Techstrong TV – May 7, 2025
Watch our live stream on Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone. Have you ever wondered how IBM can start a technology and then have to always be playing catch up? You're watching Text On Gang.
Hi everyone, it's Alan Shimel, and happy Wednesday to you. We've got some great stories here on Textron Gang today. As usual, there's a fair amount of ai, a little bit of open source, some intrigue, palace politics, and a bunch more.
We've got a great gang to bring it to you. Let me introduce you to them and we could dig right in. So first of all, he's, he's not up in Silicon Valley.
He's out in, uh, Las Vegas land to, in fabulous Las Vegas, as they say. He's our, uh, uh, Silicon Valley editor, John Schwartz. Hey, John.
How are you? I'm good. I'm good.
It's, it was pouring yesterday. Uh, we had a little bit of delay, but, uh, on our way in. But I'm looking forward to the, uh, ServiceNow Knowledge Conference this week.
Oh, very cool. Yeah, it's a good conference. Yeah.
Well, good. Yeah, we'll be looking for some good reports from there. Enjoy moving from Vegas to San Angelo, Texas, the data center capital of the world, or soon to be soon in the Tech Concho Valley, I think it's called.
She's our own editor, Amanda Ani. Hey, Amanda, how are you? Hello.
Good. I'm pushing it for it to be, we're getting a lot of tech companies here. All righty.
Then moving up. She's Futurum vp, uh, analyst, Mitch Ashley. Hey Mitchell.
How are you? Good. I've returned to the, uh, guitar background, so yes, I see that.
And they are real. One of these days we're gonna have to have you open up the show playing the guitar because I've had people ask me, does he really play those guitars? Are they just for show?
They're they're a collection. No, I don't know how to play guitar. No.
I've been playing guitar a long time. Happy to be careful what you ask for, Alan. Absolutely.
And then moving from Mitchell over to, uh, Harrison, New York. He's our chief content Officer actually on his way down what to the DC area today, right, Mike For Nutanix? Yep.
Yep. Uh, chief Content Officer, Mike Ard. Hey, Mike.
Hey, hey. It's raining here in New York and our prayers are answered 'cause the Yankees are struggling. So we're hoping for a rain out.
Pray for, what was it, Warren, someone else. And Pray for Rain is an old story. I think it was the Braves Orange spawn was a spawn.
And, uh, Johnny saying, and Rain spawn and insane and pray for rain. That's it. What a, I love being surrounded by some baseball people like this.
I thank you. Um, so Mike, I I, I teased it coming out. IBM is making a habit.
I mean, quite frankly, they should have been owning the ai, you know, they were doing Watson commercials when I was a kid, it seems like. Um, and here they are now they're making a major agentic AI push. But it feels very to me.
Anyway, I'm, I'm interested in your take and of course John and Mitchell's take it seems very me too ish. It seems very catchup ish. Why aren't they dealing from a leadership position?
Mike? What, what's the story here? Well, I'll just give you the good and the bad of it.
It's, the good of it is they are actually putting together an orchestration framework around Watson X for integrating and managing all of these AI agents that are out there. And they now have 150 partners and they're making a case that says, you know, what matters here with Agen AI is access to enterprise data. And they are going to be the ones in a best position to provide that level of integration.
The downside of it, and I'm gonna pass it to Mitch in a minute after this, is that, you know, it's, uh, hodgepodge of other stuff. They bought web methods last year. They got, um, data bricks, I think as a data lake kind of platform.
And they're once again, stitching it together in a way that you could say was a consultant's dream, which is not necessarily what it people are gonna love. So, Mitch, I mean, you would follow this, but what's your take? Well, you know, we, we've all Watson has taken on many lives, right?
And now of course, uh, being kind of the center of ai, or at least it has been, this is a pretty comprehensive announcement and, and I understand kind of the hodgepodge of it 'cause there are some sort of things thrown in, right? They also did a Linux one five, a distribution update for the, uh, C 70 mainframe that runs, that has the, uh, AI processing that tell 'em two processors. But I think what, what I take from this is whether they're late to the game or not, you know, the every, every day, every week, it's hard to even write analyst papers about this.
'cause there's news every day. You, you have to go back and update what you're writing. They have a pretty comprehensive approach.
And why I say that is they're not just introducing an agent capability, they're also including a framework called Orchestrate. Uh, they're also including an agent catalog for, uh, both agents that they built as well as third parties. And, and you mentioned the data lake, uh, from a company that they bought that you also mentioned the web methods.
You know, those are sort of the things kind of thrown in, um, if you will. But I think that's also, well, if you aren't gonna include those as part of your AI strategy, where do they fit? So they're including it.
Um, they also threw in a lot of, I say throw in. They also announced a lot of, uh, integrations with enterprise applications and enterprise services from Adobe AWS, Microsoft. You, the, the, the notable ones, you know, serves an hour workday folks.
So they're making a play to say, you know, you're still a safe bet working with IBM, we're your enterprise partner. And, uh, as you said, the integrators, the consultants, the people who up put, put these things together, now they've got a full tool chest, if you will, to go help customers. So now again, not all of this is available.
Now, some of it is in preview, like the agent catalog, but, um, I thought it was also interesting, you know, you had a really good article out on, uh, tech Strong AI about this. CEO Arvin, uh, Kirschner made a statement about it. I, AI is still being invested in, but only 25% of AI initiatives have achieved in ROI.
This is the year AI is, you know, people are looking for some return that it's gonna be worth doing. Um, and so I think it's interesting that, that he brought that up. I think sometimes it's helpful to be later to the game, as y'all say, because they can look and see what's working, what's not working, what problems do users have and come out with a better solution because they waited.
All right. Third mover advantage, right? So, but this is so quintessentially IBM ish, right?
So look, they had this Watson, and it's now called Watson XI, I remember going to IBM conferences literally 10 plus years ago. And seeing Watson, right? And some of the cool things Watson was doing with dating apps and all kinds of things they were building with it.
And then AI explodes on the world. No one thinks of AI of IBM as an AI leader per se, but yet they're IBM just, you know, they have 500 of the Fortune 500 is as they probably have 600 of the Fortune 500 as customers. You know, they have an account rep for every one of those, and they get it in there.
They're great at building ecosystems, they're great at bringing their partners in so they can stitch together this comprehensive soup to nuts kind of offering that. But sometimes when you look under the covers, you could still see the, the threads, the stitches that stitching it all together. And they're not so tight.
It's almost like we don't wanna be the first ones to market. We want to, we wanna come in with the, the big blue solution here that, you know, is, is this big and is is everything, right? And, and there's going to be a portion of the market that loves that, right?
Their, their base customer base loves that. But there's also a portion of the market that says, you know, look up overhead dinosaur, that meteorite might just, meteor might just fall on your head. And, am I getting the cutting edge?
Yeah. Ai, I'm sorry, John, right? AI was all about speed and about getting to market and about and, and, oh no, that's okay.
AI is about getting to market and hitting people over the head with all these different announcements. And the only time I've really seen IBM's name associated with AI was as a partner of all these other companies that jumped the line or moved faster than IIBM The one thing, and Mike is I think totally right, is about this consultant's dream. When you stitch together so many different parts, it makes me think of somebody who's like building a crib and there's like hundreds of parts and they're supposed to figure it out.
You usually bring somebody from the outside in to determine it. And I think that that kind of hurts. IBMI also think the fact that they, they had this legacy, they had to jump on everyone and they kind of let it slip away.
I mean, maybe they catch up and, you know, they're a safe bet, so they have a lot of huge customers who will be, feel safe and secure doing this. But I, I just think they could have done more. But, you know, we'll see this, this, this whole race is so predicated on hype and on reality and ROI is Mike Rhodes.
Um, maybe that helps him in the long run. So it was interesting to me that one of the things they called down the press conference was that they have increased r and d investment, I think it was by 40 or 50% or something like that over the last four years. Which, but the issue in my mind, and, and the example of this is that for all that investment, they seem a little slow and they keep being usurped by somebody who comes along who's moving just a little bit faster, for example.
And traffic has this model context protocol out. Well, you know, IBM has been working on the equivalent of that for a while, and then late last month turned around and donated that to the Linux Foundation. Now whether that was because CP is becoming a Deto standard, or they're trying to build a community as an alternative remains to be seen, but, um, I think most people didn't even know that IBM had such a thing in place.
And so now, you know, something is amiss with their execution, is all I can say. So, so I'm, I'm, I'm gonna disagree with you all on this, and here's my point of view on it. I, I'm, I'm pulling in Alan, I'm, I'm gonna disagree with the panel.
Is, is, uh, I don't, I don't think it's possible for IBM to keep up with an anthropic or a cursor or all these companies in the, I mean, innovation's just happening so fast. And maybe they'll have some areas where they do do carve out, you know, some places where they get ahead. But when you're dealing with, you know, the 600 companies of the Fortune 500, as you said, Alan, those people don't implement PO point solutions.
They implement solutions at scale that have to integrate across multiple systems, um, multiple geographical locations. It, it is a big effort to put things in. So I haven't looked at their solutions and, and say, and to say, are they enterprise grade necessarily?
But I gotta believe that that's an approach might that, that IBM has to take that the others don't. Philanthropic can can, can play in, in much different ponds and doesn't have to always deal with the very large, uh, companies and at scale, because they don't have an embedded base to deal with, they also can deal down mid and down market. So I, you know, let me be snarky for a minute.
They could be Apple that's behind. So there you go. That's my point of view.
Yeah, apple can get away with being late too. It is one, as IBM dos, you look at all these companies that are filling the gaps in all these different, uh, vertical applications or what, what have you, just sp specific types of agents. And by the time IBM gets it together and their customers understand how it all to put it all together, they may have been diverted to, to a better solution that was, came out faster.
I mean, again, it's all based on speed and I just, IBM just moves slowly. That's just the way they are. But, but here's Mitch, did you just call, I wanna clarify a point, Mitch, did you just call IBM the apple of ai?
Is that how you went with It? No, I was saying a Apple is even later to the game than IBM That was My point. They can get away with it though.
I mean, they're like, they're polling and surveys that are just consistently show that people are wi willing because of all else, because it's only because it's Apple. They're just willing to yeah, to wait to wait, you know, and No, let me to be so, but here's the paradox of this. Apple didn't invent ai.
Apple didn't have an AI product out there when they had Newton, uh, Dell didn't IBM invest a ton of money in pure research, pure science. And as a result, they make breakthroughs, whether it's in ai, what they did with Watson or Quantum computing, they owned the whole quantum computing thing. Now you're starting to see all these quantum companies pop up and they're gonna run circles around it a bit.
Um, think back to the, remember the IBM, what was it? The I-B-M-P-C processor, it was really sort of an early sort of risk-based processor. You know, ARM did pretty well with those.
IBM got out of the processor business basically, right? So their MO is, they spend billions and of, and a lot of time those billions are well spent in basic research that come up with groundbreaking, inventing new technologies, and then they sort of abdicate that leading horse spot and let this whole industry grow up around it. And then they'll jump back in because they don't like to be first, they don't like to, to do it, I guess.
And then they jump in a little late and play catch up. Now, apple and Dell specifically, they have very different philosophies. Apple and D are sort of the old bull and the young bull at the top of the hill, remember that story?
They're not looking to race down there and be the first one down. They don't like to jump into a market until the market is well established, it's multi-billion dollars, and that they have a plan that's gonna capture a substantial share. They're not gonna jump into a market prematurely, and they're not gonna jump into a market that they don't feel they can carve out a substantial share.
And that's their philosophy. And right, wrong or indifferent, it served them well. Um, I think that has been their philosophy in Apple, Alan, until ai, they were late to announce, and then they overpromised and underdelivered and you know, as you said, you know, apple's not gonna be the first to necessarily introduce something, but when they do it, it's done well.
That that hasn't been the case on ai. I think to your point on IBM, what IBM has done in the past is they may not necessarily invent something. They didn't invent invent SQL databases, but they legitimized it when DB two came out, right?
'cause I remember people were like, nah, nah, you would never do relational what IBM has a a relational product. They do that kind of thing. Whether they'll do that in ai, I don't necessarily know.
They're a much different company now, but I don't, I don't look to IBM to lead in every category in ai. I think they're better off, they're a services and product company. They're better off serving customers of implementing successful AI projects with an ROI as opposed to leading with the next flashy squirrel.
Yeah, to Mitch's point, they're kind of counting on the fact that AI is hard and a lot of organizations that are going down the path are gonna stumble because it takes a lot of coordination between different departments to make this work. And eventually somebody in that organization's gonna go, Hey, we're being left behind. Let's just call one 800 IBM.
Well, like Mitch pointed out that 25% of people aren't seeing the return on investment. So, um, IBM spoke to that in this article, and they think that their solution will. So, And the deployment has also been slow among enterprises, right?
In terms of, uh, governance compliance, just try and piece it together. There's been a hesi hesitancy and a fear of getting it wrong. So things aren't being deployed as quickly.
So maybe IBM benefits kind of in a small, in a small way from that, I would look to who IBM's gonna buy next. I think that's where they had, you know, big companies don't often innovate themselves. They buy or they innovate through acquisition.
Cisco does that. A lot of companies do. Fair.
Hey, we gotta take a break and come back for our next segment, our friends at Redis. You know, the old saying, you can hammer a pair of pants, but if you make it too short, you can't make it longer. Again, once you leave open source, can you go back?
We're gonna discuss that you're watching Textron Gang. All right, folks, we're back and we're moving on to Redis. And they say, you can never go home again.
But here comes Redis trying to be an open source company one more time, because they kinda led the charge with moving away from open source, uh, when there was a lot of, uh, investors were unhappy with the returns that were being generated for these companies. And yet that led to a lot of forks of Redis, and a lot of people jumped on those forks. And we've seen this play out before in open source environments.
But Alan, let's start with you. I know you tracked this whole area pretty closely. Can you go back once you've left the farm?
Sure, you can. All you gotta do is put on a pair of Ruby slippers and click your heels three times. It's no place like home.
There's no place like home. Um, look, first of all, I'll give credit to Redis. It sometimes it takes a big database company to admit you made a mistake and a mistake was made.
Um, you know, the, the, the, the open source world can be forgiving though, right? If, and, and the beauty of it, back to my analogy with the hemming of the pants, is if you had something that's open sourced, right? It stays open sourced, then you come out with a new version that's no longer open sourced, that new version, everything from that point forward is not open.
But then at some point here, you open it back up. Well, assuming you still own the IP for that non-open source stuff, you could open it up and it's like nothing ever happened, right? And, um, so I think in this case, it's a relatively easy thing.
But here's the real question. Will the community trust them that they don't pull this again? Or have they already moved over to the forks in their comfortable with them, or, you know, burn me once, shame on you, burn me twice, shame on me, and I'm not gonna give you a chance to burn me twice.
And so I think red is in addition to just returning to this open source model, you know, needs to do a confessional, a couple Hail Marys and whatever. Mike's smiling, he remembers those. Um, you know, Forgive me father, it's been six months since my last open source confession.
Yeah, Well act, so actually it's been 2020 since the last confession for Redis, because that's when, uh, Salvato spo, I think is his name is, you know, who was the original developer of Redis. He came back, he left in 2020. He's come back.
And that's a lot of what they're crediting for, why they're returning to their open source route. So maybe some holy water and some Hail Marys, you know, with him, him on board. Well, I mean, and, and he may be the personality they need for that community to, to embrace them.
It's got the credibility, right? It's got the credibility, right? That's the credibility, because that's going to be the issue.
I mean, changing the license here and going back to an open source license is a relatively trivial thing for them. Um, regaining the respect and, and commitment from the, and trust of the community is gonna be the hard thing. But I I will also say, you know, nature pours a vacuum, and there have been competitors that have popped up in the open source space there.
And it's gonna be interesting to see if just moving back to open source is enough to put Redis at the top of the hill again, Or they could know there's a path down the middle. They could support Velcade and their own open source core database as two separate forks that are, then they're delivering a bunch enterprise services on top of that and extensions. And whether you're running Valki or Redis Open source, maybe they don't care.
I was reading this article, um, and what you were talking about Valki, how they created that. And I was thinking that it just shows the, um, the stronghold open source has, and kind of the power I guess, that developers have when it comes to breaking away from open source. I look what they may wanna do with the, you know, with the founder back and everything is try to merge it back in, into, into Redis.
'cause having two versions of, of in essence the same thing, right? I gotta believe Salvador's got some pretty strong Yeah. He'll, he'll get them.
I think you're gonna see that merge back in, because over time they just separate more and more and it becomes harder to, all right, so reconcile, So then donate the two of them to your favorite consortium du jour, and then have the consortium pull 'em all together. You could do that too. Some consortiums don't like to pull it together.
They, you know, they like to see how many projects they're managing. Just saying, just saying. Um, but look, I, I think this is a good thing for the community and for the user base.
Um, I don't, I don't think Greta will have a disruption in innovation or anything like that. Um, if anything, maybe it'll be more innovative. So I, I actually think it's one of the, maybe the few credible ways of coming back to open source, having the original creator, author.
I mean, it seems to me you've got, you know, provided that person's, you know, got a good, still got a good reputation in the community, I assume so they can help, they, they can help pull it back. 'cause that's who put, you know, it's like Linus, right? Putting trust in Linux and all of that.
So, yeah, no, I, I, I agree a hundred percent Marty. Sure. Right.
You know, but we'll see. Let, let's see how, you know, how the community embraces them and do we see a emerge of, of the forks and so forth. But it's a great open source story, right?
It's part of what makes open source great. So I say congrats to Redis. Good luck.
Fair. All right, let's take a quick break and come back here with our next block. Who would've thought AI is biased in its hiring?
You're watching Text Drug Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back in. This is a subject of a lot of interest these days.
'cause well, folks are looking for work in all kinds of fields, and there's always been this perception that somehow or other, uh, the process has been biased. And John has a story now on, uh, tech Strong a talking about how, well, I guess if you look at it, the data and the process processes used to train the AI model, to apply it to HR seems to be favoring men. And I guess, John, let me ask you this.
Is that the fault of the model or is it the fault of the processes and the data you use to train the model, which are clearly biased to begin with? Yeah, it's probably a combination of, probably a combination of both. But what's disturbing to me is that there are more, uh, AI hiring, uh, models being used within organizations.
In other words, when they wanna winnow down a number of candidates and then recommend a, a handful to a person in the process, it's, especially for high paying jobs, it is shifting decidedly towards males. Uh, given this test of, uh, open source AI models, that was done by a couple professors. The title of the paper was called Who Gets the Callback Generative AI and Gender Bias.
So they basically looked at, uh, job candidates and they analyzed mid-sized open source large language models for signs of gender bias and hiring recommendations. They looked at a more than, uh, 330,000 English language jobs, job ads from, uh, India's National Career Services online portal. And they sized up various models.
And what they found with the models, with supplied, with job descriptions and asked to choose between two equally qualified male and female candidates, the callback rates for females was significantly lower. And according to the professors, and I'm quoting them, these biases stem from entrenched gender patterns in the training data as well as from agreeableness bias induced during the reinforcement learning from human feedback stage. So, in other words, Mike, the first two things that you mentioned, those two factors weigh heavily in this.
And I don't know how you address something like this, but it doesn't surprise me in the least. And, and the other thing that's interesting to me is that while this is happening, the Atlantic did a survey. It is a study of college graduates and the unemployment rate, and it's up to 6%, which is significantly high.
And AI is playing a part in that, not just in terms of taking jobs or low level jobs, but I think, um, in the hiring process, it's, it's skewing dramatically towards, towards men. So the job market, if it wasn't already difficult enough because of the, of the, uh, prospect of competing with ai, it's not being helped by the AI hiring process. That's in effect a lot of companies, Well, first of all, I'm glad this is being pointed out, but my reaction to it is, duh, we can't fix the biases in our human processes of hiring people.
Why would we believe that AI would be suddenly better of it? Maybe it's the hype of ai, but to the, to your point, John, it's all it's trained on the data. Guess what's in the data, you know, the information that the models are trained on, unless you take explicit measures and change the weights to try to try to change that model.
Yeah, of course it is. Not that it's a good thing, but, okay, let's address it now. Yeah, that was my Thought too.
Like, well, the data being used to train would be representative of that because, um, men still do overall tend to have the higher paying jobs from a percentage standpoint. So if that's the data you have to train AI on, The question is, do we fix the models or do we fix HR first? Well, this has been broken forever, right?
In my mind, we've been playing, you know, keyword bingo on resumes forever, and running them through these HR apps to kind of find somebody who's quote unquote qualified. I also think that a lot of the people who are doing the hiring kind of, you know, they kind of tangentially work with HR and they go out and post a job. But most of the people I know who hire folks, they are people they already know.
So they build their own little network, and they're not kinda, um, shall we say, very serious about what HR might bring in the door. It's not what you know, who, you know. Well, I mean, I, I'm gonna, I admit, I, I benefited from that.
And, and I, one, the one thing that I was, I, I was hoping that they might even look at these males and they tend to be probably whites. Maybe that's gonna be a follow up, but it just, it's just the same old, same old. And, uh, it's, my fear is that as these companies and hr HR departments in particular depend more on AI for hiring, is this gonna maybe even exacerbate the problem?
So in my best MAGA voice, this is DEI, nonsense. Move along. I was gonna say de I was gonna say that, but I was waiting for you to say it, Alan.
It, it's so true, though. You're gonna defund it. Alan defund it.
Not only that, I'm, I've asked the Justice Department to look into it investigate, Right? Mm-hmm. If we, if We, I'm gonna see a truth, If we stop testing, it'll go away, right?
Right. Yeah, exactly. It didn't exist.
I'm gonna say, I know a lot of people really struggling to find work, and it's come to a point where people are trying to use chat, GPT or other forms of AI tools to figure out how can they break through the AI filtering process. What's gonna be the key words the AI picks up that's gonna get theirs ahead of the thousands of other applications Or power to 'em, weaponize AI to either A lot of them. Yeah.
And, and a lot of people are using AI to write their resume, resume letters now, a Lot, most people, So they all, they all tend to be the same. So Most People are. Yeah.
Well, But, you know, for specific jobs, let's say in terms of coding, right? I, I remember interviewing a company that were based in the uk where what they would do is you would hire them if you were looking to hire coders, and they would prepare a prompt, you know, code, code, something like this. And then it would, using ai, look at the code you generated, the code you wrote without having your name, your background, your sex identity, whatever, and then just pick who wrote the best code.
And that was a way of kind leveling the playing field right now with today, AI writing the code, I think that screws the whole thing up. But, but there are ways where I think we could use AI to level the playing field and maybe try to get some of that bias out of there. Um, I don't know, Alan, because if the model was trained on the, all the code that's been developed, and most of that code was developed by males, and if you assume there's a difference in that, or maybe culturally India versus US ly, it's gonna have those biases even in the code.
It's gonna favor what it thinks is, I even English is a second language. Coders are at a disadvantage, perhaps. Not saying we shouldn't try to use it, but I think we have to recognize it.
It has a natural bias into it. And that's what we have to figure out. I, I thought that's why we had a DEI program.
No, we defunded that. Well, I said had in the past tense. Oh, okay.
But that was the reason for it, right? Was because this is, it's built into the system. It's built into the SATs and the L SATs and everything else.
You know, when you have basically white men making the rules, you're gonna have rules the favor white men. And no matter how much you stamp up and down and whine and threaten and huff and puff, it doesn't change the facts on the ground. Mm-hmm.
And I would, I would like to see the AI models vetted by some third party and maybe, you know, some sortation And that third party not made up of white males. But part of the, I think part of the reason why they're turning to AI in the first place is because so many people have access to just apply online now. There's just thousands of people randomly applying to hundreds of jobs at a time.
It makes it very difficult to filter Through. Yeah. It's not one of my favorite things is yeah, trying to hunt through resumes for a person to hire.
Anyway, let's hope it gets better. I think this is an area where we can get better with AI and we can level the playing field, and, and we owe it to all of us to, to do that. Guys, I think that's gonna wrap up today's, uh, text, text Drunk Gang.
John, enjoy Las Vegas. Stay away from those tables. Yes, thank you.
The house always wins. I don't gamble. I know I don't gamble.
All right. No, Amanda, Mitch will see you soon, Mike. We'll see you soon.
Well, you'll be at Nutanix this week. Looking forward to some reports from there. Until next time though, until tomorrow, we have a full text Drunk TV lineup following today, including, I believe we have a Tech Field day going live today.
So you'll be able to see that here on Tech Drunk tv. Until next time, this is Alan Shimel. Have a great day.
We're out. Hey everyone. Welcome back here to Tech Drunk tv.
I'm really happy to introduce you to a first time guest here on Tech Drunk TV and a new kind of a company and move movement to talk about. Let me introduce you to Manos Ku COIs. Uh, he is the CEO and co-founder of something called, excuse me, OMI, OUMI, open Universal Machine Intelligence.
He's gonna tell us all about it, but Manos, welcome to Tech Drug tv. It's great to have you on here. Thank you very much for having me, Alan.
It's my great pleasure to be here and talk more about, uh, OMI and as you mentioned, both OMI as a company and the bigger mission that we're pushing forward. Absolutely. So, Manos, um, let, before we get into umi and everything, you are the co-founder and CEO I've in, I've interviewed literally hundreds of founders, co-founders.
Every single person has founded the company because they buy into the mission. They feel in some way it's going to help change the world, help make the world better. But they, no one, no one is born and co-found a company.
Do you know what I mean? There's always a life before. Let's hear a little bit about your life before co-founding omi.
Absolutely, absolutely. So maybe I may take you a little bit, uh, very far back, but I started wanting to become pretty much like my father to become an electrician. And luckily the best school in Greece was the electoral and computer engineering school.
So, as by accident, I got into computer engineering, quickly fell in love with computer programming. Uh, and then when I was going to my PhD not knowing what AI really is, I kind of almost bumped into it. It was when the first iPhone was coming out and I said, you know, there has all these sensors, all these data you need to do something useful with it.
And that's how I bumped into ai. And way before any company said we we're an AI first company, that was back in 2007, 2008. I'm like, you know what?
AI is gonna be big. You need this machine learning, you need this technology to do something useful with all this, this data. And that's how I got and started getting deeper and deeper into ai.
Then, then moved into Microsoft, started working a lot with natural language ai. I even built something like in 2016. I was a little bit premature, uh, and then, yeah, continued on with that at Meta, working on conversational ai, uh, then a startup, then Google where I was leading all the natural language AI services, uh, including also bootstrapping the efforts for Palm.
That was the model before Gemini. Yeah. Uh, very cool stuff, really.
So you, you've literally had a, you know, been right in the middle of it here as we've launched into this, you know, era of ai. It's funny, I have a friend, John Willis, he has a new book coming out this week or this month, kind of the history of AI and the people behind it. I don't remember the name of it, but if you go on Amazon, look up John Willis, it's his newest book.
What I think a lot of people don't realize is this whole AI thing that burst on the scene, what, two and a half years ago, maybe with chat GPT Open AI has really been something that's 50 years or more in the making, right? And the idea of what we now call ai, whether it's a form of machine learning, pattern matching, et cetera, right? All the way through the latest and greatest agentic AI and LLMs and training models and all of that.
You know, it didn't just spring forth. It's been a gradual buildup over all these years, but there's always some mono, there's always some ignition point or something that lights it up, right? That, that makes it, uh, just go viral, so to speak.
Obviously, open AI's chat, GPT was that event here, but why, look, you were working on this, as you said, in 2017, 16. Why then why, why not in 2017, what was missing then? That is now.
Yeah, f first of all, Alan fully, fully agree with the points, all the points you made, uh, ai, machine learning, AI has been in the making for quite a bit of time now. Um, and as you said, you know, back in 2016, we built something like ZGBT. Even back then, I could see people were amazed how there was a chatbot like ZGBT, uh, that could respond to any question you would throw at, but the technologies are very premature at the time.
In other words, not as advanced at the time. For example, what we now, we call, we use Transformers, it hadn't been invented yet. We're using their predecessor called Ltms.
So even though people were amazed, the quality was just not there yet, uh, to becoming the product. But lemme tell you, I mean, there was quite a few times I could see people being amazed at the time, you know, almost the reaction they have with ZZPT. It just, you know, every now and then the system would say something that doesn't make sense, and then people will lose interest.
And, um, but I think that's, that's, you know, that's, uh, I think what open I did, they did manage to scale up those models and some continue making them better and better. And because, as you said, they make it, they made it so accessible to people. It, they got this viral moment that, uh, finally, you know, they took, uh, the world by, you know, uh, they, he huge excitement around the world about what they built.
But there was definitely something in the making with many research labs, not just what we did at Microsoft, but even after that building such technologies. But I think they managed to give it a good delta in the quality improvement and then make it so accessible, building the hands of people that, uh, created that earthquake in the industry in, uh, anywhere in the world. Absolutely.
Absolutely. Let's turn to Umi. What, what drove, you know, you, you worked at Microsoft and Google and Meta Giants, you know, the, the hyperscalers as we call them.
What made you, you know, people don't do this like, like, you know, uh, without good reason. What, what drove you to co-found omi? Yeah, that's a, that's exactly right.
Uh, the, the, as you were also discussing earlier, the main thing was the mission, uh, starting from the problem that we wanted to solve. The more, uh, as I was mentioning earlier, I bootstrapped the efforts of production. I found working with, I don't know, 20, 30 teams all across Google to make it happen, until that effort moved to deep mine.
But even as I was continuing to work on Gemini, when I moved to deep Mine, and I was increasingly realizing how more and more sciences, you know, for not just healthcare and the tech industry, but climate science, material science, and many, many more, pretty much all science going forward, gonna be powered by ai. I was increasingly getting worried about the future I was contributing to. 'cause I was thinking it can't be that what's gonna be the foundation for all, both the tech industry and all the sciences.
It can't be a black box that is owned by open AI or Anthropic, or let's say Google or somebody like that. It needs to be, we need all the science need to have more free, uh, access to this AI technology. It needs to be a glass box, something they can easily look at and adapt so they can promote the sciences.
So there was that, uh, you know, philosophical concern. And then I started also realizing something that was, I would say, not clear to many people. I would say still not clear to most people, which is that while these large tech giants, they may brag about the number of GPUs that they have to build these models.
This only part of the story, the thing that most people don't know is that, uh, they're actually themselves very constrained in terms of the human capacity. Those technologies are extremely complex. They don't take a lot of GPUs to train.
They take also human amount, humans, huge amount of human resource and human ingenuity to continue moving them forward and advancing them. And that's where I realized that actually AI is the most prime technology to be advanced in open source compared to operating systems like Linux, or compared to database like PostgreSQL, even more than those technologies. And the best way to advance it, both faster and safer and most cost efficiently, is to do it in the open, to do it collaboratively with all the open community that is orders and orders of magnitude larger than the couple thousand people that are in Deep Mind or in open ai.
Uh, and that's actually, again, the best, the best way to advance ai, the safest way to advance ai, and, um, uh, the best way also to make it accessible then to all the sciences and enterprises. And that was the kind of the, the most important, I would say, motivations that led us to, to fund domain. Yeah, fair.
You know, you, you, you mentioned, uh, or in, in some of the OMI stuff, is kind of trying to pattern OMI after sort of the Linux movement as it eventually triumphed over the, the many flavors of Unix, if you will. Yes. Right.
But to be fair, when Linux did that, we didn't have what I call the foundational era of open source, right? We have the Linux Foundation now, which is of course, a lot more than just Linux, as you know. Um, you know, open source now is a much more defined, uh, method of go to market.
However, there's the flip side, right? Where we, we, we've seen a lot of companies struggle goal with an open source model, right? It, you know, it used to be a Red Hat was the big success story, obviously, but we've seen many companies succeed with open source, but we've also seen many companies not how, how can OMI be successful with this open source model?
Yeah, lots of lots of good questions there. So the first one was that, uh, if you come to think about it, I, I, I, I, I, the, the, actually, the more I was thinking about, the more I was getting convinced that the best way to develop these technologies and compete even as an enterprise, would be to do it in open source. Because currently what's happening with open AI and Tropic and Google and all these companies, it's, uh, it, it's, it's like, uh, about who has the deepest pocket to keep investing in AI and keep draining all this money that if I were a shareholder of these companies, I would be very frustrated how this money is being spent hoping that they win this, and hopefully they make, make it big, and that recoup all the money they have lost across the years with some getting, uh, less and less optimistic it's gonna be happening for any of them.
Um, and that was actually the key conviction that the best way to develop this technology is not to try to spend more money than open ai, but to say, you know what, no, as a community, we're gonna contribute to this boat because there is all the open community, all the academia, all accelerator providers like Nvidia, a m, the oldest companies, all cloud providers that are not one of the few aspiring aioli guards, all these companies that won open source succeed. So the best way to compete as OMI or as any company, is to bet on open source as opposed to trying to outspend open ai. Uh, it's just, it's the best thing to do for the world, the best thing to do for humanity.
And I think the most viable strategy is to compete. And given that there was this gap, as we mentioned, the example of Linux and Unix, there was this gap of there was no Linux of ai, there was no platform that democratized this frontier, frontier AI issues and development. Uh, that's why we said also, you know, we're gonna build this because it will help.
It's, first of all, it's gonna be a positive thing to do for the world. And we think it's gonna be the MVP is gonna be the thing that will, uh, resolve the initial friction that the community has to help it then to continue advancing and doing their research advance Frontier ai. Because if you can unlock and enable this community, and the more they innovate on Frontier ai, then it, these are gonna be for Rumi and any other company to stand against this, uh, you know, as a David, to stand against those colias and compete with them.
Uh, so that's why that open source strategy, you know, I'll be very candid. I think it's, it's both self-serving for omi, but at the same time, I think it's the thing that benefits humanity and every other small enterprise that wants to be able to compete with open AI or anybody else. Fair enough.
It's gonna be interesting, you know, what else? So, open AI and, and our, our audience is familiar with this, that it's not open source open ai, but it is sort of this foundational not-for-profit. You know, there's all of this tied up in there, and of course, Elon Musk is suing over and what he's doing and everything else.
What makes us, you know, there's a lot of flavors of Linux, right? There's SUSE Linux, there's Red Hat Linux, there's Rocky Linux, there's what makes us think Umi is the one, you know, to put our efforts behind versus Yeah. Yeah.
Others? First of all, just, just a quick comment. As you mentioned, OpenAI is nothing but open.
It's as closed as it gets. Yeah. Um, and omi, the way sometimes I describe OMI to people is that the polar of open ai, you know, open AI is nothing but open.
It's fully closed. I OMI will try to make truly open frontier, but as opposed to building a model and giving it to people and say, you know, here's a great model we develop now you can use it. Instead, we're starting from empowering the community and everybody to contribute to making AI better.
I think that's the key thing for unlock open source, not develop a model and give it to everybody, but empower everybody to come on board. I think that's a big, I'd say philosophical or strategy difference for omi that I think is gonna be key to our strategy. And I think it's key for OMI to win this key for open source to win this, uh, which is that you bet on the platform, you start by enabling the community to advance Frontier.
So Manos for people out here who say, Hey, this is the thing I've been waiting for. I want to get involved in ai, but frankly, I, you know, I was waiting for truly an open, open source community to come in and do it. How can they get involved with umi?
Yeah. So I would say they definitely can and a lot more, and a lot more easily than they could until recently. Uh, and that goes again to the design of when the goals with whom it was, was to create a platform to create the lineage of ai.
That would make it easy for anybody. Definitely for researchers and metal engineers. It makes it a lot easier even for them.
But even for people who are more like application developers, uh, to experiment with, uh, ai, and they can go incrementally deeper and deeper. We say that even though OMI is open source, it's as easy, if not easier to use than the API is built by open AI or that my team was building for MI, um, at the same time, because open source, you can experiment and stay at the level you're comfortable because we make sure it's very easy with a lot of examples to follow. But then as you get more and more proficient, you can get deeper and deeper.
And I think that's key to any individual person or any enterprise to start building the up the AI muscle, which I think in this time and age, it's gonna be very critical for any individual or enterprise. Agreed. So for people here who want to get involved, what should they do?
So we have, uh, the omi GitHub. That's be the best place to start your, I think if you Google search, uh, omi, GitHub, uh, I'm sorry, it'll come up as the first entry. And yeah, sorry.
From our GitHub, somebody can find all the information, all the documentation we have about how to install, um, a library, how to get started. Again, we have a lot of examples and we got a lot of positive feedback about the quality of the documentation, because again, that goes back to our design principles, which was we want to start by enabling the community, which means we give them a great platform, great documentation, all that they need to get going easily and without friction. Any plans for, like, is there a Discord server or anything like that that we can, people can get onto?
Yes, absolutely. ai. There's a link both to our GitHub and also a link to our Discord.
Uh, we have an active Discord. It's over a thousand members right now, uh, with a lot of discussions happening and even some research efforts that are being organized through Discord, uh, on our website. Also, we have a form that people can fill if we want to contribute to those research efforts because we're spinning up more and more such research efforts.
So yeah, definitely. Um, check out GitHub, if you want to get started, discord, please join for discussions or if you want to join some of the research projects or fill up the format, uh, OMI ai and, uh, we can make sure to include you in any of the future research efforts. ai, open Universal Machine Intelligence.
Manos, I wish you guys much success in this. It would be, it's gonna be great to see how this develops. You know, clearly a couple months ago at the Chinese deep seek, one of the, one of the selling points, I don't know if it's the word selling, but one of the bright spots on it was that it was open source.
And people really liked that idea, though. How much of it is open is another story. So having one here, Umi, it'll be good.
It'll be interesting to watch how the community comes around on it. And we do have the GitHub and Discord, uh, URLs. We'll, we'll include those in the notes.
Thanks for being on text on tv, man. Good luck. Thank you very much, Alan.
It was my pleasure. Thank you. Manos Kois, uh, CEO co-founder OMI here on Text Drunk tv.
We'll take a break. We'll be right back. It is Text on tv.
It's Getaway Day here at RSAC, Lisa Martin here. Having had some amazing conversations with cybersecurity leaders across industries the last four days. But you know, because you've been tuning in to Text on TV and all of our other digital platforms.
My next guest is a veteran of Text on tv. My first time interviewing her, I'm a huge fan. Caitlyn Ian joins us.
6 million followers across social media. You should be, Caitlyn, it's a pleasure to have you on the program. I'm so happy to be here.
Talk to me a little bit about, you have a mass in a short time period. 6 million followers. I'm one of them.
TikTok, LinkedIn, Instagram, X. How did you do that in such a short time period? I, I don't, I don't know.
Um, so I started on TikTok originally and I really was embarrassed. 'cause I've been in cyber for 12 years now, and I'm like, if anyone finds out that I'm on TikTok, I'm gonna be destroyed in, in the office. And, but I really wanted to reach the next generation.
That was like the main reason. I was like, I want people to understand like everyone it, like is needed in cybersecurity. And cybersecurity is not something scary and they can get in and it can be fun.
And we also need more women. I wanted women to see themselves. Yes.
Because when I was first introduced to cyber, my immediate gut instinct was absolutely no way I'm ever gonna be a part of this. Yeah. I was like, I'm not a man.
Yeah. That's, that's the number one reason I'm not a man. And I was like, I didn't see myself there.
Like, I just was like, that's, I'm not a coder. Like I don't, that's not where I'm supposed to be. Yeah.
And that was like the main reasons why I started. And then I started doing more education on does the general public. I'm like, what cybersecurity is and honestly how simple it can be and how it's not scary.
It does not need to be scary, but it needs to be, like, the conversation needs to be had at home. And I always say cybersecurity starts at home and it's not a scary thing. It's a, it's a necessity.
It's a totally necessity. Um, and so that's kind of how it started. And I, again, I only started on TikTok four years ago and it wasn't until the last two years I put started doing on Instagram.
And the reason why I was called Cybersecurity Girl is 'cause I didn't want my name on it. So I didn't have my name affiliated with it at all for the first like year and a half, two years. Okay.
No one I worked with knew that I was doing it on the side. And then it wasn't until I got hired by TikTok and then I'm like, oh, now I can actually say it. 'cause they, they found me from my TikTok.
They found you. Yeah. So it just been incredible.
I mean, it really shows how important cybersecurity is now. Hundred percent. And how, how people really wanna know.
And the reason why I'm a little bit different is 'cause I, I like Shortform. Like I don't do long form YouTube. I don't even really do XI.
It's really just been like TikTok and Instagram and Shortform is for me is so important because people don't have the attention span. And honestly, even if they did, the general public does not wanna hear an hour long conversation about cybersecurity. No.
So what do they need to know? Like how is it impacting them and how can they fix it? Yes.
So like relatable, digestible, understandable content. And that's what I love to do. That's exactly what's needed.
I'm a marketer by training. I've been doing marketing and tech for 20 years, media for, for about 10. But people want to be educated in the simplest, cleanest way.
Yeah. And you just hit the nail on the head, digestible, clean. How does it affect me?
Right. You know, one thing too that we're dealing with now is I was mentioning my mom's almost 80 and she's digital. She's a facebooker, she's now an instagramer.
I introduced to chat GPT the other day. I know. I was so proud Of her.
I'm gonna throw my boyfriend under the bus, but he is, he still does not know anything about chatt. What? I'm like, I don't know if I can be in a relationship with you anymore.
You gotta educate him, girl. I, I, I'm Trying, I'm trying. We're working on it.
But we've got like five or six generations in the workforce today that are digitally active. Yep. And some of those populations are way more susceptible than others.
Yeah. So I learn a lot from you in the things that you post. 'cause you make it clean.
You make it simple. You make me go, oh, I didn't think about that. And so I teach my mom a lot of the things that I learned from you because I want her to just be, you have to, you can't just blindly trust everything anymore.
Right. We've learned that time. And again, ransomware is a household word.
Ransomware attack happens. I i the status from a couple years ago, once every 11 seconds. Right.
I'm sure that time is going down now. Right. It's only gonna continue.
But to your point, the education has to be there consistently. Right. Well, and there's two, two points I wanna hit on that.
So the first is, we also always think about our, like, you know, older population of like, oh, they're susceptible. But the issue actually is the younger generation. So the older population gets hit with like, larger ransomware issues.
Like they have the, the most money, but actually the most people that are getting hacked are the younger generation. Is that right? Because they're so blindly accepting of the technology that they don't think anything of it.
They're not like, meant to be skeptical of it. Yeah. Because that's what they grew up with.
And so it's real. That's, and that was why I was like, let's reach the next generation. 'cause all these people, I mean Yeah.
They're not gonna have monetary value 'cause they can't really exploit kids point. Yeah. There is sextortion, which is a whole nother issue.
And that's like, it's awful. And we're trying to mitigate that too. But a lot of these kids are actually dealing with similar issues as the elderly, but the elderly have way more to lose.
It's Right. It It's the financial it hit. And Then the other part is like, similar to what you said, like cybersecurity is a human issue.
Like phishing and like, like reusing passwords. Like again, the Verizon DBIR report just came out. I went on, I went to their session yesterday and they were saying 60% of all these, um, threats and, uh, vulnerabilities are human centered issues.
So whether you reusing passwords Yep. Or access management stuff, like, and or clicking on a link. It's all like human at the end of the day.
And so that's like what I'm trying to get at. I'm like, I feel like I'm protecting the companies at at this point. Yeah.
Too. Because it, the learning has to happen at home. Like, when was the last, last time you learned?
Like, what, what did you learn? Like last, obviously you do this so you learn a lot. Yeah.
But like, when you're at home, like how do you learn, Uh, social media? Yep. So that thing news, everyone is losing on social learning on social media.
I Through it with a grain of salt. Oh yeah. You have to.
Yep. And but, but with deep fakes and the advancement in the sophistication of like phishing, smishing phishing, it's getting harder and harder to detect. Yes.
But I like your tagline that cybersecurity starts at home. It has to It Has to. It's not a nice to have anymore.
This is how it needs to be. Like a fabric of our lives. Yep.
And we were just talking, I don't know who it was with, but like, someone was like, yes. Oh, I know the founder of the hacking games that we were talking about how cybersecurity marketing has been such, it's been terrible. I was gonna say a bad word.
I'm not gonna say a bad word, but it's been terrible. Like we've been, we've been marketing cyber all wrong, even like companies. Right.
Like, cybersecurity is not something scary. It's not like we just need to mar like market it to like, and bring it to the people where they're at. Yeah.
And they're like, you know, online just general human beings. Right. That are like, I mean, we connected on Instagram.
Yeah. It wasn't because I like met you through, you know, some Right. Yes.
Forum. Yeah. Yeah.
But, you know, so, so it's starting at home. But also another thing too is just the, the commonality of it. And we have to expect it's there.
Yeah. With, there's more data, there's more software, there's more apps. That trajectory is just going up and to the right.
And it's not gonna slow down. Nobody wants less apps or less data slower. They just don't, We do want less op op, uh, less like signing in for accounts.
Yes. Can we stop that? Like, I'm a fan of fingerprint.
I'm like, it's me. Yeah. Yeah.
Hi. I am the problem. It's me.
Yeah. But, um, it's just such an interesting Love the Taylor Swift coat, by The way. I'm a swifty.
Yeah. This is why we kinda have nice things. Yeah.
We can throw you another one. Um, but I, I just, I think that it's so important to educate folks and it has to be consistent. And, and when we're here at shows like RSAC, we get to see so much of the technology that enables that fabric.
Yeah. And now that we're in the AI era, I love, how do we secure Yes, me too. Yeah.
There's so much potential, but there's a lot of fear. And so what I like to do is, let's pull out, and I think you're similarly minded, let's pull out all the positives that are there. Like, we talked a lot this week about how does software company X, YZ help customers, whether it's financial services or healthcare or automotive, become proactive Right.
Against the attackers. Right. Because technology is neutral.
Good uses, bad uses, it's like fighting fire with fire. But it's, there's never a dull moment. And we need more people like you to educate the different user generations and groups of where the risks are.
'cause they're not going away. No. No.
And I, I also like, love the, I love ai. I think it's the coolest thing ever. And like anyone that like doesn't use ai, I'm like very skeptical around me too with my, including my boyfriend.
I'm like mm-hmm. Um, but I think there's also a conversation that needs to be had around like, 'cause people keep saying like, ethical ai, ethical ai, I am like ethical is like moral based. Like everyone has different definitions of ethical.
Yes. So I guess it's like, how do we build AI and like, like what standard like baseline standards do we need to have to say, this is good versus this is bad. Right.
Right. Because we are even talking about that on like hackers. Right?
Like, we're talking about how kids are, we're trying to get kids into ethical hacking versus like, you know, a lot of times kids get like pulled into the wrong thing when they're doing hacking. But we're like, okay, at that point, what's ethical hacking? Like, where is a line?
Like, can you scam a scammer? Yes. Yes.
Like, is that ethical? Yeah. Because you're still scamming.
Right. But like, so it's the same with ai. Like how are we drawing that line of like what's right and what's wrong?
Yeah. And what, what AI should be doing and what ai sh ai shouldn't, and That's so nebulous right now. 0 and this Japanese animation studio.
Have you seen those Japanese animations that are like flooding social media? And so the Whole, I have a very like, narrow lane with social media. 'cause all I see is like stuff for you and because it's, it's for work.
But anyways, I did not see it. But It's, so the whole copyright infringement Okay. Challenge is there.
And it's like, well, AI and, and you know, chat, DBT anthropic, all of them are, are training their models on all of this information that probably they have without permission. Right. But how else do the models learn?
So there are fine lines, but I think the challenge is it's so nebulous. There are many fine lines. Yeah.
So to your point on ethical hacking, where, where are those lines? Yeah. It's not a, it's not a straight answer.
Right. But you also talked about people, and I always say, I had this friend out my other show who created stickers and used to have stickers on his laptop. And one of them said, humans Yeah.
Ruining everything since forever. Right. And I loved it.
But in cybersecurity, humans are, I think two things. The weakest link, but also the biggest potential asset. Yeah.
Do you Agree with that? Oh, for sure. Yeah.
And I always used to say like, you're only as strong as your weakest link. Yes. With every company.
Yes. I'm like, I don't care what what you do, but if you, if someone's clicking a phishing link, it doesn't matter any of the software that anything that you deploy. Right.
So I don't, I always don't understand like why companies don't spend more money on training and awareness. Granted, I think there's a lot of, uh, training awareness companies that need improving. Agree.
Um, I, I go to a lot of training awareness conferences and stuff, and I'm like, Hey, can we not go another fishing email? But you see opportunities, please. You see.
I know, I know. Um, there's so many other ways to do it, but, um, yeah, I think there's so many opportunities because again, you're only as strong as your weakest link. Why aren't you spending more money on trying to like, again, educate the people where they're at?
Like, why do we keep shoving training awareness into, into corporate, you know, employees faces? Oh yeah. Around, Hey, you need to protect corporate.
Why do they care? Yeah. Why would, why would I care?
Yes. Who cares? I mean, yeah, it's might, you might lose your job, but like, no one, you have to get to them.
Like actually, like the impact, the impact that it matters. Like okay. How to protect your family.
'cause they guarantee you, once they start learning how to protect themselves, they're gonna start learning. They're gonna automatically protect the company, which is good. Right.
That's The right pathway. Right. But we're not even teaching 'em like that.
No. Because it's a check the box and then there's like some fun awareness stuff, but it's like, meh. Yeah.
So how do you, how do you advise companies to change that? Make it more fun, but to your point, go where they are. Go to their comfort zone.
'cause people don't wanna get comfortably uncomfortable. Right. It's hard.
Oh, very. It's cultural. Yeah.
It's behavioral. Well, that's how it, that's how I always recommend. I'm like, okay, what, what is, what is your company culture?
And if you were them, like, I always, whenever I talk about training awareness professionals and people like are wanting to get into cyber, I'm like, you should start with training awareness. Yeah. Because those are the, you are the, the prime demographic people that have no idea what cybersecurity is.
Yeah. And you're trying to get in and you're trying to understand, but like get understand the culture. Yeah.
Get someone in that's not, that does not care about cyber, does not understand cyber and start picking their brain and asking 'em, like figuring out how, like how you can relate to them. Yeah. Um, because that's where you're gonna have to meet them.
Yeah. And then I just assumed that most people fall in the mill, but like, you can't, as, you can't like do a check the box training. You can't.
No. When I worked at TikTok and I was trying to redo their internal training too, like, I had to get so much oversight from like, legal and like GRC. I'm like, this training is not gonna do anything.
Like, you brought me in to like, you know, spice things up with training and make it more fun and do short form videos and, and I'm like, I can't do any of that with like, the way that you're redoing my entire, like, script. That's Kind of anti TikTok mindset. It was, it was kind of weird.
It was kind of weird. Yeah. I love TikTok though.
But it's, yeah. What, what has surprised you in the last few years of being cybersecurity girl and, and amassing this following who are learning so much from you? What enlightens you about the direction that career paths are going?
What's out there? That's good. I mean, there's so many things that are out there that are good.
And s honestly, so many cybersecurity people are good. Like, there's so many of us because we got in, like, we were pulled in from other people that we wanna help and mentor and like help other people. What's um, incredible is like how many people are wanting to get in.
That's good. That, and I don't wanna be a negative, but like now we're at this point where I get so many people messaging me being like, Hey, I've gotten this certificate, this certificate, this certificate, and I can't get an entry level job anywhere, really. So whatever they're saying about entry level roles is a load of bs.
Okay. So, Because I think a lot of entry level roles are actually mid-level roles Okay. That are trying to be paid as entry level.
And a lot of companies don't actually wanna train the people on site anymore. Okay. Which is really sad.
'cause that's how all of us learned. Yeah. I mean, all of us got into cyber.
We were brought in by a mentor trained on, on site. Right. I'm sure, I mean, I'm blanket statementing.
I'm sure there's a few companies out there that, but like a lot of the companies I've seen, they have like entry level, well mid-level roles classified as entry level and they want people with actual like more skills. And there's so many people, like I get like at least tens to hundreds of people a day messaging me being like, how do I get in? Yeah.
I don't know what to do and there's not really a direction yet. So I'm really excited 'cause there's so many people that are interested in Yeah, that's good. Now we have to figure out as a even like a country or like a the world honestly.
Yeah. How we're gonna navigate this because also the, the definitions of cybersecurity are different in every company. Oh yeah.
Right. Like everyone has different teams. Like some has access management and they, they, they're, maybe they're doing the same thing.
They're called something different. So like I was trying to work with NIST and say, Hey, is there a way that we can have like 10 of the same exact entry level roles exactly the same or exactly like equal with the what you need. Like, so, okay, hey, we have a SOC analyst that needs these like qualifications.
Then we have like a threat intelligence person. So I want the same titles Yeah. With like clear expectations of what they need to get.
And that way, like when people are hiring entry level, at least make, make the fortune 100 all do the same when they're hiring. Yes. It'd be a lot easier to transition people in.
It would, and then you can train them then on their company culture. You pick them on their com your company culture. Right.
The alignment best. Right. Yeah.
So that consistency is, is critical. It's no longer, um, a nice to have that the, the awareness has to be consistent. Right.
Like I said, marketing 20 years in tech awareness is key, but it can't be a one and done thing. Right. And it has to be tailored to your audience.
Right. And there are so many different audiences alive and you know, in, in the digital space today, I went to the restroom earlier and I saw a payphone. I'm like, there's still payphones around here.
Yeah. I remember having to use a payphone in high school. But I have a question for you.
Yes. What's like one thing that you would change with either like awareness or marketing in like cyberspace that you like, wish it was like already fixed? I think that it needs to be, to your point, it needs to be explained in a way that this is achievable.
Right. And it's not scary. It's not scary.
It's a massive opportunity. It's only growing. Mm-hmm.
So the opportunities will only grow. Yeah. But I think to your point, from an education and awareness perspective, I, I I a hundred percent on the consistency, but it has to be explained clearly.
Yeah. A lot of people like to get on soap boxes and all these acronyms, so here and there. Oh, we Don't talk about acronyms.
No, I do not say to me, say missing qu. Yeah. I don't even say Cushing anymore.
They're scam messages. Yeah. Yeah.
That's what it is. Yeah. No one, if you start doing like technical jargon, their eyes glaze over Yes.
And they're gonna be like, I don't, I can't even touch that. Yes. That's not even something I wanna talk.
I've Learned that from my radio role where we talk to more consumers. Mm-hmm. It's, it's how do you take com and you and I were both in the sciences, both in aerospace back in the day.
Right. And it's about taking complex topics Right. And converting them to digestible sound bites that a non-technical person can understand and go, I get it.
Yeah. Well, I don't feel like I ever was supposed to be in cyber in like a weird way because I never wanted to be. And then I learned everything on the job and I still, I don't know about you, but I still feel like I never know enough.
Oh yeah. Which is the best place to be, by the way. Yes.
Like, I always wanna, I wanna be in a room that everyone knows something and I know nothing. Yeah. First of all.
But then I also just feel like because of that, I like had to learn weird ways. Like I don't think I'm, like, my brain is supposed to operate the way that most cybersecurity are, and so I have to learn it in a different way. That's Well, it's Thought diversity.
Yeah. It's, but which Is so necessary. Yeah.
You brought up earlier, you know, when you started your influence career and I that you couldn't, it was that saying, I, we can't be what we can't see. Right. I do a lot of women in tech events.
Yeah. And it's true. Yeah.
We need to have mentors out there and sponsors Yeah. That look like us, that feel like us that go, okay, I could be accepted here. Yeah.
And the older you get, the less you care about that stuff. I will tell you. Yeah.
But, um, Yeah, but it's the younger generation that we're trying to get in. Yeah. You know, it's, Yes.
But there's so much job opportunity. I mean, like, I I work with companies all the time that will have like different, um, programs. Yeah.
Like some like Boomie, I'm Mc Boomie World in a couple weeks, and they have, um, a veterans program. So they work really hard with, with war veterans to get them into cyber and into technology. Right.
And I, I think there needs to be more light shined on things like that. Like there's a lot of doors and pathways, but to your point, if the employers are making it complicated, that's not gonna help that pathway become men Easier. And the other thing is, and I don't know about you, I feel like as a woman, because there was like DDNI initiatives when I like got in like 12 years ago, I always felt like I, I didn't know if I was hired for the right reasons.
Yeah. Even though, like I, and I, I'm not, I'm gonna toot my own horn. I had an incredible resume.
Like, I, I had three jobs in school, I had three different internships. Like I nailed my interview, but I always had that like, weird thing in the pit of my stomach being like, was I only here for, because I'm a woman? Did I check a box?
Did I check a box? And then it really made me like the imposter syndrome actually really like setting a lot of times. Yeah.
And I, I actually am kind of happy, like I want as many women in this field as possible. Yeah. But I also want the best, most qualified people in the role.
Yes. And so I want to make sure, I feel like it helps with imposter syndrome too, from a woman perspective. I agree.
Like, don't hire a woman because we're a woman, hire the person for the right role. We're we're trying to train the women to be the right woman. Yes.
Right. So I think there's like a weird, Well, there's also all these stats, and I'm forgetting the actual specific stats, but like, like, I don't know, 80 plus percent of females, if they see a job on LinkedIn and they don't meet every requirement, they don't apply. Whereas men Oh, I got that.
Yeah. And so, and now with ai it's even more challenging because everybody wants people with AI experience. You're using AI to write your copy.
How do I set out? I use it, Write Everything. Oh, I wrote my radio here for it tomorrow morning.
Right. Rock chat this morning. Yeah.
It's the Best. It is the best. I, I like it as a creative inspiration.
That's how I leverage it. I, I have a lot of good stuff going in my mind. Probably you can tell with all the conversations that we have, but it, it really helps me do like a brain dump and then it helps me reorganize Oh yeah.
How I should frame things. Yes. So that's what I love about it.
Yeah. But I think for folks that rely on it, that's a different story. Yeah.
And I think I, I was reporting on this recently about like, it's a really high percentage of, of students between like 17 and 25 who are dependent on things like chat, GPT. Can You imagine going through school with that as a resource? I would be dumb.
My thesis would've been dumb. Would be so much easier. Yeah.
I Would be, that's, that's the challenge. Are you not learning enough or retaining it because you can get it spit out you back at you in seconds. Yeah.
So it's, it's a double-edged Sword. Yeah. But it's like, like I say, technology is inherently neutral.
It's used for good and bad. Right. Let's find all of the good uses and amplify that everywhere.
For sure. I feel like a sense of responsibility as, as, as a tech executive and now a reporter and media person to help more people understand how not to be afraid of things like ai. I talk about it all the time on the radio.
Yeah. Why there are risks and I want to help you be aware of them. But let me tell you all the things that it's already doing that you're interacting with that you don't know.
Well, And I think I, I was talking to someone else about this, like, I feel like everyone's like, oh, buzzword ai, buzzword ai. But like, we need to move past the point of like, ai, because ai, even when AI was a buzzword like two years ago, It was already implemented. People just didn't talk about it.
Exactly. So I'm like, it's already like, I mean, net, the Netflix recommendations, your Instagram, the face filters, your Instagram recommendation, everything. Oh, it's already used.
Technically ai depending on your definition. And so it's like, okay, well how do we move past like, okay, AI is like everywhere it's gonna take over. Here are all the, the scary risks to, okay, let's implement this in our day because we're not gonna run from this.
We can't, we can't. It's already here. Oh yeah.
So how do we like optimize it the most? I think I made a video about like the four things you shouldn't be putting in like ai LO Yes. I saw that.
I saw that. I'm like, we're gonna use it. So like, here's just ffy.
I don't, don't be putting this information Little guard rails. Yeah. But, but then there's healthy uses of it and it's like what?
Like some of the applications in healthcare Yeah. Are phenomenal. Yeah.
Detecting skin cancer, I mean, you name it. And, and the train has left the station. Right.
Chat. GPT was born. It just catalyzed this movement.
Yeah. Yeah. Where every company that I work with, either, either as a marketer or as a member of the media, we have to have an AI story.
Well, what is it? Yeah. It has to be real.
Yeah. And then you have to go, okay, here we are. RSA, how do we secure ai?
Yeah. It can be done. It's not easy, but it can be done.
We can get proactive against the defenders. Yep. We just have to be constantly doing it and learning and evolving.
Yeah. And the tech is evolving faster than laws and regulations. It's just such an interesting time to be alive and be working.
I know. I'm, I'm, I'm trying to figure out how the, to best optimize it, honestly. Yes.
Like how, what do I do to like, make sure that I'm fully taking advantage of this, like, massive growth. Agree so Fast. Agree.
It is so fast. What's next for you? We know we follow you on at cybersecurity.
Girl, you were just in Montega. Was that the NATO youth summit? Yeah.
Awesome. Yeah. And then you came here, got stuck in Barcelona, but you came here Barcelona.
But I came here. What's next? What can we expect to learn from you next?
I mean, I'm gonna just constantly, constantly be throwing out amazing videos, hopefully. And educational videos. And I'll tell you my like, future goal is to like have like a kids, like Bill and I kind of show, but for like STEM and tech and ai.
Love that. Because I, I am, and something I talked about at NATO was like, we have so much responsibility and opportunities with these kids to make AI and cybersecurity not a scary thing and not a necessity, but like fun. Yes.
And if they're able to be like curious and play with it from the beginning, we are gonna see massive growth in that field from when they as, as they get older. Um, and so I'm like really excited about the future of that. But I would love, I wanna do like a TV show.
I, I'm ultimately just trying to build like a trustworthy, continue to build a trustworthy brand. Yeah. Because I do feel like it's my responsibility.
People be the one person that's like, Hey, no clickbait, no bs. Here's what's going on. Yeah.
And here's what you need to do. And like, have, have fun. So, Well you're democratizing access to all of the generations for cybersecurity.
Why it should be part of their, their fabric, their personal fabric, their professional fabric. Yeah. And why it's a good thing and not you're demystifying it.
Yeah. And that's needed. Yeah.
That's what I always say. I always say like, I'm demystifying cybersecurity as a whole. Like in general you are careers, cyber, whatever it is.
Just, that's where I wanna be. Well keep doing what you're doing. I learn 10 from you, like every day.
I appreciate you responding to my DM the other day. I'm like, Cale responded. I felt like So cool.
Oh my gosh. I appreciate you messaging me. Of Course.
Yeah. And I wanted our audience to be able to learn from you because this is something that is just the fabric of our daily lives. And we appreciate your insights, your time, and sharing all of your knowledge with us so consistently.
Thank you Caitlyn. Thanks so much for having me. It was my pleasure For Caitlyn, Sarah, and I'm Lisa Martin.
This wraps up four days of coverage at RSAC 2025. Yay. Big hand of applause for our amazing production crew with Tuck on tv.
We thank you for watching. You can find all of this content by next week on the socials. And if there's anything that you wanna watch again, lucky enough, you can do it.
Find us at Tech Junk tv. com. Too many, too many brands to mention.
But thank you for giving us your time. We hope you've learned from our guests. We'll see you at the next show.
Hey everyone. We're back here. Live at RSA conference.
It's Wednesday morning. Things are starting to kick up here. We've already had a full day.
Of course. We recorded our Textron gang at about eight o'clock this morning. Then we did a new segment special here for RSA called the Analyst Arc with uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference.
My next guest needs no introduction to our audience here. He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement Right.
Early on with swa, everything else. Uh, he is also a co-founder, right? No, you're not.
You're C-T-O-C-T-O And founder at Contrast and founder of Contrast Security. Yep. My friend Jeff Williams.
I knew you were co-founder, but I always say CEO and it's Ct. Right? Right.
That's Why I wanted to make sure I got it right. Jeff. CEO's a terrible job.
C CTO's a much better job. CTO's the job you want. I, I agree with you.
Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess. Yep. You live and learn.
Anyway, Jeff, it's great to see you here. Good To see you too. What is this?
Maybe seven, eight RSAs more and Yeah, I've I've done Yeah. More like probably, Well, I'm saying that you and I have interview together. Yes.
Oh, I've become an RSS a since 2002. Right. So Yeah.
Similar kind of thing. Um, you know what, Jeff, let's start off though. Maybe there are some people out here don't know Contrast security.
Just quickly. Yeah. If you don't mind.
Yeah. So we're an application security company. Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things.
Mm-hmm. And we take a runtime approach to application security. So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use.
Like it's all measured directly from a running application. So it's real, it's not theoretical results. Right.
And, uh, we do that to keep you safe and more importantly your customers and children safe. Absolutely. Well, no kidding With children Safe.
You know, Jeff, one of the interesting things about contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes. Right.
And that's like sort of a black hole, right? That deployment event horizon. Yeah.
And all of our, and if we could say all of our AppSec focuses left of that horizon. That's right. Traditionally, traditionally.
And, and for good reason, it's supposedly faster, cheaper, more efficient. Well, we should talk about that. Absolutely.
But recently, I know Contrast, what was the movie Interstellar? Remember that movie? Yeah.
You've gone through the event Horizon that Through Event Horizon, It come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right. Uh, and to me that's what sets you apart.
I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right. Traditionally, we've put a lot of bets down on helping developers write perfect code.
Yep. But I, I don't know, do you feel like developers writing perfectly Charact? I don't think there is such a thing as perfect code as the problem.
Yeah. It's, and and it's, I think It's like a holy grail and it's A moving target. Yeah.
'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities. And so we've put a lot of bets on that and frankly, it's not delivering.
Right. Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work.
Mm-hmm. And so we had, uh, the insight to say, Hey, you know what? In production we can see everything.
It's not, you know, in, in development you see pieces of applications. You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs, they're all separately, but in production, they're all assembled together.
You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly. Where it's vulnerable.
And you can help companies focus on the, you know, the few percentage points of issues that are real. The ones that have crossed the event horizon that are actually being attacked in production. Mm-hmm.
Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems. So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left Right.
Problem is, it just hasn't worked. It's, it's backfired. com.
'cause I think people realize that you, when you over shift left, what are you saying Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write insecure code? No. A developer says that, but you don't have developers raising their hand and say, I'm your security guy.
Also True. That's, that's who they are. Also true.
And so that I, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps. Someone's gotta do it. Yeah.
So the way runtime security works is, is very much like other kinds of detection and response mm-hmm. Like EDR and cdr. Sure.
And the one thing to realize those technologies don't stop application layer attacks, right? Yeah. They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer.
Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs. That's how you detect things with full context.
And so after that, it, it works just like the rest of the XDR ecosystem. Sure. You, you know, telemetry gets collected.
It, there's a dashboard, but it also goes into your sim and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations. Agreed.
It's just missing. Agreed. Let me ask you a question.
You know, I was at Q con in London last month. Observability. Yeah.
Everything's observability. It is. How does the a DR play in the observability, this new universe of observability?
Yeah. It's a very similar concept. In fact, we call it security observability in a lot of contexts.
Fair Enough. And observability is interesting. It started to the left of boom, like in, in development.
Mm-hmm. And companies like New Relic and AppDynamics and so on, you'd monitor development. And then they realized, hey, what are we, what are we measuring test systems with?
You know, not real data, not real users, not real load. And they're like, well this doesn't, it's not realistic 'cause they didn't have the right context. So those tools moved into production and they measure real reality in production.
Yep. Uh, and that's the same transformation that AppSec is going through. Yeah.
That's, if you measured in test environments, you don't have enough context. You don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Do.
You're walking in that same footsteps Here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So in our never ending quest for the single plane of glass, do you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform?
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CNA P and Sure. And sim kinds of integrations that, that data they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right.
I think today, but ultimately if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, And that's, it's come a long way now too.
It has, especially with ai. So we're building a digital twin of your application layer. Not one app at a time, but the whole thing.
So That, wait, this is new to me from you now. Yeah, let's start over here. Yeah.
So talk to me. So imagine you've, you're a big complex enterprise. You've got hundreds of thousands of applications all connected to each other.
APIs containers. Right? Now we're all confusing it.
So when you deploy contrast, you can deploy it across that infrastructure. Like we got a Kubernetes operator. Just push it out.
It's part of platform engineering, right? Absolutely. You push it out, then the telemetry starts coming in and we take all this telemetry that's coming from all these apps saying, you know, things like what's the attack surface?
Where are the vulnerabilities? Where are the attacks? Where are the assets?
All that's coming together. And we're building a digital twin. It's, we call it the contrast graph, excuse me.
And it's, it's a model of how your application layer works. It's a lot like the wiz graph except for it's not infrastructure. We're talking about another layer of abstraction, all the, how the application layer works.
And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well I understand this vulnerability in this app, which has this blast radius. And, and you can really get good risk rating and you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your Sure.
Pen testing process. No, I'm, I'm a big believer in the digital twinning. I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or, or bigger Pictures.
That's what we had to do is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database. Right.
And that's limited, right? So we moved to a modern streaming data architecture. It's Kafka, it's graph databases.
And we're, we've built a massively scalable data collection Platform. That's what you to do that too. It's, it's because our new CEO e from Splunk Oh.
So obviously, so He came in and said, Hey, you know this, we need to collect more data, not less. And so we've just been en enhancing our telemetry building a a, a Awesome model. Well, no, once you're able to get your head around or your hands around all that telemetry, now you start applying the AI and stuff.
Exactly. You start seeing insights that you, you, you just couldn't see before. Runtime security and AI go together like peanut butter and jelly.
Like no doubt. Because runtime is is real. It's measured directly from running apps.
It's not theoretical stuff. It's not No, I get tons of false positives. So yeah.
They, they go together really well. Love it. All right.
This camera's on you, right? Okay. Tell them how they get, how did they go get this today?
Yeah. Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more.
com. Right. Okay.
And, uh, there's stuff you can try, if you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy. You get our installer, you push it out to your, your containers or your workloads, wherever they are.
Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications. Right. We support all of that.
And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production. And that's really where I think you should Yeah.
Put it. Then you're gonna see you, you'll get amazing visibility into what's happening. I will tell you, you're probably in for some surprises.
Like there's probably a lot more attacks going on on your application than you, you thought. Yep. And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach.
That's, you may find some log for shell that you didn't know about. By the way, We all, it seems it's all out there still, Jeff. Good stuff.
Really good. I'm really, you know, it's not often I get to hear new stuff like, Hey, application security has, has not been innovating as fast as it Used to know it. Uh, you know, with, with the boom coming from AI development, I mean, if you're, if you're Producing how you get our ducks in going 50% more code or a hundred percent more code, I, I don't, you gotta find way to Abec team is gonna double.
So you need technologies to help you scale into that double. We don't have enough abec team as it is for what we've produc Exactly three years ago. Anyway.
Hey man, this is great. I love it. Appreciate you're doing a great job.
Appreciate Jeff. It's appreciate man, you're the best. Alright.
Jeff Williams, contrast security. Go check out what he was talking about here because this is the kind of stuff you are going to need. Not three years from now, not two years from now.
Now we need it now. Go check it out. We're live at RSA conference.
We'll be back in a minute. Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Biard today with Chris Brownley, who's senior vice president of product for Yext.
And we're talking about AI search and how it may be changing the way we discover things and interact with content and maybe just turning our lives upside down. Hey Chris, welcome to the show. Oh, thanks a lot for having me, Mike.
We've all seen, I think by now the AI search results that you see and sometimes they're generated alongside Google and other times people are just going in and using AI search tools without even going anywhere near Google. Um, how prevalent is this at this point? I mean, are people not looking at the links at all?
Um, 'cause and how accurate or how, uh, comprehensive are those results? Yeah, I, I mean, being in tech, we probably we're more on the leading edge than, than anything do I think my mom is going in here right now and, and doing this? Not, not just yet, but I think it's very, very close.
Like we all know Apple's baking it into to phones. Google has it with Gemini. And so to me that's where it kind of crosses the chasm.
But, um, but obviously the big distinction here is for the last 10, 15 years when you do a search, you get a bunch of, of blue links essentially, and you gotta go hunt and find what you think is the most appropriate for you. And what changes with AI search is that you ask a question and you get a very direct answer or you get prompted to give a very direct answer. And so there's a lot less exploration happening, um, when you're looking for an offering or a product or a service or, or information even.
And some of these tools are now purporting to do research for you on specific topics and uh, you know, they're searching a bunch of different, I'm assuming websites that come up with some sort of conclusion. And I think that's based on the reasoning engine that they provide. But how do we know that they're kind of comprehensive enough to generate something that's accurate or, or most people just gonna say close enough.
Yeah, I, I mean especially with the, the last two years, I think the biggest fault that everyone would point to with any of this generative AI tech is it's prone at times to hallucinate, uh, and to give inaccurate information. And so I think that's obvious. One of the biggest areas that these, uh, companies are focused on is how do we get rid of these, these hallucinations?
And so if I'm a a a business online, I want to think a lot about like how do I make sure it has the most, um, information about me, my services, my offerings, and, and that it's being consumed as as accurate as possible so that when it does get pulled from, it has far, far less chance of turning into a hallucination that gives someone bad information about my business or, or how I could show up Some competitor that doesn't even exist. Right? A Hundred percent, yes.
So I think there are a lot of people who are having this gut check moment 'cause they're looking at the way this shift is gonna happen and they've spent years on SEO and buying Google AdWords and all kinds of things over the years and they, you know, they, they kind of understand how that system works and how to drive themselves up a response list. But, um, how do I do that in the age of ai? How do I kinda get myself inserted into an AI search that may not, you know, generate the level of links or, you know, I mean, I don't think most people make it past the 10th link anyway, but at least I was in the game.
Yeah, a hundred percent. Like there was a dashboard that you could log into to try and like update your information to know how you were even ranking in the first place to know what that was turning into for business impacts. And none of that exists.
You can't log into chat GBT or perplexity and manage how you're showing up there. It's a complete black box. Um, but going back to the last point, these LLMs are still feeding off of the web.
They're still crawling this information and they're doing it as frequently as possible so that they are getting as accurate information as possible. And so there's still ways to impact how you show up to have, ensure it has lots of, uh, good, rich, accurate information. But where you used to focus on just Google as your single pane of a most important single pane of glass for ranking, now you need to think about it across all of these different LLM AI search backed interfaces because they're crawling data and giving import to different sets of data than what Google used to do.
And so AI search for chat, GPT versus perplexity versus Gemini might use very different citations when they're actually citing this information as well. So knowing what data is being pulled and used, it becomes really important for someone trying to manage their performance online. Are there formats and ways that I should configure my data so that it is more consumable by these AI search tools?
I mean, what, what are we talking about there? Absolutely. Like, if, if anything more of the game is not just about creating content for your end consumers or people who's gonna view the content is can you even make sure it shows up in the first place?
Um, and so this is a lot about making your content easily readable by these crawlers. So it's simple things like having good schema markup on your pages or being as as clear as you can in the data, um, to help them target it to the right customer. Um, I think about the opening, I just said that they were gonna go more into product catalogs and being able to show what, what offerings you have to for more retail goods.
To me, I know that chat GPT builds up a memory about who I am. It knows I'm, uh, who I am, what I'm interested in. And so when it makes product recommendations going forward, it's going to take that into account.
So if I'm a marketer, I wanna try and add as much information about who my product is suitable for, like different use cases, different ways that we might want it to be shown up because it's going to be looking for such precise answers to give back to its end user that are very tailored to them. So I need to know, I need to provide that information that makes it have that best chance to show up to meet those criteria. I think back in the search days of when it was just straight up Google, we were always trying to figure out, well, uh, should I change my content often or less often?
Because if I don't change it so often, maybe Google will like it better that way, but then recently maybe once more updated content. So it tends to favor that with, um, AI search. Um, it feels like it's continuous, but you know, how frequently do I need to kinda update my environment to keep that position that I might ultimately get within the memory of the AI search engine?
Yeah, these are all of the experiments that we're trying to run today to figure out like we know with pretty good high accuracy what the things you are you need to do to rank in Google today. Um, and it is like frequency of updates, it's consistency. Um, the biggest things that we're seeing right now is, is just having really well structured data that's easy to be consumed and crawled so that it can be well indexed to even just show up in the first place.
Those seem to be, uh, from all of our findings, the things that will give you the most chance of showing up. If, if you don't have any of that in the first place, like good schema markup or um, well structured data, um, you, that's just step number one, uh, in the battle. What's your feeling about, you know, looking into your crystal ball?
How soon will it be that, you know, the way we currently use Google search will just fall by the wayside become antiquated or, uh, will this be like a demographic thing where, you know, old, old guys will be using Google search and the kids will be using AI search? I can't see a world where the traditional ways last long and I, I can't even imagine it being a, a, a generational thing. The ease and simplicity of not having to think about what you're searching for in terms of a Google search query where you have to like, you kind of gotta shift your brain to put it in terms of like, okay, how do I make sure I get the results I'm looking for?
Where with these LLMs I can ask a very human based pros question. Um, I can have a conversation to refine that search and know, um, how to get it more, more tuned into what I'm looking for. It's just such an ease of use solution that gives you the answers you want essentially immediately, rather than having to hunt and peck for these things that I, I like for me, in terms of timeframes, I, as I kind of touched on, like as soon as this becomes baked into our daily day-to-day devices, I think that's when it's gonna really cross the chasm.
I think, uh, even just this last month chat, GBT was the highest downloaded app in that month alone. Um, I think within Google. So it's, it's already happening though.
I think this is gonna happen, but won't I just wind up with a, a lot of AI agents that are anxiously standing by waiting to help me and every time I'm working on something they're gonna say, Hey, do you want me to launch a query looking for this, that and the other? And you know, they'll make quote unquote helpful suggestions. I don't know how annoying that might get, but um, you know, that relationship is gonna change where they're not gonna wait for me to do something.
Yeah, a hundred percent. It's funny 'cause you think of like sci-fi movies and stuff, you think of it as just being this one all seeing, all knowing ai, but really what we're seeing is the rise of these like agents where it's lots of many, many different ais that are specified to do one job really, really well. Um, I see it like the internet being 99%, these agents just like communicating with each other and finding information before it actually gets to the end consumer at the end of it.
And so yeah. What does this look like if you were to go like five years down the path? Ah, it's hard to, to even predict because you will just be interacting and behind the scenes I think it will be, uh, agents interacting with agents, interacting with other agents and, and what does that look like?
And I, I couldn't even forget guess right now in my crystal ball. So what is your best advice to folks about how to kinda get, you know, get down this path a little bit, especially, you know, I think end users will figure it out on their own, but if I'm trying to be the company that, you know, maintains some level of attention in this new age, how do I, uh, get started? It's citations.
They've always been a thing in traditional SEO. If anything, they're more important than ever right now. And it's knowing though what sources are being cited by the ais and then making sure you're on top of those places.
So it's interesting, I've been doing a lot of testing around like how do financial services businesses show up when I search for them or search for a specific agent, for example. And it's any sources like, uh, websites I'd never heard of before, um, for just like, like address phone address. It's, it's, it's using MapQuest all the time.
Like who's, who's managing MapQuest? com, like things that probably me as a financial services agent and probably paying zero attention to right now, but these are the things that are representing my brand. Um, any information about me.
And so I need to actually figure out what those sites are and get on those to manage all of my information because those are the things that are, are powering how I show up. And so you need to know broadly all of these different citation sources and then make sure they're all being up to date managed and that they also have the same information because as soon as you get dissonance between multiple sites, the, there's less trust in that data and there's less likely the, the LLM is going to surface that information because they don't want hallucinations. That's obviously one of their biggest concerns.
So it is still managing your presence online, but it's almost even more important than ever. If you wanna show up in AI search, which almost goes backwards. Will we fall back into the same trap we had with Google search where we all wound up using the same search engine?
Um, or will AI search be more diverse and there'll be more tools and more engines, and we're not gonna have this, uh, you know, concern about monopolies, et cetera, et cetera. Uh, it's such a hard one we're, 'cause we're in such early days of it. Um, you know, back when it was NetSuite and Naje Eves and all of those, probably no one forethought going down to a single tool.
And I think we're still very much in that explosion phase before we get to any kind of, of coming back in there. Also, there's gonna be a lot of lock in. I think that starts to happen with, with this memory storage.
I think, yeah, it's just too early to say, like, I would say plan for more fragmentation for the next five years before I would say like, go all in on just optimizing for one. OpenAI has a clear lead in terms of AI search engines and like referral sources. Gemini obviously being, having a lot of power behind itself too with being with Google.
Um, but I, I, I personally, if I was a marketer, would not put all of my eggs in one basket for the the next while. Do you think I might see agents in search tools that are optimized for specific, I don't know, vertical industries for salespeople or, you know, if you've got a hobby, maybe somebody's gonna tune up an AI search engine that's optimized for that specific hobby because it's trained on that particular kind of data. How granular can all this get?
Yeah. Um, there's lots of tools popping up like that with, with retrieval augmentation based on like, very industry specific data. Um, and even some of those tools are just getting baked in to the tools that we use.
You can create projects now in chat GPT, where I can load up a whole bunch of information and then be able to query against it and get, get insights. And this is where I think the agents will, will really have their time and place where they're really deep experts in doing one thing really, really well, and then can hand that off and can be reverified and rechecked. Um, and that's why I don't think it is just like one tool to rule them all.
It will be each of these individual things that will, will do their, their jobs. Uh, very specifically, I ran folks, you heard it here. Hey, they used to say, you know, the medium is the message.
Well, the medium is changing. It's called AI search now. So stay tuned and we'll see what happens.
Chris, thanks for being on the show. Uh, thanks a lot, Mike. I enjoyed it.
All right. Thank you all for watching the latest episode of the Techstrong AI video series. You can catch this episode and others on our website.
Until then, we'll see next now. Hi everyone. We're back here.
Live at RSA, it's Tuesday. Well, you know that if you're watching this live, you know, it's Tuesday. If you're not watching this live, take my word for it.
We filmed it, we recorded this on Tuesday. We don't film anything. Um, anyway, let me tell you a quick story.
com. com content March of 2014. In February of 2015, we did our very first DevOps Connect here at the RSA conference.
And the idea was to bring together the, uh, security, we didn't call it cyber, the security community and the DevOps tribe. Yep. Easier said than done.
You know, in subsequent subsequent years, we started calling it Dev DevSecOps Connect. Yep. But there wasn't DevSecOps 10 years ago.
Yeah. The closest thing I could find was something called Rugged DevOps. And Rugged DevOps was kind of the term was coined not by Patrick Dubar, of course, who did DevOps.
Yep. But Rugged DevOps came out of a tall, lanky Texan out of Austin named James Wickett. And here's James 10 years later.
There you go. There you go. And, um, what was rugged DevOps is really what we call DevSecOps.
Yeah. You know, today it was, and um, of course a lot happened in those 10 years, right? DevSecOps became a thing.
James, I think back then, this was before you were working with, um, the Signal scientist folks, the Before Signal, but you were one of the organizers of, of DevOps stays Austin, which was like the, for my money, the best DevOps stays in the, the States. Let's, let's go, Alan, let's go, let's go. And it's next, next week.
What anniversary? How many years Is that? This, this Thursday and Friday.
So I'm, I'm flying from here. Oh, you're Going right there. Two there.
How many years is DevOps Day Austin. Oh, okay. I think we're on the year 12 now.
If I, if I remember right. Probably. Yeah.
Right. Or around That's, this is my fourth day in San Francisco, so I'm sure my math may you won. May not check out right now.
Get I'm chocked full of medicine, so I'm all over the place. All right. But anyway, so I've had the pleasure of knowing James Ford 10 years, 10 plus years now.
And you know, in some ways as I get older, he does it. And, but I've seen you're very kind to say that, very kind To say that. But I've seen, I've seen his career.
Right. Evolve being a, an organizer of it, working for people. Signal science has came a long way.
And then founding his own company, dry Run Security. Um, if you're not familiar with Dry Run Security, I'm gonna make James tell you all about it. It, but he's, he's having tremendous success early on as I knew he would, frankly.
Right. Because he, he just does things the right way. Smart guy and, and works.
Right. He's a an example to all of you out there, James. Hey, talk to me.
Hey Alan. Thanks for, thanks for having me on. Yeah.
You know, it is funny you mentioned the rugged DevOps thing. 'cause it's like, I, I feel Yeah, sure I put the words together, but like there was the whole rugged stream going on at the time. Yes.
It was the DevOps stream. And so, you know, I, I don't know. It wasn't, it wasn't rocket science on my end.
It was just like, we should connect these things. And I, I've always loved how you're always trying to get these, these groups connected as well. Mm-hmm.
Yeah. We had a lot of like rugged DevOps DevSecOps days, just trying to like continue to, to bring that conversation, uh, even here at RSA, so. Sure.
Yeah. That's awesome. Um, but, you know, take credit for when credit's due.
Yeah. Okay. Thank you.
I will. A Lot of stuff is evolutionary not revolutionary. And so you had this DevOps thing going on.
You had the rugged movement going on. Bringing that together was a, was a eureka kind of moment. Yeah.
And, and look, there were others. We had Josh Cor, if you remember Josh, those first ones we had, Josh Corman was there and Gene Kim was there and you know, John Willis and, and all of these, I mean the, the folks who, Yeah, we were all just, we were all trying to figure out how to do, how to do this. Yeah.
It's great. Um, I'm, I'm drawing the blank. Did your LinkedIn DevSecOps course.
Oh, With, with Ernest. Ernest Mueller. Yeah.
Another, a Lot of the, a lot of the Austin folks. Ernest and Karthik, uh, Austin down. Were doing stuff.
Yep. There's one guy we're missing. Ernest Karthik, you, who's the fourth guy?
We also have, uh, PECO and Bill. Those are, those are some of the other recognizers that have been kind of in the mix down there, so Yep. Good times.
Good group of people. But anyway, James, enough history. Okay.
Yeah. Let's talk dry run security. Okay.
Assume some of these people have never seen or heard of Dry Run. Yeah. Yeah.
Yeah. Why, why would they have, you know, dry run security? We're very new.
Okay. And, uh, um, we see it as we've developed a new way to do code security. So we call it contextual security analysis.
Um, we, we believe that pattern matching is dead. That, uh, trying to, we've been doing, uh, in like the SAST world, uh, static, uh, code analysis and, and all that space, you know, we've been doing pattern matching and a ST parsing for, for all this time. And it's really kind of generated more or less the same results.
Um, better UI in some cases, marginally better experience for people. Um, but contextual security analysis lets us, uh, uh, takes a, take a context driven approach that doesn't do pattern matching, but we're trying to find risk in the systems. So, uh, yeah.
So driving security's great. It, it's, um, we're having a lot of fun doing it. I'm doing it.
My co-founder is, uh, Ken Johnson. He ran internal security over at GitHub. And so we, we both have, he wrote he, and he's the original creator of Rails goat.
Oh, okay. And so we've kind of just have always been friends in the AppSec rails, Ruby on Rails. They used to really love Ruby for some time there, so, yeah.
Mm-hmm. Very cool. Um, you know, it's an interesting time to start a security company.
It is, yeah. It's always an interesting time to start a security company, but this is a particularly interesting Time. This is, it's a heck of a time.
A lot of people were saying, where's the innovation? Mm-hmm. A lot of people were saying AI is the greatest thing to happen to security.
A lot of people are saying AI is the worst thing to happen to security. Yeah. AppSec has been kind of where a lot of the action in security is.
Yeah. Pipeline security, you know, all, all the software pipeline security. That's why kinda stuff.
What, where was the passion for you, James, that said, this is what I, this is what the world needs. I could somehow make things better Yeah. By doing this.
Yeah. It came outta two streams. One, I, I really felt like, um, the AppSec, the SaaS world has kind of been the same.
And I, I realized like, uh, you know, I had the whole gauntlet stuff that I worked on many years ago mm-hmm. And then just like, I care about, uh, developers having a good time with security products. And I felt like we just still really hadn't delivered on that as an organization.
And, uh, two, fortunately whenever I called my buddy Ken and I tried to convince him to start the company with me, he had been having a really frustrating time with Code ql, uh, their internal, they, they, they acquired that product and were running a GitHub. And so he was, he was ripe to, to do something new. And we knew that, like by looking at the context of what's going on, like how the surface is changing, what kinda language and framework they're using, how the developer decided to write the thing and why they're doing it, what led to that, and how, how it's overall designed and architected, and how that application's actually gonna be used.
All that stuff really, really, really matters. And, um, and that's how you can find real meaningful risk that doesn't match, like SQL injection or cross-site scripting or all the stuff that we've been talking about as an industry for the last, you know, I don't know, it seems like 20 plus years. Absolutely.
Yeah. Absolutely. Now, you know, you, you look at all that.
So I, you know, I've been in this DevSecOps thing now for 10, 12 years. One of the things that I, you know, hindsight's always 2020, right? That's Right.
That's right. That's right. Yeah.
But one of the things that, looking back I realize might have not been the smartest move we made, was really emphasizing the whole shift left thing. Mm-hmm. Right.
We're gonna shift left, we're gonna shift left some more, and when we're done there, we're gonna shift left even more than that. We're gonna go as far left as left can go. Yeah.
And I think in retrospect, thinking that developers would be able to use security tools designed by security people was a mistake. Yeah. And maybe we should have been emphasizing shift everywhere.
Mm-hmm. And maybe we should have designed security tools for, excuse me, for security for developers. Yeah.
Not for security people. I, I believe that last point is that that's a salient one because it's, I mean, the idea of shifting, it's, and, and a lot of the organizations we talked to as we're kind of building the company, and as we, we discovered, we discovered two, two key facts that, like, they felt the penalization of all those security tools being put on them. So nobody really loved, like the, the alerts and the Christmas tree of lights that they were always given, and developers weren't having a good time with that experience.
So the stuff that got shifted either got turned off or got muted or got unshifted. Um, and then we also realized that, uh, security leaders or, or engineering leaders in, in that case too, their, their code is changing constantly. Like, um, some of our customers have five, 600 developers.
Their code changes a thousand times a week. 2000 times a week. It's, it's e easy like that, that's, that's not unreasonable for them.
So now how do you find risk whenever you have that constantly evolving and, and it's only getting faster? So when those two forces are, are joined, uh, yeah. The tools that, that we had shifted weren't really Right.
They really needed a whole new class of tooling built just for, for developers to kind of solve that, that problem. I agree. Yeah.
Yeah. I agree. Um, there's been another sort of movement that I think is exerting a gravity pull on, on this whole orbiting thing, and that's platform engineering.
Yep. Right. We've seen it.
com Yep. As a, as a result. Yep.
How do you see that playing into this whole EC ops? How does it affect dry run? Yeah.
I think platform engineering is an interesting group. And specifically like we play in the infrastructure, well, some of the infrastructure is code that people are working on. Um, can I tell you a story about one of our customers?
Sure. We got, uh, I won't, I can't name their name, but, um, they're like a direct to consumer, uh, business. And they got it, um, we'll call it 60 70 developers.
Um, we came in there through the, uh, through the platform or the SRE team who was just trying to like say, how do we give security tools that work? Mm-hmm. Well, part of our product is like we, we, we ship traditional SaaS.
Like we, we can, we can beat the traditional players of SaaS, but one cool thing that we can do is find risk, um, that, uh, that you can't find. And we through in like traditional patterns, and we call that natural language code policies. And for every customer, we sit down and we start out, and we will usually build them out a natural language code policy that says something simple like, is this code change?
Adding sensitive data to our logs? So every time the developer's making changes, are they like, now emitting customer data or P-I-I-P-H-I or whatever to, to logging, you know, we've all been in the organization where it's like, you get audited and then like then, uh, somebody, um, somebody says, Hey, look, you got some whatever PII or, or some sensitive data in your logs. And then you gotta look back for 12 months and now you got an issue, a, a report and you gotta like, you know, have some sort of disclaimer on your audit or your compliance.
And if you have a tick mark on that, um, you also get stuck in a situation where like, now you're trying to triage, like, how do we ever stop this from happening again? So I called up our customer, we just, just signed. I was like, Hey, uh, how's it going?
How's, how's it been? You're like, week two or week three. He's like, that, that PII, that sensitive data logging thing hit last week.
And, uh, within 24 hours, the developer I got with 'em and told him like, Hey, we can't do that. And they were, but they were dropping data, customer data dumps for this new like LLM like recommendation engine that they were building. And we said, uh, uh, uh, let's get that fixed.
And so we were just, we were just going through like how much that would've cost, uh, to remediate and under like, our traditional lives that we've ever handled before. It's like hundreds of hours, uh, to deal with that problem. But if we can just deal with it in code before it, uh, gets shipped or gets shipped all the way, or redact it as soon as we can, um, you're able to, you know, do do amazing stuff there.
Yeah. Absolutely. But you can't find that with patterns.
And that's where our natural language code policies really, really gets into finding new types of risk for folks. What I find interesting with it though, the platform engineering stuff, James, is it's kind of like telling the developers, I know you want to build quality code. I know.
Maybe you don't want the Christmas league tree Yeah. Security thing. Yeah.
We're going to build the environment for you. Yeah. I, I think wanna, again, hindsight, 20 20, 1 of the things about DevOps is we told developers, look, you got everything.
Yeah. Including building your own platform. That's Right.
Right, right. Alright. You live and learn and you adapt.
Right. And you, it, that's, that's DevOps. We iterate, we reiterate and iterate again.
Yeah. Um, and it, it is an interesting thing. I think AppSec is a, is a perfect playground for that.
If or not a playground 'cause we're not playing, but a perfect, uh, use case. Yeah. It's for it's natural overlap that, yeah.
Now you mentioned a few times that you guys are using SAS technology, SAST for our, uh, yeah. Audience out here. That's static code analysis.
Yeah. Or it's Yeah. Static application security testing is the, the acronym and Yeah.
Yeah. There are other kinds of tests, das and Yep. Some other, there's proprietary kind of, everybody makes a few I asked and stuff I asked is another One.
Yep. There's, But the, the important thing is you recently, and I didn't talk about this with you, but I, you know, I follow you on LinkedIn. Yeah, Yeah, yeah.
You recently, you guys recently published a study Yeah. On speed. 'cause speed is important when it comes to scanning on speed and dry runs.
Yeah. And accuracy. And accuracy.
Excuse me. Yeah. Yeah.
Tell us about that. Yeah, So we, we had, we thought, alright, we built these, this really cool platform and we really invested a lot of time building the engine. And then we, uh, created across, uh, four different languages, 26 different, uh, kind of easy to get vulnerabilities, but we wanted to just test effectiveness.
And then we, uh, took some of the popular tools like Sim GRP and Sonar Cube Snyk, uh, code QL from GitHub and, and then ourselves. And then we just started committing all this code in that had, uh, these problems. And, uh, we were really surprised, uh, to just, uh, what happened is like we, because our approach is remarkably different, like we were double the effectiveness in accuracy, um, than the next, then the next category of tools.
Um, and then even in that category, there's quite a bit of divergence from like, uh, who's kind of coming, I think outta the next one in like the 40 percentile was like re but then like some of the other ones were like in the 10% or 8% percentile. So, and we dry run was in the 80. We, we got, I think we had an 88% on the, the scoring there.
So it's a limited data set. We have some more, um, languages and stuff we're gonna continue to release, we're really excited about. But we really wanted to show, like, as an industry we've been at really, um, we've been really hooked on the idea of static assessment being like matching patterns and parsing like code trees and looking for source and sync and stuff.
But contextual security analysis that does like a more holistic look, uh, building up this code context window, like we talked about. Um, it's way more effective. You can learn a lot more about your system.
Uh, it actually speaks to developers 'cause it's giving them relevant feedback about the stuff they're actually working on. Um, and we can tell security people like where their hotspots are, where what matters, what, you know, what, what they're seeing in their organization. So Of course, this year's show, like last year, frankly, we're hearing all about AI agenda ai.
Yeah. How's that figure into the dry run kinda strategy? Yeah.
I think that, you know, we are, we have a lot of LLMs under the hood that we're using to, to do a lot of our analysis. Each of our analyzers are tuned to look for their own specific things. Um, our natural language code policies are full agentic where they can go find out the real truth about a system.
So instead of just saying, we think you have a vulnerability, we can go dig into the code to, to find out if that's, uh, really true. Uh, customers love it and it's, and it's way more accurate. So that really, really helps on that.
So, um, I'm, I'm excited by what, what AI is providing to our, to our industry and like what it's allowing us to do. And, um, I think the results, the results in that report kind of speak to themselves of like how much more accurate we can be. Um, 'cause and that's really the key.
'cause we need, you know, going fast by in and of itself is not enough. You need to be fast and accurate. Accurate.
Yeah. I remember, um, I think it was in London at one of jean's, uh, DevOps Enterprise Summit. I was doing a video with John Willis and Damon Edwards.
Okay. You know, it was, it wasn't about security per se, but it was about DevOps. Okay.
But fast secure, what were the three things I want to do faster? Code Resilience, maybe resilience And security. We can, we do want it all.
Yeah. And so having fast results that are not accurate Right. Is having no results.
Yeah. Yeah. And that, That's Really the thing in our report, we kind of call that out.
We're like, some of the ones that were like, out of our payloads, they only found one or two. It's like, that's really scary. That means you could check in like legitimate, you know, problems and nobody says anything, but you do it quickly.
So, you know, that's, that's, that's, I, you know, you gotta watch out for That. It's, I remember back in the day when endpoint security similar kind of thing. Yeah.
Yeah. Because let's face it, semantic McAfee, back then you installed that on your machine. It was a pig.
It would slow your machine down. Yeah. And so a lot of the AV companies were making their whole bones on, Hey, we're faster and lighter.
Yeah. But faster and lighter. That doesn't catch viruses.
Wasn't a great antivirus. That's right. Yeah, yeah.
Yeah. It's the same thing here. Yeah.
James, what's the website? Okay. So if you just go to dry Run Security, um, and then right on the front page, it just says like, get the 2025 accuracy report and you click that button and, and we'll ship it to you right away.
And how about people maybe want to try out dry run security? What's their best on-ramp? Yeah.
There's two, two options. So if you want like a self-guided tour, you can go to Dry Run Security and install the GitHub app there. Or GitLab is coming soon.
Um, or you can click, uh, I think there's a button there. This is like, talk to an AppSec expert or whatever. And we'll usually sit down with you for 5, 10, 15 minutes to make sure, uh, write a natural language code policy with you and kind of get, get people up and running, but super lightweight to get to get rolling with it.
So, Hey Alan. Thanks. Congratulations.
James Wicker, one of the nice guys in this business, dry run, do security. Check it out. We're live at RSA.
I think we have one more coming up. So stay tuned. Good afternoon.
Welcome back to Techstrong tv. Coming to you live from the second day of RSAC bustling with over 45,000 cybersecurity experts. We've been having great conversations the last couple of days with experts in the field.
There's a lot of risk, there's a lot of challenge, but there's also a lot of opportunity. We're gonna be talking about some opportunity in the blurred lines between a personal and professional lives. I've got a couple of guests with me here.
Matt Covington, the global head of product at Black Cloak joins us. Thank you. And John Boyle from our very own tech strong team, Phil, CTO, and tech strategist.
Welcome guys. Thank you. How's your show been so far?
Fantastic. It's been, it's been great. It's been busy.
Lots of impromptu meetings with old colleagues, which is always very enjoyable. I always think it's like a reunion. Every tech trade show is a Reunion, Which I love You, a new friend face to face for the first time too.
Right. Absolutely. I met you name, like I know you from Zoom.
Exactly. So Matt, talk a little bit about Black Cloak. I know this is a pioneer in digital executive protection of DEP, but Yep.
The company was founded just a few years ago. Mm-hmm. I love the name Black Cloak.
It's a great name. Yeah. Uh, what problems or gaps in the cybersecurity market were there back in 2019 when the founder said, there's a problem here, we've got a solution.
Absolutely. I think what it really comes down to is what is the definition of your attack surface as a company? Right.
You know, traditionally you think about your, your hardware, the software, there's, you know, network telemetry security, there's boundary security, there's external security. Increasingly as little as they may like, the fact executives themselves in their home lives are increasingly becoming part of that corporate attack surface. And so really the founding mission of Black Plug was to provide security services that a CISO could buy that could protect the executive in their home life.
Whether it's personal devices, uh, personal computers, uh, and all of that security service wrapped in a sort of user-friendly concierge Yeah. Uh, kind of service. And so our, our guiding principle from our CEO is where every time we have a feature is could mom use it?
Right. We are not selling to, uh, technical people who are very technical knowledgeable. Okay.
It's really all about, you know, is this easy to use? Yeah. Uh, yeah.
That's, that's our guarding Path. John kind of brings some color here. Uh, it's never anything that I thought about.
I don't live in a cybersecurity world. I cover it, but, you know, it, it's just not something that I thought about in terms of, of executives leaving work, whether it's working from home or working from an office back in novice these days and having their personal lives be bombarded by these threats is, have you seen a trend in the last few years of this going up? So I think this was new to me.
And one of the things really that's great about this is you find some new things. There's a lot of topics that are really hot out there. Yeah.
But one of my joys is finding and, and connecting the dots between the technology new technologies and services to something like my parents who are healthcare executives. And that, and you think about healthcare, it's critical infrastructure. Right.
It's important to us. And so when I, uh, engaged with Matt and we talked about black cloak, I had not really heard of the term digital executive protection. And so it was new to me and my job was to figure out how to describe it to my dad, Bob, so Bob understands it.
Yeah. Which was better. So I think that I would say growing up with two healthcare executive parents, the problem's always been there.
Yeah. It's just that the nefarious people out there doing the attacks, they're realizing that the home life is an island hop away from the enterprise. Absolutely.
The bad guys don't respect that boundary. No. So it's Incredible.
They don't respect anything. No. Well, this is true.
They, they, they, they Kind of have a reputation for not respecting anything. But it's just, it's so interesting in the last few years with the explosion of chat GPT on the scene. Every company is ai, ai.
We've gotta have an AI story. Yeah. We've gotta enable our executives.
They need to, they need to have, especially during COVID 24 7 con communications with their team. Right. And so you're talking email, slack, text, WhatsApp, you name it, LinkedIn, all of these are now attack elements.
Yeah, absolutely. It's part of the attack service. I think one of the things we were really careful to try and do early on in the life of the company was kind of create a value proposition that gave the CS o on the one hand, the assurance okay, that folks are protected.
But on the other hand, we were talking directly to the executives themselves. Right. We were onboarding them.
Everyone gets a personalized Zoom call where we'll onboard them. We'll, we'll walk them through installing the app. Okay.
We'll describe our services. We'll ask them whether they have any particular concerns, and we don't share all of that personal in information back to the ciso. Now we'll give them enablement, uh, data so they can tell that Yes, I bought it for my 12 executives.
And yes, all of those 12 executives have now been through their onboarding. But there's a lot of the, a lot of the time you're not necessarily comfortable having your corporate IT team knowing everything about your social media posts. And yet that is an incredibly, uh, incredibly interesting attack vector Sure.
For the cyber criminals. Sure. And so we try and straddle that.
On the one hand, we have a have to have a relationship with the, on the other hand, we're really in business to serve the exec, the members themselves. Yeah. Yeah.
How much of it is, is behavioral of, of education, of le of making these executives aware? Look, there's no boundary anymore. Yeah.
This lines are blurred. How much of that is, is really just educating them and is it, I don't wanna say, I don't want to say it's an easy conversation, but they probably get it pretty quickly. They do.
Uh, one of the things we do, um, so, uh, our team will show up to that initial call with some initial findings. And like oftentimes, well, you know, we found this street address by looking at the dark web. Was this associated with you?
And somebody will say, God, I lived there 11 years ago. That's really out there. Me too.
Exactly. Yes. So typically we'll sort of softly introduce these elements and say, Hey, look, just so you know, all of this information is out there and available, and this is what we're here to talk about today, is making you safe.
You can take a, you can take a deep breath, you can take a so relief. We're, we're here to solve those problems for you. And then you get there.
It is much easier Conversation. I'm sure it is. Because it's, well, the threat service, I mean, there's just more and more vectors every day with the absolutely amount of data that's produced, all the applications, all the software.
And that's not gonna slow down. Well, The other thing is that it's not just the data online. The way I, the way when I talk with Matt immediately, the way I described it, I mean, it was the image I got.
And if anybody's seen the movie Usual Suspects, Kevin Spacey, Kaiser Soce, because how many times have you sat at a stoplight and you look at a minivan like, oh, they got six kids. Two of 'em are girls. The youngest one's a boy.
They have a dog. Uh, they like this sports team. And, and so the, the message of that movie, if people have haven't seen it, is that this person being interviewed by the police weaves the story of this, this mysterious Kaiser soce, um, with information that's behind the guy, you find out the end on a bulletin board.
Mm-hmm. Right. And that also, we have six kids at home, or not home anymore.
They're not, but, but they're on Xbox, they're on Facebook, they're on Instagram. They're posting pictures of themselves flipping a water bottle and celebrating. I mean, all these things that can be a story that's woven that, um, can be compromised.
So it's not just digital, it can be anything. Right. Mm-hmm.
And it's absolutely education. Yeah. Well, because it's, I wouldn't think, I know those stickers you're talking about, like on the back of the minivan that shows like the dad, the mom, the kids, the dogs, the cats or schools, or a proud parent of an alumni at this university.
Nice Job, Mary. You got a's That's great. I'm your dad's friend.
You know, how's your dog doing? Yes. You know, I Mean, and we don't, sounds weird.
Think that Absolutely. Because it's, it's kind of like a personal freedom. But now we have to be careful about that.
You, but you guys are, you're talking about entertainment personalities, athletes. Yep. Um, other highly visible personas who That's right.
Are susceptible and probably highly unaware of this because they're just going about living their daily lives. Absolutely. But now they have to be aware of this.
And I think that's what we provide. It's peace of mind and that expertise to take care of these problems for you. And again, a lot of what we're doing, uh, things that if you had infinite time and a lot of, you know, a lot of interest in it, you could figure out how to remove yourself from data brokers.
Yeah. Much better to let someone else take care of that for you. And so there are many elements of what we do.
There's part of a, a SaaS platform, which is doing things, data broker removal, identifying breach credentials that have been stolen. We even do like an attack surface style scan of our members home networks to make sure there are no vulnerable services, uh, exposed. There's a lot we do there.
But as you said, there's also an element you can't necessarily automate, for example, reviewing some of these Facebook settings to make sure they're appropriate and they're not oversharing. Yeah. And so on the education side, that's absolutely something we can do.
And our members at any time, they can go into the application, they can schedule a concierge, uh, appointment with a member of the black club team who walk them through those things. We get all kinds of interesting questions. I bet.
For example. Yeah. And traveling, traveling to China, what should I do?
Should I take a burner phone? What should I do when I get back? And so that's really what we're there for, is to be, it's beyond just simply the features of the automated service.
It's really to provide that expert guidance in all aspects of, uh, digital life, but also going into the physical as well as you said. Yeah, That's a great point. Going into the physical as well.
Yeah. And I think the other thing is we, and I think you, um, if we go to traditional benefits companies provide to executives, there's a reason why when I was at Oracle, so many people could travel on an aircraft together. Yep.
There's a reason why companies provide key person insurance. There's a reason why, um, some companies like the, the big, uh, OEMs will send their executives once a year for MRIs and those sorts of things. Right.
They're all preventative. Yeah. Mm-hmm.
Because my mom and dad's world, as we talked about, you can go do, have a preventative exercise and it, it's gonna cost you something, right? Mm-hmm. But there's a much steeper price for the major medical when you, you know, you find something out later.
And so I would say, people say, well, is this the CISO's job? No. This takes a burden off the ciso.
Yeah. And it, but provides a buffer. But I was talking with you and, and Tracy, uh, their chief marketing officer, I said, if I was to tell somebody this is, this should be an HR must do.
Absolutely. And it's not just a C level. You have people that are vice presidents.
Um, there's a lot of people in, you know, I group of some people who are, uh, you know, in Hollywood, and they didn't grow up like that. Mm-hmm. They didn't start that way.
They weren't born into it. And so they have the privacy. And so whereas Warhol said everybody wants their 15 minutes of fame.
My quote, the first thing I ever I ever tweeted on Twitter was anonymity is the fame of the future. Mm-hmm. Yeah.
Because absolutely, you need to, you know, you need your private life. And these guys here, um, are are just there to help. And, and so that when you, when Bob comes home, my dad and he wants to watch my ball game, and you know, he can unplug too, right?
Yeah. But do so with confidence that everything they do is not gonna be used against him in his job and in a, in a nefarious way. Yep.
And so I was very impressed with what they're doing. It's a service and a solution. Yeah.
And it's something that my dad, for instance, should be doing. My mom should be doing. So Bob's got it.
No, Bob needs it. I wanna talk to Bob, introduce you to Bob, we'll get it done. We'll deal with Dale.
He Gets the concept, though. He gets the concept. Yes.
I, I was reading on the website that Black CLOs DEP solution provides 14 pillars of protection. Yes. Summarize that for us because Absolutely.
It is. This Is the anonymity John that you talked about is that's a luxury that a lot of people don't realize I want that they don't have. Yeah, Absolutely.
And so we, around those 17 pillars, we have data broker removal. We are looking for breach credentials online. And again, the company is probably doing that for their corporate email address.
Who is taking care of that for the personal email address. The spouse's email address. As I said, we do home network scanning.
We even have what we call our deception engine. And so if you have black folk installed on a PC in your home and somebody is on your network and looking at what services are available, they're gonna see an FTP server. If they try and look into it, it sets off an alarm in our, so where we'll jump into action to protect them.
So across the full range of security, privacy, even into things like home protection, we'll remove the image of your home from Google Street view. Wow. 'cause like that, right?
Yeah, Exactly. We started to see some really scary, uh, extortion where emails, where that was front and center as in, we know where you live and therefore you better do what we say. Right.
And so we're always finding new ways to add capabilities. We just launched something called identity verification, we think is going to be really the next exciting thing for us to talk about. And this really, if I have my circle of trust with my family, and then I get a phone call or a message from one of my kids saying, Hey dad, and he sent me a thousand bucks so I can bail myself out.
Right. I don't wanna take that on faith. And so if we both have black cloak on our app, I can send an identity verification challenge Yeah.
Over the air that he can respond to. And so if it is him, he can click verify if it isn't him Yep. He can click deny.
It's just an additional step that we're able to take. So within the family or within a work group, you can trust you are speaking to the right person. 'cause both of you have black cloak on the device.
We know the device is secure, it has a secure connection to black work cloak. So we're able to sit in the middle there and mitigate, uh, and work with these identity and verify requests. So we've actually been talking about that a lot this week.
Yeah. We wanna talk about feedback from it. Yeah.
That's Amazing. I think the other thing though is that people say, well, what, what industries need this technology? Here's the thing every is that we talk about healthcare, financial services, energy, heavily regulated mm-hmm.
Critical infrastructure. Yep. We talk about nonprofits.
Where do government officials go a lot of times to work after they're done? They go to a nonprofit, a foundation, they have relationships back at intelligence community, DOD state. Right?
So it's an island hop away. And, um, I would say that it, I looked at this, I'm like, yeah, every, every organization who is responsible for protecting a service or something that is the fabric of our communities like healthcare, are responsible for engaging these things proactively. And so, uh, I think it's a HR thing.
I think that it, I agree with you on that. It's not, it's not a C level, it's not a c CTO or CSO or a CTO thing. It should be part of every HR package.
And the other thing is that you think about like, why we're all here this week, I would say, why do we fight? Yeah. Yeah.
We talk about the, the, the bottom line. We talk about the brand, the data, the end of the day we talk about healthcare. There's kids in the nicu, there's people have cancer records.
A mom was in the hospital and she coded in her room. And what if the lights went out then, right? Mm-hmm.
So, so these organizations are protecting human lives. Yes. We, we, we gloss over that.
Yeah. Yeah. So this is a way to make sure not only the family is protected, but that that connection to the organizations that are taking care of a lot of people are, are doing that extra layer of defense that is just a no brainer.
Yeah. I mean, Oh, it's, it is a no brainer. Yeah.
Are you seeing, pivoting on what John just said? Yeah. Are you seeing any talking about healthcare, financial services, insurance, some of those heavily regulated industries that have a lot of personal data on us?
Yes. Are you seeing leading industries that block clo locus working with, or this really seems to be to be a horizontal play? I think what we tend to find with a lot of security use case financial services tend to have the budget first.
Ah, but yeah, we, financial services healthcare very strongly represented. But it is across the board, it's all kinds of companies. We have consumer goods companies, we have food processing companies, uh, you know, just about any market segment you care to name, there's probably somebody in startup portfolio there.
Because the, the issues aren't industry specific. Right? No.
No. And so Is this the new way of life for executives? That's a great question.
I think it is. I I, and I say that because at the end of the day, the risk, the bad guys aren't going anywhere. Right.
The tools at their disposals are becoming increasingly sophisticated Yes. With ai, right? Yes.
Yes. You know, and particularly with deep fakes and sort of I was gonna ask that. Those are DeepFakes are crazy.
E exactly. It Just amplifies the problem. Yes.
Exponentially. It's sort of one of those, the song remains the same. Right.
I'll go for the left Reference. Definitely. Yeah.
Now we're Ripping, it's all about, uh, it's about spear phishing attacks, but the sophistication of those attacks when you can just grab 30 minutes of audio of a, of A CFO giving their earnings report, and you can feed that into a internet website and you can have them say anything at all. Anything you want that Yep. Right.
It's incredibly important that, you know, we, we have tools and services available. And again, that was really the, the genesis of identity verification. It was sort of like Google Authenticator, but you know, to verify between two individuals that yes, you are who you say you are.
I, I am who I, I say I am. And deep fake really, I think was driving a lot of concern for members of, we, we just don't know what to do. We don't dunno where to turn.
Is There a consumer play here down the road? Because I could see this being something that everyone is gonna need at some point, probably in the near future. That's a really interesting question.
I I think it's definitely the case that, I mean, you made a good point about, you know, it's not just the executives Yeah. Anybody in an organization who has a public facing role. It can be executive, uh, assistants, it can be the finance team, right?
They're dealing with vendors often. And so you're looking for all of those edges Yes. On the organization.
So I think there definitely is a hierarchy, um, that certain individuals, like it or not are going to be richer targets. Right. They they have more money.
Right? Yeah. They have more influence that I could potentially exploit as an attacker.
Um, but yeah, I, I do think a lot of these services, if you look at, you know, a lot of these, uh, consumer identity protection services are starting to get more into these areas. I think what the take we tried is to what needs to be different, right? For like the busy executive to engage.
They're not gonna sit down and fill out a, you know, four page form to our board. Right? No.
We need to make It easy for them and seamless. Yeah. Seamless Integrated.
You know, it's, it's also when you look at, you know, when you look at the, the consumer solutions, their, their technology solutions, the software, their apps, and, and the thing that Black Plug provides that's always compelling them remember, is the concierge service. Mm-hmm. They're the ones that get called at 3:00 AM It's not an automated thing.
There's people, there's education. And so I think, I guess the way I would describe it as, you know, you people buy a Porsche for a Porsche or my wife will say Porsche, sorry, Porsche. I know.
It's like that's, that's the northwest to be coming out a Porsche. Um, and you know, there's been attempts where Porsche or other, other companies that are trying to target that, that certain audience for a purpose try to make like a Toyota and well, there's a reason you make a Toyota versus a Porsche. Mm-hmm.
Um, I think that there's application there, but I think that you don't want to, as we say in the United States peanut butter spread it and take away from the focus they have. Correct. Because there's a lot of work to do Right.
There. Couldn't have said it Better myself. Very Well said.
Yeah. Drop Your mic to that. Right.
Absolutely. Guys, thank you so much for coming on the program and explaining what digital executive protection is like to you. That was a new term to me.
Mm-hmm. Um, just kind of opened my eyes to, wow, this is a new way of life for executives, but that you have the solution Absolutely. That is able to really educate them on this risk landscape Yep.
And help them protect themselves. Perfect. So I'll end on my one note from the article that in the movie they talk about the devil's greatest tricks.
I use that angle. Yes. And my closing statement on the article when I first met Matt, was the gr the devil's greatest trick is not piercing your firewall, but making you think that your executive's home life doesn't matter.
Yeah. Yep. Absolutely.
That's basically it. Wow. And and that's your job.
Everybody out there proactively Yes. To take care of this Yes. And avoid reactive incident.
Absolutely. Absolutely. This is fascinating.
I'm gonna be following Black Club. Thank you so much guys, for you. Pleasure.
You having me describing the, the risks, but also the opportunity and the ability to use technology for good. Yeah. We appreciate your insights and your time.
Yeah. Thanks for having us. All right, my pleasure.
For my guests, I'm Lisa Martin. You're watching Text on TV Live from RSAC Day two of our coverage wraps up with one more interview today. So stay tuned.
I'll see you in just a few minutes. Kubernetes pours a sidecar quantum navigation, T SMCs A 14 AI process. We're gonna reset some things to factory defaults.
CCF stops a release, HPE gets even more secure. And then we're gonna take a look at some of Intel's future layoff plans in this episode of the Tech Field Day rundown. Hello everyone, and welcome to the Tech Field Day rundown.
Today is April the 30th, 2025. And, uh, I have a, a confession. It's, it's actually three days in one that are all slightly related.
'cause it is National Oatmeal cookie Day, it's National Raisin Day. You can see how those things are related. Uh, and it's a national honesty day.
And, uh, honestly, uh, oatmeal raisin cookies get a bad rap from pretty much everybody out there. Uh, so yeah, there we go. Uh, leave your comments in the, uh, in the video below.
If, uh, you believe that oatmeal raisin is a superior form of cookie, of cohost is joining today. Well, today is an awesome day. Uh, there's a lovely storm raging outside, and I believe you've got a storm as well.
So we're sharing weather for a change. Uh, that of course brings us to something that neither of us are overly concerned about, which is National Hairstylist Appreciation Day. This wind is clearly not appreciating your hair stylist.
Unfortunately. It is not. But what we do appreciate around here is a lot of great news stories, and it's, it's been a fun week as we're wrapping up April, and we've had some stories that we wanna take a look at some fun stuff and honestly, some not so fun stuff.
But we'll get to that part towards the end. First thing we wanna do is kick off with some news about everybody's favorite container that isn't named Tupperware. 3 now includes native support for sidecar containers, which makes it easier to manage and deploy them alongside apps.
This update also improves routing, pod placement and storage handling while adding some new features for security and resource management. Al, I guess the biggest question that I have about this is, are we gonna be able to find all the Kubernetes lids for these sidecars? Well, hopefully you'll end up with matching lids and sidecars along the way, uh, as, as we want to keep our containers secure with those lids on, uh, sidecars are, are a really important characteristic of Kubernetes and, and, uh, a really common pattern for building container-based applications.
Uh, for those who haven't come across them. The issue with containers is that they hold a single process. And so where you need maybe an, an additional process to send logging messages or another process to handle maybe some sort of data delivery, uh, this is achieved in Kubernetes through this concept of a sidecar.
Uh, there's another container that runs inside a portal alongside the one that's running your application. And you can imagine that quite often there's a dependency that these sidecars need to start up before the application starts up. And that's the big change here, is that there's built-in support for that in Kubernetes, rather than every customer needing to build their own into their own application, maybe that application having to retry until the sidecar is up and having this dependency mapping essentially inside the pod is really very useful and reduces effort by, uh, large numbers of customers who are using sidecars extensively.
Uh, I think it's a, a recognition that this has been a point of paying for many customers, that dependency management, and it's required lots of customers to solve the same problem, which to me always indicates that there's a feature missing in the product. There's some other cool things in this. Um, as you mentioned, there's pod placements, things that are, uh, oriented towards places like cloud providers.
We have multiple regions and, uh, multiple, uh, data centers within a single region. And there's some awareness and traffic being sent within the actual, um, what AWS would call an availability zone within the data center. So you're not being hit with charges for moving traffic unnecessarily between those, those, um, availability zones.
I would would also flag that this continues, um, an interesting challenge that customers have. Enterprise organizations struggle with a pace of change in Kubernetes. Kubernetes is relatively for a cloud native application.
It's actually slow moving. There's only three releases a year, but there are three releases a year to stay up to date. And there are significant challenges for organizations that have standardized on Kubernetes, but not standardized on where that Kubernetes runs.
And so they might have some Kubernetes and AWS some on-premises, some running in Google, some running in Azure, some running in a service provider as well. And there are some complexities around getting everything to be at the same version. It's not like you can simply apply the same service pack across all of the operating systems because you don't control the operating systems.
And of course, new features are only available once the underlying Kubernetes platform has been updated. Now, good news is most of the providers have a pretty fast cadence of catching up with the, the latest release of Kubernetes and their underlying platforms. But then there's sometimes some challenges about getting new versions of the Kubernetes agents or all of of the other components, all of the operators and so on, getting deployed out, uh, to all of your worker notes.
So although it's relatively slow for a cloud native platform, that three releases a year can be quite challenging for enterprise organizations to get the best value outta these updates to Kubernetes. 33, once like seeing open source products with a one at the beginning of the version number, um, means they're actually fit for use. Um, Kubernetes of course has been awesomely useful for a lot of organizations for a long time.
An Australian company just over the pond from us, or as we like to call it here in New Zealand, the West Island, uh, an Australian company Q Control has launched Ironstone Opal. It's a, a, uh, compact quantum navigation system Hmm, outperforms GPS and it uses the earth's magnetic field in some really funky sensing rather than using the geostationary satellites. Uh, highly accurate, really useful in the many GPS denied areas.
And we've seen cases of real problems with GPS jamming and, um, provided getting it in the way of our universal expectation to know where the heck we are, uh, much higher precision in in their testing, uh, small enough to be used on drones and vehicles and for defense use. Uh, Tom, as you are heading out into the backwards, do you think you'll be using ironstone op? Uh, I probably can't afford it at this point, and that's probably gonna be the biggest thing we're gonna have to deal with here.
So I dug into this a little bit 'cause it had quantum written all over it, so obviously I have to talk about it. Here's the thing. Um, Q Control took a quantum magnetometer and they are, that's, that's the little cassette thing.
It's, uh, probably about yay big. I, I don't know what this is in science units. It's, it's this big.
And what it does is it detects subtle variations in the earth's magnetic fields at specific points all around the globe. So essentially what it's saying is, is that if you drop one of these magnetometers anywhere on the planet, it can read the magnetic field and tell you where you are. Okay?
That's not true. The magnetometer can tell you the reading of the magnetic field. What needs to happen then is you are going to have to have advanced denoising capabilities to basically, uh, filter out all the junk.
And then there is map making software that co control makes, that will tell you based on the reading that you got from the magnetometer where you are now. If you read through a lot of the stuff out here, and I'm not talking about the press release that coup control put out, I'm talking about like the ARVs paper that they put out and all the other stuff. They are not at this time saying that this is a replacement for GPS.
It's a backup for GPS. And the key thing that is valuable to them is that it is a passive system. So everybody, I hope at this point, knows that GPS works by you walking outside with a GPS receiver.
And if you can get in a lock on three to four satellites, then you know where you're at, or more appropriately, your sensor knows roughly where you're at based on the times delay that you, you get going to the satellites, that's great, but you can jam satellites. And we've seen that as becoming a bigger deal now because you've got, um, you know, the US has one, uh, set of GPS satellites, uh, uh, Europe uses, I believe Magellan, which is a different set than or operate a little bit. And then you have, uh, Russia uses its own set of GPS satellites.
And a fun fact, the reason why we have public access to GPS is because of the 19, uh, 83, uh, Korean Airlines, uh, flight seven disaster. We learned about GPS in like, what, 83. And it really didn't come become commercially viable, I would say, until the late nineties, early two thousands.
So that's 20 something years, 15, 20 years before that technology became commercially viable. We are just learning about this quantum GPS technology. Don't get me wrong, it's absolutely cool, but the cost is probably gonna be off the charts right now.
So here's what I expect is gonna happen, because there's already reports that Lockheed Martin is working with Q Control as a supplier to provide, uh, this as an assistance for, um, devices and things that are operating in GPS jammed areas. You should just read that as defense applications and bright, uh, neon letters. These are gonna go inside of Humvees, these are gonna go inside of jets, and these are gonna go inside of things that jets shoot at Humvees missiles, bombs, whatever, because that's important for precision work.
We might see something like this, maybe two or three revisions down the pipe. So don't chuck out your GPS receiver yet. I'm not gonna strap one of these quantum magnetometers to my, my back while I'm out on a run.
Just know that they're working on advancing this technology and making it jam proof, making it cloud proof, making it indoor proof. Um, but remember that just like any good science experiment, being able to buy this at Best Buy is probably still a decade or two away. TSMC has announced its upcoming a 14 line of chips, which is expected to be publicly available in 2028.
They're gonna offer 15% better performance and 30% lower power usage compared to the future in two chips. The company also introduced system on wafer X, which, uh, is not something that they're trying to do to be more extreme, but it's in fact a new technology that combines multiple large chips with memory and optical connections for advanced AI workloads. Since AI is dominating the market today to support these innovations, TSMC will of course be building two brand new facilities in Arizona, and that is gonna bring them into competition with Intel who has already announced plans to build facilities in Arizona as well.
Al, is this a 14 process going to drive even more adoption of TSMC silicon for AI applications? Potentially it could. Uh, one of the big challenges in in building an AI data center is getting enough power and enough compute density, well, it's usually power density, the compute density we can achieve.
It's usually feeding it with power and taking away the heat it generates. And so 30% decrease in power consumption compared to their existing, it's gonna be pretty significant. Particularly also in here is having the optical interconnects actually on the chip rather than necessarily dependent on external, um, external transceivers, which are a, a high power consumption item as well.
Not sure just how much that's gonna be, uh, optical interconnect off the chip. The, uh, things that I've read suggest it's optical interconnect on the chip between those multiple processes that are on this chip on wafer substrate. So it's multiple chips sitting on, on the wafer and interconnected.
Um, it's a, a little unclear exactly how that's gonna come out. And fundamentally they're saying this technology is gonna debut to publicly accessible in 2028, and they're, they're still building those, um, fab factories, those production facilities in Arizona, um, as well as, uh, yeah, Phoenix area packaging plants, and, uh, there's gonna be a, a lot more construction there. So, as always, this, this is a lot of promises about what will happen in the future, and we hope that TSMC will be delivering these promises and letting them go a little, little more toe to toe with maybe Nvidia, maybe, um, other vendors who are providing AI chips and AI accelerators.
Uh, nice to see in there. Some of their enhancements are things like putting voltage regulators actually on the chip alongside the processes, rather than having to send voltage, uh, regulated voltage from a distance, which again, requires more power, um, requires thicker traces, more board space. There's a whole bunch of optimization in here.
So this chip on WA for substrate technology was launched in 2024. It is a, a thing that is, uh, has been delivered particularly for high performance compute. And we know that although AI vendors will don't like to see this, there is a definite line between how high performance compute works and how AI works.
They're not the same thing by any means, but a lot of the concepts transfer across, uh, I think this will help T TSM C continue to, to compete and, um, to compete with both Intel and to, uh, to a lesser extent Nvidia. And hopefully they're gonna be able to deliver exactly those power savings and those increased performance that they're promising. With this new a 14 program process, Convault has introduced a new factory settings feature to its clean room recovery service.
This feature enables organizations to restore critical systems to a secure, well-known good state after a cyber attack. This capability helps ensure that recovery environments are free from malware or unauthorized changes, uh, supporting faster and safer restoration of operations. It's interesting that clean room recovery doesn't quite mean the forensic recovery that I would've previously thought.
Tom, this seems like it's going to be very important as we continue to see particularly ransomware, uh, attacks and on Linux systems living off the land kind of behaviors of these ransomware attacks. This is kind of the, this is the last resort button, if you wanna call it that, because like you mentioned, there's, there's different kinds of recoveries, right? Like sometimes we wanna recover files because we wanna actually see where they were and what they were doing, the forensic kind of analysis.
Then there's the, we need to get things back operational to yesterday because we need to be able to get things operational tomorrow. And, and that's a little bit more destructive, if you wanna call it that. But, uh, then there is the, I guess maybe we should call it the Ellen Ripley option.
I say we take off and nuke the entire site from orbit because it's the only way to be sure. And that's kind of what we're talking about here. And I love the fact that Commvault offers this as an option to say, we are gonna take a clean snapshot of this system, of the site, of whatever it happens to be.
And when you hit the big red button, or blue or green or whatever color you wanna make it, it goes back to this like we, and, and I'm sure that part of this is going to be that that's an immutable copy. And and maybe you can say, well, you know, every six months, every year, whatever, we're gonna upgrade our factory reset to, to X or what have you. But like I said, this is the absolute vallet.
We are not recovering anything back, you know, that has been made since this point. And that sounds harsh. Like, like I'm sure that, uh, a resident storage expert, Mr.
Steven Foskett will be listening to this episode going, oh my God, they're gonna do what? But sometimes that's what it takes. Like think about when your iPhone is so far gone, or Android, if you're using an Android, if your phone is so far gone that you just, you've gotta wipe it and restart.
I mean, I had to do that to my son's iPad a while back. It was working, but like, it kept, uh, got caught in a boot loop because it didn't have enough free storage, because somehow in the whole thing it said, oh, well, we've, we've consumed 80% of the drive, uh, for system storage. And the only solution once it was in a boot loop, was to restore it.
Now, when I restored it, everything came back just fine. 'cause I had an iCloud backup as you should have. But this is that version of saying we have a good data copy from, I don't know, call it January 3rd, and we know that things were working well then, and we backed up the transaction somewhere else.
We're just gonna wipe this thing back to what it looked like on January 3rd and go from there. Um, use with caution though, with all, uh, you know, magic erase buttons. Uh, sometimes you get unintended side effects, but at at least, you know, you've got another tool in the toolbox because if the, the alternative is to restore from a backup from two weeks ago and then go figure out how they got into your systems.
And is this malware persistent and are they able to move laterally? Again, I I, I don't have a good answer for anything other than the Ellen Ripley option. Here's a fun one.
The Cloud Native Computing Foundation is actively working to protect the open source integrity of the Nats project. That's NATS because the company that donated it to the C-N-C-F-C NAIA is attempting to remove the project from the CNCF and relicense it under the business source license because they wanna reclaim control over those assets. Now, CEDIA originally donated Nats to CNCF back in 2018.
They want to back it out because they wanna assert ownership over the Nats trademarks and infrastructure. Now, in a blog post that we're gonna put up in the show notes, CNCF contends that those actions violate community driven governance models and the commitments that were made when the project was donated seven years ago. The foundation emphasizes that the open source projects that are in the CNCF umbrella should remain community owned and vendor neutral, and is taking steps to ensure that Nats continues to operate under these principles.
This isn't the first time that we have seen an open source project create some problems because of the business source license, because this happened to HashiCorp a while back. Uh, al you're a proponent of open source and all kinds of wonderful things. Should zenadia be able to reclaim that project from CNCF just so they can re-license it?
Well, here's the thing. Uh, usually companies take some software that they've built and donate it to CNCF, uh, because it's gonna help their business. And that they hope that by making it open source, other people will contribute to their project and improve the software and therefore make it easier for them to cont the, the commercial organization that donated the software to continue to trade and make a profit.
Where it starts to fall down is where an open source project is only being developed by the original donor, and there are minimal contributions from anybody else for whatever reason. They can be a variety of reasons. Sometimes it's about how the projects are governed and led and other times it's, the feature set is just not interesting enough to, to see development.
In that case, the commercial organization looks at it and says, well, we put all of our intellectual property into the software that we donated and, and we're not getting a return for our donation. Huh? When I make a donation to a charity I want to support, I expect them to use that donation for their benefit more than for mine.
Maybe there's some altruism that I have as a, as an individual human that doesn't really apply to a commercial organization. And, uh, what we're seeing here is, uh, EDIA seems to want to bring this thing back because they've given away too much value from the organization. They're not able to add enough additional value to the open source to be able to make their own business viable.
At least that's my interpretation of why they're choosing to pull this back. Uh, the other way that this sometimes plays out, and we saw this, um, with the database that AWS released a document DB and it was a, a clone of an open source database or, or it was actually an open source database that they produced a, a service on and some challenges around that. Cloud providers taking open source and just releasing a service, leveraging what's been donated by another commercial organization.
Uh, we do see changes in licensing around that as well. Although there's some, some fun stuff in governance here. I think the CNCF is doing the right thing by standing up for saying you made a donation, you can't take it back.
Um, that's not the way donation works. And that the important, there is a very important element here of, uh, once things have be become open source, somebody has to stand up for the open source and protect that. Uh, but also the whole idea of open source is communal development.
So active projects where improvements are being made, the requirements of customers using the software are being met by these changes. This is an important part of open source. And if it starts to fall down, if there's no, uh, if, if there's no motivation for developers to improve the open source project, this is where we're going to start seeing challenges.
And maybe we need to see if there is a way for a, a graceful exit. Uh, one of the most common ways we see this is that the commercial organization will fork the original code and we'll release a new updated version of code with new proprietary code that is not covered by the existing license. It really does depend what license was applied when the, um, nets project was open sourced.
It's a project that's, that's used and embedded inside people's applications to do message passing between different parts of the application, particularly from on-premises to cloud or across multiple clouds. Um, yeah, we'll see how this plays out. I don't think it's over battles over trademarks and open source are nothing new.
Uh, we reported a while ago on the ongoing WordPress, uh, atomic Mullen work, um, dramas. There's nothing new. Open Tofu also recently, uh, joined the CNCF, which was the, the outcome of that.
Uh, earlier Terraform, uh, closed sourcing, more drama to follow. At RSA 2025 HPE announced updates to make it cybersecurity tools work better across different platforms. This includes Integr improved integration of its networking and security tools, smarter DDoS protection using ai 'cause everything's better with AI and new options to disconnect from the internet during threats.
Wow, that would've been really useful about 30 years ago when the first email based threats were coming in. Uh, HPE also added features to help protect data in the cloud and AI environments aiming, aiming to simplify security and make it more flexible. Uh, Tom security is you tell me what the heck's going on.
Um, this all comes down to everybody's favorite Explorer, Dora. Well, okay, not Dora the Explorer, although if you wanna say backpack, say backpack, uh, no, this is about the Digital Operations Resilience Act. And if you don't know what that is, that's because you don't live in Europe.
Uh, this is a new regulation. I say new, it's, it's, it's not brand new. Uh, but this Dora is aimed at financial providers in the eu and it is designed to keep them online when everything goes wrong.
And there's parts of Dora that now need to be implemented, and one of those is a kill switch. We laugh, right? Because the Morris Worm took down all of these systems, and man, if we'd have just been able to unplug 'em from the internet back in the eighties and nineties, we would've been okay.
But it's actually kind of more common now, common for large malware deployments to have a command and control server out there somewhere. And we saw this, uh, from, uh, a few years ago when, uh, Marcus Hutchins actually black hole, a massive cyber outbreak because he registered the domain name that one of the malware pieces was looking for as A-A-C-N-C black hole. If that domain name was online, then it was gonna stop propagating.
And just by sheer dumb luck, he found it and, and created that, and then of course, created a whole other mess for himself with the FBI. But I'm not gonna go there right now, but this is, this is becoming a more common thing, right? If the, the attackers are assuming that all of these systems are, uh, terminally online.
So all they have to do is make it so that when the system checks in with CNC server, then, uh, it'll keep propagating, it'll keep doing all this crazy stuff, and then it can be used to launch DDoS attacks and stuff like that. And so now what HPE is saying is, okay, we're gonna comply with Dora. We're gonna add these kill switches.
We're gonna add policy, uh, that allows you to, uh, you know, take systems offline until the threat passes until a certain amount of time elapses, or we're seeing, uh, no more anomalous traffic coming from these things. It's essentially a way to prevent you from continually reinfecting yourself, but also to shut down the capabilities that these people will have to leverage your networks to do other stuff. Because we've seen that quite a bit in, in the DDoS arena, right?
Like CloudFlare is talking about blocking, uh, DDoS attacks that are dozens, if not hundreds of gigabits in size. And, and that's a lot. But, you know, this is all being integrated into GreenLake.
This is all being integrated with HP Aruba Networking because all of this came out of, uh, some of the work that Phil Mara's team over there has been doing. Uh, you know, it's, it's designed to help people feel better about migrating things into, uh, an, uh, a cloud environment like, uh, HP GreenLake and, and the things that they're doing. But more importantly, uh, for organizations that are subject to dora, which if you do business in the eu, you absolutely are.
Um, you have to make sure that you are following these regulations because if you don't, um, then swiper will definitely swipe some things from you. Let's take a closer look at a story that involves our friends over at Intel, because they're still looking to smooth out their operations under new CEO Lip Bhutan. Last week, there was an announcement that Intel was gonna be cutting some more positions, and initial reports said that the rumors were as high as 21,000, which would have been 20% of their workforce.
And then on Friday, CFO, David Zenner said, uh, absolutely not. Uh, instead what he said was, each department will assess the structure that they have, and then they're gonna decide whether or not they're gonna cut positions or offer voluntary buyout packages. However, Zenner, who is the CFO, so he would know, said that maybe not all of those buyout offers were gonna be accepted.
And if you're one of those older people that's been sitting around going, well, I'll just take an early retirement, not so fast my friend, because Intel announced that early retirements are not gonna be considered at this time. The stated reason, of course, is that in the long term, previous early retirement options had led to some long-term problems that they don't wanna repeat again and again. All right, Al, I know that the rundown this year really feels like we have been punching intel to the point where the kid on the Simpson School bus is saying, oh, stop, he is already dead.
But I gotta ask the question, are we at the point where Intel can cut more to get to profitability, or are we gonna have to look at other options? Now? I think the, the headline of more people being laid off after 15,000 laid off, uh, last year with Pat Gelsinger, um, that that headline definitely reflects the fact that there is a large change being made at Intel.
Whether that means that it's a 20,000 existing staff, or 21,000, if, if those numbers follow up, um, these massive numbers of people leaving isn't necessarily the whole whole story. What very commonly happens in tech companies is that the bit of the company that is underperforming, the bit of the company that was awesome five years ago, but is no longer pulling its weight gets cut off and a new but gets grown, that is going to move forward and improved. So I do think there's a little element where, uh, Bhutan's plan, he says, uh, I will make it perfect when he speaks of, of Intel.
Uh, so he may be flowing that idea that perfection is achieved, not when there's nothing left to add, but when there's nothing left to remove. Um, not sure that that gets us to the, the forward space. Hopefully alongside these eliminations of, um, parts of the business that have been underperforming and that are yesterday's intel, hopefully there's a growth in tomorrow's intel because, uh, lip bhutan's there to make a recovery, to make a turnaround, to make Intel, uh, perfect.
And you can't do that by continually cutting away. You'll certainly reduce your burn rate on money, but then don't increase your income. You've gotta increase your top line.
You've gotta produce new products that are competitive in the market, that are demanded in the market, and that are taking on the people who have been eating your lunch recently, specifically Nvidia and increasingly ad you've gotta get ahead of these people and build new products. Tom, do you see Intel building new products, adding more replacement people for some of these? I, I don't right now, and that's part of the problem.
You, you mentioned, you know, lip Bhutan says, I'm gonna make it perfect, and yeah, when there's nothing left to remove it, it, it could be perfect. I mean, I think of the old story of the Zenith. Uh, CEO used to walk down the assembly line and he'd yank a piece off, and then when it didn't break the tv, he'd say, well, you didn't need that piece.
And when you yank off enough pieces that finally you break something, oh, look, we, we found a part we needed. But that's not a strategy for, I don't know, um, survival. Like, here's the thing.
Intel is finding itself in a very hard spot because their plans to become more profitable, or at least stop the slide, require people to do things like you said, but you don't know who that's going to be. And that's the weird thing about this. They've already said that they're gonna have every organization go through and figure out who needs to go and who needs to stay.
That sounds to me like it's gonna be asymmetric. You're not just gonna go in and they're gonna go like you and you and, and 20 people over here, and I guess 20 more people over here. Some of these organizations are going to get hit hard, and they're gonna make sure that the people who are left behind in the areas that they think are going to be their growth areas are not gonna be allowed to take an early buyout, and they're not gonna be able to take an early retirement.
So basically, you guys are gonna be here because we need you. And I wish they would do a much better job of communicating that upfront, because that to me is where Lit Bhutan's leadership really is needed right now. Here are the things we are going to do well, and whatever they are, you're gonna have to double down on those, right?
Because I, I remember recording rundown episodes late last year saying, you know, Intel Gouty can't miss, like, like if they wanna get on the AI bandwagon, their GPUs can't miss, and they gotta do this, and they gotta do that. And here we are, less than a year later going new CEO cutting people left and right, they need to succeed at what, that's the question that I think that Intel has to answer right now. What are you gonna be a fab facility?
Are you gonna build out that Ohio Fab and these Arizona fabs? Like in the story we talked about, we're gonna be, uh, coming into competition with tsmc. Are you gonna try to become the homegrown tariff proof company, then say it?
Because that's gonna take time for you to get those things adopted. But if I don't know what you're building other than making more CPUs, that doesn't give me any, any hope for the future. Because what if you're cutting jobs from the CPU manufacturing and the packaging people and all that other stuff, if you're cutting those from areas that I know you're good at, that's a signal to the rest of the, of the market that you are trying to either survive or that you don't wanna be good in those things anymore.
We have to see what's going on, because then what happens then the rumors come out that you're cutting 20% and everybody flips out because oh my God, how can you provide? And that, that's table stakes right now, as, as, as I see it. All right.
With that being said, luckily there are some things that are coming up on the horizon of the future, at least from the Tech Field Day side that you can absolutely hang your hat on. And the first of those will be next week, because I am gonna be in Silicon Valley talking about all things related to mobility. We are gonna be having Mobility Field Day, uh, 13.
We're gonna have presentations from great companies like, uh, Juniper, Cisco, Ubiquiti, Fortinet, Nile, cel, um, Arista and more. com and check out what's going on there. And then coming up after that, the next week, uh, Steven is gonna be at, uh, tech Field Day Experience at Click Connect 2025.
Uh, it is a great opportunity for you to learn more about what Click has been working on since we had our, uh, click Connect experience last year. And I know he's gonna have a wonderful lineup of delegates around the table, uh, enjoying, uh, all the great things that there are to offer at events like this. And then at the end of May, you're gonna be hearing from me once again at Security Field Day.
We have a wonderful lineup of companies, uh, Microsoft, Dell, Veeam, and more. com. Uh, you can also check out the delegates that are gonna be there.
Uh, it's, it's gonna be a lively bunch. Uh, luckily nobody's gonna be guessing anybody, pa anybody's passwords 'cause we're all two factor enabled. And you should be too.
You should use all of the factors of the tech field a rundown, whether you are checking out the video on the tech field, a plus YouTube channel, whether you're listening to the audio format of this audio in your favorite podcast application, or go over to the website and check on the show notes because we link to all the articles that we use for research. Uh, and sometimes we link to some other fun stuff too. But we will be, uh, producing this episode every Wednesday in the afternoon.
You know, once you get a little bit of caffeine and some lunch down, you, then it's time to listen to the news and hear what Al and I have to say about it. Because Lord knows we, we have as much fun as we can with some of this stuff. Uh, but, you know, we'll be back next week with some more exciting, fun news.
There'll probably be some stuff out of RSA and a few other things. But until then, make sure that you're subscribed to Tech Field Day, across the board, uh, website, uh, for upcoming events, our newsletters for all the stuff that you need to know. And if you have any news stories that you wanna send our way, you know, make sure you check out all of our social media channels.
Those are listed on the website as well. Uh, we'll be back next week with more great news. And until then, uh, make sure you stay dry, uh, and enjoy an oatmeal raisin cookie for me.
Will you? Hey everyone, have you ever wondered how IBM can start a technology and then have to always be playing catch up? You're watching Text On Gang?
Hi everyone, it's Alan Shimmel, and happy Wednesday to you. We've got some great stories here on Textron Gang today. As usual, there's a fair amount of ai, a little bit of open source, some intrigue, palace politics, and a bunch more.
We've got a great gang to bring it to you. Let me introduce you to them and we could dig right in. So first of all, he's, he's not up in Silicon Valley.
He's out in, uh, Las Vegas land to, in fabulous Las Vegas, as they say. He's our, uh, uh, Silicon Valley editor, John Swartz. Hey, John.
How are you? I'm good, I'm good. It was pouring yesterday.
Uh, we had a little bit of delay, but, uh, on our way in, but I'm looking forward to the, uh, ServiceNow Knowledge Conference this week. Oh, very cool. Yeah, it's a good conference.
Yeah. Well, good. Yeah, we'll be looking for some good reports from there.
Enjoy moving from Vegas to San Angelo, Texas, the data center capital of the world, or soon to be in the Tech Concho Valley, I think it's called. She's our own editor, Amanda Ani. Hey, Amanda, how are you?
Hello. Good. I'm pushing it for it to be, we're getting a lot of tech companies here.
All righty, then moving up. She's Fu Futur vp, uh, analyst, Mitch Ashley. Hey Mitchell.
How are you? Good. I've returned to the, uh, guitar background, so yes, I see that.
And they are real. One of these days we're gonna have to have you open up the show playing the guitar because I've had people ask me, does he really play those guitars or are they just for show? They're they're a collection.
No, I don't know how to play guitar. No. I've been playing guitar a long time.
Happy to be careful what you ask for Alan. Absolutely. And then moving from Mitchell over to, uh, Harrison, New York, he's our chief content Officer, actually on his way down what to the DC area today, right, Mike for Nutanix?
Yep. Yep. Uh, chief Content Officer, Mike Ard.
Hey Mike. Hey, hey. It's raining here in New York and our prayers are answered 'cause the Yankees are struggling.
So we're hoping for our rain out. Pray for, what was it, Warren, someone else. And Pray for Rain.
It is an old story. I think it was the Braves or Spawn was a spawn. And, uh, Johnny saying, and pray for Spawn and Insane and pray for Rain.
That's it. What a, I love being surrounded by some baseball people like this. I thank you.
Um, so Mike, I I, I teased it coming out. IBM is making a habit. I mean, quite frankly, they should have been owning the ai, you know, they were doing Watson commercials when I was a kid, it seems like.
Um, and here they are now they're making a major agentic AI push. But it feels very to me. Anyway, I'm, I'm interested in your take and of course John and Mitchell's take it seems very me too ish.
It seems very Catchup ish. Why aren't they dealing from a leadership position? Mike?
What, what's the story here? Well, I'll just give you the good and the bad of it. It's, the good of it is they are actually putting together an orchestration framework around watsonx for integrating and managing all of these AI agents that are out there.
And they now have 150 partners and they're making a case that says, you know, what matters here when the Gentech AI is access to enterprise data, and they are going to be the ones in a best position to provide that level of integration. The downside of it, and I'm gonna pass to Mitch a minute after this, is that, you know, it's a hodgepodge of other stuff. They bought web methods last year.
They got, um, Databricks, I think as a data lake kind of platform. And they're once again, stitching it together in a way that you could say was a consultant's dream, which is not necessarily what it people are gonna love. So, Mitch, I mean, you've been following this, but what's your take?
Well, you know, we, we've all Watson has taken on many lives, right? And now of course, uh, being kind of the center of ai, or at least it has been, this is a pretty comprehensive announcement. And, and I understand kind of the hodgepodge of it 'cause there are some sort of things thrown in, right?
They also did a Linux one five, a distribution update for the, uh, C 70 mainframe that runs, that has the, uh, AI processing that tell 'em two processors. But I think what, what I take from this is whether they're late to the game or not, you know, the every, every day, every week, it's hard to even write analyst papers about this. 'cause there's news every day.
You, you have to go back and update what you're writing. They have a pretty comprehensive approach. And why I say that is they're not just introducing an agent capability, they're also including a framework called Orchestrate.
Uh, they're also including an agent catalog for, uh, both agents that they built as well as third parties. And, and you mentioned the data lake, uh, from a company that they bought that you also mentioned the web methods. You know, those are sort of the things kind of thrown in, um, if you will.
But I think that's also, well if you aren't gonna include those as part of your AI strategy, where do they fit? So they're including it. Um, the also threw in a lot of, I say throw in, they also announced a lot of, uh, integrations with enterprise applications and enterprise services from Adobe AWS, Microsoft, you know, the, the, the notable ones, you know, serve now Workday folks.
So they're making a play to say, you know, you're still a safe bet working with IBM, we, you're enterprise partner. And, uh, as you said, the integrators, the consultants, the people who up put, put these things together, now they've got a full tool chest, if you will, to go help customers. So now again, not all of this is available.
Now, some of it is in preview, like the agent catalog, but, um, I thought it was also interesting, you know, you had a really good article out on, uh, tech Strong AI about this. CEO Arvin, uh, Kirschner made a statement about it. I, AI is still being invested in, but only 25% of AI initiatives have achieved in ROI.
This is the year AI is, you know, people are looking for some return that it's gonna be worth doing. Um, and so I think it's interesting that, that he brought that up. I think sometimes it's helpful to be later to the game, as y'all say, because they can look and see what's working, what's not working, what problems do users have and come out with a better solution because they waited.
All right, third mover advantage, right? So, but this is so quintessentially IBM mish, right? So look, they had this Watson, and it's now called Watson XI, I remember going to IBM conferences literally 10 plus years ago.
And seeing Watson, right? And some of the cool things Watson was doing with dating apps and all kinds of things they were building with it. And then AI explodes on the world.
No one thinks of AI of IBM as an AI leader per se, but yet they're IBM just, you know, they have 500 of the Fortune 500 is as they probably have 600 of the Fortune 500 as customers. You know, they have an account rep for every one of those, and they get it in there. They're great at building ecosystems, they're great at bringing their partners in so they could stitch together this comprehensive soup to nuts kind of offering that.
But sometimes when you look under the covers, you could still see the, the threads, the stitches that stitching it all together. And they're not so tight. It's almost like we don't wanna be the first ones to market.
We want to, we wanna come in with the, the big blue solution here that, you know, is, is this big and is is everything, right? And, and there's gonna be a portion of the market that loves that, right? Their, their base customer base loves that.
But there's also a portion of the market that says, you know, look up overhead dinosaur, that meteorite might just, meteor might just fall on your head. And, am I getting the cutting edge? Yeah, I, I'm sorry, John, right?
AI was all about speed and about getting to market and about kind of, and Oh no, that's okay. AI is about getting to market and hitting people over the head with all these different announcements. And the only time I've really seen IBM's name associated with AI was as a partner of all these other companies that jumped the line or moved faster than IIBM The one thing, and Mike is I think totally right, is about this consultant's dream.
When you stitch together so many different parts, it makes me think of somebody who's like building a crib and there's like hundreds of parts and they're supposed to figure it out. You usually bring somebody from the outside in to determine it. And I think that that kind of hurts.
IBMI also think the fact that they, they had this legacy, they had to jump on everyone and they kind of let it slip away. I mean, maybe they catch up and, you know, they're a safe bet, so they have a lot of huge customers who will be, feel safe and secure doing this. But I, I just think they could have done more.
But, you know, we'll see this, this, this whole race is so predicated on hype and on reality and ROI is Mike Rhodes. Um, maybe that helps them in the long run. So it was interesting to me that one of the things they called down the press conference was that they have increased r and d investment, I think it was by 40 or 50% or something like that over the last four years.
Which, but the issue in my mind, and, and the example of this is that for all that investment, they seem a little slow and they keep being usurped by somebody who comes along who's moving just a little bit faster. For example, Andro has this model context protocol out. Well, you know, IBM has been working on the equivalent of that for a while, and then late last month turned around and donated that to the Linux Foundation.
Now whether that was because CPS becoming a Deto standard or they're trying to build a community as an alternative remains to be seen. But, um, I think most people didn't even know that IBM had such a thing in place. And so now, you know, something is amiss with their execution, is all I can say.
So some, I'm, I'm gonna disagree with you all on this, and here's my point of view on it. I'm, I'm pulling it now, I'm, I'm gonna disagree with the panel. Is, is, uh, I don't, I don't think it's possible for IBM to keep up with an anthropic or a cursor or all these companies in the, I mean, innovation's just happening so fast.
And maybe they'll have some areas where they do do carve out, you know, some places where they get ahead. But when you're dealing with, you know, the 600 companies of the Fortune 500, as you said, Alan, those people don't implement PO point solutions. They implement solutions at scale that have to integrate across multiple systems, um, multiple geographical locations.
It, it is a big effort to put things in. So I haven't looked at their solutions and, and say, and to say, are they enterprise grade necessarily? But I gotta believe that that's an approach, Mike, that, that IBM has to take that the others don't.
Philanthropic can can, can play in, in much different ponds and doesn't have to always deal with the very large, uh, companies and at scale, because they don't have an embedded base to deal with, they also can deal down mid and down market. So I, you know, let me be snarky for a minute. They could be Apple that's behind.
So there you go. That's my point of view. Yeah, apple can get away with being late too.
It was one A as IBM dos, you look at all these companies that are filling the gaps in all these different, uh, vertical applications or what, what have you, just sp specific types of agents. And by the time IBM gets it together and their customers understand how it all to put it all together, they may have been diverted to, to a better solution that was came out faster. I mean, again, it's all based on speed and I just, IBM just moves slowly.
That's just the way they are. But, but here's Mitch, did you just call, I wanna clarify a point, Mitch, did you just call IBM the apple of ai? Is that how you went with it?
No, I was saying a Apple is even later to the game than ibm. That Was my point. They can get away with it though.
I mean, they're like, they're polling and surveys that are just consistently show that people are wi willing because of all else, because it's only because it's Apple. They're just willing to yeah, to wait to wait, you know, and hey, Apple, to be so, but here's the paradox of this. Apple didn't invent ai.
Apple didn't have an AI product out there when they had Newton, uh, Dell didn't IBM invest a ton of money in pure research, pure science. And as a result, they make breakthroughs, whether it's in ai, what they did with Watson or quantum computing, they own the whole quantum computing thing. Now you're starting to see all these quantum companies pop up and they're gonna run circles around it a bit.
Um, think back to the, remember the IBM, what was it? The IBM PC processor was really sort of an early sort of risk based processor. You know, ARM did pretty well with those.
IBM got outta the processor business basically, right? So their MO is, they spend billions and of, and a lot of time those billions are well spent in basic research that come up with groundbreaking inventing new technologies, and then they sort of abdicate that leading horse spot and let this whole industry grow up around it, and then they'll jump back in because they don't like to be first, they don't like to, to do it, I guess. And then they jump in a little late and play catch up.
Now, apple and Dell specifically, they have very different philosophies. Apple and D are sort of the old bull and the young bull at the top of the hill, remember that story? They're not looking to race down there and be the first one down.
They don't like to jump into a market until the market is well established, it's multi-billion dollars and that they have a plan that's gonna capture a substantial share. They're not gonna jump into a market prematurely, and they're not gonna jump into a market that they don't feel they can carve out a substantial share. And that's their philosophy and right, wrong or indifferent, it's served them well.
Um, I think that has been their philosophy in Apple, Alan until ai, they were late to announce and then they over promised and underdelivered and you know, as you said, you know, apple's not gonna be the first to necessarily introduce something, but when they do it, it's done well. That, that's hasn't been the case on ai. I think to your point on IBM, what IBM has done in the past is they may not necessarily invent something.
They didn't invent invent SQL databases, but they legitimized it when DB two came out, right? 'cause I remember people were like, nah, nah, you would never do relational what IBM has a a relational product. They do that kind of thing.
Whether they'll do that in ai, I don't necessarily know. They're a much different company now, but I don't, I don't look to IBM to lead in every category in ai. I think they're better off, they're a services and product company.
They're better off serving customers of implementing successful AI projects with an ROI as opposed to leading with the next flashy squirrel. Yeah, to Mitch's point, they're kind of counting on the fact that AI is hard and a lot of organizations that are going down the path are gonna stumble because it takes a lot of coordination between different departments to make this work. And eventually somebody in that organization's gonna go, Hey, we're being left behind.
Let's just call one 800 IBM. Well, like Mitch pointed out that 25% of people aren't seeing the return on investment. So, um, IBM spoke to that in this article, and they think that their solution will.
So, And it's, the deployment has also been slow among enterprises, right? In terms of, uh, governance compliance, just try and piece it together. There's been a hesi hesitancy and a fear of getting it wrong.
So things aren't being deployed as quickly. So maybe IBM benefits kind of in a small, in a small way from that, I would look to who IBM's gonna buy next. I think that's where they had, you know, big companies don't often innovate themselves.
They buy or they innovate through acquisition. Cisco does that. A lot of companies do.
Fair. Hey, we gotta take a break and come back for our next segment, our friends at Redis. You know, the old saying, you can have a pair of pants, but if you make it too short, you can't make it longer.
Again, once you leave open source, can you go back? We're gonna discuss that you're watching Textron Gang. All right, folks, we're back and we're moving on to Redis and they say, you can never go home again.
But here comes Redis trying to be an open source company one more time, because they kinda led the charge with moving away from open source, uh, when there was a lot of, uh, investors were unhappy with the returns that were being generated for these companies. And yet that led to a lot of forks of Redis, and a lot of people jumped on those forks. And we've seen this play out before in open source environments.
But Alan, let's start with you. I know you tracked this whole area pretty closely. Can you go back once you left the farm?
Sure, you can. All you gotta do is put on a pair of Ruby slippers and click your heels three times. It's no place like home.
There's no place like home. Um, look, first of all, I'll give credit to Redis. It sometimes it takes a big database company to admit you made a mistake and a mistake was made.
Um, you know, the, the the, the open source world can be forgiving though, right? If, and, and the beauty of it, back to my analogy with the hemming of the pants, is if you had something that's open sourced, right? It stays open sourced, then you come out with a new version that's no longer open sourced, that new version, everything from that point forward is not open.
But then at some point here, you open it back up. Well, assuming you still own the IP for that non-open source stuff, you could open it up and it's like nothing ever happened, right? And, um, so I think in this case it's a relatively easy thing.
But here's the real question. Will the community trust them that they don't pull this again? Or have they already moved over to the forks and they're comfortable with them, or, you know, burn me once, shame on you, burn me twice, shame on me, and I'm not gonna give you a chance to burn me twice.
And so I think red is in addition to just returning to this open source model, you know, needs to do a confessional, a couple Hail Mary's and whatever. Mike's smiling, he remembers those. Um, you know, Forgive me father, it's been six months since my last open source confession.
Yeah, Well, so actually it's been 2020 since the last confession for Redis, because that's when, uh, Salvatore spo, I think is his name is, you know, who was the original developer of Redis. He came back, he left in 2020. He's come back.
And that's a lot of what they're crediting for, why they're returning to their open source route. So maybe some holy water and some Hail Marys, you know, with him on board. Well, I mean, and he may be the personality they need for that community to, to embrace them.
It's got the credibility, right? It's got the credibility, right? That's the credibility because that's going to be the issue.
I mean, changing the license here and going back to an open source license is a relatively trivial thing for them. Um, regaining the respect and, and commitment from the, and trust of the community is gonna be the hard thing. But I I will also say, you know, nature of pours a vacuum and there have been competitors that have popped up in the open source space there.
And it's gonna be interesting to see if just moving back to open source is enough to put Redis at the top of the hill again, Or they, you know, there's a path down the middle. They could support Velcade and their own open source core database as two separate forks that are, then they're delivering a bunch of enterprise services on top of that and extensions. And whether you're running Valki or Redis Open source, maybe they don't care.
I was reading this article, um, and what you were talking about Valki, how they created that. And I was thinking that it just shows the, um, the stronghold open source has, and kind of the power I guess, that developers have when it comes to breaking away from open source. I look what they may wanna do with the, you know, with the founder back and everything is try to merge it back in, into, into Redis.
'cause having two versions of, of in essence the same thing, right? I gotta believe Salvador's got some pretty strong Yeah. He'll, he'll get them.
I think you're gonna see that merge back in because over time they just separate more and more and it becomes harder to, all right, So to Reconcile, donate The two of them to your favorite consortium du jour, and then have the consortium pull 'em all together. You could do that too. Some consortiums don't like to pull it together.
They, you know, they like to see how many projects they're managing. Just saying, just saying. Um, but look, I, I think this is a good thing for the community and for the user base.
Um, I don't, I don't think Redis will have a disruption in innovation or anything like that. Um, if anything, maybe it'll be more innovative. So I, I actually think it's one of the, maybe the few credible ways of coming back to open source, having the original creator, author.
I mean, it seems to me you've got, you know, provided that person's, you know, got a good, still got a good reputation in the community, I assume so they can help, they, they can help pull it back. 'cause that's who put, you know, it's like Linus, right? Putting trust in Linux and all of that.
So yeah, no, I, I, I agree a hundred percent Marty. Sure. Right?
You know, but we'll see. Let, let's see how, you know, how the community embraces them and do we see emerge of, of the forks and so forth. But it's a great open source story, right?
It's part of what makes open source great. So I say congrats to Redis. Good luck.
Fair. All right, let's take a quick break and come back here with our next block. Who would've thought AI is biased in its hiring?
You're watching Text on Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Techron Group. Hey folks, we're back. And this is a subject of a lot of interest these days.
'cause well, folks are looking for work in all kinds of fields, and there's always been this perception that somehow or other, uh, the process has been biased. And John has a story now up on, uh, Techstrong DOA talking about how, well, I guess if you look at it, the data and the processes used to train the AI model, to apply it to HR seems to be favoring men. And I guess, John, let me ask you this.
Is that the fault of the model or is it the fault of the processes and the data you use to train the model, which are clearly biased to begin with? Yeah, it's probably a combination of, probably a combination of both. But what's disturbing to me is that there are more, uh, AI hiring, uh, models being used within organizations.
In other words, when they wanna winnow down a number of candidates and then recommend a a handful to a person in the process, it's, especially for high paying jobs, it is shifting decidedly towards males. Uh, given this test of, uh, open source AI models that was done by a couple professors. The title of the paper was called Who Gets the Callback Generative AI and Gender Bias.
So they basically looked at, uh, job candidates and they analyzed mid-sized open source large language models for signs of gender bias and hiring recommendations. They looked at a more than, uh, 330,000 English language jobs, job ads from, uh, India's national Career Services online portal. And they sized up various models.
And what they found with the models, with supplied, with job descriptions and asked to choose between two equally qualified male and female candidates, the callback race for females was significantly lower. And according to the professors, and I'm quoting them, these biases stem from entrenched gender patterns in the training data as well as from agreeableness bias induced during the reinforcement learning from human feedback stage. So in other words, Mike, the first two things that you mentioned, those two factors weigh heavily in this.
And I don't know how you address something like this, but it doesn't surprise me in the least. And, and the other thing that's interesting to me is that while this is happening, the Atlantic did a survey, they did a study of college graduates and the unemployment rate, and it's up to 6%, which is significantly high. And AI is playing a part in that, not just in terms of taking jobs or low level jobs, but I think, um, in the hiring process, it's, it's skewing dramatically towards, towards min.
So the job market, if it wasn't already difficult enough because of the, of the, uh, prospect of competing with ai, it's not being helped by the AI hiring process That's in effect in a lot of companies. Well, first of all, I'm glad this is being pointed out, but my reaction to it is, duh, we can't fix the biases in our human processes of hiring people. Why would we believe that AI would be suddenly better of it?
Maybe it's the hype of ai, but to the, to your point, John, it's all it's trained on the data. Guess what's in the data, you know, the information that the models are trained on, unless you take explicit measures and change the weights to try to try to change that model. Yeah, of course it is.
Not that it's a good thing, but, okay, let's address it now. Yeah, that was my thought too. Like, well, the data being used to train would be representative of that because, um, men still do overall tend to have the higher paying jobs from a percentage standpoint.
So if that's the data you have to train AI on, Question is, do we fix the models or do we fix HR first? Well, this has been broken forever, right? In my mind, we've been playing, you know, keyword bingo on resumes forever, and running them through these HR apps to kind of find somebody who's quote unquote qualified.
I also think that a lot of the people who are doing the hiring kind of, you know, they kind of tangentially work with HR and they go out and post a job. But most of the people I know who hire folks, they hire people they already know. So they build their own little network, and they're not kinda, um, shall we say, very serious about what HR might bring in the door.
It's not what you know, but who you know, know. Well, I mean, I, I'm gonna, I admit, I, I benefited from that and, and I, the one thing that I was, I, I was hoping that they might even look at these males and they tend to be probably whites. Maybe that's gonna be a follow up, but it's just, it's just the same old, same old.
And, uh, it's, my fear is that as these companies and hr HR departments in particular depend more on AI for hiring, is this gonna maybe even exacerbate the problem? So in my best ma of voice, this DEI nonsense, move along. I was gonna say de I was gonna say that, but I was waiting for you to say it, Alan.
It, it's so true, though. You're gonna defund it. Alan defund it.
Not only that, I'm, I've asked the Justice Department to look into it, that case, right? If we, if We stop, I'm gonna say a truth. Hey, if we stop testing, it'll go away, right?
Right. Yeah, exactly. It didn't exist.
I'm gonna say, I know a lot of people really struggling to find work, and it's come to a point where people are trying to use chat, GPT or other forms of AI tools to figure out how can they break through the AI filtering process. What's gonna be the key words the AI picks up that's gonna get theirs ahead of the thousands of other applications Or power to 'em, weaponize AI to either a lot Of, yeah, and, and a lot of people are using AI to write their resume le resume letters now, a lot, most people are, so they all, they all tend to be the same. So most people are.
Yeah. But, But, you know, for specific jobs, let's say in terms of coding, right? I, I remember interviewing a company that were based in the uk where what they would do is you would hire them if you are looking to hire coders, and they would prepare a prompt, you know, code, code, something like this, and then it would, using ai, look at the code you generated, the code you wrote without having your name, your background, your sex identity, whatever, and then just pick who wrote the best code.
And that was a way of kinda leveling the playing field right now with today, AI writing the code, I think that screws the whole thing up, but, but there are ways where I think we could use AI to level the playing field and maybe try to get some of that bias out of there. Um, I don't know, Alan, because if the model was trained on the, all the code that's been developed, and most of that code was developed by males, and if you assume there's a difference in that, or maybe culturally India versus us, it, it's gonna have those biases even in the code. It's gonna favor what it thinks is, I mean, even English is a second language.
Coders are at a disadvantage, perhaps. Not saying we shouldn't try to use it, but I think we have to recognize it. It has a natural bias into it, and that's what we have to figure out.
I thought that's why we had a DEI program. No, we defunded that. Well, I said had in the past tense.
Oh, okay. Right. But that was the reason for it, right?
Was because this is, it's built into the system. It's built into the SATs and the L SATs and everything else. You know, when you have basically white men making the rules, you're gonna have rules the favor white bed.
And no matter how much you stamp up and down and whine and threaten and huff and puff, it doesn't change the facts on the ground. And I would, I would like to see the AI models vetted by some third party and maybe, you know, some sort Of, and that third party would not made up of white males. But part, part of the problem, I think part of the reason why they're turning to AI in the first place is because so many people have access to just apply online now.
There's just thousands of people randomly applying to hundreds of jobs at a time. It makes it very difficult to filter Through. Yeah.
It's not one of my favorite things is yeah, trying to hunt through resumes for a person to hire. Anyway, let's hope it gets better. I think this is an area where we can get better with AI and we can level the playing field and, and, and we owe it to all of us to, to do that.
Guys, I think that's gonna wrap up today's, uh, tax, tax Strong Gang. John, enjoy Las Vegas. Stay away from those tables.
Yes, thank you. The house always wins. I Don't Gamble.
I know I don't gamble. All right. No, Amanda, Mitch will see you soon.
Mike will see you soon. Well, you'll be at Nutanix this week. Looking forward to some reports from there.
Until next time though, until tomorrow, we have a full tech drunk TV lineup following today, including, I believe we have a Tech Field day going live today. So you'll be able to see that here on Tech Drunk tv. Until next time, this is Alan Shimel.
Have a great day. We're out. Hey, everyone.
Welcome back here to Techstrong tv. I'm really happy to introduce you to a first time guest here on Techstrong TV and a new kind of a company and movement to talk about. Let me introduce you to Manos Ku COIs.
Uh, he is the CEO and co-founder of something called, excuse me, OMI, OUMI, open Universal Machine Intelligence. He's gonna tell us all about it, but Manos, welcome to Tech Drug tv. It's great to have you on here.
Thank you very much for having me, Alan. It's my great pleasure to be here and talk more about, uh, OMI and as you mentioned, both OMI as a company and the bigger mission that we're pushing forward. Absolutely.
So, Manos, um, let, before we get into umi and everything, you are the co-founder and CEO I've in, I've interviewed literally hundreds of founders, co-founders. Every single person has founded the company because they buy into the mission. They feel in some way it's going to help change the world, help make the world better.
But they, no one, no one is born and co-founder a company. You know what I mean? There's always a life before.
Let's hear a little bit about your life before co-founding umi. Absolutely, absolutely. So maybe I may take you a little bit, uh, very far back, but I started wanting to become pretty much like my father to become an electrician.
And luckily the best school in Greece was the electoral and computer engineering school. So, as by accident, I got into computer engineering, quickly fell in love with computer programming. Uh, and then when I was going to my PhD not knowing what AI really is, I kind of almost bumped into it.
It was when the first iPhone was coming out and I said, you know, there has all these sensors, all this data you need to do something useful with it. And that's how I bumped into ai. And way before any company said, we are an AI first company.
That was back in 2007, 2008. I'm like, you know what? AI is gonna be big.
You need this machine learning. You need this technology to do something useful with all this data. And that's how I got and started getting deeper and deeper into ai.
Then, then moved into Microsoft, started working a lot with natural language ai. I even built something like Ja ZP in 2016. I was a little bit premature.
Uh, and then, yeah, continued on with that at Meta, working on conversational ai, uh, then a startup, then Google where I was leading all the natural language AI services, uh, including also bootstrapping the efforts for Palm. That was the model before Gemini. Yeah, Very cool stuff, really.
So you, you've literally had a, you know, been right in the middle of it here as we've launched into this, you know, era of ai. It's funny, I have a friend, John Willis, he has a new book coming out this week or this month, kind of the history of AI and the people behind it. I don't remember the name of it, but if you go on Amazon, look up John Willis, it's his newest book.
What I think a lot of people don't realize is this whole AI thing that burst on the scene, what, two and a half years ago, maybe with chat GPT Open AI has really been something that's 50 years or more in the making, right? And the idea of what we now call ai, whether it's a form of machine learning, pattern matching, et cetera, right? All the way through the latest and greatest agent AI and LLMs and training models and all of that.
You know, it didn't just spring forth. It's been a gradual buildup over all these years, but there's always some mono, there's always some ignition point or something that lights it up, right? That, that makes it, uh, just go viral, so to speak.
Obviously, open AI's chat, GPT was that event here, but why, look, you were working on this, as you said, in 2017, 16. Why then why, why not in 2017, what was missing then? That is now.
Yeah, f first of all, Alan, fully, fully agree with the points, all the points you made, uh, ai, machine learning, AI has been in the making for quite a bit of time now. Um, and as you said, you know, back in 2016, we built something like ZGBT. Even back then, I could see people were amazed how there was a chatbot liked ZGBT, uh, that could respond to any question you would throw at it.
But the technologies are very premature at the time. You know, they were not as advanced at the time. For example, what we now, we call, we use Transformers.
It hadn't been invented yet. We were using their predecessor called L SDMs. So even though people were amazed, the quality was just not there yet, uh, to be coming to product.
But lemme tell you, I mean, there was quite a few times I could see people being amazed at the time, you know, almost the reaction they have with ZZPT. It just, you know, every now and then the system would say something that doesn't make sense, and then people will lose interest. And, um, but I think that's, that's, you know, that's, uh, I think what open AI did, they did manage to scale up those models and some continue making them better and better.
And because, as you said, they make it, they made it so accessible to people. It, they got this viral moment that, uh, finally, you know, they took, uh, the world by, you know, uh, they huge excitement around the world about what they built. But there was definitely something in the making with many research labs, not just what we did at Microsoft, but even after that building such technologies.
But I think they managed to give it a good delta in the quality improvement and then make it so accessible, building the hands of people that, uh, created that earthquake in the industry in, uh, anywhere in the world. Absolutely. Absolutely.
Let's turn to omi. What, what drove, you know, you, you worked at Microsoft and Google and Meta Giants, you know, the, the hyperscalers as we call them. What made you, you know, people don't do this like, like, you know, uh, without good reason.
What, what drove you to co-found omi? Yeah, that's a, that's exactly right. Uh, the, the, as you were also discussing earlier, the main thing was the mission, uh, starting from the problem that we wanted to solve.
The more, uh, as I was mentioning earlier, I bootstrapped the efforts of production. I found working with, I don't know, 20, 30 teams all across Google to make it happen until that effort moved to DeepMind. But even as I was continuing to work on Gemini, when I moved to DeepMind, and I was increasingly realizing how more and more sciences, you know, for not just healthcare and the tech industry, but climate science, material science, and many, many more, pretty much all science going forward, gonna be powered by ai.
I was increasingly getting worried about the future I was contributing to. 'cause I was thinking it can't be that what's gonna be the foundation for all, both the tech industry and all the sciences. It can be a black box that is owned by OpenAI or Anthropic, or let's say Google or somebody like that.
It needs to be, we need all the science need to have more free, uh, access to this AI technology. It needs to be a glass box, something they can easily look at and adapt so they can promote the sciences. So that was that, uh, you know, philosophical concern.
And then I started also realizing something that was, I would say, not clear to many people. I would say still not clear to most people, which is that while these large tech giants, they may brag about the number of GPUs that they have to build these models. This only part of the story, the thing that most people don't know is that, uh, they're actually themselves very constrained in terms of the human capacity.
Those technologies are extremely complex. They don't take a lot of GPUs to train. They take also human amount, humans, huge amount of human resource and human ingenuity to continue moving them forward and advancing them.
And that's where I realized that actually AI is the most prime technology to be advanced in open source compared to operating systems like Linux, or compared to database like PostgreSQL, even more than those technologies. And the best way to advance it, both faster and safer and most cost efficiently, is to do it in the open, to do it collaboratively with all the open community that is orders and orders of magnitude larger than the couple thousand people that are in DeepMind or in open ai. Uh, and that's actually, again, the best, the best way to advance ai, the safest way to advance AI and, um, uh, the best way also make it accessible then to all the sciences and enterprises.
And that was the kind of the, the most important, I would say, motivations that led us to the fund domain. Fair. Fair.
You know, you, you, you mentioned, uh, or in, in some of the OMI stuff, is kind of trying to pattern OMI after sort of the Linux movement as it eventually triumphed over the, the many flavors of Unix, if you will. Yes. Right.
But to be fair, when Linux did that, we didn't have what I call the foundational era of open source, right? We have the Linux Foundation now, which is of course, a lot more than just Linux, as you know. Um, you know, open source now is a much more defined, uh, method of go to market.
However, there's the flip side, right? Where we, we, we've seen a lot of companies struggle with an open source model, right? It, you know, it used to be a Red Hat was the big success story, obviously, but we've seen many companies succeed with open source, but we've also seen many companies not how, how can OMI be successful with this open source model?
Yeah, lots of lots of good questions there. So the first one was that, uh, if you come to think about it, I, I, I, I, I actually, the more I was thinking about, the more I was getting convinced that the best way to develop these technologies and compete even as an enterprise, would be to do it in open source. Because currently what's happening with Open AI and Tropic and Google and all these companies, it's, uh, it, it's, it's like, uh, about who has the deepest pocket to keep investing in AI and keep draining all this money that if I were a shareholder of these companies, I would be very frustrated how this money is being spent hoping that they win this.
And hopefully they make, make it big, and they recoup all the money they have lost across the years with I'm getting, uh, less and less optimistic it's gonna be happening for any of them. Um, and that was actually the key conviction, that the best way to develop this technology is not to try to spend more money than open ai, but to say, you know what? No, as a community, we're gonna contribute to this boat because there is all the open community, all the academia, all accelerator providers like Nvidia, a m, the, all those companies, all cloud providers that are not one of the few aspiring aioli guards, all these companies that won open source succeed.
So the best way to compete as OMI or as any company, is to bet on open source as opposed to trying to outspend open ai. Uh, it's just, it's the best thing to do for the world, the best thing to do for humanity. And I think the most viable strategy is to compete.
And given that there was this gap, as we mentioned, the example of Linux and Unix, there was this gap of there was no Linux of ai. There was no platform that democratizes Frontier Frontieres and development. Uh, that's why we said also, you know, we're gonna build this because it will help.
It's, first of all, it's gonna be a positive thing to do for the world. And we think it's gonna be the MVP is gonna be the thing that will, uh, resolve the of friction that the community has to help it then to continue advancing and doing their research advance Frontier ai. Because if you can unlock and enable this community, and the more they innovate on Frontier ai, then it, these are gonna be for Rumi and any other company to stand against this, uh, you know, as David stand against those colias and compete with them.
Uh, so that's why that open source strategy, you know, I'll be very candid. I think it's, it's both self-serving for omi, but at the same time, I think it's the thing that benefits humanity and every other small enterprise that wants to be able to compete with open AI or anybody else. Fair enough.
It's gonna be interesting, you know, what else? So, open AI and, and our, our audience is familiar with this, that it's not open source open ai, but it is sort of this foundational not-for-profit. You know, there's all of this tied up in there, and of course, Elon Musk is suing over in what he's doing and everything else.
What makes us, you know, there's a lot of flavors of Linux, right? There's SUSE Linux, there's Red Hat Linux, there's Rocky Linux, there's what makes us think OMI is the one, you know, to put our efforts behind versus Yeah. Yeah.
Others? First of all, just, just a quick comment. As you mentioned, open AI is nothing but open.
It's as closed as it gets. Yeah. Um, and omi, the way sometimes I describe OMI to people is that the polar of open ai, you know, open AI is nothing but open.
It's fully closed. I Nomi will try to make truly open frontier, but as opposed to building a model and giving it to people and say, you know, here's a great model we developed, now you can use it. Instead, we're starting from empowering the community and everybody to contribute to making AI better.
I think that's the key thing for, to unlock open source, not develop a model and give it to everybody, but to empower everybody to come on board. I think that's a big, I would say, philosophical or strategy difference for omi that I think is gonna be key to our strategy. And I think it's key for OMI to win this key for open source to win this, uh, which is that you bet on the platform, you start by enabling the community to advance criteria.
So, Manos for people out here who say, Hey, this is the thing I've been waiting for. I want to get involved in ai, but frankly, I, you know, I was waiting for truly an open, open source community to come in and do it. How can they get involved with umi?
Yeah. So I would say they definitely can and a lot more, and a lot more easily than they could until recently. Uh, and that goes again to the design of, and the goals with whom it was, was to create a platform to create the lineage of ai.
That would make it easy for anybody. Definitely for researchers and ML engineers. It makes it a lot easier even for them.
But even for people who are more like application developers, uh, to experiment with, uh, ai, and they can go incrementally deeper and deeper. We say that even though OMI is open source, it's as easy, if not easier to use than the API is built by open AI or that my team was building for Gemini. Um, but at the same time, because open source, you can experiment and stay at the level you're comfortable because we make sure it's very easy with a lot of examples to follow.
But then as you get more and more proficient, you can get deeper and deeper. And I think that's key to any individual person or any enterprise to start building the up the AI muscle, which I think in this time and age, it's gonna be very critical for any individual or enterprise. Agreed.
So for people here who want to get involved, what should they do? So we have, uh, the omi GitHub. That's be the best place to start your, I think, give you a Google search, uh, OMI GitHub.
Yeah, I'm sorry. It all come up as the first entry. And yeah, sorry.
From our GitHub, somebody can find all the information, all the documentation we have about how to install OMI as a library, how to get started. Again, we have a lot of examples and we got a lot of positive feedback about the quality of the documentation, because again, that goes back to our design principles, which was we want to start by enabling the community, which means we give them a great platform, great documentation, all that they need to get going easily and without friction. Any plans for, like, is there a Discord server or anything like that that we can, people can get onto?
Yes, absolutely. So I mentioned about the GitHub in our GitHub or also on our webpage, ww dot omi ai. There's a link both to our GitHub and also a link to our Discord.
Uh, we have an active Discord. It's over a thousand members right now, uh, with a lot of discussions happening, and even some research efforts that are being organized through Discord, uh, on our website. Also, we have a form that people can fill if they want to contribute to those research efforts because we're spinning up more and more such research efforts.
So yeah, definitely. Um, check out GitHub, if you want to get started, discord, please join for discussions or if you want to join some of the research projects or fill out the format, uh, OMI ai and, uh, we can make sure to include you in any of the future research plan. That's OU Mami ai Open Universal Machine Intelligence.
Manos, I wish you guys much success in this. It would be, it's gonna be great to see how this develops. You know, clearly a couple months ago at the Chinese deep seek, one of the, one of the selling points, I don't know if it's the word selling, but one of the bright spots on it was that it was open source.
And people really liked that idea, though. How much of it is open is another story. So having one here, Umi, it'll be good.
It'll be interesting to watch how the community comes around on it. And we do have the GitHub and Discord, uh, URLs. We'll, we'll include those in the notes.
Thanks for being on text on tv, man. Good luck. Thank you very much, Alan.
It was my pleasure. Thank you. Manos Kois, uh, CEO co-founder OMI here on Text Drunk tv.
We'll take a break. We'll be right back. It is Text on tv.
It's Getaway Day here at RSAC, Lisa Martin here. Having had some amazing conversations with cybersecurity leaders across industries the last four days. But, you know, because you've been tuning in to Text on TV and all of our other digital platforms.
My next guest is a veteran of Text on tv. My first time interviewing her, I'm a huge fan. Caitlyn Sien joins us.
6 million followers across social media. You should be, Caitlyn, it's a pleasure to have you on the program. I'm so happy to be here.
Talk to me a little bit about, you have amass in a short time period. 6 million followers. I'm one of them.
TikTok, LinkedIn, Instagram, X. How did you do that in such a short time period? I, I don't, I don't know.
Um, so I started on TikTok originally, and I really was embarrassed. 'cause I've been in cyber for 12 years now, and I'm like, if anyone finds out that I'm on TikTok, I'm gonna be destroyed in, in the office. And, but I really wanted to reach next generation.
That was like the main reason. I was like, I want people to understand, like everyone it, like is needed in cybersecurity. And cybersecurity is not something scary.
And they can get in and it can be fun. And we also need more women. I wanted women to see themselves.
Yes. Because when I was first introduced to cyber, my immediate gut instinct was absolutely no way I'm ever gonna be a part of this. Yeah.
I was like, I'm not a man. Yeah. That's, that's the number one reason I'm not a man.
And I was like, I didn't see myself there. Like, I just was like, that's, I'm not a coder. Like I don't, that's not where I'm supposed to be.
Yeah. And that was like the main reasons why I started. And then I started doing more education on, this is general public.
I'm like, what cybersecurity is, and honestly how simple it can be and how it's not scary. It does not need to be scary, but it needs to be, like, the conversation needs to be had at home. And I always say cybersecurity starts at home.
And it's not a scary thing. It's a, it's a necessity. It's a total necessity.
Um, and so that's kind of how it started. And I, again, I only started on TikTok four years ago, and it wasn't until the last two years I put started doing it on Instagram. And the reason why I was called Cybersecurity Girl is 'cause I didn't want my name on it.
So I didn't have my name affiliated with it at all for the first like year and a half, two years. Okay. No one I worked with knew that I was doing it on the side.
And then it wasn't until I got hired by TikTok and then I'm like, oh, now I can actually say it. 'cause they, they found me from my TikTok. They found you.
Yeah. So it's just been incredible. I mean, it really shows how important cybersecurity is now.
A hundred percent. And how, how people really wanna know. And the reason why I'm a little bit different is 'cause I, I like short form.
Like I don't do long form YouTube. I don't even really do XI, it's really just been like TikTok and Instagram and short form is for me is so important because people don't have the attention span. And honestly, even if they did, the general public does not wanna hear an hour long conversation about cybersecurity.
No. So what do they need to know? Like how is it impacting them and how can they fix it?
Yes. So like relatable, digestible, understandable content. And that's what I love to do.
That's Exactly what's needed. I'm a marketer by training. I've been doing marketing and tech for 20 years.
Media for, for about 10. But people want to be educated in the simplest, cleanest way. Yeah.
And you just hit the nail on the head, digestible, clean. How does it affect me? Right.
You know, one thing too that we're dealing with now is I was mentioning my mom's almost 80 and she's digital. She's a facebooker. She's now an Instagrammer.
I introduced her to chat JPT the other day. I know. I was so proud Of her.
I'm gonna throw my boyfriend under the bus, but he is, he still does not know anything about chatt. I'm like, I don't know if I can be in a relationship with you Anymore. You gotta educate girl.
I, I, I'm Trying, I'm trying. We're working on it. But we've got like five or six generations in the workforce today that are digitally active.
Yep. And some of those populations are way more susceptible than others. Yeah.
So I learn a lot from you in the things that you post. 'cause you make it clean, you make it simple. You maybe go, oh, I didn't think about that.
And so I teach my mom a lot of the things that I learned from you because I want her to just be, you have to, you can't just blindly trust everything anymore. Right. We've learned that time.
And again, ransomware is a household word. A ransomware attack happens the status from a couple years ago, once every 11 seconds. Right.
I'm sure that time is going down now. Right. It's only gonna continue.
But to your point, the education has to be there consistently. Right. Well, and there's two, two points I wanna hit on that.
So the first is, we also always think about our like, you know, older population of like, oh, there's susceptible. But the issue actually is the younger generation. So the older population gets hit with like, larger ransomware issues.
Like they have the, the most money, but actually the most people that are getting hacked are the younger generation. Is that right? Because they're so blindly accepting of the technology that they don't think anything of it.
They're not like, meant to be skeptical of it. Yeah. That's what they grew up with.
And so it's real. That's, and that was why I was like, let's reach the next generation. 'cause all these people, I mean Yeah.
They're not gonna have monetary value 'cause they can't really exploit kids point. Yeah. There is extortion, which is a whole nother issue.
And that's like, it's awful. And we're trying to mitigate that too. But a lot of these kids are actually dealing with similar issues as the elderly, but the elderly have way more to lose.
It's Right. It's, It's the financial it hit. And then the other part is like, similar to what you said, like cybersecurity is a human issue.
Like phishing and like, like reusing passwords. Like again, the Verizon DBIR report just came out. I went on, I went to their session yesterday and they were saying 60% of all of these, um, threats and, uh, vulnerabilities are human centered issues.
So whether you reusing passwords Yep. Or access management stuff, like, and or clicking on a link. It's all like human at the end of the day.
And so that's like what I'm trying to get at. I'm like, I feel like I'm protecting the companies at at this point Yeah. Too.
Because it, the learning has to happen at home. Like, when was the last time you learned, like, what, what did you learn? Like last, obviously you do this so you learn a lot.
Yeah. But like, when you're at home, like how do you learn, Uh, social media? Yep.
So that thing news, everyone is losing on social learning on social media. I through it with a grain of salt. Oh yeah.
You have to. Yep. And but, but with deep fakes and the advancement in the sophistication of like phishing, smishing, vishing, it's getting harder and harder to detect.
Yes. But I like your tagline that cybersecurity starts at home. It has to It Has to.
It's not a nice to have anymore. This is how it needs to be like a fabric of our lives. Yep.
And we were just talking, I don't know who it was with, but like, someone was like, yes. Oh, I know the founder of the hacking games that we were talking about how cybersecurity marketing has been such, it's been terrible. I was gonna say a bad word.
I'm not gonna say a bad word, but it's been terrible. Like we've been, we've been marketing cyber all wrong, even like companies. Right.
Like, cybersecurity is not something scary. It's not like we just need to mar like market it to people, like, and bring it to the people where they're at. Yeah.
And they're like, you know, online just general human beings. Right. That are like, I mean, we connected on Instagram.
Yeah. It wasn't because I like met you through, you know, some Right. Yes.
Forum. Yeah. Yeah.
But, you know, so, so it's starting at home. But also another thing too is just the, the commonality of it. And we have to expect it's There.
Yeah. With, there's more data, there's more software, there's more apps. That trajectory is just going up into the right and it's not gonna slow down.
Nobody wants less apps or less data slower. They just don't, We do want less op, uh, less like signing in for accounts. Yes.
Can we stop that? Like, I'm a fan of the fingerprint. I'm like, it's me.
Yeah. Yeah. Hi.
I'm the problem. It's me. Yeah.
But, um, it's just such an interesting Love the Taylor Swift coat, by The way. I'm a swifty. Yeah.
This is why we kind have nice things. Yeah. We can throw you another one.
Um, but I, I just, I think that it's so important to educate folks and it has to be consistent. And, and when we're here at shows like RSAC, we get to see so much of the technology that enables that fabric. Yeah.
And now that we're in the AI era, which I love, how do we secure Yes, me too. Yeah. There's so much potential.
Yeah. But there's a lot of fear. And so what I like to do is, let's pull out, and I think you're similarly minded, let's pull out all the positives that are there.
Like, we talked a lot this week about how does software company X, YZ help customers, whether it's financial services or healthcare or automotive, become proactive Right. Against the attackers. Right.
Because technology is neutral. Good uses, bad uses, it's like fighting fire with fire. But it's, there's never a dull moment.
And we need more people like you to educate the different user generations and groups of where the risks are. 'cause they're not going away. No.
No. And I, I also like, love the, I love ai. I think it's the coolest thing ever.
And like anyone that like doesn't use ai, I'm like very skeptical around me too with my, including my boyfriend. I'm like mm-hmm. Um, but I think there's also a conversation that needs to be had around like, 'cause people keep saying like, ethical ai, ethical ai, I am like ethical is like moral based.
Like everyone has different definitions of ethical. Yes. So I guess it's like, how do we build AI and like, like what standard like baseline standards do we need to have to say, this is good versus this is bad.
Right. Right. Because we are even talking about that on like hackers.
Right. Like, we're talking about how kids are, we're trying to get kids into ethical hacking versus like, you know, a lot of times kids get like pulled into the wrong thing when they're doing hacking. But we're like, okay, at that point, what's ethical hacking like Yeah.
Where is a line? Like, can you scam a scammer? Yes.
Like, is that ethical? Yeah. Because you're still scamming.
Right. But like, so it's the same with ai. Like how are we drawing that line of like what's right and what's wrong and what, what AI should be doing and what ai AI shouldn't, and That's so nebulous right now.
0 and this Japanese animation studio. Have you seen those Japanese animations that are like flooding social media? And so the whole, I Have a very like, narrow lane with social media because all I see is like for stuff for you because it's, it's for work.
But anyways, I did not see it. But It's, so the whole copyright infringement Okay. Challenge is there.
And it's like, well, AI and, and you know, chat, DPT, philanthropic, all of them are te are training their models on all of this information that probably they have without permission. Right. But how else do the models learn?
So there are fine lines, but I think the challenge is it's so nebulous. There are many fine lines. Yeah.
So to your point on ethical hacking, where, where are those lines? Yeah. It's not a, it's not a straight answer.
Right. But you also talked about people, and I always say, I had this friend out my other show who created stickers and used to have stickers on his laptop. And one of them said, humans Yeah.
Ruining everything since forever. Right. And I loved it.
But in cybersecurity, humans are, I think two things. The weakest link, but also the biggest potential asset. Yeah.
Do you Agree with that? Oh, for sure. Yeah.
And I always used to say like, you're only as strong as your weakest link. Yes. With every company.
Yes. I'm like, I don't care what what you do, but if you, if someone's clicking a phishing link, it doesn't matter any of the software they anything that you deploy. Right.
So I don't, I always don't understand like why companies don't spend more money on training and awareness. Granted, I think there's a lot of, uh, training awareness companies that need improving. Agree.
Um, I, I go to a lot of training awareness conferences and stuff and I'm like, Hey, can we not go do another fishing email? But you See opportunities, you see. I know, I know.
Um, there's so many other ways to do it, but, um, yeah, I think there's so many opportunities because again, you're only as strong as your weakest link. Why aren't you spending more money on trying to like, again, educate the people where they're at? Like, why do we keep shoving training and awareness into, into corporate, you know, employees faces?
Oh yeah. Around, Hey, you need to protect corporate. Why do they care?
Yeah. Why would, why would I care? Yes.
Who cares? I mean, yeah. It's, it might, you might lose your job, but like no one, you have to get to them.
Like actually, like the impact, the impact that it matters. Like okay. How to protect your family.
'cause they guarantee you, once they start learning how to protect themselves, they're gonna start learning. They're gonna automatically protect the company, which is good. Right.
That's The right pathway. Right. But we're not even teaching 'em like that.
No. Because it's a check the box and then there's like some fun awareness stuff, but it's like, meh. Yeah.
So how do you, how do you advise companies to change that? Make it more fun, but to your point, go where they are. Go to their comfort zone.
'cause people don't wanna get comfortably uncomfortable. Right. It's hard.
Oh, very. It's cultural. Yeah.
It's behavioral. Well, that's how, that's how I always recommend. I'm like, okay, what, what is, what is your company culture?
And if you were them, like I always, whenever I talk about training awareness professionals and people like are wanting to get into cyber, I'm like, you should start with training awareness. Yeah. Because those are the, you are the, the prime demographic people that have no idea what cybersecurity is.
Yeah. And you're trying to get in and you're trying to understand, but like get understand the culture. Yes.
Get someone in that's not, that does not care about cyber, does not understand cyber and start picking their brain and asking 'em, like figuring out how, like how you can relate to them. Yeah. Um, because that's where you're gonna have to meet them.
Yeah. And then I just assume that most people fall in the mill, but like, you can't, as, you can't like do a check the box training. You can't.
No, because I, when I worked at TikTok and I was trying to redo their internal training too, like I had to get so much oversight from like legal and like GRC. I'm like, this training is not gonna do anything. Like, you brought me in to like, you know, spice things up with training and make it more fun and do short form videos and, and I'm like, and I can't do any of that with like, the way that you're redoing my entire like, script.
That's what kind of anti TikTok mindset It was. It was kind of weird. It was kind of weird.
Yeah. I love TikTok though. But it's, yeah.
What, what has surprised you in the last few years of being cybersecurity girl and, and amassing this following who are learning so much from you? What enlightens you about the direction that career paths are going? What's out there?
That's good. I mean, there's so many things that are out there that are good. And s honestly, so many cybersecurity people are good.
Like, there's so many of us because we got in, like, we were pulled in from other people that we wanna help and mentor and like help other people. What's um, incredible is like how many people are wanting to get in. That's good.
That, and I don't wanna be a negative, but like now we're at this point where I get so many people messaging me being like, Hey, I've gotten this certificate, this certificate, this certificate. And I can't get an entry level job anywhere really. So whatever they're saying about entry level roles is a load of bs.
Okay. So, Because I think a lot of entry level roles are actually mid-level roles Okay. That are trying to be paid as entry level.
And a lot of companies don't actually wanna train the people on site anymore, which is really sad. 'cause that's how all of us learned. Yeah.
I mean, all of us got into cyber. We were brought in by a mentor trained on, on site. Right.
I'm sure, I mean, I'm blanket statementing. I'm sure there's a few companies out there that, but like a lot of the companies I've seen, they have like entry level, well mid-level roles classified as entry level and they want people with actual like more skills. And there's so many people, like I get like at least tens to hundreds of people a day messaging me being like, how do I get in?
Yeah. I don't know what to do and there's not really a direction yet. So I'm really excited 'cause there's so many people that are interested in Yeah, that's good.
Now we have to figure out as a even like a country or like a the world honestly. Yeah. How we're gonna navigate this because also the, the definitions of cybersecurity are different in every company.
Oh, right. Yeah. Like everyone has different teams.
Like some has access management and they, they, they're, maybe they're doing the same thing. They're called something different. So like I was trying to work with NIST and say, Hey, is there a way that we can have like 10 of the same exact entry level roles exactly the same or exactly like equal with the what you need.
Like, so, okay, hey we have a analyst that needs these like qualifications. Then we have like a threat intelligence person. So I want the same titles Yeah.
With like clear expectations of what they need to get. And that way, like when people are hiring entry level, at least make, make the fortune 100 all do the same when they're hiring. Yes.
It'd be a lot easier to transition people in. It would, and then you can train them then on their company culture. You pick them on their com your company culture.
Right. The alignment best. Right.
Yeah. So that consistency is, is critical. It's no longer, um, a nice to have that the, the awareness has to be consistent.
Right. Um, but like I said, marketing 20 years in tech awareness is key, but it can't be a one and done thing. Right.
And it has to be tailored to your audience. Right. Right.
And there are so many different audiences alive and you know, in, in the digital space today, I went to the restroom earlier and I saw a payphone. I'm like, there's still payphones around here. Yeah.
I remember having to use a payphone in high school. But I have a question for you. Yes.
What's like one thing that you would change with either like awareness or marketing in like cyberspace that you like, wish it was like already fixed? I think that it needs to be, to your point, it needs to be explained in a way that this is achievable. Right.
And it's not scary. It's not scary. It's a massive opportunity.
It's only growing. Mm-hmm. So the opportunities will only grow.
Yeah. But I think to your point, from an education and awareness perspective, I, I I a hundred percent on the consistency, but it has to be explained clearly. Yeah.
A lot of people like to get on soap boxes and all these acronyms here and there. Oh, We don't talk about acronyms. No.
Straight. I do not say to me straight, say missing, straight pushing. Yeah.
I don't even say C anymore. They're scam messages. Yeah.
Yeah. That's what it is. Yeah.
No one, if you start doing like technical jargon, their eyes glaze over. Yes. And they're gonna be like, I, I can't even touch that.
That's not even something I wanted to, I've learned that From my radio role where we talk to more consumers. Mm-hmm. It's, it's how do you take com and, and you and I were both in the sciences, both in aerospace back in the day.
Right. And it's about taking complex topics Right. And converting them to digestible sound bites that a non-technical person can understand and go, I get it.
Yeah. Well, I don't feel like I ever was supposed to be in cyber in like a weird way because I never wanted to be. And then I learned everything on the job and I still, I don't know about you, but I still feel like I never know enough.
Oh yeah. Which is the best place to be, by the way. Yes.
Like, I always wanna, I wanna be in a room that everyone knows something and I know nothing. Yeah. First of all.
But then I also just feel like because of that, I like had to learn weird ways. Like I don't think I'm, like, my brain is supposed to operate the way that most cybersecurity are and so I have to learn it in a different way. That's Well, it's thought Diversity.
Yeah, it is. But which Is so necessary. Yeah.
You brought up earlier, you know, when you started your influence career and that you couldn't, it was that saying like, we can't be what we can't see. Right. I do a lot of women in tech events.
Yeah. And it's true. Yeah.
We need to have mentors out there and sponsors Yeah. That look like us, that feel like us that go, okay, I could be accepted here. Yeah.
And the older you get, the less you care about that stuff. I will tell you. Yeah.
But, um, yeah, but It's the younger generation that we're trying to get in. Yes. You know, It's Yes.
But there's so much job opportunity. I mean, like, I I work with companies all the time that will have like different, um, programs. Yeah.
Like some like Boomie, I'm Mc Boomie World in a couple weeks and they have, um, a veterans program. So they work really hard with, with war veterans to get them into cyber and into technology. Right.
And I, I think there needs to be more light shined on things like that. Like there's a lot of doors and pathways, but to your point, if the employers are making it complicated Yeah. That's not gonna help that pathway become men easier.
And the other thing is, I don't know about you, I feel like as a woman, because there was like DNI DNI initiatives when I like got in like 12 years ago, I always felt like I wa I didn't know if I was hired for the right reasons. Yeah. Even though, like I, and I, I'm not, I'm gonna toot my own horn.
I had an incredible resume. Like, I, I had three jobs in school, I had three different internships. Like I nailed my interview, but I always had that like weird thing in the pit of my stomach being like, was I only here for, because I'm a woman?
Did I check a box? Did I check a box? And then it really made me like the imposter syndrome actually really like set in a lot of times.
Yeah. And I, I actually am kind of happy, like I want as many women in this field as possible. Yeah.
But I also want the best, most qualified people in the role. Yes. And so I want to make sure, I feel like it helps with imposter syndrome too, from a woman perspective.
Like, agree, don't hire a woman because we're a woman, hire the person for the right role and we're, we're trying to train the women to be the right woman. Yes. Right.
So I think there's like a weird, well There's also all these stats and I'm forgetting the actual specific stats, but like, like, I don't know, 80 plus percent of females, if they see a job on LinkedIn and they don't meet every requirement, they don't apply. Whereas men Oh, I got that. Yeah.
And so, and now with ai it's even more challenging because everybody wants people with AI experience. You're using AI to write your copy. How do I set out?
I use It, write everything. Oh, I wrote my radio here for it tomorrow morning. Right.
GR chat this morning. Yeah. It's the best.
It is the best I get. I like it as a, a creative inspiration. That's how I leverage it.
I, I have a lot of good stuff going in my mind. Probably you can tell with all the conversations that we have, but it, it really helps me do like a brain dump and then it helps me reorganize Oh yeah. How I should frame things.
Yes. So that's what I love about it. Yeah.
But I think for folks that rely on it, that's a different story. Yeah. And I think I, I was reporting on this recently about like, it's a really high percentage of, of students between like 17 and 25 who are dependent on things like chat, GPT.
Can you Imagine going through school with that as a resource? I would be dumb. My thesis would've been would so much easier.
Yeah. I Would be, that's, that's the challenge. Are you not learning enough or retaining it because you can get it spit out you back at you in seconds.
Yeah. So it's it's a double-edged Sword. Yeah.
But it's like, like I say, technology is inherently neutral. It's used for good and bad. Right.
Let's find all of the good uses and amplify that everywhere. For sure. I feel like a sense of responsibility as, as, as a, a tech executive and now a reporter and media person to help more people understand how not to be afraid of things like ai.
I talk about it all the time on the radio. Yeah. Why there are risks and I want to help you be aware of them, but let me tell you all the things that it's already doing that you're interacting with that you don't know.
Well, and I think I, I was talking to someone else about this, like, I feel like everyone's like, oh, buzzword ai, buzzword ai. But like, we need to move past the point of like ai, because ai, even when AI was a buzzword like two years ago, It was already implemented. People just didn't talk about it.
Exactly. So I'm like, it's already like, I mean, net, the Netflix recommendations, your Instagram, the face filters, your Instagram recommendation, everything, it's already AI already used, technically ai depending on your definition. And so it's like, okay, well how do we move past like, okay, AI is like everywhere it's gonna take over.
Here are all the, the scary risks to, okay, let's implement this in our day because we're not gonna run from this. We can't, we can't. It's already here.
Oh yeah. So how do we like optimize it the most? I think I made a video about like the four things you shouldn't be putting in like ai Lm Yes, I saw that.
I saw That. I'm like, we're gonna use it. So like, here's just FYI don't, don't be putting this information.
Little guardrails. Yeah. But, but then there's healthy uses of it and it's like what?
Like some of the applications in healthcare Yeah. Are Phenomenal. Yeah.
Detecting skin cancer, I mean, you name it. And, and the train has left the station. Right.
Chat. GPT was born. It just catalyzed this movement.
Yeah. Yeah. Where every company that I work with either, either as a marketer or as a member of the media, we have to have an AI story.
Well, what is it? Yeah. It has to be real.
Yeah. And then you have to go, okay, here we are at RSA, how do we secure ai? Right.
It can be done. It's not easy, but it can be done. We can get proactive against the defenders.
Yep. We just have to be constantly doing it and learning and evolving. Yep.
And the tech is evolving faster than laws and regulations. It's just such an interesting time to be alive and be working. I know.
I'm a, I'm, I'm, I'm trying to figure out how the, to best optimize it honestly. Yes. Like how, what do I do to like, make sure that I'm fully taking advantage of this like massive growth.
Agree so fast. Agree. It is so fast.
What's next for you? We know we follow you on at cybersecurity. Girl, you were just in Montega.
Was that the NATO youth summit? Yeah. Awesome.
Yeah. And then you came here, got stuck in Barcelona, but you came here Stuck in Barcelona, but I came here. What's next?
What can we expect to learn from you next? I mean, I'm gonna just constantly, constantly be throwing out amazing videos hopefully. And educational videos.
And I'll tell you my like future goal is to like have like a kids, like Bill and I kind of show, but for like STEM and tech and ai. Love that because I, I am, and something I talked about at NATO was like, we have so much responsibility and opportunities with these kids to make AI and cybersecurity not a scary thing and not a necessity, but like fun. Yes.
And if they're able to be like curious and play with it from the beginning. We are gonna see massive growth in that field from when they as, as they get older. Um, and so I'm like really excited about the future of that.
But I love, I wanna do like a TV show. I, I'm ultimately just trying to build like a trustworthy, continue to build a trustworthy brand. Yeah.
Because I do feel like it's my responsibility. People be the one person that's like, Hey, no clickbait, no bs. Here's what's going on.
Yeah. And here's what you need to do. And like, have, have fun.
So, Well, you're democratizing access to all of the generations for cybersecurity. Why It should be part of their, their fabric, their personal fabric, their professional fabric. Yeah.
And why it's a good thing and not you're demystifying it. Yeah. And that's needed.
Yeah. That's what I always say. I always say like, I'm demystifying cybersecurity as a whole.
Like in general, you are careers, cyber, whatever it is. Just, that's where I wanna Be. Well, keep doing what you're doing.
I learn 10 from you, like every day. I appreciate you responding to my DM the other day. I'm like, Caleb responded.
I felt Like so cool. Oh my gosh. I appreciate you messaging me.
Of course. Yeah. And I wanted our audience to be able to learn from you because this is something that is just the fabric of our daily lives.
Yeah. And we appreciate your insights, your time, and sharing all of your knowledge with us so consistently. Thank you Caitlyn.
Thanks so much for having me. It was my pleasure for Caitlin, Sarah. And I'm Lisa Martin.
This wraps up four days of coverage at RSAC 2025. Yay. Big hand of applause for our amazing production crew with Tech Junk tv.
We thank you for watching. You can find all of this content by next week on the socials. And if there's anything that you wanna watch again, lucky enough, you can do it.
Find us at Tech John tv. com. Too many, too many brands to mention.
But thank you for giving us your time. We hope you've learned from our guests. We'll see you at the next show.
Hey, everyone. We're back here. Live at RSA conference.
It's Wednesday morning. Things are starting to kick up here. We've already had a full day.
Of course. We recorded our Textron gang at about eight o'clock this morning. Then we did a new segment special here for RSA called the Analyst Arc with, uh, three FU analysts and talking about their vibe, not vibe, coding, their vibe from RSA conference.
My next guest needs no introduction to our audience here. He is one of our good friends. One of the, you know, I don't wanna embarrass him, but he's one of the founders of the AppSec movement Right.
Early on with swa, everything else. Uh, he is also a co-founder, right? No, you're not.
You're C-T-O-C-T-O And founder at Contrast and founder of Contrast Security. Yep. My friend Jeff Williams.
I knew you were co-founder, but I always say CEO and it's Ct. Right? Right.
That's why I wanted to make sure I got it right. Jeff. CEO's a terrible job.
C CTO's. Much better job. CTO's the job you want.
I, I agree with you. Um, but you know what, young kids out there don't know that everyone's gotta find out for themselves, I guess. Yep.
You live and learn. Anyway, Jeff, it's great to see you here. Good To see you too.
What is this? Maybe seven, eight RSAs maybe more? Yeah, I've, I've done Yeah.
More like probably 12. Well, I'm saying that you and I have have interviewed together. Yes.
Oh, I've become, become an RA since 2002. Right. So Yeah.
You're similar kind of thing. Um, you know what, Jeff, let's start off though. Maybe there are some people out here don't know Contrast security.
Just quickly. Yeah. If you don't mind.
Yeah. So We're an application security company. Uh, application security risk is accelerating really quickly now, particularly with vibe coding and, and other things.
Mm-hmm. And we take a runtime approach to application security. So we actually watch the code run, give you real details on what's really exploitable, who's attacking you, what libraries are actually in use.
Like it's all measured directly from a running application. So it's real, it's not theoretical results. Right.
And, uh, we do that to keep you safe and more importantly your customers and children safe. Absolutely. Well, no kidding With Children's Safe.
You know, Jeff, one of the interesting things about Contrast, and I've told this to people before and I got this spiel down now, is for much of the AppSec industry you focus on, the AppSec industry focuses on the security of the application before the event horizon of deployment. Yes. Right.
And that's like sort of a black hole, right? That deployment event horizon. Yeah.
And all of our, and if we could say all of our AppSec focuses left of that horizon. That's right. Traditionally, traditionally.
And, and for good reason, you it's supposedly faster, cheaper, more efficient. Well, We should talk about that. Absolutely.
But recently, I know Contrast, what was the movie Interstellar? Remember that movie? Yeah.
You've gone through the Event Horizon. That's Right. Three Event Horizon.
We come out the other side and, and one of the few AppSec vendors that actually have a story about real runtime application security. Right. Uh, and to me that's what sets you apart.
I don't know, as a CTO you have a better handle on this than me, but as an observer, that's what sets it apart. Well, you're exactly right. Traditionally, we've put a lot of bets down on helping developers write perfect code.
Yep. But I, I don't know, do you feel like developers writing perfect Charact? I don't think there is such a thing as perfect code is the problem.
Yeah. It, it's, I Think it's like a holy grail and It's a moving target. Yeah.
'cause stuff changes. Um, It's like saying, I'm never gonna publish something that doesn't have vulnerabilities And look, so we've put a lot of bets on that and it, frankly, it's not delivering. Right.
Right. Like, most companies have massive backlogs of vulnerabilities that they're not triaging that that whole approach to the problem just doesn't really work. Mm-hmm.
And so we had, uh, the insight to say, Hey, you know what? In production we can see everything. It's not, you know, in, in development you see pieces of applications.
You see one repo of 20. You see, uh, the libraries, you see the source code, you see the APIs all separately. But in production, they're all assembled together.
You analyze the whole thing at once and you can see exactly where it's being attacked. Exactly. Where it's vulnerable.
And you can help companies focus on the, you know, the few percentage points of issues that are real. The ones that have crossed the event horizon that are actually being attacked in production. Mm-hmm.
Those kinds of problems. That's where you wanna spend your, your very limited critical AppSec resources on fixing those problems. So even though it seems counterintuitive to focus on security to the right, 'cause people like the idea of shifting left.
Right. The problem is it just hasn't worked. It's, it's backfired.
com. 'cause I think people realize that you, when you over shift left, what are you saying Your developers, your security guy, I'm not saying developers raise their hand and say, man, do I like to write in secure code? No.
A developer says that, but you don't have developers raising their hand and say, I'm your security guy. Also. True.
That's Not who they are. Also true. And so that, I think the whole rise of platform engineering is recognizing we can't ask developers to build their own secure platform in addition to coding their apps.
Someone's gotta do it. Yeah. So the way runtime security works is, is very much like other kinds of detection and response.
Mm-hmm. Like EDR and CDR. Sure.
And the one thing to realize those technologies don't stop application layer attacks. Right? Yeah.
They see stuff in the kernel layer in the cloud or whatever, but there's a gap, the application layer. Yes. And so into your platform, you install a DR and it instruments the actual running applications and watches it as it runs.
That's how you detect things with full context. And so after that, it, it works just like the rest of the XDR ecosystem. Sure.
You, you know, telemetry gets collected. It, there's a dashboard, but it also goes into your SIM and you can correlate it with the rest of your events and so on. But it's, it's a very natural part of operations.
Agreed. It's just missing. Agreed.
Let me ask you a question. Yeah. I was a Q con in London last month.
Observability. Yeah. Everything's observability.
It is. How does the a DR play in the observability, this new universe of observability? Yeah.
It's a very similar concept. In fact, we call it security observability in a lot of contexts. Fair Enough.
And observability is interesting. It started to the left of boom, like in, in development. Mm-hmm.
And companies like New Relic and AppDynamics and so on, you'd monitor development. And then they realized, Hey, what are we, what are we measuring test systems with? You know, not real data, not real users, not real load.
And they're like, well this doesn't, it's not realistic. 'cause they didn't have the right context. So those tools moved into production and they measure real reality in production.
Yep. Uh, and that's the same transformation that AppSec is going through. Yeah.
That's, if you measured in test environments, you don't have enough context. You don't have real users, you don't have real threats, you don't have real anything. Yep.
And you get all these theoretical findings. So when you move into production, that's when you're measuring reality and you can focus on what matters. And that's, that's what we're helping companies Do.
You're walking in that same footsteps here. Exactly. Right.
It's, it's the logical route. It's how stuff evolves. So in our never ending quest for the single plane of glass, be you envision a future where security observability and, you know, call it mainstream observability or whatever, can be in the same interface, could be in this, the same platform.
I could imagine that, although I think it's more likely in the short term that we'll see it as part of, uh, CAP and Sure. And sim kinds of integrations that, that data, they're already collecting security telemetry and building a security graph. And our data, you know, we have a graph.
It fits into the other graph. Like that's, that's how that works. Observability is a little bit more of a jump 'cause it's different users, right.
I think today, but ultimately, if we achieve the vision of DevSecOps, that we'll break down those silos and everybody will be working off one model of reality. We call it a digital twin. And, and that's, it's come a long way now too, especially with ai.
It Has. So we're building a digital twin of your application layer. Not one app at a time, but the whole thing.
So That, wait, this is new to me from you now. Yeah. Let's start over here.
Yeah. So talk to me. So Imagine you've, you're a big complex enterprise.
You've got hundreds of thousands of applications all connected to each other. APIs containers. Right?
Now we're all confusing. So when you deploy contrast, you can deploy it across that infrastructure. Like we got a Kubernetes operator.
You just push it out. It's part of platform engineering, right? Absolutely.
You Push it out, then the telemetry starts coming in and we take all this telemetry that's coming from all these apps saying, you know, things like, what's the attack surface? Where are the vulnerabilities? Where are the attacks?
Where are the assets? All that's coming together. And we're building a digital twin.
It's, we call it the contrast graph, excuse me. And it's, it's a model of how your application layer works. It's a lot like the wiz graph except for it's not infrastructure.
We're talking about another layer of abstraction, all the, how the application layer works. And with that, you get a lot of benefit. You can put vulnerabilities in context and say like, oh, well I understand this vulnerabilities in this app, which has this blast radius.
And you can really get good risk rating. And you can use that data not just for like vulnerabilities and attacks, but you can use it to feed into your threat modeling process, your pen testing process. No, I'm, I'm a big believer in the digital twinning.
I, I think one of the nice things about all the AI buzz that goes on and, and our ability now to kind of get our hands around bigger, uh, infrastructure or, or bigger Pictures. That's what we had to do, is it's not easy. Our old, you know, two years ago contrast used, uh, our telemetry flowed into a SQL database.
Right. And that's limited work, right? So we moved to a modern streaming data architecture.
It's Kafka, it's graph databases. And we're, we've built a massively scalable data collection Platform. That's, you can do that too.
It's, it's Because our news from Splunk Oh. So obviously, Yes. And so he, he came in and said, Hey, you know this, we need to collect more data, not less.
And so we've just been en enhancing our telemetry building a a, a awesome Model. Well, no, once you're able to get your head around or your hands around all that telemetry now you start applying the AI and stuff. Exactly.
And you start seeing insights that you, you, you just couldn't see before. Runtime security and AI go together, peanut butter and jelly. Like no doubt.
Because runtime is is real. It's measured directly from running apps. It's not theoretical stuff.
It's not No, I get tons of false positives. So yeah. They, they go together really well.
Love it. All right. This camera's on you.
Right? Okay. Tell them how they get, how did they go get this today?
Yeah. Uh, it's, it's easy. I mean, you can go to our website, you can learn a little more.
com. Right. Okay.
And, uh, there's stuff you can try. If you want to give it a, give it a spin, um, we're happy to come in and do a POV with you. But the, the deployment process is easy.
You get our installer, you push it out to your, your containers or your workloads, wherever they are. Uh, we don't really care whether it's on-prem or in the cloud or whatever, whether it's APIs or applications. Right.
We support all of that. And, uh, almost immediately the telemetry will start flowing. Uh, particularly if you deploy in production.
And that's really where I think you should Yeah. Put it. Then you're gonna see you, you'll get amazing visibility into what's happening.
I will tell you, you're probably in for some surprises. Like there's probably a lot more attacks going on on your application than you, you thought. Yep.
And attackers are probably reaching vulnerabilities that you didn't think that they were able to reach. That's scary. You may find some log for shell that you didn't know about.
By the way, we All, it seems it's all out there Still, Jeff. Good stuff. Really good.
I'm really, you know, it's not often I get to hear new stuff like, hey, Application security has, has not been innovating as fast as it do Know it. Uh, you know, with, with the boom coming from AI development. I mean, if you're, if you're Producing how you get our ducks in there, 50% more code or a hundred percent more code, I, I don't gotta find AEC team is gonna double.
So you need technologies to help you scale into that double. We don't have another AppSec team as it is for what we were producing exactly three years ago. Anyway.
Hey man, this is great. I love it. Appreciate you're doing it a great job.
Appreciate Jeff. It's always, man, you're the best. Alright.
Jeff Williams, contrast security. Go check out what he was talking about here because this is the kind of stuff you are going to need. Not three years from now, not two years from now.
Now we need it now. Go check it out. We're live at RSA conference.
We'll be back in a minute. Hello and welcome to the latest edition of the Techstrong AI video series. I'm your host, Mike Bazar today with Chris Brownley, who's senior vice president of product for Yext.
And we're talking about AI search and how it may be changing the way we discover things and interact with content and maybe just turning our lives upside down. Hey Chris, welcome to the show. Oh, thanks a lot for having me, Mike.
We've all seen, I think by now the AI search results that you see, and sometimes they're generated alongside Google and other times people are just going in and using AI search tools without even going anywhere near Google. Um, how prevalent is this at this point? I mean, are people not looking at the links at all?
Um, 'cause and how accurate or how, uh, comprehensive are those results? Yeah, I, I mean, being in tech, we probably we're more on the leading edge than, than anything do I think my mom is going in here right now and, and doing this? Not, not just yet, but I think it's very, very close.
Like we all know Apple's baking it into to phones. Google has it with Gemini. And so to me that's where it kind of crosses the chasm.
But, um, but obviously the big distinction here is for the last 10, 15 years, when you do a search, you get a bunch of, of blue links essentially, and you gotta go hunt and find what you think is the most appropriate for you. And what changes with AI search is that you ask a question and you get a very direct answer or you get prompted to give a very direct answer. And so there's a lot less exploration happening, um, when you're looking for an offering or a product or a service or, or information even.
And some of these tools are now purporting to do research for you on specific topics. And, uh, you know, they're searching a bunch of different, I'm assuming websites that come up with some sort of conclusion. And I think that's based on the reasoning engine that they provide.
But how do we know that they're kind comprehensive enough to generate something that's accurate or, or most people just gonna say close enough. Yeah, I, I mean, especially with the, the last two years, I think the biggest fault that everyone would point to with any of this generative AI tech is it's prone at times to hallucinate, uh, and to give in accurate information. And so I think that's obvious.
One of the biggest areas that these, uh, companies are focused on is how do we get rid of these, these hallucinations? And so if I'm a a a business online, I want to think a lot about like, how do I make sure it has the most, um, information about me, my services, my offerings, and, and that it's being consumed as as accurate as possible so that when it does get pulled from, it has far, far less chance of turning into a hallucination that gives someone bad information about my business or, or how I could show up And some competitor that doesn't even exist. Right?
Hundred percent. Yes. So I think there are a lot of people who are having this gut check moment, 'cause they're looking at the way this shift is gonna happen, and they've spent years on SCO and buying Google AdWords and all kinds of things over the years, and they, you know, they, they kind of understand how that system works and how to drive themselves up a response list.
But, um, how do I do that in the age of ai? How do I kinda get myself inserted into an AI search that may not, you know, generate the level of links or, you know, I mean, I don't think most people make it past the 10th link anyway, but at least I was in the game. Yeah, a hundred percent.
Like there was a dashboard that you could log into to try and like update your information to know how you were even ranking in the first place, to know what that was turning into for business impacts. And none of that exists. You can't log into chat GPT or perplexity and manage how you're showing up there.
It's a complete black box. Um, but going back to the last point, these LLMs are still feeding off of the web. They're still crawling this information and they're doing it as frequently as possible so that they are getting as accurate information as possible.
And so there's still ways to impact how you show up to have, ensure it has lots of, uh, good, rich, accurate information. But where you used to focus on just Google as your single pane of a most important single pane of glass for ranking, now you need to think about it across all of these different LLM AI search backed interfaces because they're crawling data and giving import to different sets of data than what Google used to do. And so AI search for chat, GPT versus perplexity versus Gemini might use very different citations when they're actually citing this information as well.
So knowing what data is being pulled and used, it becomes really important for someone trying to manage their performance online. Are there formats and ways that I should configure my data so that it is more consumable by these AI search tools? I mean, what, what are we talking about there?
Absolutely. Like, if, if anything more of the game is not just about creating content for your end consumers or people who's gonna view the content is can you even make sure it shows up in the first place? Um, and so this is a lot about making your content easily readable by these crawlers.
So it's simple things like having good schema markup on your pages or being as as clear as you can in the data, um, to help them target it to the right customer. Um, I think about you, the opening, I just said that they were gonna go more into product catalogs and being able to show what, what offerings you have to for more retail goods. To me, I know that chat GPT builds up a memory about who I am.
It knows I'm, uh, who I am, what I'm interested in. And so when it makes product recommendations going forward, it's going to take that into account. So if I'm a marketer, I wanna try and add as much information about who my product is suitable for, like different use cases, different ways that we might want it to be shown up because it's going to be looking for such precise answers to give back to its end user that are very tailored to them.
So I need to know, I need to provide that information that makes it have that best chance to show up to meet those criteria. I think back in the search days of when it was just straight up Google, we were always trying to figure out, well, uh, should I change my content often or less often? Because if I don't change it so often, maybe Google will like it better that way, but then recently maybe wants more updated content.
So it tends to favor that with, um, AI search. Um, it feels like it's continuous, but you know, how frequently do I need to kind of update my environment to keep that position? Then I might ultimately get within the memory of the AI search engine.
Yeah, these are all of the experiments that we're trying to run today to figure out, like we know with pretty good high accuracy what the things you are you need to do to rank in Google today. Um, and it is like frequency of updates, it's consistency. Um, the biggest things that we're seeing right now is, is just having really well structured data that's easy to be consumed and crawled so it can be well indexed to even just show up in the first place.
Those seem to be, uh, from all of our findings, the things that will give you the most chance of showing up. If, if you don't have any of that in the first place, like good schema markup or, um, well-structured data, um, you, that's just step number one, uh, in the battle. What's your feeling about, you know, looking into your crystal ball?
How soon will it be that, you know, the way we currently use Google search will just fall by the wayside become antiquated? Or, uh, will this be like a demographic thing where, you know, old, old guys will be using Google search and the kids will be using AI search? I can't see a world where the traditional ways last long and I, I can't even imagine it being a, a, a generational thing.
The ease and simplicity of not having to think about what you're searching for in terms of a Google search query where you have to like, you kind of gotta shift your brain to put it in terms of like, okay, how do I make sure I get the results I'm looking for? Where with these LLMs I can ask a very human based pros question. Um, I can have a conversation to refine that search and know, um, how to get it more, more tuned into what I'm looking for.
It's just such an ease of use solution that gives you the answers you want essentially immediately, rather than having to hunt and peck for these things that I, I like for me, in terms of timeframes, I, as I kind of touched on, like as soon as this becomes baked into our daily day-to-day devices, I think that's when it's gonna really cross the chasm. I think, uh, even just this last month chat, GPT was the highest downloaded app in that month alone. Um, I think within Google.
So it's, it's already happening though. I think this is gonna happen, but won't I just wind up with a, a lot of AI agents that are anxiously standing by waiting to help me and every time I'm working on something they're gonna say, Hey, do you want me to launch a query looking for this, that and the other? And, you know, they'll make quote unquote helpful suggestions.
I don't know how annoying that might get, but um, you know, that relationship is gonna change where they're not gonna wait for me to do something. Yeah, a hundred percent. Well it's funny 'cause you think of like sci-fi movies and stuff, you think of it as just being this one all seeing, all knowing ai, but really what we're seeing is the rise of these like agents where it's lots of many, many different ais that are specified to do one job really, really well.
Um, I see it like the internet being 99%, these agents just like communicating with each other and finding information before it actually gets to the end consumer at the end of it. And so yeah, what does this look like if you were to go like five years down the path? Ah, it's hard to, to even predict because you will just be interacting in behind the scenes.
I think it will be, uh, agents interacting with agents, interacting with other agents and, and what does that look like? And I, I couldn't even forget guess right now in my crystal ball. So what is your best advice to folks about how to kinda get, you know, get down this path a little bit, especially, you know, I think end users will figure it out on their own, but if I'm trying to be the company that, you know, maintains some level of attention in this new age, how do I, uh, get started?
It's citations. They've always been a thing in traditional SEO. If anything, they're more important than ever right now.
And it's knowing though, what sources are being cited by the ais and then making sure you're on top of those places. So it's interesting, I've been doing a lot of testing around like how do financial services businesses show up when I search for them or search for a specific agent, for example. And it's adding sources like websites I'd never heard of before, um, for just like, like address phone address.
It's, it's, it's using MapQuest all the time. Like who's, who's managing MapQuest? com, like things that probably me as a financial services agent and probably paying zero attention to right now, but these are the things that are representing my brand.
Um, any information about me. And so I need to actually figure out what those sites are and get on those to manage all of my information because those are the things that are, are powering how I show up. And so you need to know broadly all of these different citation sources and then make sure they're all being up to date managed and that they also have the same information.
Because as soon as you get dissonance between multiple sites, the there's less trust in that data and there's less likely the, the LLM is going to surface that information because they don't want hallucinations. That's obviously one of their biggest concerns. So it is still managing your presence online, but it's almost even more important than ever if you wanna show up in AI search, which almost feels backwards.
Will we fall back into the same trap we had with Google search where we all wound up using the same search engine? Um, or will AI search be more diverse and there'll be more tools and more engines and we're not gonna have this, uh, you know, concern about monopolies, et cetera, et cetera. Uh, it's such a hard one we're, 'cause we're in such early days of it.
Um, you know, back when it was NetSuite and Naje Eves and all of those, probably no one foresaw it going down to a single tool. And I think we're still very much in that explosion phase before we get to any kind of, of coming back in there. Also, there's gonna be a lot of lock-in.
I think that starts to happen with, with this memory storage. I think, yeah, it's just too early to say, like, I would say plan for more fragmentation for the next five years before I would say like, go all in on just optimizing for one. OpenAI has a clear lead in terms of AI search engines and like referral sources.
Gemini obviously being, having a lot of power behind itself too with being with Google. Um, but I I, I personally, if I was a marketer, would not put all of my eggs in one basket for the the next while. Do you think I might see agents in search tools that are optimized for specific, I don't know, vertical industries for salespeople or, you know, if you've got a hobby, maybe somebody's gonna tune up an AI search engine that's optimized for that specific hobby 'cause it's trained on that particular kind of data.
How granular can all this get? Yeah. Um, there's lots of tools popping up like that with, with retrieval or augmentation based on like very industry specific data.
Um, and even some of those tools are just getting baked in to the tools that we use. You can create projects now in chat GPT where I can load up a whole bunch of information and then be able to query against it and get, get insights. And this is where I think the agents will, will really have their time and place where they're really deep experts in doing one thing really, really well and then can hand that off and can be reverified and rechecked.
Um, and that's why I don't think it is just like one tool to rule them all. It will be each of these individual things that will, will do their, their jobs. Uh, very specifically Around folks, you heard it here.
Hey, they used to say, you know, the medium is the message. Well, the medium is changing. It's called AI search now.
So stay tuned and we'll see what happens. Chris, thanks for being on the show. Uh, thanks a lot, Mike.
I enjoyed it. All right. Thank you all for watching the latest episode of the Textron AI video series.
You can catch this episode and others on our website. Until then, we'll see you next now. Hi everyone.
We're back here. Live at RSA, it's Tuesday. Well, you know that if you're watching this live, you know, it's Tuesday.
If you're not watching this live, take my word for it. We filmed it, we recorded this on Tuesday. We don't film anything.
Um, anyway, let me tell you a quick story. com. com content March of 2014.
In February of 2015, we did our very first DevOps Connect here at the RSA conference. And the idea was to bring together the, uh, security, we didn't call it cyber, the security community and the DevOps tribe. Yep.
Easier said than done. You know, in subsequent subsequent years we started calling it Dev DevSecOps Connect. Yep.
But there wasn't DevSecOps 10 years ago. Yeah. The closest thing I could find was something called rugged DevOps.
And Rugged DevOps was kind of the term was coined not by Patrick Dubar, of course, who did DevOps. Yep. But Rugged DevOps came out of a tall, lanky Texan out of Austin named James Wickett.
And here's James 10 years later. There You go. There you go.
And um, what was rugged DevOps is really what we call DevSecOps. Yeah. You know, today it was, and um, of course a lot happened in those 10 years, right?
DevSecOps became a thing. James, I think back then, this was before you were working with, um, the Signal scientist folks Before Signal, but you were one of the organizers of of DevOps days, Austin, which was like the, for my money, the best DevOps stays in the let's States. Let's, let's go Alan, let's go, let's go.
And it's next, next week. What anniversary? How many years is That?
This, this Thursday and Friday. So I'm, I'm flying from here. Oh, you Going right there?
Two there. How many years is DevOps Day Austin. Oh, okay.
I think we're on the year 12 now. If I, if I remember right. But probably, yeah.
Right. Or around That's, this is my fourth day in San Francisco, so I'm not sure my math may you won. I get may not check out right now.
I'm chock full of medicine, so I'm all over the place. All right. But anyway, so I've had the pleasure of knowing James for 10 years, 10 plus years now.
And you know, in some ways as I get older he does it. And, but I see You're very kind to say that, that very kind to Say that. But I've seen, I've seen his career.
Right. Evolve being a, an organizer of it, working for people. Signal science has came a long way.
And then founding his own company, dry Run Security, um, if you're not familiar with Dry Run security, I'm gonna make James tell you all about it. But he's, he's having tremendous success early on as I knew he would, frankly. Right.
Because he, he just does things the right way. Smart guy and, and works. Right.
He's a an example to all of you out there, James. Hey, talk to me. Hey Alan.
Thanks for, thanks for having me on. Yeah. You know, it is funny you mentioned the rugged DevOps thing.
'cause it's like I, I feel yeah, sure I put the words together, but like there was the whole rugged stream going on at the time. Yes. It was the DevOps stream.
And so, you know, I, I don't know, it wasn't, it wasn't rocket science on my end. It was just like, we should connect these things. And I, I've always loved how you're always trying to get these, these groups connected as well.
Mm-hmm. And yeah, we had a lot of like rugged DevOps DevSecOps days just trying to like continue to, to bring that conversation, uh, even here at RSA, so. Sure.
Yeah. That's awesome. Um, but, you know, take credit for one credit's due.
Yeah. Okay. Thank you.
I will. A lot of Stuff is evolutionary not revolutionary. Yeah.
And so you had this DevOps thing going on. You had the rugged movement going on, bringing that together was, was a eureka kind of moment. Yeah.
And, and look, there were others. We had Josh Cor, if you remember Josh Corman, those first ones. Josh Corman was there and Gene Kim was there and you know, John Willis and, and all of these, I mean the, the folks who Yeah, we were all just, we were all trying to figure out how to do, how to do this.
Yeah. It's great. Um, I'm, I'm drawing the blank.
Did your LinkedIn DevSecOps course. Oh, With, with Ernest. Ernest Mueller.
Yeah. Another, A lot of the, a lot of the Austin folks. Ernest and Karthik, uh, down there doing stuff.
Yep. There's one guy we're missing. Ernest Karthik, you, who's the fourth guy?
We also have, uh, PECO and Bill. Those are, those are some of the other recognizers that have been kind of in the mix down there. So yeah.
Good times. Good group of people. But anyway, James, enough history.
Okay. Yeah. Let's talk dry run security.
Okay. Assume some of these people have never seen or heard of Dry Run. Yeah.
Yeah. Yeah. Why, why would they have, you know, dry run security?
We're very new. Okay. And, uh, um, we see it as we've developed a new way to do code security.
So we call it contextual security analysis. Um, we, we believe that pattern matching is dead. That, uh, trying to, we've been doing, uh, in like the SAST world, uh, static, uh, code analysis and, and all that space, you know, we've been doing pattern matching and a ST parsing for, for all this time.
And it's really kind of generated more or less the same results. Um, better UI in some pace, marginally better experience for people. Um, but contextual security analysis lets us, uh, uh, takes a, take a context driven approach that doesn't do pattern matching, but we're trying to find risk in the systems.
So, uh, yeah. So driving security's great. It, it's, um, we're having a lot of fun doing it.
I'm doing it. My co-founder is, uh, Ken Johnson. He ran internal security over at GitHub.
And so we, we both have, he wrote he, and he's the original creator of Rails goat. Oh, okay. So we've kind of just have always been friends in the AppSec rails, Ruby on Rails, used to really love Ruby for some time there, so, yeah.
Mm-hmm. Very cool. Um, you know, it's an interesting time to start a security company.
It is, yeah. It's always an interesting time to start a security company, but this is a particularly interesting Time. This is, it's a heck of a time.
A lot of people are saying, where's the innovation? Mm-hmm. A lot of people were saying AI is the greatest thing to happen to security.
A lot of people were saying AI is the worst thing to happen to security. AppSec has been kind of where a lot of the action in security is. Yeah.
Pipe, pipeline, security, you know, all all the software pipeline security Yep. Kinda stuff. What, where was the passion for you, James, that said, this is what I, this is what the world needs.
I could somehow make things better Yeah. By doing this. Yeah.
It came outta two streams. One, I, I really felt like, um, the AppSec, the sast world has kind of been the same. And I, I realized like, uh, you know, I had the whole gauntlet stuff that I worked on many years ago and mm-hmm.
And then just like, I care about, uh, developers having a good time with security products. And I felt like we just still really hadn't delivered on that as an organization. And, uh, two, fortunately whenever I called my buddy Ken and I tried to convince him to start the company with me, he had been having a really frustrating time with Code ql, uh, their internal, they, they, they acquired that product and were running a GitHub.
And so he was, he was ripe to, to do something new. And we knew that like by looking at the context of what's going on, like how the surface is changing, what kinda language and framework they're using, how the developer decided to write the thing and why they're doing it, what led to that and how, how it's overall designed and architected and how that, how application's actually gonna be used. All that stuff really, really, really matters.
And, um, and that's how you can find real meaningful risk that doesn't match, like SQL injection or cross-site scripting or all the stuff that we've been talking about as an industry for the last, you know, I don't know, it seems like 20 plus years. Absolutely. Yeah.
Absolutely. Now, you know, you, you look at all that. So I, you know, I've been in this DevSecOps thing now for 10, 12 years.
One of the things that I, you know, hindsight's always 2020, right? That's right. That's right.
That's right. Yeah. But one of the things that, looking back I realized might have not been the smartest move we made, was really emphasizing the whole Schiff left thing.
Mm-hmm. Right. We're gonna shift left, we're gonna shift left some more, and when we're done there, we're gonna shift left even more than that.
We're gonna go as far left as left can go. Yeah. And I think in retrospect, thinking that developers would be able to use security tools designed by security people was a mistake.
Yeah. And maybe we should have been emphasizing shift everywhere, and maybe we should have designed security tools for, excuse me, for security for developers. Yeah.
Not for security people. I, I believe that last point is that that's a salient one because it's, I mean, the idea of shifting, it's, and, and a lot of the organizations we talked to as we're kind of building the company, and as we, we discovered, we discovered two, two key facts that like, they felt the penalization of all those security tools being put on them. So nobody really loved, like the, the alerts and the Christmas tree of lights that they were always given, and developers weren't having a good time with that experience.
So the stuff that got shifted either got turned off or got muted or got unshifted. Um, and then we also realized that, uh, security leaders or, or engineering leaders in, in that case too, their, their code is changing constantly. Like, um, some of our customers have five, 600 developers, their code changes a thousand times a week.
2000 times a week. It's, it's easy like that, that's, that's not unreasonable for them. So now how do you find risk whenever you have that constantly evolving and, and it's only getting faster?
So when those two forces are, are joined, uh, yeah. The tools that, that we had shifted weren't really Right. They really needed a whole new class of tooling built just for, for developers to kind of solve that, that problem.
I agree. Yeah. I agree.
Um, there's been another sort of movement that I think is exerting a gravity pull on, on this whole orbiting thing, and that's platform engineering. Yep. Right.
We've seen it. com as Yep. As a result.
Yep. How do you see that playing into this whole tech ops? How does it affect dry run?
Yeah, I think platform engineering is an interesting group, and specifically like we play in the infrastructure, well, some of the infrastructure is code that people are working on. Um, can I tell you a story about one of our customers? Sure.
We got, sure. I, I won't, I can't name their name, but, um, they're like a direct to consumer, uh, business, and they got, uh, we'll call it 60, 70 developers. Um, we came in there through the, uh, through the platform or the SRE team who was just trying to like say, how do we give security tools that work?
Mm-hmm. Well, part of our product is like we, we, we ship traditional SaaS. Like we, we can, we can beat the traditional players, the SaaS, but one cool thing that we can do is find risk, um, that, uh, that you can't find.
And we through in like traditional patterns, and we call that natural language code policies. And for every customer we sit down and we start out and we will usually build them out a natural, natural language code policy that says something simple like, is this code change? Adding sensitive data to our logs?
So every time the developer's making changes, are they like, now emitting customer data or P-I-I-P-H-I or whatever to logging, you know, we've all been in the organization where it's like you get audited and then like, then somebody, um, somebody says, Hey, look, you got some whatever PII or, or some sensitive data in your logs. And then you gotta look back for 12 months and now you got an issue, a, a report and you gotta like, you know, have some sort of disclaimer on your audit or your compliance. And if you have a tick mark on that, um, you also get stuck in a situation where like, now you're trying to triage, like, how do we ever stop this from happening again?
So I called up our customer, we just, just signed. I was like, Hey, uh, how's it going? How's, how's it been?
You're like, week two or week three. He's like, that, that PII, that sensitive data logging thing hit last week. And, uh, within 24 hours, the developer I got with 'em and told 'em like, Hey, we can't do that.
And they were, but they were dropping data, customer data dumps for this new like LLM like recommendation engine that they were building. And we said, uh, uh, uh, let's get that fixed. And so we were just, we were just going through like how much that would've cost, uh, to remediate and under like our traditional lives that we've ever handled before.
It's like hundreds of hours, uh, to deal with that problem. But if we can just deal with it in code before it, uh, gets shipped or gets shipped all the way, or redact it as soon as we can, um, you're able to, you know, do do amazing stuff there. Yeah.
Absolutely. But you can't find that with patterns. And that's where our natural language code policies really, really gets into finding new types of risk for folks.
What I find interesting with it though, the platform engineering stuff, James, is it's kind of like telling the developers, I know you want to build quality code. I know maybe you don't want the Christmas League tree security thing. Yeah.
We're gonna build the environment for you. Yeah. I, I think one of, again, hindsight, 20 20, 1 of the things about DevOps is we told developers, look, you got everything.
Yeah. Including building your own platform. That's right.
Right, right. Alright. You live and learn and you adapt.
Right. And you iterate. That's, that's DevOps.
We iterate, we reiterate and iterate again. Yeah. Um, and it, it is an interesting thing.
I think AppSec is a, is a perfect playground for that. If or not a playground 'cause we're not playing but a perfect, uh, use case. Yeah.
It's for that, it's natural overlap of that. Yeah. Now you mentioned a few times that you guys are using SAS technology, SAST for our uh, yeah.
Audience out here. That's static code analysis. Yeah.
Or it's Yeah. Static application security testing is the, the acronym and yeah. Now there are other kinds of fests, das and Yep.
Some other, there's proprietary kind of, everybody makes a few I asked and stuff Asked is another One. Yep. There's, But the, the important thing is you recently, and I didn't talk about this with you, but I, you know, I follow you on LinkedIn.
Yeah, yeah, yeah, yeah. You recently, you guys recently published a study Yeah. On speed.
'cause speed is important when it comes to scanning on speed and dry runs. Yeah. And accuracy.
And accuracy. Excuse me. Yeah.
Yeah. Tell us about that. Yeah, so we, we had, we thought, alright, we built these, this really cool platform and we really invested a lot of time building the engine.
And then we, uh, created across, uh, four different languages, 26 different, uh, kind of easy to get vulnerabilities, but we wanted to just test effectiveness. And then we, uh, took some of the popular tools like Sim GRP and SonarCube Snyk, uh, code QL from GitHub and, and then ourselves. And then we just started committing all this code in that had, uh, these problems.
And, uh, we were really surprised, uh, to just, uh, what happened is like we, because our approach is remarkably different, like we were double the effectiveness in accuracy, um, then the next, then the next category of tools. Um, and then even in that category, there's quite a bit of divergence from like, uh, who's kind of coming, I think outta the next one in like the 40 percentile was like sim grip, but then like some of the other ones were like in the 10% or 8% percentile. So, and we dry run was in the 80.
We, we got, I think we got an 88% on the, the scoring there. So it's a limited data set. We have some more, um, languages and stuff we're gonna continue to release, we're really excited about.
But we really wanted to show, like, as an industry, we've been really, um, we've been really hooked on the idea of static assessment being like matching patterns and parsing like code trees and looking for source and sync and stuff. But contextual security analysis that does like a more holistic look, uh, building up this code context window like we talked about. Um, it's way more effective.
You can learn a lot more about your system. Uh, it actually speaks to developers 'cause it's giving them relevant feedback about the stuff they're actually working on. Um, and we can tell security people like where their hotspots are, where what matters, what, you know, what, what they're seeing in their organization.
So Of course, this year's show, like last year, frankly, we're hearing all about AI agenda ai. Yeah. How's that figure into the dry run kinda strategy?
Yeah. I think that, you know, we are, we have a lot of LLMs under the hood that we're using to, to do a lot of our analysis. Each of our analyzers are tuned to look for their own specific things.
Um, our natural language code policies are full agentic where they can go find out the real truth about a system. So instead of just saying, we think you have a vulnerability, we can go dig into the code to, to find out if that's, uh, really true. Uh, customers love it and it's, and it's way more accurate.
So that really, really helps on that. So, um, I'm, I'm excited by what, what AI is providing to our, to our industry and like what it's allowing us to do. And, um, I think the results, it's the result in that report kind of speak to themselves of like how much more accurate we can be.
Um, 'cause And that's really the key. 'cause we need, you know, going fast by in and of itself is not enough. You need to be fast and accurate.
Accurate. Yeah. I remember, um, I think it was in London at one of jean's, uh, DevOps Enterprise Summit.
I was doing a video with John Willis and Damon Edwards. Okay. You know, it was, it wasn't about security per se, but it was about DevOps.
Okay. But fast secure, what were the three things I want to do faster? Code Resilience, maybe Resilience and security.
We can, we do want it all. Yeah. And so having fast results that are not accurate Right.
Is having no results. Yeah. Yeah.
And that, that's really The thing in our report, we kind of call that out. We're like, some of the ones that were like, out of our payloads, they only found one or two. It's like, that's really scary.
That means you could check in like legitimate, you know, problems and nobody says anything, but you do it quickly. So, you know, that's, that's, that's, I, you know, you gotta watch out for That. It's, I remember back in the day when endpoint security similar kind of thing.
Yeah, yeah. Because let's face it, semantic McAfee, back then you installed that on your machine. It was a pig.
It would slow your machine down. Yeah. And so a lot of the AV companies were making their whole bones on, Hey, we're faster and lighter.
Yeah. But faster and lighter. That doesn't catch viruses.
Wasn't a great antivirus. That's right. That's right.
Yeah, yeah, Yeah. It's the same thing here. Yeah.
James, what's the website? Okay, so if you just go to dry Run Security, um, and then right on the front page it just says like, get the 2025 accuracy report and you click that button and, and we'll ship it to you right away. And how about people maybe want to try out dry run security?
What's their best on-ramp? Yeah. There's two, two options.
So if you want like a self-guided tour, you can go to Dry Run Security and install the GitHub app there, or GitLab is coming soon. Um, or you can click, uh, I think there's a button there. This is like talk to an AppSec expert or whatever.
And we'll usually sit down with you for 5, 10, 15 minutes to make sure, uh, write a natural language code policy with you and kind of get, get people up and running, but super lightweight to get to get rolling with it. So, Hey Alan. Thanks.
Congratulations. James Wicker, one of the nice guys in this business, dry run, do security. Check it out.
We're live at RSA. I think we have one more coming up. So stay tuned.
Good afternoon. Welcome back to Techstrong tv. Coming to you live from the second day of RSAC bustling with over 45,000 cybersecurity experts.
We've been having great conversations the last couple of days with experts in the field. There's a a lot of risk, there's a lot of challenge, but there's also a lot of opportunity. We're gonna be talking about some opportunity in the blurred lines between a personal and professional lives.
I've got a couple of guests with me here. Matt Covington, the global head of product at Black Cloak joins us. Thank you.
And John Boyle from our very own tech strong team, Phil, CTO, and tech strategist. Welcome guys. Thank you.
How's your show been so far? Fantastic. It's been, it's been great.
It's been busy. Lots of impromptu meetings with old colleagues, which is always very enjoyable. I always think it's like a reunion.
Every tech trade show is a Reunion. It, Which I Love meeting new friends face to face for the first time too. Right.
Absolutely. I met you name, like I know you from Zoom. Exactly.
So Matt, talk a little bit about Black Cloak. I know this is a pioneer in digital executive protection of DEP, but Yep. The company was founded just a few years ago.
Mm-hmm. I love the name Black Cloak. It's a great name.
Yeah. Uh, what problems or gaps in the cybersecurity market were there back in 2019 when the founders said, there's a problem here, we've got a solution. Yeah, Absolutely.
I think what it really comes down to is what is the definition of your attack surface as a company, right? Traditionally, you think about your, your hardware, the software, there's, you know, network telemetry security, there's boundary security, there's external security. Increasingly as little as they may like, the fact executives themselves in their home lives are increasingly becoming part of that corporate attack surface.
And so really the founding mission of Black Log was to provide security services that a CISO could buy that could protect the executive in their home life. Whether it's personal devices, uh, personal computers, uh, and all of that security service wrapped in a sort of user friendly concierge Yeah. Uh, kind of service.
And so our, our guiding principle from our CEO is where every time we have a feature is could mom use it? Right? We are not selling to, uh, technical people who are very technical knowledgeable.
Okay. It's really all about you know, is this easy to use? Yeah.
Uh, yeah. That's, that's our guarding path. John Path John kind of brings some color here.
Uh, it's never anything that I thought about. I don't live in a cybersecurity world. I cover it, but, you know, it, it's just not something that I thought about in terms of, of executives leaving work, whether it's working from home or working from an office back in novice these days and having their personal lives be bombarded by these threats is, have you seen a trend in the last few years of this going up?
So I think this was new to me, and one of the things really is great about this is you find some new things. There's a lot of topics that are really hot out there. Yeah.
But one of my joys is finding and, and connecting the dots between the technology, new technologies and services to somebody like my parents who are healthcare executives. And that, and you think of healthcare, it's critical infrastructure. Right?
It's important to us. And so when I, uh, engage with Matt, and we talked about black cloak, I had not really heard of the term digital executive protection. And so it was new to me and my job was to figure out how to describe it to my dad, Bob.
So Bob understands it. Yeah. Much better.
So I think that, I would say growing up with two healthcare executive parents, the problem's always been there. Yeah. It's just that the nefarious people out there doing the attacks, they're realizing that the home life is an island hop away from the enterprise.
Absolutely. The bad guys don't respect their boundaries. No.
So it's, They don't respect anything. No. Well, this is true.
They, they, they, they Kind of have a reputation for not respecting anything. But it's just, it's so interesting in the last few years with the explosion of chat GPT on the scene. Every company is ai, ai.
We've gotta have an AI story. Yeah. We've gotta enable our executives.
They need to, they need to have, especially during COVID 24 7 communications with their team. Right. And so you're talking email, slack, text, WhatsApp, you name it, LinkedIn, all of these are now attack elements.
Yeah, absolutely. It's part of the attack service. I think one of the things we were really careful to try and do early on in the life of the company was kind of create a value proposition that gave the CS o on the one hand, the assurance okay, that folks are protected.
But on the other hand, we were talking directly to the executors themselves. Right. We were onboarding them.
Everyone gets a personalized Zoom call where we'll onboard them, we'll, we'll walk them through installing the app. Okay. We'll describe our services.
We'll ask them whether they have any particular concerns, and we don't share all of that personal information back to the ciso. Now we'll give them enablement, uh, data so they can tell that, yes, I bought it for my 12 executives. And yes, all of those 12 executives have now been through their onboarding.
But there's a lot of the, a lot of the time you're not necessarily comfortable having your corporate IT team knowing everything about your social media posts. And yet that is an incredibly, uh, incredibly interesting attack vector Sure. For the cyber criminals.
Sure. And so we try and straddle that. On the one hand, we have a have to have a relationship with the ciso, but on the other hand, we're really in business to serve the execs, the members themselves.
Yeah. Yeah. How much of it is, is behavioral of, of education, of le of making these executives aware?
Look, there's no boundary anymore. Yeah. This lines are blurred.
Yes. How much of that is, is really just educating them and is it, I don't wanna say, I don't want to say it's an easy conversation, but they probably get it pretty quickly. They do.
Uh, one of the things we do, um, so, uh, our team will show up to that initial call with some initial findings. And like, oftentimes, well, you know, we found this street address by looking at the dark web. Was this associated with you?
And somebody will say, God, I lived there 11 years ago. That's really out there. Me too.
Exactly. Yes. So typically we'll sort of softly introduce these elements and say, Hey, look, just so you know, all of this information is out there and available, and this is what we're here to talk about today, is making you safe.
You can take a, you can take a deep breath, you can take a so relief. We're, we're here to solve those problems for you. And, and then as you get there, it is much easier conversation.
I'm sure it is. Because it's, well, the threat service, I mean, there's just more and more vectors every day with the absolutely amount of data that's produced, all the applications, all the software. And that's not gonna slow down.
Well, the other thing is that it's not just the data online. The way I, the way when I talk with Matt immediately, the way I described it, I mean, it was the image I got. And if anybody's seen the movie Usual Suspects, Kevin Spacey, Kaiser Soce, because how many times have you sat at a stoplight and you look at a minivan, like, oh, they got six kids.
Two of 'em are girls. The youngest one's a boy. They have a dog.
Uh, they like this sports team. And, and so the, the message of that movie, if have you haven't seen it, is that this person being interviewed by the police weaves a story of this, this mysterious Kaiser soce, um, with information that's behind the guy, you find out the end on a bulletin board. Mm-hmm.
Right? And that also, we have six kids at home. They're not home anymore.
They're not, but, but they're on Xbox, they're on Facebook, they're on Instagram. They're posting pictures of themselves flipping a water bottle and celebrating. I mean, all these things that they can be a story that's woven that, um, can be compromised.
So it's not just digital, it can be anything. Right? Mm-hmm.
And it's absolutely education. Yeah. Well, because it's, I wouldn't think, I know those stickers you're talking about, like on the back of the minivan that shows like the dad, the mom, the kids, the dogs, the cats or schools, or a proud parent of an alumni at this university.
Nice job, Mary. You got a's That's great. I'm your dad's friend.
You know, how's your dog doing? Yes. You know, I mean, wet sounds weird.
Think Absolutely. Because it's, it's kind of like a personal freedom. But now we have to be careful about that.
You too. But you guys are, you're talking about entertainment personalities, athletes. Yep.
Um, other highly visible personas who That's right. Are susceptible and probably highly unaware of this because they're just going about living their daily lives. Absolutely.
But now they have to be aware of this. And I think that's what we provide. It's peace of mind and that expertise to take care of these problems for you.
But again, a lot of what we're doing are things that if you had infinite time and a lot of, you know, a lot of interest in it, you could figure out how to remove yourself from data brokers. Yeah. Much better to let someone else take care of that for you.
And so there are many elements of what we do. There's part of a, a SaaS platform, which is doing things, data, broker removal, identifying breach credentials that have been stolen. We even do like an attack surface style scan of our members home networks to make sure there are no vulnerable services, uh, exposed.
There's a lot we do there. But as you said, there's also an element you can't necessarily automate, for example, reviewing some of these Facebook settings to make sure they're appropriate and they're not oversharing. Yeah.
And so on the education side, that's absolutely something we can do. And our members at any time, they can go into the application, they can schedule a concierge, uh, appointment with a member of the black club team who walk them through those things. We get all kinds of interesting questions.
I bet. For example, yeah. I'm traveling, traveling to China, what should I do?
Should I take a burner phone? What should I do when I get back? And so that's really what we're there for, is to be, it's beyond just simply the features of the automated service.
It's really to provide that expert guidance in all aspects of, uh, digital life, but also going into the physical as well as you said. Yeah, That's a great point. Going into the physical as well.
Yeah. And I think the other thing is we, and I think you, um, if we go to traditional benefits companies provide to executives, there's a reason why when I was at Oracle, so many people could travel on an aircraft together. Yep.
There's a reason why companies provide key person insurance. There's a reason why, um, some companies like the, the big, uh, OEMs will send their executives once a year for MRIs and those sorts of things. Right.
They're all preventative. Yeah. Mm-hmm.
Because my mom and dad's world, as we talked about, you can go do, have a preventative exercise and it, it's gonna cost you something, right? Mm-hmm. But there's a much steeper price for the major medical when you, you know, you find something out later.
And so I would say, people say, well, is this the CISO's job? No. This takes a burden off the ciso.
Yeah. And it, but provides a buffer. But I was talking with you and, and Tracy, uh, their chief marketing officer, I said, if I was to tell somebody this is, uh, this should be an HR must do.
Absolutely. And it's not just a C level. You have people that are vice presidents.
Um, there's a lot of people in you. I have a group with some people who were, you know, in Hollywood, and they didn't grow up like that. Mm-hmm.
They didn't start that way. They weren't born into it. And so they have the privacy.
And so, whereas Warhol said everybody wants their 15 minutes of fame, my quote, the first thing I ever I ever tweeted on Twitter was anonymity the fame of the future. Yep. Because absolutely, you need to, you know, you need your private life.
And these guys here, um, are are just there to help. And, and so that when you, when Bob comes home, my dad and he wants to watch my ball game, and you know, he can unplug too, right? Yeah.
But do so with confidence that everything they do is not gonna be used against him in his job and in, in nefarious way. Yep. And so I was very impressed with what they're doing.
It's a service and a solution, and it's something that my dad, for instance, should be doing. My mom should be doing. So Bob's got it.
No, Bob needs it. I wanna talk to Bob. I'm gonna introduce you to Bob, we'll get it Done.
We'll deal with Dale. He gets The concept though, Dale, he gets the concept. I was reading on the website that Black CLOs DEP solution provides 14 pillars of protection.
Yes. Summarize that for us because Absolutely. It is.
This Is the anonymity, John, that you talked about is that's a luxury that a lot of people don't realize I want that they don't have. Yeah, Absolutely. And so we, around those 17 pillars, we have data broker removal.
We are looking for breach credentials online. And again, the company is probably doing that for their corporate email address. Who is taking care of that for the personal email address.
The spouse's email address. As I said, we do home network scanning. We even have what we call our deception engine.
And so if you have black cloak installed on a PC in your home and somebody is on your network and looking at what services are available, they're gonna see an FTP server. If they try and look into it, it sets off an alarm in our sock where we'll jump into action to protect them. So across the full range of security, privacy, even into things like home protection, we will remove the image of your home from Google Street View.
Wow. 'cause Again, that Right? Yeah.
Exactly. We started to see some really scary, uh, extortion where emails, where that was front and center as in, we know where you live and therefore you better do what we say. Right.
And so we're always finding new ways to add capabilities. We just launched something called identity verification, we think is going to be really the next exciting thing for us to talk about. And this really, if I have my circle of trust with my family, and then I get a phone call or a message from one of my kids saying, Hey dad, I, he sent me a thousand bucks so I can bail myself out.
Right. I don't wanna take that on faith. And so if we both have black cloak on our app, I can send an identity verification challenge Yeah.
Over the air that he can respond to. And so if it is him, he can click verify if it isn't him Yep. He can click deny.
It's just an additional step that we're able to take. So within the family or within a work group, you can trust you are speaking to the right person. 'cause both of you have black folk on the device.
We know the device is secure, it has a secure connection to black work cloak. So we're able to sit in the middle there and mitigate, uh, and work with these identity and verify requests. So we've actually, we've talking about that a lot this week.
Yeah. Talk About about though, great feedback from It. Yeah.
That's amazing. I think the other thing though is that people say, well, what, what industries need this technology? Here's the thing.
Every is that we talk about healthcare, financial services, energy, heavily regulated mm-hmm. Critical infrastructure. Yep.
We talk about nonprofits. Where do government officials go a lot of times to work after they're done? They go to a nonprofit, a foundation, they have relationships back at intelligence community, DOD State.
Right? So it's an island hop away. And, um, I would say that it, I look at this, I'm like, yeah, every, every organization who is responsible for protecting a service or something that is the fabric of our communities like healthcare, are responsible for engaging these things proactively.
And so, uh, I think it's an HR thing. I think that it, I agree with you on that. It's not, it's not a C level, it's not a c CTO or CISO or a CTO thing.
It should be part of every HR package. And the other thing is that you think about like, while we're all here this week, I would say, why do we fight? Yeah.
Yeah. We talk about the, the bottom line. We talk about the brand, the data, the end of the day we talk about healthcare.
There's kids in the nicu, there's people who have cancer records. A mom was in the hospital and she coded in her room, and what if the lights went out then, right? Mm-hmm.
So, so these organizations are protecting human lives. Yes. We, we, we gloss over that.
Yeah. Yeah. So this is a way to make sure not only the families protected, but that that connection to the organizations that are taking care of a lot of people are, are doing that extra layer of defense that is just a no brainer.
Yeah. I Mean, oh, it's, it is a no brainer. Yeah.
Are you seeing, pivoting on what John just said? Yeah. Are you seeing any talking about healthcare, financial services, insurance, some of those heavily regulated industries that have a lot of personal data on us?
Yes. Are you seeing leading industries that block CLO is working with, or this really seems to be to be a horizontal play? I Think what you tend to find with a lot of security use case, financial services tend to have the budget first.
Ah. But yeah, we, financial services healthcare very strongly represented. But it is across the board, it's all kinds of companies.
We have consumer goods companies, we have food processing companies, uh, you know, just about any market segment you care today. And there's probably somebody in startup portfolio there, because the, the issues aren't industry specific, right? No, no.
And so Is this the new way of life for executives? That's a great question. I think it is.
I, and I say that because at the end of the day, the risk, the bad guys aren't going anywhere. Right. The tools at their disposals are becoming increasingly sophisticated Yes.
With ai, right? Yes. Yes.
You know, and particularly with deep fakes and sort of I was gonna ask that. Those are DeepFakes are crazy. E exactly.
It Just amplifies the problem. Yes. Exponentially.
It's sort of one of those, the song remains the same. Right? I'll go for the left thing Reference.
Exactly. Yeah. We're now, we're ripping, It's all about, uh, it's about spear phishing attacks, but the sophistication of those attacks when you can just grab 30 minutes of audio of a, of A CFO giving their earnings report, and you can feed that into a internet website, and you can have them say anything at all, anything you want.
But it's incredibly important that, you know, we, we have tools and services available. And again, that was really the, the genesis of identity verification. It was sort of like Google Authenticator, but you know, to verify between two individuals that yes, you are who you say you are.
I, I am who I, I say I am. And deep fake really, I think was driving a lot of concern from members of, we, we just don't know what to do. We don't know where to turn.
Is there a consumer play here down the road? Because I could see this being something that everyone is gonna need at some point, probably in the near future. That's A really interesting question.
I, I think it's definitely the case that, I mean, you made a good point about, you know, it's not just the executives. Anybody in an organization who has a public facing role. It can be executive, uh, assistants, it can be the finance team.
They're dealing with vendors often. And so you're looking for all of those edges Yes. On the organization.
So I think there definitely is a hierarchy, um, that certain individuals, like it or not, are going to be richer targets. Right. They they have more money, right?
Yeah. They have more influence that I could potentially exploit as an attacker. Um, but yeah, I, I do think a lot of these services, if you look at, you know, a lot of these, uh, consumer identity protection services are starting to get more into these areas.
I think what the take we tried is to, what needs to be different for like the busy executive to engage. They're not gonna sit down and fill out a, you know, four page form to our board, right? No.
We need to Make it easy for them and seamless. Yeah. Seamless Integrated.
You know, it's, it's also when you look at, you know, you look at the, the consumer solutions, their, their technology solutions software, their apps, and, and the thing that Black Plug provides that's always compelling to remember is the concierge service. Mm-hmm. They're the ones that get called at 3:00 AM It's not an automated thing.
There's people, there's education. And so I think, I guess the way I would describe it as, you know, you people buy a Porsche for a Porsche, or my wife would say Porsche. Sorry, Porsche.
I know. It's like that's, that's the northwest to be coming out a Porsche. Um, and you know, there's been attempts where Porsche or other, other companies that are trying to target that, that certain audience for a purpose try to make like a Toyota and well, there's a reason you make a Toyota versus a Porsche.
Mm-hmm. Um, I think that there's application there, but I think that you don't want to, as we say in the United States peanut butter spread it and take away from the focus they have. Correct.
Because there's a lot of work to do right there. Good to said it by to myself. Right.
By Well said. Yeah. Drop your mic to that.
Right. Absolutely. Thank you so much for coming on the program and explaining what digital executive protection is like to you.
That was a new term to me. Mm-hmm. Um, just kind of opened my eyes to, wow, this is a new way of life for executives, but that you have the solution Absolutely.
That is able to really educate them on this risk landscape Yep. And help them protect themselves. Perfect.
So I'll end on my one note from the article that in the movie they talk about the devil's greatest tricks. I use that angle. Yes.
And my closing statement on the article when I first met Matt, was the gr the devil's greatest trick is not piercing your firewall, but making you think that your executive's home life doesn't matter. Yeah. Yep.
Absolutely. That's basically it. Wow.
And and your job, everybody out there proactively Yes. To take care of this Yes. And avoid react incident.
Absolutely. Absolutely. This is fascinating.
I'm gonna be following Black Club. Thank you so much, guys, for pleasure having describing the, the risks, but also the opportunity and the ability to use technology for good. Yeah.
We appreciate your insights and your time. Yeah. Thanks for having us.
All right. My pleasure. For my guests, I'm Lisa Martin.
You're watching Text on TV Live from RSAC Day two of our coverage wraps up with one more interview today. So stay tuned. I'll see you in just a few minutes.
Kubernetes pours a sidecar quantum navigation TS MCs A 14 AI process. We're gonna reset some things to factory defaults. CNCF stops a release HPE gets even more secure.
And then we're gonna take a look at some of Intel's future layoff plans in this episode of the Tech Field Day rundown. Hello everyone, and welcome to the Tech Field Day rundown. Today is April the 30th, 2025.
And, uh, I have a, a confession. It's, it's actually three days in one that are all slightly related. 'cause it is National Oatmeal cookie Day.
It is National Raisin Day. You can see how those things are related. Uh, and it's, uh, national Honesty Day.
And, uh, honestly, uh, oatmeal raisin cookies get a bad rap from pretty much everybody out there. Uh, so yeah, there we go. Uh, leave your comments in the, uh, in the video below if, uh, you believe that oatmeal raisin is the superior form of cookie, because the superior form of co-host is joining me today.
Mr. Alistair Cook. Al, how are you today?
Well, today is an awesome day. Uh, there's a lovely storm raging outside, and I believe you've got a storm as well. So we're sharing weather for a change.
Uh, that of course brings us to something that neither of us are overly concerned about, which is National Hairstylist Appreciation Day. This wind is clearly not appreciating your hairstylist. Unfortunately, it is not.
But what we do appreciate around here is a lot of great news stories, and it's, it's been a fun week as we're wrapping up April, and we've had some stories that we wanna take a look at some fun stuff, and honestly, some not so fun stuff. But we'll get to that part towards the end. First thing we wanna do is kick off with some news about everybody's favorite container that isn't named Tupperware.
33 now includes native support for sidecar containers, which makes it easier to manage and deploy them alongside apps. This update also improves routing, pod placement and storage handling while adding some new features for security and resource management. Al, I guess the biggest question that I have about this is, are we gonna be able to find all the Kubernetes lids for these sidecars?
Well, hopefully you'll end up with matching lids and sidecars along the way, uh, as, as we want to keep our containers secure with those lids on them. Uh, sidecars are, are a really important characteristic of Kubernetes and, and, uh, a really common pattern for building container-based applications, uh, for those who haven't come across them. The issue with containers is that they hold a single process.
And so where you need maybe an, an additional process to send logging messages or another process to handle maybe some sort of data delivery, uh, this is achieved in Kubernetes through this concept of a sidecar. Uh, there's another container that runs inside a portal alongside the one that's running your application. And you can imagine that quite often there's a dependency that these sidecars need to start up before the application starts up.
And that's the big change here, is that there's built-in support for that in Kubernetes, rather than every customer needing to build their own into their own application, maybe that application having to retry until the sidecar is up and having this dependency mapping essentially inside the pod is really very useful and reduces effort by, uh, large numbers of customers who are using sidecar extensively. Uh, I think it's a, a recognition that this has been a point of paying for many customers, that dependency management, and it's required lots of customers to solve the same problem, which to me always indicates that there's a feature missing in the product. There's some other cool things in this.
Um, as you mentioned, there's pod placements, things that are, uh, oriented towards places like cloud providers. We have multiple regions and, uh, multiple, uh, data centers within a single region. And there's some awareness and traffic being sent within the actual, um, what AWS would call an availability zone within the data center.
So you're not being hit with charges from moving traffic unnecessarily between those, those, um, availability zones. I would also flag that this continues, um, an interesting challenge that customers have. Enterprise organizations struggle with a pace of change in Kubernetes.
Kubernetes is relatively, and now for a cloud native application, it's actually slow moving. There's only three releases a year, but there are three releases a year to stay up to date. And there are significant challenges for organizations that have standardized on Kubernetes, but not standardized on where that Kubernetes runs.
And so they might have some Kubernetes and AWS some on premises, some running in Google, some running on Azure, some running in a service provider as well. And there are some complexities around getting everything to be at the same version. It's not like you can simply apply the same service pack across all of the operating systems because you don't control the operating systems.
And of course, new features are only available once the underlying Kubernetes platform has been updated. Now, good news is most of the providers have a pretty fast cadence of catching up with the, the latest release of Kubernetes and their underlying platforms. But then there's sometimes some challenges about getting new versions of the Kubernetes agents or all of of the other components or of the operators and so on, getting deployed out, uh, to all of your worker notes.
So although it's relatively slow for a cloud native platform, mat three releases a year can be quite challenging for enterprise organizations to get the best value out of these updates to Kubernetes. 33, always like seeing open source products with a one at the beginning of the version number, um, means they're actually fit for use. Um, Kubernetes of course, has been awesomely useful for a lot of organizations for a long time.
An Australian company just over the pond from us, or as we like to call it here in New Zealand, the West Island, uh, an Australian company Q Control has launched Ironstone Opal. It's a, a, uh, compact quantum navigation system Hmm, outperforms GPS, and it uses the earth's magnetic field in some really funky sensing rather than using the geostationary satellites. Uh, highly accurate, really useful in many the many GPS denied areas.
And we've seen cases of real problems with GPS jamming and, um, provided getting it in the way of our universal expectation to know where the heck we are, uh, much higher precision in in their testing, uh, small enough to be used on drones and vehicles. And for defense use, Tom, as you heading out the back, do you think you'll be using, uh, I probably can't afford it at this point, and that's probably gonna be the biggest thing we're gonna have to deal with here. So I dug into this a little bit 'cause it had quantum written all over it, so obviously I have to talk about it.
Here's the thing. Um, Q Control took a quantum magnetometer, and they are, that's, that's the little cassette thing. It's, uh, probably about yay big.
I, I don't know what this is in science units. It's, it's this big. And what it does is it detects subtle variations in the earth's magnetic fields at specific points all around the globe.
So essentially what it's saying is, is that if you drop one of these magnetometers anywhere on the planet, it can read the magnetic field and tell you where you are. Okay? That's not true.
The magnetometer can tell you the reading of the magnetic field. What needs to happen then is you are going to have to have advanced denoising capabilities to basically, uh, filter out all the junk. And then there is map making software that crew Control makes that will tell you based on the reading that you got from the magnetometer where you are now, if you read through a lot of the stuff out here, and I'm not talking about the press release that Crew control put out, I'm talking about like the Rix paper that they put out and all the other stuff.
They are not at this time saying that this is a replacement for GPS. It's a backup for G Ps. And the key thing that is valuable to them is that it is a passive system.
So everybody I hope at this point knows that GPS works by you walking outside with a GPS receiver. And if you can get in a lock on three to four satellites, then you know where you're at, or more appropriately, your sensor knows roughly where you're at based on the times delay that you, you get going to the satellites, that's great, but you can jam satellites. And we've seen that as becoming a bigger deal now because you've got, um, you know, the US has one, uh, set of GPS satellites, uh, uh, Europe uses, I believe Magellan, which is a different set than or operate a little bit.
And then you have, uh, Russia uses its own set of GPS satellites. And a fun fact, the reason why we have public access to GPS is because of the 19, uh, 83, uh, Korean Airlines, uh, flight seven disaster. We learned about GPS in like, what, 83.
And it really didn't come become commercially viable, I would say, until the late nineties, early two thousands. So that's 20 something years, 15, 20 years years before that technology became commercially viable. We are just learning about this quantum GPS technology.
Don't get me wrong, it's absolutely cool, but the cost is probably gonna be off the charts right now. So here's what I expect is gonna happen, because there's already reports that Lockheed Martin is working with Q Control as a supplier to provide, uh, this as an assistance for, um, devices and things that are operating in GPS jammed areas. You should just read that as defense applications and write, uh, neon letters.
These are gonna go inside of Humvees, these are gonna go inside of jets, and these are gonna go inside of things that jets shoot at Humvees, missiles, bombs, whatever, because that's important for precision work. We might see something like this, maybe two or three revisions down the pipe. So don't chuck out your GPS receiver yet.
I'm not gonna strap one of these quantum magnetometers to my, my back while I'm out on a run. Just know that they're working on advancing this technology and making it jam proof, making it cloud proof, making it indoor proof. Um, but remember that just like any good science experiment, being able to buy this at Best Buy is probably still a decade or two away.
TSMC has announced its upcoming a 14 line of chips, which is expected to be publicly available in 2028. They're gonna offer 15% better performance and 30% lower power usage compared to the future in two chips. The company also introduced system on wafer X, which, uh, is not something that they're trying to do to be more extreme, but it's in fact a new technology that combines multiple large chips with memory and optical connections for advanced AI workloads.
Since AI is dominating the market today to support these innovations, TSMC will of course be building two brand new facilities in Arizona, and that is gonna bring them into competition with Intel who has already announced plans to build facilities in Arizona as well. Al, is this a 14 process going to drive even more adoption of TSMC silicon for AI applications? Potentially it could.
Uh, one of the big challenges in in building an AI data center is getting enough power and enough compute density, well, it's usually power density, the compute density we can achieve. It's usually feeding it with power and taking away the heat it generates. And so 30% decrease in power consumption compared to their existing, it's gonna be pretty significant.
Particularly also in here is having the optical interconnect actually on the chip rather than necessarily dependent on external, um, external transceivers, which are a, a high power consumption item as well. Not sure just how much that's gonna be, uh, optical interconnect off the chip. The, uh, things that I've read suggest it's optimal inter interconnect on the chip between those multiple processes that are on this chip on wafer substrate.
So it's multiple chips sitting on, on the wafer and interconnected. Um, it's a, a little unclear exactly how that's gonna come out. And fundamentally, I, they're saying this technology is gonna to publicly accessible in 2028, and they're still those, um, there's production facilities in Arizona, um, as well as, uh, yeah, Phoenix area packaging plants, and, uh, there's gonna be a, a lot more construction there.
So, as always, this, this is a lot of promises about what will happen in the future, and we hope that TSMC will be delivering these promises and letting them go a little more toe to toe with maybe Nvidia, maybe, um, other vendors who are providing AI chips and AI accelerators. Uh, nice to see in there some of their enhancements. So things like putting voltage regulators actually on the chip alongside the processes, rather than having to send voltage, uh, regulated voltage from a distance, which again, requires more power, um, requires thicker traces, more board space.
There's a whole bunch of optimization in here. So this chip on life of substrate technology was launched in 2024. It is a, a thing that is, uh, has been delivered particularly for high performance compute.
And we know that although AI vendors don't like to see this, there is a definite line between how high performance compute works and how AI works. They're not the same thing by any means, but a lot of the concepts transfer across, uh, I think this will help TSMC continue to, to compete and, um, to compete with both Intel and to, uh, to a lesser extent Nvidia. And hopefully they're gonna be able to deliver exactly those power savings and those increased performance that they're promising.
With this new a 14 program process, Convault has introduced a new factory settings feature to its clean room recovery service. This feature enables organizations to restore critical systems to a secure, well-known good state after a cyber attack. This capability helps ensure that recovery environments are free from malware or unauthorized changes, uh, supporting faster and safer restoration of operations.
It's interesting that clean room recovery doesn't quite mean the forensic recovery that I would've previously thought. Tom, this seems like it's gonna be very important as we continue to see particularly ransomware, uh, attacks and on Linux systems living off the land kind of behaviors of these ransomware attacks. This is kind of the, this is the last resort button, if you wanna call it that, because like you mentioned, there's, there's different kinds of recoveries, right?
Like sometimes we wanna recover files because we wanna actually see where they were and what they were doing, the forensic kind of analysis. Then there's the, we need to get things back operational to yesterday because we need to be able to get things operational tomorrow. And, and that's a little bit more destructive, if you wanna call it that.
But, uh, then there is the, I guess maybe we should call it the Ellen Ripley option. I say we take off and nuke the entire site from orbit because it's the only way to be sure. And that's kind of what we're talking about here.
And I love the fact that Commvault offers this as an option to say, we are gonna take a clean snapshot of this system, of this site, of whatever it happens to be. And when you hit the big red button, or blue or green or whatever color you wanna make it, it goes back to this like we, and, and I'm sure that part of this is going to be that that's an immutable copy. And, and maybe you can say, well, you know, every six months, every year, whatever, we're gonna upgrade our factory reset to, to X or what have you.
But like I said, this is the absolute vallet. We are not recovering anything back, you know, that has been made since this point. And that sounds harsh.
Like, like I'm sure that, uh, a resident storage expert, Mr. Steven Foskett will be listening to this episode going, oh my God, they're gonna do what? But sometimes that's what it takes.
Like think about when your iPhone is so far gone, or Android, if you're using an Android, if your phone is so far gone that you just, you've gotta wipe it and restart. I mean, I had to do that to my son's iPad a while back. It was working, but like, it kept, uh, got caught in a boot loop because it didn't have enough free storage because somehow in the whole thing it said, oh, well we've, we've consumed 80% of the drive, uh, for system storage.
And the only solution once it was in a boot loop was to restore it. Now, when I restored it, everything came back just fine. 'cause I had an iCloud backup as you should have.
But this is that version of saying we have a good data copy from, I don't know, call it January 3rd, and we know that things were working well then, and we backed up the transaction somewhere else. We're just gonna wipe this thing back to what it looked like on January 3rd and go from there. Um, use with caution though, with all, uh, you know, magic erase buttons.
Uh, sometimes you get unintended side effects, but at at least, you know, you've got another tool in the toolbox because if the, the alternative is to restore from a backup from two weeks ago and then go figure out how they got into your systems. And is this malware persistent and are they able to move laterally? Again, I I, I don't have a good answer for anything other than the Ellen Ripley option.
Here's a fun one. The Cloud Native Computing Foundation is actively working to protect the open source integrity of the Nats project. That's NATS because the company that donated it to the CNCF syn, AIA is attempting to remove the project from the CNCF and relicense it under the business source license because they wanna reclaim control over those assets.
Now, CEDIA originally donated gnats to CNCF back in 2018. They want to back it out because they wanna assert ownership over the Nats trademarks and infrastructure. Now, in a blog post that we're gonna put up in the show notes, CNCF contends that those actions violate community driven governance models and the commitments that were made when the project was donated seven years ago.
The foundation emphasizes that the open source projects that are in the CNCF umbrella should remain community owned and vendor neutral, and is taking steps to ensure that Nats continues to operate under these principles. This isn't the first time that we have seen an open source project create some problems because of the business source license, because this happened to HashiCorp a while back. Uh, al you're a proponent of open source and all kinds of wonderful things.
Should zenadia be able to reclaim that project from CNCF just so they can re-license it? Well, here's the thing. Uh, usually companies take some software that they've built and donate it to CNCF, uh, 'cause it's gonna help their business.
And that they hope that by making it open source, other people will contribute to their project and improve the software and therefore make it easier for them to cont the, the commercial organization that donated the software to continue to trade and make a profit. Where it starts to fall down is where an open source project is only being developed by the original donor, and there are minimal contributions from anybody else for whatever reason. They can be a variety of reasons.
Sometimes it's about how the projects are governed and led and other times it's, the feature set is just not interesting enough to, to see development. In that case, the commercial organization looks at it and says, well, we put all of our intellectual property into the software that we donated and, and we're not getting a return for our donation. Huh?
When I make a donation to a charity I want to support, I expect them to use that donation for their benefit more than for mine. Hmm. Maybe there's some altruism that I have as a, as an individual human that doesn't really apply to a commercial organization.
And, uh, what we're seeing here is, uh, Sania seems to want to bring this thing back because they've given away too much value from the organization. They're not able to add enough additional value to the open source to be able to make their own business viable. At least that's my interpretation of why they're choosing to pull this back.
Uh, the other way that this sometimes plays out, and we saw this, um, with the database that AWS released, uh, document db and it was a, a clone of an open source database or, or it was actually an open source database that they produced a, a service on and, and some challenges around that. Cloud providers taking open source and just releasing a service, leveraging what's been donated by another commercial organization. Uh, we do see changes in licensing around that as well.
Although there's some, some fun stuff in governance here. I think the, the CNCF is doing the right thing by standing up for saying you made a donation, you can't take it back. Um, that's not the way donation works.
And that the important, there is a very important element here of, uh, once things have be become open source, somebody has to stand up for the open source and protect that. Uh, but also the whole idea of open source is communal development. So active projects where improvements are being made, the requirements of customers using the software are being met by these changes.
This is an important part of open source. And if it starts to fall down, if there's no, uh, if, if there's no motivation for developers to improve the open source project, this is where we're gonna start seeing challenges. And maybe we need to see if there is a way for a, a graceful exit.
Uh, one of the most common ways we see this is that the commercial organization will fork the original code and will release a new updated version of code with new proprietary code that is not covered by the existing license. It really does depend what license was applied when the, um, NATS project was open sourced. It's a project that's, that's used and embedded inside people's applications to their message passing between different parts of the application, particularly from on-premises to cloud or across multiple clouds.
Um, yeah, we'll see how this plays out. I don't think it's over battles over trademarks and open source are nothing new. Uh, we reported a while ago on the ongoing WordPress, uh, atomic Matt Mullen work, um, dramas.
There's nothing new. Open tofu also recently, uh, joined the CNCF, which was the, the outcome of that. Uh, earlier Terraform, uh, closed sourcing, more drama to follow.
At RSA 2025 HPE announced updates to make it cybersecurity tools work better across different platforms. This includes improved integration of its networking and security tools, smarter DDoS protection using ai 'cause everything's better with AI and new options to disconnect from the internet during threats. Wow, that would've been really useful about 30 years ago when the first email based threats were coming in.
Uh, HPE also added features to help protect data in the cloud and AI environments aiming, aiming to simplify security and make it more flexible. Uh, Tom security is you tell me what the heck's going on. Um, this all comes down to everybody's favorite Explorer, Dora.
Well, okay, not Dora the Explorer, although if you wanna say backpack, say backpack. Uh, no, this is about the Digital Operations Resilience Act. And if you don't know what that is, that's because you don't live in Europe.
Uh, this is a new regulation. I say new, it's, it's, it's not brand new. Uh, but this Dora is aimed at financial providers in the e eu and it is designed to keep them online when everything goes wrong.
And there's parts of Dora that now need to be implemented, and one of those is a kill switch. We laugh, right? Because the Morris worm took down all of these systems, and man, if we'd just been able to unplug 'em from the internet back in the eighties and nineties, we would've been okay.
But it's actually kind of more common now for large malware deployments to have a command and control server out there somewhere. And we saw this, uh, from, uh, a few years ago when, uh, Marcus Hutchins actually black hole, a massive cyber outbreak because he registered the domain name that one of the malware pieces was looking for as a a C NNC black hole. If that domain name was online, then it was gonna stop propagating.
And just by sheer dumb luck, he found it and, and created that, and then of course created a whole other mess for him himself with the FBI. But I'm not gonna go there right now, but this is, this is becoming a more common thing, right? If the, the attackers are assuming that all of these systems are, uh, terminally online.
So all they have to do is make it so that when the system checks in with CNC server, then uh, it'll keep propagating, it'll keep doing all this crazy stuff, and then it can be used to launch DDoS attacks and stuff like that. And so now what HPE is saying is, okay, we're gonna comply with Dora. We're gonna add these kill switches.
We're gonna add policy, uh, that allows you to, uh, you know, take systems offline until the threat passes until a certain amount of time elapses or we're seeing, uh, no more anomalous traffic coming from these things. It's essentially a way to prevent you from continually reinfecting yourself, but also to shut down the capabilities that these people will have to leverage your networks to do other stuff. Because we've seen that quite a bit in, in the DDoS arena, right?
Like CloudFlare is talking about blocking, uh, DDoS attacks that are dozens, if not hundreds of gigabits in size. And, and that's a lot. But, you know, this is all being integrated into GreenLake.
This is all being integrated with HP Aruba Networking because all of this came out of, uh, some of the work that Phil Mara's team over there has been doing. Uh, you know, it's, it's designed to help people feel better about migrating things into, uh, an, uh, a cloud environment like, uh, HP GreenLake and, and the things that they're doing. But more importantly, uh, for organizations that are subject to dora, which if you do business in the eu, you absolutely are.
Um, you have to make sure that you are following these regulations because if you don't, um, then swiper will definitely swipe some things from you. Let's take a closer look at a story that involves our friends over at Intel, because they're still looking to smooth out their operations under new CEO Lip Bhutan. Last week there was an announcement that Intel was gonna be cutting some more positions, and initial reports said that the rumors were as high as 21,000, which would've been 20% of their workforce.
And then on Friday, CFO, David Zenner said, uh, absolutely not. Uh, instead what he said was, each department will assess the structure that they have, and then they're gonna decide whether or not they're gonna cut positions or offer voluntary buyout packages. However, Zenner, who is the CFO, so he would know, said that maybe not all of those buyout offers are gonna be accepted.
And if you're one of those older people that's been sitting around going, well, I'll just take an early retirement, not so fast my friend, because Intel announced that early retirements are not gonna be considered at this time. The stated reason, of course, is that in the long term, previous early retirement options had led to some long-term problems that they don't wanna repeat again and again. All right, Al, I know that the rundown this year really feels like we have been punching intel to the point where the kid on the Simpson School bus is saying, oh, stop, he is already dead.
But I gotta ask the question, are we at the point where Intel can cut more to get to profitability, or are we gonna have to look at other options? Now? I think the, the headline of more people being laid off after 15,000 laid off, uh, last year with Pat Gelsinger, um, that that headline definitely reflects the fact that there is a large change being made at Intel.
Whether that means that it's a 20,000 existing staff or 21,000, if, if those numbers follow up, um, these massive numbers of people leaving isn't necessarily the whole story. What very commonly happens in tech companies is that the bit of the company that is underperforming, the bit of the company that was awesome five years ago, but is no longer pulling its weight, gets cut off and new, but gets grown, that is going to move forward and improve. So I do think there's a little element where, uh, lit bhutan's plan, he says, uh, I'll make it perfect when he speaks of Intel.
Uh, so he may be following that idea that perfection is achieved, not when there's nothing left to add, but when there's nothing left to remove. Um, not sure that that gets us to the, the forward space. Hopefully alongside these eliminations of, um, parts of the business that have been underperforming and that are yesterday's intel, hopefully there's a growth in tomorrow's intel because, uh, lip bhutan's there to make a recovery, to make a turnaround, to make Dell, uh, perfect.
And you can't do that by continually cutting away. You'll certainly reduce your burn rate on money, but then doesn't increase your income. You've gotta increase your top line.
You've gotta produce new products that are competitive in the market, that are demanded in the market, and that are taking on the people who have been eating your lunch recently, specifically Nvidia and increasingly amd you've gotta get ahead of these people and build new products. Tom, do you see Intel building new products, adding more replacement people for some of these? I, I don't right now, and that's part of the problem.
Uh, you, you mentioned, you know, lit Butan says, I'm gonna make it perfect, and yeah, when there's nothing left to remove it, it, it could be perfect. I mean, I think of the old story of the Zenith. Uh, CEO used to walk down the assembly line and he'd yank a piece off, and then when it didn't break the tv, he'd say, well, you didn't need that piece.
And when you yank off enough pieces that finally you break something, oh, look, we, we found a part we needed. But that's not a strategy for, I don't know, um, survival. Like, here's the thing.
Intel is finding itself in a very hard spot because their plans to become more profitable, or at least stop the slide, require people to do things like you said, but you don't know who that's going to be. And that's the weird thing about this. They've already said that they're gonna have every organization go through and figure out who needs to go and who needs to stay.
That sounds to me like it's gonna be asymmetric. You're not just gonna go in and they're gonna go like you and you and, and 20 people over here, and I guess 20 more people over here. Some of these organizations are going to get hit hard and they're going to make sure that the people who are left behind in the areas that they think are going to be their growth areas are not gonna be allowed to take an early buyout and they're not gonna be able to take an early retirement.
So basically, you guys are gonna be here because we need you. And I wish they would do a much better job of communicating that upfront, because that to me is where Lit Bhutan's leadership really is needed right now. Here are the things we are going to do well, and whatever they are, you're gonna have to double down on those, right?
Because I, I remember recording rundown episodes late last year saying, you know, Intel gouty can't miss, like, like if they wanna get on the AI bandwagon, their GPUs can't miss and they gotta do this and they gotta do that. And here we are, less than a year later going new CEO cutting people left and right, they need to succeed at what, that's the question that I think that Intel has to answer right now. What are you gonna be a fab facility?
Are you gonna build out that Ohio fab and these Arizona fabs, like in the story we talked about, we're gonna be, uh, coming into competition with TSMC. Are you gonna try to become the homegrown tariff proof company, then say it? Because that's gonna take time for you to get those things adopted.
But if I don't know what you're building other than making more CPUs, that doesn't give me any, any hope for the future. Because what if you're cutting jobs from the CPU manufacturing and the packaging people and all that other stuff, if you're cutting those from areas that I know you're good at, that's a signal to the rest of the market that you are trying to either survive or that you don't wanna be good in those things anymore. We have to see what's going on because then what happens then the rumors come out that you're cutting 20% and everybody flips out because oh my God, how can you cut 20% of your workforce and continue to be a market leader leader?
You've got to provide guidance. And that, that's table stakes right now, as as, as I see it. Alright, with that being said, luckily there are some things that are coming up on the horizon of the future, at least from the tech Field Day side that you can absolutely hang your hat on.
And the first of those will be next week because I am gonna be in Silicon Valley talking about all things related to mobility. We are gonna be having mobility Field Day, uh, 13. We're gonna have presentations from great companies like, uh, Juniper, Cisco, Ubiquiti, Fortinet, Nile, cel, um, Arista and more.
com and check out what's going on there. And then coming up after that, the next week, uh, Steven is gonna be it, uh, tech Field Day experience at Click Connect 2025. Uh, it was a great opportunity for you to learn more about what Click has been working on since we had our, uh, click Connect experience last year, and I know he's gonna have a wonderful lineup of delegates around the table, uh, enjoying, uh, all the great things that there are to offer at events like this.
And then at the end of May, you're gonna be hearing from me once again at Security Field Day. We have a wonderful lineup of companies, uh, Microsoft, Dell, Veeam, and more. com.
Uh, you can also check out the delegates that are gonna be there. Uh, it's, it's gonna be a lively bunch. Uh, luckily nobody's gonna be guessing anybody, pa anybody's passwords 'cause we're all two factor enabled.
And you should be too. You should use all of the factors of the tech field a rundown, whether you are checking out the video on the tech field, a plus YouTube channel, whether you're listening to the audio format of this in your favorite podcast application, or go over to the website and check on the show notes because we link to all the articles that we use for research. Uh, and sometimes we link to some other fun stuff too.
But we will be, uh, producing this episode every Wednesday in the afternoon. You know, once you get a little bit of caffeine and some lunch down, you then it's time to listen to the news and hear what Al and I have to say about it. Because Lord knows we, we have as much fun as we can with some of this stuff.
Uh, but, you know, we'll be back next week with some more exciting, fun news. There'll probably be some stuff out of RSA and a few other things. But until then, make sure that you're subscribed to Tech Field Day Field across the board, uh, website, uh, for upcoming events, our newsletters for all the stuff that you need to know.
And if you have any news stories that you wanna send our way, you know, make sure you check out all of our social media channels. Those are listed on the website as well. Uh, we'll be back next week with more great news.
And until then, uh, make sure you stay dry, uh, and enjoy an oatmeal raisin cookie for me. Will you.