Techstrong TV July 18, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
Looking for super intelligence. I'd be satisfied with anyone who's smart out there. You're watching Textron Gang.
Hey everyone. Happy Friday. Wow.
Friday. I, I just felt like we were talking about AI on Monday, you know, and then maybe it was Tuesday or Wednesday. Artificial general intelligence, a GI today is super int intelligence.
Are we all dumb? I don't know, but we've got a lot to talk about here at Techron Gang. We've got great people to talk about.
We've got a whole Seattle crew going on today. He's always in Seattle, usually, unless he's traveling. Our friend Fred Wilmont, joining him in Seattle though, and he is traveling, is Ira Winkler staying on the West Coast man with in Silicon Valley, John Schwartz, and still up.
I don't know if you're in Lake Placid still, but the dean, Mike Ard. Hey Mike, how are you? Still am.
And boy, it's hot and sweltering Lake Placid, but there's No such local as it is in Seattle, as it is in Seattle, we hear. Not as hot as it is in Dubai probably. But anyway, that was the green room discussion.
Let's jump into our real discussions for today. We're gonna start off, you know, AWS had a bit of a shindi this week, and, uh, they made a whole bunch of announcements, as you would imagine around ai, AI agents, Q bedrock, all, all the AWS buzzwords, as well as opening up registrations for reinvent in December. But Mike, what's the deal with AI agent builders?
It looks like AWS wants to be king of the hill. Yeah, oddly enough, AWS and all those folks in Seattle descended upon New York this past week and launched a thing called Amazon Bedrock Agent Core Services. And it's basically a, the frameworks that you need to go build and deploy AI agents at scale.
And they're pointing out that all these things right now are missing for all our chitchats about AI agents taking over the world. They're like saying, you can't really do that unless you have things for securing their identities and giving them gateways to access APIs. And then the tools we're building and deploying them.
And admittedly, this is a preview of something that they're rolling out, so they're a little bit early. But one of the things that seems to be coming through loud and clear is that, uh, enterprises are now looking at all this stuff and starting to put the pieces together. And it's not sure to my way of thinking, but maybe more of them are gonna rely on the cloud than ever because they don't have these capabilities in an on-premise environment.
At least that's what AWS is betting on. And it was interesting 'cause they had the head of development for Intuit was there talking about how they built a whole operating system for AI agents on top of the AWS service. You know, this will warm your heart, but the, uh, head of platform engineering enablement for Reuters was there also talking about what they're up to and their plans for building out AI agents.
And it's still early days as far as the enterprise is concerned, but it looks like I'm betting that AWS all these services will be copied by every other cloud service provider shortly. So Alan, or it looks like we're in a race for AI agent infrastructure. Yeah, well, there's a lot of, as in that AI agent infrastructure thing.
But look, this is not a new story though. You know, for me, the agent agent AI thing first kind of burst on the scene with Benny, often Salesforce Agent Force and building thousands and tens of thousands of agents. And ever since that day, every vendor under the sun has said, we wanna be your agent, man.
I want to be your backdoor agent, man. And why wouldn't AWS want to be that too? My, my issue here though, is I'm sure they'll build great agents.
B Bedrock is a fantastic platform. Yeah, but let me, oh, sorry, Alan, I, one second, let me just put the chair on. The problem is the world is moving away from single cloud platforms to multi-cloud.
Everybody wants to put, you know, a little piece here, a little piece there. They don't wanna be locked in any one platform. Do do the a, the AWS agents work outside of AWS ira?
Go ahead. Well, that was actually kind of the point I was gonna bring up because really, I, I hate the whole broad term ai, if you haven't known that before. Mm-hmm.
And because AI is really just mathematical, um, library programs, it's algorithms. And so what AWS is essentially doing is they're putting together and packaging and making it easier to implement the algorithms when you're using it within AWS. But just because you have these algorithms in place and something easier to make them possible, the problem is you need the data to put into it because it, you know, you have to train the ai, the AI has to be able to make good decisions in order to make good decisions.
It has to be able to have access to the appropriate data and so on. And having the program itself is one thing, but having all the data being able to pull into it is another thing. And to your point, Alan, if it's sitting there looking at, if all your data is on AWS in buckets that are accessible to the agent, maybe you have access to the data, but it still has to be in the right formats and stuff.
And that's one of the problems, however. But if you're in a multi-cloud environment and all this stuff, it's, it's like any other program. The program is only as good as the data that you put into it.
But the problem is most people aren't sure what data to put into it first. And they're guessing, and this is why, for example, a chief data officer is critical in most large organizations now, because they have to be able to architect all the data in the organization to be able to feed these a God, I hate the word AI programs, and this is where AWS it's, it's kind of nice to have, you know, but at the same time, you know, it's kind of like going to one of these little, um, maybe I'm dating myself, where they used to have these little art studios where you could go in and make your own ceramics. They still don't have those places, the Pottery places.
Oh, that's good to know. But you could go in there and get one of those, you could get one of those turn tables. But the problem is you still have to get the right clay, you still have to have the skills to make the clay in the right area, even though you have the turning tables.
So AWS is giving everybody those little spinny tables, but they don't necessarily have the right clay. They don't know how to architect the programs to do it. It just makes it easier for people who know what they're doing to have a set of library programs to implement.
Yeah, I would agree with you in the sense that, um, there's a handful of organizations like maybe a Reuters and, uh, Intuit that have the tech resources and have been early on this whole journey. But I'm, I'm betting that 95% of the companies out there are still trying to figure out, you know, how do we make the actual AI agent never mind actually give you data or anything else. They're just struggling with the little piece of code that they're gonna use as the baseline.
So we living an AI bubble. I'm sorry, John or Fred, go ahead. Yeah, so there's a couple things that I think are interesting here.
Um, both of you guys are right, but the challenge is where AI workload's gonna get executed. And so who owns the agent, right? Owns the workload regardless of where the data is.
And the challenge is, it's inaccessible to a lot of folks, right? And, and, and here until now, there wasn't an SDK, there wasn't, you know, sort of this reach into the browser. There wasn't some of the buildable tools.
And then also the thing that everybody fights about is which service during what time of day gives you enough course to return your AI workload at the speed you need it with the amount of tokens required to generate it. And so, you know, doubling down on the amount of infrastructure they're willing to put behind it, I think is a statement. And I would argue, you know, the rationale behind choosing between, you know, using Gemini for this particular workload or, you know, the bedrock, bedrock framework that allows you to get access to all of these other models.
You know, AWS says, Hey, look, I have the highest percentage of the infrastructure in the cloud. I want everybody running their AI workloads here, but adherence. So now they haven't given us any tools aside from like, let me weaponize bedrock specifically in order to make, you know, the entire user flow easier for people that don't do this organically and aren't, uh, data scientists and, and, uh, platform wizards as well.
You know, that's an interesting take, Fred. It's, it's a discussion I had not on the gang, on a Textron interview, tech strong TV interview I did yesterday or the other day. And that is, we are at a funny juncture in this AI journey right now.
I think you're a hundred percent correct. Initially, the people who were, they were building this for, the people who were using it, the people who were pushing the envelope were very much, let's call them AI engineers, data scientists, you know, tho these kinds of people that they were the initial audience, if you will. But now I think it's transitioning to, we want platform engineers, we want developers, we want security people, we want DevOps engineers, we want SREs.
We want that sort of traditional IT stack from the developer on down to start using ai. And that that means what? We've gotta change the interfaces, the use cases, the nomenclature to make it fit their world, not the world of the data scientist or the AI geek.
And it's gonna take time, right? There's, there's a transition that's going on right before our eyes, but you're right, he who controls, you know, the platform that these agents are being built on and going forth is in the cat bird seat. And the way I see it is everybody and their mother recognizes that in, in the tech world, and they're all vying for it.
And part of the problem with ai, we discussed it on yesterday's show, is, you know, it's the ultimate billionaires club. Yeah. You gotta have serious cash to be able to play in this.
So just say, I think DevOps engineers should just rebrand themselves as ai, DevOps engineers get themselves a 30% raise. And who's to say they're not an expert? 'cause nobody else knows what they're doing either.
So Maybe, yeah, You know, there was an interesting, was it, I think part of the announcement with that this, uh, new addition of market marketplace, um, kind of as a central hub to, for businesses to deploy and manage specialized AI agents. And again, you talk about the billionaires club. So there's AWS and I think Microsoft has agent store Google Cloud's, AI agent marketplace.
I mean, there's kind of paring, Well, the does agent force, right? They want it. Cisco's doing its service now is doing it Again.
But these are the biggest of the biggest companies, Right? It's, it's the billionaires clubs. Well, yeah, I still think I'll use the example and what people need to understand.
To me, it's, I like analogies. It's like a spreadsheet right now. The problem is that if you go to a spreadsheet, like most people do a spreadsheet to create a very, very simple table because, and, and it's like you're paying a lot of money for something that could be done in a Word document, frankly, at the end of the day, for most people.
But if you happen to really, really know how to work a spreadsheet, you could work magic. You couldn't run your company off of Microsoft Excel. Not that I'm saying you should, but you could because the capability is there.
The problem is what AWS is doing sounds incredible at the moment for a variety of reasons. You know, much like Fred said, it's enabling a lot of what companies can do. The problem though is most companies don't have to Fred's and everybody else's discussion.
They don't have the expertise to take all these library of agents. They don't have the data, they don't have all this other thing to actually make it useful. They, to Alan's points like a mil, you know, billionaires club, where a few large companies will have the people, it will simplify their way of ramping up.
But it's a people who are few and far between who have the ability to staff it up and like what we're talking about in a later segment today, you know, you have to throw lots of smart people to make it useful at it with lots of money. Absolutely. So we're gonna wrap this one up and take a break, but, you know, we're creating ai, have and have nots, and maybe that's what we're destined to, you know, You know, I was gonna say before you, before you end this segment, um, we, we can maybe talk about it later in another segment, but Oxford University has been doing a lot of research into the haves and the have nots, and it's a very small pool of the haves and the vast majority of the rest of the world are the have nots.
Oh, no, no doubt about it. But those haves will accelerate, right? Become super intelligent.
Maybe that's what we're gonna talk about next. Nice segue. John.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back. And we're talking as Alan John.
We're talking about super intelligence, which I'm not quite clear is any different than what we call, uh, a is it A-G-I-A-G-I? It's artificial general intelligence. But there's a report now that meta's out trying to train machines to think like humans by starting over and treating them like babies and trying to teach them from the very beginning everything you need to know to be a human.
And of course, they have been spending in mountains of money just trying to attract talent. John, I know you've been covering this space a little while, but it seems like especially out in the Valley, everybody in his brother who can have AI on their resume is now worth a billion dollars plus. But how real is Superin intelligence to you?
Uh, I think it is real. I mean, we, you alluded to Mike the, uh, this teaching study. Well, what Mike Metta is doing is their researchers are studying how babies learn.
So one of the examples or a simple action like throwing a tennis ball under the air and predicting what it will do to require to catch it. And they're, they're looking at things like the ability to form full sentences. Uh, there's a, uh, chief AI scientist at Meta who said they're building a world model akin to embedding an AI agent with common sense.
But it kind of all goes back to, we talked about super intelligence and a GI, and again, they kind of blur together for me at times. But simply Meta is trying to create this AI lab that would surpass human intelligence with super intelligence. So there's this research lab under development.
This is the, the, the news where Meta had acquired essentially scale ai, CEO. Uh, they made a, an investment of about $15 billion in scale ai, or 49% of the company. And Zuckerberg is very heavily engaged in this, evidently, reportedly spearheading this effort.
And he's trying to put together this super intelligence group of 50 top AI researchers and engineers. And since he's not happy with AI's, that meta's AI efforts. And so he has kind of taken, taken the lead in putting together this, this team in which they're offering these incredible pay packages and are trying to poach people from open AI with packages worth up to a hundred million dollars.
And the idea is to move beyond AI research to a more specialized focus on a GI and ultimately super intelligence. And the idea is they're gonna weave a GI and let's just say, let's just stick with a GI, they wanna weave it across their product suite or chat bots, augmented reality glasses and other projects that we don't know about. So in a sense, this is where they're going.
And it all kind of ties in what we talked about yesterday with this incredible amount of money that these companies are spending. I think in the ca uh, on data centers, in the case of meta, I think it's 60 to $65 billion they claim this year alone. Um, it's gonna be interesting to see this race and this concept of a super intelligence lab.
Um, it's, it, it also shows Zuckerberg's ultimate frustration with LAMA four, um, and, and kind of trying to move forward and trying to gain some sort of competitive edge. But again, as Alan has said, and we all have agreed upon this the last couple of days, it's all about the companies with the resources sitting on piles of cash who are gonna be able to do this and try to gain some sort of advantage over everyone else, and then cook the rest of us in. So, John, I'm so confused.
I I did, before doing the gang today, I was texting with Daniel Newman from Future. Yeah. Oh, yes.
Yes. He, he's, he's been very keen about this. About, Yeah.
So, but we were talking from the way Daniel and I were talking, and the way Daniel's explaining it, super intelligence is sort of a way station on the way to a GI it sounds like you are saying super intelligence is beyond a GI Yes, that's, that's based on what has been reported out of meta. They consider it's the next threshold or next level. But then again, they use these phrases so, so often interchangeably that I almost would prefer just to make, to simplify things, to just continue with the a GI reference.
Super Intelligence is probably new marketing spin or a marketing, uh, branding of its, uh, maybe they've dec decided that it has more sex appeal, but in a sense, the, the project within Meta is this super intelligence lab that they're working on. Yeah, Well, the, the data center, the building, two of these data centers, one's in Ohio, and that's the big one that's, uh, uh, I forgot Hyperion, which is No, Prometheus. Prometheus is the one in Ohio.
Yeah, Louisiana. Hyperion is in Louisiana. It's gonna be bigger than Manhattan ira, right?
That No, I'm, I'm not kidding you. Seriously. It's what they said.
It's gonna be bigger than Manhattan one day, a data center complex. You know What also OpenAI is working on something in Texas that they claim is a data center that can be the size of, uh, central Park. Yeah, no, that's, well, but that's, that's small potatoes.
That's a parking that's smaller than Manhattan of Manhattan. Yeah. But it's just, again, a scale.
You think about it, it's like near, it's crazy. But let's bring, let's bring Lisa in here for a minute. Um, it seems to me, Lisa, that these definition of a GI keeps changing and it is becoming more of a marketing term, and the goalpost are shifting and, you know, for what's supposed to be really just research and development, there sure is a lot of marketing spin here.
What's going on from your perspective? There is, I actually, um, great to see you guys. I, I agree with John that super intelligence is a sexier term and folks are really wrapping their heads around it.
People can, I won't say people can wrap their heads around it, but I was just on stage at a big conference a couple months ago and interacting with a robot, talking about super intelligence and what it's going to be enabling everyone to do from marketing perspective. Marketers I talked to every week, everyone's, and I've saw this on this program before, heavily leaning into AI powered marketing tools. What they're gen ai, they're using it for content creation, for videos, et cetera.
Now they're leaning into how to deploy AI agents. So that's where marketers are in really understanding, well, how can AI agents actually be on our org chart, help marketers leverage these tools to enhance campaigns, improve customer engagement, how can agents help marketers create more personalized, um, more engaging customer experiences? But I think from a terminology perspective and is a little bit blurry, and I think I like John's point of, of, of super intelligence being, it's kinda like a sexier, well, you, You know, and, and a weird, I'm, I'm glad you mentioned that, Lisa, because in a weird way, think back to when, uh, Facebook or Meta, whatever you wanna call it, well, Facebook, when they were throwing billions of dollars into the metaverse, remember that, remember that big push a metaverse then became, and, and I went back and forth with Facebook about this, they renamed the company, and I said, so you basically squandered billions of dollars in this metaverse push?
And they're like, no, no, no, no, you, you're wrong. It's not a metaverse, it's, it's AI now. So they it is like a moving goalpost.
Yes. It kind of redefine Well, they're just right. That's pure spin Again, actually.
Well, but guys, let me, I'm sorry. Go di Well, could I just point out what this company is essentially doing from, I like to simplify things. This company is essentially training AI data right now, because this whole concept of super intelligence, again, I look at the fundamentals fundamentally, when you have artificial intelligence, using my Dr.
Evil quotes, artificial intelligence requires models, it requires data, and it requires the tuning of these models with the data at hand. So when they're talking about, like, you know, when I read the articles, it's like, oh, they're talking about a child, how a child slowly learns No, what they're doing is they're talking about taking data, forcing it into their programs, and then figuring out how to tune and train their AI programs to anticipate the right data. Like you said, a ball being thrown up in the air.
What they're really doing is they're saying, okay, here's the trajectory of a ball. A person watches the ball intuitively and figures out where it's gonna land. What they're essentially doing is tuning their mathematical models to calculate where it's gonna land.
Now, to Alan's point again and again, this is a case where the have, where the haves are gonna beat out the have nots. And the reason that this is important is that Zuckerberg and everyone else are investing billions of dollars into pre-training these AI models so that they can better think. And the fact that they have these very well trained AI models, possibly definitely years, if not decades ahead of everyone else, is gonna make their models that much better in the future.
And everybody's going to either have to license them or catch up. Now I see Fred shaking his head. I don't know if I he agrees or disagrees.
Yeah. What I think is interesting is the way that we talk about the, the storyboard of what the mission is in these particular cases. Mm-hmm.
And so if you look at the mission for like anthropic, right? Which is to, you know, have a steerable interpretable ai, and you look at X AI is to understand the universe, you know, what meta wants to do basically is have a, you know, uh, uh, an AI assistant for every person on the planet. They're very different sort of goals.
So when you look at the overall outcomes, you know, IRA, a hundred percent, if you look at each of those organizations, their mission's based off of the data they have, for sure. But the in the intention behind that is the question mark that I have, right? These labs are, are, you know, uh, basically a supercomputing, uh, cold war that's happening right now.
And the characteristics of those things are how fast, which models, and then what's the value for the end user? I think the curious part there is going to be what happens after all of that data analysis has been, has been run through, and what does the democratization look like? Mm-hmm.
So on yesterday's show, guy Courier, our friend Guy Courier said something I re really made me think, and I thought about it a bunch yesterday and last night. You talk about their mission. Fred, let me tell you what could be another mission here that is not said out loud.
When you look at Zuck and you look at Elon Musk, and you look at, at the, you know, Larry and Serge from Google and Sam Altman and all these AI tech bros, Peter, Theo, the whole bunch of them, this whole cabal of tech bros, multi-billionaire, AI tech bros. Are they really doing this for the money? Are they doing it for the ego to say they were first?
Or are they doing it for immortality? Are they looking to set up systems that they could download into and live forever and it's gonna take, and that is the ultimate billionaires club, right? Is there, is there anybody I think there who thinks that, you know, training AI for intelligence based on humanity is kind of a fool's errand?
Because I'm like, is Well, no, because Facebook is trying to give it a human, a human touch because it, for them, it's about robot. They're going at, they're not looking to get developers developing more code or security, people making better security. They're looking to do humanoid robots, very humanistic sort of interface.
But make no mistake that that immortality is, is a thing. Yeah. And, and you're absolutely right.
Agree. They're, they're motivated by all, all of the above all agree, but especially the brutality angle. Sure.
Everybody has to live for others, but they have the money to actually try to, and they can Do it. Yeah. To try to do it.
And is that of a Hollywood kinda script, right? Anyway, let's take a break. We're gonna be back here on Textron Gang.
We've got one more poor Elmo. What happened to our little Elmo? com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. Hey folks, we're back in Poor Elmo.
Nobody's safe these days. He got hacked and was made to say all kinds of mean and nasty things. But Lisa, let's jump to you right away.
This feels like to me, like every marketer's nightmare. Oh, is this gonna become more commonplace? Yes.
You know, when you think about Elmo, he's lovable. He's furry, he's eternally three and a half years old. The, the picture, the face of innocence in the cyberspace.
He's been a force for good for Sesame Street since the 19 hundreds in recent years, he's become more cyber, obviously on X. But you know, what happened was really shocking. Many people, I, I thinks got about 650,000 followers on X and the Sesame Street workshop that runs it was absolutely shocked.
The Anti-Defamation League was shocked. Emma's account was hacked over the weekend, and it included a string of posts. They were racist, they were anti-Semitic messages criticizing the president calling for the release of the Epstein files.
I mean, it was really, really hot. And so now, now, while Sesame Street Workshop has addressed these quote disgusting anti-Semitic posts that were hacked, there's still screenshots out there. That's the challenge with things on the internet, is they can live forever.
There's about six screenshots in total that are going around. Sesame Street says the account is now secure. But what it shows is no one is safe.
You know, they, they went to something that is probably the essence of innocence on the internet and have it now. That also kind of reminded me of some of the gr troubling posts that we've seen just a couple weeks after XAI put a hold on the X account because Grok went crazy posting similar messages. It posted an apology, but still, um, yeah, but, But Grok wasn't hacked.
There's a difference. That's true. That's a good point.
No, Elmo was, was purely innocent and purely hacked. Right. And it just goes to show that parents need to know cyber and kids what parents need to do.
Um, and it's some of the basic things like multi-factor authentication. I don't know the specifics of what happened with Elmo's account, but it just goes to show that nobody's safe. Well, Could I jump in as the only person who's probably been personally targeted by the New York Wa, Washington Wa what was it?
The Wall Street Journal? Um, if you go ahead. This is, there's zero new to this in the first place.
Kids who will follow Elmo shouldn't be on Twitter anyway. That's they, you know, like 13 years old. This is like, oh my God, Elmo, I, I don't think Elmo's the icon of innocence.
I mean, Elmo was manhandled by a sexual predator for a while. This is not shocking in any way, shape, or form, but let's look at what happened. We're talking about the takeover of Twitter accounts, which is not new at all when you go back and search for ever all the listeners, uh, while you're listening, Google Iber, Winkler Syrian Electronic Army and Cockroach.
And you will see that the Syrian electronic army targeted me personally. I was told by the FBI, they hated me more than Obama, by the way. And they hacked the Wall Street Journal Twitter feeds to call me a cockroach.
They hacked Buzzfeeds Twitter feeds to call me a cockroach accounts, which are much larger. They hacked the Associated Press Twitter feed at one point in time saying that there was an attack on the White House, which moved the stock market. So what we are talking about fundamentally are attacks against personal accounts.
And even the DOD accounts were hacked in the past. So what we are talking about is an identity compromise because of a lack of multifactor authentication, sharing of accounts, and a bunch of other stuff. How Elmo was hacked.
It's probably the same thing. They guessed the password or some or comp phish to password more likely, and were able to go ahead and hack. But the bigger lesson is not poor Elmo.
I mean, anybo, anybody on Twitter who's looking at Elmo, you're not looking at him for serious motivational, good warm, fuzzy feelings. In general, if you ask me, it's kind of a get a joke account, but it's just a sign that there are much more critical accounts. I mean, Trump is using Twitter as public policy, which to me is horrifying.
But at the same time, his account was hacked in the past. You know, you had Biden's account hacked in the past. You had all these other people's accounts who were hacked.
And we have to learn, yes, we need security, but we also need to learn, wait a second, what it goes on on these accounts might not really be what is going on on these accounts. And it requires public perception, public awareness that Twitter is not an authoritative source on that identity, even though you think it should be. You mean if I don't pay Elon the money to get the check mark in everything, I'm, I thought if you did that, you are secure.
I can probably pay for a check mark and start an Alan Shimmer account for you if you want a check mark. And Ill be happy to, to tweet out. Should I would disagree with Ira on one point.
I think it might be helpful for adults to check in with Elmo every morning. 'cause you know, it just levels you out and maybe makes you a better person. But let me ask a question.
So Elma was a victim of abuse and manhandled. I I thought it was Cookie Monster. No, It was not.
It might have been the same one. De I has two hands, remember that? No, I mean, look, this is, you know, I filed this under why we can't have nice things.
Mm-hmm. Right? Whether you think Elmo should have an account and how much you believe in Elmo Santa Clauses and the Tooth Fairy, the fact that, you know, people will use these accounts to spout this kind of garbage.
And like it or not, there are miners on the internet. They are on X and they're gonna see it and eh, you know, this is very nice people. Hey, you're, I guess that means you're not anybody till you get your account hack is that I was hacked Black Hack 2005, also anti-Semitic stuff, and it was pornography, it was all kinds of nonsense.
And I had to get all my emails back. I know Fred, you knew me then. You might probably remember.
Yeah. Um, what a pain in the ass out what's, but anyway, it, it, yeah. It's not fun.
It's not fun. And, you know, I found out who hacked me and he's in jail now, not for hacking me, but he deserves to be in jail. Wow.
Um, anyway, poor Elmo, you know, but look, shock and all, as Iris says, Elmo's really kind of the tip of the iceberg here. Yeah. Somebody better protect big bird.
That's all I gotta say. And Grover, let's not forget Grover. Grover.
Grover. Grover's. Awesome.
Poor Grover. All Right. I don't, Guys, There's more lessons from Oscar the Grouch.
If you ask me Oscar, the Oscar was definitely a person. Guys, we, we gotta we gotta pull the plug on this Great Friday. Lisa, thanks for joining in.
I know you had some technical difficulties and we appreciate you fighting through those rest of my gang members. Enjoy the, the cool Northwestern weather up in Seattle, out in the West Coast or Lake Placid or whatever you are. Mm-hmm.
Of course, we're roasting here in, uh, south Florida, but we do have a full tech, strong TV lineup immediately following the gang today. Check that out. We'll be back Monday with lots more new good stuff.
Enjoy the weekend. We're out. Hey everyone, welcome back here to Tech Trunk tv.
Our next guest on techron tv today is Casey Kinder. Casey is the founder and CEO of a company called Rock Stream. Let's welcome him.
Casey, you're on Tech Trunk tv. Thanks for being here. Thanks For having me, Alan.
So, as I mentioned, you are the founder and CEO of Rock Stream. I always like to explore what drove you to this crazy level of craziness to go out and found a company and, and, you know, try to make a go of it here. And I don't have to tell you every day's a battle, right?
You breathe life into this every day as a founder, especially as CEO. Give people a sense of your background and, and how you wound up here. Yeah, sounds good, Alan.
So I think really there are three things that led me to, uh, where we are today. Um, number one is, uh, I'm a, I'm a math guy. I was a, a math major and, uh, undergrad at U Chicago.
Um, I like solving hard problems. It's sort of just what it's, it excites me. It's what kind of keeps me going every day.
Um, and, uh, the, the second thing I guess is I started my career at Deloitte Consulting, just kind of, uh, you know, as many, uh, quant focused people do in the consulting industry. And, but I got really fortunate and I, I landed in Silicon Valley on a project or on multiple projects when Silicon Valley was really just building out the, the, you know, sort of the first generation, the first wave of large scale infrastructure buildouts. And, and it, it's, it's sparked something and made the complexity of it, the excitement of it, the energy of it.
Um, you know, I was there for just a couple of years before I started my first company. Um, you know, what it gave me was a, a grounding and a problem that I thought was really, really interesting and wasn't going to be easy to solve. And that is, how do we manage the complexity that is inherent in the, this evolving it and network infrastructure that really powers our world today.
Um, that problem, you know, excited me 20 years ago. And, um, I, I'm even more excited today because I think we're we're closer than ever to really getting our arms around the solution. Absolutely.
So this is one of these overnight sensations that's 20 years in the making, huh? Well, I mean, yeah. I mean, you know, I, I, this is my third company, you know, I had two hypotheses prior to this on what it would take to solve the, you know, that foundation problem.
And each iteration, sort of the problem domain has shifted and, and the complexity level has grown. And with the, the advent of ai, I started, you know, down this path about eight years ago with a, a small research team with a real simple problem. Okay?
Now, we've, we've attacked, we've attacked the problem in a couple different ways. Um, I won't go into the details of the prior hypotheses, but the, you know, um, you know, our, our fundamental goals starting at Rock Stream was we're gonna, we're gonna harness machine learning and AI to solve all of the problems that were intractable for us in our prior to, to runs it the problem. And, um, and that really was the goal.
So I, you know, had a small team of researchers started to identify what the, what the kind of underlying problems are and attacking it with, uh, with AI and machine learning algorithms. Excellent. Casey, you know, you know the old saying you can't make wine before it's time.
Right? And, and, and I agree with you, right? So many problems.
And I like you, I've als I've been in tech 30 plus years, infrastructure, uh, security mostly. And yeah, I look back at problems that seemed insurmountable then that are kind of common, you know, table stakes today. But yet, you know, things keep getting more complex and new problems.
And much like in the book, the goal, you ever read the goal, right? As soon as you solve one bottleneck, the next bottleneck presents itself, right? And that's kind where we are today.
AI has, you know, a crazy potential to help us. It also has crazy potential to make yet more headaches for us. Right.
Um, talk a little about Gro you said you, you gave us the setup into GR stream, but as it existed, they give, give our audience a sense of where it's at, what it's doing mission wise and stuff like that. Yeah. And, and the mission is really simple for us.
It's so without AI and machine learning, large, complex IT, and network infrastructures with cloud overlaid, um, in order to keep that up and running and optimal and delivering the services that continue to evolve on top of that, um, requires a large number of, of engineers doing operational tasks to keep the lights on, to keep the systems up and running and optimal, right? Um, our, our goal really is fundamentally to reduce the amount of effort required to do upkeep and respond, you know, respond to incidents and fix problems and allow more of that talent to do innovative tasks. So what we've built is a, a cognitive AI architecture that consumes sensory data, basically telemetry data, everything that's happening in, in the environment, in the, you know, um, com complex web of network data centers that drive an enterprise, um, set of services.
And we take all that telemetry data, we process it through a series of algorithms, each of which a distinct learning algorithm from their own sort of research domains. Um, and at the end of that, we predict when an incident is going to occur. We allow for, um, operations engineers to, to prevent any occurrence, any similar occurrence in the future.
So they don't fix the same problem twice. They don't have to do the same maintenance task over and over again. And, um, once the system has evolved with the team and they're sort of functioning well, um, it takes on more and more of that operational repetitive work for the support teams.
So, DevOps teams do less ops, more dev, um, network teams, do more engineering, less operational support and so on. That's fundamentally what we do. We process it through a series of algorithms.
We enable automated action at the end of that that's intelligent. That is, you know, isn't a set of, of rules that have been built, uh, you know, a runbook that's been coded, but rather a, an intelligent response system based on learning algorithms. Love it.
Love it. You know, we didn't even mention the URL people who want to go explore this themselves. Where, what's the best way?
dot com or? com. G-R-O-K-S-T-R-E-A-M.
Just like it's spelled underneath your name here on the video on the lower third. Alright, Casey, let's shift gears. You guys recently re, uh, announced a new release, grs, excuse me, grok predictive IT operations, uh, provides IT operations service management teams with an AIOps platform that continuously learns and adapts self-healing.
That's always been a kind of holy grail. Um, talk to us about rock predictive IT ops. Yeah, so I'll, I'll just say that the first, the first rung of the ladder that we had to, we had to climb up was, um, making our systems smart enough to respond quickly when a problem occurs, when something happens in the environment that requires action to be taken.
So the kind of the first step is to understood, kind of sift through the noise that telemetry data, and figure out what is actionable, what's actually just the shift in the system redundancy exists in all of these, um, you know, large networks and, you know, bubble up what act what requires action and respond appropriately to that signal to, to fix something, to restart a service, to create a ticket and dispatch it to an engineer, whatever that is. So, still reactive, but just fast and dynamic. That was kind of the first rung of the ladder.
And what we've been working on for the last several years on the research team is, okay, so we've, we've gotten, you know, the, the problem has always been, you know, in our space we wanna go from ro reactive to proactive. So step one was to solve the problem with ai, the, the reactive problem with AI to relieve some of that pressure from operations teams. Um, and the second part of that problem is forget about reaction.
We actually want to stop the problems before they occur. And, um, and, and we do that in several ways. I would say, let's say three, three ways.
One is we have a predictive algorithm that monitors the, the, uh, the occurrence of incident patterns in the environment and the operational data that kind of precedes those incident patterns. And it predicts when an incident's going to occur, well then we can kind of fine tune the timeframe, but say 8, 12, 24, 36 hours. Instead, there's a high likelihood that this particular incident is going to occur, this problem in the environment's going to occur.
So let's go out and take action to prevent that. So, you know, rather than waiting until something breaks and dispatching an engineer to fix it. Um, so that's number one.
Number two is we can observe the, the pattern of occurrences. So the problems that have happened over a long period of time, we can surface the, this pattern in a, uh, an actionable list. Think of it as an automation pipeline.
Things that are sucking energy from our high value engineers, requiring them to do operational tasks over a period of time listed out and, and identify what items on that list ought to be, uh, automated. What can we do to automate each of those, those items to prevent them from occurring in the future? So that's the second poll on the tent.
And the third poll is enabling our, um, language models to process the information, apply reasoning, and take autonomous action to prevent the issues from happening in the future. And, you know, those three polls in our, our preventative and predictive tent allow us to really kind of take it once and for all from being reactive to being fundamentally proactive and predictive. Agreed.
com website and it's right there on front. It Is. And we have some great videos too.
I mean, I, I think it's, it's tough for folks to, you know, read a whole lot of text content these days. So I would encourage you, and we're we're, That's why we're on here, my friend deny I didn't do this as a written q and a. Yeah.
And we're working, that's an understatement of, We're working really hard to produce videos that not, don't just talk about what we do, but actually show you a lot interactive. So you can click on things and see how our user experience matches with the kind of the value that we deliver. And that's the, be that, that's sort of the really important when it, when it comes to, uh, AI powered systems because a lot of, you know, a lot of folks will deliver products and the AI is so deep under the covers that you don't really know what's, what's a rule?
What's just a rule that's been coded versus what's a predictive model? What's a, and the reason that's important is because, you know, if it's a rule, it doesn't evolve. And all, you know, every environment changes, every company changes rapidly.
And if you don't have learning algorithms kind of producing the output, then you know, it's only gonna work for a short amount, amount of time. That really is so key to the whole look, even before ai, you know, it, the time crunch is continuously accelerating, it seems. Right?
And what worked two years ago certainly doesn't work today. It's ancient history. Um, but, you know, you mentioned what people like, we, we do the same thing.
You know, we do do maybe 400 webinars a year and we survey our audience, what do you like, what don't you like consistently? Their favorite type of, we call a webinar a learning experience. Their favorite type of learning experience are hands-on demos.
Not, not a PowerPoint with, with screenshots of a product, but actually logging in and following along how the product actually does what it's doing, what, what, how do you do it? And they love this. And, and it's almost counterintuitive because it's very vendor specific.
It's very product specific. But they'd rather do that than listen to a talking head with a bunch of slides. Yeah.
You know, narrating the slides. So I, I agree with you. That is, that's what people like today of, of course, you know, get it all done in seven and a half minutes, because that's kind of the attention span.
But um, right. You gotta break it up into pieces. Yep.
I mean, we're human humans learn with Our hands. We're tactile creatures we have to touch in order to really learn That. That's, I think that's it right there case.
Alrighty. Hey man, thanks for coming up here on Text Drunk tv. This was great.
I appreciate it. com, check 'em out. We're here on Text Drunk tv.
We're gonna take a break. We'll be right back. Hey guys, thanks for the thrill.
We're here with Daniel Tomek, who's the CEO for Cipher, and we're talking about robots and security. 'cause while they're gonna be everywhere soon, but I'm not quite clear if we thought through exactly how all these things might not just be another thing that someone's gonna try to hack into. Daniel, welcome to show.
Thank you very much. Thanks for having me on. Robots are kind of starting to show up, and maybe they'll soon be pervasively employed and who knows, they might even be running around our houses soon.
But, um, are we in a situation once again where we seem to have created yet a new cool it thing and we're thinking about securing it later? Yeah, I, I, and I think it all comes down to what's, uh, in the background of development of this devices. Uh, just like we have seen the, you know, BYOD, we've seen the IOT devices, right?
Uh, come into both commercial and personal space. I think robots are the next phase. I mean, for one side, it's a, it's a wonderful thing, but it does add another portal to think about in terms of security and access to data.
So does that mean we need to worry about, I don't know, uh, maybe there's a robot someday that's doing my chores and somebody hacked into it, and the next thing you know, it's chasing me around the house with a knife, or how's that gonna play out? You know, again, you, you never know. I think we'll have seen, uh, quite a bit of a sci-fi, uh, flicks out there that, uh, sometimes have a gloom and doom about them.
Um, I think when you look at robots and, uh, we've actually done quite a few, uh, security assessments on various robotics and mechanisms and so on. In the end of the day, um, a robot is just like a technical device out there. Let it be a phone, uh, a server, right?
Uh, an IOT type device, a toaster that communicates to you, you know, when the bread is ready or sends you a, a, a signal that it's ready. I think what's important is, is actually looking at the inheritance connection, the internal connection of that device. You know, in this case being a robot, how it's programmed, how it's actually receives information, and what are the protocols that are being used, uh, to protect that actual access of data with a response and an action.
Uh, that's really a robot. I mean, really the only difference between a robot and a toaster is a robot is actually gonna be mobile and can move around, uh, and can potentially have some kind of, uh, uh, you know, a, a physical action versus a toaster, right? Mm-hmm.
At the end of the day, is this just another instance of needing to protect our software supply chains? 'cause the robots ultimately will be built using software, and a lot of the software, unfortunately, that we use today to build things has no vulnerabilities in it, and they get inherited. And now we have dependencies that will show up in our robots.
But do we just need to kind of think through the way we're managing the software supply chain for these things? That is, that is a great point. And to me, again, you know, whenever, uh, you know, we conduct an assessment, we always go back to that actual supply chain, right?
What is the actual chip, uh, what is the actual item that controls the actions of the robot? What data that is stored? Does it communicate this data anywhere?
Right? So these are what I would call the pillars, uh, of any of, uh, or any, any, anything robotic that will have, uh, a decision making capability or an action oriented, uh, basically steps. You're, you're dead on.
Yeah. It also seems to me like, and I'm not sure what the robotic equivalent of a password is gonna be, but at some point somebody needs to log into these things or control these things, and we kind of suck at protecting passwords today. So what are we gonna do about robots?
Yeah. When you look at the, I would say about 85% of the, uh, robots that are out there, they're all driven by, uh, a particular programming, right? And so on, uh, all of them so far.
Uh, and I'm talking about robots that are not free-willed, right? I'm not going too far into the future, uh, where they kind of have a full AI automation to them to make their own decisions. But 85% of the, of the robots that are, are in the workforce or entering the, uh, the residential commercial type space, they're all programmed by a panel, by a control panel, right?
A fancy gui, uh, where you can actually come and enter, you'll have a username password, and you program a set of things that this robot is actually gonna conduct. Uh, you're absolutely right, Michael. We, we are horrible with keeping passwords.
Uh, so, but we're gonna have to get better at what we do, uh, also, uh, in, you know, add encryption into our passwords and have an ability to protect ourselves better. But a lot of these devices are all still with what I call an admin password usage profile. Mm-hmm.
I'm also assuming the robots are gonna talk to each other and communicate the kind of complete some kind of task or in tandem with one another. Um, but if I have one that's compromised, then it will pass along whatever malware it has to the other one potentially. So am I gonna need like, the equivalent of a robot firewall?
How does that look? Yeah, no, great question. I, I feel today let it be in the workspace or at home.
Um, a lot of those robots are basically connected on the network, so it adds like another device on the network that's inherently how they've been operating so far. Um, there is, uh, early tests have shown that there is spread of malware, just like any type of, uh, a device out there. Uh, one of the most important parts is really to keep them enclosed within a network and what information actually gets accessed the robot, uh, externally.
Uh, otherwise we can have, uh, quite a bit of a spread of, of malware, viruses, or particular attacks on a vulnerability within this, um, this ecosystem. Uh, I don't think you would require an additional, you know, robot firewall. I think it's about protecting the actual network where the robot actually operates.
Uh, so as long as that network is protected, uh, your devices on it, including the robot will be, will be protected. Hmm. Who's thinking about this stuff right now?
Because the number of people that I know about robotics is few, and there's maybe more people I know who know something about cybersecurity, but the number of people who know something about security and robotics probably wouldn't fit inside the room. I mean, yeah, yeah. No, no.
Great, great point. Um, you know, I, I, I'll say this, um, and it, I, it sometimes gets frowned upon in the industry, but I feel sometimes cybersecurity is an afterthought. Uh, there's more concern about functionality and, you know, going from point A to point B, uh, I believe proper cybersecurity hygiene should include that at the core of the programming and the core of the asset versus leaving it, you know, as an afterthought for somebody else to worry about it.
Um, we have seen definitely situations where, um, devices, uh, were breached, uh, because of a non vulnerability inside, inside the device, uh, all going back to a, a chip or a functionality, right? And, uh, the manufacturers kind of comment on that, well, you know, that was not our problem. It kind of needs your problem once it's in your network.
Um, so I believe, um, just as industry, we need to collaborate better and, and really make cybersecurity at the pillars of any type of a device that is out there. It's, I I find it's everybody's problem, right? Mm-hmm.
So to your point, we have a shared responsibility model in the cloud that's kinda worked for the most part, but, you know, there are still issues there. Um, is it, are we gonna have the same kind of thing with robots? I mean, it's gonna be kind my responsibility to secure once I get it, but there'll be some fundamental security built into the infrastructure.
How will that balance get struck? I, I think it's getting better, but the early versions have definitely really been left to, Hey, you kind of gotta deal with this. Uh, and so on.
Uh, I think it's getting better. I, I believe we still have quite a bit of work to do, uh, to get to, to that, uh, that level of maturity that, you know, when a product is placed somewhere, there's already pre protections, uh, are available with that versus leaving it again to the consumer, the, the owner, the business to actually deal with that and create another layer. Um, we definitely have some work to do.
Yeah. Mm-hmm. It feels like to me that the scenario is probably gonna play out something to the effect of somewhere there's gonna be some robot that gets hacked somewhere and some mayhem will ensue.
And, um, that may set the whole industry back though, in this case. Right. And that's different than, say, the cloud, where if I had an incident, it, it wasn't kinda catastrophic to the entire industry 'cause it didn't show up everywhere on the front page.
But I feel like ro robots, we need to get this right from the get go. Is that fair? Uh, that's a, that's a a a very important statement you made, you know, uh, several years ago, um, you probably, and, and, and I'll, I'll keep the name anonymous, uh, is, you know, there were a bunch of, uh, toys, uh, that were basically breached, right?
Uh, from nanny camps to children toys and so on. What we need to understand is that, again, unfortunately our industry is driven by risk. Um, and only, you know, once something actually occurred, you know, the manufacturers get into a next phase and say, Hey, how do we de-risk ourselves because we don't want the litigation and we don't want the reputational losses out there.
So, un un unfortunately, that does drive a, a, a more positive outcome. Unfortunately, it does have, uh, some consequences to it. And, and robots are not any different.
I just believe that it, I think it's critical, uh, for any robot out there, which is kind of the next level of consumer and business goods and assets that operate, that they need to come with pre-packaged assurance and security before kind of getting plugged in and integrated into the system, into the force, into the operation. Mm-hmm. Are there gonna be regulations in this space?
Are they, are people talking about that yet? Or is it still too early? Or do the folks who make the regulations don't really understand the issue?
Yeah, it's a little early. There's definitely some things that are in early stages in terms of, uh, regulations and so on. Uh, you know, what I call lessons learned from other incidents, like, you know, like the toys and cameras that are being breached and, and other items that are made overseas and, you know, added the levels of protections out there.
Um, like recently, we have seen, um, uh, a very large network of, uh, of cameras by a very particular organization from overseas that was literally, uh, uh, it's been communicated that these assets are no longer allowed to operate, for example, in the us. Um, I believe the same thing is gonna happen with robots where, uh, consumers, businesses are gonna want their assurance, uh, that there's a certain level of protection, um, you know, as you leveraging and using this assets. Mm-hmm.
Do you think some of the stuff that we're talking about in terms of securing AI will carry over here? Because I might argue that an AI agent is really a type of robot, and we need to secure that. And so if an AI agent is a, a software robot, well, the next step is a hardware robot.
Follow me? Yeah, no, no, that's a, that's a great point. Uh, we'll, definitely, I, when I look at robots and, and this type of automated type devices assets, uh, they're always gonna split into two.
Uh, one of them is gonna be, you know, here are the six functions this assets does day in, day out, day in, day out. And once in a while, somebody walks in with, uh, some sort of a USB and, you know, upgrades the, the firmware. Uh, and then we're gonna have a class of assets that are gonna be AI driven, and, uh, they're gonna have, uh, a little bit more intelligence and decision making power.
And, um, those are the ones I think we're gonna have to worry a little bit more. Uh, as you know, we're kind of looking for them to be intelligent and learn, um, but you know, what will fit and what will not fit into our expectations. Mm.
So what is your best advice then, where we are now for folks as they kind of look at this? We can all see this future coming. What should we be doing today to get ready to secure it tomorrow?
Yeah, I think it's very important, once any type of a robotic asset is added into an infrastructure, into a network, uh, is really to better understand how your actual network is protected. To me, that is the first layer of protection. And number two, better understand, um, you know, what is the actual functions of this robot, this asset, uh, and what it can do, what it cannot do.
That is very, very important. I feel those days of, oh my God, this looks really convenient. Let me just plug it in and see what happens.
We really have to think twice about that, right? I think there's some wonderful benefits with this assets, uh, both from convenience and assistance and so on. But we definitely have to have the thought process of what happens if I lose control of this asset, right?
And these are the reasons. Um, so I believe we have to be proactive about that. Um, I believe that we should also be, uh, setting, um, a a stage setting a certain expectations from the manufacturers to provide assurance to us as consumers, as businesses that, you know, this is what they have done.
And this is kind of their protocols or their strategy, their compliance, uh, with these devices. And it comes around data actions, right? The communication of data out of the network, uh, which sometimes these devices need to be consistently upgraded.
So we just gotta ask the right questions. All right. Well, folks, I heard it here.
I think, if I'm not mistaken, one of the first laws of robotics is not to hurt the humans. The challenge is we gotta make sure the robots know that. Hey, dang, thanks for being on the show.
Thank you very much. Thanks for having me on. All right.
And back to you guys in the studio. Welcome to the AI Security Edge. I'm your host, Caroline Wong, tech Strong TV podcasts feature your favorite video series, industry thought leader, commentary and analyst research on DevOps, security cloud native and digital transformation.
In a podcast format, AI is revolutionizing cybersecurity, both as a weapon for attackers and a shield for defenders. Our podcast, the AI security Edge, dives deep into the evolving cyber battlefield, where AI driven threats, challenge traditional defenses and cutting edge AI solutions offer new ways to fight back. This podcast explores real world case studies, expert insights and practical strategies for building cyber resilience.
In an AI powered world, you might be a security leader, a practitioner, or an AI enthusiast. In any case, I'm confident that here with us, you'll gain valuable knowledge on the risks, innovations, and ethical considerations shaping the future of digital defense. Today's guest is someone you'll definitely want to hear from.
Jill. Ro is currently leading the tech team at Data Dom, where he is building the systems that protect apps, websites, and APIs from bots and online fraud. If you have ever wondered how companies stay one step ahead of automated threats, Gils is right at the center of that fight.
He has deep expertise across cybersecurity, machine learning, and distributed systems, and he's fluent in more programming languages than most of us have. Browser tabs, open, modern c plus plus, Python, JavaScript, Ruby, you name it. But what really stands out is how he brings all that technical depth into real world impact leading teams, defining product vision and scaling technology to meet the pace of modern threats.
Today we're gonna dive into some really fun topics, including how bot mitigation works behind the scenes, what it takes to build accurate, real-time fraud defenses, and how to stay innovative when the threat landscape never stops evolving. Let's go ahead and get into it. Welcome to the S show, Gils.
We're so happy to have you here. Thank you, Caroline. Nice To be here.
Tell, tell our audience how to pronounce your full name correctly, please. It's a French name, so it's Gil. Beautiful.
Thank you so much. Gils. Let's start off with this.
What is your experience with ai, both personally as well as professionally? So, I'm using AI for years now. I've been, uh, you know, trained when I was a student about ai, especially, you know, our network and all of of the technology we had at that time that we're not able to scale as we have today.
Today I'm very excited to use AI on a daily basis. Um, I'm using, uh, generic especially to, uh, generic content, for example, when I want, you know, to, uh, start with an id, uh, and generate contents, uh, triggering new ideas, uh, on your mind. So I like this kind of ideation process, uh, where you can, uh, easily generic content and be surprised by the things that you can see from getting out from the AI here.
So I'm using it, uh, personally here for my personal life. Also for the, for the work and, uh, sometimes to have ideation processes with the team. Uh, as well.
I also use ai, uh, now for morning routines. 'cause it's a, it's a good tool nowadays to have, uh, um, automation here. It's easy to build automation with AI nowadays.
Uh, like, you know, getting the latest trends of something, um, especially for my work security issues, uh, the top of the current security issues or, uh, to quickly summarize, uh, things like, especially research papers. Uh, I don't have the time anymore to read all the research papers. I would, uh, like, so, uh, the new, uh, operators with, uh, with here on the markets are now are able to retrieve the sources so you can, uh, summarize them and, uh, access to the whole content if you want.
So it's really nice and fun to have this kind of morning routines with the content, uh, that's pushed, uh, can craft the content to be pushed and it's pushed, uh, to you every morning. So I really like it. Um, I'm also using AI to generate code, for sure, uh, not for production.
Um, but I'm using it to generate, generate, you know, POCs or, uh, small steps, uh, of, um, of testers or ideas that I would love to, uh, to, to try. As you mentioned, I'm fluent in a lot of languages, but, uh, we are building a software for a lot of different stacks, so having the ability to generate the right, uh, code for the right stack is really, uh, saving me a lot of time here. And it's not production facing, so I can tweak it, I can play with it, and then I move, uh, move forward.
Uh, I'm not so much into audio or video, uh, picture generation, uh, feels like a toy to me. I like to, uh, to play with it, uh, with my kids, you know, uh, to, to craft new stories. I, uh, even doing, did that to, uh, design stories for the kids.
Uh, but for me, it's tour, you know, I'm, I'm, I don't use it for work on a daily basis. Uh, I'm mostly used, uh, gene AI and, uh, new AI stuff to, uh, to generate, uh, content and to think about new ideas. That's so awesome.
Um, you know, Gils, I'd love to double click on one topic that you brought up, which is that you are a person who knows hands-on how to code in so many different languages. Mm-hmm. And you mentioned specifically that you are using AI to help you generate code, not for production, but for POCs and for some small stubs.
And I wonder if you can tell our listeners a little bit more about that. You know, what happens, you know, you've got an idea you wanna try out, uh, you, you generate the POC, uh, and then what, what is, what is the process for, for you and your team to take kind of something that might start out as AI generated code, and then what does that process look like to get to kind of a production phase? Let's take one example then.
Uh, if we want to, um, to try to, uh, simulate a volumetric attack, for example. So I will, uh, to debug, uh, an issue or to test a limit on, uh, new kind of stack will support. So I will, uh, ask the generate, generate, like, for example, LU code, uh, for a given stack.
Uh, it'll generate the right, um, code given the constraint I will given. So, uh, for example, I, I want to, uh, I want to, um, create HDP request with this kind of, uh, different, uh, headers, volume, et cetera. And the AI will generate the right syntax for the language, but if I just pick it and plug it inside the system, it'll fail because probably it'll miss some built-ins, basic features, basic, uh, APIs that will, uh, miss for this environments.
So generally, when we have JavaScript generation, lu generation, it'll expect you'll have some kind of environments you may not have in this kind of systems. So it's really nice for me. Then, let me take an example.
I want to forge, uh, p request, and I want to u on code something I'm missing. The features I can have the generic to, uh, to generate, uh, nice and short u on code function, not production ready. Once again, probably it'll miss a lot of edge cases here, but I don't care for this test.
Uh, it's in a few seconds. I can, uh, probably feel it, you know, and run it, uh, as expected, run my test, and then once again, move forward. So that's the, you know, the ideation I have.
And, uh, at the end, what I want to extract value from it, like to deliver it as a test, for example, then I can, uh, generalize the, the code. Uh, in general, I'm seeing patterns I don't like in the outcome of the, the, of the gene ai. So just get rid of it, uh, replace it with my knowledge and, uh, for example, at some parameters to, uh, to make the function free, uh, free, uh, uh, available.
So that's the kind of process we have. So it's, uh, really generate a basic, uh, basic structure and then, uh, start to, uh, iterate like we would do as a normal code if you were to create such a code. Yeah, that's incredible.
Thank you so much for sharing that with our listeners. Um, ails, I wanna move on to kind of our next topic, which is how AI is helping attackers. Um, I think in your role and with your team and the work that you do, certainly you have a front row seat to exactly this.
Um, and I'd love for you to tell us a little bit about what are you seeing and how are things changing? To be honest, that's a game changer. It's a small one today.
Uh, good news, it's, it's still early. Uh, technology is not available to everybody. Uh, it's costly at some point.
So, uh, we can see only a smaller subset of the traffic today being impacted by the ai, uh, part at least. But AI power attacks are definitely a game changer in the, in the field. So how the foster are leveraging such technologies, uh, it's, um, making them, um, um, a able to, uh, craft new kinds of attacks, especially for our job.
You know, the, we have a behavioral, um, uh, engine to analyze the, the behavior of the attack, for example. That's how we can fingerprint the behavior of an attack in general. Uh, the, what we'll see on the market is static, uh, thing that's are relying on static rules.
You match the rule or you don't match the rule. If you match the rule, you'll be blocked. Otherwise, it will be a road.
Attackers know that. So, uh, they want to, uh, try to find the right combination of headers, payload that they will, uh, that, uh, allow us, allow them to, uh, get through. So what they're doing, they're putting in place and automate that will generate such things.
Making, try, try, try and fail, try, try. And then they will, uh, slip through. Then they will, uh, what we can see, they will keep these kind of signatures, continue this kind of trend, a small trend to, uh, try to forge the signatures.
And they will leverage signature one by one. Generally, you can find on market system that will detect such elementary volumetric attacks. They will try to, uh, create a signature and block them.
Then it's too late. They will just rotate and use the next signature they found. So it's, this was, uh, possible before with a human code that will try to hack it, and you can, you, you could feel, you know, when you, when you block the traffic, you can feel that, uh, it's a human behavior in front of you that will try to, uh, to find the right combination.
Now we can feel that it's ai, it's, uh, fully automated. So the, the game changer is time, time to adapt, time to, uh, needed to find this kind of combinations. And, uh, to be able to scale an attack.
That's, that's really game changing. Uh, we can see on the, on the market, especially for the, for this kind of complex attacks. And, uh, they try to evade every detection system you can find and try to mimic human behavior as much as possible.
Next thing we can see, we can see on the film is every system that are in, uh, charge of, uh, securing an endpoint, one of them is captures and captures. We can see, we could see that, uh, we moved from human, uh, real human passing. The captures like capture forms, you know, uh, to, uh, fully automated, uh, on capture systems.
And same here. They're trying to find the right combination to forge the, the right signature to try to pass the capture. And we can see as well, uh, computer vision aided system, or where they, uh, they will locate in, they will locate the right, uh, challenge and try to pass it with ai.
So that's, that's a game changer as well. And, uh, the price, uh, and the cost to pass such systems, decrease the loss thanks to ai. Once again, the scale and the cost, hence, lots of systems bought as a service on capture service you can find on the market that are packaged to bring, to bring you a, a way to evade a specific, uh, protection system for a vendor.
If you want to buy a limited edition product, for example, uh, or to access something on a, on a website. So we can see a lots of that. And, uh, that's something we want to bring to the customers, uh, more and more often, uh, to show them the kind of attackers they have in front of them, and to tell them, this is what we blocked.
So to connect the dot between, uh, what they saw, what they feel, and what we are able to know in terms of threat intel plus, uh, signatures of what we blocked. Wow. You know, I have a, I have a funny little joke, uh, to share, which is, as a human, I often encounter captions.
Yeah, for sure. Uh, and sometimes they're hard, you know, sometimes really hard. Sometimes I cannot read the letters.
I cannot tell what numbers it is. Sometimes I cannot find all the bicycles or all the bridges. Mm-hmm.
You know, and so, uh, my funny joke is, uh, maybe I should be, uh, using AI, or maybe I should be, uh, using a service, you know, uh, capcha farm, you know, um, ask some folks, uh, who live in a part of the world where, uh, you know, this is a type of service that they can provide. Maybe, maybe I should hire them so that I can in fact, uh, bypass my own caps that I, that I experienced as a user. Um, so that's just a, that's just a silly, silly joke.
And bots are better than you to pass the capture. It's, uh, it's no joke, you know? So it's, uh, it's frustrating.
I, I have the same experience, uh, here. So to be presented with a capture, it feels like, uh, gate you need to pass, uh, to show that your real person is not, uh, the best re chance in the world. So what we did at, at Data Home is to, uh, expose this kind of challenge.
We have a very simple capture puzzle game. Uh, and it's, the security is not the challenge itself. It's an easy challenge.
Security is how the, the how we are collecting the data, uh, while you are passing the capture. So we present the capture only if we think you are a bot, Ah, Way to validate you if you, if we think you are a bot. And at some point, I, I would love to put my fingerprint somewhere to say, I don't want any capture anymore.
Take my blood, take my fingerprints, and through them, and I, my blood Don't make me do a capture. I'm a human. And you know, what I feel at some point with all the gene AI hype, we can see with the open AI operators, all the agents we can see on the market today, I'm basically sure at some point we'll have to do it for the bots, for the agent you will have that will, uh, act as yourself on the web.
So I feel at some point, maybe not the blood, or maybe not the fingerprint, but at some point, you'll, you'll tell this thing, this is me, and this, this thing is acting as me. So, uh, let's, uh, make this thing go through on the website, because it'll bring with business. And that's one of the big concerns here.
Uh, for the, uh, eCommerce website, all the vendors that are exposing, uh, business on the, on the web, what should we do with the AI agents? Is it bad? Is it good?
Is it between? So how we can see where they are, how we can fill them, and how we can hack on them. You know what, that's exactly what we did with the bots.
So it's be, thanks to behavioral analysis, we can do that. So it's not a matter of your headless chrome or not, probably it will, uh, open your period. It's based on it.
So it's bot okay. But it's a good one that will bring good business, not hurt your business. So you have to be able to have a signature on it, not based on the network necessarily, but based on the behavior it'll have.
And that's one of the key technology we have, mixing those two things to be able to analyze the behavior and create the right pattern to, uh, identify this kind of traffic. This is all automated and this is what, what, uh, why we can scale and block this kind of attackers. They have ai, so we do, but ours is better.
So we can, uh, and at scale, you know, we have all the data, uh, of the traffic worldwide, so we are able to identify the right patterns in the whole traffic. So that's why we can do sometimes a better job than our own, uh, customers, because we have a wider scope in term of traffic that's a key asset, uh, in this field. Wow.
You know, this is a, this is a relatively new concept for me to consider, right? Because of course, for a long time we are thinking about bot versus human, which is which. Mm-hmm.
But now with this introduction of like a new character into the story, right? Human or good bot, or bad bot. Mm-hmm.
Uh, and, and perhaps more accurately bought, which is intended for legitimate use mm-hmm. Versus bought, which is intended for malicious use. And so I think that's, um, that's so fascinating.
You know, Gils as a, as a, as a final question for today, uh, and you gave us a bit of a preview. You said the attackers are using AI and we are also using ai and our i AI is better. And tell me more about that.
How, how is AI helping cyber professionals cybersecurity defenders? In lots of ways? In lots of ways.
So first one is to be able to detect fingerprinting, you know, it's, uh, quite classical, uh, now. So it's a way to, uh, have a kind of a scoring based on a number of features. So you can use HDP error, you can use, uh, the contents.
You have lots of features here to, to decide if something looks like a bot when it'll, uh, get on your website. So it was kind of the WAF technology, you know. But behind that, you need to have behavioral analysis, anomaly detection, uh, ways to be, uh, to, to be able to split the traffic in term of different semantics.
You know, one example, the ip, we have a whole flow of data to be able to analyze what's going on with the ip. Is it a hundred percent bot? Is it well known in our database?
Uh, like it's fully bought. Is it linked to a botnet? Is it linked to, uh, a ticketing bot, for example, in this field?
So we have like, expert system, uh, and today, we'll call them agents, you know, uh, dedicated on a part of the job and what we can see today emerging yet again, um, with the AI technologies, multi-agent systems. So expert system that are well for this one, uh, expert in the ip, uh, analysis. Then, uh, the session analysis then, uh, how the, the session will behave.
Is it a scraper, like it'll go through the, all the three of the, the websites, is it, uh, um, a bot that will, um, go to the product page, then to the checkout, and to the, to the, uh, the paying segments, uh, very quickly. So all these kind of things you have, we have and specialized, uh, AI here that will, will detect those signals, and at the end they will say, okay, this is looking like a bot with my scope. Then signaling the signal to the other ones.
And we have kind of a consensus here that will detect and we'll say, okay, this is, this is a bot for sure. Uh, we have all the red flags that we were, so this is about for sure, and we'll provide the right answer to this decision. Are we sure?
Absolutely. Sure. Let's block it.
Hmm, maybe, maybe not some. Let's present a caption and see if we are wrong or not. If we are, we learn from it.
Uh, we, we miss some signals, let's push a dedicated challenge, invisible one, so we can bring more signals here and take a better decision later. So all this is done in a matter of milliseconds, uh, with the technology we have. So it's very fast.
You know, we know that we have adaptative system in front of us, but architecture is very, very fast, and it's self-learning, you know, so that's the key aspect here. If you want to fight against the bot, you can put a lot of humans reviewing the traffic experts, like, uh, the one I described. But with ai, you have something at scale very fast, very quickly to decide, and that we can, you can track during time.
That means if you want to provide to customers something that is not a black box that looks like a good decision, you can, you can explain to the customer why we took this decision, which is key as well in the field. If we don't have that, that's a black box. Security experts doesn't like black box, trust me.
They want to have control here. They want to, to be able to build trust with a vendor, and you know that for sure. So that's how I think, uh, ai, uh, is useful for the, the security, the cyber defenders today, being able to scale, being able to act quickly, and being able to have expert system that are able to log that decision to expose why we choose to, to do this on the traffic of our customers.
Wow. I mean, you know, when you're talking about being able to go through that whole workflow and to pivot and to give a different, uh, path and a different response, um, you know, in, in just the time that it took you to explain that to us today on the podcast, the system, your AI system has already done this. Thousands, tens of thousands.
Yeah. Maybe hundreds of thousands of times. Yeah.
You know, that, that to me is like, it's like actually a little bit incomprehensible. Like, I don't, like my human brain doesn't really know how to think about that. I think that's absolutely astounding.
Thank you so, so much. Welcome. Thank you.
Hey, it's been so much fun to have you on today's podcast. Thank you for taking the time to be with us and to teach us a little bit about your work and what you're seeing, uh, in this constantly changing field. Um, folks, we really appreciate you being with us and listening.
Uh, this is the AI security edge. Um, please, uh, you know, enjoy all of the different episodes, uh, that we've got here for you. Um, we've got, uh, some already, uh, for you to view and we've got many more, uh, coming.
So, uh, we really hope you are enjoying it. Uh, and don't forget to check out the other Techstrong TV podcasts as well. Um, whether you're interested in learning more about DevOps, security Cloud native or digital Transformation Tech, strong TV is your place.
Thanks so much. Thank you, Caroline. Hey, everyone.
We're back here. Live at RSA conference. It's Wednesday morning, things are starting to kick up here.
We've already had a full day. Of course, we recorded our Textron gang at about eight o'clock this morning. Then we did a new segment special here for RSA called the Analyst Arc with, uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference.
My next guest needs no introduction to our audience here. He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement, right.
Early on with Opsis, everything else. Uh, he is also a co-founder, right? No, you're not.
You're C-T-O-C-T-O And founder at Contrast and founder of Contrast Security. Yep. My friend Jeff Williams.
I knew you were co-founder, but I always say CEO and it's Ct. Right? Right.
That's why I wanted to make sure I got it right. Jeff. CEO's a terrible job.
C CTO's a much better job. Job. CTO's the job you want.
I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess. Yep.
You live and learn. Anyway, Jeff, it's great to see you here. Good to see you too.
What Is this? Maybe seven, eight RSAs more? Yeah, I've, I've done, yeah, more like probably 12.
Well, I'm saying that you and I have have together. Yeah. Oh, I've become RSAs since 2002.
Right. So Yeah, you're similar kind of thing. Um, you know what, Jeff, let's start off though.
Maybe there are some people out here don't know contrast security. Just quickly. Yeah.
If you don't mind. Yeah. So we're an application security company.
Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things. Mm-hmm. And we take a runtime approach to application security.
So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use. Like it's all measured directly from a running application. So it's real, it's not theoretical results.
Right. And, uh, we do that to keep you safe and more importantly, your customers and children safe. Absolutely.
Well, no kidding With children Safe. You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on, the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes.
Right? And that's like sort of a black hole, right? That deployment event horizon.
Yeah. And all of our, and if we could say all of our AppSec focuses left of that horizon. That's right.
Traditionally, Traditionally. And, and for good reason, you it's supposedly faster, cheaper, more efficient. Well, we should talk about that.
Absolutely. But recently, I know Contrast, what was the movie Interstellar? Remember that movie?
Yeah. You've gone through the event Horizon, horizon, that Event Horizon Come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right.
Uh, and to me, that's what sets you apart. I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right.
Traditionally, we've put a lot of bets down on helping developers write perfect code. Yep. But I, I don't know, do you feel like developers writing perfectly Code?
I don't think there is such a thing as perfect code as the problem. Yes. And, and it's, I think It's like a holy grail and it's A moving target.
Yeah. 'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities.
And the, so we've put a lot of bets on that. Yeah. And frankly, it's not delivering.
Right. Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work.
Mm-hmm. And so we had, uh, the insight to say, Hey, you know what? In production, we can see everything.
It's not, you know, in development, you see pieces of applications. You see one repo of 20, you see, uh, the libraries, you see the source code, you see the APIs, they're all separately, but in production, they're all assembled together. You analyze the whole thing at once and you can see exactly where it's being attacked.
Exactly. Where it's vulnerable. And you can help companies focus on the, you know, the few percentage points of issues that are real, the ones that have crossed the event horizon that are actually being attacked in production.
Mm-hmm. Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems.
So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left Right. Problem is, it just hasn't worked. It's, it's backfired.
com. 'cause I think people realize that you, when you over shift left, what are you saying Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code? No, the developer says that, but you don't have developers raising their hand and say, I'm your security guy.
Also. True. That's who they are.
Also True. And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it.
Yeah. So the way runtime security works is, is very much like other kinds of detection and response mm-hmm. Like EDR and cdr.
Sure. The one thing to realize those technologies don't stop application layer attacks, right? Yeah.
They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer. Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs.
That's how you detect things with full context. And so after that, it, it works just like the rest of the XDR ecosystem. Sure.
You, you know, telemetry gets collected. It, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations.
Agreed. It's just missing. Agreed.
Let me ask you a question. You know, I was at Q con in London last month. Observability.
Yeah. Everything's observability. It Is.
How does the a DR play in the observability, this new universe of observability? Yeah. It's a very similar concept.
In fact, we call it security observability in a lot of contexts. Fair enough. And observability is interesting.
It started to the left of boom, like in, in development. Mm-hmm. And companies like New Relic and AppDynamics and so on, you'd monitor development.
And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load. And they're like, well, this doesn't, it's not realistic.
'cause they didn't have the right context. So those tools moved into production and they measure real reality in production. Yep.
Uh, and that's the same transformation that AppSec is going through. Yeah. That's, if you measured in test environments, you don't have enough context.
You don't have real users, you don't have real threats, you don't have real anything. Yep. And you get all these theoretical findings.
So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Do. Walking in that same footsteps Here.
Exactly. Right. It's, it's the logical route.
It's how stuff evolves. So in our never ending quest for the single plane of glass, do you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform? I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, cna P and Sure.
And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph. It fits into the other graph.
Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right. I think today, but ultimately, if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality.
We call it a digital twin. And, and that's come a long way now too, especially with ai. It Has.
So we're building a digital twin of your application layer. Not one app at a time, but the whole thing. So That, wait, this is new to me from you now.
Yeah. Let's start over here. Yeah.
So talk to me. So imagine you've, you're a big complex enterprise. You've got hundreds of thousands of applications all connected to each other.
APIs containers. Right? Now we're all confusing.
So when you deploy contrast, you can deploy it across that infrastructure. Like we got a Kubernetes operator. Just push it out.
It's part of platform engineering, right? Absolutely. You push it out, then the telemetry starts coming in, and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface?
Where are the vulnerabilities? Where are the attacks? Where are the assets?
All that's coming together. And we're building a digital twin. It's, we call it the contrast graph, excuse me.
And it's, it's a model of how your application layer works. It's a lot like the wiz graph except for it's not infrastructure. We're talking about another layer of abstraction, all the, how the application layer works.
And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well I understand this vulnerabilities in this app, which has this blast radius. And, and you can really get good risk rating.
And you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your Sure. Pen testing process. No, I'm, I'm a big believer in the digital twinning.
I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or bigger Pictures. That's what we had to do, is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry floated into a SQL database.
Right. And that's limited. Doesn't work.
Right. So we moved to a modern streaming data architecture. It's Kafka, it's graph databases.
And we're, we've built a massively scalable data collection Platform. That's what you could do that too. It's, it's because our new CEO from Splunk.
Oh. So obviously He came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry, building a a, a awesome Model.
Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff. Exactly. You start seeing insights that you, you, you just couldn't see before.
Runtime security and AI go together, peanut butter and jelly. No doubt. Because runtime is is real.
It's measured directly from running apps. It's not theoretical stuff. It's not get tons of false positives.
So yeah. They, they go together really well. Love it.
All right. This camera's on you. Right?
Okay. Tell them how they get, how did they go get this today? Yeah.
Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more. com.
Right. Okay. And, uh, there's stuff you can try.
If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy. You get our installer, you push it out to your, your containers or your workloads, wherever they are.
Uh, we don't really care whether it's OnPrem or in the cloud or whatever, whether it's APIs or applications. Right. We support all of that.
And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production. And that's really where I think you should Yeah.
Put it. Then you're gonna see you, you'll get amazing visibility into what's happening. I will tell you, you're probably in for some surprises.
Like there's probably a lot more attacks going on in your application than you, you thought. Yep. And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach.
That's, you may find some log for shell that you didn't know about. By the way, We all, it seems it's all out there still, Jeff. Good stuff.
Really good. I'm really, you know, it's not often I get to hear new stuff like, Hey, application security has, has not been innovating as fast as it used, Used to know it. Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're Producing now, you get our ducks in there, 50% more code or a hundred percent more code.
I, I don't find AEC team is gonna double. So you need technologies to help you scale into that double. We don't have enough abec team as it is for what we've produc Exactly.
Three years ago. Anyway. Hey man, this is great.
I love it. Appreciate you're doing a great, great job, Jeff. Appreciate man, you're the best.
Alright. Jeff Williams, contrast security. Go check out what he was talking about here because this is the kind of stuff you're going to need.
Not three years from now, not two years from now. Now we need it now. Go check it out.
We're live at RSA conference. We'll be back in a minute. I have a great pleasure of being joined by a wonderful panel here.
We will make sure that everybody's mic is working. Steve, would you introduce yourself? Sure.
Happy to. Uh, hey everyone, my name is Steve Boone, uh, executive of Product Growth at Check Marks. Uh, excited to be here and, uh, answer your questions.
Wonderful. Yeah, Naomi, Excited to be here. My name's Naomi.
I work at Contrast, the best security company ever. Best one on this stage, right? Well, my boss.
My boss Is Oh, I see. Okay. Right There.
Um, but no, I really do love it. What I am the senior director of product security. Happy to answer any questions about that?
Fantastic. Tyler. Hey all.
I'm Tyler, head of product at, uh, Sonatype. Nice to be here And fantastic. And we have a special substitution at the end here.
The slide is not caught up with, uh, Romy sauce. Who's joined us. Welcome Romy.
Hi. Yes, thank you. Hi everyone.
Uh, Rami, I'm one of the founders and CEO of, uh, men filling in for Baal because this was originally my project before Baal came in. So Good to have you all here. Let's start out with kind of where we are with AI powered AI assisted development.
You know, there's a lot of data out there with whether you kind of intrinsically watch LinkedIn or, uh, TikTok. Somebody talking about vibe coding and what they're doing with the latest development tools. Or for example, we've done our own research just around how many people say that they're using AI tools in development anywhere between 40 to 60%.
That could be AI assisted code completion, it could be vibe, coding, et cetera. I'd love to get each of your sense of where are we of thinking about security and all of this because of course we've never rushed before and tried out new technology before we thought about how we were gonna secure it. So, you know, we'll know to do it the right way this time.
Uh, maybe Naomi, you wanna give you a start and give us your, I'm gonna pick on you, uh, if you wanna give us your kind of your sense of, are we talking about security in terms of how we create software with AI power tools? I think actually this is like another, it's an old story told again, because if you think about who's old enough to remember the first time you ever used open source or your developers begged the security team, can we please use open source in our projects? And you're kinda like, Hmm, I don't know yet.
And now you look back, you're like, well that was hilarious. 'cause everyone uses open source nowadays. I think we're just experiencing the same thing.
An old story told, again, the use of ai, our developers are using AI begging security teams. Is it okay to use AI in 10 years? People are just gonna be like, how did we ever try to stop you?
It's just that story told again. And I don't think our job is to, to say no. I think we're gonna try to tell them how it's always the purpose of security and the fun part is, you know, playing alongside them, making sure they're doing it right.
Um, to answer your question directly though, right? Actually I did forget your question, so I'm just gonna keep Talking. Question was, are we talking about security as we're using AI powered?
We are because the developers are gonna be doing it without you, with or without you. So if security is alongside them, play nice and making friends, they're gonna start listening to any guidance that we can give them. What we're trying to figure out now, it's a little chaotic as a security, uh, industry, we don't really know what we're talking about yet because we don't understand what they're building yet, understand what they're building, it'd be a lot easier to give them guidance.
I, I really liked your analogy of kinda the open source usage. I think, you know, when we think about open source in your organizations, my mind goes to, uh, supply chain security, right? Understanding what's coming into your organization, especially if you don't take ownership for it.
So AI is no different, right? If our developers are leveraging ai, uh, the best time for us to be looking and analyzing and scrutiny, that code is at the moment, moment that they're actually generating, right? So if we're gonna encourage our developers to leverage AI as a new powerful tool to help them generate faster code, then we also need to support them with the right tools that allow them to scan that code, get instant feedback on the quality of that code, and give them confidence on whether or not to use that code.
Because it's not a silver bullet, it's not a magic wand. And so really our job now is to start putting those right guardrails in place so that organizations can use AI more confidently. Yeah, and I think that there's two vectors there, probably more than two.
There's the coding assistance you talked about. Mm-hmm. And then there's the AI models and, and technologies that being put into the software that the developers are creating themselves, right?
So there's the kinda like, uh, you talk about open source components like a component selection. You're making a model selection. So there's that vector and then there's the vector of using the, uh, coding as systems and toolings.
I think we, uh, it's our responsibility and privilege to work in both areas. Uh, I think the coding assistance get more press, um, but I don't know if they're more important or actually less than what's being brought to the, uh, data science pipelines and product delivery pipelines in the products that are being shipped and, uh, provisioned, Right? I think there's also the issue of, uh, of scale, volume of code being generated, right?
So with automated tools, you can, one person can create, I dunno, three times, five times, 10 times more code than an individual contributor typing on a keyboard. And so that's almost by definition going to cause a lot more vulnerabilities to occur in that code. That's one.
Two is almost all of these models have been trained on open source corpus, which inherently is less secure than what you'd find on average in an enterprise that goes through some testing and some QA and some, you know, rigorous, uh, process of release. No way. No, No way.
Yeah, I've seen it. I've Read it, read about that happening. Yeah.
So, you know, I think everyone expects code generated by an agent to be less secure, uh, on the one hand. But to Naomi's point from before, these people have been around for open source 10 years ago, 15 years ago, and are not as resistant now. So they get it, they learn the lesson.
Mm-hmm. They're not going to try and stop the tide with two hands and they're already starting to think about, you know, the right way to adopt it and not resist it. Yeah, I was thinking about the same thing.
Different analogy though. If you remember cloud, we're not going to the cloud 'cause it's not secure. How long did we kind of stay in that one or two year period before we started really moving applications and software there?
That's actually a very interesting analogy for a different characteristic of, of ai, which is, you know, when cloud came out and everyone rushed to protect it, it took it a long time before it got into a meaningful market share of the number of applications in the world, right? So within one year, two year, three years, 10% of applications were on the cloud. And I think it's the same with AI now, where less than half a percent of applications in the world today are ai, but the most innovative, the most strategic, the most future looking ones are on ai.
So I think it is worth watching, uh, what's happening there despite it not being that of big, of a portion of the world yet. Yeah, I I it's definitely arguable that we're moving a much faster pace in terms of adoption to AI and our tool set, et cetera, than even cloud was. I'm curious, we're in a different place too of where security teams and software teams are today and how they work together, that kind of tools that they need, uh, collaboratively defining what those are, selecting vendors, et cetera.
Is that part of why we don't see security teams in enterprises saying, wait, wait, stop, don't be using this stuff. It's not secure. We can't, we haven't secured it yet.
So we don't see the brakes being put on. At least not, you know, to the degree I'd argue cloud was Steve. Yeah, I, I think there's a really big opportunity, and I think that's what a lot of AppSec leaders see, right?
There's an opportunity to use AI to get your developers engaged in AppSec, right? I mean, let's face it, a lot of developers aren't security experts. Um, but now we have the ability to bring them the information they need when they need it, about a vulnerability to give them the, uh, feeling that, Hey, I can roll up my sleeves, I can actually start to work on this.
I can remediate this. I can, I don't have to spend days looking at it and trying to debug it or learn about it. I can position a developer, you know, I always make the analogy of running a marathon.
I don't run a marathon, right? That's not my, that's not my, uh, skillset. But if you put me two miles from the finish line, alright, I can do that.
And I think that's one of the reasons why we're seeing this, uh, you know, both AppSec and developers embrace this, is it's giving everybody this head start, it's putting people right in front of their finish line of their goals. And now all of a sudden, even if I'm not a security expert, I got the right context, I got the right confidence. And if we put in the great guardrails, now I feel like I can go and actually be engaged in AppSec.
And by the way, if your developers are engaged in AppSec, that's how you're going to have a faster and more productive AppSec program, right? You need them to be engaged. But isn't that so possibly dangerous though?
You're starting two miles before the finish line, those first 18, how many miles is in a marathon? 2022. There We go.
Yeah. I've never run one either. Yeah.
So those first few miles, what, what if something had happened in those first two miles? I twisted an ankle, I hit a pothole. Sure.
Or I did something and now, now I'm hobbling towards the end because I never had that foundation. Right? I think we're setting ourselves up for a potential failure in the future if we rely on AI too much as a crux.
That's what I say. Well, I I wouldn't say use it as a crux, right? There's, there's gotta be a, a balance of, of trust but verify.
Um, but at the same time, if we ask, you know, an average enterprise, how long it takes to remediate a vulnerability? If you don't know that, work on that. Now, when you have that number, how do we improve it, right?
How do we improve the mean time to resolution? Well, AI can really help us as a developer if I don't have to spend two days on that and I can get that down to a couple of hours or even the time that I might research to understand the risk to actually come up with working code, that's a huge benefit. Like that's worth the risk in a lot of places in the trade off.
Again, you gotta have the right checks and balances in place, but I think that's ultimately where people are embracing this technology is that it provides a lot of opportunity. I also think you have a growing with a difference is you have these kind of, these more security as code more security groups, writing code platform engineering teams that are responsible and wanna use the tools themselves. So there's this, how can my life be better?
They're, they're seeing that the code that they're writing themselves is, uh, faster and more efficient. So I think maybe than a, a decade ago, you see more security as code security coding. And so that kind of wanting to embrace from the beginning, I think is, you know, kind of raising the floor of expectation and velocity.
Right? So look, honestly, I think we just haven't had an Equifax level security event coming out of AI yet. And so I, I think it's a question of when, not if and when it happens, that's when you know how good the relationships between security and developer really are.
Right? I think right. Now it's kind of up in the air.
Some, some organizations are very good at it, others not so much. Sometimes you see friction, sometimes you see a lot of push and pull. Uh, but I think it's still to be, to be figured out what it really looks like when, when the rubber meets the road.
So it's, uh, during those trying conditions, everybody reverts to type. Right. It's kind the type, right.
It's, we all work well. Nice. Together when under pressure it Right.
It's a little Tougher. Um, by the way, we'd love to have some questions for our panel. If you wanna step up to a microphone, I'll do my best to, to call on whoever steps up if I'm not blinded by the, the lights here.
But feel free to join us with a question. I'm curious, I'll all of you talk with security teams, development teams, what are the questions that organizations are asking you about using AI tools, the security of the software that we're developing, maybe even security of the tools themselves, right? These, and a lot of new tools that we're using.
Uh, what are customers bringing up to you or potential customers asking you about AI and software development, Rami? Sure. So I think, again, taking on the, uh, corollary of, uh, of SCA and open source, we are super early days in the, in the lifecycle of ai.
And most people I talk to just wanna know where they even have ai, right? So if you talk to a large enterprise organization, mostly we talk to, you know, the security people, DevSecOps, compliance, those kind of people, they have zero visibility into what the developers are doing, right? Very commonly, I've had hundreds of conversations where I'd go and ask again, our champions, you know, how many applications do you have with AI in them?
They would tell me, you know, 10, 15 and then run a super basic simple scan and find 200, 300, right? So I think the first kind of stepping stone is for them to just figure out what the engineers are doing and where and to what extent before they can even start any kind of, uh, meaningful analysis of security or anything else. That Inventory discover stuff, right?
You need to know what you have to know, what you have to protect. Exactly. Well, it's even more hard because no one's making their homegrown models.
They're building off philanthropic, they're using Claude, they're just taking someone else's work and then building on top of it, whether it's an MCP server that they've built for themselves or some integration or some tool. So there, that's just another thing. If we're gonna be doing asset management on ai, we have to know exactly how the developers are using ai.
So they're borrowing from these places. How are they actually using it in the tools that you're building and the stuff that you're using for your own customers? Like, what, what is going on in their ecosystem?
And I think it's gonna differ between teams. You have to have those relationships. I would echo we hear the exact same thing verbatim.
We also see an interesting kind of upshoot or, uh, kind of the first green right outta the ground of, uh, those same people now being asked to also look at the data science organizations, the data engineering or organizations mainly we see as a lack of, well, we don't know where else to put it. So kind of feels like AppSec, even though we're not shipping the product, we're deploying into production. So we also see that same sphere of scan and understand in the AppSec teams are now being asked to also look at data science teams, which is a whole other set of, um, let's say silo busting that they're being asked to go do.
So, um, scope changes, uh, as well, including not only security, but a lot of questions we hear about legal risk and policy and understanding of what the legal implication of the models are. IP protection of the model data usage. So it's, uh, kind of an expanded scope, both in terms of breadth and depth of what people are being asked.
At least we start, we're starting to see that kind of bubble up in the, at least in our customers. Yeah, I, I think those are all really great things that I, I'm glad you guys are paying attention to. I, I get inundated with questions about trust.
Um, and people largely come tore marks and ask, how can we trust the AI generated code? Um, how can we be assured that the AI remediation is actually going to fix my vulnerability? Um, they come to us with questions about, you know, how do we put in bend but don't break policies where we can, you know, give the developers an inch and say, yes, use these new tools, but also come back to our higher ups and to our board and say, but here's how we're evaluating that code.
Here's why we're scanning that code to make sure that we're not introducing more risk into our pipelines. Um, and so we work with them on scanning that code in real time. We work with them on understanding how you can use reflection in a model, right?
So we've come up with this idea of a confidence score, right? When a model gives you a response on how to fix something, you gotta question that model. How confident model are you that the code you're giving me can actually go remediate my vulnerability and have it explain how it came up with that solution?
Because education is, is a continuous thing, or at least it should be, especially this day and time with all these new technologies. So if developers are going to use these tools and apply 'em into our code, we have to give them a chance for that human intervention that, uh, we always hear the human in the loop. But I think that's one of the most important things is people come to us and say, how do I trust this?
How do we put in policies in place that are gonna allow us to be able to sleep at night, uh, when we're introducing this new code into the organization? Great. Had Tyler, speaking of trust that Steve brings up, one of the conversations we don't have yet is zero trust.
And how should we treat software that's generated or created through ai? O one of the questions I asked, like testing companies early on is, do you think of code created by AI as a junior developer? You've treat it as any other developer.
Do you treat it as the most suspect of, we don't know where this came up from. Maybe it's like an open source project we've never heard of. What, how do we treat, do we need to apply some, some zero trust type principles or we have to take a totally different approach?
When you think about AI and development, I think that academically I could sit up here and talk to you about zero trust and as a, as a, as a framework. And, uh, I'm not gonna say it's bad, right? But I also think we all work in support for organizations that have goals of, of completing a mission.
And in that case, it's this kind of bend don't break set of policies we see the most. And that iteration, and it's been said before, but I don't really have a better metaphor than the early days of open source and that kind of, um, iterative disclosure and trusting it more. We don't see, it's not necessarily a, a good set of policies, a good set of tooling, a good set of processes can work and I think, think be effective regardless of what or who writes the actual code.
But what we don't see is any removal of accountability in that RACI matrix. What what we don't see is any removing of the developer that does the merge request or the pull request still carries that accountability, uh, and responsibility to the work that they are, are, are doing. And that I think is the foundational, uh, thing of success is that accountability is never removed.
There is that pull request, that merge request who somebody's name is next to somebody's job. It is to make that happen. And that, uh, think sets a foundation of process and policy and trust, uh, that we see kind of as a, a good place to start.
Mitch, we might be looking at this the wrong way too. I think we're sitting here thinking, is there another security control that we need for ai? And I'm gonna just sit here.
I think the security controls that we have today are pretty decent. I catching the bigger risks. Like I'm worried that my developers are putting in intellectual property into these models, right?
What controls do we have out there guys that stop developers from doing that? We have DLP, right? These are security controls that we should already have in our organizations that should technically work for some of these risks that we have today.
What we're most concerned about, I think, and we haven't really voiced it yet, is the non-deterministic factor of ai. Like in computer science, we know this, you have code, you build it, and you end up with a binary, right? And you build that thing every single time the same way you're gonna end up with the same exact binary.
You do a hash on the thing that hash is gonna come back the same exact way, right? You know this, it's deterministic. The only problem is with ai, everything's changing all at once.
It's just so much faster. And you can't run something through a model on day one and have that exact same thing happen on day two or day three or day 10, because that model just keeps changing if you do it that way. So we're trying to explain it to ourselves.
Are our security controls good enough? I think it is for now, but we still need to understand how our developers are using ai. And if so, how is that changing our day to day?
And if we can't figure that out, we're always gonna be behind. And I always think security is a laggard behind technology. Technology's gonna happen with or without us.
We better play along and play. Nice. Alright.
Look, I, in principle, I agree that existing practices are, is a very good start. However, I also think we should keep in mind the fact that there are some attack vectors that are unique to ai. My favorite example is all these code generating models, uh, always hallucinate, uh, dependencies.
Mm-hmm. They make up open source dependencies that don't exist. And some of them do it in a consistent way, meaning they would hallucinate the same dependency over and over again, which kind of gives you an opening to create this dependency in real life and, and do it maliciously.
So that's something a human developer doesn't do. Okay. Just as an example.
So I think yes, existing tools and practices super important and apply to the code being generated by the agent, but there are a few additional things to also keep in mind and take care of when you let, uh, when you let AI write your code. It's kinda like typo squatting for open source packages and libraries. Exactly.
Steve, any thoughts on, on the trust side of you, or the one that brought up trust? Yeah, no, it's, it, these are all really great points. Uh, I, I think that there are a lot of good measures in place.
Um, ultimately I, I feel like this is more being driven by engineering than anything else, right? At least in the early days where we're seeing a lot of adoption for ai, it's with developers either using it to write code or building applications where they're embedding ai. So for me, on the trust side, uh, it's important.
Now we always talk about shift left. I think we've sick of hearing that term. Uh, but now more than ever, AppSec should be sitting with engineering and understanding what your developers are doing.
How are they using ai? What types of applications are they trying to build? You need to understand the roadmap.
You need to understand if they have plans to adopt these libraries. You need to start putting in and understanding and building policies internally where you are comfortable with AI usage, right? Maybe we say, okay, yes, it makes sense.
You're gonna use you, uh, AI on the, the front end. Cool. If we want you using it for authorization, maybe not right now.
Why? Because trust takes time, right? We're not just gonna trust everybody overnight.
But that's how you can start putting systems in place where your organization can monitor the usage, understand the usage, and then build practical policies around it, right? So to me it's, it's crawl, walk, run, and, and you know, don't throw the baby out with the bath water. Uh, to, to your your points guys.
I mean, there's been a lot of great things that we're already doing. We have to keep doing them. Um, but you know, I think just really sitting with engineering and understanding where their push is coming from, where they're trying to use this technology is, is vitally important.
Okay, this next question's got a little bit of wind up, so hang up, hang on with me for it. So we've gone through this transition of thinking about security and software where rather than deploy software stay stable, we don't change it. That's how we know it's secure because we don't deploy software very often to an, an environment that we deploy software quite frequently, maybe multiple times a day, multiple times a week.
I like to use the analogy of software's not a solid, it's a fluid. It's constantly changing, whether it's open source or third party or APIs or SaaS services, your own code. So that's the windup to your, to your point Naomi, I, I wanna explore that a little bit further.
The non-deterministic nature of generative AI doesn't mean it's gonna generate the same code the same way every time. You may say that fix didn't solve it, try it again. Who knows what changes.
Mm-hmm. Are we in a better spot today because we have automated processes today that handle changes in code that we aren't predicting coming through the development pipelines. Is that gonna help us address some of what you brought up?
I mean, if I wanna be honest, the processes and tools we have in place are not sufficient for code that changes all the time. But if you're still building code, writing code, building code, and running it somewhere, hopefully your controls are good enough for that. I'm worried about more of that age agent future that we all talked about and listened to for the past few hours.
That part scares me a little bit. I don't even want know what that future looks like. Honestly, More philosophically, I think potentially there could be a lot of value to the lack of predictability of these models, right?
Because from a security standpoint, when you are too predictable, it makes you open for an attack. Whereas I don't, like, I don't have anything concrete. I'm just thinking about loud, out loud.
Maybe you can find a way to leverage the non-deterministic nature of AI to create more security rather than less Subcu security through obscurity. Yeah, exactly. 'cause it's not the same every time.
Right? Interesting. Tyler, any thoughts?
I know I'd hate to make a judgment call on better or or worse. What I think is we're in a, uh, state of I think iteration that some things are better. I, I know plenty of, uh, engineering friends that like would rather speak and let the code be written, move up the level of abstraction.
I think that in that way can be very good. Um, and I think that just like anything from a security perspective, I think there are some aspects of what we do that are better now. Um, patching speed and, and, and frequency.
Um, so on net I feel like we're raising the, raising the floor. Um, and that comes of both good and bad. Uh, but uh, what's that Chinese, what's that proverb that you live in interesting times?
It's interesting, yeah. Getting more interesting by the moment. That's Right.
I I think one of the ways that we, uh, can also address this is by, um, not making it so unpredictable. I mean the, you know, part of what the big effort is, is building large language models, models where the output is more predictable, right? And we can do that.
We can red team, we can ab test, you know, we can verify and, and pre-check just like we do a lot of things. But one plus one is still equals two in that model. And then as soon as we start seeing deviation from it, 'cause we're doing things like continuous testing, then we know we have an issue, right?
But more than anything, right, when we think about the impact of, of ai, the, the amount of new code, how fast everything is, is being developed. If you don't have good CICD processes today where you're automating builds, running union tests, doing, uh, you know, uh, automated testing, this is, this is gonna be extremely painful for you. 'cause you're gonna need those good checks and balances.
You're gonna need to be able to make sure that you've got the good regression testing in your models themselves, uh, to, to really I think get to the point where you're talking about of of having that trust. Great. Jake, is that you out there?
You have a question? Um, so, you know, we've sort of talked about one side of AI here, which is how you empower development with ai, but the other folks who are being empowered by AI are the bad guts. Absolutely.
Um, and I think one of the things that we're gonna see, and we saw, um, some of this in the Mandiant and the, uh, DBIR report last week, is there's gonna be an increase in zero days, um, because it's so much easier for folks to come up with really difficult attacks or sophisticated attacks. So how do you see the future of defense against zero days based on the fact that it's gonna get easier and easier and easier? Yeah, I mean the, the really scary truth is, um, if you think about how far we've come from a, let's say publicly accessible productization, you know, the companies we represent, what we're building out there, um, our attackers are years ahead of us right now, right?
So they have a large runway to work with and it's gonna take the AppSec market, I think years to catch up until we can balance things out and be playing on a level, level playing field. So, um, vigilance is, is gonna be key. You know, we've got a lot of research at check marks that, uh, kind of to your point shows that already attackers are doing things like, um, open source, large language models and poisoning them, right?
We were able to prove remote code executions. We're able to show that these models are now really the, the kind of vehicles for malicious packages. So your spyware, your ransomware, your malware.
Um, and so, you know, when we think about zero days and we think, you know, for us it's, it's gonna take us, I think all collectively as an industry to stay on top of this and, um, to really look out and start thinking about creative solutions and education around what the latest threats are and building them into our threat landscapes. Uh, but I think it's, it's a, you bring up a very, very good, very big challenge in the market that, that we're all facing right now is how we're gonna close that gap. If I was, if I was a threat actor and I'm, I, I'm not, but if I was, I would go into GitHub, I would point my mo my model at it, I'd be like, tell me the top 10 most popular projects on GitHub and what vulnerabilities exist in those projects.
I would then try to go to a sonotype. I know we have a sonotype here. I would then see where those projects are actually used.
Like if it's an open source library that's popular log for shell log for J is a popular one. For an example, I would then ask Sonotype point my model to Sonotype. How many open source projects use that vulnerable library or have that vulnerable thing that I'm looking for, right?
How many of those are in commercial or uh, cots software? How many things are sold? How many things are for free, right?
Like, and then I would attack that all day every single day. I think that's, it's like log for shell, but more all the time. Yeah.
And I don't wanna like scare anyone, but if you don't have the visibility into your applications since you know what's actually running in your applications, like how are you supposed to defend against that? Right? And I will say there's a pretty good software out there.
Contrast does that pretty darn good. So I'm gonna say like, if you guys don't have that visibility in your applications, check out contrast pretty great. Alright.
Look, I'd say fight fire with fire, meaning I think we're already starting to see where agents are being used for protection and for creating better and faster security to combat those, uh, bad actors using AI to create the attacks. So this is something we are working on, but I see many those people do it as well, which is deploy agents to on your side in your defense, that can act as quickly as the ones against you. Yeah, I would say, I was gonna say the same thing.
Fight fire with fire. Um, 'cause we're doing similar things. I would also say that there's the, uh, rapid response that can further be accelerated by the AI agents, acceleration, tech technologies.
Let's say you're not perfect. Uh, somebody breaks through the offensive line to go into the, to the secondary. It's how fast you can collapse on that.
So it's visibility agents help with that. So you can fight fire with fire, both in protection and then rapid response to close that. I think that's what we're seeing is, um, there's a lot of hardworking, talented people on trying to protect, um, and innovate in a lot of those areas.
So I think that's, that's exciting to see. Great. As Mark comes up, hold for a moment, please thank our sponsors and thank all of our sponsors that were part of, uh, helping you bring this to us today.
So I'm sorry we didn't get to your question, but we'll try to talk to you in the back. Okay. So I hope we'll see you again next year.
Okay. Thank you. Thank you.
Certainly appreciate you.