in two months. I love it. I wanna close this segment out with this, though, no doubt that the, the, the lens has been focused, or the, in, in terms of the AI mar ai market on how AI is taking over coding or has the potential to, to really ruled coding and software engineering.
But as humans, as humans, and we're all humans, I think here list someone's a deep fake, um, what it's doing in software coding, it will do in other verticals, whether it's medicine or lore or manufacturing or what have you. That's why we spend so much time talking about ai. It's not just that we're geeks and this is the world we live it.
This is, this is happening. This is going to, this is going to, you know, send ripples and waves and tsunamis across every piece of it. And, and it, we can't, you can't lose sight of that when we talk.
You know, I, I've already spoken to some on my wife's family, to tell you the truth. They're not tech people. And they're like, ah, yeah, this ai, it's a tech thing.
You know, they, they don't see it coming, you know, as Bobby Bala said to, uh, Tony Soprano, do you think you even hear it when it comes? You should be hearing it right now. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey, folks, we're back, and we're gonna shift gears a little bit.
We're talking about some ai, but we're talking about cybersecurity and impersonation of government officials using deep fakes. And the latest victim, apparently is Marco Rubio. But this has been going on for a little while now.
So, Chris, are we on the cusp of, I don't know, outright anarchy? I mean, who's in charge? And nobody knows.
I am shocked, shocked to find gambling going on here. Um, yeah, with this in 1990 at General Electric in South Carolina, we, you know, I was there. We put a video conference centers, we had a demo tape.
It was the world's leading graphics, uh, animation, and it had like, real fluid, fluid mo uh, T-Rex running around with silver skin. But, you know, moving realistically was amazing. And sitting there in 1990, and I look, you know, talking to my, my colleague saying, at some point, we're gonna make it so you cannot tell the difference can't be admissible in core.
What do we do? Right? So it's not like this hasn't been a long time coming and we're here now, like we were talking about in the break, but ai, yeah, if, if never, okay, you know, but if eventually this isn't, eventually, eventually we will have these capabilities turn, take out.
Now, what does that even mean? Well, it means we're gonna have these sort of conversations where we say, did anybody think about, how do we know who's who on the internet? Uh, we skip that part.
Um, you don't, and, and, you know, to get my favorite topic, you know, we're making all these things with ais that have no common ethical framework, and we'll do anything anybody feels like, you know, prodding them into. So, yeah, this is where we are. And I personally, along this, um, side, no, go ahead, Kate.
Uh, I think disinformation is, is tearing our nation apart. It is horrible what we see happening, and we don't have any real security mitigating controls at present. And, and, and, you know, since I, since I just acknowledged the problem, let me, you know, take a stab at, at the solution.
I think there is solutions and, and, you know, we saw this coming from miles and miles away. There are all sorts of structures out there, including attestation systems and whatnot that have, that are exercised to reasonable depths. And, and again, all my biases, uh, being acknowledged, you know, civic ai, ai that actually has a common shared referable reference boundary that attest to things, it does, you know, that, you know, like a human, you know, and again, on the AI side, just like, just like this, will we never, ever, ever get to the point where they are, quote unquote, you know, the same as us or smart as us.
And if so, you know, what do we need to do with it? If not, then forget it. If so, then we had to in advance think about how do we manage that?
And I think the answer is ethics, right? You knowis right now will do whatever, whatever. There's no tracing, there's no tracking, you know, civic ais, you know, that are following the, the can in this that we publish, you know, we, and now others are, are working on out there.
Um, they will not do things because it's unethical, and they will write it down. If you ask them, Man, I would give 10 K to be able to do a mission impossible, tear off my mask right now, and I'm someone else under here. Because here, here's the issue with this.
A let's not make AI the whipping boy for deep fakes, right? DeepFakes has been, have been going on since before AI and AI makes it easier. AI makes these deep fakes better, but deep fakes, you know, have been going on.
I I, I have a confession. When I first started getting involved in computers, the first thing I was playing with were graphics programs. And, you know, I would love switching people's heads onto other bodies and then doing stupid things.
I was young and stupid. Dom gi old, still not so smart sometimes, but, you know, deep fakes is a long time, as you say, Chris, this is, this is not new stuff. It's just easier to do.
Now, Kate, to your point, it's not just deep fakes. That's, that's tearing the fat. It's, it's the whole misinformation, fake news, conspiracy theories, everybody goes into their own echo chambers and all that stuff.
Again, let's not blame AI for that, right? Let's, AI has enough problems, right? Hybrid.
Go ahead, Mike. Just to be clear, Alan was switching heads on action figures like 50 years ago, even Before computers. Yeah, Joe, one guy had the beard, one guy did it.
But anyway, Well, you know, the, this the, the Rubio thing, isn't that remarkable to me, I think what's a more important one is it's been less than two months ago, I think it was in June when the company was Arup, I believe Hong Kong based firm, where somebody got a phishing email, and that led to a conference call with the deep fake. The fake was, I believe, wasn't it? It, was It Singapore?
Yeah. Okay. I, I think it was Hong Kong or whichever, but they transferred $25 million, I think it was, and, uh, only to figure out, oops, that was not a, that was not our CFO.
So that's one example. You think that's the only example? That's where the real kind of, yes, it's Steve fake and false information in society, and that's, that's its own set of problems.
But the money behind this and how much money will be stolen or already is being stolen because you can do this is scary. So how will I know whether or not Dan O'Brien on this call is a deep fake? Do I have to have two machine services validate who he is, plus somebody who actually knows him to verify to me that that's actually Dan, or, um, I know it's not gonna play.
I'm gonna take a page from Kate. I think where you're going with this, you know, and, and, and I think I've said this on the show, my favorite little artifacts right now is seven years ago, I told a nation of 25 million years that in seven of, uh, people that in seven years, they would have to have an answer to this question, or their lights will turn because I, people like me will tell 'em to turn off. Hey, why not?
So this is it. It is, and it isn't. This has been a long time coming, but it's woven in with everything else.
How do we verify that the person telling you to turn off the power of a major city is the person telling you, and they're authorized answer is not well, and folks like me and people with, you know, interesting motivations can get around those, you know, should they choose to. Now, again, this is an inevitably question, will it always, I tell you, amongst security people, I, I love, uh, arguing with my friends about this one. It'll never be bad.
It'll always be really like, it'll never, things never change. It's always gonna be exactly this bad. Now I think I can get a lot better.
I think it's always been sloppy. We've gotten away with it forever. We're being forced into ways to fix it, and we have the ways to fix it.
So with everything from a video to a social media post or whatnot, we'll get the visibility into provenance and so forth to the point that we can function. We have to, well, we have, we have, we have fixed similar issues with security. When you look at the whole, you know, uh, digital, uh, uh, certificates like the Digi Cert business, right?
And, and that kind of thing. And we even have post quantum algorithms for these certificates we've been, we've been able to solve, is that information real with digital certificate technology? Now, that doesn't mean that someone doesn't get a phishing mail saying, Hey, I got your updated, uh, wire information, and you say, oh my goodness, that's the wrong wire information.
Let me correct it for you. Right? That, that's human error.
And it's the same thing here with deep fakes. We could have certificates and, and digital watermarks and all of these things for our own right protection, but it's still the person behind the keyboard, especially, you know, when we talk about electronic stuff, it's the human error that we need to correct. Don't blame the technology Defenders, you know, tend to feel, you know, uh, uh, you're looking at it from the wrong side.
You gotta think about this from the attacker perspective. It's hard to imagine it being easier to successfully pull these sort of narrative attacks. Now, it's unlikely that it will stay exactly as easy.
In fact, I think small changes make the world of the, the narrative attackers much harder. I Think that people process technology. I Amen.
Absolutely. I, I think at the end of the day that, um, it can get better, but we are, as the article points out, woefully unprepared for this along. So, Yeah, I mean, we, we really are getting to the point where we all almost need a zero trust mindset when it comes to consuming any information, right?
Like, it all needs to be authenticated. It all needs to be verified. I mean, I think a lot of the problem we talk about, you know, when it comes to more of the disinformation things, where Kate was talking about earlier is, you know, the media landscape has moved from one that's been fairly highly centralized to massively distributed, right?
And, you know, we, we've gotta, you know, get back, you know, particularly when it comes to, you know, government officials and the messages that they're communicating out to the public, we've gotta have those trusted channels that they're flowing through, right? Like, you know, seeing it on an ex post or, you know, seeing it on a, a, a web, you know, a a a web video. That's probably not enough.
We, you know, we need to be able to have places we can go where, you know, we know what we consume through that channel is gonna be real and gonna be verified. Um, but yeah, no, No, well enough, right? Because the, you know, it is easy to get this, you know, feel despair when you look at increasing volumes of, you know, how am I going to process all of, and if the answer is, you'll never be able to then this either.
We'll never be able to fix it or there's something else. And I think we look back, not as far back as you think, um, at how human culture has maintained, you know, enough shared narrative to get through the day. It's small bits of a tested information that everybody can agree on.
You know, that's a rock. And we all agree that rock's been there for the last two weeks, and that's the sort of capability that we have to today and, and is beginning to happen today. But enough narrative reference points that most of the time, we'll, we'll have the same results as we do in life, which isn't perfect, but, you know, it's, it's enough.
So, Chris, I think you just said we're all gonna agree that something's an actual fact when in reality we can't even do That. Yes, we can. Yeah.
You mean you'd be surprised. You really would be surprised. You know, the sky is blue on sunny days, right?
You know, there's, there's enough things we agree on. It doesn't have to be much, it's not about out shouting, you know, think about it, you know, large numbers of people going down the street, you put one little thing on the street, the entire flow of people changing around it. It's not about convincing everybody, anything, Dan.
Yeah, I was just gonna say, uh, you know, I think we deal with deep fakes to deal with the way we deal with fakes of everything else, right? I mean, you know, look at the a hundred dollars bill. Now, how do we make sure that the hundred that we, you know, have in our wallet is real, right?
You can market with the little pen, you've got the hologram, you've got all these things, right? Uh, you know, I, I think we're just gonna need to approach digital assets the same way we, we approach fakes with physical assets, whether it be a hundred dollars bill, a concert ticket, um, you know, a high-end luxury item, like a, a high-end watch or, you know, piece of, uh, piece of, uh, you know, clothing or furniture. Um, you know, we're, we're gonna need to find ways to validate that things are what they say they are.
Glad you said that, because I, it comes down to something physical, right? Something you have, you recognize this Chris, right? Something, you know, something you have when it comes to a person, anything can be faked, right?
I can fake your social security once I have your social security number could go do bad things with it. I can fake you, uh, with your voice or with your image. But today we re we rely on, I think increasingly it's gotta be something physically that we have.
If I'm sitting on a conference call and I have a device that I'm holding that is my VI device, and verified that it's mine and electronically and can verify that that device is present during my conversation with you, or it's watermarked in my digital image, or whatever it might be, the physical part of this, to your point, Dan, the dollar bill, whether it's the strips we're inserting into it or the holographs, there is a physical component to security to be able to validate human identity and who we're, So are we gonna have to do two factor every time I do a Zoom with you, Mitch? No. Yeah, I'll disagree with you, Mitch, on this one, because it, the difference is not something you have is something you are, and other words mean biometrics, and, you know, it's like, and we're pushing time here, but yeah, that's the something you are, is you can't be taken away from you and, and you, you know where you are, Simon, the environment, right?
Yeah. So let, you're Right, let me wrap this up for us. You know, my con law teacher in law school a hundred years ago taught us something, and I, it's proven true.
Society runs three to five years behind technology, right? And this ai deep fake stuff. And by the way, I'll point that on the ticker Taylor, it's Secretary Rubio, not senator.
He's the secretary of State three. It's gonna take us three to five years to catch up with what the bad guys are able to do right now with ai, and not just bad guys, with, with whatever's going on with ai, it society, society has a lot of inertia built in. It doesn't, it doesn't slalom, you know, a ski course.
It, it takes big obtuse turns. And, and so we could rail on here all we want, but it's gonna take three. But in five years, we will come up with, whether it's biometrics or something, or it's, Chris is your point, you know, we'll come up with something, we'll mitigate it.
It's just gonna take time. This stuff is happening so quick, right? Maybe someone will come up with a vibe to, to, to fix the deep fakes.
I don't know. Anyway, gang, what a great discussion today. We live in interesting times, that's for sure.
Thank you for watching. We hope you've enjoyed today's text on gang. As usual, we have a full text on TV lineup immediately following, so stay tuned for that.
Of course, you can always check this out on, uh, text Drunk tv, on the text Drunk tv OTT app, or our Textron TV yacht, uh, YouTube channel. By the way, we now have the individual segments broken out on the YouTube channel, so you don't have to watch all three segments. If there's a particular segment you like, go check it out on YouTube.
Until then, until tomorrow, though, everyone is Alan Shimel, we're outta here. Thank you. Hey, everyone, welcome back here to Techstrong tv.
We've got another interview coming at you in this segment, I want to introduce you to Dan Candy. Dan is the CEO of a company called Cork Protection. Dan, welcome to Tech Drunk tv.
Thanks for coming on today. Thanks For having me today, Alan. Ah, it's our pleasure to have you on.
So, Dan, we're gonna talk about Cork, but before we do, let's talk Dan. Yeah. Tell us a little bit about your journey.
Yeah, you bet. Uh, perhaps just, uh, like any other college dropout, uh, a guy trying to figure out, uh, uh, how to do things in life, and, um, been fortunate enough to have some great mentorships, some interesting education, and, uh, be an insatiably curious person along the way. Um, so yeah, uh, you know, I, I had originally dropped going to college on the East coast and, and I'm a Colorado boy, but, uh, I ended up, uh, uh, deciding it was time to, uh, start a house painting company so I could save a couple bucks and start traveling the world a little bit more.
I had been living overseas and studying abroad, and, um, uh, had a lot of, learned a lot about customer satisfaction and, uh, how to manage employees through that very first, uh, that first experience in my twenties, eventually sold that, which helped me, uh, afford going back to college and finishing the degree and going back and doing some international business stuff. But I always was involved in startups and building businesses and early stage companies and, um, and technology and, you know, that's kinda the, the sweet spot for me. Uh, I eventually sold a couple of businesses as well, but, uh, got recruited Good for you to EMC, and right around the time that Doll was buying, uh, EMC.
Sure. I remember it. Yeah, the, you know, strong software background.
I got to help lead some of the VMware, uh, side of that, that, uh, experience. And that was really fun. Uh, helped grow that to just under a billion dollars, uh, in a couple of years.
And then, uh, got recruited to AWS, got to build the VMware cloud and AWS for Andy Jass and, and p Gelsinger, and, uh, did the enterprise, uh, side of things for a little over four years. And again, you know, that was during COVID and what a wild experience to help, uh, you know, the world move to cloud or hybrid cloud, whatever the world needed to do, uh, in order Digital transformation. Yeah, you nailed it.
Um, and, and when my tour of duty was up, uh, from Amazon, I couldn't wait to get back to, to, you know, small and mid-sized business and really be focused on managed service providers in it, which is where, uh, all of my early career had been and where my heart is. My parents own a restaurant. My brother's a police officer.
My sister runs nursing facilities, and so Wow. That's great. Yeah.
Talk to the earth, right, man. Yeah. This is what we do every day.
Right? Similar, similar story here. Are you still out in Colorado?
I am, yep. I've got, uh, an amazing wife, uh, of just over a decade. And then my 7-year-old son, Luca and my nine-year-old daughter.
Good for you. We live out in the country, uh, just a few minutes outside of Boulder. And then of course, you running a, running a business these days, it means a lot of time, uh, on airplanes on the road, wherever our partners and customers are and, and just being of service, right?
Because it's always these days it's about listening. Yes, we have ai, yes, we have lots of technology, but there's nothing more important than sitting down, um, and, and listening to people and asking questions and understanding how we can be of value to one another. Absolutely.
Excellent, man. I spent some time out in Boulder myself. One of the companies I co-founded was based out there.
I have a good friend, Brad Feld, who kind of really helped the whole Boulder scene happen. Of Course, Brett, Brad is a force to be reckoned with, and, uh, you Know, yeah, he still is. Yeah.
I sold my very first company to Brad about 30 years ago. Oh my gosh. And, um, worked every venture backed company I did after that were always either Mobius or Foundry, you know, they were Brad companies Yeah.
Was there when they were starting Techstars, so yeah, similar story. Yeah. His, his office is about 15 minutes west, uh, or you know, of my, my old Air Street.
Yeah. I, I have out here. Yeah.
So, well, Brad spends a lot of his time out in, he has a place out near Aspen now, or in Aspen, and actually, I haven't seen Brad in a couple years. I, I owe him a trip out there. But anyway, we'll talk about Colorado all day.
We, but we're here to talk about cork protection. How long, you know, how, when did you become CEO of Cork protection? Yeah, you bet.
Cork's legacy story, uh, is little over two and a half, about two and a half years ago, uh, maybe three years ago with Austin McCord as one of the co-founders, Austin, of course, of Datto fame. Uh, and Austin is insanely passionate about managed service providers and how, uh, you know, collectively we work to support, uh, small and medium sized business. And he saw, along with John McNeil from, uh, DVX, and John McNeil is another, uh, incredible business person, uh, and very compassionate business leader.
Uh, uh, they saw this opportunity to, uh, to really think about where cyber insurance was falling short for SMB and how MSPs in particular were trying to be of, of service in that market. And by falling short, meaning, um, not that a lot of those products were not designed for SMB, and I saw the same thing, uh, at, at AWS right, where I was, uh, although I had an s and b business, it wasn't as large as a lot of my enterprise customers, where we were doing, you know, incredibly large deals with some of the biggest, uh, banks and financial, various financial institutions and healthcare institutions and manufacturing worldwide. Um, and a lot of the cyber insurance and financial protection things were designed for the biggest, not the smallest, but medium size.
And, and, and I didn't want it when I left a WSI didn't, I didn't want to do that anymore. It's just like there's this gap. And so that's where Austin and I are very aligned in the purpose of Cork.
Cork is a cyber risk platform that, that understands exactly all the open windows and doors of where the threat actors can get in. And we do that by working with an a managed service provider's existing stack, API agent list, right? And less than an hour, less than a time it takes to order a eat a pizza, as we like to say, we're fully integrated and we can make the MSP that much smarter with all of our compliance, monitoring, compliance insights, and we can create incredible efficiency and security within the first day.
Right? But the interesting piece of all of it, and we're the only company in the world doing this, is we tie it into cyber warranty and cyber insurance. We believe that just understanding risk is okay, but what is phenomenally important in this next, in the next decade of our lives and are running businesses, is being able to write checks to have money in the bank account when things go wrong.
And that's the only way that s and b is gonna stay in business. The average s and b only has 18 days of cashflow on hand. And so that's where our cork solutions, our warranty, et cetera, puts, you know, writes checks.
So I've got an SLA within an hour, I'm handing over a $10,000 virtual credit card just, just to spend, like, wherever you need to go, just go. And within another SLA 14 days reimbursement, that's for like a CH wire transfer fraud. I've got a number of these different situations.
We real use cases we could talk about where, you know, 20, $30,000 of, uh, of money is going out the bank, uh, that shouldn't have because, And, but you know what? That, that could be fatal for SMBs, that kind of money. It is, yeah.
And that, and that's, and honestly, that's the world we're living in where enterprise is so well protected because they have the bank accounts, they have the deep bench of cybersecurity expertise, and they have incredible cyber insurance policies, and then cash in the bank to be able to deal with the short term hits. That in many ways, the threat actors are going, all right, this is pretty tough. Where is it easier?
And that's where they're looking and They always, yeah, they look for the lowest hanging fruit man. Yep. That's, that's the mo there.
And that, you know, Dan, I, I, I've been in security 25, 30 years. I have an interesting take on cyber insurance. When I first really got into InfoSec, there was only, I mean, the only company that was writing cyber was Aon.
If you, I don't know how long you remember, he goes back on this, but Aon was the only one, then it started becoming a thing. But I would say maybe five years ago, four years ago, during COVID, perhaps I saw an interesting thing happen. The cyber insurance companies became sort of the police officers, the enforcement agents of good cyber hygiene and resilience, right?
Because as you mentioned, without insurance, a lot of these companies are dead in the water, you know, without some sort of coverage. And the cyber insurance people were in a fantastic place to say, Hey, we'll give you coverage, but, you know, let's do something about managing the risk here, right? Let what you know, and so, and I am not getting political or anything, but where we didn't have the political will to have enforcement on certain compliance and best practices around cyber, the cyber insurance industry became the, the enforcers of, of best practices.
When if you think back to being a third grader, right? You're learning how to do a math equation. Your teacher says to you, show me your work.
Right? Right. And in a way, if I'm being generous to the insurance companies, they're saying to s and p and to managed service providers, show me your work, prove that everything was taken care of at the time of the incident.
That burden has been very difficult in a way, because a lot of the technology and a lot of the compliance monitoring and, and the systems haven't been set up for the proof and just needing to demonstrate the proof to insurers companies. It's been about protecting the castle, right? It's been about providing the answer to the teacher Here, I, I got the answer right, or I'm really trying to learn how to get the answer in part because the threat actors are so damn good and they're just keep getting better.
And so that's where Cork and a number of other really good companies are leveraging the same tools and better tools than some of the threat actors to actually simplify the show your work concept, which may, which means we're working hand in hand with the insurance companies to go, Hey, we're doing our part. Which means that when there is a scenario, Mr. And Mrs.
Insurance Company, you gotta pay out. Like we actually have the tooling to enforce payouts and to, for the first time ever, we've got the leverage to assist companies in making sure that insurance companies pay out. And in the meantime, I'm not gonna wait around, right?
Insurance companies typically pay four to six months after an incident. Cork said, you know, there's an opportunity in the market for, for doing good in the market, but there's also a business opportunity where, which is where the best businesses exist when there's a triple win, right? There's a win for the end user client.
It's a win for the managed service provider. There's a win for cork, which is let's do something immediately, let's be of service to one another right now within the first few minutes. And that's how we're creating a, a better environment for all of us.
And I'll tell you something, I'm not throwing stones. I wish every cyber insurance carrier had that attitude though, right? I I, I have friends, I have a friend right now who's going through this.
This company's more in the, let's call it a small medium enterprise than small medium business. But they suffered, uh, I mean, it was a phishing attempt that cost them in the, you know, high six figures and they're cyber insurance carriers trying to return it from a phishing attempt into an improper invoicing thing. And it really makes you sick.
'cause you pay your premium, you think you're protected. I see you getting sick from it. Yeah.
Look, I, I'm not an insurance company. I don't sell cyber. No.
I, I realize you Don't, you what? Mean? Like, it makes me sick too.
And, and that's where, you know, that's where data matters. So we all have to have the source of truth in our life personally and within our communities and professionally, the data matters, right? My entire framework for success is that it's been an output of love plus performance.
That performance piece is the data, right? That love piece is the integrity, it's the accountability. What else are we gonna do on top of the data?
And that's when us as humans are making intentional choices to do business with people we know we'll be there when things get tough, right? Yep. Because we all got choices on how we spend our money or spend our time, right?
Alan? Absolutely. AB and who and who you wanna spend it with, right?
And companies, you wanna do business. And I, you know, I preach this, I I say to the kids, you get to be a certain age, right? But I preach this to the people in my company, right?
You, if you're gonna go to war, you want someone you could trust in that foxhole with you. And if you don't think today's cyber climate with the bad guys using things like AI and all of these other things are, are, you're not in a war. You're kidding yourself, right?
And, and so pick your allies, pick your friends, pick your, you know, your, your war fighters with you. Yeah. I, I couldn't agree with you enough.
I'll give you a quick example, real life example if that's okay. Um, we have a great managed service provider. This one happens to be out of Canada.
Uh, they're, they're called Plexus. They've been in business for over 20 years, and they're a cork partner. They, uh, they not only use our risk insight platform, but they also provide the cork warranty to their partners.
One of the three top, uh, top sectors industries that are being hit that I'm seeing over the last 12 months is construction services. Okay? Construction services is prime, prime target for these sub $100,000 attacks, primarily a CH wire transfer fraud through business email compromise.
There's some ransomware as well, right? The reason is because of invoices and cash flow, and in these construction businesses, everybody's paying one another. You gotta pay, you know, concrete bills, you gotta pay architecture bills, you gotta pay steel bills, and on and on and on, right?
Well, in, in this case, uh, the architecture firm that service the construction client, our, our client got infiltrated, and they, and they just sat through business email compromise for about three months, and they learned who was gonna receive the invoices in the construction company. And then they sent the three emails needed to, the construction company used the real invoice for that month and said, Hey, this month is $21,000. Uh, but we did have to change banks, ironically, because there was a, uh, an in cyber incident, here's the new a CH, please send it, uh, on over.
And despite great things from our friend at, uh, our, our managed service provider, uh, including Sentinel One for endpoint protection, ninja for remote monitoring, Microsoft email, datto for business to cover discovery and like, you know, real security awareness training that had been done despite these things. Construction company just didn't pick up the phone to verify the a CH transfer, so the funds went out, right? Like, that's the world we're living in.
Where not only is the threat actor using time and research, but also the tools, right? Those smart tools in order to get around some of these things. And so if people are not thinking about cyber insurance, cyber warranty, right?
And compliance monitoring as a way to have that next layer of protection, then it's not if, but when, right? And we're all on a journey, but over the next five, 10 years, these things are gonna become more and more common. Does that, does that story make sense, Ellen?
It's like I said, Dan, we're at war. Except if you don't know you're at war, but the other side does, you're at an extreme disadvantage, right? And, and that story you just made is exactly the story I was telling you about my friend, except that was to the tune of 800 plus thousand dollars.
Oh, That's, that's end of, that's end of days for people's careers and for, for businesses. Isn't it Crazy? It's crazy.
Anyway, Dan, we're, we're in low on time. For people who want to find out more about Cork protection, what's the website? You bet.
com. Uh, we're also constantly doing, taking an education based approach. Uh, what is ours is yours.
So where we can be of service, uh, we try to be, uh, we, we have recently released something called the Cyber Insurance Analyzer, which is a free tool where people can put their cyber insurance policies in there. And we're able to provide a summary analysis of it. We, um, on the backend of our tooling, we have connections with companies like Datastream and Yukon so that people can access cyber insurance and risk, uh, risk, uh, insurance platforms such as that.
Um, and then, uh, we make sure that our team is always, uh, well educated in being able to, uh, provide answers. And if, if I can ever be of service to you or anybody in your community, please let me know. It's, it's about the love, uh, even more than the performance, honestly, in this world that we're living in.
Dan Candy, thanks for being on Text Talk tv and thanks for what you're doing, man. It's good work. Pleasure to say hello to Alan.
I hope you have a wonderful and safe afternoon. You as well. Dan Candy Cork Protection here.
com. Check him out. We're gonna take a break on Techstrong.
We'll be back in a moment. Hi everyone. Welcome back here to Techstrong tv, Alan Shimmel back in studio.
I've got a first time guest on here for me. His name is Drew George. Drew is the CEO and co-founder of a company called orus Think Orchestration, like the plural, if you will, of orchestration orus.
Drew, welcome to Text Drug tv. It's great to have you on here. Hey, thanks for having me, Alan.
Uh, nice to be here. Nice to have you. So, drew, let, before we talk about orcas and orchestration and all that good stuff, let's talk a little bit about you.
You're the CEO co-founder, and you know, I, I think everyone's always interested in what, what made this man sign up to, you know, go through co-founding and, and running his own company. It's not something we do lightly. Yeah.
And, uh, a lot of, uh, it has to do with, uh, my time at Netflix. And, um, you know, before starting Oracle, I, I did spend some time at Uber before the IPO, but spend a significant amount of time at Netflix, and that's where it all started. And, uh, if you Uber back in the day, um, the cloud was still coming up, right?
You know, pre-cloud era, like everything was big data centers, more of the applications. Netflix was also the first company of its size to operate completely in the cloud, right? Yeah.
And, and so much so that every single cloud computing principle that you see on the internet today came out of Netflix. And, and we used to have folks from AWS sit in, sit in the Netflix offices trying to take feature requests, and a year later they would make up, uh, into the AWS tool set, like, you know, things like auto scaling and how to do multi-region, how to do reliability and, you know, failure, uh, addressing and scale and all of that stuff, right? And, um, Um, whole idea of chaos engineering.
Absolutely. And, and, uh, you know, that that's May, that's, that's also, you know, those principles also is what made Netflix really great and operate extremely efficiently. And at a scale, when we talk about scale, like, you know, we talk Netflix scale because, uh, you know, it is hard to find companies that operate at that scale.
Um, and, and especially in the early cloud days when, and these things were still being formed and how to do these things at, at like really large scales, right? Um, conductor, the product that was built on Netflix also had a lot to do with one, how do we move a big business? Back then, you know, we were like under 20 million or so paid subscribers.
Um, it was hard to find paid subscriber services that were that huge in number, right? Uh, but that said, conductor had also a big role to play in, in that journey on Netflix, moving from completely on the data centers to operate completely in the cloud and making this transition while keeping the business operational, right? That was one aspect of it.
The second one, um, was today, if you go to Netflix, most of the content that you see on the website is origin programming, right? Content that you would only see on Netflix, not anywhere else, right? Back in the day it was more licensed content.
Um, and there was a big starting shift back then saying, yeah, how do we, uh, create some differentiation in the business? And, and the answer was, let's try to produce our own content. And that's where the scale comes in.
Imagine that today we have, Netflix has over 300 million subscribers doing several, I would say a hundred thousand pieces of content every year, 50, 60, 70 different languages, lot of different artwork combinations, and then you multiply them all together. And then how do you run something, uh, a complex process as this at Scale Conductor enabled a lot of that and continues to enable a lot of that in Netflix today, right? Um, we saw that, and you talked earlier about a little bit about microservices.
The, the whole microservices architecture also started when, when cloud came about, also led to an interesting problem where we had lot more, uh, microservices that people in the company have. The microservices were built to talk to other services. And that's where the whole notion of orchestration came in.
Conductor was born to kind of fill these gaps and fit the need and solve this problem. At Netflix, we just hit the problem first because we were one of the early adopters, right? So seeing this big traction in Netflix, we decided to open source that that was back in 20 16, 17.
Over the last few years, we have seen over two 3000 companies use the open source product at scale, uh, and some of their very, very core business units. So take a company, for example, like Tesla, Tesla's entire stack is built on open source, right? Uh, the, the conductor.
So if you look at how, how people go and place a, uh, order for their car online, few months later, the car shows up home, right? Their payment systems, billing systems, CI ICD pipelines, right? And we saw that same journey in, in companies like Tesla, companies like Rigi, which is the, you know, they both put out data with their kind of the DoorDash of India, saw that in the big banks like JP Morgan, Amex, you know, Morgan Stanley, healthcare companies like G Healthcare, that's where we saw there was this big shift of, you know, how the cloud came about and changed everything, right?
No one builds data centers anymore. Similar thing on a layer above that, when people are thinking about building applications, um, you spend a lot of time getting the foundational systems right, on how do you run this at scale? How do you run this at extremely high liability team?
And those are things where Conductor was super, super good at. And we are seeing a big shift on how developers think about building applications. And that's where Conductor fits in.
That is a passion that basically came about and say, Hey, this is, there's this world that is completely set for kind of making this big transitional shift happening on building applications, right? And that's, that's how we go invented Start Orcas, right? Um, it's been, you know, three plus years right now.
We have an enterprise rate conductor on the top of open source that we built, um, Netflix and Orcas combined together, and then, you know, took the open source story for a couple of years since we started Orcas, and then we got worked with Netflix, called them to archive that project, and more, more conducted to an open source foundation. And we're continuing that fabulous journey in, in the enterprise orcus world as well. I love it.
Thank you. That was a great, a great history and explanation. Drew.
You know what I always like, I co-founder is always pa not just co-founders, but founders, people who stock companies, entrepreneurs, their passion bleeds through when they talk about it, almost like they're talking about their children. Absolutely. You know what I mean?
And, and so, and it comes through with you. So, and that, that's genuine and that's, that's a good thing. So, so congratulations on that.
Let's talk a little bit. So I, I mentioned in the opening orcas is kinda sh plural, shortened orchestration in some way. Expand on that a little bit.
Yeah. So if you look at orchestration, what Orchestrate was conducted as it enables developers to build applications, applications that are typically run in the backend, uh, they are asynchronous or synchronous in nature, right? You know, long running workflows to real time, a p orchestration that is run at high scale, um, you know, high throughput, low latency, for example, and off late, uh, the last couple of years, building out agentic applications, agent workflows, and you know, how to also build I reliable AI agents, right?
And these are all forms of applications. And, and that's, you know, changed over the years. But, uh, we are the platform that enables all of that, right?
And, uh, how do you do this, especially when you want to run this at enterprises, how do you do this in, in a way, which enterprises are, you know, the things that enterprise look for, right? Outside of the, the regular stuff, which is security governance. Uh, but, you know, we need to run this at extremely high liability, extremely high scale when needed.
Not everyone needs scale, but extremely high liability. And when we talk about liability, what that means is low error rates, which means that, you know, how do we detect errors? How do we make that error rates really slow?
How do we take the, you know, time to detect and time to fix and time to deploy when these things happen? And this things happen all the time. Um, and, uh, that's really where kind of we fit in, right?
And, uh, this is an area as as big as the cloud itself. And, um, and then we have seen, you know, with, with also agent take stuff coming in, like, you know, the, the mode of how people kind of go and develop applications has already changed as well, right? So, um, and then if you look at it like, you know, everything that you build, you know, there are individual small pieces that you build, but you need to tie all these things together to make business sense out of it.
Um, and whether it's at the high level business layer or platform layer, but, um, and then things are talking to each other, that's where the orchestration comes in, right? And then the common things that almost every single company on the planet needs, who's, who's building software, whatever size or shape it, it might, might end up, uh, being used in, right? And that's where like an orchestration's really come into play.
And, uh, when we started, orchestration was still fairly new, right? Like even the term was getting coined and, and, and, uh, fairly new things. But that has really accelerated in the last couple of years, right?
And, uh, we have seen a lot of companies also come out emerging in this category, but I think we are really primed to go only in this space as well, right? And that's also very, very exciting. And we see this, this journey is also being great because the, the usage and how people are thinking about building applications also changed.
Yeah. All right. So Drew, as you can expect, I fair, I spend a fair amount of time talking to people about ai, right?
Everybody wants to talk about AI today and what effect it's having on their job, on their industry, on society. com, our newer site. So, you know, things like microservices and, and let, let's call them new architectures and, and new ways of looking at, you know, building out applications are what I spend a lot on, right?
And sometimes I, I, so I think I live in a bubble where like, I think everyone knows this, right? We're all living in this, well, maybe you are too, and you're in my bubble. But when you step back and look at it, Jew, we're in a, these are very interesting times.
It's kind of a revolutionary kind of timeframe where things like cloud and cloud native are being married to ai, agentic AI and, and things like this. And the, I don't think as we sit here, we're not a hundred percent sure how this all shakes out, except we know it's gonna be big and it's gonna be very different. I'm wondering if where you are sitting, what you are seeing, and, and do you feel that way?
And if so, in what, how is it going to shake out? Yeah. And I think this has been a fundamental shift, right?
I think the last big shift that happened, uh, you know, combined with cloud coming out and, and how people can go and easily deploy microservices at scale. And then obviously that with that comes orchestration. That was a big last shift that happened probably from, you know, 2007, eight, you know, up until now.
Um, last couple of years is where kind of AI really, really took off, right? Uh, with obviously things like Chad, GPD coming out and, um, and then people basically seeing all the magic that it can do, right? But that said, uh, there is the consumer aspect of it.
Like when you go and use strategy PT over the last few years, you've seen, like, you know, how it's really taken off. Um, it is, it is, you know, hallucinations were a problem early on, right? Like, you see less and less of that right now.
But it is, it is magical to think about, like, you know, all the great stuff that it can do, but sometimes it also trips up, some trips up on very, very simple things, right? And then we, we chat with, uh, the application and try to get the right answer out of it. Right?
Now, you take the same thing, go to an enterprise, the enterprise, you don't want to have any kind of those things you need to have building these agencies. You see the efficiency benefits that comes out of it, but you also wanna make sure it works really, really well and it, it doesn't do things that it's not supposed to do, right? And when you, the two big areas that LLMs AI has been kind of really being used and found, it's, I would say like, you know, product market, fittest in, in chat, complete areas, chat areas, and also code, right?
But when you want to run these applications and build these things at scale, few things that come into play. One is you have existing application stacks that enterprises have right now. One is how do you go and use AI in those companies without the need of rearchitecting your entire s stack?
'cause that takes a long time to do. People don't want to kind of break down an existing business and spend two years kind of, you know, you know, getting, getting that right. So that's one piece of it.
The second piece is how do you, for, for agents, when you think about agents, right? Like, you know, there's this whole thing about, you know, the agency aspect of it, but there's like a, how can you build an agent in such a way that you can enable that to make autonomous decisions, right? And to make autonomous decisions happen, it needs the right kind of tooling and enterprise, which means that the ability to go and connect the agent and the LLM models to the internal tooling within enterprises, and that could be tools, that could be APIs, whatever format, they kind of expose that.
And then also, how do you connect that to internal knowledge base, internal databases, right? That is where it makes this things agents really powerful, right? And then the principle on where to use ai, where to use LLMs and where not to use it, right?
And right now, if you look at it, the way, the feedback that we've been getting and how people have been using our, uh, you know, agent workflows and AI and products have been things which are very deterministic in agent. Like, you're gonna call an API, right? Like, uh, there's nothing an agent needs to do magical to call an API because an API is already built out.
It's already exists. Enterprise, it's working calling that is not really where the power of an agent comes. But when to call that and how to call that, that is something an agent can really do well, right?
LLM models can really do well. Um, non-deterministic things, which if you were to go and build these things from scratch, it can be extremely much more efficient. So the mixing and matching of these things, and also to build in the guardrails that you need to, right?
Like if you want to, uh, make actions, uh, the autonom University of the agents, if you wanna make them happen really well, you need to also put the right kind of, when, when agents are gonna call into the tooling, you also wanna put in the right car titles and placing that, Hey, I build this agent, this agent has been built for doing a specific purpose. If a human, were going to do that. You have put in the right checks and balances in place, right?
Can you do the same guardrails on agents as well? And that's really what makes agents really, really powerful, right? And obviously, you know, this is also fast moving industry, right?
Um, things will change rapidly and you know, this is where things are right now, right? And we, we think this is where the industry is gonna meet, move in the next, you know, year or so. But, you know, we have to keep a very, very close tab of how, how things are also getting developed in the industry so that, you know, we can, we can adapt to what enterprises are looking for, address problems, right?
But so far, this is the direction where we have seen really, really good adoption coming. Absolutely. You know, gee, we're we're running low on time.
We mentioned the website was ores io. That's right. Or io, O-R-K-E-S io.
Well, someone out there who says, you know, this seems very interesting for me. I'd like to find out more. I'd want to maybe try it, whatever.
What, what's like, what's the path they should take? Yeah. So if you go to orchestra io, right?
If you want to, as a developer, if you wanna try it out, uh, on the top of it, you see a developer tab you can go to or you can go directly to orchestra io slash developers. There is, um, developer edition that you can sign up for free, perpetually free. You can go sign up on that and you can, uh, you know, with your social accounts, with your company accounts, whatever you may choose.
And then you can build applications, you can try out and get a sense of the enterprise product, uh, every single thing in, in, in what you find in enterprises enterprise product. You can find it here as well, right? So that's one option specifically made for developers.
Um, if you want to use an enterprise, um, you can, there's a get a demo tab on the top. You can talk to someone there. Um, you can, we can, uh, sit with you and figure out your needs and, you know, carbo Enterprise edition for your business as well.
There's like two different ways to go, you know, get in touch with us, right? Uh, but if you're an existing open source user or, uh, if you have questions, there's a Slack channel out there, there's a discuss channel out there, but Slack is one of the easiest ways to connect with us. But people, enterprises, or people who don't have access to Slack, there's a discourse format there.
Both the links can be found on the homepage, on the top right corner, um, and you can, you can get in touch as, uh, touch with us in that manner as well. Excellent. Drew, we're about outta time.
I want to thank you for coming on, educating us a little bit about Orcas, giving us a little bit of your own journey. And, and look, there's no doubt we're living in a time where we're seeing change reshaping our, our daily workflows, our daily tasks, and how we're doing things. It's gonna be an interesting couple of years.
Maybe you could come back on and tell us more sometime soon. Absolutely. Thanks for having me.
I'm love to come back again. Love it. io, uh, here on Text Trunk tv.
We're gonna take a break. We'll be back with more in just a moment. Hello and welcome to the latest edition of the Techstrong AI Leadership Insights series.
I'm your host, Mike Bazar. Today we're with Nadab Iran, who is head of cloud engineering for cruso, and we're talking about AI infrastructure, and a whole lot of things are going on with these folks. They got a $750 million line of credit partnership with a MD, and I think they're expanding into Europe if I read all the announcements correctly.
But Nadav, welcome to the show. Yeah, Thank you. Thank you, Mike.
Happy to be here. Um, it's a funny thing, but I think we've talked in the past and it felt like this was gonna be some sort of interesting little niche, and now I've turned around and it's kind of this billion dollar industry and everybody and his brother's talking about more efficient ways to consume AI processors. Is there some sort of rapid maturation process going on here?
I I, I think there is. I think, I think we actually talked about it last time we talked, uh, a little bit about kinda like the pace of how it happens and, you know, this hockey stick we're in. I'm, I'm not horribly surprised.
Um, maybe just a little bit. Uh, definitely the, the pace is picked up and, and I think the, the market also looks a lot more interesting in terms of like how you see, uh, both the consumption and the supply of, uh, compute infrastructure. Um, uh, that's, that's focused on AI for sure.
I feel like it's also changing in terms of who's responsible for what. I think early on it was a data science team, and there was a couple of infrastructure people attached to that, and they built one application. I think we're at some point now where people are trying to figure out how to operationalize AI infrastructure across multiple applications, and that's changing the nature of the conversation.
Is that a fair assessment? I, I, I think to some extent it is. I, I think there is, um, also the, the focus is shifting to some extent from AI as a technology to the applications that are enabled by ai.
Um, it's, it's, you know, it's less interesting what the AI is and more interesting what it does for you. And I think we're seeing that more and more as people start to use AI in more and more areas. We, we do see that, we do hear from our customers more and more.
Like, I just want this thing to work. I have a day job to worry about not building AI infrastructure, not figuring out how to optimize the performance. It's not figuring out how to, uh, you know, find the right device driver for the hardware I'm using.
Um, I have a day job and, and that means building a business or building an application or something like that. AI is a tool and, and not the, uh, not the objective of the work. I also feel like there's more separation between the process of training an AI model and the actual running of the AI model.
In terms of the inference engine and where that might be, and are, are we seeing some shifts there or, you know, how is that evolving in your mind? There, there, there's definitely a lot of, um, uh, focus, you know, like, like I mentioned as, as people try to use AI more, that means they do more inference. Um, inference is becoming more and more important.
I think last time, um, we spoke, we, we talked about manage inference, you know, that's a, a product that we, uh, we have out there that is seeing more use even within our, uh, straight up infrastructure, uh, users. We are seeing more and more focused on inference. And, and to me that's just natural.
Again, because people are using AI more than they're focused on making AI better, bigger, et cetera. That's still an important thing. But as a percentage of the slice of the pie, uh, you know, that slice that is using AI is the one that's driving the growth.
There's also a point where, um, you know, certain things are at a good enough place. Um, and again, there, there's always the, the, the leading edge, the bleeding edge, the place where you are finding new capabilities in, in the technology. But there's also, you know, to your point about maturation, there are parts of ai, you know, large language models have been with us, um, roughly with the same general direction.
They're, they, they have today for, for a couple of years now. And so at, at that point, you do see like the, the, the core LLM becoming less of a focus and how you use it becoming more important. Mm-hmm.
And to your point, I also feel like l LMS now come in t-shirt sizes. They're small, medium and large, and, um, and people are getting smarter about which to use when, and then what the infrastructure resources are required to support those. Uh, for sure, 100% that, that's actually something that, that has happened.
Um, I, I think pretty since, pretty early on, um, you know, the, the full scale, the large LMS are super expensive to, to use, uh, the, they're slow. Uh, you need, you need a lot of hardware to make them work. And for a lot of stuff you don't need the power that they provide.
I think more and more we're gonna see actually systems that, you know, dynamically use, uh, the, the right size model for, um, the, the situation you're in, depending on, you know, your context window length, depending on the prompt you have, et cetera. All these things to me are, are natural optimizations that are happening as, um, as a technology matures. Um, you know, there, there's, there's a rule that I've learned in, in, in building infrastructure over the last couple decades, which is the, the closer you are to the end user, the bigger the leverage you have over optimizing the problem.
So, you know, we started by optimizing these things by looking very close to the hardware. Um, that's important early on to understand how the hardware works, et cetera. But you really get the leverage where you look at a prompt from a user or you look at an application in general and say like, you know what?
I don't need a 400 billion parameter to serve that need. 4 billion is enough. That's a huge optimization you can make.
And so I I, I do think we see as the technology matures people more and more looking at that place in the value chain saying like, Hey, you know, I have a 10 x improvement I can do here by just using something else. Mm-hmm. Now you also partnered with a MD recently.
So are people looking at GPUs from different vendors now and mixing and matching, or are they saying I'm either an all Nvidia or all A and d Or is it becoming a little more nuanced That, that, that, that's a great question. I think, um, in general, as a, as a cloud service provider, um, and I think it's good for, for the customers as well, the users, the end users of the technology, uh, competition is good. Um, I think right now we're still at a place where people have a preference for one or the other.
Uh, there is like the, the level at which that we work with our customers, they would be aware, Hey, you know, I'm going to get a MB hardware, I'm gonna get Nvidia hardware. To me, the really interesting next phase, again, going back to that point of like, the further up the stack, the more leverage you have is actually building services that can make it match. Um, we're not quite there yet.
Um, but I think that is forthcoming. And I'm, I'm, I'm super happy, you know, to have our hands on on those a MD machines. I think just by having two things from two different vendors that are different from each other, we're gonna, we're gonna find the niches, we're gonna find the place where one is really useful, where the other is really useful.
We do see, um, healthy demand for, for both, you know, we also have, uh, B two hundreds that, that we started, um, uh, offering to our customers a few months back. We have the A MD that, that is still a couple months out. Um, both of these we see healthy demand for, um, and I, I think this is recognition in the market that, um, competition is good as well as specialization.
You know, uh, this, this workload is with this model on this type of hardware, this workload acts differently, needs different type of hardware, different model. It's all good. Um, speaking of different classes of processors, are we also gonna see more usage of things that aren't GP used to run inference engines?
And what might that look like, Perhaps? I, I, I think, um, I think in general, um, as the market grows, it would make more and more sense to try and hyper optimize for a fraction of the market, right? So like, if you have a market that's a hundred billion dollars, whatever, just to, just to pick a random number, uh, an easy round number, um, you know, 20% of that market is a 20 billion market.
It's worth an investment to, to create hardware that's hyper optimized for that. I do think that hyper optimizing hardware makes the problem simpler and therefore allows you to get, um, uh, more benefit out of it. And, and as I mentioned before, also from the usage perspective, as your software stack becomes smart and is able to direct the traffic to the hardware that's most useful for it, that, again, will lower the bar for people to come up with with new types of hardware.
I, I would say today we are seeing, um, more and more interest in the asics that the, uh, big hyperscalers have. So like, you know, train them and, and infinium with, with, um, AWS TPUs with Google, you see them taking more and more, uh, perhaps of the market share. Um, we've been, uh, exploring things with, with several startups that, that work on interesting hardware solutions.
Again, all these solutions are trying to limit the scope of their problem to be able to do better than the big GPU vendors. You know, if you wanna build something that will accelerate any AI workload under the sun, it's a very tall order. But if you're just focusing on, let's say, inference for small to medium models and, and you make that simplifying assumption, I think there's a lot to gain there.
And as the market in general grows, even optimizing for just such a slice will become lucrative enough that we will see innovation happening in the hardware in that space. Mm-hmm. Is it me?
But I feel like, and maybe it's just part of that whole maturation process, but people are more sensitive to the cost of AI as they try to figure out what to operationalize. 'cause it's one thing to have a thousand experiments, it's another thing to figure out what can I actually afford to run in production. Yeah.
I, I think that's fair. I think, um, the, the way we sometimes refer to it here is there's, there's sowers and there's harvesters and, uh, I, I think we are leaning more towards the harvesters, and the harvesters do behave somewhat differently. They're not just, um, more, uh, cost sensitive.
They're also, um, less tolerant of complexities and, you know, the need to gain expertise and to learn and to experiment. They want something that just works and hopefully just works and doesn't break the bank. I, I think for ai, this is actually something super important.
You know, when, when you think about using a new technology, um, there is, there is, you know, the 5%, 10% kind of improvement in, in cost performance, which, which is good. That just helps the current players, you know, uh, improve their products by a little bit or make a little bit more money. We, we are still seeing, and there's a bunch of data about this, about, you know, the cost of inference over the last two years, basically going down by orders and orders of magnitude.
When something becomes order of magnitude cheaper, that opens up a whole new, you know, universe of possibilities in terms of the kind of products that you can use it in, the kind of business model you can use to monetize it, et cetera, et cetera. And so as we're seeing those cost improvements, um, you know, compound, um, and, and continue to improve, uh, I'm, I'm super excited because I think those harvesters will have all, all kinds of different things they could harvest all kinds of different areas where AI will all of a sudden be a great solution just because it's now cheap enough to justify its use. Can we simplify the stack?
And I'm asking the question because one of the great things about the cloud was it made it relatively easy for developers to stand up infrastructure and build and deploy software. I look at AI today, and I still feel like there's, you know, ML ops people, data engineers, security people throwing a bunch of developers and shake and bacon. Maybe by the time I get the village together, something good happens.
Can we streamline that? I, I, I think we can. I think, again, this is partly the, the transition from the sewers to the harvesters where, like I said, I think people are looking for more simplicity, so there's more and more demand for that.
Um, I, I, I will say a lot of the complexity even starts before you get to ai, for example, you know, um, as, as you know, we, we at Cruise who are building the world's favorite AI cloud, but we're not pretending to the, to be building a general purpose cloud. So many of our users have a footprint on a general purpose cloud as well, to run the known AI parts of their workloads. And even just that, you know, the, the ability to work together across two different cloud providers, sometimes three or four, um, and, and hide the complexities there.
That's, that's a demand that we see coming from our users and that we're working on helping them with. So the, the complexities start even before you get to the, you know, the science of ai, if you will. Um, so we're trying to fix that.
We're definitely seeing that in the, in the AI space itself. Like I said, we're seeing more and more demand for managed services, for managing friends, for, you know, a a point and click kind of interface of like, here's my data, um, do something with it. Um, you definitely see much more demand for that.
I think, again, that that part of the journey is still in, in its infancy. We see some first steps in the right direction, but I think it's still a long journey ahead. So what's the plan for the funding?
And as part of that, what's coming next for you guys? Um, so again, we're, we're excited, uh, as, as everybody knows, um, this is, uh, a pretty CapEx intensive, um, uh, industry and, and so like having that funding secured is, is great. Um, I, uh, I'm not here to talk about future financials for sure, financials in general.
So I, I, I, I'm not gonna say what's what's ahead in terms of the funding, but I can say in terms of our expansion, um, as you mentioned, we just announced, um, a new data center in Norway, um, that uses 100% renewable energy. Um, we, we announced a big deal with, with a MD. Um, there's more things coming, you know, the business is growing for sure.
Um, it does require a lot, a lot of capital to feed it. But, but we do see a lot of growth. But I would also point out, we had, um, an announcement, um, a couple weeks back with Redwoods materials, which is a company that, um, uh, recycles EV batteries where we have, uh, a pilot deployment with them, um, that is 100%, uh, powered by solar energy and recycled EV batteries off the grid.
Um, so all sorts of interesting things are happening in terms of our, our growth. The, the business is definitely, um, on the up and up. So what's the thing you see people doing today that kind of just makes you shake your head a little bit and go, folks, we could be a little bit smarter than that.
I, I think, um, this is a great question. I, I, I think one of the things, uh, is, is something that we've touched on in terms of like the, the hyper focus on the model versus the application. Um, you know, like I said, there's, there's a lot of optimization that can be done at the top layers of the application in terms of like, what actually you're gonna use for when, uh, we don't have good infrastructure for that, and therefore a lot of the people in the space, I think, overlook the ability to optimize at that level.
Um, I, I also think, um, that there is still, um, maybe I would say focus on expanding the capabilities where the capabilities are good enough. There is a little bit of like chasing like, oh, let's, let's, let's, let's work on transitioning to this new model, uh, where actually the system that you have is good enough. Um, I, I would say it's in general, in my experience, something that you need to watch out for with software engineers.
Software engineers don't like good enough. They like to be the best. And so a lot of times, you know, there's a point of diminishing returns, those last 2% of squeezing something, um, is oftentimes really, really hard.
And, and 98% may be good enough. So I, again, this is part of moving from like expanding the envelope of the technology to just using it. Um, and I think shifting that focus will allow us to iterate a lot faster, because again, those last 2% take forever.
Very inherit folks. There's a thing called AI optimization. It's come into a store near you soon.
Nadav, thanks for being on the show. My pleasure, Mike. My pleasure.
Thank you. All right. And thank you all for watching the latest episode of the Techstrong AI Leadership series.
You can find this episode and others on our website. We invite you to check them all out, so then we'll see you next time. Hey everyone, it's Alan Shimel, founder editor-in-chief of Techron Group.
Welcome to our second video in a series we've done with our good friends at Adobe. Looking at the influence, the impact of AI and security. I've spoken to five different Adobe security professionals.
In this next video series, you're gonna watch about how Adobe themselves are using AI to make their security more effective, to make the Adobe products you use more secure. The beauty of this, it's not just about making Adobe more secure, but there are lessons here for everyone in how to use and leverage AI to make security more secure. And my first guest in in this series is Brian Payne, who's Adobe's VP of product and software security, and he's gonna give us a little bit more of an overview of the work his teams are doing in AI and security.
Now, welcome back to our continuing series, discussing Software Insecurity with our good friends at Adobe. My guest for this episode is Brian Payne. Brian is the VP of product and software security at Adobe, and let's welcome him.
Hey, Brian, how are you? Doing well, thank you. Thanks for coming on here.
Brian, VP product and software security. Sounds like an awesome job, but tell us a little bit about kind of your journey and how you view your role. Sure, absolutely.
So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well. Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years. Um, I've been with the government, I've been in academia doing research, and, uh, I've spent the last 15 years or so in the private sector here, Brian, of, of course, we've, you know, we've entered into the age of ai.
Sounds like a, an old song. It's not Aquarius though. Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect.
It, it promises all kinds of disruptions. Um, and, and ai, quite frankly, to those of us in the security world, it, it's kind of a shield and a sword, if you will, right? Unfortunately, it is for the bad guys too, you know, that's always the case in security.
Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security. If you wouldn't mind, again, without giving up trade secrets, or let's not get us ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone.
Uh, it's a tool and you can use tools for, for good and for bad. And I think, you know, in the security world, we're keenly aware of that, that history, that's always been the case with tools. And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge, right.
Um, at the end of the day, we find that it's very useful to help us scale. Um, I've rarely run into a security person who just feels like they have so much extra time in the day. Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right?
Using their brains to solve those security problems, um, that's really the key for us. And, uh, and it comes out in many, many ways throughout our work. So if you don't mind, Brian, let's, if we could dive, peel that onion back a layer or two, how, how does this manifest itself?
What are some of the ways you're leveraging ai? You know, we look at different code bases all the time. If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger.
And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful. Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right? Uh, which functions receive untrusted user input?
Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic. It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially. Um, some other examples of things that we've done, um, think about network scanners.
Uh, you often need to stay up to date on the latest CVEs, the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities. Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things. Um, it can turn around and create the scan til puts rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them.
We also use it, um, internally for developers. Uh, we like to give them as much information as we can around the security problems that we find in code and help them to fix them quickly. And, um, we have found that it's much better to provide some context around this is how we think it should be fixed.
Um, this is the best practices around fixing it and those things as opposed to just saying, here's the problem. And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them. Excellent.
Brian, everyone today is talking about agentic AI and AI agents. We're, we're definitely looking at, um, different ways that this can play out. Um, we have, um, been exploring code generation, um, using some AI systems, and one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure, and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SQL injection.
Maybe it doesn't quite do the right filtering on that input. Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code. And then all of a sudden, the code that it generates, it's the bar is raised in terms of the security quality of the output.
Um, in a world where more and more code is likely to be generated by AI year over year, if we can get ahead of that curve, and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time. So I'm very excited about, about that space and where that's heading. Um, we're also using it in, um, more of a chat bot situation, right?
So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password, right? Or, um, you know, any sort of question they might have. And a lot of these things are actually written up as internal policy here at Adobe.
And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them. And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time. And we can go back and, of course, double check, do we think it gave the right answer?
And then kind of train it over time in the cases where maybe it missed. Brian, thank you so much for, for, uh, coming on here today for people who maybe just want to find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information? So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work.
Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community. Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference. We are quite often there, so Absolutely.
Ryan Payne, VP product and software security of Adobe here. Thank you for joining us, Brian, and keep up the great work. Thank you, Alan.
It's been great. I want to introduce you to our next guest in this series. His name is Alex Stan.
Alex is the senior pro product security engineer at Adobe, and he's responsible for triaging and validating bug bounty reports, planning, life hacking events, developing security automation for scale, and, uh, to scale the program's activities, and as well as collaborating with the various stakeholders, both internally and externally to improve security workflows. Alex, that's a mouthful, but welcome and it's great to have you here on Techstar tv. Thank you, and very glad to be here.
It's obvious. What are the, what are the benefits to a company like let's say, Adobe, um, with having a bug bounty program? Well, you're gonna find out, hopefully your software becomes more secure as a result, because there are people who are not, you know, who are on the outside looking in, let's say, or who are, you know, beyond the team who are letting you know about, uh, potential bugs and defects in your software or maybe their features, right?
It's not a bug, it's a feature, but what's in it, what's in it for the security researcher who discovers this? Yes, for sure. And, uh, of course that I, I cannot, uh, you know, it, it's just financial.
Uh, it's definitely one of the main reasons. Uh, but they do have some advantages. Like I, I think internal flexibility.
They get to choose their targets. They can hack whichever company they, they want, like if they're specialized, maybe in desktop testing or web application testing or mobile testing or cloud, large language models. Like they, they can try to test everything they want.
And also there is, uh, an, an important part to this, which is the reputational aspect. Um, they get recognized by the companies. They maybe, um, have CVS on their day name, you know, they report the vulnerabilities in the program, which is a CV numbering authority issues, the cvs, they can sign a cv.
So, uh, it's, it's a great aspect on the reputational part as well. Absolutely. It, and that in many times, many ways, it's even more, that's more of a, of a, a carrot, more of a, of a reason to do this than, than some of the financial rewards.
But now we, of course, Alex, we're in a new world, right? We've got AI and we've got, well, even before ai, I remember when fuzzing came out, right? All of a sudden that made, you know, doing scanning with a fuzz.
And may you, you can do a lot more with that than you, than you did with the old way of, of doing it. But talk to us a little, talk to us a little about how bug bounties are changing in this new AI world we live in. Definitely, I, uh, believe the backbone, the hunters are using AI and large language models to, you know, help, uh, discover more exploitable opportunities.
But we, on our end, in the programs we need to scale as well. So we're trying to definitely leverage ai, um, to reduce our, you know, our manual tasks and focus on the more important tasks. So I can give a little examples if that's okay.
Sure, please do. Cool. So, um, we definitely, from time to time, you, you know, as, as, uh, bug bounty program owners have a lot of reports.
So we do want to ensure, uh, we are doing report validation, very efficient. So, uh, one of the manuals tasks we, we have to do is maybe identify duplicate reports. It's, uh, mostly unfortunate, but, uh, bug bounty time hunters are, uh, can find duplicate reports of one another on our end is, is pretty tricky to, to, uh, lead the pieces together.
Um, and we try to use olms to maybe identify, uh, duplicate reports and also maybe the LLM can assist on the reproduct reproducible aspects. Like if there are unclear steps to reproduce, like for example, I'm not sure from step three to step four, um, how I can actually reproduce the finding, but maybe the NLLM can already do an, an analysis for us before we actually jump into the report and, and provide the extra steps or, uh, make, uh, you know, some, some distinctions maybe DLM telling you, you can go back to the researcher, ask more information about this or, uh, it isn't enough security impact illustrated. Can you, can you show us, um, so it actually help us, uh, reproducing.
So yeah, uh, this is, uh, usually how, uh, LMS can, can help with a report validation. There are others application as well. Absolutely.
Alex, I want to hit on two things. Number one, you mentioned you as, you know, the a person at Adobe who goes through all of these bug bounty reports that you receive. Give us an idea how, how big a job is that in, in like sifting through all these reports, eliminating duplicates, finding out which ones are, are in fact valid, which ones are critical, which ones are not deciding how much money a particular bounty should be paid on a particular thing?
I, if you wouldn't mind, you know, 'cause that sounds like a huge job and then it, you know, now in the age of ai, is the aim to replace the external researcher with the internal ai, or is it really you want the, you want both? I think my answer is we want both. Uh, especially since, you know, the external researchers are very creative.
So an AI definitely cannot, uh, cannot get to that level. Um, and regarding the volume and, uh, let's say the technical, uh, technicality of the findings, uh, yeah, it, it, it's, it is challenging and yeah, we, we need to handle, uh, the, the payout. So we need to assess each finding correctly.
So, uh, in the order of ai, uh, actually another application is to auto enrich reports. So we have pretty much a lot of findings, right? So, uh, we can use an LLM, for example, to predict CVSS score based on similar reported findings.
So we don't have to each time, uh, need to check those and see we, uh, we align with, you know, with previous submissions. And, you know, of course there will be many bugs and many products reported against. We can also use the LLM to identify the product that is reported against and pre-populated, uh, in, in a ticket and actually categorize the findings.
So in order to track the findings, you, you need to, to know like certain information and what's the vulnerability, like, is it cross size scripting? Is it SQL injection? What's the proposed CPSS score?
Because, because of, on the CVSS score, where you pay the bounties was the reported product. So, um, yeah, uh, the LMS can can be used for that as well. So it sounds Alex, like the, the, the LLM, the ai, right?
Because the LLM is just sort of the, the data from which the AI is drawing upon, but we could use the ai AI to, to actually manage the Bug Bounty program itself, right? So in addition to finding particular bugs using an AI, an LLM, we could use the AI LLM to manage our Bug bounty program, contact the researchers immediately see, is this particular report a duplicate of one we've already received, as you mentioned, uh, uh, take a, a, a shot at predicting what the CVSS score would be for this bug. I mean, it really, it sounds like it makes your job a lot easier.
No, Yes, it is. Uh, but yeah, that comes with, uh, a limitation actually, because, uh, uh, it's, uh, providing a lot of extra value, but it needs to be verified. So, uh, we have all the information there, but, uh, in the end, uh, human touches is required for these.
So, uh, and we really want to give the, you know, the researchers a chance to, uh, like we want to understand them. We don't want them to be blocked by, you know, an AI decision. So that, that's definitely a limitation.
Absolutely. Uh, well, it's not just in this particular instance, I think that's good lesson for everyone who's using AI chatbots for customer support and, and service and so forth, is people do get fussed. I, I'm, I'm the first to admit it.
I'm the guy yelling representative. Representative, you know, I want to get a real person to talk to. Uh, and, and I think it's, it's true in bug bounty programs too, Alex, we're almost outta time for, we have a huge security audience here for security folks out there who say, you know what, I'd like to be involved in the Adobe Bug Bty program.
Where, how can they, how can they get involved? For sure. com/adobe and read the policy, the assets in scope, and start there.
com/adobe. Alex, Hey, keep up the great work. You know, everyone, every, all software has bugs and vulnerability, right?
Vulnerabilities. I, and it can happen to anyone. I, I've learned a long time ago, don't point fingers, but Adobe's done a great job, I think, and the Bug Bounty program is one of the ways that you guys have done a great job in ensuring your software is the most secure and safest it could be.
So keep up the great work and keep us posted. Thank you very much, diam. Thank you.
We'll be back with more information and insight into Adobe security. I want to introduce you to Mka NI Bakar, and hopefully I pronounced it right, but, um, this gentleman's too nice to correct me, I'm afraid, but I, I hope it's the right, uh, pronunciation. Mcar is the senior manager cyber threat Research and intelligence at Adobe Mcar.
Welcome to Text Strong tv. It's great to have you on here. Yep.
It's my pleasure to be here. And you pronounced my name absolutely right. So it is, thank you for that.
Thank you. Thank you. I try.
So, um, Cara, yeah, I gave them your title. What, what is it, what does it mean when you, uh, you know, when we talk about threat research and intelligence? Sure.
Uh, I can definitely talk a little bit about that. Um, so I lead a team of cyber threat researchers responsible for proactively identifying and analyzing adversaries, tactics, techniques and procedures, gtps, um, and which who are also responsible for providing actionable intelligence to enhance OB security posture and support or incident response efforts. So that's what the team does, but at the core, it is really about threat intelligence.
And if you look at the whole, uh, idea of threat intelligence, threat intelligence at the core is practice of gathering, analyzing, and disseminating intelligence on current and emerging threads so that you can strengthen your overall defenses. So the trade graph really focuses on gaining deep insight into understanding who your adversaries are, understanding their tactic, tactics and targeting strategies so that you can generate actionable intelligence to proactively defend against their attacks. Uh, the goal here is really to get insights into adversaries intense capabilities and opportunities so that you can inform risk-based decisions to enhance defense posture.
And when I say enhance defense posture, there are multiple ways to do this that threat intelligence really helps with. Uh, like, for example, threat intelligence is kind of an input loop into threat hunting exercise. So that based on adversaries threat intelligence team is tracking, threat hunting team can go and look for specific behaviors of that tactic, techniques and procedures into the organization's environment.
Threat intelligence also informs detections engineering, so that detections engineering can actually instrument lot of detections for the adversaries that would be interested in your organization or would've actually targeted your organization in the past. So the overall goal of threat intelligence is to make it more actionable and timely in order to, um, improve overall defense posture in multiple ways. Makes sense, makes sense.
Um, now, like, like almost everything else, AI has the potential to change the game here, right? And not only to future tense, but is in many cases, is today. Talk to us about how, how AI is, is changing how Adobe does threat research and intel.
Yep, absolutely. Uh, and you're absolutely right, like AI is changing like our lives every day, uh, and from work perspective, like as we think about technology, so when I think about ai, like it is so much evolving, and similarly when I think about like overall threat landscape, uh, for industry that is also always ever evolving. So this two things, uh, connecting together are really helping solve like a lot of problems piece in threat intelligence world.
So by leveraging ai, uh, threat, digital teams can really automate and augment like threat analysis performed by a human threat. Intelligence teams can move from reactive threat signals triage to more strategic proactive defense. And I, I can give like couple of examples in the way we are doing this here at Adobe.
So what we call it as AI powered threat analysis. So large language models, LLMs are able to digest and understand vast volume of unstructured data from various threat intelligence reports, block articles, research papers that are talking about specific attack campaigns. They have specific context around adversaries, what their tactic techniques and procedures look like, what their indicators of compromise are.
So LLMs can easily digest this information, identify patents in a much, much better way with more contextual insight to extract indicators of compromise so that organizations can actually go and, um, look for those indicators across your environment. And what this really helps with is automating threat analysis for emerging threats by reducing manual bandwidth. Like if you look at the news, like there are so many threats every day that are evolving, like the landscape has been rapidly changing.
So for humans to, for the analyst or researchers to actually sit down and analyze that every threat, it's a very manual type bandwidth consuming task. So AI is really helping us to do that faster and better by reducing noise overall from threat intel feeds, prioritizing relevant indicators of compromise based on organization's context, which ultimately helps with faster dissemination of intel, uh, where the goal of intelligence is really to make it time and also actionable. So that is one example.
Uh, the other example that I can give is threat landscape report generation. So I'm sure like, like Adobe, every organization would be interested in understanding what their threat landscape looks like. This is where AI can really help by analyzing both external threat data, uh, through multiple sources, both public, there might be some vendors providing threat intelligence data.
So AI can actually help analyze external data as well as internal organizations signals to generate more tailored threat landscape reports for executives, for security teams, uh, for various engineering teams, which can be, uh, created at regular cadence. Uh, so that all those teams are informed about evolving threats specific to their organizations or specific for their team. Um, so the benefit here is really, uh, rapid and relevant threat landscape reporting with minimal manual effort.
And the best part about this is that ai, due to the contextual understanding, um, AI is able to generate tailored threat intelligence for specific organizational needs so that it is more tailored for your use case and not generalized. I love it. So Omkar, I'm gonna ask you an important question important to our audience too.
We're all hearing how AI might replace people, you know, that we're calling some of these agentic AI things, digital workers, right? As you sit here and, and how Doby is using it. Is it, is it replacing anyone on the cyber threat intelligence research and intelligence team?
Or is it augmenting and, and making you more effective? That's a really good question. So I don't believe like AI will is replacing threat intelligence analyst as of today.
As I think about AI, technology definitely helps augment human analysis and it helps us be better and faster at what we do as threat researchers compared to like replacing. So it's a little bit away from replacing and, and the reason I see this is because, um, AI is better, but it is still not at the point where it would really replace, uh, like we still keep seeing false positive based on what AI generates because it really depends on what the quality of data that you are training your model on. Um, it also has like a lot of contextual awareness, but it still requires human oversight for decision making in some cases because AI might miss the nuances that a seasoned security professional would catch it immediately.
So it is definitely a game changer to augment and make us faster at what we do, but I don't believe it is at a point where it will replace us right now. But it definitely augments and makes you more effective, and I think that's the important thing. Yep, absolutely.
It is definitely a game changer in that way. Excellent. Omkar, thank you for coming on and talking to us about threat research and intelligence, which, you know, was such an important arrow in the quiver for our cyber teams today and about how you're using ai.
Again, another really great example of how AI is making us more effective in our cyber jobs and making our security better. Thank you. Awesome.
Thank you for having me. Uh, it was pleasure talking with you. I'm happy to introduce you to our next guest.
His name is Poin Resh. I hope I've got that right, but if not, please correct me. P Poin is a, a senior application security engineer.
Poin, welcome to Techstrong tv. It's great to have you on. Hi.
A, uh, great to be here as well. Howard would as a senior application security engineer at Adobe, talk to us about how you are harnessing the power of ai, and not just you, but Adobe and your team and teammates. How are you guys harnessing the power of AI to define the future of security?
Right? Yeah. Oh, great question.
So, uh, I'm essentially part of like the threat modeling team. So we handle like the threat modeling efforts across, uh, the board for Adobe. So, uh, one of the ways that we are exploring to leverage AI in the threat modeling space is to make sure that we can, um, essentially have like better faster feedback to product teams.
Because as a small team, scalability is one of the, our primary issues, right? So, uh, the way we're thinking about this is making sure that we can leverage AI at the early stages of like the SELC process where teams can come and provide us a little bit of information and in return we provide them with potential threats and potential mitigation strategies that they can leverage. And from there, if we see any critical issues or areas that we want to manually focus on, that's where we would like go ahead and do a manual threat model or like the traditional threat model, if I may.
So that's how we're currently thinking about leveraging AI in the, in the threat modeling space. You know, you, you think about it, it would seem like threat modeling is probably a, uh, a great area to harness the power, the positives that AI brings to it, that AI brings to a, you know, an issue like that. Can you dive in maybe a little deeper about why AI is a, is a great technology for threat modeling specifically?
Oh, yeah, for sure. So, um, over the last year or so, we've started leveraging like, uh, an LLM to essentially analyze like architecture diagrams, the user flow diagrams, as well as like any documentation that the team provides us. And based off the documentation itself, we uh, would be able to like look into, uh, and understand the context, the LM would be able to understand the context and then provide back potential threats and mitigations.
And right now we're exploring the concept of using agentic pipelines. So, uh, one is essentially figuring out, uh, one agent will be figuring out what the content looks like and if there is not enough content that the, that pro product team is provided, then getting back to them saying, Hey, can you give us more details about your authentication, your authorization, maybe how you see, uh, how you store your secrets, and so on and so forth. And then from there, we have another threat detection engine.
So this is where like the meat of it happens, right? So, um, this essentially takes all the context that, um, the product team has provided along with like a prompt that we've created that would then like provide us with a list of like the top end number of threats that might affect the product itself. And that is where we go into the interesting phase.
So we are currently leveraging what we call like a, a retrieval augmented generation system or a rag system for us to like provide the mitigation strategies. Before what we were doing was more so just leveraging the base or the foundational knowledge of the LLM to provide mitigation strategies. And that wasn't working as well because like, um, it would just be a little generic in terms of like the medications, uh, in, in terms of what it, uh, gave us back in terms of the mitigations.
But, um, right now the way we're doing it is, uh, hey, these are the documents that we have curated over the last few years that are very Adobe specific, that, uh, talk about like the products that we use at Adobe, the solutions that we use at Adobe, and then that is leveraged by the LLM to provide very specific or pointed, uh, mitigation strategies to the team. And we're hoping that this would make it more actionable for product teams to leverage and, uh, at the same time make sure that they don't see, or like, it doesn't make it too generic to a point where they don't leverage the medication strategies altogether. So that's essentially the parts that we're moving towards right now.
Love it. I love it. You know, I, I'm just realizing and listening to you talk.
I I've been in security a long time. I, I of course understand everything you're saying about what you do in threat modeling, but you know, Adobe does threat, not just Adobe, but a modern cybersecurity strategy today includes threat intelligence, threat modeling. If you wouldn't mind take just a quick minute talk about how these, these things, you know, how they go together, but yet they're each their own sort of independent, uh, discipline, if you will.
Oh yeah, for sure. So, uh, threat modeling is sort of moed over the last few years, but essentially it is a very systematic way of like detecting potential issues and like providing mitigation strategies for teams very early on in the development life cycle. So you can think of it as like a shift left strategy and, uh, the way we would approach it is essentially understanding like, uh, the components that are being part of like a particular workflow, the way they interact with each other, uh, how data flows from like the entry point all the way to the exit point.
And, uh, if there are trust boundaries, how those trust boundaries interact with each other as well. So, uh, essentially understanding the complete picture of how a product works and then figuring out where there are weak points or like potential areas where new risk or, uh, potential threats can be introduced. And once we identify those, we share that with the product team along with like a curated list of, hey, if you do this, this potential risk can be mitigated, and so on and so forth.
So, uh, this, uh, threat modeling essentially becomes like a part of the early, uh, se early part of the development lifecycle, but we essentially try to like keep that flowing from like the ideation phase all the way to production so that we help teams like secure their workflow, uh, from from to shift left to right. And the earlier we do threat modeling, the better it is purely because it reduces the kind of double work that teams need to do to like prevent these risks from happening after they go to production itself. So, uh, that's where, uh, threat modeling as a concept comes into play and that's why it's so important in the industry right now.
Love it. This next question is the most important question you're going to get asked here. So give me a good answer on, we hear so much about AI taking people's jobs.
We hear also about AI helping people with their jobs when it comes to using threat to using AI and threat modeling, maybe even with agentic ai, is it replacing security engineers or is it making you more effective in your job? Oh, great question and the answer is resoundingly. Uh, to say that it is making us a lot more efficient.
I don't think, uh, agentic pipelines or however complex these AI systems become, it would, uh, replace our jobs altogether purely because there is that human factor that comes into threat modeling. We understand like the, the nuances between how interact with each other, uh, the co uh, the business impact of like a potential threat that could, uh, affect a particular product. And there are other human aspects that cannot be like taught to an ai.
But at the same time, having said that, it does make our lives a lot more efficient with the introduction of AI itself because, um, we call it the low hanging fruits, but essentially, uh, AI is able to cover our base when it comes to like, uh, the lower risk areas or like, uh, some of the gotchas that are easy to detect, and that is where it helps us, like cover our bases. And from there, if there are any critical components, we go in and still continue to do like a manual threat model. So, um, essentially think of it this way, right?
Instead of doing like, um, 20 threat models, we are able to focus on the top five highest risk threat models and the rest of it is sort of handled by ai. So we are able to focus our time and energy towards the, towards the critical workflows that matter for Adobe and that have like, uh, like dire consequences if there is like an issue with that workflow. So I would say that it is not replacing our job, but like making our lives a lot better and our work a lot more efficient.
Got it. I think a lot of, a lot of, uh, security engineers are breathing, breathing a sigh of relief. Ha ha.
Hearing you say that. Um, one last question. This, this AI stuff is evolving so quickly, it, it seems like every day it's like a generation ahead.
How is Adobe and yourself, how are, how are you staying ahead here? How are you continuing to kind of ride the crest of that wave? Oh, a great question again.
So, uh, what we do at, within our team is spend a lot of time doing open-ended research, unlike topics, essentially making sure that we do a lot of research in the areas and trying to keep up with the trends. Just yeah, open-ended research, making sure that teams reach out to us, uh, early on in the development life cycle so that we can like, learn with them as they're like experimenting with the new LMS or the new workflows so that, that they're doing it in a secure manner. So yeah.
I love it. Han I wish we had more time to talk 'cause this is such an interesting area, but thank you for coming here on techstrong TV and, and talking to us about threat modeling and AI and how Adobe is harnessing AI to stay ahead here and, uh, keep us all more secure. Thank you.
Have a great day. Our next guest in this series is Shrudy Gupta. Shrudy is the product security, AI and data engineer at Adobe Shrudy.
Welcome to Techstrong tv. It's great to have you on here. Thank You so much, Aden, it's great to be here as well.
So Shirley, let's, before we dive into topic at hand, let's talk a little bit about yourself. Give us an idea of your journey and how you came to have this role at Adobe. Yeah.
Um, yes, so I am a product security, AI and data engineer. Uh, I've been at Adobe for four years now. Started as an application security engineer and then my role evolved into what it is right now.
So basically my background is at the intersection of cybersecurity and, uh, machine learning and ai. So I've always been curious about how do we apply AI to solve cybersecurity challenges? And, uh, that's at the heart of what I do right now at Adobe.
So I, uh, research and develop AI capabilities that can enhance product security. And, um, in addition to my engineering role, I'm also the product lead for my team. And in that function, like in that capability, um, I am responsible for understanding developer needs, translating that into what we are building, um, communicating and collaborating with stakeholders, and also setting the long-term vision for what we are building.
That's a great role. What an interesting role because in some ways, shady, you are the conduit, the translator, if you will, of what business is asking for, what the developers, the non-security folks are asking for, and dealing with the security team as well. And then fashioning what really is new technology when it comes to AI and agent AI to kinda meet, meet those needs.
What a, what an interesting intersection to be at, at this moment in time. Absolutely. Let's talk a little bit about kind of things you're doing.
And I, when, I mean you, I don't mean just you personally, I mean your team, things, you, you guys are building, deploying, using, along these lines that are helping to define how, how AI is being utilized in security by Adobe. Yeah, absolutely. So we, my team are basically building a suite of AI capabilities that are designed to reduce product security toil.
Um, and the way we want to achieve this is by making security guidance, security knowledge, security expertise more available, more accessible to product teams whenever and wherever they need it. Um, and those services that we are building, we are, uh, we are making them available as, um, API endpoints. Basically they should, anybody at Adobe should be able to use them in a self-serve manner, and you can integrate our services seamlessly into existing developer workflows.
So think, uh, messaging platforms, ticketing platform IDs, web widgets, et cetera, right? So be where developers are, uh, provide security guidance as in when they need. And for this, we are using ai.
Um, so fundamentally we think of all the stuff that we are building, uh, we kind of categorize it into two large buckets. I would say. The first is, um, AI security assistance.
Um, you can also call it ask security. So anybody at Adobe can come to the assistant, ask their security question and get an answer. And now we are doing this by leveraging Adobe's internal policies, uh, standards developer product and platform documentations, so that, you know, when a developer is coming with a question, the AI assistant can answer that question in a way that is as close as possible to how a human security expert at Adobe would answer that question.
So that's one. And then the second pillar is, uh, remediation recommendations. So, uh, we want to equip engineering teams with the right resources that they need to remediate to fix vulnerabilities.
And again, for that, we are using Adobe specific information, Adobe specific product, specific best practice guidance, trying to understand the context in which the vulnerability is, and then put all of that together to provide the guidance that can aid the developers, that can enable them to go fix the vulnerability. So these are kind of like the broad two categories, uh, of capabilities that we are building. So in, in hearing you describe them, they sound to me more almost chatbot type of things where an engineer could say, Hey, how do I, what's this vulnerability?
What's the best way to patch it or remediate it? I know patch is a mm-hmm. An old word.
And, you know, these are, it's great chatbot type of, uh, opportunity or description. So, uh, Go ahead. Yeah, No, no, go.
I think you know where I'm going. Go ahead. So, uh, chatbot is one way to get this guidance wherein yes, like you have a, you have a chat bot, the developer comes to the chatbot, asks a question, and gets the guidance for the question, uh, be it generic guidance, or how do I do X, y, z, or how do I fix a bug, right?
Um, one of the other ways that we are doing this also is when we find, uh, security bugs, uh, we have a process for ticketing them. You've spoken, uh, with, uh, like Alex on the bug bounty side. So we, we create tickets, and then we assign those tickets to the developers.
So another way that we are integrating in that existing workflow is, um, call our APIs that understand what the bug is, and then provides remediation guidance in the ticket itself. So when the developer is assigned the security ticket, they don't just have, uh, a description of what the vulnerability is, but they also get a guidance as to how they can go about fixing the vulnerability. So, so that is how we are doing it today.
We also, of course, have the chatbot functionality. Another aspect is, like right now, um, AI assisted IDs is the new thing, right? Like it's gaining a lot of popularity among developers.
So that's, that's another outlet. So as developers are writing code, how do we detect vulnerabilities? And instead of having the AI agent in the IDE provide like a generic guidance, how do we get that tailored to, uh, what Adobe recommends is the way to go about it?
So that's another way to kind of, um, address this and make this information available to developers. Let me ask you a big question. Sure.
When do you think we'll see agents that actually go out and just do this and kinda tell the human after the fact, if you will, or do a report, but they're actually doing the remediation in an autonomous type of, uh, setting like that? Yeah, that is a tough question, right? And I think, uh, it's, it's an ambitious goal as well, right?
Of course, that would make all of our lives so much easier. But it's also difficult goal to achieve with state of the art AI models and AI agents. The thing is, when you're talking about a single code file or like a small enough code repository, state of the art models do okay-ish, that can be hits and misses.
But the thing is, like at Adobe, each product team is so different. Our code bases are vast. So realistically, I would say we are not there yet, uh, wherein we can have AI agents figure out what the fix is and go do it, uh, at the PR level themselves.
And I would say we don't necessarily want that. Also, um, in my team, since we've been developing these AI capabilities for what, almost one and a half to two years now, like, we have learned along the way that human feedback, human in the loop is absolutely critical in these workflows. Um, like we don't think that the answer is to give the AI agents a hundred percent agency, uh, but there has to be a human oversight involved, right?
Like, these agents are, uh, very useful when it comes to doing the manual laborious, tedious tasks, right? Like going through documentations, um, like finding the right resources, those kinds of things. But at the end of the day, uh, we do need, like, like our recommendation also is that there has to be human oversight involved.
Go take a look at what the AI agent has produced, what the AI agent has generated, right? Does it meet, meet your requirements? Does it meet the, the, your requirements, what you've asked for, what, what the right way to do things is, and then you kind of, for the lack of a better term, approve those changes.
So I would say that's, that is more realistic than, uh, like let agents go to whatever they want to. Uh, I don't think, um, even with the state of the art, we are not there yet. Yeah.
Trudi, I wanna thank you for coming on and talking with us today. As I said, the time goes quick. Keep up the great work though.
And this is, as I said, an exciting place to be in this moment in time. So good luck to you Absolutely. Trudi, Dr.
Gupta, product security, AI and data engineer at Adobe. I hope you've enjoyed this session of four or five actually segments of different areas of the Adobe security team using ai, leveraging AI to make their software more secure. It makes your work more secure.
I hope you can take these lessons and apply them in your own organization as well. Thank you. Hi, welcome to the six five Summit AI Unleashed and this enterprise app Spotlight, intentional innovation.
I would like to welcome Gobin Bala Krishnan, senior Vice president and general manager responsible for Adobe Express. During his 19 plus years at Adobe. His passion has been to build tools and run times that cultivate creativity on all platforms.
Most recently, this has led to his leading the Adobe Express business. Govan, thank you for joining us. Thank you, Mel.
I'm really, it's my pleasure to be here. Great to have you. Before we dive into this topic of intentional innovation, let's set the stage a bit.
Can you tell us a little bit more about Adobe Express? Who's it for? What it aims to do?
Yeah, more than happy to. Um, so we've been on this journey with Adobe Express for, uh, for a few years, for two to three years now. We've had it in market for, I would say, around a year and a half.
Uh, and, uh, the premise, so to speak, is that Adobe Express brings the best of Adobe's creative and document tools into an application that's quick and easy to use for everyone, right? And the idea is that it enables everyone to create content that helps 'em stand out. And we have numerous examples of a number of, uh, users from different genres, so to speak, using the application in very impactful and meaningful ways.
Uh, we have marketers who have been, who, who have successfully used express to create new campaigns, to repurpose content from existing campaigns, to localize content for regional markets. Uh, we have solopreneurs and small businesses, uh, using Express to build their professional and personal brand to grow and, uh, to grow their social audiences. Uh, we have educators, uh, using Express to help students, uh, communicate and learn more creatively.
Uh, we also play, we also see Express playing a very critical role in enterprises, uh, as it relates to their content supply chain, uh, solutions where we are empowering both business professionals to, uh, who need to create visual content, be it presentations or social content or, uh, even, uh, sales pitch decks, uh, and, and sort of working hand in hand with marketing leaders who are focused on ensuring that the content that's created stays on brand, right? It's not that you just enable everyone to create content, but you, the, the core component or a critical component of the content supply chain is ensuring that any content that gets created within an organization stays on brand. And, and marketing leaders are sort of collaborating very effectively with business professionals to ensure that any content that's created by business professionals in the enterprise stays on brand.
And the, the, the, the good news is that through these efforts and through some of these in initiatives, we have seen a very large number of enterprises, uh, experience a significant level of success, uh, with Express. Uh, some of the examples that come to mind are the PGH or AstraZeneca, uh, Virgin Australia, uh, PRAL Financial, uh, Workday Paramount. The list is really, really long.
And, uh, we believe that as we continue to go through this journey, we, we expect to see an incredibly large number of, uh, large businesses, actually it's large and small businesses for that matter, uh, deliver, uh, success, uh, from, from leveraging the capabilities of, uh, of Express. So you named a variety of users like marketers, solopreneurs, small businesses, educators, and enterprise teams that use Adobe Express. Can you share a couple of examples of how some of these customers have achieved success with the platform?
Yeah, sure. A couple that I'll go drill deeper into are, uh, one is Red Hat, uh, where we have seen them empower the breadth of their organization to create content using Adobe Express, which has helped their company achieve a time saving of almost 10 x, which is incredible to hear. Yeah.
The other one that I will highlight is with, uh, dsu, where we are seeing that they have enabled their entire distributed, uh, marketing and social teams across 120 offices to create content, uh, using Express, which has helped them get to market, uh, 70% faster than they could without express. So two clear, uh, proof points of success where our customers are realizing some significant ROI from, uh, incorporating express into their workflows and, uh, processes. That's great.
It's great to hear those outcomes and innovation, that it has to be customer centric and it has to solve real problems, but that doesn't just happen. It's not magic. So what does that customer centricity mean for Adobe, and how do you ensure that these tools enhance the process for your customers?
Yeah, that's a, as, as you've heard me say that, that's a topic that's near and dear to my heart, Mel. Mm-hmm. Um, as I've said in the past, one of the key, uh, components of innovation is to, is to ensure that obviously the capability, uh, is, it's, is is inherently interesting and, and compelling by itself.
But, uh, innovation that does not necessarily do enough to, uh, to address real customer problems, to, well, a, we have to ensure that we are identifying the right set of customers that the innovation is addressing, uh, identify the right problems that we are, uh, that we are addressing for those customers, and then making sure that the innovation that we deliver drives the right business outcomes. I mean, that to me is when innovation becomes truly magical and is something that we try to deliver to the extent possible. Within Adobe, it's about getting the, finding the right problem for the right customer to drive the right outcome, and obviously the capabilities themselves, how to be compelling to start with.
So once we get to that, the question then is how we applying that within Adobe? And, uh, I would take the example of Adobe Express and how we have built Adobe Express. We, uh, when we started on the process a few years back, we ensured that we built every feature with a clear customer in mind.
We, uh, the person that we kept asking ourselves is, who's the bullseye for the product to start with? And how, what pain point, uh, are we, are we addressing as we, as it relates to addressing the needs of that bullseye customer? And then once we started delivering the capabilities for that bullseye audience, the question is, okay, what business outcomes are we driving for that customer?
And we started that process by, uh, ensuring that we validated every one of our capabilities within Adobe. So we have, um, a very, uh, compelling dog footing program, so to speak, where we encourage every one of our users to use the products or use every one of our products on a daily basis. But more importantly, we also get them to use some of the new capabilities that we are intending to launch and have them provide feedback before we have them, uh, you know, made available to the external audiences.
So we, we sort of start by ensuring that we are delivering real value, uh, to our customers. And there are a couple of examples where I feel like this has really moved the needle. One is with how we brought generative AI into the product.
Uh, when we started building the product, we had started building it as an AI first solution, but generative AI sort of became a thing, uh, while we were building the product. And rather than bolting generative AI onto the product as an afterthought, we decided that it made more sense for us to be customer centric by contextually integrating generative AI into these workflows that our customers go through to ensure that it does not feel obtrusive, but end ends up feeling more, uh, like a, like a, like something that they can leverage as they go through the creative process. It's clearly helped us, uh, uh, see signals where the ability to use generative AI as part of their workflows has helped them create significantly more, uh, compelling content, uh, that has helped them drive better, uh, business outcomes.
So there are a few more examples, but I'll, I'll pause there and, uh, see if you have any other questions related to that. Yeah, I mean, you said like it allows them to create more. And so let's talk a little bit about creativity and productivity, because we're seeing a trend where those concepts are really coming together.
They really have to, right? I mean, this is somewhat caused by demand. So how do you see Adobe's role in this?
Yeah, This is an interesting trend that has actually been around for, for a while. I mean, we've always known that visual, uh, communication is by far the most effective, uh, form of communication. But an interesting trend that we have been noticing, uh, recently is that even, uh, PDF documents that have historically been more text-based are increasingly visual in nature.
I mean, we, we did some analysis recently and found that roughly 10 to 15% of all PDF documents that are created today, uh, are visual in nature. So, uh, it is clear that, uh, creativity and productivity are, are coming closer and closer together. Uh, more and more communication is happening through visual channels.
Uh, previously it was primarily, uh, personal, uh, communication, but we are also seeing business communication happening through social and visual channels. And the opportunity that we have, obviously is to, uh, make sure that we deliver solutions that, uh, meet the, the customer need that we are sensing in that, in that space. And, uh, we are doing that by, uh, ensuring that the products that we have, uh, like with Express, for instance, is deeply integrated with, uh, Acrobat.
Uh, we are increasingly building workflows that connect Acrobat with, uh, Adobe Express and the capabilities of Adobe Express that make it easier for, uh, users of, uh, an a of Acrobat and creators of PDF documents bring in more visual elements into that, into their documents. Mm-hmm. Uh, we're also, uh, looking for opportunities to make it so that even within Express, you have the ability to bring in your creative assets from applications like Photoshop, illustrator, InDesign, Lightroom, bring them into Express and, and build on the content that you have created in some of these flagship creative applications.
And we are taking that even further by ensuring that we have, uh, expressed, well integrated into the downstream applications for building full fledged campaigns by ensuring that we are integrated into applications like a EM Workfront and, uh, gen Studio. So it's the end-to-end connectivity, so to speak, of, you know, making sure that Express can work with both creative and productivity applications. To build that seamless end-to-end workflow is an area that we have focused on.
And we've taken that even a step further by bringing, uh, making the product extensible and ensuring that express as a product can be integrated with solutions that our users are leveraging outside of, you know, the creative space. So ensuring that, uh, express is integrated into applications like box applications like Slack. Uh, we have recently launched now an integration with Miro, which is actually, uh, has been doing incredibly well, um, or even actually in, in, in an interesting way, integrating it into consumer use cases like, uh, an integration that we launched with EA Sports that, uh, was, was, was a fun one with the college football game and EA sports, uh, chat, GPT.
Uh, and more recently we just, uh, announced a partnership with the NFL that we are super excited about because we feel, we see that there's an opportunity to drive fan engagement, uh, with a tool like Express through our partnership with, uh, NFL. So it's, it's sort of the fact that creativity and productivity are coming together has helped us take our solutions like express to, to new levels by enabling more of our users, uh, to be creative even in productivity, like use cases and situations. That's really helpful.
I love the overview express of Express and also how Adobe is working hand in hand with customers to answer to those organizational demands. And also really just kind of to answer to human creativity and expression. And as you look towards the future and where we go from here, what do you think people need to be thinking about when using AI in their organization and when adopting it?
I actually love what you said about just getting AI into people's hands. I think that's really great for you as an organization with the feedback mechanism, but also getting it into people's hands is such a big way of getting people to use it, right? So what do you see in the future of how, you know, getting people to adopt it, getting it in people's hands?
What, where do you think we're going from here? Yeah. One of the, uh, the key, uh, tenets that we have held, we have held true to, uh, all along, uh, at Adobe, is that everyone has a story to tell.
And, um, the opportunity that we have had, uh, all along is to enable everyone to tell the, tell their stories in a visually compelling way. And, uh, when I look at our journey, uh, with Adobe Express and where we started, uh, when we started, uh, as I said, we started working or building this product around three years back and back then, uh, one of the key, uh, components of building the product was to make it AI first. And the idea there was we would provide, uh, our users with tools and, uh, recommendations and contextual recommendations to help them on their journey using AI to help them on their journey to get to their output, uh, as quickly as possible.
That was phase one or step one. Step two was when generative AI became a thing, and we started incorporating generative AI into the tool where not only do we provide contextual recommendations, but now you have the ability to use a prompt to convey or to communicate what you're looking for, and we would, uh, be able to generate either images or videos, or even text effects in the context of your workflow as you go through the creative process with a tool like Express. Mm-hmm.
What we are now seeing, though, is the next step, so to speak, or the next phase of this evolution with Agentic ai, where now with the prompt, you now have the ability to essentially generate a design from scratch. And what it does for us as a company, and what I'm most excited about here is that it gives us the opportunity to completely reimagine and rethink creativity and how creativity is done. And it gives us the opportunity to dramatically lower the barrier to entry for anyone to come in, anyone with a story to tell, which we believe is almost everyone.
Mm-hmm. Anyone with a story to tell, to come in and interact through a prompt. It could be a conversational interface or a text space interface, but interact through a prompt to essentially communicate or convey what they would like to create.
It could be an image, it could be a video, it could be a full fledged design, and have that show up on the screen. And what's, what's, what's quite exciting or truly exciting about all of this is that we obviously have the ability to generate what's in their mind's eye, but we still have the tools, or they still have access to the tools if they choose to, to go in and, and, and tweak the content to meet their needs, right? So it's not that the tools are completely taken away from them, they don't need to use the tools, they don't need to learn to use the tools, but if they choose to, they still have access to the tools to go in and fine tune the, to fine tune the content as needed.
So what it does is it gives us this, this, uh, ability for us to reimagine, as I said, reimagine creativity, and it gives new ways, entirely new ways for everyone. Um, and I mean really everyone to tell their stories and, and scale their businesses. And that to me is just an unbelievable, unbelievable opportunity that we have ahead of us that I can't wait to deliver on and see what, uh, everyone creates and does with.
Well, this was great. I love to hear all of this, and we're so appreciative of you joining us at this enterprise app keynote at the six five Summit. Great.
It was my pleasure to be here. Thank you, Mel. Thank you.
com slash summit. And stay tuned for more insights coming up next. Hi everyone, welcome to the six five Summit AI Unleashed.
I'm joined today by Tristan Holton, group Vice President Corporate Strategy and Development at Applied Materials. This is going to be an excellent semiconductor spotlight, and we're gonna be talking about accelerating energy efficient computing. Tristan, welcome to the show.
Great to have you on the six five and at the Summit Summit. Thanks so much, Daniel, it's great to talk to you. So let's do, uh, the quick backdrop on this, uh, you know, applied materials like, you know, everyone that knows the six five knows Patrick and I knows that we are semiconductor geeks, nerds, chip guys, anyone that reads our stuff watches us on the tube on the news.
We love talking about this, but applied materials, massive company. But just give us that quick backdrop for everybody out there in our audience and those that may or may not know applied materials. Sure.
So I think, think many of the other speakers at this summit work for companies who are leading the way either in the development of AI hardware or software that ultimately is gonna be used by companies or consumers, um, at apply materials. We're really working at the other end of the technology stack. And apply materials is actually quite a descriptive name for the company.
We're a material science or materials engineering company at our core. And those large pieces of capital equipment that go into the fabs that we're well known for, they're really just the life support system for that material science. One of the examples that we often give is, if you look at that application processor chip in your phone, uh, that chip has 19 billion transistors, about 70 miles of wiring.
It's all contained in a sliver of silicon, as small as your fingernail, as thin as a piece of paper. And today that chip is made from 25 different materials that are combined together in a hundred, uh, different ways. And the smallest feature of that chip is about two atoms tool.
So creating, depositing, shaping those materials, that's really what a applied materials does better than anyone else in the world. Tristan, really appreciate you giving a little bit of the background. Now, let's talk AI for just a second here.
I mean, yes, people know applied materials and now they know it even better. They know you're one of the top suppliers of equipment for basically every chip fab in the world, but one of the areas that they may not be as familiar with is how you enable ai. Talk a little bit about where applied plays in the overall AI technology stack.
In terms of our role in ai, we look at AI as a technology stack with the applications, the models, the softwares at the, uh, the software at the top of the stack. So that's companies like OpenAI, Google, Microsoft, and Meta. The data centers themselves in the middle, and then the chips and the chip making technology at the base and at apply materials.
We are really the foundation of that stack. Our focus is on those foundational technologies that define how chips are made, and we work up from there and we partner with the different layers of the hardware and software companies, uh, in the ecosystem With such a foundational role in the tech ecosystem, applied as a unique perspective on where AI AI is headed, uh, and what might be some of the big challenges facing the industry. But what would you say is the number one thing?
Uh, and I have my answer by the way, but I'm gonna, I'm not gonna tell you what it is, but what do you think the number one thing that's going to really limit this large scale deployment of ai? Yeah, so I would say, you know, if we were gonna use one word, that word would be energy. Uh, but to explain why we believe that's the case, maybe I'll back up a little bit and explain where we think we are in the adoption curve of ai.
And I think the first thing that we can say is that AI has almost infinite potential applications, and we're really just at the beginning of this large scale deployment, and that deployment is gonna take multiple decades. And as AI gets better and better and more cost effective, you can think of these economic crossover points for all of the different types of application. Um, the second thing I'd say is we see the adoption of AI becoming a necessity rather than discretionary.
So if you step back and you look at some of the big macro trends in many of the developed countries, there is significant changes in demographics taking place. So people are having less children, they're living longer, and that means the ratio of the working population to the non-working population is getting smaller and smaller. And the way to offset what is effectively a shrinking workforce is through productivity growth, increasing the average output per worker.
But productivity growth, uh, over the last decade has been very slow in those economies. I think in Japan, for example, it's less than 1%. So I think that this will probably sound like a very Silicon Valley thing to say, but the only way to drive future productivity growth that the magnitude that's needed is through technology, specifically AI and automation.
So with that as some background, you know, given those factors, why don't we see AI being deployed much faster? And I think you'll hear throughout this summit that there are numerous reasons, cultural, ethical, technical, but in our view, the biggest one is energy. And I don't think it's any secret that AI consumes a lot of power, uh, today to train a generative AI model like chat, GPT, those companies are typically using a 10 megawatt class data center.
So a data center like that is consuming the same amount of energy as 5,000 homes within the next year or so. We expect those data centers to have a hundred times more compute and use 10 times more power. So at that point, you're gonna be at a hundred megawatt class, and then a few years further out, we can expect another a hundred times increase in compute, another 10 x in power.
So at that point, you're at a one gigawatt class data center. And in fact, meta recently announced that they're building a two gigawatts data center in, uh, Louisiana. 1 gigawatts.
So that means that we see this grand challenge for the industry is to significantly improve the performance and energy efficiency of those data centers. And the metric that we think about is flops per watt, and it's really flops per watt, per dollar. And an emerging consensus in the industry is that we're gonna need a 10,000 times improvement in that computing performance per wat over the next 15 years or so.
You Tristan, I I really like how you set that up too because I've spent a lot of time thinking about the productivity gains, thinking a lot, sort of what it means, um, how quickly we do move in this direction and, and how do we get more productivity and also those sort of rate limiters. Because I think even at this event you probably hear a lot of people talking about, it's been pretty exponential. It's been pretty mind blowing to see in two years or two and a half years since that first instantiation of check GPT to the model iteration innovation and the exponential growth in the, in their capabilities to reasoning, um, the development of the chips, the ones that you help support from, uh, various, uh, you know, fabulous designers and uh, you know, different, um, even hyperscalers building their own.
And of course you play a role in in how this all all comes to pass. And then kind of how you came back to this, that it is energy and I've spent a lot of time talking about this too. And of course there's different ways to achieve energy.
There's more energy through, you know, kind of dirtier mechanisms like coal fire and, and then there's nuclear, which we've spent a lot of time talking about. And you know, people like Elon Musk are, are, are kind of swearing by the sun being the answer that we can get all of this power we need from solar. But then even when you put into perspective of like the Hoover Dam and one single data center for one company, we go, holy smokes, we are way, way over our skis right now in terms of how fast we're building data centers versus how much power we have.
Um, so that's gonna be a real challenge. But the other side of this is some of this efficiency can come from the design. Some of this efficiency comes from the material.
Some of this comes from the way we interconnect and network systems to optimize. Um, and that's been a big advantage here in the US of why we have AI leadership that we do is we don't necessarily get more total compute, we can just do it more efficiently. And that's a big part of, of what's going on.
So let's, let's just dive a little deeper into that though because I'm hearing, and hopefully you're all hearing from me as well, my opinion as well as Tristan's here. So clearly a big topic, hyperscalers chip designers, but where do you, where does a company like yours play a role in sort of delivering efficiency? Yeah, absolutely.
So we would agree with everything that you've said and I think you'll hear from many leaders in the industry right now saying that AI is not an evolution in computing, but it's really a revolution in computing. And that new era of computing requires new software, it requires new data center architectures, it requires new chip architectures. And then from where we sit from a manufacturing perspective, it requires new ways to make those chips.
So at apply materials, we're really focusing on five key areas, and the first one of those is how do we accelerate the leading edge logic roadmap? So really how do we create those better transistors, those better interconnects, the better wiring to advance, uh, leading edge logic. Uh, the second area is how do we enable the next generation of compute memory?
Uh, so, so DRAM and DRAM is really undergoing some very big device architecture inflections at the moment and they will play out over the next five or 10 years. Uh, the third big theme for us, it is advanced packaging both for dice stacking. So for example, where example you, you have high performance dram chat chips and you're stacking them on top of each other to make high bandwidth memory and then also heterogeneous integration where you're putting multiple chips together using very, very sophisticated packaging techniques.
So they act as one integrated system. The fourth area we are focused on is next generation power devices. And those power devices are gonna use compound semiconductors, so gallium nitride or silicon carbide.
And the potential there is that they can provide significant energy savings in the data center's power systems. And then fifth, which is a little bit further out, uh, is silicon photonics. So silicon photonics is all about using light to move data from chip to chip rather than traditional copper wiring.
And what we would say is in each of those areas, there are very significant innovations underway. There's a wealth of possibilities on the roadmap. So we're very optimistic about what can be done at that foundational chip level.
And, and those are many things, and I'll skip the editorial as I bounced into the next question because I I've got a bunch. I was thinking about everything you just said with materials with light, like these things are happening and they're happening very quickly. Um, and, and, and they're, they're essential.
So companies like yours, doing what you do is going to be essential because I think we, we've shown that we can keep pushing the limits on compute and you know, there's been sort of these pronouncements about the death of Moore's law. Um, I think different companies argue this in different ways, but we're seeing a, in just AI data center architecture, we're seeing a year to year cadence from multiple companies now that in that tend to include exponential magnet orders of magnitude, more computing at greater efficiencies. But we're also seeing software and use cases develop that are going to use all that computing and more concurrently.
So it's gonna put a lot of pressure on the system. So, you know, we hear about the death of Moore law, Moore's law, we, uh, now see trillion transistor, uh, GPU systems in a single package. Um, how do you see the chip making roadmap evolving, uh, in the coming years from your lens?
Well, I, I found that it's very unpopular to say that Moore's law is dead. And that's really because it depends on how you define Moore's law. Agree.
Uh, but I do think it's safe to say that the benefits of traditional 2D scaling, which is all about packing more transistors or bit cells into the same area on the chip, those benefits are slowing down or have stopped for many types of chip. When that 2D Moores, uh, 2D scaling Moores law was working well, you would shrink the feature sizes on the chip and then you would make all kinds of adjustments to the materials to make them work at those smaller dimensions. And the outcome of that would be a simultaneous improvement in performance power, an area cost of the chip, which is often called Ppac or PPAC in the industry.
So today, even though that 2D scaling still has an important role to play, much more of the ppac is coming from different types of innovation. And that might be the architecture of the chips themselves. It might be three dimensional devices and structures in the chips.
So things like new transistors and interconnects. It might be new materials like compound semiconductors or it might be things like advanced packaging. So if we just took the transistor as an example, transistors have moved from being a planer two dimensional device 20 years ago to fin fat and now to gait all around.
And that first generation of gait all around transistors gives us about a 25 to 30% improvement in energy efficiency over fin fat. But those devices are a lot more complicated, complex to make and they actually require atomic level precision in the material science. So in the channel of those transistors, there's actually five different materials and each layer of material is only one to two nanometers thick.
And then end to end that process flow to make the ga all around transistors is actually 10 to 15% more process steps. So more complexity compared to that prior generation FinTech. But I think a simple way to think about it is as both the devices and the packages are getting much more three dimensional as that happens, materials in innovation is playing a much bigger role.
I love that you pointed that out. I think one of the key takeaways for everyone out there is we are still getting really significant scaling, but the way we scale is different. So when you thought about Moore's law, it was very centric, like you said, to a certain idea and two dimensional.
A lot of what we're hearing now is about package, you know, two and a half d, 3D, um, you know, how we're basically putting more and more into not just the, the, you know, into, into the system to create more computing power, but doing it differently. I mean, you talked about light earlier, you know, things like co packaged optic optics are really changing. Um, you know, the future of design and how systems are able to communicate, network, these are just a few of the examples, but where does innovation come from?
So innovation used to come from one place, now it's kind of coming from many, some of it is materials by the way, which is where, you know, you're very focused on. So let's kind of bring this all home, you know? 'cause I think what I was trying to summate, maybe not as eloquently as you, but was the traditional version of Moore's law may not in fact exist.
And you may be very unpopular for even suggesting that, but I think again, that comes down to the definition. But it sounds like there's a lot of reasons to be optimistic. Uh, the industry as a whole is driving incredible innovation, which includes this AI era, which is almost a brand new computing architecture ground up.
Um, so chips are getting more complex, this means more r and d, this means more collaboration in the semis, silicon and, and systems ecosystem. Um, this means risk because companies like yours has to make big bets and big investments to get to new products, new materials, new uh, designs. Um, so talk a little bit about that.
How do you sort of make sure we keep pushing the envelope but make it worthwhile for companies like Applied materials to take this risk to support these next generation of designs? And what do you see in terms of the role of r and d in all of this? So your role r and d's role, and how do we keep the innovation going Tristan?
Yeah, AB absolutely. So as we talked about earlier, the technologies that are being used in these early phases of AI deployment, they're gonna change quite significantly in the coming years. And maybe another way to frame that, another way to say that is much of the technology that we need to deploy AI at scale either hasn't been invented yet, or if it does exist in an r and d lab somewhere, hasn't been fully commercialized.
And then of course, in many cases there are multiple competing technologies and it's not entirely clear which of those, uh, is gonna win out. So I think all of that means that we're really in a race to bring these new technologies to market. And whether you are a company or at a national level, those companies or countries that can get there first, they're gonna have a significant competitive advantage.
So at Applied, we're spending a lot of our time thinking about what we can do to speed up, how can we accelerate those technology roadmaps essentially for our customers. And we believe there's a number of things that can be done to change the way that the ecosystem is working together. So if you look at how this works, traditionally, if you look at how a new breakthrough in a material, immaterial science makes its journey all the way through to a commercial chip, it's actually quite a serial process.
And there are several, you can call them clunky handoffs along the way. That process usually starts in a skunk work type environment. So that might be a, a university lab environment.
Then you have to develop a commercially viable process technology and the equipment set to support that process. That's really the core of what companies like Apply materials, uh, does. Uh, then you need to integrate those new technologies into the device itself.
So that entire process can take 10 to 15 years. So one of the things that we can do is we can start to make that journey more parallel and less serial. So as we start to think about speed, and I think really we should say velocity because direction is important, one of the things that we can do is we can work on collaboration, tighter collaboration, and we think there's an opportunity to work differently, not just with the immediate upstream and downstream partners, but across the stack.
So for example, if the companies at the top of the stack understand the art of the possible in the material science roadmap, they can actually help steer and optimize that roadmap and also those investments. And then finally, I think this is true for everyone in the industry. We all want to maximize the impact of the r and d dollars that we're spending.
So for a company like Applied, we're we have to invest in our RD platform, which is our labs and the equipment sets, and then we also invest in r and d programs. And it's really only those r and d programs that generate innovations and products and revenue. The platform itself is important, but it's really a necessary evil and it's a very expensive, necessary evil.
So one of the other things that we can do is share platforms with others, and that means that across the ecosystem we can start to make our assets work harder and free up more investment. So we can spend more on the r and d itself. And Tristan, what do you think the industry can do?
You talked about that collaboration. What could the industry do to accelerate the pipeline of r and d to commercialization? Because 10 to 15 years, as you suggested, that may not be fast enough.
Yes. So Daniel, we can definitely talk about the theory of industry working together more effectively and efficiently, but actually applied is making some real investments to make this a reality. Um, our vision is what our CEO calls high velocity co-innovation.
So in other words, getting more speed through better collaboration. And to do that, we've been building our Epic platform and EPIC stands for equipment and Process Innovation and Commercialization. And Epic really is designed to be an open platform that brings together our customers, our r and d partners, our suppliers, other companies that bring complimentary capabilities and technologies.
And using Epic, we can run either bilateral or multi-party r and d. And really the goal here is to give us faster cycles of learning and then ultimately higher mutual success rates. So the centerpiece of this platform is the Epic Center.
So this is a new facility that we're building here in Silicon Valley. It's a $5 billion investment for applied materials, and it's gonna provide us with three acres of state-of-the-art, clean room space that we'll share with our partners. And interestingly, the building itself has several innovations in both design and construction to support the way that we want to work in the future.
And in, in r and d, uh, we're about two thirds of the way through that project. The center is on track to come online in the spring of 2026, and we're just very excited about the work that we're gonna be able to do with our partners and our customers, uh, at Epic. And Daniel, as you can probably tell, uh, we're very excited in general about the future.
You know, we truly believe technologies like AI and automation have this huge potential to have a positive impact on the world. And today we're really just only scratching the surface of what's possible. Yeah, and, and a thing I'd like to point out, and this is definitely my opinion and certainly not proclaiming it to be yours, Tristan, or that have applied, but is there's a reason I'm such an advocate of, of, of research and the r part of r and d.
Um, it's a very long slog and the companies that do it take on a ton of risk. And this is also why I tend to be pretty bullish on anything that's IP protection. Now there's a certain amount where we want to, you know, diffuse and not use it to take advantage in the market, uh, or create, create asymmetry or make things not accessible.
But at the same time, we have to give companies like yours the ability to breathe and, and feel comfortable that their investments will be protected and they'll have a chance to profit on the risk they take. Because when you take such a big risk, you should, same thing we see in pharma and other areas, risks and opportunities should be in parallel. That's what keeps, you know, you talk about Silicon Valley, you talk about that's what keeps this engine of innovation ecosystem going.
And that's what's made this such an exciting time for AI is that there are people and enterprises and entities taking big risks, doing really important work. Research is a big part of it. Um, great.
Tristan to have a chance to talk to you here at the six five Summit. Hopefully everybody out there learned a little bit more about applied materials, about what's going on in material sciences and how it really is feeding this exciting time of AI developing more energy efficient silicon and chip designs, and then of course powering the future, uh, across our industry. Tristan, let's do it again soon.
I I have a feeling there's gonna be more to talk about. Thanks so much Daniel. It's been a, a pleasure and thanks so much for inviting us to participate.
Absolutely. And thank you everybody for joining us here in this semiconductor spotlight session here at the six five Summit. com slash Summit Summit.
More content coverage and summit coming up next.