Techstrong TV – May 27, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. Have you heard about the new sequel to Total Recall? It's called Can't Recall.
You're watching Text on Gang. Hi everyone, it's Alan Shimel for Techstrong. Welcome back from your holiday weekend.
It's Tuesday. It's not Monday, it's Tuesday, but get ready for work. Me, I'm personally excited.
I'm outta here tomorrow, heading out to Italy for about 10 days with family. Looking forward to it. Um, you know, I I it's, it's interesting as an American traveling the world these days, so I'll report when I get back.
But let, let's jump into what we have going on here today. We've got, it's a bit of a security heavy day, and it's good 'cause we have some really security heavy people. I don't mean they're heavy, I mean, they're big into security.
Let me introduce you to our, our group for today. First of all, from the great white North. We'll go north to south, perhaps from the great white North.
He's a resident security expert. Frank, Chris Blask. Hey, Chris.
How are you? I am good. And, uh, I just wanna put a, a term in your ear to think about as we go forward.
Narrative resilience. Narrative resilience. Yeah.
We, we will, over the coming weeks and months, I think it'll be a fascinating topic. Okay. You heard it here first from Chris Blask.
Again, moving. Well, I'm not sure who's further north here. I'm gonna go with Mike Vizard in, in upstate New York.
Well, it's not really upstate, but It is, it is a grand total of 20 minutes north of New York City. So it just depends on where your definition of upstate is. But on Long Island, anything north of the Bronx is upstate For, for us locals.
It's generally anything north of New Paltz. But what do we know? What do you know?
All right, Mike, welcome. Welcome home. Next we'll go to Jack Poller.
Jack, I'm forgetting where exactly you're based. Well, I am in the north of the south. I am in Chapel Hill, North Carolina.
That's, remember right now I remember. Yes, right. We got Three square miles of northern, very deep in Yankee, uh, you know, in, in southern territory here.
Yep. Around C they called it. So down here in Florida, we call that the halfback.
Right. It's for people who came all the way down here and then only moved halfway back. And it, it's halfback land.
Well, continuing south though, to the mountains of New Mexico. She's the CEO of the Deploy hub, an open source extraordinaire expert, our friend Tracy Ragan. Hey, Tracy, how are you?
I'm doing great, and I hope you have a fabulous trip in Italy. It sounds like a wonderful thing to do right now, and it's a well deserved vacation, I'm sure. Yes, it is.
Yes. I'm taking, uh, well, it it's 10 of us going. It's gonna be fun.
What makes you think you're gonna be let back in you? That was pretty optimistic statement. You know, I've told Bonnie the do not be surprised if at some point on one of our trips I'm detained because they, they could look up my social media or they'll look at something and say, I don't, I'm not a huge fan of this administration, So we'll just have to call it Text on Gang International after that.
Yeah, yeah. We got your back. We got your back.
Alan, let me just for, for posterity. Look at my hands right now. I have no tattoos on my fingers.
Okay. Oh, they could fix that in case they case they have, right? Oh, they'll, but in case they try to pull that, I want, I want a record.
Um, let's, let's, let's move along here and, and jump into today's, into today's, um, topics. So Mike, you want to take this one? It looks like Signal is telling Microsoft No.
Can do. Yeah. Basically, uh, the controversy surrounding this recall feature that Microsoft is putting into Windows 11 continues.
Uh, now Signal is saying that they're gonna block that feature for recall, which is designed to capture, uh, automatic screenshots and everything on your screen and will make that available somehow or other on that platform, but maybe in the cloud. Who knows where all that data winds up. And signal, of course, is all about, you know, privacy and not sharing data.
So, Chris, are we gonna see more of this? Will other folks follow suit, do you think? And is data privacy like actually becoming a real thing now?
Well, as you know, I try to find a positive, you know, path out of these sort of things. Either there's teaching lessons and so forth, and I use terms too much like dumb ass. I don't actually, can I use dumb ass on this show?
I mean, I, no, this is, it's an indication of the immaturity of corporate governance in certain ways, right? Regarding privacy and so forth. I mean, this is tone deaf is the, right, I mean, I mean, you, you said it literally everyone on earth now.
I mean, you know, single has been this sort of geeky app, you know, for years and years and years. But suddenly everyone, literally, everyone knows. So someone at Microsoft, you know, made a decision that indicates that the decision making structure of Microsoft on this issue, we is not mature.
Yeah. So maybe it's a forcing function to get better process in place, but, uh, it has us talking about it. So maybe that's the upside, Jack.
Is this just another example of the well-intentioned gone wrong, you know, that road paved to hell? Yeah, I think so, sort of. But it's also an indication where Microsoft forgot all about security, right?
The very first, you know, yeah, shocker. They forgot about security. Um, the, the, the first release of recall when it was first announced, had no concept of security whatsoever.
They went back and rethought it and said, okay, well we'll tie it to your, um, windows, hello login. And so you can't access that. But that ignores a whole bunch of other concerns.
Like, do you want an AI engine to be indexing your private data to begin with? You know? And so I look at it and I say, you know, many years ago I called Java the virus description language, and I think we can call recall is remember everything secure?
Nothing. It's just, it's really just a huge privacy issue. And, you know, we think about it on a personal level, but for, you know, if you think about it in the enterprise, to have something that screenshots and executives, uh, PC every three seconds on what they're doing is just a huge opportunity for data leak, data exposure.
Uh, and I just can't see how this is gonna be successful in the long run. I, I think it's a Darwinian sort of thing, you know, and again, that's what always gives me hope on this stuff, because, you know, this is so blindingly, fumble, fingered, you know, for a big corporation. Be clear, Microsoft actually does a lot of good security, a lot of good folks there.
We all, you know, many of us here, remember the days when they really did Trustworthy computing initiative. They had some of the best security people in the world. But, so it's, again, not so much a Microsoft thing.
And again, maybe it's my focus on supply chain, but I don't see how we can have secure functional supply chains, particularly in c critical sectors in the very near future, measured in a handful of years without the kind of clarity on policy, you know, implemented for that. But I think, you know, maybe I'm trying to stretch the analogy, but I think this is the same sort of thing. And Jack, to your point, you know, this is a big corporation that actually spends a lot of money and does some good security stuff, and even they can't have enough operational policy at the product management level for someone to say, not only, no, I mean, no, that's, no, this Is not.
But I, I think the ques the question is, who were they listening to when they, uh, decided to implement this, uh, feature? Uh, were they listening to enterprises that said, we do want this to feature on all of our employees, uh, workstations. We find that this would be a useful feature.
Um, or maybe they weren't listening to anybody and they thought it was a really cool idea and don't have really good use cases and forgot about the spyware aspect of it. I wanna give 'em at least some benefit of the doubt. But we don't, we don't know who asked for this and somebody asked for that.
I, I can't imagine Microsoft just delivering something because they thought it would be a good idea without doing any kind of customer discovery. I, it would be shocking. It would be shocking for me for to know that they just did it without asking.
So who asked for it? And what are, what were the use cases and why can't you turn it on and off is the question I'd be asking Microsoft? Yeah, I think there's, there, there is a, there is a, uh, an ulterior motive here is that PCs were had become commodity items, right?
And I think there was a lot of movement towards Apple as a different form of a pc and to take advantage of AI and push more AI hardware and reinvigorate PC sales, which become stagnant, right? In order to use these features, you really do need, um, you know, not to do the screenshot version, but to do the analysis. You need the AI PCs and have an AI chip in your pc.
So there is a motivation to sell more hardware to take advantage of these features, or, you know, and so that's part of the motivation is to push more hardware. And part of it is to make the PC something more than a dumb client where the web browser is your interface to everything. Or Chromebook as you may, I'm sorry, yeah, Chromebooks.
Right. Alan, we're at the point now where Microsoft is quite literally begging slash forcing people into Windows 11. So does this become another reason maybe not to go to Windows 11 and use a Mac, or to your earlier point, Chromebook, or having forbid a Linux desktop?
So I'm, I'm gonna be the contrarian here. I think you guys are missing the boat. As a matter of fact, I would expect a feature like this more from Mac, from Apple than I would from Microsoft.
I think this is clearly aimed at to consumers, because here's the newsflash old people like us. We, we tend to give a crap about our so-called privacy. Young people don't, a lot of them don't even have a concept of privacy.
They think everything online is online. Well, it is by definition. If it's online, it's online.
But that being said, it may be more important to them to have the utility of this recall feature than it is to have the risk of that information making its way out there because they don't have a concept of privacy anymore. We've younger the, and I don't want to be go play in front of your old household men, but you know, a lot of the younger generations do not have a concept of privacy. And when they do, if they do, then they are very selective about it.
And if Microsoft were to put this on right, in terms of when you want to turn it on, when you want to turn it off, what kind of things it recalls, what kind of things it doesn't, it may find a market in people who, who, who, like, you know, it sound, I mean, you take the security aspect outta it. Yeah, that's a pretty cool, useful thing I might have. Right?
And if, and if security's not important to you, privacy's not important to you, Chris. Yeah. Let me see if I can combine my point with yours.
Right. You know, I, I stand by my, my point that there isn't the governance structure inside corporations to make these sort of decisions. You know, there, there, you know, there should be a function that if I say I wanna do this or some internal control that says before X do Y and y is, is the decision point doesn't exist.
But to your, to your point this map, those two together, because that's a very common perception of, of folks our age, right? And I think, and I've been, this is to be pedantic, one of my inevitability curve things decades ago, I'm, I was looking at this and saying, alright, in the future there will be cameras everywhere, everywhere. Nothing on earth is going to stop that.
It may be sooner or later it's happened at some point and after that point forever, for all of human future for thousands of millions, where people who live in the world where cameras are everywhere, this is the last part where we don't, and they will either exist in that world in a constant soup of privacy compromise, or they will have figured it out. And I think this is a perfect example of how much we haven't figured it out. And your comments about the current generation, I think mark this difference between our generation that says we can build a wall around all of this and no one will ever find it.
And a generation that grew up in it, who, I wouldn't take it as far as your point privacy is, is is a more fundable thing. We just think that it's a, a save for the brick, you know, wall. Uh, it'll never get open.
You know, this generation understands that nothing privacy isn't forever. And they may have thrown their hands up because us folks who built this system have no governance structure for what privacy even means, Right? I'll disagree on two points.
One is the Europeans damn well do care about this regardless of their age. And so I'm being, making broad generalizations based on age. I don't see that.
I also see my kids routinely use apps like WhatsApp, even here in the US now, because they are conscious of the privacy issues. And so they have a whole separate channel for certain conversations that they wanna have. And then I also would say, yeah, maybe we'll have video cameras everywhere and we're also gonna have meetings and block parties where there'll be no cameras a lot.
So there you go. You might, Well, to Alan's point, go ahead. To Alan's point, there was a market, there was a market because Microsoft is, Um, yeah, mi just are too smart to just roll that out.
Yeah, Yeah. They, there was a market, and I think to, to Alan's point, I think he might be spot on, um, that this was a market to a younger generation, uh, because of the way that they're much more voyeuristic than we would ever have been. They're used to having things on that, you know, all of them wanna be content creators.
Anybody I speak to who is under the age of 19 think that that's their next job. So, um, yeah, I think that there, there's a market for it. And as Alan's point, turning it on and off would've been a good idea.
Well, that, that, that may be the answer that the Microsoft makes it easier to say, like, before it recall. So is this something you wanna recall? You, you wanna set your recall policies, you know, or, or what have you?
Because I'm, I can see a, I can see a a a total use for this for gamers. I'm sorry. I just can, yeah, No, I, I It's a, a great application for gamers.
It's like, you know, as the, the, the best intentions, right? The road to perdition and all that good stuff. But, you know, is this where we're heading?
I mean, your point about cameras, we, I, I got, so I'm president of the HOA where I live, don't ask, but we, I get a thing last week that, uh, we had a, a break in. I said, oh my God, there's like no crime where I live. What kind of break in?
So we send out a thing, if anyone has video of, of the, you know, of last night showing someone potentially breaking in, let us know every, almost every house. So I live in a, on a canal to the Intercoastal, and there's houses on, it's sort of a U shape, if you will, right on both sides of the canal. And we, every house has video, it seems, either it's ring or whatever.
These are not official like surveillance videos. It's, it, each house has their own thing. We have this guy walking in at 1130 at night.
He tries to jump on someone's boat and misses, 'cause he misses the boat, winds up in the canal, pulls himself out of the canal, climbing up some, some, uh, a ladder that is encrusted with barnacles. He must have cut himself all up. He comes off the water with one shoe and no shirt, and he's walking around, he doesn't know what to do.
He sees a ladder, two doors down, he grabs a ladder, he, 'cause the door was closed, he puts the ladder up and he's cl trying to climb to the second floor of this villa to get in there. He climbs up the ladder, he falls down the ladder, how this guy didn't die trying to break into the house. He then gets up and he says, I better get the hell outta here.
And he grabs his shirt in one shoe and he leaves the neighbor and we have him walking through 4, 5, 6 house, you know, backyards to get outta my neighborhood. And we gave it all to the police. The police said, we go, we know this guy.
We caught him on the LinkedIn Boulevard Bridge at a half hour before this, but he doesn't doing anything illegal. So we let him go. He was just kinda walking around, you know, crazy.
So he never broke into anything, by the way. But yes, that's the world we live in. And those are good things to have, I guess It kind of always has been, right?
Uh, you know, if you ever lived in a small town, right? And you on a Sunday morning, put on your spouse's bathrobe and walk out of the backyard and walk back inside, they know about it downtown before you get inside, right? And that's so, and, and what I said about the past and the future, like, look, privacy, since we, you know, unless we live in a tree stump by yourself, privacy is a relative thing.
And we all deal with it all the time. If you're out in public, you are out in public, you know, people may see you, people may take pictures. The funny thing, and it's, but again, in 1742, it was the same, you know, old Broadway walked down the street yesterday.
Did you see him? Oh my God, where's he going? We'll figure it out.
But, well, You had well-armed militias back then, though. So, so this, if this issue that starts us with this, again, I, I think it is just an indication of the immaturity of our handling of this tech, right? We can figure it out.
But this is a, this is a misstep they should have thought on through at optics. So clarify that point for me. Is being online essentially being out in public, or is my laptop the equivalent of my castle is my home, is my laptop?
Only If you bring down the cone of silence, It's the same being done in public. Honestly, if you're gonna, you're gonna send the information in a email or a parchment on a carrier pigeon, it's out in public Or a whole lot of stuff we do on our computers is not involved sending that information out to the internet. And that's not public, right?
We do a whole lot of confidential work, whether it's our own personal accounting, our own personal journal, whatever you wanna talk about. We use our computers for a whole lot of stuff the same. We use our phones and everything else.
And it is not stuff that we ever intend to be shared or make public. And I think the challenge of what, you know, getting all the way circling all the way back to the beginning with Signal Signal's challenge, is there is no granular control of recall. And they had to do unnatural acts to make recall, not take screenshots of what Signal is doing, which was never meant, It definitely needs more granular control.
But, you know, Jack, I'm reminded of what I used to tell people when they were talking about risk and how could they be more secure. Don't connect to the internet, unplug your router, right? If that, if that's, you know, if you're gonna have a machine that you're gonna do stuff that you don't want it to find its way online, don't connect to the internet.
Because anytime you connect to the internet, there's going to be some risk. Whether you want to accept that risk or not, that's a risk management issue. And this is, and this is their job, right?
Like Jack, you're saying. Right? You know, and to be really clear online and online this, my machines actually have cloud bits.
You know, it's, I'm not all about physically here. There's a difference between online and online, but you know, there's also, you know, in the physical world, it's not that clear either. As we all and security people, I can listen to you in your house, in your basement with an audio microphone from not that bloody far away and andand, right?
You know, security and risk all relative, as you said, we accept a re no, we need to address all of this the same way we do all other risks. Some of it we worry way too much. Some of it we don't worry nearly enough and we have a lot of work to do yet.
Crazy. All right. Hey, we're over time on this one.
So we're gonna have to bug you for the next ones. Let's take a break here on the gang. We're gonna come back and speaking of the cone of silence, we're gonna talk about cybersecurity chaos.
Is that a new organization that Maxwell Smart is fighting? I don't know. You're watching Textron Gang.
Hey everyone, we're back here. Hey, you know, I was reminded during the commercial break. We, we broke protocol here.
We got so excited over this recall stuff. We went back, recalled it, and realized we made a mistake. You, you know, Jack Poller, who, who I've known now for some time, I, I met Jack most recently via the tech field Day gang, Stephen Foskett and, and Tech Field Day.
Jack's a regular delegate on tech field days, but Jack's also a pretty well known fellow in the security space analyst. But Jack, I don't want to introduce you. Introduce yourself.
Well, thank you Alan. It is a pleasure to be here. Uh, and yes, uh, I am, uh, a tech Field Day delegate, and actually next week we'll be doing security field day live.
So that'll be very interesting. Uh, I actually started life as an engineer developing chips and software, and then turned myself into a marketing person and did marketing for startups for a while, and then became an industry analyst focused on cybersecurity. Uh, so I, uh, speak a lot about a lot of different, speak a little bit about a lot of different things, and That's the perfect profile for a, a, uh, text on gang member.
So welcome to the gang jacket. It's great to have ya on. We look forward to having ya on as a regular.
Um, excuse me, that being said, chaos in cybersecurity. Imagine that. So Splunk has this report out where they surveyed a bunch of folks and they found that nearly half, 46% at least, claim that they're spending more time maintaining their cybersecurity tools and environments than they are actually protecting the organization.
And we've talked in the past on the show about the potential rise of what you might call the cybersecurity industrial complex. But Jack, are, are we a little outta control on our tools here, and is something amiss or, um, you know, is this just kinda, uh, nature of the game? Uh, well, I like the, uh, the reference to the cybersecurity industrial complex.
Um, there are more than 4,000 cybersecurity tool vendors with more than 10,000 products. So it is a huge endeavor. And I think what the Splunk report sort of highlights is three perpetual evergreen themes.
One of which is, you know, from a cybersecurity tools perspective is platforms versus point tools, and one of which is people and process. And the third is the critical lack of cybersecurity skills, right? And so if we think about, go back to that, is, um, you know, platforms versus point tools, and I've done my own research in this area, and practitioners always tell us that they want platforms because they want all the different domains of cybersecurity.
Whether you're thinking about endpoint security or network security or identity, they want it all to talk together and integrate because there's just so many different domains that are, that interact with each other. The problem is, platforms never provide, in their opinion, the practitioner's opinion never provide the best tools for each particular area. So they always, while they say they want platforms, they always buy point tools or best of breed tools, right?
And so when you do that, you end up with tools from different vendors that don't talk to each other or collect the same data, but store it in a different way or so you have overlapping data sets and huge data sets. And managing this becomes a problem, particularly when you think about Splunk, who originated the study in their environment where they're collecting so much data that simply the cost of storing man collecting, storing, and managing that data is a problem in and of itself, where there are now other tools available to solve that problem, right? So now you have to manage, just solve the problem of how expensive it is to collect data you need in order to figure out if you, how to secure your environment.
So it is a, you know, it's, it's something that I've seen before. It's a big problem. It's a big challenge.
And then when you throw on top of that the lack of cybersecurity skills, right? And, you know, and the research that I've done over the last 15 years, perpetually says that roughly half of organizations say they don't have the skills and they can't hire for those skills. They don't have the, the resources to staff up.
And for one reason or another, then it's just, it becomes an overwhelming challenge of how do I, you know, I need this tool because it's the best at securing this particular part of my environment, and I need this tool over here. It's the best at securing this part of my environment, but how do I make 'em work together without me spending an inordinate amount of time and doing unnatural acts? So I think a lot of people suffer from this, though.
I'm not surprised at all with the, the, the data from Splunk. I, I've got two, two things on this sort. Number one, something that really drives the, the chaos here is shiny trin and syndrome.
Jack, you touched on it. You go talk to the security administrator, he says, oh yeah, no, I wanna standardize, I wanna standardize on the platform. I'm all, I'm all in on Palo, I'm all in on Cisco, I'm all in on whoever de Jo platform is, right?
And then they're like little kids in the candy store. They walk the aisles of RSA and all those blinking lights and puppies and goats that were there this year and everything else. And, and they see that the shiny trinket, the magic bullet that's gonna kill those vampires, and they just gotta have it.
They just gotta have the sh But it doesn't work with your platform. It's okay, because I gotta have, I gotta have the shiny new trinket. And we have suffered from shining trinket syndrome and security for as long as I'm insecurity and I'm insecurity 25 plus years.
And how many of those shiny trinkets, like gifts that I buy for my wife that she's ashamed to tell me she doesn't like wind up staying in the jewelry box in the top drawer of her dresser, right? So did these, a lot of these shiny trinkets and, and, and I, until we break that syndrome, I don't know if we'll ever solve this. Totally.
Secondly though, I started a company called Still Secure in 2001, co-founded company in 2007 eight. I came to the conclusion that for all but a handful of organizations, security is just too g*****n hard. They're never gonna have the the enough resources, manpower, skill sets, everything needed to really do security, right?
And that the only answer to this was mssp, right? You had to just let them buy the security and you come in and, and provide all the security they need and want and could use pivoted. The company bought an MSSP and then organically started building more tools.
And then the board 2008 came 2009, you know, the economic downturn. And, and the board didn't want to give us more money to buy more mss ps 'cause I was out shopping. Um, I don't think it's really changed.
I, I think we have more tools. We have more attack surfaces. We, you know, we, we, we may even have more budget.
That's a good thing. I guess we have more budget for security than we did then, but it's still too hard. It's still too hard.
And there's still too many tools and a lot of them are shelfware. And it's, you know, I think there's some irony in that Splunk did this survey, but I'm not going to get into that one. Chris, you got your hand up?
I am gonna get into that one, right? 'cause I, I happened to be, I didn't even know this was a segment of hair. I'm wearing a Tito shirt, you know, the, my first round in the sim space, and then there was Alien Vault, which I think it was around the time Spunk came out.
And yeah, at that point, you know, to, to jack your point know, then there was, Hey, we already have these platforms and logging and so forth, why do we need this extra thing? But there was, and we sold this to Cisco, who in theory plug it into their bigger, you know, to your point now and, you know, uh, Cisco platform, and we keep doing this. And the analogy might be, I'm trying to think of something physical, maybe a house.
Like, you know, you get a brand new house that's perfect, it's fine. But you start adding this and adding that in 20 years later, it's a bit of a mess. You know, put all that in the, in the context of this ever-growing cybersecurity answer we're trying to find while we are building and sailing one internet that's half finished, right?
So we keep saying, it's too many pieces. Here's a platform, oh, thank God. And right or wrong, you know, Alan's maybe a not shiny things.
Maybe we're like, oh, it doesn't have one of those. We bolt that on and bolt that on and bolted on until somebody says it's not a platform anymore. And does that, is it an infinite regress forever?
I don't think so, but I think it again, marks that, you know, we thought we had everything in the platform and realized there's a bunch of things. We're doing it all yet. So here we are again.
And it's a ma it's a matter of focus. We have a focus issue. We really do.
Or A lack of focus issue. It's a lack of focus. Yeah.
If you look at, uh, and you're right, Alan, the attack service for cyber is massive. So there may be a reason to have different tools for different applications of cyber, but if you just look at open source packages, which is, you know, sort of what I specialize in, we have, there has been billions of dollars invested in this space, literally billions of dollars. And it still takes us over 90 days to fix a vulnerability, a single vulnerability.
And we have, what, 10,000 were reported in the first quarter of this year. And it takes us 90 days to fix one with all the billions spent. So again, we, we started with observability, you know, uh, uh, event management systems that says if you find an issue, these are the steps you have to go through.
And these tools can be very, um, create a lot of toil in the process, but they're not focused on fixing a problem. And it's the same with the, with, um, any of the, um, uh, networking tools. A lot of it has to do with observability.
And I'm hoping that we will see in the future, AI applied to helping us get through this problem. Because we can't throw up our hands and say, we, we have to stop doing this because it's too, too hard. We can't do that.
We don't have an option. So is AI the new, is ai the new silver bullet? I don't know, but I can tell you right now that, that we, I've been working with the CI CD cybersecurity working group at the CDF, and our goal was to take the secure software dev development framework, take every task and map it to a tool.
And I have a team of hotshot DevOps engineers and some security folks on that. And we are struggling to do it. So the the software development framework is actually too complicated.
It's, it's too, um, uh, it, it's, it, it doesn't have fo it, it tries to have focus, but it, it's really hard to think through how you would actually implement it. So the result is you don't do it. So yes, it, we, we, we need to do work in this area, but we can't throw the baby out with the bath water.
And I'm hoping AI can help. I, I really do believe that in, in terms of some work that can be done, being able to do predictive analysis, being able to troubleshoot things before they happen, being able to update configurations on a network before that they're, they're a problem or fix things in a palm file because you have the wrong pin version and, and it's done automatically for you as the way out. So, so Tracy, you're highlighting a lot of what, you know, one of the themes that I said this highlights is that, uh, it's a people process problem, right?
And it's a people process problem developing the tools as a said, the people process problem and chasing the shiny toit, the new bubble, rather than focusing on cybersecurity hygiene. Look, we know from things like the Verizon Data Breach Investigative report, that the vast majority of cybersecurity, uh, data breaches are originate in an identity related attack. And if organizations would simply make MFA mandatory, we would probably cut that in half overnight.
I mean, I've, I've talked to a, I talked to a CISO of a financial institution with had 30 million customers. And when they made MFA mandatory for their 30 million customers, they saw the number of attacks, not successful attacks, just the number of attacks they faced on a daily basis dropped 95% in a week, right? It's just, it's simple things like this that isn't a shiny toy.
It's well known. It works, and it will stop most of the breaches that most companies attack. The real, the, the most fun companies face.
The reality is most companies aren't getting attacked by nation state actors. And most companies aren't getting attacked. But with, uh, zero day obscure things that they haven't discovered yet, most of it is we've somehow, somewhere, somehow got a, uh, somebody's account and we're logging in and going from there.
And if we could simply focus on these low hanging fruit, we'd be just so much better off than implementing yet another tool in our tool chain. There are people starting to ask the question about whether cybersecurity people are Craig Cray, right? The amount of investment that we keep putting into this space keeps going up, keep buying tools, and then you tell us that you don't have enough people.
Well then where are you getting the people to master all the tools you wanna buy? So there's a lot of folks who are standing around going, you know, do these cybersecurity people really understand the ROI of the situation? And why are we giving 'em more money?
There's no ROI, I mean, look, I I, and you're talking to someone who you made an ROI calculator when I used to sell security, right? It's very hard to prove ROI 'cause how do you prove or nothing happened. But to, to, to Jack's point, you know, recently identity has been recognized as the leading cause of breaches In previous versions of the Verizon data breach report.
They used to give you a, a statistic like 80 to 85% of all breaches took place from known vulnerabilities. If we would just patch our vulnerabilities, we wouldn't have 80 to 85% of these things. Now it's 80 to 85% of these take place because we've given up identity.
If we would just put in multifactor authentication, we would do these things. I don't know. I don't know.
Did Jack and Tracy with both pain points that sort of speak to that? You know, Jack, the way I read your point, I, I agree is that most of the time if you, you just, you can mold the lawn and get rid of most of the problem, then you just focus on the rest. You know, to your point, um, is the rest gonna expand again to take over the lawn?
Yeah. I mean lines, however, right? You know, it's this focus part of it that you were talking about, Tracy, right?
You know, because as the average consumer, uh, where do you start? You read an article, you do that thing, does it solve a problem? No, that's our focus is messed up.
We're not, you know, quite often not addressing the easy things that would at least let us focus back on the big things. Le Let's look at, let's look at MFA for a second, right? So we're on a big push here with Future and Touch Strong.
We, we've gone to MFA mandatory get a lot of pushback from people. Why? Anybody, same thing like developers in DevOps.
Anybody raise their hand and say, I wanna develop insecure code. No, we all want secure code. Anybody say, I don't wanna do MFA 'cause I like to be insecure and live on the edge.
No one raises their hand for that. Why can't we get people to adopt more MFA then? Is she even what?
Like the fact we need to make it mandatory. Why wouldn't everyone say, I wanna be more secure. I wanna make sure my company's not the next headline.
What is it about MFA that's such a giant PIA that we can't get people to do this Because it is API a. There You go. Because it's a p wait, it introduces friction.
And that's, that's an implementation issue. And the market should be beating up the vendors for that. How many people use, how many of you guys use Face ID on your, your Android or your Apple phones, right?
That's MFA, that's the very secure way of Logging. Well, that, that's what I've gone to. They call 'em pass keys and everything else.
It's all fine. Pass Keys and pass keys, which is Passwordless is a much more secure way of doing it. It No doubt, I'd love to see the whole world go there.
And, and so what I, and it takes time, right? And, and I'd be happy if most organizations said, we don't have MFA, let's skip over MFA completely and go to Passkey. But that's not a realistic journey for most organizations.
And but, but my point, it wasn't like, But the technology's there, Jack to do it. We all have phones that have recognition. We all can get keyboards with the fingerprint.
We all can get fobs if we wanted it. I'm telling you that to me, it screams that people are not seeing this as a priority. They don't see security as a good enough priority to just do something simple like that.
And if more vendors built it in and made it mandatory, don't rely on the organization, go to the vendor with it, we'd be better off. And I'm convinced it's not gonna happen during my work lifetime. Well, so now here's the interesting thing is Microsoft just flipped the switch and is now making password is mandatory for its consumer accounts.
And that is, and that is under total recall too. So, so, so my issue, my issue with MFA is not that it, I'm against it on any level, but I swear every time I go implement it, it takes three times to implement it. Then somebody goes and upgrades something and I gotta go back in and re-implement everything that we previously implemented.
So, you know, it is not a one and done kind of thing. It's like I constantly have to do that. Now how many apps do I have and how many platforms?
You know, I could be doing MFA every day of the week if I wanted to. Oh, several times. I'll, many times during the day.
It's not just once a week. It's many times. Yeah, No, it's every time you log in, I know, I'm, I'm, I have to have my phone by my desk just to use my software.
That's exactly what it is. You need your phone in your hand. But let me just tell you something I learned in security early on too.
You gotta have a little bit of a breach to get religion. So Mike, when we see naked pictures of you up on the internet, you'll go to MFA. That's gonna be, I'll tell you, that's gonna be an awesome story for Security Boulevards.
Absolutely. Let, let's take, let's take a break here. Mike's going to go put on some clothes or whatever.
We're gonna come back and we're gonna shift a little bit to DevOps. You're watching Textron gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're gonna talk about DevOps and of course they'll probably be a little dovetail in the DevSecOps 'cause it's that kind of theme this week.
But we're talking about a new effort by CloudBees, which kind of help pioneer this whole space with the development at Jenkins to unify DevOps. And what they're saying is that they'll provide a control plane that will talk to multiple DevOps platforms, not just Jenkins, but GitHub actions and GitLab or whatever else you can imagine. Tracing, you've been around this space for a long time.
The land of DevOps is the land of bespoke tools. Is is that gonna change? And can we just have an overlay?
Well, you know, we've been, um, work, we, the CD Foundation has been working on, um, CD events for a very long time and trying to create a standard control plane that would define, uh, actions within the pipeline that could be managed as an event. So, you know, CloudBees, I'm glad Cloud CloudBees is talking about Jenkins again, thank you. Uh, but I don't know if, if we're going the right direction, um, for solving this problem.
So if we think about where we've been, and I've been in, so in configuration management my entire career, there was a point in time that there was an argument that you should only have one SEM tool and everybody should stay on that standard SEM tool. And every tool out there fought for it ca with Harvest fought very hard for that position. There were other tools who were fighting for that position, but it never worked.
So now we're thinking about, we're giving up on that conversation and now we're thinking about doing the same, but with the control plane on top of it so that we can try to unify and standardize, um, this fragmented information that comes from multiple locations. You know, deploy hub's, doing it too. We're doing it with, with configuration data around deployments.
But to be quite honest, I think that it's time that we disrupt, uh, DevOps tools completely. I'm ready for a, you know, a, a hand grenade to be thrown in the middle of it all. We need a massive disruption in the way that, that we do, um, work manage workflows and do DevOps because it is not, it's very inflexible.
Uh, I have complained many times on this show about the how brittle all the DevOps workflows are. Why are teams not able to add easily things like an SBO m or a collection of evidence so that they have a historical record of what occurred? Why is it so hard?
Well, it's so hard because we keep doing the same thing over and over and over, and that is scripts. So I don't know if adding a control plane for unifying the DevOps information goes far enough. And in their announcement, they did talk about standardizing on some other tooling that probably will make it hard for them to implement or to get adoption across, um, a broad audience.
Because every team wants to use their own tools. And this kind of goes back to our previous discussion around security. We are, we are creatures of habit.
We have a culture around security that says we hate having to use multifactor ification. And in DevOps, we, we like to have our custom scripts built. And until we can step aside and figure out a better way to manage this, um, we're always gonna be having this conversation about unifying the, the configuration management data into one place.
My point is though, not to necessarily manage the workflows in one place or even to watch the workflows, but as to gather the data about the workflows. Because if we're gonna ever build a, you know, an SML that's DevOps data, we're gonna have to start collecting it. And we don't do that as a community.
When if you talk to CloudBees, they, they run, I don't know, 50 million workflows and their, uh, CloudBees SaaS environment. How much of that data do they collect? And that is where I believe the answer's going to be in terms of better DevOps processing, uh, in the future.
I have a few thoughts. First of all, cloud who I haven't, I, I'll be very honest with you. I thought CloudBees was either in some quiet period that they were getting acquired or that everyone left and the last person shut the lights out.
I haven't heard anything come outta CloudBees in months and months and months, if not a year or more now, right? Um, to be clear, they, they were sort of the Jenkins company, but they didn't invent Jenkins. Jenkins was a fork of Hudson by kk, KK ssa before he joined CloudBees.
They brought him into CloudBees as chief, uh, tech CTO, and then Chief Science Officer. And then KK and Har Pete left to start Launchable. And then they brought Launchable, which I'm not quite sure what they're doing with Launchable.
That was all about testing. But I think they wanted to have KK back because once he left, kind of the whole momentum behind Cloud Beats seemed to have gone with them. They've had a bunch of fits and starts over the last couple years, right?
They tried, first they were the Jenkins company, then they weren't the Jenkins company, then they were sometimes the Jenkins company, then they were the partial Jenkins company. Then they gave Jenkins to the CDF, and they were big behind it then They weren't so big behind it. It's, it's been a muddled path for them.
And now what do they do? They say, wait a second. There's a lot of people using GitLab.
There's a lot of people using GitHub. Wouldn't it be great if we could suck in that information and just give them one pane of glass or one plane where we can manage these other open source based tools that'll get us back in with the good DevOps guys, I don't, I don't know if this is what the industry wants. I don't know if this is what the industry needs.
I, I don't see a lot of, you know, streamlining CI/CD management. Tracy, to your point, hey, I say better off. Go look up something called native AI dev.
Patrick Dero started, DevOps is behind it. Geico, Jeremy, Geico from snyk Dev SecOps behind it. There's a lot of people coming behind it.
They are looking at a better way of doing development and deployment utilizing AI and, and maybe missing some of the, uh, the sins. And, and I'm not blaming anyone. DevOps was very organic.
It grew very organically almost by design. com, I'm still a big fan. And I think it's done wonders for our industry and how we build and deploy software.
I think the platform engineering people have some ideas, right? That, that helps. They don't replace the DevOps engineer, but it's like a precursor to the developer and DevOps engineer.
Here's the real bottom line though, fundamentally, I had this conversation with Mitch Ashley the other day. Fundamentally, we make software in a factory. Software has outgrown being a craftsman, gilded, kinda small cottage kinda way of building stuff to factory level where you have hundreds if not thousands of people involved in, in developing and deploying your software.
And in a factory, you have specialists, you have robots, you have, you know, all different kinds of people working in that factory. DevOps is one kind of worker there. The security guy will be a worker there.
The platform engineer will be a worker there. The testers a worker there. Certainly the developer is a worker there.
They all work at the factory. Mike's saying, eh, maybe not. No, don't, don't nec.
I don't look, most developers that I know are are not excited about going to work in Detroit and factory. It's just not, well, Not every factory's in Detroit, Right? But that's the idea.
So, you know, they, they, they, they're, they are in their minds problem solvers and artisans, not just craftsmen. So, you know, presenting them with that metaphor has always been problematic. And they have resisted it immensely for years now, and I don't see them changing that.
Well, They'll be, they'll be replaced by ai. I'm kidding. I'm kidding.
I, I do see an opportunity for, you know, this platform and platform engineering to kind of converge. Like, I think there's a certain amount of, uh, desire for something that feels more like an easy button. So if you show up with a SaaS platform, there's some folks who are gonna say, yeah, that's good enough for now.
And, but there is to Tracy's point, much work to be done. And there are people talking about how AI agents will eliminate scripts altogether. So it could be a journey, Could be Chris, You folks know more about, you know, the current state of DevOps than I do.
But you know, something, uh, you said Tracy, you know, uh, sparked this. You asked, you mentioned SBOs, right? And in the SBO world and the working groups where we're all working, we got putting this stuff together, you know, week to week and month to month over the last couple years, you know, when some of this people like me will say, you know, we're not just talking about an bomb attached to some product.
We're talking about through the development life cycle, all sorts of telemetry about what's going on being produced and retained. And I think the reason that makes people's head reboots is 'cause how much data is that? But again, this is where we're going, you know what, and, and, and not that not to try or to try to combine too many issues, Alan, this is the, that that sort of an everlasting, uh, security issue.
You know, it's, if it's just a cost of something complicated I need to add to things, it doesn't add a business value, then yes, security's a problem. But I see in the development life cycle, actual benefits of having the kind of telemetry that Tracy, you were talking about, where, where you really do have that continuity of visibility in the workflows so that, you know, 'cause because it is a factory world, how do we actually do this if it's not all done by hand and we don't do it with the amount of telemetry and, and visibility into how we into, into the Cobra building. All right.
So Microsoft's gonna come out with GitHub recall and they will have it solved. Yeah, Exactly. I was thinking we need recall in DevOps.
I mean, Jenkins doesn't even create, you don't really have a history in Jenkins doesn't even have the, the concept of his, of historical records, right? The ch The challenge is they don't have any recall at all. The, the, the challenge is that corporations have an idealized picture of the software factory and a, uh, a, a large corporation like a Home Depot or a Target may have a hundred or 200 engineers working in a software factory.
The reality is that most open source tools originated from some guy saying, I have a very specific problem I'm gonna solve. I've created that. I built a tool to solve it.
I'm gonna throw it out in the wild, right? It's, it's sort of a variation. If you love something set of free, if it comes back to you, it was yours.
Right? And it's, you know, if you love your software set of free, if it comes back improved, great. And that's how, so, you know, open source.
So that, that, that's basic open source. But Jack, when you look at the open source of DevOps, when you look at things like GitHub and GitLab and changes, But how did those, how did those tools arise? Those tools arose not because somebody did a market test, not because somebody created minimum viable product, figured out what's actually needed in the world and did it.
They grew organically with somebody adding this and somebody adding that. So I, I'm gonna, I'm gonna, I'm gonna call bs I'm gonna call BS on you. GitLab was started because Sid Ani looked at GitHub and said, I could build a better GitHub.
This is something people want. Jenkins was fork because they said, Hudson, we don't like the rules around Hudson and who has it. And we can make an industrial strength Hudson, right?
For most open source, Jack, you're right. But for DevOps tools, these were tools that were supposed to in conference. Your Developer team.
They did, right? Except for if they had done that, they would've thought about some, a lot of these issues They did that we're talking about. They absolutely did.
In the case of GitLab, they did. No, no, no. This is why 25 years after we created make files, which are tab delimited files that are stupid, we created YAML with the same stupid thing of requiring tabs and spaces to set structure.
If we had thought about it and said, rather than saying, I'm gonna create something that solves my problem and grow it organically, if we thought about it and said, how do you create a config file that actually works, that doesn't have syntax? All of that. We know we had 25 years of history with make files before we ever got to yamo.
Right? We could've, we, we should never have gotten to where we are today. If we had done an MVP for yamo, somebody would've said, this is ridiculous that I actually have to figure out how many indents I need in order to, But I know people who love yamo.
Okay, let, let, let me could chime in here. Part of the problem has been open source, because it's free could be easily downloaded and a DevOps engineer or a developer can get started with it without doing what? Without doing a single product evaluation.
Now, if it's a paid for product, they're gonna say, we need to find two or three products. We need to sit down and write what our criteria them should be, right. And bake them off.
And I used to get so frustrated in my open make meister days when, you know, go back to, to make, we were generating, um, what we called build control files that got rid of a lot of the problems with a standard make, uh, and standardizing how libraries were being pulled in. And we struggled because we would try to go out and do a bake off with nobody else. And the developers would already had written these massive make scripts, and the companies would say, well, we've, they already fixed it, but they really hadn't.
They just have something running. Right? But there was never in open source and Jenkins benefited from this.
You never had to go through a proper, uh, uh, product, uh, evaluation. And so what happened? We stopped listening to our end users because they would just download whatever they could get their hands on.
And if it was failing in certain areas, they overlooked it because It was great. Well, that was the tool, right? Jenkins was the tool.
That was the tool. It had the most attention. I gotta pull the plug.
I'm gonna take the prerogative here as host to give you my last word. A lot of the open source DevOps tools. Jack didn't follow that Cathedral and Bizarre do Open Source because it's, it's cool they did Open source as a business model.
And there's a difference when you do open source as a business model. You're just thinking, how could I use open source to get greater distribution of my product that I fully intend to make a lot of money from? Anyway, we're gonna break.
We're coming back tomorrow with more Tech Drunk Gang. Jack, it's been a great first time out here. Can't wait to have you back on Chris.
Good seeing you, Mike. Tracy, we will have you on again real soon. Maybe tomorrow.
Stay tuned for Tech Drunk tv. I think we have no, no Tech Field days next week. We won't have a Tech Field Day immediately following, but text Drunk TV's on.
Check it out. I'm Alan Shimel, we're out. Hey everyone.
Welcome back here to Techstrong tv. You know, I, as someone who's founded a couple, co-founded a couple of companies, I love interviewing co-founders and founders of startups because it's their passion that, for me, makes the tech world go round. Yeah, there's Microsofts and Oracles and Googles and all those hyperscalers, but you know, my people are the startup people and, and so I'm happy to re have one on with us today.
Let me introduce you to Monzy Merza. Hope I got it right. Mony is the co-founder and CEO of a company called Kroger.
We're going to hear all about him. Manzi, welcome to Tech Drunk tv. How are you?
I'm doing very well, Alan. Thanks. Good to be here.
So, I, I, I hope I didn't oversell you here, but, you know, tell us, tell us what gets you excited? What made you so driven that you, you went out and co-founded and you're CEO of a company? I've always worked in the cybersecurity space.
I worked in the weapons labs. I worked at Splunk for about a decade. Um, and then I was at an executive at Databricks, and I had this crazy idea.
And so before starting Kroger, I actually, I'm so passionate about this space. I went back and worked for one of the largest banks in the world on the cybersecurity team to really try to understand the problems, the day-to-day problems that security practitioners face every day. And that's why we started Kroger.
And our mantra at Kroger was to make every security analyst as effective as the entire team. What does Kroger do? It's very simple.
Kroger works on tickets. Security teams get thousands of tickets per day. There's not enough time to work on all of them.
And Kroger works on those tickets. I love it. Manzi, I'm thinking back 'cause I remember you, I think we, Splunk, Splunk had bought a company.
I was at a Splunk comp, and I think you and I did an interview or a, a talk, um, was it on their research team or what were you doing at Splunk? My last role there was VP of Security research. Yeah.
And, um, I, so yeah, anyone on the call who uses Splunk? Thank you for, for being Splunk customers and, and by extension, you know, our work at Kroger because a number of people at Kroger are, have that same Splunk, DNA. Very cool.
So it's been a couple years. Manzi. I'm glad to see you.
This is great, man. I love to see people advance along and, and, you know, taking this baby out. com, that's a great domain.
But what, what's Rogel actually, what's the, what's the, you know, there's always a story behind these names, Manzi. Yeah. What's the Story?
It goes back to our mantra. We wanted to make every security practitioner, if we want to make every security practitioner as effective as the entire team, what's it gonna take? Well, it takes three things.
And I learned this from the weapons world is gonna take power, it's gonna take knowledge and is gonna take reasoning. And so the CRO in COBOL stands for Kronos, uh, from, from the, the, the Greek mythology, very powerful entity. The G is fornos.
Unfortunately, most people know it from Avengers now, but Exactly. That's condos and Kronos. Yep.
Yeah. And so the, so the CRO comes from Kronos, which is order and power, and the G comes from gnosis, which is, which is the knowledge. And the l is the logic, which is rationale.
So we combine the three ingredients that make a trite. So it's not a lock or a shield, it's a, it's a weapon to be used by the security community to, to make its life better and to make its customers lives better. I love it.
I love it, man. That's a great story. It's a great, it's a great angle.
A great explanation. Very cool. Very cool.
Excuse me. So Zi, let's, first of all, let me get this outta the way for people who wanna find out more about Kroger. What's the website?
com. I love it. And then Manzi, give us a little history of Kroger.
When did you found it venture backed? What, what's the story? We founded the company officially in March of 2023.
And, uh, we started with a small, uh, friends and family round, and then we raised the seed round. And then, uh, we, we raised a series A round that was led by Menlo Ventures and Total Capital, um, in, uh, a November December timeframe of 2024. I love it.
And we finally came outs steal. We've made our first big announcement coming outta steal in, uh, in March of this year through two years and a quarter in almost. Good for you, man.
Congratulations. Thank you. Thank you.
It's a blast, isn't it? Good for you. Good For you.
Yeah, it's amazing. I mean, we've, we've gotten such great feedback. We, even in this short period, we have, we have customers both in Fortune 500 and really well-resourced government agencies.
We have, we have a product, a, a shipping product that, that we're selling. And, and, and, and customers love it. So we're, uh, you know, in this small period of time, we've been able to make really, really good progress.
Good for you. So, Mony, you know, look, you've been in security, you've been in places I haven't any that I've not been in, you know, in my 28 years in security. But, you know, as the co-founder and as a CEO, you, you have a worldview, right?
You have every, and we all do, we're all guilty of this. And whether it it makes us bias or prejudice it, so be it. But we have our view of kind of what, what works, what doesn't work, what's missing, what needs to get done.
Uh, let's talk a little bit about your worldview. What, what, what can, and what, you know, and it, it ties directly into Kroger's mission, right? Which ties into their products starts with this view from you.
Let's hear about your view on cybersecurity and, and what we've done, right, wrong, and what Kroger's gonna make better. Our view is really shaped by the experience that the founders at Kroger have and the experiences that we've learned from the community. We are part of this community.
We didn't wake up one morning and said, Hey, this AI security thing is kind of cute. Let's make a company. This is, this is all we know for good reason or bad reason.
And we've lived in this community for a very long period of time. And so a couple of core of base principles that we've learned. The first thing in talking to lots and lots of organizations and, and practitioners, what we learned was tools were actually getting in the way of the security practitioners.
And what they meant by that was there were too many tools. There are too many schemas, there's too many different programming languages, and there's too many things for a particular practitioner to keep in their head at any given moment in time. I mean, if you really think about it, those who are practitioner on the team, on the, on, on, on the video here, they, you, you know this, you're supposed to know how to use 17 different products.
You're supposed to understand how email works, and you're supposed to be able to explain to somebody how authentication happens across your enterprise in any given moment. That's a ridiculous proposition. I mean, we don't ask a, a cardiologist to be a dentist and to be, be very good at baking bread for you at the same time.
So this is a unique discipline in cybersecurity. So the, and because of that expectation, the tools actually get in the way. The second piece that we, we, we kept hearing from leaders on the flip side was, well, we don't have enough people, and everybody says that, but when you tear it apart, you realize what they're really saying is they, they can't find these unicorns.
Well, that's a big surprise. Like, where are you gonna get all these, these people with so many different facets, right? So our worldview was that this expectation being ourselves as practitioners, this expectation of being an expert in everything is just unreasonable and perhaps even naive.
It's layered by a number of people in wherever that somehow believe and don't understand the security operations world. And then on top of that, we hear from a lot of companies, especially now with the advent of ai, that somehow they're gonna replace the analyst, anyone who says that has obviously not worked the job of a security practitioner. And so those are the three basic routes of us creating a company that we said, how do we get this capability in the hands of the practitioner that amplifies their work, that enables them to exercise their intuition?
And that, and that gives them the capability as a multiplier. And that's why, you know, the name rogel is important because we, we, we think of it as a weapon, as a, as essentially a superhero suit for the security practitioner to accelerate them and to do what they actually want to do, uh, and eventually create an environment and a product that enables every practitioner to be as effective as the entire team. And so that's, that's really our worldview on it.
And that's the thing that we're passionate about. We serve, we serve the security practitioner and nobody else, You know, as someone like you Mony who's been in security, this is, to me, this is like duh. Right?
You know, captain obvious things. But I, we, we were just talking about it today on our text on gang recording. You know, the Linux Foundation came out with yet another framework now for how cybersecurity teams can interact with developers and DevSecOps and DevOps and what have you.
We got enough products, God knows, we've got enough frameworks, we've got enough certifications that people can take, right? To be a security person. But when I started, there was no cybersecurity.
We, well, we didn't even call it cyber, but it's a whole nother story. Um, but we do live in interesting times, right? This, this, this AI stuff, how real it is now, but I'll leave that, I'm not going to get into those arguments with you, but I will tell you, it's getting more real every day.
Yes. And it's getting more part of what we're gonna be doing every day. And I think it is going to change the game for too long.
You know, one of the laments in security has been that we've been totally reactive. We're always almost by design, we're, we're like Tom and Jerry, and we're the big dumbo cat, right? With the mouse running circles around us in, in a lot of ways.
It would be great to to, to change that. So let's talk about Kroger's mission. How are you changing that?
I obviously, we'll leverage ai. Obviously we're gonna leverage your, you and your team's expertise. Where does rubber meet the road?
Modsy? Yeah. Thank you for that question.
I wish more people were talking about this, because the key point for, for the practitioner community is what's the work to be done, right? We, as practitioner security analysts, we, or, or whatever role we have within a, on a secure cybersecurity team, we come to work to do a job. And, and that job for many of us boils down to working on tickets.
But if you peel the onion just one layer deeper, what is really happening? We're touching lots and lots of systems. We have a lot of questions, and we're trying to answer a whole bunch of those questions.
And we can talk about AI all day long. But I'll give you a very simple concrete problem that Kroger solves for the security team in that respect of resolving tickets. One of the things that happens is data that is required for analysis is spread across multiple data stores.
Even within one data store. Data is not normalized. com or fill out the form and tell me that your data is normalized.
It's not normalized by any standard. I've yet to meet that organization. And especially when you get across multiple data stores, then all bets are total.
I mean, that is not even a question. It is, uh, unto themselves, these data sets are not normalized. So Kroger, as far as I know, and I'm open to comments from back from the community, we're the only product that says data normalization is optional.
Because what Kroger does is goes in, when you install Kroger, and Kroger learns the data that's in your environment, just like an analyst goes and learns from the data and environment and then operates on that data without normalizing the data. Because as we think about ourselves as practitioners, you show up to work first day and somebody gives you an account, whatever the tool is, it's Splunk, it's log analytics from Microsoft, whatever tool that you're using, you don't say, oh, your data's not normalized. I can't work here.
We figure it out. Kroger does the same thing. That's the very useful way of using a knowledge graph.
It is not actually, it's not an LLM problem. It's a knowledge graph problem. And, and it's, and so we, we utilize the best tool for the job.
And in this particular case for that very specific thing, enabling the analyst to operate on data that we know is not normalized, that we know will not be normalized over a long horizon of time. So that's just, that's just one example of, of, of the many things that we do under the hood as a product, because we're so focused on the tactical work that the analyst community is doing. And that work is, you have alerts that come in, you have to analyze those alerts, and then they have to respond to them.
Agreed. Zi, first of all, man, it's good to see how your career has, has progressed to this. I wish you all the luck in the world with Kroger and all the success, but look, I know the kind of work you're capable of, and I know the kinda work you've done, I, you're well suited to, to do right here.
And I think, I think you're in the right place at the right time, right? Because this is a great time to change the whole, you know, latitude. If you borrow a phrase from Corona beer to change the whole latitude of how we approach doing security cyber, right?
Well, I think we're in an inflection point, right? In the sense that right now we, right, we've seen the, the cloud inflection, the high speed networking inflection, the big data inflection. This is another inflection that creates new opportunities.
And I think the consumer, the business users that all security teams support, the business user's ability to do work has expanded a lot because they're using AI products and services. So if we think about it from a practitioner's point of view, and we get this feedback a lot from customers and prospects. The business user previously was able to, let's say was, let's rewind the clock five years ago, was able to do one unit of work Today that business user is able to do five units of work.
And if that business user is doing five units of work, that's creating additional five units of activity for the security team to protect and defend, right? So that the security teams, we have to, we have to evolve very, very rapidly and keep up With that growth. But the security teams should be able to do five units of work where they did one unit before.
Yes. And and that's the thing. And I'll say one other thing, Zi, these other inflection points you mentioned, excuse me, they were technology industry inflection points, the cloud, you know, some of these other things.
What, what's happening here with ai? It's more akin in the internet, like commercial, yes. There's civilization inflection points Yes.
Right? That are bigger than even us here in security or tech in general. It's changing.
To me, there's been three big inflection points in my four, in my work career. Number one was the advent of the personal computer. Number two was the advent of the internet.
Number three was the cell phone. Cell phones, yeah. Stability.
Yes. Just changed everyone's life. And I think AI is the next big one.
The other ones are big, but they don't rise to those four. I agree with you all heartedly. This is, this is way bigger.
This is a compound effect. And, uh, and it's, and it, and, and, and it is of that nature. It's a completely new terrain in the and and modality of use of work and, and how we interact and as, as human beings and how we live.
And now We live, man, it's crazy. Hey. Amen.
But nevertheless, I wish you a lot of success in everything I've said. I stand by. I'm, I'm pulling for you.
Keep please come on here. Keep us posted on Kroger. Look forward to hearing about your progress regularly and keep doing what you do, man.
We you. Thank you, Alan. Great to See you.
All right. Marzie me, co-founder, CEO Kroger here on Tech Drug tv. We'll be back.
Stay tuned. Hello and welcome to the latest edition of Techstrong AI Leadership Insights series. I'm your host, Mike Bazaar.
Today we're with Peter Wang, who is Chief AI officer for Anaconda. And we're gonna be talking about well OpenAI models. And you would be surprised there's a lot of controversy on this subject.
Hey Peter, welcome to the show. Thanks for having me. Really glad to be here.
We've seen people toss around the term OpenAI models left, right, and center. Some of them are partially open, some of them are all the way open. Some of them have different licenses.
What you be thinking about here? Well, I think, um, you know, we should, we should definitely be very clear about what we mean by it. 'cause if, if we're not precise and clear about the meanings, then we can think ourselves and convince ourselves of things that are actually not true.
Um, and the term open source AI is rooted in, of course, the term open source software. And the reason why the term open source software became important was because software, you know, used to be source code that got compiled to opaque binaries that people could not understand what was inside them. People didn't know if they would always do the right thing.
People could fix their own bugs. They couldn't innovate on them. You'd have to have the source code in order to allow all of those things to happen.
And, you know, fast forward 40 years, we're at a point now where people sort of take it for granted that most of the source code we use, most of the software use, we can look at the source code. Uh, and now we go to AI models. We have now the same question.
We have to, I think, recover the origins of that, of that word and that phrase and the motivations in order to think clearly about what it means for an AI model to be open, and what are the virtues and values we want from such open models. There's also, it seems like different kinds of licensing terms used for different models for that matter. We see the same thing in software, but there's also the notion of whether or not the weights are actually open as well.
Because I may get access to, uh, the model, but I don't know how it was built. Yeah, well, there's the training process that produced the weights. There's the data that was crunched through the training process.
Those are different things, actually. And then there's the weight themselves. Now, in almost all cases, uh, no, sorry.
In many cases, the weights are open to you. And that's why people use the term open weight models to distinguish from open source. 'cause almost none of the models will tell you the actual source data that went into them.
So I don't wanna be too much of a stickler on the, on the details of this, but it is really, really important if we're gonna say open source, that implies you can see the source of it. But if you don't tell me the data, then I don't know the source of it. You can give me numbers.
You can give you a giant, you know, several hundred billion parameters and weights. That's very helpful and that's great, but that doesn't actually tell me what went into it. Um, so I think that's where, you know, there's definitely a, a spectrum of what people make available.
So are any of these things truly open in the sense that how we think of that term? Or are they all just different degrees of proprietary? There's only a few that are really open.
Um, not very many. And, uh, they include some of the models from IBM, uh, where IBM is, is pretty transparent about the data that went into it. Um, there's once Element Institute, uh, and from plaus, they just released one.
And I think maybe news researcher prime, prime, um, prime meant alike. Um, but for the most part, almost all of the open weight models do not reveal what their sources are. Um, they, they don't wanna talk about it at all.
So what's the danger there? Am I gonna get locked in? 'cause I also see that it seems like standard APIs now.
So can I swap out these models regardless of how open or closed they may be anyway? Well, um, we need to think about what are the things that people actually want in terms of, well, in, in, in terms of anything, right? Besides free.
And besides not being locked in or having the option of substitutability, um, there's many other things that people actually want from these things because these models, right now, we use them for, you know, gen AI for like text and images and video. That's all great. But if you're using these things as serious, like the engines inside, uh, a real computational system that looks at customer data, looks at business data makes really, you know, meaningful, impactful decisions or helps you, you know, predict the future, you really want to know what's happening there.
And, and you wanna not just have like a guarantee that things will be free forever. You actually wanna understand what went into it and actually have the ability to change that and to modify it. Uh, if you don't have the source weights and training data, uh, sorry, if you don't have the source training data and the training regimen, then you actually, you could do some fine tuning.
But at the current state of technology, you have no way of guaranteeing to yourself that, you know, there's not gonna be something smuggled inside there. And every single day, every single week, we see these instances where, yeah, these models start popping out stuff that wasn't a trading day that people didn't quite expect. So we're such a in or such an early stage of the industry that, you know, the, there's lawsuits flying right now and people will start catching liability for these things.
And, you know, that's, that's gonna be a problem for potentially for users. So I think, you know, we're, we're right now people are in a little bit of a YOLO mentality. Um, but, but I don't think that's the way it will be in the long run.
We've also seen the rise of AI agents, and a lot of those AI agents seem to be able to swap out from one LLM to the next, or at least that's mm-hmm. Promise. Um, so will the LLMs and the models become more disposable in time?
How's that gonna evolve? I think there will be less and less distinction. There's been really fascinating research over the last couple of years that, um, well, I guess it sort of tells something we already knew, which is that for the most part doesn't matter what actual model you use in terms of the code, you know, of the transformers and this and the other, or your training regimen in the limit.
Most models that are produced by kind of any, sorry, most weights produced by any of these models, um, they're really an expression, a compression, some, you know, representation of the, of the original training data. So if you have, uh, different, the same training dataset, different models, they'll produce weights that are actually, uh, within a rotation, isomorphic to each other. Sorry for big words there, but just to say, you actually get very, very similar weights coming out of similar source data.
So the bigger the models are, the more likely they are to actually be kind of the same model, even if they're made by different teams, even with slightly different data sets. And even if the codes for the models are somewhat different, at the end of the day, the alt the weights, like the giant pile of numbers that we use to then generate the outputs, those weights are actually very, very, very similar. So this is a long-winded way of saying, emphatically to your question, emphatically yes, right?
That if you try to build really big ones, well, what goes into a big one? All the data in the world, well, if you take all the data in the world, they basically all look the same. You know, they all contain all sorts of different same ideas.
Not, not different, but all the same ideas, the same source, the same various things. So you end up with kind of the same weights at the end where you get differences. We have differentiation possible.
And therefore, differentiable markets is, if you go to smaller subsets of those things, if you go to very narrow, very specific, the high saliency, high quality, high purity kinds of data sets, if you use those to fine tune, if you use those as agents inside a larger framework, if you use those as, you know, thinkers inside a chain of thought or, uh, a mixture of experts, now you can actually have a somewhat differentiated product. So there's also different sizes of LLMs. There's different context windows, and, um, they cost differently, right?
I talked to some folks and they're experiencing what we call token shock, and they're like, mm-hmm. So many of these things require inputs and outputs, and they're paying for things as on both ends of this, and it quickly adds up. Um, but do we need big LLMs for everything?
Or can we be smarter about which LLMs we're using to be more cost effective? And dare I say, do we need something that feels like finops for LLMs? Well, um, the answer is yes, we can expect them to get smaller.
Oh, sorry, you asked if they, do we need really big ones? No, we don't. We do expect them to get smaller.
We do expect more people to use small ones and harness them in pipelines or in, you know, kind of a somewhat dynamic fashion. Uh, and what we've seen again, or just over the last eight to 12 months, uh, is really, I think a lot of people buying into the mentality or converting to, to, to the mentality that pre-training to post-training or what they call test time scaling, like those kinds of things. It really is a spectrum of how much, how much do you want, where do you wanna put all your energy, right?
And, uh, you can pre-trade a gigantic model, then you have to quantize it down to something like a fraction of the size, what was the point of all that? And then you do this like test time scaling where you let it think for longer, why not have a less precise model, then, you know, let it think for a little bit longer. And then you, you're balancing your costs in that way.
So absolutely, I think we'll see smaller models and we'll see people trying a ver a variety of different, uh, reasoning architectures, uh, to, um, to get great performance. And one of the reasons why the token costs are expensive, just keep in mind, one of the reasons they're expensive is because, uh, people are still running these, for the most part on GPUs, which are supply constrained or have a significant markup on them. But actually the work that you need to do to, um, do token inference, token generation, and inference on smaller models, you can run that on A CPU, you can run that on a Mac mini.
So that at that point is not just a more efficient model, but you break into being able to run on a category of hardware that doesn't have the price premium of a top of the line Nvidia server grade GPU People are also trying to figure out, well, it feels like it takes a village to build an AI application, right? I got data scientists and developers and software engineers and data engineers, and, um, uh, assuming that they're all on some common platform, but how do I operationalize that? And, and from an enterprise perspective at scale in a way that, um, you know, is cost effective?
How do you think this is all gonna come together in the future? Well, it's, it's, I I, I think right now, it, it takes a village to do it, right? And that doesn't stop many people from trying and end up doing it wrong.
And even if you have a village, you can still end up doing it wrong, because we're in such early stages of this stuff. You know, when a company, uh, as large and visible as X AI ends up having some of the, like they just had this week, right? One rogue engineer does something to a system prompt, and then you end up with a, a, you know, sort of a real controversial sort of headline, um, you know, the best practices for enterprises.
I, I think that, that that's still being figured out. And in terms of actual ROI for things, you know, it's, it's, it's sort of a dirty secret right now, but the ROI is still there. It's still yet to be seen for some of these folks.
People believe it's there. I think it's there, but we have to figure out how to get there. And, uh, but the real value ultimately is when AI doesn't require a team, when it doesn't need all these experts to carefully craft this thing.
When you can actually empower a single end user or someone just, you know, in whatever line of business, um, not particularly technologically sophisticated, but they have wisdom about their problem. They have information about their data and their customers, and the business reality and context. So what AI can do as a true digital transformation, the AI transformation of businesses, is to bring that person's insight in, in the most effective way possible, and then connect it to an infrastructure a backend that is well plumbed, well thought out, that is enabled to say, here's the best practices.
No, if you don't know what Python is, you should probably not go try to find which of the million models a HuggingFace is the right model for your application. Here's the golden path, right? And when you deploy a model, you don't have to know how to detect vulnerabilities in the software pipeline for that model.
We have a platform that'll help you manage that. And we have central it, which used to just deal with a few, you know, hundreds internal developers. Now they're faced with literally tens of thousands of end users, business end users deploying LLM agents.
How do they end up not having, not ripping their hair out? This is all really stuff that we've been hearing from our customers as they've been on the vanguard of deploying ai. That's why we built the Anacon ai, the enterprise AI platform, which we just released this week.
It's really to allow all these different stakeholders to play their role well, and to have visibility and have traceability and provenance across the entire process of building an actual operationalized enterprise grade ai. So we may not get to some magical Uber platform that automatically democratizes everything overnight. But it sounds like what you're describing is there will be, uh, swim lanes where everybody can more easily collaborate with each other within the context of the same project.
And, and so doing, reduce a lot of the friction we're currently seeing. Yeah, it's, um, the way I think about it's like, you know, any kind of complex system, right? Um, it can, it can fail.
It can fail if any one of the parts fails, right? So if you wanna have secure, reproducible and reliable ai, if any of the steps go wrong, then the thing doesn't work. So you have to do each of the steps, right?
But to find a single person or build a magic team that knows how to do all the steps right, is virtually impossible. It's like hunting a unicorn. Um, it's a very similar problem to what we saw with people trying to operationalize data science.
And MLOps, the same problem. AI makes it even bigger and harder. So the goal here is to create success lanes, right?
So people who are good at understanding the data, they can make their data available, they put it in a registry, people can know what data sources they can use, what models are, are, are well tested, vetted by the organization for what kinds of use cases. So you're looking at internal model catalog as opposed to trying to scroll through, you know, piled millions of open source models. You can just bring ones in and, and then the people who take a model and they wanna do a domain problem, they're able to do that part of it, and then again, kick it over to the fence to the next guy.
So it's really about every stage of that, that factory floor doing its part right, and being connected well to the next stage. Uh, it is not, not trying to be some Uber thing that solves everything. It's just setting standards and doing the right thing at each of the steps so you have a better chance of, of success throughout the whole process.
All right? You're heard in here, folks, they say, good engine, please, based on separation of concerns. And that's right.
If we have a platform that enforces that, we might get to where we're going faster. Hey, Peter, thanks for being on the show. Thank you so much, Michael.
All right. And thank you all for watching the latest episode of Techstrong AI Leadership Insights. You can find this episode and others on our website where you might check them all out till then.
We'll see you next time. All right. Welcome to episode 82 of Infrastructure Matters.
The whole team is here, except I think I'm the only one at, well, I don't know, Diane, I don't think you really have a home, so to speak. Like, you're, you're, you're, you're probably the best example of what the future looks like. Where in Europe are you this week?
I am still in the Balkans. So just across the way now from, uh, Italy. Uh, we're in a town called Vore, uh, in Albania.
Hmm. That I, I've never been Additional noad for the rest of the, for till the fall. I've never been to the Balkans, and you're making, I never actually desired to go to the Balkans, and you're making a very good case for why I should visit that region of the world.
So I Have pull up a map, I have to pull up a map to figure out where you, I knew where Montenegro was. It's right below, yeah, Montenegro, it includes part of Greece and, and, and Macedonia. That's all the Balkans.
Okay. And it's a big day here. 'cause, uh, Zelensky is in town along with every other EU leader is all here today, uh, for the European Council.
So, um, it's a big day for the country as well. All right. So let's get started.
We have quite a bit of news to go through. Cameron, we we're gonna start out with you. Uh, I, I actually just read an interesting article leading up to your story, how a developer who, uh, got laid off two years ago, gen X guy with 20 years, couldn't find a new job because of ai.
I, I I, this was in Business Insider, I'm a little, nah, that, that story doesn't quite, uh, match up for me for what I'm saying in the market. But you have a, a story about a AI robotics and augmenting versus, uh, replacing humans. Yeah.
So I was looking at, there was a bunch of things I was looking at, and one of them was a post that Daniel Newman put up about Klarna. And Klarna had a, um, I think last year about this time they had, there was a post that was in Fortune saying they're replacing all their people with ai. And then they just had another post that was up there saying they're not, you know, and, and so why the difference?
And then the other, one of the other pieces I was reading was, um, a very well done article on, um, Amazon and how they're using AI and robotics and the efficiency they're getting. And I think when you take those things, I mean, there's, there's this huge fear on one part of the world that we're just gonna take away all the jobs and everything else, and AI is gonna, and those of us that have been working with AI know that's not necessarily true because we, we can see some limitations, but yet you see the efficiency that Amazon is getting with this on Amazon, seeing, talking 25% or more efficiency that they have, how much robotics they have in there. But if you listen to what they're saying is they're not replacing people.
What they're doing is they're augmenting what the people are doing. Um, and one of the curious little pieces they said is that one of the, the number one thing that is the, um, task that people would have is walking when they're working the warehouse, right? And so what they've done is the robotics has, has augmented the humans and eliminated much of that walking around, which is not really efficient.
So then I think about, okay, so how does this play out when, you know, Klarna is about, um, shopping and healthcare and that kind of thing? How does that work? It's like, well, what we're seeing here is with AI is AI is augmenting not replacing the humans.
So in the situation where it's maybe a system of something, what you're doing is you are assisting maybe in gathering all the information I need to do in order to be a customer service person, or, or in order to do a, or process an order or something along those lines. So I think it's, we need to re rethink about, or people need to rethink about how this plays out. And that is, how does AI augment what my world is, whether or not it's through an AI robotic, whether or not it's through a chat assistant of some sort, whether or not it's, you know, some of the things that you've been doing is that you're looking at it, um, Keith is, you're using AI with Reddit to kind of give you a better streaming or some of the investments that Futurum is making in terms of how do I use AI to consolidate all the information that as an analyst you're plowed in with and you've gotta, you've gotta absorb all this information.
I mean, it's, it's overwhelming at times trying to keep up. So really, really interesting way, I think for CIOs and other people to think about. It's not replacement, it's augmenting.
And that's gets back to the, you know, the programmer. How do you augment your programming to making you more effective and efficient? Well, and we just had the, the CEO of IBM, Marvin Krishna, who says they are, they've replaced the hundreds of HR professionals completely with ai.
So, I mean, I think we're seeing both sides of the coin and the US study by, uh, out from the University of Copenhagen and Chicago Booth, I did a study of, uh, 50,000 workers in Denmark, which is a, um, um, highly dynamic workforce. In other words, you don't have a lot of barriers to, to, to people leaving, entering the workforce. So it's like the US reported that, um, AI benefit are largely accruing to the, to the employers, not the employees are not seeing higher wages, even though they're putting up better work and more creative work.
'cause they have more time to be creative. 'cause AI is getting all the grunt work out of their way. Uh, they're, they're, uh, and they're saving a bit of time, but all the benefits are right now, at least the way everything's structured is going to their work, uh, to the employers, which is very interesting.
Yeah. And I've been running a, uh, basically a 100 day of ai, another 100 day of AI that I do. It's, uh, zero to builder learning how to code organically with AI from not knowing how to code or likely coming to coding from being away from quite some time.
And I think it is a mixed bag. There is absolutely, uh, you know, an, uh, uh, area of the workforce that's going to be, uh, negatively impact. And that, I think for what my research is showing in my, this qualitative research that I've been doing is going to be the junior developer.
Uh, I've talked to principal, uh, software developers at Amazon who's working at, on some of the most advanced application development projects in the world, and they're finding tasks that they would've got given to a junior developer, creating unit tests, et et cetera. They can just do 'em with ai and it makes them incredibly more productive. They're not gonna lose their job, the principal architect, because, you know, they are the architect of, they're, they're the human engine, but the junior engineers, they've definitely, uh, been able to, uh, displace some of that and be just more productive.
So I, I do agree it, what I'm seeing, it is a mixed bag. It is augmentation, but that productivity is coming from some part of the workforce and that part of the workforce will get impacted. Alright, moving on.
HPE Morpheus VM Essentials, that is a mouthful. And I was on some of this briefing. Kimberly bring us up to speed While Morpheus was bought by HPE last year, um, you know, in their cloud management product, et cetera.
But they've done a lot of other things. Good friend of mine, Brad Parks was over there, is a CMO, um, actually ex HPE folks that were over there. Yeah, it was kind of circular.
Yeah, It was very circular. And Calvin Zda who left and is now back over there as, you know, doing stuff over there as well. But anyway, so what, um, what they announced here is the VM Essentials is it, is it's, this is, this is H HP's vm, which is based upon KVM.
Um, it's a type one vm, meaning that it lies on bare metal. It's not sitting on another hypervisor or something along those lines. Um, and this is, and I've looked at the demo, it's really slick.
It looks really good. Um, you know, of course the devil's in the deployment and those kind of things. There's, um, so they're talking about clients replace, this is for clients that wanna look at another alternative to ESX, but at the same time, the morphous environment will manage not only H-V-M-H-H-V-H-V-M-H-P-E-V-M, it will also manage ESX.
So one of the nesses of there is that you've got to, you've got the same tool to be able to do some of the similar kind of functionality across, across the board. So, um, I need to dive more into it. So you might have even seen the demo, um, Keith since you were on the formal briefings.
Yeah. So the, uh, Morpheus folks have been around for a long time adding what I would argue an, an amazing amount of value for such a small company. They, uh, pre HPE, they didn't like to call themselves a multi-cloud management solution.
Uh, but mostly that's, that's how I would classify them as a multi-cloud management solution. You can take your, uh, your AWS VMs, your VMs running on vs. Spear hyper VKVM, and now HP's, uh, VM Essentials.
And Ron, it, one of the things that Russ, uh, from Signal 65, uh, me mentioned is that the naming is a little confusing because VMware has a VM essentials product as well. So they have to clean that up a bit. But it is a really interesting thing.
Uh, whenever I tweet post about VM replacement, uh, VMware replacement, it gets amazing traction. Much more so than most of my AI products, uh, uh, uh, post it is because this is where the challenge relies with Broadcom disrupting the marketplace. It opens up opportunities for HPE, uh, Dell Tech world is next week.
I'm sure Dell will have a, uh, an announcement around how they're helping customers, uh, have hypervisor choice. It is a huge fo focus of the enterprise, uh, if not the CIO, his, his, his or her direct, uh, reports are trying to figure out how do they do, how do they maintain what they were doing yesterday? Uh, not, you know, not, not necessarily, uh, uh, paying less than that what they were, they, I think they'd be happy with paying what they were paying yesterday.
Yeah, Definitely. Anyway, this is gonna be running on their DHCI box, which is their disaggregated hyper-converged, which is a, yeah, it not, it's like, okay, disaggregated hyper-converged. Where, where, where are we going with that?
But anyway, their DHC Box, which yeah, it's composable, right? Yeah, exactly. Ironically, I, ironically, I own one of those.
It is a I heard that. Yeah, it's a pretty cool box. Uh, Dion, Microsoft failed to deliver a special version of, of Azure for EU providers.
This is spicy. What, what, what's going on here? Yeah.
Well, well, EU um, uh, customers, uh, of have a long complaint that, uh, if they go to a non Azure provider, that Windows server and it's related, uh, components are more expensive. And that's what, of course, 'cause the cloud provider still has to do everything Microsoft does, except they also have to pay for server licenses, right? So, um, in addition, the, uh, those businesses also complain that there are stuff in Azure that you can't do in any other Azure cloud provider.
There's special features that they've added because they own the operating system. They know all the ins and outs. So those twin complaints, uh, the EU had negotiated a, a settlement with Microsoft saying, okay, we'll provide a special version of, uh, Azure that, um, uh, that has those features, um, that you can even run locally if you wanted to.
Um, and they have missed that deadline. And there's not clear when they are gonna reach it. Now, I think they're gonna, I think they'll, they'll get there.
But since it was a, it was a court deadline, uh, there is, uh, legal provisions that that could come down. And the question is whether they'll ever really be able to provide the parody that they, that they have. There's, there's some question that the product they're actually delivering will make people wish they never asked for it in the first place.
So there, there's that whole, that whole issue that you get with be careful what you ask for, you might get it. Um, and so, uh, it's, it's a big brouhaha and it's just a test case because I, I we're gonna see, um, and for lack of a better word, you know, the balkanization of the, of the cloud, um, is, is, you know, is here, given that there's so many different regulatory regimes and requirements around it, cloud providers can't make everyone happy in every region of the world. Uh, and I think we're gonna, we're, this is just another argument for why you need to get really good at multi-cloud if you are a, uh, multinational organization, which more and more of all businesses are, uh, just to be able to, to meet all your requirements.
But in the meantime, Microsoft has its work cut out. They have not said when they're gonna meet the deadline, uh, and, uh, the court, the court deadline's like in two months, uh, and they're not expected to meet it. So it's gonna be interesting to watch, but I think it's just a test case.
We're gonna see more and more of these types of things happening. Yeah. I'm, I'm hearkening back to 2012 to 2016, and all of the folks who spent all that time deploying OpenStack and being extracted away from the cloud providers are saying, aha.
Aha. That's right. We have our moment, we have our moment in the sun because we're not dependent on Broadcom, Microsoft, but we see this across not just the cloud providers, but client computing as well.
My experience on my surface laptop is exceptionally different than my experience on my Dell SPS, the, uh, the fact that Microsoft just owns the bits and you get this vertical integration. We see a difference in quality. The hardware is, you know, spec for spec.
There's no question that my Dell SPS hardware is a better piece of hardware, but because of that integration, it gives Microsoft a competitive advantage. And I think we're seeing this in the public clouds. When you own the, when you own windows and you own the infrastructure, you can do things that other providers can't do.
And we see this practically, and Microsoft actually flaunts it as a sales, uh, as a sales, uh, advantage. But as the feature, uh, even though they're actually using kind of, uh, you know, not a level playing field to achieve it. Yeah.
Well, some people would. Eu I think it would be fair to say the EU calls any competitive. So yes, it's, it's not there.
You, it's, it's, it's, uh, it's, uh, interesting thing. I can get Windows cheaper. And Amazon is complaining about this, right?
It's not just the EU providers. Amazon has complaining that you can get an, uh, Oracle, that you can get Microsoft components cheaper on their cloud than you can on any other cloud. Just e EU ironically tends to jump on the courts and user regulatory power more.
So I think we're seeing, yeah, that's why EU is often a good test case. 'cause you'll see this soon, uh, in other markets as well. Yeah, exactly.
So, All right, we have some, uh, uh, CO reporting about AI attacks. Uh, the AI is attacking. What, what's going on there, Diane?
Uh, well, uh, Darktrace just released a report saying that, that, uh, CSOs are telling them, uh, the majority, the vast majority, 78% are saying that they're experiencing AI based attacks. And that's really no surprise. 'cause AI is uniquely, um, uh, positioned to give the, give lots and lots of assets to the bad guys in terms of, uh, finding vectors and, and, and then writing the code to take advantage of them and doing so in scale.
Um, there is a real tool set and all powerful tools cut both ways or benefits. And of course, the bad guys can use 'em as well. And the CISO say that we're seeing the bad guys clearly using these types of things.
They're seeing uptakes in the type, in the intensity of, you know, a variety of things that could, that is best explained by ai. Um, and, uh, the majority of those, those CISO also report that they don't know what they're gonna do about it. Um, and that's the, in my latest, um, CIO insight survey, the only two bright areas in the IT budget right now is cybersecurity and ai, which should be no surprise to anyone, but it's cybersecurity in particular.
And, um, the CIO can ask for any amount of money right now if it will help, uh, keep the company in business. And, uh, AI is gonna be a, is increasingly an actual threat to organizations. And I, I think that, that the industry's not ready to talk about it, but that's, we're seeing that in the data.
Yeah. We've, uh, I mean, one of the things I've been looking at is, um, the impact of AI and AI at AI attacks with state, local government and those, and, and the government agencies, um, going even beyond, you know, the, the other companies in that, those areas. And one of the things on the scene reported is that we have, um, we will call it a deep fake or whatever, but it's fakes on voices and people, the interpretation of somebody calling in and sounding like a, a boss, a senior official, um, using I've heard That.
I've worked to director meetings. I've heard that that's their biggest fear, actually. Exactly.
Right. And that's, that's pretty darn scary because you mean, I, you mean there's been times that, you know, for instance, like for wire transfers and that kind of thing, I've had some issue, you know, had some issues at my company, and the final test on that was the banker to call me and have us have a voice to voice conversation. And if voice to voice conversations, because they're talking about these AI modeling, can actually do interactive if that voice to voice conversation doesn't, you know, if I can't have a voice to voice conversation, what now?
Yes. How do I prove? And I remember, uh, when I was, I went from a fairly large organization, uh, SMBA, a medium sized business that got acquired by Deutsche Bank.
And when they were reviewing our security controls, and one of the security controls was around password resets. And the, uh, and the verification that we used locally was a, uh, was basically voice verification. Hey, this is Larry Thompson, I need my password reset.
And the bank auditors asked us, well, how do you know it's Larry Thompson because it's Larry on the phone? What do you mean? How do I know it's Larry Thompson?
Mm-hmm. I know Larry. And when you can, uh, social engineer that using AI and you know, and, and, and Diane, you're you're talking about like social engineering, I'm thinking of, I'm just coming outta click connect and I'm thinking about the Rich Lake houses, the rich vector databases.
With all of this data that we don't wanna put in the cloud, we've now centralized it and made what's essentially a honey pot for bad actors to say, wow, why I don't have to go throughout the organization to find the data is right here in your rag data pipeline. So I have been, uh, talking to a lot of people who are actually worried about how do they secure their AI pipeline and this whole other avenue of how do, how are bad actors using AI to, uh, infiltrate organizations is, is is an amazingly complex problem. Well, It, it is.
And, and you know, the data shows though that the only, the only threat that's really hard to secure against is insider threats, uh, social engineering, anything that requires people who already have access to be somehow tricked or compromised into giving access that they already have, handing it over. And, you know, I see, uh, all the, the AI video tools now have voice cloning so you can, you know, make the, make the AI puppet, have your voice or anyone else's voice. All these types of things.
Uh, and, and this is, this is real concern. I I, I predict right now that we're gonna see a public, uh, key private key encryption, just like we're seeing pass keys with passwords, uh, and the whole password, um, exchange. Now we're, we're now protecting the endpoints of password validation with public key, private key.
We're gonna have to have voice conversations where you, you should only really talk to somebody through an authenticated channel where you know that you're, you're, you know, talking to somebody who has control of that key. Uh, that's kind of the world we're heading to. And I don't know if the, if, if the user audience is ready to come up to that level of sophistication.
And that's why the bad guys are focusing on these, the weakest link in the chain, which is us, right? So, All right. So more, uh, new CIO survey data.
I love seeing the CIO data points. And, and Diana has had an internal opening, the fu room veil a little bit. We had this really great internal conversation about data quality and how important it is to understand when, when you're a research firm who you're surveying.
So I do wanna give a head tip to Diane and his CIO chats that he holds every Thursday. These are people that, uh, in a lot of cases, Diane knows personally, uh, from his CIO network. So, uh, Diane, tell us about the latest CIO data survey.
Well, like you say, these are mostly folks that we know. They're actually all handpicked by us, so we know, we, we know who they are, and they're representative of the, of the Fortune 500 and Global 2000, uh, although they're a little bit more advanced. So I use a, a slightly, uh, an audience that's slightly ahead so that everyone can see what they're about to be facing.
Uh, so if survey data looks in the past, it's not useful. If survey tells you about the data, tells you a little bit about the future, that's, that's useful. Um, and we we're seeing that AI maturity broadly, uh, moving away from experimentation to rollouts.
Uh, we'll go over this data, uh, in a, in an upcoming, um, episode. Uh, here, uh, we're seeing, as I mentioned, ai, uh, and cybersecurity are the two bright spots in the, in the, in the budget. Although, as I watched the survey, we had, the survey takes two months to do.
So as I watched the survey, as the new administration came in, I saw net responses going up this way and down this way, versus how much they're we're looking at cost cutting. Uh, but we're still seeing, people are a little bit worried about CIOs are conservative, and they were, uh, and they're worried about things then they were last year. Um, but I can tell you from the survey that they, they're, they're a little bit less worried towards the end there.
So we'll see what happens. Um, but, uh, budgets are, are definitely tighter unless you're in the cyber or AI team, in which case, uh, you probably are having easier time getting access to the funding that you need. Uh, and we see, um, still a lot of, I, I think a lot of decision making was made last year.
The data shows that, that deciding where your cloud workloads are gonna run was something that CIOs really focused on last year. And it's a little bit less this year. It seems like they've kind of settled that, but it's still very, the second highest reading we've ever had about, uh, CIOs are really rethinking where best to put cloud workloads with these always on workloads with AI and, and so on.
So, um, it's interesting. We'll, we'll preview the data here, uh, soon on, on the show. Looking forward to it.
Thank you. I am, I am almost the, the, those insights always, uh, quite surprising. You know, it goes through my more qualitative approach to research, and I'm always like, oh, okay.
It challenges some of my, uh, perceptions. So I'm looking forward to seeing the output of that, uh, last story from you, Diane. New major AI benefits to workers study, uh, and your analysis.
You, you, you posted a little something to XI Did, uh, and I alluded to that when, uh, um, Kimberly was talking about, uh, a AI and labor. Everyone's really trying to understand what's gonna happen. I'm, I'm seeing these increasingly bold pronounced pronouncements that will all be outta jobs in five years.
Uh, not just knowledge work, but physical workers as all the androids, uh, you know, uh, get up to speed. And I think my personal take is that, uh, you know, before we get into this study here is that, um, I'm on this, uh, uh, on the side where, uh, we always think in the short term, we overestimate the, the impact of technology, then we greatly underestimate the medium and long term impact. So, very big things are gonna happen because of ai, but they're not going to happen as fast as most people think.
It takes time. Uh, AI adoption is just not that fast. Um, we're still seeing the old machine learning budgets are still bigger than most of the AI budgets just because they're, you know, predictive maintenance and everything got so entrenched over five to 10 years of investment.
Um, it takes time for those giant ships to steer and money to be reflowed and the talent to be built up and the products to be built. So I do think we're gonna see very big impacts to the labor market. We see signs that it's happening and, and, but it's not happening that fast.
Uh, but we see it's happening. And so, uh, so who's getting the benefits though? The study that I, that we mentioned, it's from University of Copenhagen, um, and, uh, Chicago Booth, two researchers said, let's look at some, let's look at a lot of data, a lot of workers from a lot of companies, and see what they're experiencing in terms of productivity, time saved, um, creativity and things like that.
And they saw, uh, surprisingly small time gains. Uh, they, they did see time, time savings, um, uh, what they, uh, did see that was creativity, thinking outside the box, uh, more time with strategic thinking, the things that we would expect, we'd hoped to see with ai, that instead of spending all your time, you know, working down in the weeds, trying to get basics done, the AI could do that for you and offload you. But the real concern was, is the benefits seem to be going to the employers.
There is virtually no one reported that they were getting, uh, raises or, um, better wages due to their use of ai. Uh, all those, all those, uh, benefits we just, I just mentioned are all going to the wor to the employer just 'cause of the way we're structured. And employee saves money and finds a better way of doing something.
I mean, I've seen some companies, I remember working at Geico where they had a, if you come up with an idea, you would get 10% of that, that whatever the benefits of that idea for the first year, right? So, but most companies don't do that. And so it's just, we, we ha we're not designed for transformation or for encouraging workers to trans transform by incentivizing them in any way.
So it just, that's what the, that's the structural deficiencies and transformation we're trying to highlight with AI is that, you know, workers will will use it when it's convenient for them, but they're not, they don't have incentive to, uh, to use it as much as they could. And That's, that's a really interesting point about having the incentives for transformation, having the, uh, incentives for using and augmenting your role and being appreciated, um, and respected for picking up and running with it. Um, yeah, that, that's a really interesting to see what the HR people will start looking, thinking about here are, you know, leaders in, in the, in that space on how we do people management going forward.
Yeah. And I'm, uh, I think, uh, to that point, I'm coming out, you made the point about machine learning. I'm coming outta click connect and click, uh, has absolutely led the way, uh, when it comes to dashboards and taking, uh, enterprise data and using that to do some type of predictive machine learning.
It's kind of like their calling carbon, their claim to fame. And this year was the introduction of generative AI into some of their main products, such as click and answers, et cetera, which enhances that machine learning experience with natural language processing. So whether you're talking about that transformation, and, you know, a lot of my pushback or challenge to them is who's the buyer for this in our enterprise?
Like, these are silos. Who's, who's motivated or who's incentivized to take the leap from predictive, uh, maintenance, which are predict predictive, uh, learning to more of a, uh, generative AI agent based workflow who's incentivized to make that motion because it doesn't get a pat on a back or, or promotion for, uh, reducing the head count or labor costs associated with the manufacturing floor. So how do you get the, the innovation in front of the right people?
And it's, it is a significant challenge. And at least what I've, what I, from what I've experienced, This is this, yeah, the longstanding challenge of, of if, if, if it takes, uh, you know, uh, an army or it takes a village to, to change the organization, um, uh, time and again, management, uh, studies have shown that incentives matter, uh, using the top one or two in terms of, uh, how, how much buy-in you get, how much commitment, how much time spent, uh, how much initiative is given, all those sorts of things. So is this something, in fact, as we get faster and faster changing in our organizations, we need to rethink how we're, how we're doing that.
All right. We're gonna call off the last of the stories to preview the next, uh, next week's infrastructure matters. The week of this recording, the next week is a busy week.
Google io. Diane, I'm pretty sure you'll be ASAP Sapphire next week. No, I will not.
This, uh, this time around, I'll be watching it from a apart covering It. You'll be watching from afar, SAP SA Sapphire, uh, Dell Technologies World, uh, and it, uh, I think Microsoft, I wanna say Microsoft Ignite is next week as well. It is, it is going to be a busy week of announcements.
We're going to have our hands full or our brains full covering all of the announcements. Uh, the, uh, the, I I'm calling it now from Dell Tech World, Kimberly, you cover the storage announcements. I'll cover the AI announcements and we'll, we'll, we'll, we'll split the load that way.
I'll be at Dell Tech world, and I'll try and, uh, watch, uh, I'm trying to figure out how to fix some of the Google IO in my schedule. Uh, anything you folks watching outside of those, you know, four or five major events for next week. You know, I think that's enough if, uh, well, and I'll check on the Ignite one.
We, with what's going on there. So if that's happening. All right.
So if you, uh, if, if that's not a direct enough warning for you, what we're telling you each or Wheaties, get plenty of sleep because we are going to struggle to get through this show in a half an hour next week. But it is going to be a, uh, mountain of stuff Until then, uh, follow us online, whether you're talking about my Zero to Builder, uh, series, or Diane, CIO chat, or the work that Kimberly is doing, uh, the, somehow, if you haven't heard, Kimberly is retiring or in the, she's officially retired from rum. I've, I'm floating into other areas here.
We're Just, as I predicted, Kimberly is just as busy as she's been, uh, when she worked at rum. So, uh, she'll, she'll share kind of, uh, the, the research that she's doing independently and the organizations she's helping talk to you guys. Then Modern AI servers generate a lot of heat, but the industry is ready with revolutionary technologies like Immersion Cooling.
This episode of utilizing tech features Micah Jordan from Doug, discussing specialized server solutions with Janice Roski of Solid and myself, join us in learn how these servers are dissipating heat and becoming more reliable in the process. Welcome to Utilizing Tech, the podcast about emerging technology from Tech Field Day part of the Futurum Group. This season is presented by soy and focuses on AI at the edge and related technologies.
And today's episode is especially talking about AI at the Edge. As you will soon hear, I'm your host Steven FoST, organizer of the Tech Field Day event series, and joining me today from Soy as my co-host is the fabulous. Janice Roski, welcome to the show.
Thank you, Steven. It's great to be back. Appreciate that intro.
It's great to have you. Um, you know, this has been a lot of fun talking to various companies, and of course, uh, it's always fun to nerd out with the latest technology. And that's just what we're gonna do today.
We're talking some pretty cool cooling technology, aren't we? Very cool. This is gonna be literally and maybe figuratively the coolest episode we've done.
We'll see. Well, I guess with that introduction, uh, you know, let's, I guess let's dive in. Um, do you wanna introduce our guest today?
I would love to. I am, I am so excited about Micah Jordan, who is joining us from down under Geo. Micah, welcome to this program today.
Thank you. I appreciate the Doug Technologies and, uh, really excited to be here and chat a little bit about cooling. So you guys are doing something very, very cool.
Now, you're not just blowing a bunch of air at these things, you're cooling these servers in a special way. Tell us a little bit more about it. That's right.
I feel like I need to push my glasses up for this bit. Um, so I'm gonna geek out a little with you and tell you a little bit how immersion works. Um, we're using immersion cooling to, to cool all of your high performance compute GPUs, ai, right?
So your standard data center, the way it works, they have them in racks. Um, they're air cooled via crack crawl units, hot and cold aisles. We take those racks, lay 'em down on their back, um, and then fill them up kind of like a bathtub with a dielectric, dielectric hydrocarbon fluid.
Um, that fluid pulls the heat away from the servers and then, um, expresses it out via kind of like a car radiator. They're called fluid control modules, um, which then either pulls the heat out and expresses it with a chiller or, uh, idiomatic or dry cooler. So it's a much more efficient method of cooling your IT hardware and something we've been using for, uh, decades.
So we're talking a lot about, we just jumped right in and started talking about the cooling. Right. Um, but tell us Micah, a little bit more about the overall solution.
Obviously down under Geo creates some very fascinating technologies, um, but this one is, is very, very different in unique. So as you mentioned, lots of cooling capability, which is terrific. But tell us a little bit more about the overall container and what's inside.
Well, so a little background information. Um, Doug was built on a, a simple idea, um, find smarter ways to solve really tough geoscience problems, right? We're called down under geo because that's where we started, was in, uh, uh, geosciences.
So when we started back in 2003, we didn't really have a lot of money. Um, just a lot of really big ideas and, um, the drive to get things done. Um, so that meant we had to stay very agile, um, invent our own technologies, uh, from the ground up, including, um, very energy efficient and immersion cooling systems.
Uh, well, those technologies led us to create one of the largest and most efficient immersion cool data centers in the world at Skybox, just outside our US office in, in Houston, Texas. Um, so we've been running skybox now as an immersion cooling data center at scale for well over a decade. Um, yeah, and lemme tell you, the benefits have been pretty amazing from reduced water usage, um, to increased IT hardware lifespan.
Um, it's just been very surprising. So when we would show that location off to customers, they started telling us you should sell this. And that's what we did.
Uh, Doug Nomad is built on that idea of immersion cooling efficiency at the edge. Um, so you can put HPC AI anywhere you need it. Uh, it's where the data is born and processed, um, using our patented Doug cool technology.
So we're talking, I mean, the harshest uh, environments. I mean, you could put a Nomad 10 anywhere from Abu Dhabi to Anchorage. The, the benefit here, as you said, is that with immersion cooling, it's not just cooling like one spot or one component, it's cooling the entire system, right?
And, and so essentially, rather than, than having this sort of, you know, hot and cool and lots of fans and lots of air guides and all that kind of stuff, you're just pulling the heat out of the entire server. And that, I, I think that would lend the server to, to, to being more reliable and, and, and being able to be maybe turned up a little, uh, a little notch, right? That, that's exactly right.
Uh, a lot of the things you see nowadays is directed flow, uh, especially direct liquid cooling, um, to the hottest pieces of the IT hardware, right? Your CPUs, your GPUs, and absolutely those, those places need help. They need, uh, directed flow.
But the benefit of immersion here is that it covers everything, including the things that are starting to generate a lot more heat now and used to not. Um, plus you said it yourself, you remove your fans. Uh, there's no more vibration, there's no more dust settling in the, the, the IT hardware components.
And that's what I meant when I said we were surprised by some of the benefits. We're recognizing a lifespan increase of some of our IT hardware by two, three, even four times. Um, and that's, mind you overclock, that's running them hotter and stronger than they normally are run in an air cooled environment.
Um, so pretty surprising and, and remarkable benefits. So, you know, a a lot of of edge computing today is driven by mission critical workloads. Um, can you comment a little bit on how this, this device or this box is really being used for mission critical AI workloads at the edge?
Yeah, yeah. Uh, so we, like I said, we have been using our immersion cooling for our own products, you know, since 2003, right? Um, we geoscience data processing in our data hall in, in Katy, Texas.
Um, and we essentially take everything that we've learned, all the experience we've, we've gained from those inhouse and take that experience and put it inside our Nomad 10 and help our customers run their AI at the edge. Um, now mind you, we're building the infrastructure. We let the customers or clients, uh, run it how they want, right?
'cause it's gonna be different than, than a geo solution company is gonna run it. Um, but we can kind of handhold a lot of them through what that looks like in the infrastructure side, because we've been doing it. And, uh, you know, I, I imagine, yeah, geoscience, for what it's worth, I used to work in Houston for a geoscience company as well.
And so I know the demands that they've been placing on hardware for many, many years. But of course, AI frankly has taken this whole thing to another level. You know, I mean, it's just like with HPC technology, um, you know, what's happening in, in AI workloads especially at the edge, is, is pretty remarkable.
And this is one of those areas, I think, where people are starting to wake up and realize that they're gonna need not just a little compute, but a lot of compute all over the place because we're collecting more and more data everywhere. I think that, um, the, the container that you sort of, the, the containerized liquid cooled solution that you're, that you're suggesting, what is the scale of that thing? What kind of, of processing can be performed in one of these containers?
The, the space in the Nomad 10, we're, we're talking about 26 RU of space in one of our tanks, right? Um, essentially 56 kilowatts of it heat rejection. So we have a outstanding partnership with hypertech, um, via their Trident line where you can essentially put six of the, um, H 100, uh, Nvidia GPUs in a two RU space, right?
Um, you put 10 of those in one of our tanks, and what is that 60 GPUs in the, the space of a 10 foot container? That's quite a bit of, of workloads, right? When you compare that to a standard data center, uh, a rack running at 5, 10, 15 kilowatts per rack, it's night and day.
I mean, getting that level of power at the edge is unheard of. So that's, that's an interesting, gives me an interesting thought here. So who really is, uh, utilizing these types of systems, like what, um, what types of end customers do you see really gravitating toward this technology?
It's a great question. Um, without using any names, um, just talking kind of verticals, right? Uh, so obviously AI use cases, so, um, I, I think I mentioned it earlier just in conversations.
Um, uh, uh, an LLM company could build out their, uh, data centers somewhere remote because it's less expensive, and learn the LLM and then put some of our products at the edge where their end users are, say San Francisco, they could put five of our nomad tens so that the latency is not nearly as, as, uh, intense as it would be if it was in the middle of South Dakota, right? So LLM companies are really interesting, uh, uh, fits for this. But some of the, the less, um, obvious ones that kind of surprised some of us would be things like cloud gaming, um, where latency is absolutely imperative.
Um, putting that at the edge, uh, precision agriculture. So gathering a bunch of data around your crops and your livestock, processing it at the edge and making decisions same day, um, without having to, you know, run all your fields. That's a pretty exciting, uh, option, right?
Um, defense, uh, contracts and being able to deploy something like this, which can deploy in three months in the middle of Abu Dhabi, or, well, let's say a more remote location, that's something that not a lot of people cannot offer, right? Yeah. The desert somewhere.
Yeah. There you go. Yeah.
Thank you. Yes. Um, and I mean, there's others, like, mining is a big interesting, uh, fit oil and gas and energy.
Uh, you know, I, I usually don't do this, but I have a question for you, Janice. Um, yes. So theoretically, you know, maybe not specifically soy, but you know, component suppliers, when somebody like Doug comes to them and says, Hey, we're gonna be taking this server and immersing it in this special liquid for cooling, um, how does a component supplier react to that and what's their, um, well, I mean, I imagine that you react by saying, cool, fun technology challenge, let's make this happen, but what does that mean for component suppliers and, and, and, and, and how do you build and modify your products to be used in a, in an environment like this?
Yeah, yeah. Um, it's a great question. And there's a lot of, uh, you know, SSD suppliers out there kind of looking at okay, the overall solution, right?
The GPUs are running really hot a lot of times, um, the overall system. Um, you've got fans to cool those things, but you don't always look at how do you cool the SSD, right? And so our company is, um, really big and bullish on this.
They're going out and figuring out how do we liquid cool our SSDs in a number of ways. Uh, the diabolic cooling that, uh, Mike is talking about is a little bit unique for us as well. When we started working with Hypertech and now working with, um, down under Geo, it was an opportunity for us to say, Hey, how can we dip these into the, the cooling solution?
And the worst thing that happened at first was I think the label fell off. Um, but so we had to get, uh, get that put back on. But at the end of the day, I think our team's really always on the cusp of innovation.
And we take this very seriously as an opportunity. We know energy and edge is a, a growing market, and we see this as an opportunity to, to, to take a different look at how our SSDs work. So our team is continuous, uh, continuously innovating with, um, companies like down under Geo and Hypertech to make these solutions real, and honestly don't know of any others really leaning into it, but we're kind of fearless.
That's all I'm when it comes to these things. Yeah. Micah, I mean, kind of the same question back to you too.
So we just heard, you know, what do you, what has been your experience in working with customers? 'cause there are so many varied components in these systems. Um, you know, how, how do your suppliers react and, and what have they needed to do to make their products ready for a a, an immersion cooling environment?
Well, the easy answer to this question is, uh, talk to hypertech, uh, or, uh, an IT hardware provider who has already done this work for you, right? Um, because they've built servers from the ground up for immersion. Um, now to be clear, we are totally IT hardware agnostic.
So it doesn't matter whether you're buying Dell, Lenovo, HPE, hypertech to CRSI, what have you, right? It all works in ours, and we know this because we've done a lot of them in our own, uh, data centers, right? Um, but some of the steps that what Hypertech takes, um, and uh, say Dell through unicom takes is they remove the fans first off.
Um, they remove the, um, thermal paste on the processors and replace it with indium foil. And then some of the cables that connect, different things need to be replaced if they have PVC in the casing, uh, because that PVC does break down in, uh, some of the dielectric fluids. Um, and it'll just get really brittle.
So yeah, those are kind of some of the steps. And then I think, uh, bios, you, you need to go into the bios and say like, Hey, don't freak out. You don't have a fan running.
Right? I imagine you would. 'cause I think most of these servers would be like, ah, don't Man.
Yeah, exactly. I know what's happening. Um, so it's definitely, we're, we're in the stage, but literally the cutting edge of, of moving, um, shifting this, this entire industry towards a more efficient means of heat rejection because air just can't keep up with what's being put out by the likes of Nvidia a MD and Intel.
So, so Micah, where, I mean, I'm gonna take it back for a second because I'm just really interested in the use cases. I kind of keep coming back to this, but what's the most interesting place that you guys have deployed this? Can you share that?
So, one that has been really exciting, uh, for me is an, an area that's close to a coast, um, in a very hot, arid environment, right? That has been historically one of the hardest places, uh, to cool your data centers, right? Um, and so think about like Iceland would be perfect if you could have all your data centers in Iceland and you just open the doors and everything is cooled with the environment right?
Now, imagine, uh, putting it in, you know, the middle of a, a desert that's right on the coast, so you've got really humid air, you have very hot temperatures that don't really get below 70 degrees, right? Uh, those two things, I mean, you're just kind of stuck. Whatcha gonna do?
How are you gonna build the data center that if you want low latency? That's an example of one of our, I mean, our Nomad 10 is running in that environment today and performing spectacularly. It's really exciting to talk about some of that stuff.
I wish I had a little bit more, uh, meat to say like names and, and locations. But, um, that's always been really fun to, to point to, um, and, and say with confidence too, you know, because we're doing it. So how do You power all this if you're dropping it into a remote location like that though?
Yeah, yeah. Uh, so there's a lot of ways, um, if you wanna be entirely green, there are some companies who have, uh, very remote deployable, um, solar, uh, setups that kind of fold up into like a 40 foot container shaped thing. You also have like a portable wind.
Uh, those are really green solutions. Um, you also have, I mean, generators, uh, you can put a generator out and run that, uh, anywhere. And then some of them, like the example of running five in, uh, uh, San Francisco just run power and networking directly to the nomad, right?
Um, and it's powered. All we really need is level ground. And of course, um, you know, it's not enough just to pull the heat away from the servers.
You have to dissipate the heat as well. So you got me thinking when you're talking about that hot humid coastline, uh, how are you dissipating the heat from the container itself? Depends on the, the, the mechanical method by which we're heat rejecting, right?
If we were in a, a nomad 40, which uses either idiomatic or dry cooling, it expresses the heat based on your, um, dry and weed temp. We kind of tailor the, the, um, chiller or the cooler based on where it's going. But the nomad 10 uses a, a chiller, which is refrigerant, right?
Um, not as efficient but deployable anywhere no matter the, the environment. And that's what we're using in that, uh, example I gave. Yeah.
So, so be, because that's a, a pretty proven technology. The challenge is getting that cool, that cool down to the component level, uh, not being able to dissipate the, the, that amount of, of heat. Well, I mean the fluid, just basic physics fluid is a much better method of heat rejection than air is, right?
You think about jumping into a 70 swimming pool pool and standing out in a 70 degree temperature air, one of those is much cooler, and that's because it's pulling your body heat away a lot more efficiently. It's the exact same method that we're using here, right? Just a little bit hotter, uh, and um, more consistently.
And of course it's not water, it's a specialized, Right? Yeah. Right.
That's valid. Actually, I'm glad you said that. Uh, I do kind of wanna talk about the fluid a little bit.
That's one thing that we are also agnostic on. Uh, doesn't matter what dielectric hydrocarbon fluid you use, we, um, it all works in our system. Um, but some of the similar properties they all have would be, um, so dielectric, so they tend to have flashpoint, um, upwards of two 50 C.
Um, I've seen some as low as 150 C. Um, they are all biodegradable. They break down their, um, base carbon, their, their, uh, carbon, they're, they're, uh, carbon based, um, components within 30 days in the environment.
So if there is some sort of a spill, it's not something you have to, it's not like an oil spill. Uh, this is a, a completely different type of fluid. In fact, when we are transporting it, it's considered a food grade lubricant, um, during transportation.
Um, so it's non-toxic. I've actually tasted it doesn't taste good, but it's edible. Um, and, uh, I think actually I've heard that there's talk about a, a peanut butter and jelly flavored one.
So We, we don't want that. We do not, do not want to be drinking our peanut peanut butter and jelly hydro Marvins out of our data center. Um, I dunno, Steven, I think I would try it.
You wouldn't try it. No, I would try it. It's funny though because, you know, you go to these h HPC shows and you see companies like yours on display and right next to them are some of the big names in industrial chemicals.
And, um, you know, you know, and, and, and, and I think people are scratching their heads like, why is, why is the company that I buy gasoline from at the, you know, supercomputing show and this is the answer, right? Yep, That's right. That's exactly right.
These fluids that are being produced by them are pretty remarkable. And mind you, they have been around for decades. This, some of this fluid, similar fluids are used in your transformers, and they're right around you right now.
Um, they're the same types of dielectric fluid used there. Um, they're tailored a bit more for the, uh, data center market, um, and made specific, but they're not anything new and cutting edge in that respect. They're tried and true and, uh, it's perfect for this use case.
Yeah. 'cause we've been seeing, uh, immersion cooling in computing in high performance computing and specialized approaches for a long time. I guess just sort of to sum up, I mean this, the interesting thing here is that you're taking this tried and true technology, but that you're deploying it specifically for challenging applications and specifically at the edge, which again, I think a lot of people might say, whoa, whoa, whoa, you're taking this stuff out into the, into these challenging environments.
But in many ways, these, these things are better at these edge than conventional solutions, right? That's exactly right. I mean, think about your, your entire infrastructure is insulated by this fluid, right?
There's no more dust concerns. Uh, there's no vibrations. It's lasting longer.
Um, and this is expensive hardware. This is the kind of stuff you wanna protect, and that's what this does. Exactly.
So even though it might be a little scary to people to think about, um, you know, it's not like you're dipping your server in water. It's, it's a proven technology. And, uh, yeah, I I think that the fact that it's insulated from shocks, uh, thermal shocks, physical shocks and so on, I think is a, is another thing that people might not consider, but that could be pretty valuable.
Well, it, it's incredible stuff. Um, will we see you at some of these, uh, future shows? Where can we get our, I i, I don't wanna say get our hands on it because frankly I don't wanna stick my hands in there, but Well, You can.
I mean, you have the softest hands in the data center world. Uh, it's really good, good fluid. I know I do.
So where are we gonna see you? Yeah, where, where can we run into this, uh, solution? So you can actually come and see the Nomad 10, uh, fully kitted out, um, at the YADA conference in a few months in Vegas.
I think it's September 8th. Um, we'll have our Nomad 10 there showing it off in a booth. Um, and our CIO will be speaking at that, uh, conference as well.
So, um, really interesting conference created by, uh, some of the creators of, uh, data Center Dynamics. Think George Rocket is his name. So come check us out there in Vegas in September.
And of course, Vegas in September is a hot environment that you could deploy one of these things. It Is, absolutely. Yeah, it most certainly is.
How about you, Janice? I mean, we'll be all over. Where are we gonna see us next?
Yes. Uh, well you might see us at the YADA conference as well, you know, but certainly, uh, Dell Technologies world, um, we'll be at, uh, flash Memory Summit will be at the open compute, uh, summit as well. So we'll be in a lot of places.
We go everywhere, but we might, we might show up with, uh, Micah and his and his team in a couple more occasions, so stay tuned. Maybe not quite ready to announce anything, but it would be very fun to be able to get, uh, I'd love to get the Tech Field Day delegates hands on some of this stuff too. So Micah, we will make sure that we do that at some point in the next, uh, little bit here because it's just neat.
It's just very cool stuff and I really appreciate having you on the show. Yeah, I appreciate you guys, uh, uh, letting me join and talk a little bit about this really cool tech. Thanks for listening to this episode of Utilizing Tech.
Uh, if you can, uh, if you enjoyed this, uh, you can find this, uh, podcast in your favorite, I'm gonna just redo that 'cause I stumbled twice. Here we go. Well, thank you very much for joining us and thank you everyone for listening to this episode of Utilizing Tech.
You can find this podcast in your favorite podcast application as well as on YouTube. If you enjoyed the discussion, please leave us a rating. Please leave us a review and, uh, maybe provide a comment too.
We'd love to hear from you. This podcast was brought to you by Soy as well as Tech Field Day, part of the Futurum Group. com, or find us on X Twitter, blue sky, and Mastodon as utilizing tech.
Thanks for listening, and we will catch you next week.