Techstrong TV – May 11, 2023
Watch discussions on firewalls, automation and more on today’s episode of Techstrong TV.
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, Cybersecurity, Cloud-Native, Containers and deep-dives into specific technologies and best practices.
You can watch the free live stream on the web, or on YouTube at DevOpsTV Channel, Facebook Live, Linkedin Live, Twitter or on Roku, Apple TV and Amazon FireVTV via the DevOps.com TV app. Also on Android and iOS devices via the DevOps.com mobile app.
Transcript
Hello everyone and welcome to Techstrong tv. Today's Thursday, May 11th, and I hope you'll having a wonderful day so far. I'm your host, William Willis, and in today's show, we're gonna bring you some fantastic interviews with incredible guests from around the world.
So stay tuned. As always, I'm gonna start off with our tech Strong news recap, filling you in on the biggest tech headlines that are making waves. Then we'll air some interviews from Con Club NATO Con Amsterdam.
First up, Alan will interview Zach Butcher, founding engineer for TI rate. Let's talk about how launched a new tech preview of TI rate Service Express at con. Then Alan met with Cedric gig out vice President of Product Management at Canonical to talk about canonicals.
Two big announcements for con, then Mike Baard met with Jonathan Simons, CMO of Minayo at Con Cloud Native Con to talk about why object storage has been so successful in the Kubernetes ecosystem. We'll also air an interview from RS a C 2023. Mitch sat down with Carl Chobe, senior Vice President of product management and General Manager of Application Security of Imperva to talk about automated threats and what trends Imperva has monitored over the past 10 years.
Then Mitch will speak to Arthur Hicken, a Parasoft evangelist to discuss the upcoming automated software testing and quality summit. Next we have an episode of Text Strong Research Review where Mike and Mitch give their perspectives on RS SAC C. Finally, we will wrap up this broadcast with two episodes of View of ard.
In the first episode, Mike interview still valani as CEO O of onshore security to talk about why Stella believes that steps must be taken now to ensure cyberspace in the future. Then Mike interviews Jason Davis, vice President of product Management for testing applications at SA Labs to talk about why the quality of applications that are being developed faster thanks to DevOps has not improved. And that's what we have coming up for you on this episode of Techstrong tv.
So without further ado, let's get the show started. com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more. com where the world meets DevOps.
Hi again. Everyone hear the headlines from May 11th. First up, Chinese authorities have made one of the first arrests under the new anti AI guidelines to prohibit the misuse of artificial intelligence services to distribute false information.
The suspect, surnamed Hong was detained in the Gosu province for allegedly using chat G P T to generate fake news articles. Hong is accused of rewriting existing viral news articles and posting them online to make money through internet traffic. And the fake articles were viewed over 15,000 times before being removed.
Hung was charged with the pinking picking quarrels and provoking trouble, a catchall offense that is often used to arrest individuals accused of creating and spreading misinformation. Critics have widely criticized the offense for its potential to limit free speech and arrest. Government critics zooming out.
While many countries are apprehensive about ai, China is one of the few countries that has completely blocked access to chat G P T, and this arrest shows China's determination to put a leash on AI technology. Next Anthropic, an AI startup founded by former OpenAI employees recently revealed its written principles for its AI to follow, which draws from various sources, including the UN's Universal Declaration of Human Rights and Apple's terms of service. The company has been working on a way to make AI safe through constitutional ai, a method of training AI systems to allow the AI system to manage itself and reduce the reliance on human moderators to rate its output for things like hate, speech and toxicity.
The document includes guidelines to encourage freedom, equality, and prevent racism, sexism, and discrimination and considered on Western perspectives. With all this being said, though, the AI industry is already grappling with perceived bias in chatbots, but this constitution sets to mini minimize that as well as toxicity on Anthropics own chatbot and paved the way for other ais to follow. In other news, a new EU draft states that Amazon, Google, Microsoft, and other non-European Union Cloud service providers seeking an EU saver security label to handle sensitive data must enter a joint venture with an EU based company.
Additionally, US tech giants can only have a minority stake in the venture, and employees with access to EU data must undergo specific screening and be located in the 27 country block. The cloud service must also be operated and maintained from the EU and all customer data stored in the region. The EU certification scheme would vouch for the cybersecurity of cloud services and determine how governments and firms in the block to set a vendor for business, as well as also working towards the EU goal of continuing to reign in US big tech.
Next up, LinkedIn, the professional networking platform announced that it's laying off of our 700 workers and closing its China Jobs app. In career marking, the most recent set of tech company layoffs the company cited shifts in customer behavior and slower revenue growth as the reasons for the cut. This being said, though, they say that the number of job losses could be less than 500 as part of a strategic shake up.
LinkedIn is set that it will be opening over 250 roles as part of its operations team, new business and accounts management teams. The local jobs app for China in Korea, however, will be shut down by August, citing fierce competition in the challenging macroeconomic climate on Security Boulevard. We have an article that looks at a new ma cart skimmer scam that DS the store's checkout page.
This scam uses a customized web element to make it harder to distinguish a fake form from a real checkout page according to malware bytes. While using a modal is not new, the researchers said that this campaign was different because the skimmer looks more authentic than original payment pages. com.
On digital cxo, we have an article looking at the digital transformation of healthcare. 0 or digital wellness allows for new opportunities to improve health services worldwide. 0?
This article gives a deep dive into the subject. com. com we have an article looking at AWS's announcement that it is making it Cedar Policy as a code tool and open source project.
AWS has been using C to provide IT teams with the ability to write authorization policies as code that can be deployed anywhere. And the release of Cedar as an open source is part of its efforts to contribute to intellectual property that plays a pivotal role in organizations applications. com, and that's today's text on news recap, Discover the cutting edge insights of our new show, AI Times a series that explores the limitless potential of artificial intelligence sponsored by the AI Infrastructure Alliance.
The AI Times is at the forefront of the AI revolution, tackling the crucial questions of how we can leverage AI for the betterment of humanity. Stay ahead of the curve as this show delves into all things surrounding ai, including trends, pressing concerns, and the positive impact AI is making around the globe AI times. This is Techstrong tv.
Hey everyone. We're back here live in Cube Con Amsterdam. My next guest is Zach Butcher from Ted Drake.
And Zach, welcome. Hey, how are you man? Hey, I'm doing really well.
So, Zach, share with the audience. Give us a little bit of your background here. Yeah, so, uh, I was one of the original engineers on the STO project at Google.
Very cool. Before then, I worked on a whole bunch of different stuff in Google Cloud Pro. If you ever made a project in Google Cloud, that was my baby for quite a while.
Um, and then I moved over to start to work on, on sto. Um, and there, you know, the project caught fire when we released it in 2017. And uh, I worked very closely with the original product manager there to go meet with a bunch of users and, and try and get iseo the initial ISEO adoption.
Right? Yep. And out of that, we heard a bunch of really compelling case studies and, and a bunch of compelling use cases that prompted us to go and, and start pet rates to try and bring, you know, the goodness that Istio does up to enterprise, right?
Sure. Uh, cuz there's a big delta between, you know, an open source project and what you need to be successful in enterprise, in, you know, a heavily regulated enterprise and, you know, and, And that's usually the spot where a commercial entity comes in and fills the gap. Correct?
Correct. So, Um, you know, we've been hearing about Service Smash and we, and EO is, you know, probably the leading one man before covid going back to San Diego and Seattle before that. Yeah.
But it seems like at this show, service Smash has hit a maturity level that I think makes it more critical mass acceptable. A hundred percent. That's been exactly my impression here on the floor as well.
It's super exciting for me cuz it's, you know, I I started working on ICO in the middle of 2016. Really? So it's been a, it's been a minute.
Yeah, it has. So this really has been the first coupon where I go around and almost everybody I'm talking with goes, yeah, we've, you know, we've been messing with this, yo we have it already. Yeah.
We're using Envoy. And so it's been incredibly, incredibly exciting to see. Very good.
And congratulations. Thank you. Let's talk a little bit about Tek though, right?
Yeah. So you, you, I'm, I'm assuming it's a, a commercial enterprise grade sto uh, product, but what makes it different than the open source? What makes it enterprise Great?
Yeah. Yeah. So, uh, the, the analogy I like to explain, again, I, I work for Google Cloud, outside bubble bunch of these management planes.
Uh, you know, if you think about what AWS console is to the AWS services, that is what we are to Istio. By that I mean, you know, user login, user management permissioning, who can do what, where with the system, the feedback, the, the metrics, the global view of, of what's happening in the system, all that stuff to really operationalize a service mesh in an enterprise so that app devs can go and, and push config and, and roll out apps as fast as they can. The platform team can make sure that there's a consistent baseline of networking behavior, of resiliency and of security there for them.
And really bring 'em in a way that enables the multi tendency that we see large enterprises doing, uh, and helps bridge the heterogeneous environments that they're in. Right? We regularly work with folks that are in Azure and Google and on-prem, and they're in OpenShift and K three s and everything under the sun.
And we come in and help give them a single coherent place to control application security, traffic, and observability across all of that. I love it. Love it.
That's great. I want to jump to some new stuff, but before we do, people who want to get more information on Tetra, where do they go? Tetra?
Where do they go? io is the best place to go. Uh, you know, you can find us on all the social media as well under the, the Tet rate or TE rate IO handle.
Uh, but go check that out and, and that's where we are. Fantastic. So now let's, let's take a right turn.
Yeah. You do some work with nist, Correct? Yeah, that's one of the other big hats that I wear.
Uh, so in addition to, to working here at TE rate, uh, along with TED Rate, I, uh, go work with the Secure Computing and Information Systems group at nist. Um, and I help write a bunch of special publications there. Uh, historically I've been writing what's called the S P 802 0 4 series.
That's the set of guidelines for the US Federal Government for secure microservices and multi-cloud. I love it. But what we're super excited about, and I didn't even know what was happening, uh, today, but I found out about 3:00 AM this morning Amsterdam time.
Um, the next sp that I've been collaborating with NIST on 2 0 7 A, which is the next installment in Zero Trust. So Zero Trust is the big thing in Vogue. NIST s P 802 0 7 defines zero trust.
We have just released for Public Comments s P 802 0 7 A. And so this is that next installment in the Zero Trust series. And really my goal with this was to try and make it concrete.
Yeah. I'm tired of, there's a bunch of, there's, you know, there's a bunch of vendor FUD around what is Zero Trust or not. There's a lot of, of wishy washy stuff.
I tried to really make it very clear and I gave five runtime checks, and we argue that if you do these five runtime checks at minimum, then you are implementing a Zero Trust run time. And those five are ambitious. I'm, I'm, you know, I'm have to go check this out now.
Yeah, please. Cause Zero Trust was was the term at the RSA Conference last year. Correct.
I expect it'll be pretty heavy this year as well. Only more. Yep.
So, you know, so NIST has put this out. It kind of has the blessing of this whole White House, uh, push for zero trust and better cyber. Yeah.
It'll be part of security. Yeah. So the, the existing White House push for Cybersecurity predates this one, but I, we do expect it's pretty likely that this one will be rolled into the next set of White House guidance that'll come out shortly.
Excellent. Where can people get information on that, man? gov.
gov website there. And please, you know, my, my call to action would be give us feedback. It's the current open review period, and so now is the time to give your input on that standard.
And, uh, you know, tell us where we got it wrong. Tell us where we got it. Right.
Tell us, tell us how to make it better so that it can help as broad uswa the industry as possible. Hey, Zach, there are folks watching this out there right now, engineers who say, you know, I'd like to work with Nest and, and some of these organizations to do what Zach's doing. Yeah.
What advice would you give 'em? Yeah. Um, start to get involved in some of the working groups and things like that.
So in this holds a variety of different ways to kind of start to, uh, comment and get involved. One of those is something like research groups. So, for example, we currently have a research group that is running on, uh, zero trust in multi-cloud, and specifically focusing on identity in multi-cloud.
And I help lead that group there. And we've been meeting weekly for quite a while now with representatives from different cloud providers, representatives from different end users, talking about the problems that they have around multi-cloud and security. The outcome of that then is research that we use to form the next set of standards.
And so, for folks that want to get involved in this, start with those groups, then that gives you that input in. And then often the people that write those sps are folks that are in that groups that, that do those research. We get it.
I love it, man. Hey, last topic I'm gonna bring up with you. So we're two days in, here's, we're two days into con, about three for some of us who are here early.
Yep. Same, You know, sto service messages reel. Any other kind of observations you wanna share with the audience?
Um, no. My biggest one is, you know, I personally have been really, really energized and excited about this coupon. You know, I don't, I don't know how you felt about the last couple ones, but it felt kinda like Vendor Con for a while there, right?
Well, the one in LA was for sure that was, And you know, I don't know about you, but for me at least, the energy feels like the old, old Yeah. No, we're Back. Like, I feel like we're back.
And you know, for me that's super exciting. Cause that's what it's all about. I, I don't wanna hear a bunch of vendors talking about their stuff, even if it's cool.
Sorry, I'm a vendor talking about my stuff. Yep. Uh, I wanna hear users, I want to hear people that are in the trenches doing this stuff and, and how they're doing it.
Right. That's that feedback and that's what's makes it important. Exactly.
And I feel like we're finally back in that. I hope, I hope it stays there. I'm gonna be at RSA next week.
I'm hoping to see a similar thing there, man. Yes, sir. Zach, thank you for coming on today.
And I think we hit it all. I appreciate it. Go check out.
io io. Yep. Ted Tt.
R a r A T E Io. Got it. If you misspelled it, imagine what I would do.
I know, Right? All right. We're taking a break.
We're live as they're playing some announcements here. We're gonna be back. We're live.
Incan. Stay tuned. This is Techstrong tv.
Hi everyone, it's Alan Shimel, and we're back here at Cloud Native Con, right. Also known as Cape Cod. We're with 10,000 people.
We're in Amsterdam. Mike Ard and I have been, uh, interviewing people all day. Let me introduce you to our next guest.
His name is, and I'm gonna do my best on this, but my French is weak, his name is Si. Siji. Jugo.
Jiu. Yeah. Perfect.
No one's ever gonna confuse me for a, a French waiter, but hey, we do the best we can. Saji welcome to Text Drug tv. Thank you very much.
As important as Ji's name is, I should also mention Saji is with Canonical, or of course, the people behind him. Buntu, uh, still, you know, I, one of the most popular Linux distributions in the world has been for 20 years, 25 years. 18 years.
18 years. Yeah. Yeah.
About 20 years. Mark funded, uh, Ubuntu 18 years ago. Indeed.
Yeah. Crazy. I I was around then.
But anyway, um, so you may ask, what is Canonical and Ubuntu doing at Cloud Native? Right? What, what is the connection?
What is, what brings you here? Well, first of all, I happen to know Canonicals been involved in the CNCF for a very, very long time. Sure.
Probably since the beginning. Um, it is a Lennox Foundation Foundation, but specifically this year here at Amsterdam, you guys have two big announcements that were made at the show. So, Jake, if you don't mind, why don't you share with our audience a little bit about them?
Sure. Yeah. So basically, uh, here we are here in, uh, con, because, uh, actually we really want to promote the fact that Kubernetes should be easy for everyone.
So it should be what we call zero ops. One of the key products that we're promoting is micro cakes. And, uh, micros is actually, uh, easy to deploy, easy to maintain, easy to upgrade, to enhance with add-ons, uh, version of Kubernetes that can address multiple use cases.
Uh, in one common line, you can install a Kubernetes cluster in two command line. You have ha you have service mesh, you can connect to it. You don't have to be knowledgeable about Kubernetes.
You don't know how, you don't have to know how to co configure it, but you want to use it, and you want to really develop cloud native applications. Micro Kit is a tool for you, right? But you don't want also to have just something which is for development purposes.
You want a unify experience, an Ubuntu experience from development develops to production at scale. My c**k is really the tool for that, right? Because it can run at scale in production.
And we, I'm sure we will speak about the use gauge of ED Cloud, edge Cloud, but this is actually a very hot topic those days. So Edge is, is certainly a hot topic, but you know, when we start thinking about zero off, so we start talking about zero ops. com, uh, nine years ago, 10 years ago now, actually.
Yes, 10 years ago. Wow. 10 years ago.
So it was ops, then it was DevOps ops, then we started hearing about, uh, no ops. Then there was sort of new ops. None of 'em have really, it seems like the names change, but the mission stays the same, right?
Right. I think there is a change here. I think there is an acknowledgement that DevOps before was perceived like platform engineering, right?
It's like, okay, we need to build a lot of things, orchestrating a lot of components, and then we need complex tool configure to configure all those components. Actually, now people realize that no, they need to have yes, orchestration of the pipeline, but they need to have easy, uh, appliance to deploy, right? Even in the DevOps use case, you want to create your Kubernetes instance, do all the tests that you have to do, and then to remove it.
Because you don't want to re to use resource if you don't, if you don't have demand about it, right? So this use case is very, you know, important for us to address, and that's why we have micro kits, because you can actually, as a DevOps engineer, create your c instance, do all the integration tests that you want to do. Maybe you want to offload to public cloud.
And that's why we created micro kits on aws. So you have an AWS appliance in one click, you create a community instance, you play with it. When you are done, you decommission the pipeline, right?
So this kind of use case where indeed you don't have to actually configure everything in term of Kubernetes, but what you are looking for is a unified experience and something really to, to launch. This is where DevOps is going, right? So, so then the complex DevOps is really about, again, orchestrating the pipeline, but each component that you are running needs to be in a wave well packaged well, uh, uh, with a, let's call it a zero ops envelope around it, right?
There is one point which is important, is you don't compromise about security as well, right? Security should be part of the equation. And for us, it's, it's very important.
It's part of the ubu to pro experience where you will have all the things that I mentioned, but it'll be continuously patched, will be continuously updated, you know, with, uh, fixing critical severity because security was behind us in a way, way, right? Everybody now wants to have something. Well, I, I agree with you, security.
So I've been in security for 25 years, and, and you're absolutely right, security was always at the back of the bus, right? It was, it was bolted on after. And now, in the last year, two years, excuse me, security has become front and center in everything.
Not just, you know, os but across, but here, I don't know what that noise is. I don't know if it's coming out. Um, but, but here is the, the crux.
Here's the problem. We've had the ability to patch and to remediate OS and applications for years, getting people to automate, to just say, okay, hey, like, you know, for instance, on our phone, no one thinks twice the phone updates it, no one says anything. Yep.
When we go to update instances in the cloud or a server with mission critical stuff running, I don't want you to update it so quick. I, because they've almost, and, and this used to upset me, people were more upset about if the security patch some broke something down the road, down the line than they were about being in, having an insecure, you know, sure, sure Thing. Stable of Armand.
Yeah. But, you know, yes, I fully agree with you. And that's why, you know, we are promoting the technologies such, such as snap, right?
Because first, when we do an upgrade, when we with the TU live patch, okay, first we update with snaps, we update the applications, right? If there is something wrong, for instance, you can still roll back. So it's a very safe way to patch it, right?
And the, the technology, a snap is very useful for those, okay? Those, those use cases. But also in the iot use cases where actually it's not a server here, but it's a device.
But this, this device should not have any run time, uh, done time, sorry. Right? So you want to update, you, you, you download the new apps, and then you like a firmware update.
When it's ready, you update, and then you reboot just the device, right? So the done time is limited to very, very few seconds, right? So this is a kind of use case where we are working on, and this is the technologies that we have built so far in order to make it happen.
And that'll probably take us into an edge discussion too, as you start talking about these iott. Yeah, yeah, yeah. We move here, you see, I'm moving to the I see what you're doing there.
Yeah, yeah, yeah, yeah. So, Because what is H Cloud at the end of the day is just, you know, putting the, all the iot space in the, in the, in the cabinet or rack, which is close to the antenna, right? Mm-hmm.
So in the Edge cloud use cases, what you really are looking for is zero ups, because the field engineer, what you will do will install the cabinet switch on the machine and do something else. And you will have thousands of edge cloud like this, right? And we are working on you on, on scenarios where you will have 20,000 Edge Cloud for Telco in a country like France, for instance, right?
So in this case, you want really zero ops for each of the edge clouds that you have deployed, okay? All also Edge Cloud are connected to the nos, the network operating center, and are monitored, right? But, but if something is going wrong, you reboot it or you update your roll back to the previous version, et cetera, et cetera, right?
So all the technology we just discussed needs to be there, right? So now we see exactly this use case, which is feasible with micro case, with zero ups, with things also that we are doing already for one year, which is MicroCloud. So if you look, watch out on the MicroCloud, because we will have some announcement for the next cube con, for instance.
And, and this is, you know, it, we are working with some partners and some customers on those use case, and we believe that we have the right technology and the right support from the common, the open source communities to make it happen. Excellent. I wanted to come back to the security offering you mentioned was INU Pro.
And it's great. I, I think, you know, all kidding, and talking aside, it's important. Security is job one for many, many, all of us.
But if we agree, it's so important, will we see this kind of filtered down to, you know, the, the freedom tus and the [unknown] in the version? So, so we don't have different versions when TU Pro, it's a subscription, right? So EZ you are an individual and you wants to have ATU Pro, you subscribe to it, but it's free for you because you have only one machine for small businesses that's the same.
You are actually you. When you have deploying more at scale, then yes, you need to actually, uh, have support from us, which required to pay for the subscription, right? But we want to be sure that the economics are actually me, very meaningful for the people that wants to keep their environment secures.
Cause at the end of the day, our mission is to amplify the usage of open source, right? This is what we're trying to do. And for that, you need to have a secure, stable environment, right?
So, So let me just get this straight up for individual users who may be running a buntu on their laptop, or maybe a server, a workstation, or for small businesses under 10 or whatever the number is, they get the ABU From. Yeah. com/pro pricing.
Okay? Go there, check it Out, all the description, which is aligned with basically what I just described, right? So, because, you know, as, as important it is, as it is for enterprises, it's just as important, you know, if you're a small business, those couple of servers or you know, machines you have are really important to you as well, right?
Yeah. And if you are a developer, you want to have, again, the same experience, but you don't want to compromise on security. Exactly.
So why you have, you know, you have one machine, why you want to pay only for that, right? Yeah. But if you want to go to production in its real business that you're running, you need to be, you know, you need to have a secure communication and support from canonical.
Right? Excellent. So Jake, I want to thank you for coming in.
Thank you guys. It was a pleasure. com.
com. Yeah. com.
I was just gonna say that Canonical has a big business besides Ubuntu as well. We have a company behind Ubuntu, but we're promoting, obviously all the Buntu community and all our fans are here. And it's, uh, it's a pleasure to meet all our fans here.
10,000 people. All right. Hey, we're gonna take a break.
We'll be back in a minute here. If live from Amsterdam, this is Alan Shimmel for techstrong tv. This is Techstrong tv.
Hello. And we're back at Cuban plus Cloud, native Con Europe, and we're here with Jonathan Simons, and we're talking about storage and Kubernetes. Jonathan's with Min io and they are kind of the experts in the space.
So Jonathan, welcome to the show. Thank You very much. I'm delighted to be here.
We were there with you guys last year in Valencia, and we're excited to be back The debate around stateful versus stateless applications. And Kubernetes continues at this show. I'm still hearing people talk about it.
Yeah. So what is your sense of, um, how mature is it for running stateful applications on Kubernetes these days? Cuz there's no shortage of opinions on both sides of the aisle.
Yeah, yeah. So listen, the way we see it is that, um, as we mature the ability to run stateful applications is, is there, um, one of the things that we introduced in the past year is direct pv, um, which allows us a CSI driver that allows you to connect directly to the disks. Um, and that allows you to run staple applications inside the container storage being one of those.
The thing with Kubernetes that I think is, uh, you know, everybody understands, but it's hard to basically engineer it into, is the more you put into the container, um, the more valuable the orchestration can become. And so by having more, um, things in that container such as storage, um, you have more flexibility, you have more resiliency, and you have more, um, basically optionality. And so that's one of the things that, uh, we think is important.
We see folks who have small containers and we see people who have really large containers. Kind of reminds me of the early days of VMs when we had monster VMs. Is there a best practice or a thought process and how those things should be structured?
Yeah, so that's a great question. And I, and I would say that, you know, there is very much of a workload, um, looking at what your workload is and the attributes of that workload and how dynamic that workload is, um, and what the data requirements are are gonna define that for you. Um, if your, you know, data sets are very large, you do an AI ML training, uh, it may be that you need to have, um, a larger container, right?
You want to have more things in there. It it, so it's gonna vary. Um, we don't have any solid guidance to say, you should always be doing this, or you shouldn't be above this size.
Um, we, we kind of take a more of a workload centric approach, uh, when we talk to our customers. Now, as I understand it, you guys wrote your own CSI driver. Yeah.
What was the reasoning behind that? So the primary reasoning was, uh, that we wanted to get at the performance capabilities, right? So when you are going through other, um, hops or or other layers, um, you don't get the full performance.
And so given that MIN IO is a high performance work, uh, object store to start with, and we focus on those high performance, high value use cases, we needed, uh, a CSI driver such as direct pv that allowed us to get directly to the underlying disk. Now, VMware gave us this, um, uh, you know, uh, when we did the, uh, the OpenShift implementation. And so we basically saw the power of that, of being able to get directly to the disks for the best performance.
And so that's why we wrote direct pv. You know, prior to that we were a big supporter of cozy, um, so the container object storage interface, um, and we, you know, had a number of people working on that initiative as well. Um, but it just didn't really kind of catch, um, on with the community.
So we decided that, like we deal with a lot of things at MIN io. We would just give our customers what they really wanted, which is direct access to the disks. Mm-hmm.
Who is managing storage in Kubernetes environments these days. Historically we've had storage admins, but when you look at, um, Kubernetes environments, it's much more converged or hyper-converged depending on whatever buzzword you want to use. Yeah.
Um, so has that function become something that's the compute and the storage all being unified in terms of management? Or is there still somebody who is, you know, king storage? So what we're seeing is that, um, there's been such a change in how storage and who takes care of storage and who provisions storage.
It's really more developer driven than it's ever been in the past. So the traditional IT storage admin, uh, is not really, has not made that leap to Kubernetes yet. The complexity of Kubernetes coupled with, um, you know, just how modern, uh, the overall stack is, um, has really changed things.
So developers, architects are really driving a lot of those source decisions these days, particularly around, you know, as it as it is Kubernetes storage. Um, and so that is a change, right? That's a change in terms of the, the balance of power.
Uh, it's in change, uh, in terms of how you go about looking at security, uh, across these, uh, applications. And, um, so it is a shift and, um, we think that over time it is going to come more up to speed, uh, and, and, and become more adept at managing these things. But today, um, just given, uh, kinda where the stack is, it really is more the developers that are driving a lot of those decisions.
How much are we seeing Kubernetes in an on-premises environment? Because, you know, the noises all around the cloud. Yeah.
But, you know, a lot of customers I talk to are still like, you know, we got data that can't be going anywhere other than our data center. So how much are we seeing Kubernetes in these on-premises environments? So I, we have a pretty strong position here, which is that the cloud is an operating model, it's not a place, right?
When you say cloud, that does not mean AWS, GCP or, or, or, or Azure. Um, min Minayo runs in all of those we're agnostic to this. 5 million ips running today, uh, in those.
And so we run on a ksg Ks and, and, and so forth. What we see OnPrem is that same model. And we're seeing more and more companies adopt that cloud operating model on-prem, particularly as they mature and understand the parameters of their workloads, right?
So you go to the cloud to optimize for developer agility, for flexibility, um, for speed, for provisioning of hardware. Um, once you understand that, you start to think about what's the next level optimization, well, obviously the next level of optimization for you is gonna be around cost. Um, and it may be around some other things.
And so that's when you know how this works, you know, how you deployed it, uh, in the cloud, bringing it back isn't hard. It's the same basically principles that you would use on-prem that you would use in the cloud. So we see Kubernetes on-prem as much as we see it, uh, in the cloud.
And, you know, we've always rolled out this stat, but I think it's really telling, basically, uh, containerization dominates the, the min IO workloads. 64% of all of our workloads that we see, um, are containerized. And 46% of those, um, are, are orchestrated using Kubernetes.
So that's the default deployment model for MIN io. Um, and that doesn't matter if it's in the cloud or on-prem. Do you think we'll get to the promise of hybrid cloud computing?
We've been talking about multiple clouds for a while. When, when you run into hybrid cloud, then suddenly, you know, the compute somewhere else and the data's somewhere else and you're trying to access that and it doesn't always work out so well, cuz you, you know, in the old days we both have some gray hair. You wanted to bring the compute to the data, and I think we're going back to that.
I think we spent 10 years of pushing data away from compute, but are we coming back around? So I I'm gonna say no. Um, I think that our position is that what we see now in terms of kind of this next generation, and listen, let's be clear, hdfs, we're talking about bringing data to the compute.
You know, the entire industry owes us, owes a huge debt of gratitude to that. But that doesn't work anymore from a capacity utilization perspective. Just because you have so much storage and you have so little compute that the the balance is, is doesn't work economically and the complexity doesn't work economically either.
Um, what I think you do see, and when you talk about hybrid cloud, I, I think there's a definitional piece that we should probably address a little bit as well. You know, hybrid cloud would suggest that you have one private cloud and one public cloud. Well, the reality for large enterprises is they have multiple private clouds and multiple public clouds.
And so, you know, we think about that in terms of this concept of multi-cloud. Um, and so, you know, min io is built for that specific use case. Um, you can run min io in both of those locations seamlessly.
Um, and again, you'll find us in the marketplaces and all the public clouds plus, you know, obviously our credentials on the private cloud. So, um, that shouldn't matter, right? And the principles of cloud native architectures shouldn't matter.
So you should be able to run all those things everywhere. Now to your second point around, you know, moving data and so forth, one of the things that I think has been most interesting this year and and over the last 12 months is that you're seeing more and more what we would call traditional database players create the ability for you to query data on external tables, right? So it doesn't have to be there.
So you look at snowflake's external tables, you don't have to move the data into Snowflake in order to query it. You can query it externally. SQL Server 2022 made this a made object storage, a first cast citizen.
Again, your ability to query data where it sits. And again, the point there is that those database companies see themselves more and more as high speed query processors at large scale rather than they do of, you know, I'm a query processor and a data management, uh, platform because the data management problem has become so, um, acute that they need to focus on the thing that's most competitive and their clients care most about, which is high speed query processing. And effectively they're outsourcing a lot of that, um, uh, storage capability to high speed, um, performance optimized object stores.
So what's that one thing you see organizations doing that you know, makes you shake your head a little bit or, you know, what's that newbie mistake or sometimes known as the idiot attacks Yeah. That you would could share with some folks to help them avoid it? Well, um, that's a fair question.
Um, so in terms of things that we see is that we, we, we generally see customers think about where they're gonna go and architect for what they think they can see over the next 12 months. But the timeframe is so much bigger than that when you're dealing with data. And so architecting for the ability to decommission, architecting for the ability to expand over time in a heterogeneous way, architecting for, um, you know, scale in ways that you just don't envision today, um, is the mistake that we see really most frequently.
And we try to guide clients to think, think much bigger than what they are today. Because invariably when you plan small, um, you have a tendency to kind of grow into different problems that you wouldn't otherwise experience. Just think about this, over the last really nine months since chat D p T came out and, you know, the acceleration of acceleration is, is at a level that I don't think, certainly I've never, ever seen before.
I would probably assume that, that you share that sentiment and that's not going to diminish. I, I think that we're in an ever accelerating mode right now and it's scary from a technology perspective, but the amount of data that's going to come out of these types of large language models, um, the requirements that are gonna come out of training on private data inside of these companies, it's going to be such that they want to access everything. They don't want to access small s SLRs of that.
They want to access everything in the portfolio. And I think that's, um, when you talk about planning for scale, if, if that's not a big giant red light on your desk that's flashing for you, I don't know what is, All right folks, they say date is the new oil, but if we don't have any refineries, we're kind of missing the point. Jonathan, thanks for being on the show.
You bet. Thank you. All right.
And we'll be back in a minute. This is techstrong tv. Welcome everybody.
We are, we are at R S A C here in San Francisco, 2023, having some fantastic conversations and I, and I know the next one will be another one cuz Carl and I've had a chance to spend some time together on prior discussions. I'm joined by Carl Tribu, who is SVP product Management and GM application security. Sorry to read the cue card, but it's quite a mouthful title.
It's a lot of responsibility Carl. Yeah, no, I appreciate that. Thanks for having me here.
I'm excited to be here and talk to you today. Cool. Well tell us about you and tell us about, uh, a little bit about your role at Imperva.
No, absolutely. So at Imperva I'm responsible for the application security business unit and we formed that about a year ago, about a year and a half ago when I joined the company as previous, previously with aws. I spent many years at F five in, in previous company.
So I have a long kind of history in the application security space. And, um, but, but they wanted to build this bu cuz we specifically wanted to ensure we had, you know, that that intense focus on our application security solutions and our roadmap and kind of where we're going into the future and kind of bring, you know, the experience that I've had and help build a team and you know, a whole group around that. And that's what I've been doing this last year and a half.
And so Very representative of the market, kind of all of us have shifted from just security to also application security and how that's part of the bigger picture. Yeah, absolutely. In fact, it was interesting cuz you know, I go way back to the early days of application security and the whole idea around it was the perimeter was changing.
Mm-hmm. Right Before it used to be more, you have an edge device, you have your firewall, you have a DMZ and you're trying to protect there. But, but the real perimeter was around that user session and how they're accessing content that the application is managing.
So how do you protect that? And so now today we've, we're extending that obviously over time is that cuz there's new types of threats that have come, but the application has always been that kind of that fertile ground where these attackers go and try to mine and, you know, plant their seeds of discord to extract your data. And that's, and they've been very successful in some cases with that.
So it continues to be an area, a ripe area for them to go off an attack. And applications of course change. The application footprint has changed massively in the last, you know, 10 years.
It's no longer these monolithic apps. It's, you know, it's now these very distributive apps that are running on different types of infrastructure. They could be apps that are running under cloud VPCs.
They could be running, um, in Kubernetes clusters. And these could be of different types of Kubernetes clusters. They'd be running as virtual machines, but they're highly distributed.
And you know, part of the rationale for that is that it gives you, you know, in some ways I I think of it as like Java two, ik, you know, Java, when Java came out, the whole idea right, was that hey, I can run this on any hardware platform. I no longer have to just build my applications to be targeted for a particular CPU type. That's what's happened with Kubernetes and infrastructure and applications is now I can run 'em anywhere.
So yeah, that and containerization and now the fact that we built our applications more API first API centric, that that is kind of the new attack service. Of course bots love that. Right?
Absolutely. More things to go after. Absolutely.
Talk a little bit about that cuz you obviously are, you know, right in the center of that in so many important industries like finance and, and others. AB Absolutely, you know, the world has gone to APIs, um, and part of that is that there's the whole aspect of automation. So if you look at your, you know, your phone, any individual app is accessing, you know, maybe 10, 11 APIs during any particular session.
Mm-hmm. So, you know, that's the whole mobile, you know, world now. Um, and in fact we, you know, um, we're gonna be publishing our annual bad bot reports here in the couple weeks.
Um, and this is our 10th edition of doing that. But one of the things I think is interesting now is that when you look at the, the application traffic, over 60% of it on the internet now is mobile based. Mm-hmm.
And so what we're seeing is that transition to more of the mobile devices. But, but um, but on top of that there's interesting and unique challenges because, um, now the mobile, you know, like Apple and others are providing all these privacy features. Mm-hmm.
Um, but with those privacy features, they allow your attackers now to obfuscate be obfuscated. So it's actually created a new attack surface, for example. So that's, that's one area that we look at.
But overall, when you look at bot traffic, about half of the traffic on the internet is, is basically bot based traffic. Mm-hmm. So just under 50% and that's a 5% increase, um, in the last year alone.
And that's pretty steadily that we've seen these increases. And there's a variety of reasons for that obviously. But bad bot traffic is a large percentage of that, you know, close to 60% of the bot traffic out there is bad bots, um, doing malicious things in many different ways.
Um, everything from trying to take over accounts or steal data or create DDoS, floods, you name it. And so that, that, so that's the big trend that we see. And one of the areas that they focus their attacks on now are through APIs.
Mm-hmm. Because APIs do not have the same legacy of kind of the traditional web front end application backend and all the mechanisms you build, you know, into that. APIs are freeform, they are developed by develop, they're built by developers, managed by developers, and the security teams have very little control or management over that because it's been part of that workflow.
Mm-hmm. And so those have become that big attack surface now, and bots just line up nicely with that. Yeah.
What complete aside, I don't know whether it's start a show called Bad Bots. Bad Bots, or maybe there's a band I should start called Bad Bots anyway, Complete side, that bots Yeah, It's interesting because I mean, just operating as a much smaller infrastructure myself, um, and, and you as a company who not only a product company, but you have your own, you know, cloud provided. Mm-hmm.
Yep. It is something you deal with directly as well, so you see it yourself as well as what you see through your customers and what's happening. Absolutely.
Yeah. In fact, that's one of the benefits. You know, we provide a, a, you know, we have a large SaaS based service mm-hmm.
And we, we have a run our own network of pops, global pops, and we, we see about 9 trillion, I would say, attacks, um, in a given year. Mm-hmm. You know, so we see a ma we get a massive amount of data mm-hmm.
And we leverage that data, you know, obviously we anonymize and do things like that, but we leverage that because, um, we're able to then see something that affects one customer or developing, and then we can apply those rules that we create for that customer across our entire base. So basically you get kind of that crowd sourcing in a sense, uh, of the data. Now we use all sorts of other feeds as well, but, but that's, that's, you know, we see a lot of benefits to being able to provide that type of service.
The other thing is that we, we can update it real time. So for Log four J for example, um, we saw that the attacks start to occur. We started seeing 'em about a week beforehand, and we, we went and analyzed those and we'd actually built signatures and had those deployed long before the announcement came out.
Mm-hmm. And then as the attacks mutated, we were still on top of that, we could see that and we were automatically updating and blocking on behalf of our customers. We, we literally add, you know, or change our rules on a daily basis, you know, behind our waf for example, you know, hundreds of rules, you know, and we do that transparent, you know, transparent to our customers.
So they basically, they get the protections. They don't have to manage the rules, it's just easy to onboard. And so one of the stats that's funny, so when I first joined Invo, like I said, I was here 18 months ago, they said they go, oh, 90% of our customers use some blocking mode right out of the gate.
And I said, no way. That's not, yeah. I wouldn't have guessed that.
I wouldn't have guessed that. I would've said 25% best case at the time May maybe, and I thought you exactly, maybe 20%, you know, maybe 15, you know, I've been just coming from my experience. And so, and sure enough that was the case.
We went through the data and I went, wow, that's an amazing stuff. That's pretty, that's pretty shocking actually. So, so I, I was, you know, so it just speaks to the effectiveness mm-hmm.
I think of, of having that type of curated service that we can manage and provide out to our customers. And so, you know, and when you look at kind of the way we were architecting our roadmap and our products, and we talked about kind of this, be able to run anywhere motion. Mm-hmm.
But it's also about ease of security management, you know, that, you know, we, you know, there's an interesting report out that we published, um, um, well we didn't publish it, but Secure IQ Labs published it. Um, and uh, they, they basically tested a bunch of different, um, providers in our space and we wound up having what they call the highest return on security investment of all of them by far. We were kind of in that poll position.
And what they evaluated was, um, was the effectiveness of the security. So did we block, you know, these different attack types? They measured false positive rates, which goes back to what I was just saying about people being, putting us in blocking mode because Exactly.
You don't need that alert fatigue. And then the third thing was they evaluated ease of management, you know, and updating and how you manage it. Um, and you take all this three into effect and boom, we, we were the top notch by quite a, quite a spread actually.
So, so we're excited about that, but that it's exa you know, finally we got recognized for something the other analysts don't necessarily recognize you for. That speaks to the core value proposition of Imperva in our, in, in our, in our portfolios. Mm-hmm.
So, so we, we keep building on that, you know, make that easier because at the end of the day, I think the threats continue to get much more sophisticated. You know, AI is gonna create a whole new spectrum of problems mm-hmm. You know, for, for applications.
And so we need to stay on top of that on behalf of our customers because it's so, so hard for them to be able to do that. And that's hence why I think that whole ro you know, the rosi is such important metric to think About pretty much. So, you know, that that high auto automated block rate, I think I was also representative, patient of trust the customers have in you, right?
Mm-hmm. Wouldn't do that if they didn't trust. If you're making that kind of change to adapt, then obviously they're counting on you to do that and do it smartly and wisely and, you know, proof is in the pudding.
So that's, that's great news. I'm, yeah, absolutely. I'm curious about your thoughts.
You mentioned ai. We monitor, by the way, have our end of every interview before AI comes up. So we're, we're pretty well on track here.
So I checked the AI bingo card. There we Go. We go exactly.
The duck comes down, you know? Um, gimme your thoughts about the role of AI today in security products and technology, and also, you know, how do you see the attackers leveraging that? I mean, none of us can predict the future.
It'll, it'll happen the way it happens, but kind of what do you see that right, that forefront look like? Yeah, so we use a lot of AI today on the bot front, especially because you know what the bots, you know, if, if, and you'll see this in the bad bot report, like I mentioned, but the sophistication of these evasive bots, that that's about half of the bots that are bad bots that are out there. Mm-hmm.
But that sophistication continues to go up. And so today though, for an attacker to build that, they pretty, man, they, they basically have to get the sit down with the code, punch it all out, try it, see what comes back, update it, try it, maybe they build some of that into the code that can do some of these things a more automated way. But they're the ones, basically, you have a human in the middle of this recursion.
Mm-hmm. As they go through and try to try to look at that. Well, um, you know, and that works great for us cuz we can block and defend against that.
But now imagine being able to put a self-learning model mm-hmm. In, in the middle of that instead of that human, so it can much more quickly adapt and update. So it's kind of like, uh, I dunno, your Star Trek fans out there, remember the borgs, you know?
Mm-hmm. Um, mm-hmm. And you know how you, you know, you would attack and then they would start rotating shields and things like that, and suddenly, you know, they get a get offend.
Well, that's exactly because they'd learn. Well, that's exactly the type of thing I expect to see from the attackers is they're gonna learn a lot quicker and be able to zero in on attacks. So, for example, let's say you have a big breach, like a data breach, and they get a bunch of these files, they're gonna go out and start just instantaneous go after all these I ATO style attacks.
Mm-hmm. And so as a, as a, as a security provider, we actually have to, you know, essentially provide that rotating shield as quick as we can. As they learn, we have to learn faster.
And that's our, that's how we think about our use of ai is the ability now with these generative ai AI systems, is that we train the models based upon what we're seeing and quickly then update and iterate that. Um, and also use that in predictive ways where you can say, ah, okay, based on what were these behaviors now, what would we expect to see based on that? So we're actually trying to predict what the AI is, you know, AI is gonna do with that.
And so that's why I see one major area of that. But, but we're using now, um, we're using it through all parts of the organization as well. Um, like on my product marketing team, you know, we're, we're actually, we actually built an interface, um, a web-based interface that helps us create content much more quickly, you know, so to me it's like a force multiplier.
Mm-hmm. You know, things like that. And so we're using it elsewhere within the organization to help assist us do things faster, not just on the security side, but also on helping educate customers and produce content and things like that.
So. Excellent. So it's very broad based.
You Just have to keep us from all becoming leq to Subor. You knew, you knew, I knew my story, But I was just watching Picard last night. Okay.
Excellent. Excellent. Well, let's, let's shift, and I appreciate your perspective on AI very much, very much.
Um, not, not our first rodeo at R S A C, right? Yeah. We've been to several of these.
I'm curious about your perspective on, on how this year has changed Yes. Has changed as in we're kind of back and it, it kind of feels like the, the healthy vibrant RS A C again. Um, but what, what's your perspective on what's different about this year than maybe in years past?
Yeah. You know, and we were talking a little bit about this earlier, but, uh, the one, one of the trends I think is going on is, yeah, yes, we're back. Uh, but, uh, I think what we're seeing now is an acceleration and change of customers infrastructure and the applications.
Mm-hmm. That, that is, that during the Covid lockdowns, a lot of, a lot of organizations, companies went into kind of stasis mode. They were trying to preserve what they had.
They're trying to support the remote workforce. They're, you know, trying to ensure business continuity through, through kind of that, that scenario. Um, uh, and so they had to invest in those areas.
Um, but now coming out of it, you know, one of the things that, uh, in fact, I was at a CISO round table a few weeks ago, and this is pretty common when I talked to our customers, is that the, the, the big quote was, we want to do less with less. Mm-hmm. So they're looking at ways to consolidate their security services, um, so that they don't have kind of this Congo line of different products.
Mm-hmm. They want to get to more, I don't wanna say a platform approach, but they want to be able to, to narrow down the number of their kind of trusted security partners work With. There's complexity, you know, absolutely.
Costs are managing that. Cost is a big factor in that. Um, in fact, and, and then the second piece of all this is that now as they're, as they're trying to manage their costs, they're trying to, to change their infrastructure to, to help manage with that cost.
So, you know, before they'd say, all right, we're in aws, we're gonna stay in ADU at, despite the cost, well, now it's like, well wait a second, we're gonna go more multi-cloud. We wanna optimize. Maybe we'll run this service over here, this one here, but we don't want to be so beholden to any particular cloud player.
And that's one of the big themes we see now is multi-cloud. And also even a lot of customers bringing, um, some of their, uh, services back into their own infrastructure, their own data centers. I don't think they're gonna grow their data centers massively, but they want to have that choice and that optionality, because once you get locked in to a cloud, the costs just go one direction.
Mm-hmm. You know, and they can, they can spiral pretty quickly having been in, you know, working for one of the major cloud players myself. Mm-hmm.
So I know exactly kind of the, some of the challenges there. But, but, so I think those are the two big themes is how do you manage costs? And then on top of that, it's like, how do I get on top of these new threats that are out there?
These business logic attacks, these other very sophisticated attacks that are occurring so that I don't have to hire these very vertically oriented, sophisticated security teams that are very expensive and pretty much unobtainium for most companies. Right. So that's, that's kind of how, you know, that's, I think those are the factors that are changing the conversations here at rsa.
Mm-hmm. So what's been great for us is we've just had really good in-depth conversations with customers, not these superficial kind of fly by things. It's been, you know, very meaningful.
Like, Hey, how do you help us, you know, solve these issues? Um, and so it's, it's, it's, it's nice to see this, you know, back, you know, it's A really good point cuz I was talking with your, your cto, CISO Canal mm-hmm. Anand, and he and I were talking about, we've kind of entered a next generation of CISOs who weren't strictly, kind of came up through the sort of paranoid network mm-hmm.
You know, kind of mindset of don't tell people what you're doing, don't share what products you're using to people that maybe have some more software experience, but are also have a, an open, more openness about wanting to share converse and talk and how you solving this problem, what's happening here? Are we on the right track? Are you on the, you know, let's, let's collaborate more across maybe within competing in inside an industry.
Yeah. AB absolutely. In fact, you know, um, I, I think it's very analogous to what happened with CFOs years ago.
Mm-hmm. Because originally CFOs were more focused on, I'm, I'm managing the finance side of it, I'm, you know, the accounting pieces of it, but not necessarily a partner in the business. Mm-hmm.
And so over the last 20 years that that changed radically, where this, the, the, the, if you'll get a cfo, yes, they still have those responsibilities, but it became more of how do I partner with the business units or with the, with the, the, you know, the sales functions and all that to drive the business to grow it. How do I become a piece of it, not just kind of, you know, so being more proactive, the CISO's done the same thing. Mm-hmm.
Um, and it's that, uh, the problem is that you can create all sorts of obstacles, you know, in security. Cuz you know, security is one of these, it's a spectrum of things you can do. In fact, you know, I've always said selling security is excelling an insurance policy that, that you're only willing to spend so much for perceived level of security.
Mm-hmm. Um, and, and there's a lot of things that go into that. Right?
And so, so the CISOs could be way up here and they could be, you know, hurting the business because they're not taking a more pragmatic partnering approach. And so when you talk to Canal, that's been his approach is how do we partner and ensure that, that we have the right, you know, absolutely the best security, but let's ensure that, that it's, it's aligned with our business needs and our customer's needs and what we're doing there. Um, and so it's a more collaborative system.
And I think that's a general, a trend over most executive roles in the industry is, is we've kind of moved more to that instead of these strict kind of, you know, you know, functions that would've existed thir, you know, 25, 30 years ago. And I think we needed that level of conversation, the engagement with each other. Yeah.
A absolutely, because, you know, a lot of the, the problem too is that there's a lot of, you know, we're going, you know, we do the PCI audit process, for example. And so there's a lot of nuance to, to understanding how that your, your systems are either vulnerable or affected that, that, you know, you need to be able to have kind of that closed loop conversation to say, well, here's how data traverses our network and here's what it accesses it. Oh, now I understand that.
So yeah, you don't need to change that. But over here we see that, you know, it becomes more of that kind of conversation, like saying, instead of them coming with some template and saying, you must conform to this, and then you go through a two-year dev cycle or something like that. Mm-hmm.
You know, you can't have that. It's, the business needs to move quickly. And so, and hence every part of the company needs to move at the pace of the business.
And so security has to be a part of that. Yeah. You know, we actually see this with our customers as well, is that, like, for example, we're seeing, you know, the business teams now have much more say in what security products are getting selected.
Hmm. Because again, it goes back to, it goes back to the pace of business, you know, and, and, and as things become competitive, which I, you know, you see it in the tech markets, you know, all these, you know, start, you know, startups is, um, things are getting more competitive. And so you need to make sure that, that you have a way to move faster than that competition.
I think it's a great note to end on right there. Terrific. All right, Carl.
All right. Hey, thank you for having me now. Good stuff.
Excellent. Carl, Carl with, uh, SVP with Imperva. You're welcome back anytime.
Love talking with you. Thank you So much. You bet.
Cheers. We'll be back. We've got some other great conversations.
So from R S A C to you, we'll be back in a few minutes. This is techstrong tv. Well, the great pleasure of being joined by Arthur Higgin.
Arthur is evangelist with Parasoft. Welcome, Arthur. Hi.
It's great to be here. Um, good, good to be on talking with you. Always fun to talk to, uh, someone in an evangelist role because you like to talk about what's going on and what customers are doing, and that's all good stuff.
Before we get to that, and we're, we're gonna talk about software testing and some interesting aspects of that. Would you tell us a little bit about yourself and tell us a little bit about Paris off? Yeah, so, uh, I, I'm the evangelist of pof, which is, uh, it's a great ice icebreaker for any situation.
It's an interesting title, but I've been at the company since let's say before the worldwide web and, and leave it at that. Okay. Um, we make all kinds of automated software testing tools, and, and it's, it's been an interesting and fun journey.
We, we are always looking for ways to take something that's tedious, boring, and free people up to, you know, do something clever and interesting and hard because software engineers like to do challenging things. They don't like to do boring things. Imagine that.
Mm-hmm. I can relate to that too, being a software engineer way back, and then today for that matter. Yeah.
You know, talking about that kind of longevity in the career in your career, Arthur, you know, testing has certainly changed a lot, just like software development with Agile and new kinds of architectures like Cloud native, et cetera. And, uh, one thing that I find fascinating, we did a study well while back where testing was kind of thought of as a back, back office thing, sort of, we might do it if we still have time, you know, at the end of the release. It always got squeezed today.
It is vital. I mean, and people know it, people know that we've gotta do a good job of testing and build that into the continuous process about how we create software. Are we, are we, I'm assuming we're in the similar neighborhoods on that same page on that?
Yeah. Yeah. You know, I, I hate to say it.
I remember when, uh, an enormously huge application might have been two or 300,000 lines of code. Right. Like, we thought that was, that was really something.
And now, you know, a car with over a hundred million lines of code is, is kind of normal for modern high-end cars. Mm-hmm. But yeah.
The, you know, unit testing, did you have to do it right? Like, did it really matter? And, and people are still following on that journey in their own organizations, but yeah, it's, it's just one of those things, static analysis, right.
That was definitely, uh, you know, an interesting technique and now you just wouldn't think about living without it. Right. And exactly.
It, yeah. It's, uh, it's a much more mature discipline. Mm-hmm.
You know, the, I remember one of the early automations that we made internally was a, a simple script to run our, our regression suite over and over. And, and it had some little cues in it, like it would summarize the failures, and if it was over 80%, it would say, ship it. And if it was less than, you know, 80 and more than 70, it would be like, maybe you should check it.
If it was less than 70, it would be, you know, you need to do more tests. If it was less than 60, be like, go fire somebody. Right.
That was like our first level of automation. What we need is a bahe script telling us whether to ship it or not. Yeah.
Yeah. But that, but that is, you know, I mean, that is the goal with C I C D, right. That you have some kind of a, a definition of done and that the software can move itself along based on hopefully more than just like, past fail rate.
Right. But, uh, yeah, it was something we were trying to do. I mean, it was, it was ridiculous.
But it's, in, in today's world, you have all this complexity, so many lines of code, so many dependencies. You, you know, you're, I, I always think about like rebuilding my sprinkler system with software and, and connecting it to like, to Noah, so I know when it's gonna rain and I can turn the sprinkler off and I can connect. I live in California.
We have regulations about when you can water. And so connecting it to that in the time of day, and is the ground wet? And, and maybe I can tell if a pipe is versed, you know, like, like all the complexity in the third party de dependencies that applications have now.
Everything used to be monolithic. Right? Nothing's monolithic anymore.
When you hear, there's all kinds of stats. If people have different numbers around how much of our application, how much of a code that we ship is actually open source, third party, other systems interfaces to online services, you know, upwards around your numbers tossed around 70 to 80%, which probably is true in the end when you really think about software stack that we're operating on both the application infrastructure of the app itself and Yeah. All the underlying technology.
I'm curious, what's your perspective on, you know, we talked about, so my, I remember many times, you know, when I was running product development organizations, ShipIt was, I would go talk to the QA team and tell 'em, tell me what's going on. And I would know by the kind of, and the severity of bugs that we had found, whether we're gonna make it or not. I'd know weeks before, like, yeah, we should be here by now, or we're not there.
But that, those sort of gut feels, I'm sure probably still are part of the equation, but how do people make that, that decision now with quality and QA and, and, uh, development and, you know, platform engineering and cloud engineering, all the different, you know, pieces that go into shipping software. I, you know, I've, I did an interview years ago, and one of the guys is like, gut is all that matters. And if you have a small group and a well-defined project, like if you can hold it all in your head, it probably works as well as anything.
But again, we have, you know, distributed teams and distributed technologies and, and your really DevOps, you're taking into account the deployment platform and the third party dependencies and, and the, the quality of the open source you're using, uh, your gut can't be it. And by the way, if, if this is a machine and it's kicking off a build and then a set of tests and standing up virtual machines and, and setting up services in the cloud, automatically deploying, how does your gut fit that? I can't even pace with that.
Right? Yeah. They can't be a, yeah.
Check how Arthur's feeling Yeah. Press here to continue. So To read a lot of, a lot of logs between, I, I do think people have to do it.
And, and when you've had, you know, been relying on your gut, you have to step back and say, what was it I was noticing? What was I paying attention to? And I do think that understanding what were the criteria we were basing it on?
Was it, was it the volume of the test? Was it the failure rate of the test? Was it the severity of the tests that were failed?
Was it the, you know, in a, in a simplistic traditional model, we looked at, if you had good beta testers, was the flow of noise from them shrinking? You know, the, what's the variability in the, in the failure rate day on day, there's lots and lots of numbers you can look at. And I, I don't believe that there's a single number that's right for everybody.
I do think it's really important today to have some idea of what you're measuring, why you're measuring it, a way to measure it so that you can tell if things are getting better or worse. And if, if your gut says things are better and the metric says they're worse, fix the metric. And if you're, if your gut says things are good and, and things aren't good, fix the metric, right?
Mm-hmm. And, but get one that, that works for you, right. That, that matches your gut.
Right. It seems like we, we've elevated the role of testing in our delivery process now, partially because, you know, developers more involved, oftentimes not always in, in creating unit tests and automating testing with, with QA teams, but it's happening so much earlier in the process, and it happens continuously, you know, as code checked in and environments are set up, um, it isn't the thing that gets squeezed. Documentation in QA gets squeezed at the very last, you know, hours of the, oh yeah, we did some before we ship code.
Um, fortunately we, I hope those days are gone. But it seems like the discipline of testing of QA is, uh, it is got more engineering to it. It's got more visibility to it.
It's a profession. Uh, not that it wasn't before, but it's even a, a, a more, a greater profession than it may have been a decade or two ago. Is your sense the same thing?
Yeah. Yeah. People, again, people were relying on their gut and doing a pretty good job, but they, you know, they've formalized and learned best practices, and we've shared those best practices and, and we, you know, rationalize the techniques that we've used over the years and decide which ones are actually having in effect.
You, you can do a lot of testing and not end up with much of a difference if you're not doing the right thing. You know, the, the common answer I used to get, if I'd ask somebody, are you doing unit test? Yeah.
Well, how much are you doing? And I'd get a quantitative number, we've got 10,000 tests, we've got 20,000 tests. I'm like, I, I don't know what that means.
Like I literal, you know, like people testing without coverage. Uh, so I don't know, did you do a good job? Did you do a bad job?
Like, I, I can't tell that. So those kinds of things have definitely changed, right? Mm-hmm.
We've, we've learned to quantify what we're doing to measure what we're doing and, and to share that knowledge, right? It's not just that you'll hire, you know, an old guy with gray hair and have him tell you how it works, right? Yeah.
Yeah. Exactly. You can trust me.
You can trust me. I know what I'm doing. Every software release, it gets a little grayer.
Yeah. Well, let's, let's jump ahead. You know, the hot topic right now is of course, ai, ai, ml, generative ai of course.
Which at G P T, I'm curious, you know, every, every tech company is either has incorporated AI and part is part of their product and or, or is in the process of doing that. And of course, I think as technical people, we're always skeptical, right? Is it, you know, is it a case statement or is it really a machine learning algorithm, and what is it doing?
Or do I need to really know that? I mean, that's, that's probably the better question is I don't have to be an AI ops person to run your testing product, but I do want some of the benefits you can gain from ai. Yeah.
Yeah. And that's, you know, that's, that's really how I like to roll and how we like to roll with, with ai. There's a, there's a lot of startups that are playing with some really cool tech right now, like abs and everywhere in every area, right?
This crazy, crazy cool stuff. But some of 'em, you have to really understand ai and, and even I think about using like, you know, generative ai, you can ask basic questions to get amazingly good answers, but sometimes to get a really right answer that a human would've done, you've gotta go back and understand how to ask the question. Mm-hmm.
How to prompt the thing. And, and I feel like I want my AI to be behind the scenes. I, I, yes, it's telling me what to do, but I don't want it to feel like it's telling me what to do.
I want to feel like it's just making my life easier. It's doing, it should be my servant. I don't wanna be its servant.
Right. Or Assisted to you, you know, something That's helping. Yeah.
AI augmentation, taking over tedious tasks and, and, you know, watching and viewing and monitoring. So if I stray from best practices, it can gimme a tap on the shoulder and say, Hey, hey, Arthur. I wouldn't, I wouldn't do that that way if I were, you.
Remember, we have to, we have to do this in Europe and we have to comply with gdpr, right? Or mm-hmm. We have to worry about privacy.
We have to worry about performance and, and the system reminding you, or, Hey, you know, your coverage is a little low here, which you'll like me to try and bump it up. I, I've got a few things I can try to increase the number of unit tests and, and I think, I think AI under the hood, just helping you work is much better. And, and as much as, you know, engineers, we all want to know how the AI did it, but you know, if it starts doing the right thing, it, it matters less and less.
Right. You learn to trust, trust it. You Trust it.
Right. Exactly. Now, that may be the most dangerous thing ever, because, you know, if you've played with these things, you see that sometimes they give an amazingly good answer.
Sometimes it's like the obvious, and sometimes it gives you an answer that looks right and is just wrong, and that's insidious. Mm-hmm. Right.
If you're generating code and the code looks right, and compiles code can compile and be horrible, right? Like, I mean, it can compile and pass static analysis and not meet the business requirement. Mm-hmm.
Right. 1, 1, 1 minor thing in an interest calculations is, Yeah. So I, I think that the generative AI stuff is cool, and it's gonna be interesting to see how it really shakes out and how we, how we learn to use it in a regular life.
But I think it's made testing far more important than it was six months ago. Mm-hmm. Right?
Because now we really have to look at things and because they're already done, they've missed that first layer of eyeballs. Normally, developers are staring at now, if the developer is cutting and pasting from an AI thing, he may be doing a quick once over, but hasn't looked at it as deeply as he would've if it was written, you know, by himself. So yeah.
Testers really have to be out there understanding is this working? Not just is it well built, but does it really do what we want it to do in all the cases that we want it to do it. Mm-hmm.
And, and I think we're still in the formative, uh, phases, if you will, of how much of that are we going to use. Now we have, you know, in intelli code and co-pilot and things like that are built into our IDs, and those have been with us for a long time, and those, they're becoming more intelligent, um, gender of AI based. There's also the go into Chad G P T and say, write me a Python script that does blah, and it might work, you know, I'd have to like, let's run it and play with it and test the code and really see, but it's sort of like taking a, it's, it's kind of a touring test for code, right?
All right, let me see if this really actually does what I asked it to do. And if you weren't the person at the right level of skill. Yeah.
So maybe we just take that, paste that into their, uh, browser or their runtime at home or whatever, and think, you know, it's kinda like that spreadsheet that's rud with errors, but you don't know it unless you know how a spreadsheet works. Yeah. Yeah.
And that, that's the the most scary thing, right? Because some tests are completely safe and innocuous. I mean, even if they're giving you a wrong answer, they're not, they're not harming anything other than lying to you.
But, you know, imagine that you're working for a bank or whatever, and you're doing some real testing and, and somewhere the script does something really stupid and starts changing people's balances, right. Or, or deleting accounts. And it can be a real nightmare, you know?
And it's certainly plausible that this is going to happen. It will, it will be one of the outcomes. I don't think it should stop us from using ai, but I do think that we, we need to really take a, a cautious look.
I I almost feel when I'm having these discussions, that we need to have like an s ae level like we do for driving. Mm-hmm. Mm-hmm.
Mm-hmm. Right? Where we have level one and level two is the human's really in charge and level three, the, the system's in charge, but the human needs to keep an eye on it.
And I feel like we're probably at like level two right now, s a SAE level two with, with some of this stuff where we're asking it to do a thing and it's giving it to us. And, and we may move very quickly into a level three where it's the driver and we're supervising, or we may not, that might take five years. We don't know how big and how quick the next leap will be.
It'll be fascinating. But at the moment, I don't think AI's gonna like, destroy tester's jobs right now. I think it's gonna create them.
Ultimately, change always destroys, but I, I think in the short term, I think it's gonna help testers get more work done. And, uh, Hey, Um, before we run outta time, I make sure we, we have some time to talk about your conference that's coming up. Yeah.
Uh, tell us a little bit about that. Yeah, so this is the automated software, uh, testing and quality conference. We've been doing it for a few years now.
And it's a really fun event where we actually reach out to our customers and, and we, we reach down into real practitioners and talk to them about problems they have. So they're on, and they're doing a short presentation, maybe 15, 20 minutes, talking about an actual business problem, what they did to solve it, what worked, what didn't work, how they figured out their metric, their determination of success. And so, you know, my goal is that you could show up there, no matter what business you're in, here's someone else's problem.
Maybe they're a bank, maybe they're a car manufacturer, but you can hear that problem of, you know, expensive resources, decoupling, uh, doing security earlier and learn what someone else did and go, Hey, I, okay, I can apply that in mind. My goal is at the end that everybody's learned how to solve some problem. Not how to use the tool, but just how to approach the problem that you have that other people have the same problem.
Guess what? Every, we all do have the same problems, right? Well, That's what we're sharing those stories, right?
We're sharing those experiences. Yeah. Yeah.
So it's, I think it's really fascinating. We also have a, you know, a speaker, uh, from Forrester, uh, Diego Uch talking about AI in general and about touring bots. And so that's some fun stuff, and we'll, and we'll cover the spectrum ai, uh, use at Parasoft.
We basically implemented little AI augmentations at every layer of the testing pyramid, whether it's, you know, UX testing or, or all the way down to static analysis, just different aspects. So we'll talk about that. And it's, it's, there's some pretty interesting stuff.
All just designed to make people's everyday life better as you're, you know, either developer or a tester. Very cool. Now, is this a all virtual conference then?
It's on May 16th, right? Is that Correct? Yeah.
Yeah. It's May 16th and it's virtual. It's, uh, four hours starting at 8:00 AM Pacific.
So whatever that translates to where you're at, uh, again, the sessions are, are pretty short. They're roughly 20 minutes. There's a panel.
We have the, uh, the ability to do q and a with people, so you can ask live questions of the speakers without pestering 'em at the end. We'll, we'll get a few people together so you can ask. So if you've got questions, it'll be great.
But I, I think it'll be a lot of fun. And of course, afterward we'll make things available through, you know, various channels like YouTube. Excellent.
Excellent. com site. Find out more to sign up and of course, check out your products and the capabilities that you have.
Yeah. Go to parasoft and then hit that register button. And we'd love to see you there and hear from you there.
And if you've got a great story you'll wanna tell, I'll reach out to us. Very cool. I'll bet some folks do.
I hope. I'm sure they'll be using great ones. Well, Arthur, thank you very much for spending some time with us and chatting a little bit about, um, both software testing and kinda how it fits into the today's age of software development and where we're kind of going with AI and some of those capabilities.
And it's been a lot of fun. Wish you the best at the conference. Thanks.
It's been my pleasure. All righty. Please check 'em out.
com and you can, uh, find out more about the automated software conference. All right. Thank you much.
We'll see you soon. All. Okay.
Hi everybody. Mike Rothman here with K Flu voice. So, um, yeah, I'm getting over a little bit of a head cold after, uh, a couple of weeks of travel, uh, including the R S A Conference.
So in this week's Techstrong Research Review, we are going to talk a little bit about what we experienced at R S A, who we saw what we, you know, thought the themes were, you know, kind of just really the general perspective on, you know, what the show was. I'm joined as always by my partner in crime, Mitch Ashley. Mitch, how are you?
Good, Mike. Welcome. Good morning.
Happy, uh, being in town for a whole week. Happy Being in town for a whole week. Yes.
I spent the weekend moving my kids out of their freshman dorms, so my, thankfully I didn't break anything. My knee held up well, my back, you know, held up pretty good. So, uh, I actually feel pretty good, so, Okay.
That's a successful move for your kids. Pretty Serious, no doubt. But I, I, I gotta tell you, it, it really was great being, you know, kind of at rsa and, and so many of my friends are like, ah, I hated, you know, I don't like to go.
And man, I missed last year cuz I, you know, an overlapped with the family vacation when they rescheduled it. And I got to see so many people I hadn't seen in a long time. Right.
You know, some folks are doing great, some folks about a little bit of a rough go over the last couple years, but it was really nice to really catch up with folks right. To make that human to human connection. Which, you know, we kind of forget over Zoom.
I mean, again, we're fortunate, right? We get together at least once a month, if not a little bit more. Um, so we get to see each other.
But, uh, again, there were some folks I hadn't seen in a couple years, so that really was, you know, to me that was the highlight of that side from, you know, kind of all the, the, the mess around security, really kind of being able to reengage a a lot of those relationships was, was fantastic. And I got all new wardrobes. See, Mitch, you, you make me this.
Yeah. And you, uh, you, you should, uh, start the text strung research catalog there. You're looking pretty stiffy iy, there it Is.
Pretty spiffy Under Armor shirt on that part. So Mitch, what were your general impressions that you know about the show? You know, uh, so, uh, number one, everybody kept saying, yeah, it feels like RSA spec, this feels like the old R s A that we, uh, you all kind of know and love.
Like Yeah, it does actually felt like, other than gaps of seeing people, it felt like r s a of all, um, in that respect. And, and to your point, you see a lot of people that, you know, but also I got to meet people I had not met in person yet Right. Who I'd been talking to over Zoom for a year or two or three.
And that was really nice. And then there were people I met who, um, like DJ Shaleen, who lives in Golden Colorado, you know, about 20 minutes from where I lived Yeah. That I'd never met in person, but we gotta go to, gotta go to, uh, San Francisco to see.
But that, that was definitely, I mean, I didn't hear anybody say, yeah, eh, it still seems a little loft. No. Everybody kind of felt like back to normal for the most part.
Yeah, yeah. So, Yeah, I mean, it was obviously the show floor was bonkers. Right?
You know, I went down there, you know, two or three times for meetings and it was loud. Right. Everybody was trying to grab at you.
It felt like going through a gauntlet. I mean, you know, for me it was yeah. You know, one hand, like, totally disconcerting because I'm just not used to that.
Right. Just the, the blinky lights and the, and and all the noises and people grabbing at me and stuff like that. Um, but I got to run into a whole mess of other people that I wouldn't normally see just by roaming around.
Uh, so it was, you know, a little bit of, give a little bit of take, uh, on that front. I, you know, nothing, everybody kept talking about the themes, right? Oh, the theme AI and whoa xdr everything.
And I didn't get it. To me, I, it was hard for me to discern the themes because of the noise, right? You, you know, there was just so many folks barking.
It was just like, everything kind of, you know, blended together after a, a little while. Mm-hmm. So in, in, you know, taking a step back, clearly it was, you know, everybody about improving detection, you know, and using AI in that, uh, kind of, of aspect.
Uh, I'll tell my little AI story in, in a little while. But, um, again, I just, I didn't, nothing kind of jumped out at me as like, oh, this is, this is the overwhelming theme and, and, and everything is, you know, kind of gonna be focused on that for the next year. I mean, you, you, you did mostly interviews as opposed to being on the, on the show floor.
So, you know, what were some of the themes, uh, and, and concepts that were happening with the interviews? Yeah, I was definitely doing almost back to back interviews and, um, you know, I think XDR is still hot topic, you know, zero Trust is very much talked about. Sure.
Uh, but for me, the two new ones were, you know, we, we joke about timing every interview to see how long it takes for AI to come up. Usually about two minutes, I think is the, the standard plus or minus a minute standard deviation. Um, so that was definitely part of it, but there was a lot more real conversation about, so how are we using it?
Um, which I thought was, was, uh, interesting and relevant for, for me, the, there was a big standout. And, and that is a, you know, I've gone to R s A for, I don't know, almost a decade now, thinking, okay, we gotta start talking about software and then we gotta start talking about software development and architecture and how do we kinda get these worlds to merge. And then this year was the first year where I would, I had back to back to back to back to back interviews talking about supply chain security, a p i security, application security.
And these were, were people who were in that space, but selling two security companies. Yeah. Not developer tools.
And, you know, they're at R S A and they're having those conversations. So there, there's, you know, the traditional security vendors of course, that we all know and love to the Cisco, the love, the Ciscos and, and Twilio's and software, I mean, cloud architecture and cloud security and all that kind of thing. That, that was a big difference.
We, I felt like we kind of hit the, okay, now we're crossing into the starting to merge. And what, that was one of my questions for people. It's like, why are we talking about this?
I, I've hoped we would, but why is this of conversation? And I think it's just sort of the inevitable where things are with, you know, the attack surface today. It's time.
And, and I think it's become more clear how security needs to start expanding their purview beyond just the infrastructure, right? Mm-hmm. And when we did DevOps ops on ramp, you know, last week, which was a great show, um, you know, we had a lot of engagement from the folks that were there.
That was, that was really fantastic. Um, you know, we took two sides of it, right? You know, the dev sec piece of it.
Uh, and, and I did a, a panel with John Willis talk about the SEC ops piece of it, uh, on that front. So you, you know, clearly security folks are being pulled in that direction, right? But, you know, again, the easiest thing is put a box in there or now a virtual box, uh, right.
You know, with some blinky lights and, and do some detection and try to block some, you know, stuff of the perimeter before it, you know, kind of gets into the applications. And, and I think we're starting to generally understand that that's not good enough that we need to, you know, start thinking about how Im fits into this. So there's a lot of, you know, kind of, um, at least announcements and, and and activity around Kim, right?
And that's c i e m, so that, that's, uh, actually consumer, uh, identity and, and entitlement management on that front. And I don't know how you get Kim from that, but whatever. Um, a little too close to Sam, I guess.
So I, I, I think, yeah. Uh, you know, so, so there are a whole bunch of different things, but you know, obviously a number of different XDR and, and zero trust, uh, type ideas. But I, I do wanna dig into the, into the AI thing a little bit, right?
Ok. Do that's everybody else's, let's do it. Well, But, but, you know, and, and, you know, and it doesn't just coincide with the fact that we, we may be launching a, uh, a property in, in ai, you know, sometimes, You know, one, one of the, the, the experiences that, you know, on one hand was just incredibly exciting.
And then the other hand just scared the crap outta me was I was, you know, kind of talking to an, an assessment vendor. You know, they started in CS P M, and now they're in a tech service management. Just, you know, one of those, they were five or six of 'em, you know, you picked your favorite one.
Um, you know, they do a bunch of, of AI to, you know, kind of determine where potential misconfigurations are, uh, you know, in, you know, kind of both the cloud and, and a Kubernetes and application stack, uh, space. Um, so you get a, a set of alerts and it's like, Hey, you know, you, so you, you click into it, you know, you figure out, hey, you know, what's this issue? And then you see six buttons at the bottom, right?
That, you know, kind of say AWS or Azure or GCP or you know, Kubernetes or, you know, whatever, OpenShift or, you know, just a whole mess of other buttons, command line. Mm-hmm. Um, other buttons that, that are there.
And then it said, powered by, you know, G P T four, I think maybe G P T three, right? And, and they're like, oh, look, this is really cool. They click the button and code is generated right code to fix that specific issue that had been identified by the API or by the AI as, as potentially misconfigured.
And on one hand I'm like, holy crap, is that like real code? And on the other hand, I'm like, holy crap, somebody's actually gonna believe that's real code. That's right.
And they're In some sense, right? Yeah. And they're gonna put it into, you know, kind of their production environment and what, right.
So that was when I, I kind of got a, a chill down my spine. Like y y you know, uh, does that seem just so shiny and really cool on a trade show floor? Yeah.
Would I be comfortable with that in a production environment Now, N F W, right? You know, hey, yeah, six months from now we'll have a different discussion because things are improving just incredibly rapidly. Sure.
12 months, 18 months from now, would I get comfortable with that? Maybe, right? But there's a whole bunch of vetting that has to be involved in that.
We, we have to do this stuff, you know, kind of in a, in a staging type of environment, uh, in order to, you know, kind of make sure that the code isn't gonna cause some type of, you know, regression issue or, or create, you know, other problems. A along those lines. So for all of you that are scared and concerned that the AI is coming for your, you know, tech troubleshooting or tech operations job, uh, I, I don't think that's happening, you know, anytime soon.
But I do think that over the next, you know, 18 months, things are gonna get a lot easier, especially relative to multi-cloud, because a lot of the constructs are the same unless you're in Azure, that's a little bit of a different animal. Um, but the constructs are same, but the syntax and vernacular is different. And I think that something like a A G P T or you know, some of this automated code, uh, generation, you know, can help bridge those gaps without having to be an absolute expert, you know, on a w s syntax versus G C P, you know, syntax.
Um, so, you know, again, I, I do think this time next year we're gonna be seeing a lot, lot, lot more cool stuff, you know, in terms of application of, of AI and security. But my message is as of today, be really careful with that stuff because, uh, again, we are just not, I'm not in a place right where I can feel comfortable saying, yeah, that's gonna be production rate code. It still falls into the, if it's on the internet, it must be true.
Yeah. Right Category. Right.
Um, and I don't mean that as a skeptic. It's, you know, I think, you know, who knows how it's gonna happen, but I kind of think we're gonna go through the same kind of maturations that AI has gone over so many years where it finds a domain, right? Because cuz chat G p t four or whatever version is, is a mass market tool.
And that's why it's gotten all of our attention cuz all the things that it can do, everybody Can use it. Yep. Everybody can use it, use it, been using it for code can now everybody can use it for code without downloading an I D E.
But, you know, what does it generate and is it something that you can ge if you've been writing software, you know, the easy part is writing the code. The hard part is maintaining it, hard part is upgrading it and fixing it and doing, you know, up upgrades and fixes and integration and all the stuff that takes that. Now I'm spending that technical debt.
Right. So is is chappy G P T ready to do that too? Probably not yet.
Maybe someday. It is. Maybe someday.
What would be great is that actually if we turn that G p t generative code into solving those so shoes, right? Versus writing new code, right. That actually, I think about the technical debt on the security or the, the software stack that would be, you know, game changing.
That's Right. Maybe even more so than writing new code, who knows? But yeah, I, I I think so.
And, and we're starting to see that, right? You know, kind of obviously Microsoft's security co-pilot that they are, you know, rolling out Google has a similar type of thing for their cloud, uh, environment to, to really assist in, you know, kind of detecting, uh mm-hmm. What many of those issues are based upon your specific environment, right?
Your telemetry. So it's not the ma I mean obviously they're training it on, on mass market and massive amounts of data, but you know, kind of the, it it applies specifically to yours because they are somewhat sensitive to, to data governance and data isolation shockingly enough. Um mm-hmm.
Which allows us to, to pump our data ops, um, conference, which we we'll be doing in a couple months. I don't remember which, you know, one it slots in cause there, so I'll like it up Here real quick. It's coming not too far down the road.
Yeah. But we are, we are going to, to do a data op show because that is something that's, uh, uh, obviously critical on that front. Um, so, you know, lots of really cool stuff going on.
Um, y you know, interesting data point, you know, our pals, uh, over at Cyber reason, uh, had to do another round of, of funding and, uh, they took an 80 to 90% haircut on their valuation. Um, so, you know, again, just shows the rich get richer. CrowdStrike and Sentinel are, you know, kind of well ahead of everybody, uh, in that space and, and those that, uh, spend a bunch of money, um, you know, they really have to, uh, you know, focus on that approach.
So. Mm-hmm. Um, that's about all the time we have today, Mitch, any other parting thoughts for, you know, kind of this week's review on our site?
Yeah, one of the things I wanted to point out is check out, there's a couple of articles, um, about, about the c e O of Tay b boutique of OpenAI, um, in Fortune Magazine. And one of them was talking about sort of how even though he ran the Y Combinator, um, breaking all the rules of what we, what we tell startups to do around, uh, viral and free downloads and all the things you have to do to be successful. They kinda, and you know, you don't, don't sell a technology, sell a solution to a business problem.
They kind of did the opposite. He broke a lot of rules. So there's interesting lessons where even the rules from the rule makers can be broken.
So check that out. I think it's worthwhile to look at, to help all of us think about the patterns we fall into and the belief systems we've become accustomed to, which can be disrupted too sometimes by ourselves. You bet.
All right. Well, that's great. Really appreciate it, Mitch.
Fortunately, you know, again, we all have too much stuff to do, uh, this morning, so we've gotta keep this one pretty short. Uh, but we'll be back next week with a more extended discussion on whatever it is we started to talk about. So, Hello everyone.
Here's some of our upcoming tech strong learning events. First up on May 4th. Be sure to join us for our DevOps on-Ramp virtual event.
Whether you are diving into DevOps for the first time or trying to do it right this time, DevOps on-Ramp will provide you with all the information you need for a successful DevOps journey. Then on June 1st, join us at the virtual DevOps Connect DevSecOps RSA Conference 2023 event as we discuss the emergence of security engineers and DevOps, and explore the role of developer security champions on July 11th. At our Cloud Native Now virtual event, we will explore the various facets of Cloud native that are essential for our successful digital transformation and enterprise modernization.
We hope to see you at all these events. com. Thank you.
This is techstrong tv. Hey guys, thanks for the throw. We're here with still Veni, who's C e O for onshore security, and we're talking about the change in the tenor of the conversation as it relates to offensive security.
Still welcome to the show. Well, thank you for having me. Not too long ago, we were having this debate for years now that I think about it, but it was always kind of one of these things where the defense department was kind of saying, maybe we should be more aggressive.
And maybe the folks over in the uh, uh, state Department were saying, well, if you're more aggressive, you're gonna start a war. And that's probably a bad thing. It seems like the tenor of that conversation and tone of it at least has changed with the National Cybersecurity strategy and other signals from DC where maybe we are gonna get more aggressive.
What's going on? Well, there's been events in the world, uh, uh, you know, uh, it's China, North Korea, Russia, I mean, those are kind of the, you know, the, the big ones each are different. Uh, China's stolen IP and, you know, even though there was a little bit of a agreement in place, a verbal agreement to, to back off on that, they k ramped it right back up.
So, uh, that's not necessarily cyber warfare, but it's definitely not the accepted spying, so to speak, tolerated spying. Russia's a little different. Russia, uh, has been able to have some kind of plausible deniability with the, you know, the criminals that do do the, uh, uh, infrastructure attacks.
But I, I, I think we're kind of getting past that and seeing it a cyber warfare, if you look at the Eastern European countries, they've been used to it for a long time. Uh, the Baltic countries especially. Um, you know, uh, I heard the, uh, an uh, uh, higher up in the cybersecurity Estonia go into some detail about the kind of attacks they've been seeing from Russia for years.
So yeah. So the climate's changed, basically. I know this is the digital age, but is this fundamentally any different than going after the Barbery Pirates?
Back in the day when we had ships and we sent, you know, the Navy to go fight these guys and come back and, you know, are we gonna do the same again? Uh, it's identical. I, I mean, right.
I mean, it was basically the, the, the, the, you know, the what the British government were happy to see pirates nailing Spanish ships, and then he eventually, uh, you know, they spread their wings, uh, further, you know, and so that was, that also, you know, the case, uh, I think that was us' first foreign involvement was going into the, into the Mediterranean to a, a attack the, the Barbery Pirate. So, um, yeah, I, I, I really think there's this history repeating itself To that end. Um, I get that countries can go and do this, but should individual corporations that have access to resources be engaged in this behavior or they should, they always defer to the national government.
Well, history tells us that, you know, both have happened and with lots of successes and lots of failures, um, we can't predict the future. Um, but, uh, but that said, it's dangerous. Um, the, the federal government and the state governments too.
But, but, and, and not just our federal government, I really think generally have not done the hack back. I mean, it's pretty much been, uh, you know, peace time, uh, so to speak, you know, in, uh, in, uh, cyber realm and, uh, um, and so, so companies that have chosen to do some of these things very, very quietly, um, they've done so, uh, you know, with, you know, not exactly as their first line. I mean, this is something they would do, uh, reluctantly.
Um, the federal government even saying that they would do something more aggressive, they'd be, you know, add offense to their defense alone, really reduces the, the, the, the needs. Poor corporations get involved and, and they'd rather not. Uh, but, um, corporations are very powerful.
We, we can name names, and as a result, they are actually, you know, going to be participants. Excellent examples. What's going on in Ukraine?
I mean, uh, Microsoft in particular is extremely involved, uh, with, with Ukraine, and don't think that's done without, uh, uh, very close involvement of the United States government. We've also seen the hacker groups of, all right. So I think it's kil net as its name that is now advertising and that it has services for sales.
So maybe they've become the digital equivalent of the Wagner Group and the Ukrainian War. But basically they're saying we're for hire anywhere in just about any place. So is this all gonna spiral out of control soon?
Uh, yes. And so the, uh, the cyber tech accord, which, um, which we're signatories of, uh, from the get-go now, going in a, I think we're at five year point now. Yeah.
We just did our, our five year, um, meeting at our rsa. Um, uh, Microsoft's probably the, the, you know, the number one, the main company behind it. And, and, uh, some of the leader positions are with entre, with, uh, excuse me, with Microsoft people.
Um, and, um, uh, our recent announcement was a, um, a, uh, you know, signed, agreed upon initiative and a request to the United Nations who we have the ear of, uh, so all the governments of the world to reject cyber mercenaries, uh, because we see it as a growing threat, uh, because we see cyber mercenaries not as a way to keep our own forces from being involved, but rather to escalate. And so, so we reject it on the grounds of, uh, of trying to keep the peace. Aren't we also involved in something that feels like a cybersecurity AI arms race all of a sudden?
Because, um, we seem to be making a lot of advances, but the bad guys are discovering things like chat G B T as well. So are we entering some sort of new phase without really realizing it? Yeah.
Uh, it, it's, uh, it, it's early, but it's inevitable. Um, and I don't know, uh, arms, this would not be a bad, you know, term to use to describe it. Um, but I, I think it's gonna be a lot more complicated than what we can really envision at this point.
Uh, you know, a AI is a tool rather than like a replacement for humans. It empowers humans more than replaces them. I think there's a lot of this thinking about that.
It really acts like a human. Uh, it looks a lot more intelligent than it is, you know? It, it really, it really doesn't quite have enough context to, to, to do things on its own.
That said, it's gonna be very powerful with things like, let's say, iterating, uh, software so that it becomes less detectable. And an AI can probably do a million tests in a second to find a way to modify, uh, a certain, uh, you know, uh, point in the kill chain to make it less detectable at that point. So, so, so find its flaws.
So, so that I, you're probably, that's probably actually the lowest hanging fruit as far as where AI is gonna enter into cyber crime. You're gonna see malware become more effective, more quickly, vulnerabilities being weaponized more quickly, um, zero days rather being weaponized more quickly. That that's really the first thing you're gonna see.
Uh, and then, and then on the defense side, AI's gonna also be better at finding anomalies, uh, identifying activity as suspect, uh, en enrich, uh, um, adding contacts and enrichments to data that you see on the detection side, because that's a, there's a lot of work to do there. And AI could do that faster. Think anything that a machine can just do a lot faster, that's the number those are, that's where the low hanging fruit is.
The challenge has always been, at least in my mind, is it's never been clear. If we know for certain where an attack was launched from, the bad guys are good at masking that activity and AI may make that even more challenging. So if we're gonna be more offensive, how can we be certain?
Yeah, I mean, it's, nobody's gotten it down. Um, you know, to this day there's very, very famous, well studied investigative attacks with lots of forensics data without a confident attribution. So, so, um, yeah.
Uh, I think we're gonna make mistakes. Um, I think the, you know, the hack back attempts are going to probably, uh, at least if his history tells us how it's been with the US government, at least, it's gonna be a little more careful than, than our adversaries have been. They don't mind seem to mind as much if they, um, have some casualties, you know, let's say out of it, we're gonna be a little more careful.
Uh, we, we, uh, we would be hurt more by the optics of that, um, uh, for one. Um, but, uh, you're most likely then gonna see tactics that are, um, that are closer to what we've done in the past, information gathering, triangulating, uh, uh, maybe various kinds of testing, probably waiting for, uh, on the ground type of, uh, validation for high attribution before we do something that is very impactful. Uh, we're gonna be more careful.
Is that detrimental to us? Uh, to some extent, sure. But, uh, but don't, don't, um, don't think that we're, we're going in ill-equipped.
I mean, th this is, there, there is no more powerful hacker, uh, in the world than, than, uh, the, the United States federal government entities. I mean, it's just, we are the best by far. And, and, uh, that doesn't mean that we rest on our laurels.
It, it means that, that we have the luxury, let's say, to do it carefully, do it right, and, uh, and minimize casualties. Are we getting better at collaborating? In theory, my enemy's enemy is my friend, and yet cybersecurity, the history of it has been not really great when it comes to information sharing.
So are we getting better at that A little bit? Um, there's, you know, there's a lot of attempts that focus on the, um, commercial side of things. Um, you know, we're members of a number of information sharing organizations.
There's some that are industry focused. Uh, there are some that happen in certain cyber security communities. Uh, you know, tech Accord is, uh, the sub tech accord.
I was, you know, uh, uh, referencing earlier, uh, you know, as part of that, um, we have certain agreements we put in place about, about sharing data and, uh, and talking about breaches and vulnerabilities. Uh, there's also been some, uh, uh, uh, legislation coming down that would help with, um, you know, white hat hackers and with, uh, bug bounty, um, uh, you know, uh, what would you wanna call 'em? Freelancers, whatnot, uh, whistleblowers.
I mean, those are the kinds of things that enable it full on information sharing. Um, it's tough, uh, but I think we're, even those things I'm talking about really would move the needle a good bit. Um, I would like full-on information sharing the FBI is not a bad container for that.
Um, uh, but, uh, but yeah, I don't see anything really full fledged coming out in the near future. Are we also getting better at using our, uh, physical resources to track down criminals in, in much the same way we went after mobs with their bank accounts? Or are we doing the same now?
Well, you've probably seen some of the news I've seen. I mean, I, I mean, I, I, I, I'm sure you would agree, you're looking at, let's say, look at a last, you know, two years, uh, you know, way more big Interpol busts, networks being taken down. Um, you know, people being picked up when, after a couple years, they didn't know that they, you know, they were not careful about flying to a certain country or another.
Yet we've, we've done a much better job with the, the, the physical side of it and, and connecting those. And interestingly, uh, um, there have been times where, where Russia and China have been cooperative in those kinds of efforts. Not, not a whole lot, but, uh, um, they have problems with criminals too.
Don't think we're alone on that. We're not the only target far from it. Uh, Interpol's probably been the, you know, the, the most active there.
Um, but there is, you know, there's a politics to that, of course. Um, and we're weak on some of the treaties with country that probably would matter a little more. Um, but, you know, it's, um, uh, I, I do think that I, I'm, I'm kind of optimistic there.
I do think that enough of the world, even our adversaries, um, you know, are not a hundred percent adversaries that they see the threats that we see. And, and even though they might support some things from a nation state perspective, uh, they, to them, the criminals are only useful for a moment. So, so I think you're gonna see more cooperation on the physical front as a result.
So, Stella, given all that, what's your best advice to folks as we go forward? Well, look, we're talking about people with significant assets and, and heavily impacted by any kind of disruption. Uh, you know, and, and don't assume that you're, you are gonna be able to cover everything and who you circumstances that come up dotted lines to, uh, to, uh, D o D and to, uh, to entities that are much more targets.
So, honest, I'll, I'll, I'll throw in our, our mantra that we give, you know that the detection is your superpower. You know, assume your hack, assume your perimeter is inadequate. Assume your your devices aren't trusted and, you know, put in detection, in additional protection.
Take every protection component you have and integrate that with your detection practice. That's the thing that I, that we not reached the maturity level needed yet, or, All right, folks, you heard it here. I think it's still true.
The best defense is a good offense. And here we are still doing the same thing still. Thanks for being on the show.
You're welcome Back to you guys in the studio. This is Techstrong tv. Hey guys, thanks for the throw.
We're here with Jason Davis, who is vice president of product management for testing apps for Sauce Labs, and we're talking about DevOps and testing. And somehow or other, these always feels like two ships passing in the proverbial night. Jason, welcome to show.
Thanks, Mike. We've been at this DevOps thing now for the better part of a decade or more, depending on how you wanna start counting. And the question always comes back to, it seems like we're building software faster than ever, which is great, but the quality something, I don't know if we're making as much progress on that side of the equation.
So from your perspective, where are we in terms of embedding testing in the DevOps workflows, and why does it feel like maybe we're not making as much progress as we should? Yeah, no, that's great. Great intro question.
And something I've been looking at for a number of years, not only, um, in this particular role, but generally, like looking at GitHub study of the state of DevOps and how teams who are really, uh, skilled at adopting those practices still end up spending about the same amount of time doing testing as, as teams that aren't, um, as adept at, uh, uh, adopting, you know, quality DevOps practices. So it is something that I think we've, we've consistently seen over the years, um, in, in addition to kind of just working with customers, um, recently, sauce Labs worked with, uh, uh, tech targets enterprise strategy group to survey, uh, the market. And we talked to 300, uh, practitioners.
So app devs, QA engineers, uh, DevOps, uh, practitioners, SRE engineers, mostly at enterprise organizations. Uh, th those with over a thousand, um, employees. And the goal of that was to really understand, you know, what's the current state of testing approaches, uh, what are the challenges that they see there, and where are they looking to invest in the coming years?
So to kind of summarize some of the main, uh, findings there, and then we could dig into the details. Um, one thing that we've seen is even, even though DevOps has now been in practice for a number of years, just over the last three years, we're seeing more than 50% of our respondents are managing twice as many apps as they were before. So in general, there's just more apps to be managed to be tested.
Um, second key finding, and you alluded to it, Mike, speed is prioritized over quality. Um, and that's not necessarily a bad thing. Uh, we were seeing that dev teams were 33% more likely to prioritize speed over quality.
And what that means is we need better tools to support that speedy delivery, whether that's, uh, being able to test better pre-release or getting data after we've been released so that we can identify, uh, and teams can identify if there's a problem and how to fix it. So the second thing that, that we've seen is, uh, like I said, speed is prioritized over quality and, and teams need better tools to, uh, to help, um, uh, to support this. And then the third thing is, um, as I alluded to actually in the beginning, the amount of time, um, spent doing code and new functionality hasn't really shifted.
Um, the balance of time spent doing code and new functionality hasn't really shifted from, um, uh, from where it's been over the last few years, where 60% of the time is really spent on new coding, and 40% is still spent on testing and remediating and fixing. Um, so that's the state that we've seen, um, the challenges, like we said, like we said, uh, number of apps being managed, the fact that speed is being prioritized and, and tool and, and really, if we get down to it, what hasn't changed is that people are still relying on in-house DIY or do-it-yourself testing systems or shift shifting and shipping devices to developers so that they can run their tests locally. And that just really doesn't scale anymore.
To that end, we hear a lot about shifting left, and I guess I scratch my head sometimes cause most of the developers I know wanna write code and asking them to test their own code is kinda like, you know, the fox and the henhouse kind of conversation. So, um, what is the state of the art for shifting left? What should be actually shifted left versus what needs to be done elsewhere in the process?
And I guess, what does a testing workflow need to look like these days? Yeah, great. So, um, I think in terms of, we're seeing both shifting left and shifting, right?
Um, when we talk about shift left, it's not necessarily about like unit tests and, and, and the longer integration tests, but it's more about identifying functional tests, uh, that should be performed as early as possible. This doesn't necessarily mean that you have to have like, test driven design, um, but the idea is that while the, the t the the, the capabilities are being built, making sure that there's a set of tests that are defined, even if they're manual tests, to, to capture the expected, um, uh, function, the use of the functionality, and address any sort of, um, uh, uh, complexities that might arise. You know, uh, in general with the usage beyond that, when we talk about shifting left, understanding the breadth of devices or browsers that we need to support.
And if there are, um, kind of in-depth, um, uh, complex features, maybe on mobile devices, things like biometrics, um, or, uh, um, uh, or, uh, understanding the breadth of different types of Android devices and versions that are out there, if that's understood early on, defining tests for that early will allow you to, uh, to identify those bugs earlier, fix them earlier, saving time. So when we talk about shifting left, it's about functionality testing as well as the, the unit testing that folks do, and then trying to get breadth of coverage, um, uh, earlier on as well, so that you're not stuck kind of remediating that code later on. So the type of testing matters when and where it's done during the DevOps workflow, and you kind of need to think that through.
Um, are you seeing more people think about security as part of the testing process? And is security really just a function of qa? We're seeing a, a bit on, uh, a bit security overall.
Everything from, um, teams being under, uh, certain procedural, uh, guidelines for things like SOC two, if they need to have data, um, policies in place there, um, to, you know, just penetration testing and, um, and making sure that if crashes are encountered in your app, that it's not a backdoor into, um, accessing the code or, or taking over, um, uh, the application or the u the, uh, the app space. Um, so we are seeing organizations rely on, uh, doing security testing as they're doing their end-to-end testing, their integration testing, embedding it, uh, within that standard testing where they can. I think that's the change that we're seeing.
Uh, historically, we had seen security testing as its own phase kind of later on in the development life cycle. And more and more we're seeing elements of it introduced earlier. Um, I think a lot of that has to do with security teams, working with development teams and, uh, helping them understand what requirements there are upfront and baking that into the development process.
You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. Um, what is the state of the art for AI and testing these days? I mean, can janitor of AI be applied or is it different kinds of ai?
What should people expect? Yeah, um, that's a, that's great. We've, um, actually at Sauce Labs, uh, we've had employed a team of r and d, uh, scientists, PhD scientists who actually have focused their study on machine learning and ai.
And yeah, you're right. Over the last few months, just the, uh, the public introduction of chat, G P T and the um, uh, the emergence of so many different, uh, large language models. There's, there's various different applications that we're seeing.
Um, the way that we're looking at it, we see three core phases of testing, um, and we think that A I M L and large language models can, can help improve, um, things in indeed, in, in those different areas. So first we see test authoring. Um, in fact, the SAUCE Labs has capabilities.
We've been working on, uh, N L P technologies for a number of years to support people who are doing low-code testing rather than having to, to, to know how to develop automated tests and write, um, write testing code to be able to define your test in a natural language way, and then have the system generate the code. We see that one, that one area, uh, where the LLMs are really advancing, um, almost exponentially from what we were doing previously, um, in their ability to, uh, generate code in different frameworks. So having somebody define their, their, uh, their test steps in natural language and say, I'd like this, um, written as Selenium code or Cypress code, or Test Cafe code, these different frameworks that could be used.
Um, the advances we've seen there so far, like that, uh, it appears that the, the, the newer systems, the G P T four based systems, uh, are even getting like 80% of the code there. So test authoring and doing some N L P work is one area we see, um, uh, uh, potential improvements also in test authoring. Um, you know, especially with new mobile apps, uh, and new apps, when do we start testing?
And another area that we see is the ability to explore an app i, in an autonomous way, um, clicking on different, uh, elements in the screen, um, and identifying then if there are crashes or errors that occur. Um, and then capturing things like visual snapshots to identify if there are diffs between different builds. So this notion of, rather than even having to write tests, but have the system start to explore and get full coverage and iden help you identify where their errors, uh, in your app is another area where we see support.
So that's when we look at test authoring two key things, and there there's a bunch of other, um, uh, interesting projects in those areas, but that's, um, uh, one, uh, focus. Um, a second focus area is on the results, right? Once I author all these tests and execute them, uh, I get pass and fail.
When I get a failure, there's always time spent digging in what actually failed? Um, was it a real test failure or did my test infrastructure fail? Can I not access, you know, uh, a system that should have been up?
So maybe we need to do a retry, um, or I'll get through a, a full, uh, set of tests and they all, you know, are checked off as passed because they pass, but the system generates a few errors or crashes along the way. Um, so, so when we look at, uh, uh, the test results, all of this data is consistently being generated and it's still requires the end user to sift through it. These large language models are doing a really good job at summarization of that data.
So if I have a failure, um, or if I see a pattern of failures, these LLMs are, are really helping to identify, um, what changed or where, what line of code is it, where the error occurred. Um, so that's the second key area where we see, uh, ai, ml and large language models starting to, um, uh, improve the environment. It's around results analysis, log summarization, and, and then, uh, taking that feeding into the third area, which is test optimization and execution.
How do I know what tests we should run, um, based on potentially like what code changes just went into place, how my tests normally proceed. If I can, um, understand those test results, I could feed them back into the engine that's doing the execution and the optimization and make some decisions for you on the order of tests. Um, for example, if it's a new piece of functionality, the new tests that were written should probably be run first.
Um, and you can further, you know, take that a little bit further, but making suggestions and, and optimizing execution is kind of that third area. So we're looking at it in those three different phases of, uh, uh, of, of tests and how it can improve authoring, um, results. And then, uh, execution and optimization, an orchestration.
So every year, as long as I can remember, somebody stood up and said, this will be the year. We won't need dedicated testing teams, and every year we still need dedicated testing teams. So what is the future of those dedicated testing teams and how will their roles evolve?
Yeah, uh, we're always gonna need, I, I don't know if I wanna say dedicated testing teams, but there's testing teams. Um, and in fact we have seen, I think, a big shift in the, the level of responsibility for tests falling onto the developers in addition to just qa. So absolutely, I think we are always gonna need teams and responsible individuals.
Um, but I do see a, a bit of a, um, a of a, a shift in where the responsibilities lie. Uh, that said, uh, one of the things that, that, again, anecdotally I had seen this, and then in the, um, uh, in the, uh, uh, the, the survey, we saw this as well. Um, manual testing is still pervasive.
Uh, almost, um, two thirds of testing teams have at least half of their workflows in manual tests. Um, so that's huge area for improvement. Um, part of the reason for that is automating test is actually a relatively skilled, um, job, uh, writing selenium tests and so on.
And as I just mentioned, like there's some new technologies and test authoring that might start to, um, improve that, but we always need somebody who's gonna define what is it that we're testing, what is the functionality? Um, and that requires domain knowledge, uh, knowledge of the application of the, the, the, the, the, the goals of the app and how users actually start to use it as well. So one of the main things we see for the future is a push towards more automation, but not necessarily needing automation engineers, rather taking the folks who are good manual testers today, and as they're doing their exploratory manual testing, use that as the basis for low-code testing for rerunning those tests and future versions, et cetera.
Um, so that that's, you know, when we look at the future de definitely teams that are responsible for tests, um, leveraging some of this new technology so they can go further, um, towards automation and that, and that move towards automation is huge because we see that teams that have high levels of automation, um, C Q A and testing in general as a competitive differentiator for them, and that, um, they, they feel that not only do they feel that their, their, their applications are more tested, but it, it shows up in the results of, of, um, of changes in production where those teams that do have high levels of automation see lower amounts of production code changes causing functional issues that require mediation. So if I step back for a minute, um, overall, the, the survey tells us that about a quarter of production code changes, um, require some level of remediation because there's a problem that's introduced with that production, uh, code change. Um, when we look at just teams that have a high level of automation testing, we see that number, uh, decrease, where 25% fewer, um, production code changes require, um, remediation steps.
So overall, we see a continual push towards automation, and we see that the numbers are telling us that that's good because teams have more confidence in their releases, they view it as a competitive differentiator, and in fact, when they roll out changes to production, they are seeing less errors in people who rely more predominantly on manual testing. So in our minds, we have always made this kinda bargain between quality versus speed. Do you think that we can get to a point where we just don't have to make that trade off anymore and we can actually have both?
Yeah, the, the last few years there's been more, um, I'd say, uh, more level of comfort of doing what's called like production and testing where we'll release very frequently and you could release new functionality to a canary test, to a small pest set of users and make sure that it meets the level of quality that you expect, that the, that it meets the level of usability that's expected before rolling it out further. So I do see more of a trend towards that. Um, sauce Labs as well has seen that and is focused also on bringing error and crash reporting into the fold so that as people release not only their web-based apps but their mobile apps, that production error data gets fed back into the system.
And then teams have tools to help them quickly decide if that error is important enough to need a fix. And then when they make that decision that they have enough information to know what to fix. Um, so I do see more of a trend towards releasing more frequently.
Mobile apps do make that more difficult because mobile apps require a, uh, a cycle through the app store before they get approved. So I'm also, another trend we are seeing is more people doing hybrid apps where parts of their apps could be delivered over the web and they can make those changes more quickly. Um, but overall, I, I do see that trend of testing and production and pushing things out, um, to, to be more frequent, not only in smaller startups, but it's encroaching in the enterprise space as well as there's that expectation from their users that they get the latest and greatest as quickly as possible.
All right, folks. I think that the end user wants developers to spend more time testing their code versus testing them and their tolerance for updates in the future to fix things. So let's get it right the first time, as they say.
Jason, thanks for being on the show. Thank you, Mike. Appreciate the time.
All right, back to you guys in the studio. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network at work. Hi again, everyone. I hope you all enjoyed today's episode of Techstrong tv.
We had some amazing interviews with industry experts to give you the latest in the tech world. We'll be back again tomorrow, so we hope to see you then. In the meantime though, if you want more tech strong TV content, be sure to check out our podcast or download our mobile app.
Thank you so much for watching, and I hope you have a wonderful rest of your day. As always, stay strong. Text strong.