Techstrong TV October 23, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
He slicked back my hair. Greed is good. Greed is what made America great.
Gordon Gecko coming at you on Textron Gang. Hey everyone. Happy Thursday.
Wow. Thursday, man. This week's flying by.
I'm Alan Shimmel. Welcome to the Textron Gang. We've got another, uh, Rockham soum lineup of, of topics to cover today on the Gang, and we've got our favorite Rockham Soum gang members to, to talk about it with.
Uh, let me introduce you to Terry Robinson, Garima Boal, John Swartz, and of course, Mike Ard. Ladies and gentlemen, welcome. Thank you for, for coming on.
It's good to see you all. Uh, Mike, you know, the pigs at the trial, as some might say, So, so let me set this a little bit for you. So John has an article up on Textron one AI that you should all check out, but it's really talking about from his perch in Silicon Valley about how the whole ethos of the Valley has fundamentally changed.
And it seems it's taken a while. I mean, I think I've observed this trend happening maybe in the last decade, but it's now just full throttle. And it seems like, John, that all these companies that care out there is, um, you know, how much money they can make, and it's all about the almighty dollar.
And I think the customer's getting lost in this conversation. But walk us through what you're seeing. Yeah, you know, it, so it all hit home for me last week at Dreamforce when Mark Benioff stuck his foot in it.
Um, he got caught by the New York Times. Uh, he basically was advocating for the National Guard to come in and clean up San Francisco, which is the site of Dreamforce. And you know, coincidentally, he's done this the last three years and he uses it.
He uses the show as kind of a perch to get what he wants. And New York Times also did a report that the reason why he was so pro National Guard is that Salesforce had put a bid into the, to es to, uh, use Asian force. So it was motivated as much by money as it was by politics.
In a sense. Politics is almost secondary to this, the pure greed that's going on. And I, and I remember yesterday, uh, Mike and I were just talking about this a little bit, and, uh, with apologies to Paul Simon and Joe DiMaggio, where have you gone, bill, if you will?
What happened to this kind of ideal of the garage, you know, startup, um, discovery, uh, you know, you make products to make money. I'm not gonna, I'm not gonna fight or push back on that. I, I totally understand that, but I think we've actually reached a point now where it almost, we were in an era where the apps were almost incremental to the point where they were silly, but they were about convenience, about making money and about getting more data from the customer, which became part of the product.
And I think we, as Mike has said, we've come full throttle, full circle. This has been moving this in this direction for quite a long time. I think it was underscored by Benioff who subsequently apologized.
But I, I, I consider that a hollow apology, honestly. And I, I just think of this, this valley and the fact that they are so ingrained with the government, it's all a money grab. AI is huge.
I understand that, but everything's gone by the wayside in terms of ethics and integrity, the customer. Um, maybe I, I might throw it back to Mike about what he mentioned about the product and how things have changed from kind of some of the foundational companies that were here and how they address the customer base to where we are today. Yeah, I mean, capitalism is a good thing and always has been.
So I don't think anybody's arguing against that in particular, but it does feel like in their PROEs of competition with each other and what they perceive to be threats, they've kinda like turned inward to the point where, um, you know, it's all about how much data we can pull and maybe we're gonna own the future of AI and all these other things. And that's an interesting theory. But I also think that they're gonna misread the politics of the situation as well.
I mean, the short term, you know, greed is good, I guess, but longer term, if it's perceived that AI is costing people jobs, and Amazon was talking about laying off like 600,000 people over the next few years, you know, people are gonna start looking for folks to blame. They're gonna find those guys in a, in the AI world and start pointing their finger at them. And more of them are gonna vote for folks like the guy who's running for mayor in New York City.
So that's, I mean, oh, let, Alan, lemme just point at one thing. I'm sorry, Alan, I'll get outta the way. But there's this, this common refrain actually, it's growing, it's growing into a chorus out here, and people are noticing this.
And they've been talking about, there've been other folks who have written about this. I, I, I've heard secondhand. Um, and I did go to lunch with a guy who was in the semiconductor industry who's been around forever.
He worked at Fairchild, he worked at a MD, worked at Actel. And he said, look, I mean, this is nothing new here, but I think what happens, what has changed is there's more money and there's more power at stake, and it absolutely has corrupted people. Sorry, Alan, Chuck.
No, don't be sorry. I'm say your peace, John. I need a little time to step up onto my soapbox.
Anyway. So let me, let me address a couple of things here. First of all, my friends, welcome to the Oligarchy 'cause make no mistake, what we're living in is a tech bro, oligarchy.
A vital piece of the Trump Coalition is the Peter, the LED brotherhood that went down in Silicon Valley that corrupted what was one of the greatest innovation engines in the history of mankind. Okay? That's what went down here.
Lemme tell you something, I've been in tech for 35 plus years, Mike, John, you have two. Terry Greener, you're younger, but you've been around, right? What attracted us to Silicon Valley, what attracted us to tech was the meritocracy of it.
Whether you are white, black, male, female, non-binary, or whatever you want. Whe whether you come from India and Bangladesh or, or, or Idaho, if you had a good idea and you were talented, you could go into that garage like Woz and Steve Jobs or Bill Gates and, and, and Paul Allen or, or he, Hewlett and Packard for that manner, or countless others like Larry Ellison and all these other, you know, people who are now in the tech, bro oligarchy. And, and if you have a good product at the right time, and you got good marketing, you could live the American dream, right?
Why did, when I was coming outta school, you had a choice. You go work on Wall Street and you get like a $800,000 Christmas bonus and go buy yourself a red Ferrari. Or you go work for a startup and you get some options.
And look, nine outta 10 startups didn't have such great exits. But if you got your golden ticketing, you were on that 10th startup. Man, those options made you a tech millionaire.
I've, I lived that dream for 25, 30 years, did the IPO thing, did all that stuff. And the beauty of it, it wasn't just Silicon Valley, it started spreading to places like Austin, Texas and Boulder, Colorado, Boston was always a big tech haven. New York, everybody down here in Miami, they keep, or in South Florida, they keep dream dreaming of Silicon Beach and Silicon Island and silicon this, and, but no one ever recreated Silicon Valley.
It was the envy of the world. And the politics of Silicon Valley were for every man. Mark Benioff apologized because one of his main board members who's kind of the dean of Silicon Valley, chastised them in, in public and said, what happened to you?
You piece of garbage, right? And then all of a sudden he made that half-hearted kind of, uh, apology. But the, the real Silicon Valley would, this is, this is disgusting to them.
This is not what's, this is tech, bro, oligarchy, plain and simple. I always have a feeling with these guys, and this is not to undermine what goes on out there and all the brilliant ideas and all the hard work, but you talked about meritocracy too. There's this sense, at least to me, that they haven't earned their riches like this, this is not earned, you know, stuff.
This is convenience, this is influence. This is, you know, who you know, and, uh, being, yeah, It's an oligarchy. That's how an oligarchy functions.
It's, it's all, you know, and it is a brotherhood. Make no mistake about it. It's tech bros.
The greed is the point. I mean, too, it's like, you know, it's the greed stupid right? To borrow from the Clinton campaign.
But, uh, yeah, it's just, I've been around as long as you have, uh, Alan and, and I, I remember a lot of those people fondly in silicon, uh, valley and a lot of the personalities and, you know, they'd be abrupt and crusty and, you know, and everything else. But there was a lot of respect for them and what they were doing. And I, it's hard to find that right now.
No, you know, you're in San Francisco, and I would just love to get your opinion on this. 'cause you know, I lived out there for a decade, and I feel like everybody beats up on the town because of the Tenderloin district that sits around the convention center. And, you know, the Tenderloin district has always been, you know, I see ever since, you know, the gold rush and maybe the days of Jack London.
But if I go around the rest of San Francisco and I'm up in Pacific Heights and I'm in the Outer Richmond and the sunset, it's still a nice town. And so it's not like, you know, we have this kind of emergency crisis that people keep painting about that particular city, or am I wrong, Right? Yeah, you're totally right.
You're totally right. This is, I mean, the fact that Mark Boff Benioff, who's a fourth generation San Franciscan, by the way, and he talks about this quite a bit, the fact that he plays into that narrative, which is off. And by the way, go to any major city in the United States, and you're gonna find home.
Absolutely. I'm sorry, I'm sorry. I go to see my son in San Diego.
The problem there is as bad as it is anywhere. And, and I love San Diego, but here's the point, though, in San Francisco, he plays into this caricature, this, this stereotype, which is totally inaccurate. And he does this as, as kind of a, a way to hold the city hostage.
And I think there was a, there's a fair amount of pushback this time around. And he, he cut, he stuck his foot in, as I said earlier, and that led to Ron Conway, who does have a conscience. He's the angel investor who was on the board.
He's just like, what's the matter with you? And he walked away, and I think Benioff maybe be as he accumulated billions and billions, and he became more like his mentor Larry Ellison, who has always been this way. By the way, Larry Ellison was the epitome.
He was the Gordon Gecko of Silicon Valley before there was a Gordon Gecko. And, and I think that whole persona has permeated. I think it also is being pushed by people like Mark Andreessen.
Yes. Who, who is among the worst offenders on so many levels, not just, I mean, in terms of, uh, I won't go into it because I don't want to get us in trouble, but he has said some really horrible things and, and he truly believes in them. Um, you know, these, these guys were all the, sorry, You know how bad this has gotten all these guys, they're making Microsoft look good.
Yeah, exactly. That's what I was gonna say too. So, so the mediocrity of Microsoft now is, now, now they're the leaders in ai.
And that says so much to me about the state of things. But again, it's, with them, it's, it's been an Investment. But here's the deal, John, the leaders in AI today are not the leaders.
'cause they're out innovating. They're the leaders because they're out tech broing, And they're also investing, uh, Well, the circular jerk, right? The circle jerk of investment that we see going on between these five or six different companies.
Right? I never Thought I'd ever hear that. The blessings, the blessings of, of the contractor in the White House building, building his grand bull.
That's The other point I was gonna get to these guys are hand in hand with, with Trump. But just to, to point out the hypocrisy of these guys, these guys are like, uh, uh, Zeig, right? They just adapt to whoever's in office.
Remember that famous photo of, of Obama flanked by jobs and Zuckerberg? Now you can, you can just insert Trump and you would have Tim Cook on one side and Zuckerberg on the other, and Sam Altman and Ellison and all the rest of this crew. All of 'em.
So I, I gotta tell you the truth I expected of Larry Ellison and Benioff is his evil disciple like Lucifer. And, uh, you know, uh, I, Tim Cook hurt me, uh, that, because I thought Tim Cook had, that's like A dagger. Yeah.
Yeah. I think, You know what, I, I thought Tim was better than that. I Think there's, I think he, I think, uh, he's near the end and I think he's gonna be retiring fairly soon.
He's gonna turn 65 in a few days. And I think he's probably tired of it, but yeah, you're right. It pained me to see him sell outs, Bend the knee like That.
I, I thought he would hold outs, You know, so, so, So there is, there is a conversation happening around dining room tables today, and it goes something like this, little Johnny or Little Jane just got back from college and can't find a job, especially in computer science or any of these other places. And they're starting to ask questions about, well, what are these tech bros up to here? Because it doesn't look good for, you know, their aspirations for that American dream that Alan was talking about.
And, you know, their mindsets are starting to change, and you're gonna see some interesting things in the next couple of years. I hope so. I think so.
I, I really, really hope so. I, I, I, you know, it is, uh, it, it it's just, It's, you know, you know, if there is a, if there is a change, and I'm saying this in terms of the government, watch these guys pivot as hard as possible and pretend like this never happens. Yeah.
But the, they, they will try, they will try to reinvent themselves like they always do. But you know what? The public's not as stupid as they think we are.
Well, not all of the public, not the public, and, you know, not all of it. Yeah, some are, but it's just the damage is done too. So how do you get off the track?
You know, even with regime change. And, and also don't underestimate that large swaths of this world who were not in the tech world already resented the way the tech world operates, right? It was taking good jobs.
It was, you know, replacing taking away jobs. And, you know, a lot of them would say they had it coming, they have it coming, right? Because, you know, there's, there's so much, you know, you, you talk, so I live here in south Florida.
It's not a poor area where I live, but you know, it, it's, it's very common to say, oh, where, how'd that guy buy that house? Oh, he's a tech millionaire. He's one of those tech billionaires, right?
And it's one of four houses he owns. And, you know, and they say it not with admiration, but with resentment. And, and there will, and you know what, Mike, you brought up the mayoral race in New York.
I think that's a perfect example of it. People are saying, enough, we, what, what about us? What about us?
Right? We're not a tech bro. You know, what's interesting about that though too, is that was a sentiment, I think, among Maga until the tech bros started going Trump's way.
Yeah. I think they really felt that way. And, you know, now they're all in with the tech rose.
But I wouldn't make that assumption. I think that there's a significant portion of the right that also is asking these questions. Oh, no.
Yeah. I think that, Yeah, there's a, there's a certain bi there's a, a bipartisan, um, agreement in, in Congress, especially about the power of, of big tech and about its morals and about its technology. I mean, they're, they're from the extreme right to the extreme left.
There seems to be a general distrust. And that's a one of the few common grounds they share is, is the fact that Bing tech is just, can't be trusted, Can't live with them, can't live without them. Hey, let's take a break here.
We're gonna come back and, and talk about a another war. This one about browsers. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. All right, folks, we're back and we've talked about this forthcoming browser war, and now it's actually here, at least in my opinion, we see open AI is now pulled out their browser, and they're going after Google. And of course, there's been other choices out there, but at least in, in my opinion, OpenAI is the most credible player in this space.
And we'll see how this plays out. But Karima, you've been following this. What's your take?
I'm more conscious than thrilled, and I'll tell you why. com as well, uh, regarding this topic, AI browser race when Comet was about to launch, right? And there was a lot of buzz around, you know, uh, how the, uh, the come browser would, uh, integrate AI and AI agents.
Now we see the similar challenge, uh, coming up from OpenAI. 5 billion users of Google through their, uh, browser, which they, they call Atlas. And they are trying to leverage, uh, 800 million users, which they have on charge GPT, right?
But you know, the caution or the concern I have, I will point out a few features from the Atlas browser, and then probably we can discuss how do you feel about this whole challenge? So the first feature I was, uh, uh, investigating this, that they are putting browser memories and data retention, which means that, uh, browser memory would be storing context for personalized in interactions, and of, of course, they will have controls for Optin optout and all that, right? Another aspect is AI training of browser data.
Now, how this training would happen, of course, uh, you need user behavior data, you need, uh, data for interactions and how this is playing around. And of course, the controls will be there, but think about this. The user con consent and control has complexity to it, right?
So what features you will be opting out, which features you want to log out, uh, and you what kind of mode you have. And I think there is another sensitivity to this that, uh, these whole whole, uh, you know, emerging tech integration into browsers is susceptible to, uh, security risks, right? So this will be a lot of vulnerabilities introduced through prompt injections.
Another area which I wanted to also highlight was, um, AI literacy and comfort gap. And this is again, uh, what we have discussed in the first, uh, part that, you know, this technology is, is hitting a larger masses, a user base, which is probably not that tech savvy, right? So we'll have to ensure that people understand the implications of opting and opting out, right?
How, uh, AI centric design of Atlas would work. And think about these things like if there is a reduced traffic on authentic, uh, websites, for example, because there is algorithmic intervention of agents, uh, putting you to different kind of websites and maybe chosen websites or personalized content or context, right? How the biases would be built.
And, you know, not everybody would be represented in that bias, right? So things like that is a lot of, uh, concerns I have on the table. And of course, now, Mike, you would ask me that, you know, where these discussions are taking place, how can I be part of this discussion and how I can build a governance around it?
But I, I have to say this as a technologist, that, uh, we need to lead this, right? We need to lead this independent oversight. And, um, like media houses, like yours, uh, tech strong TV plays an important vital role in this oversight.
Because if we do not bring regular external point of view or multi-stakeholder evaluation or systematic oversight of these AI applications, I think we will remain blindfolded. And that is what would be needed. And of course, I don't have a straightforward answer.
Maybe, you know, you guys have more insights into how the Silicon Valley is thinking about it or how, you know, the more developed countries would take, uh, the space and say, okay, we, uh, own the space and we build an audit mechanism. We o uh, build an, um, uh, accountability mechanism into all this. So it is also subject to kind of seeing how all this plays around.
I am quite skeptical about this whole thing be just because of the fact that it is hitting the masses. You know, we have seen this whole technology revolution, uh, in let's say critical infrastructure area or defense area, or mining area, which we probably are not concerned that much about, right? Because it doesn't hit like 8 billion people, but browsers, everybody's using it.
And one more thing I want to kind of highlight, that if you work for the government and you start using these browsers, how your identity will be mapped and what kind of data is, is being pulled out of your, uh, browsers is also, uh, subject to kind of, you know, consideration. So let me just summarize that big tech is experimenting on millions of people without any regard to the implications thereof, Alan. Well, but, but you know what?
This, we've seen browser wars before, right? Internet Explorer, Netscape, Mozilla, uh, Google, uh, Chrome, chromium based, you know, seems to have one of the day. This one's a little different though, right?
I, and, and I'm gonna bring you back to when Google, uh, launched the Chromebooks, right? The promise of Chromebooks is you could go buy a device for $300, $250, and instead of running Mac Os or Windows, you really didn't care what os you ran, it ran, it all ran through the browser. The browser was the interface, the browser was the ux.
This is that battle on a whole new level. 'cause what we're talking about is not just the browser, we're talking about the new ux. How are you going to interact with your world, right?
The idea of running apps outside the browser on your device probably gonna go away. You could run the apps right on the browser and the way you, it, it may not be typing. You may talk to it, you may, you know, the whole in human computer interaction here is changing.
And it may not be a browser window in terms of what we normally think of as a browser window. It may just be a talking head that I talk to and it pops stuff on the screen for me or whatever, right? This is, I mean, is it a little, am I being a little farfetched?
Maybe, but not that far. Not that far. And so, you know, the, so the, the, the, the spoils of this war are huge, right?
To the winner goes the spoils. I think you're gonna see, now Google has the incumbents chair, but it's the old way. So they're gonna want to do incremental, start building AI into my search results and, and this kind of thing.
I think open AI, perplexity, they're all gonna try something. But I think there's a tremendous opportunity here for something just totally revolutionary new that does away with the hu the the traditional human computer conduit of interaction and using AI more like spot check One difference, which, uh, you'll feel yourself, right? I mean, comet was launched a few days back, right?
So I was also curious and inquisitive to try it out. I went into their like, uh, website multiple times, but I didn't download it. Why was that?
Because I didn't have the trust, Right? I could do this with Google. I do this with Chrome because they have built that trust.
And until, and unless I see registries of AI model, which they, they're using Explan, uh, explanation of, uh, you know, how these agents work, uh, some kind of explanatory reports, which are out there, I wouldn't, because, you know, ignorance is bliss. I always say that, you know, people who don't know would try and use it, but people who actually understand that how the data, user interaction, user behavior is kind of recorded and used on in the leverage of these big tech companies, I think we'll be very, very conscious about it. So let me throw some metrics.
I think, well, there's two things. First of all, I'm gonna let Alan go first and see how it goes. Well, Let me go ahead.
90% of developers use ai, 40% don't trust it, but 90% still use it. But go ahead, Mike, That's for hobby court, not for production. And the second thing about this is, you know, I'm open to using a different browser, and I've been using Google Chrome forever, but the current Google Chrome experience is crap.
And so it, it's, I'm like, willing to think about something else here. You know, what was that? Like, somebody has an article or a book out talking about how, you know, the big tech is running down the, I believe the technical term that uses and ification of the web, and, and that's what we're getting these days.
So if the browser kind of gives me a better experience, you know, I'm hoping it does. I, but I agree with Garima. I, I know for certain they did not think through the security issues.
So I'll just wait to see what Alan experiences and, you know, in six months I'll come back. I can't wait to use it and I'll let you know, right? But that's really, It's be interesting to see.
They, they, they will We'll be booking our airline tickets as Ellen is booking from, uh, this website, which she's using for years, right? So we'll know about it. It's, this is how you know your daytime.
It's gonna be interesting where they around. Go ahead, John. It's Gonna be interesting.
What? Oh, yeah, sorry. There's gonna be interesting what they do with, with Atlas.
I mean, they refer to it as an AI browser agent. And I, I wonder how Johnny Ive, and that whole IO acquisition plays into this. Like maybe that's a mechanism or delivery of some sort.
But I also think that open ai, it's an uphill battle. I mean, as, as bad as, or as mediocre as the Google experiences, they've embedded the AI agents across Gmail, docs search Chrome, Android. So it's quite a, it's quite a task, but you're, it's, it's gonna be interesting.
I also think, I wonder if Perplexity ends up becoming part of another company like Apple, for instance, and that shakes things up. But I'm, I mean, I'm all for some al alternatives to Chrome. I also will point out one more alternative, which is in the making is confidential ai.
Because some of us who are more aware of the technology revolution, I think we will pivot into some kind of a confidential models for, uh, using these kind of industrialized applications and for the larger masses who don't care how this user interaction and how the data is being captured. Maybe the, this is the answer to that, that question, but for me, I think I'm leading towards some kind of a movement for confidential ai. Kareem is reading my mind.
'cause that will be a topic next week. So we'll come back to that. All right, on that note then, let's take a break here and come over.
Come back to our C block today, which is, uh, regarding face facial recognition. That's been a controversial one. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation.
We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group.
Hey, folks, we're back. And as Alan alluded to, facial recognition technology is going to court. There's a lawsuit that's aimed at the Dolans who own, um, Madison Square Garden and the New York Knicks and The New York Rangers, And I think they have a piece of the liberty.
And, um, the at issue here is apparently, at least according to the suit, um, the Dolans have what amounts to in enemies list that they don't wanna have in the garden. And they are using facial recognition to enforce that. And the suit says that's part of a larger cultural issue that is at the heart of that particular lawsuit.
But Terry, you wrote this story up on Security Boulevard. Is this gonna become the test case for facial recognition and how we use it and don't use it? It maybe, I mean, New York lawmakers had sort of raised the alarm last year about this.
They had heard tell that the facial recognition, uh, technology wasn't being used as advertised by Madison Square Garden, which, you know, ostensibly was to protect the garden. And all the fans who come in from some sort of attack, you know, the terrorist attack or some untoward activity, um, I don't think much happened between the time that the lawmakers sent their letter out last year and the time that this suit really started gaining some, some traction. But, but maybe it should be the test case for, um, how it's used.
Uh, of course, it's just also something is really rotten at Madison Square Garden in their security, you know, department overall. And, and maybe just in the, the business of the garden, because the guy that brought this suit really was bringing a suit, uh, you know, first and foremost about disability discrimination because, um, basically the head of security there and, and, and other people were using private information about his health condition, he's diabetic, um, you know, to bully him and, uh, and, and sort of publicize it in the workplace. And, you know, I, they called him old and weak.
He's 49, by the way, um, and, and diabetic. So I mean, 40 nine's hardly old, um, these days. But, um, in filing that suit, all of this other stuff came out about their security practices and, uh, the mishandling of, of, uh, data.
So yes, you're right. Madison Square Garden has an enemies list. Um, it's pretty interesting because that could include, you know, guests, lawyers, customers, sports fans who might have former players, former players, Charles Oakley, former player, Charles Oakley.
Yeah. And, And soon to be Terry Robinson. So there You go.
And soon to be Terry Robinson who might have expressed frustration about the Knicks losses come on. Now, you know, who doesn't follow the Knicks and expressed some, you know, frustration on that part. I mean, they've done pretty good the last couple of seasons, but it's, it, it, you know, the list was fairly broad of what they looked at.
So you wear a t-shirt, you know, you, they recognize your face. Um, there was one woman who was targeted who is transgender, and she was, you know, targeted for no other reason than her gender identification. It wasn't as if she had done something.
James Dolan was being accused of sexual harassment by, you know, another woman. And this guy that filed the suit had been asked, uh, by the head of security to record, you know, phone conversations that could be used to, uh, dissuade and intimidate her going forward. And that's where he drew the line.
He said, Nope, not going to, you know, not gonna do it. Um, the guy who filed the suit, by the way, um, you know, was the, he's not like some low level employee. He was the VP of shared security services.
So he was up the food chain. Well, let, let me say this. First of all, if the Dolans would put as much energy in the building winning franchises as they do into this crap, maybe we wouldn't be sitting here that the last time the Knicks won a championship was my Bar Mitzvah in 1973.
Okay? And the Rangers when, you know, mark messier before he went out the door. But that being said, are the Dolans any different than the president telling the Department of Justice Go indict this one, he's an on my enemies list.
We live in a country where having an enemy's list is, is okay. It's okay. Yeah.
It's a okay. Yeah, right. When Nixon did it, they wanted, they ran him outta town.
No, today it's, it's, We had morals, then we had principles. Now it's okay, but they're my enemies and I'm, and this is my toy, and I'm going to use my toy the way I want. Whether it's the Department of Justice or Madison Square Garden Security Team, right?
Well, so it's no longer that, that kind of thing. An n a's list is no longer a deal breaker for politicians, for, you know, business people at the top of the heap. It's, you know, used to be it Would be, I again, welcome to the oligarchy.
Exactly. We Sure there are other owners, other owners who are watching and wondering, maybe we should do the same thing. I, I wouldn't discount, I wouldn't discount Joe Laker from doing it for the Warriors.
I, I, you know, it's, I I think the Warriors put a good, a good product on board. Well, they do. I know I do, but I just think They go to a w's An enemy or perceived, you know, the enemy's list thing has become so prevalent and so pervasive that I could see it used in limited cases.
Not, not to the extent, maybe to the Knicks, but to a shorter, shorter extent. Well, I, and, and then it's not just public sports. It's, it's everywhere.
It's, it's everywhere. It's A whole bit, it's the workplace, you know? Well, which is also part of this, but yeah.
Um, yeah, It's, it's shame That that's who we'd become or that's the direction we're heading in. We're, and we're comfortable with it. Not us, we're not comfortable with it, but I'd still like to see the next win.
I, I, I confess I do have a list. It's called the Text Strong Gang Friends List. And it's very nice and it's opening, welcoming, and everybody should come.
Yeah, We like that kind of list. That's a good list to have. Alright, Murray, It was, it was like a badge of honor to be on Nixon's enemy list, wasn't it?
Back in the day. Yeah, It was then, right? Somebody considered a badge of honor to be be on other enemies list.
Yeah. Charles Oakley's not losing, no sleep over it. Awoke.
All right, I think we're gonna call a ARAF on this version of Text on Gag. It was, it was a little controversial and heated today, folks. Um, as usual, we've got Text Drunk TV coming up.
Watch that. If you're not watching this on the live stream, I hope you enjoyed it on YouTube or the OTT channel or however you got it. We do this every day from nine 30 till about 10 15, so Eastern Time that is in the us so check us out there, gang members.
Thank you. We'll be back tomorrow with our Friday text on Gang. But for now, enjoy Text Drunk tv.
Hey everyone, welcome back here to Tech Shark tv. You know, I, when I first saw the time we were recording this interview, I felt bad for my, my, uh, guest here today. He's a friend of mine.
He is been on Textron TV over the years, a couple of, more than a couple of times, but he's based kind of on the other side of the world a bit. And it's usually, you know, to have him on in the middle of the day means it's the middle of the night, but he's in California today, so it all works out. Let me introduce you to Peter Dou.
Uh, Peter, of course is the CEO chairman and co-founder for Secure Code Warrior. Peter, welcome back to Techstrong tv. It's great to have you.
Hello. Thanks so much for having me. I'm very grateful to be here in, uh, nice sunny California.
Uh, a good 40 hour flight from Australia, but I'm happy to be here. It it, did you say 40 hours? 14, sorry?
14. Oh, 14, yeah, that's about right because we're about five hours from five to six hours from California here, and it's about 19, 20 hours though. You know, there aren't that many nonstops nonstop.
You gotta go up to like New York, and there is a Qantas, I think that goes in the Sydney nonstop, and that's about a 20, 21 hour flight or something like that. Uh, I've taken it, it's a long flight. That's a long flight, but it is nonstop.
Anyway, Peter, I'm glad that we don't have you up in the middle of the night. I, I appreciate you coming on. For people who maybe this is their first time seeing you and maybe even hearing about Secure, secure Code Warrior, let's start about kinda your journey.
What led you, what path did you take to co-found and, you know, lead Secure Code Warrior? Yeah, so long story, like I started in cybersecurity in the early two thousands. Like I was mostly on the offensive side of cybersecurity.
I co-founded the Hacker Conference of Bru Con, uh, over in Europe. Um, and I think after and teach it for the Sand Institute. And my goal was always to kind of teach people on how to break into systems.
Now, having done that for about 15 years, in 2015, I realized that I need to help the people that are actually building the software, because very often it allowed me to, it allowed me or my team to break in to steal data out to do what all these malicious backers are doing. And we were always being able to kind of draw it back down to a problem in the software. Like somebody or something kind of wrote a piece of software and they were using the wrong libraries, they were losing load function calls, and as a result, somebody was able to exploit this weakness and gain access and all prior access to a system.
And that's why I said, okay, I need to stop teaching people how to hack and I need to start helping people how to build software in, uh, in a secure way. And, and that's how Secure Code Warrior was founded in 2015. And our whole mission, uh, is and still is today, is to help software developers to build code in the most secure way as possible.
Excellent. You know, in many ways I kind of mimics my own journey a little bit, right? I, uh, got into security in the late nine, late 1990s, late nineties.
I remember Sand's Institute, my good friend Steven Northcutt, I don't know if you were there when Steven was there. I'm still friends with Steven on Facebook that's communicate with him all the time. And those were the heydays.
I mean, SANS was where you went to learn security. We didn't have cybersecurity majors coming outta college and stuff like that. You went to Sans and it wasn't cheap, but it was great courses and they had great conferences around the courses.
I had co-founded still Secure back then. And, you know, we were a big, big supporter. We used to buy those big blow up like yoga balls and put 'em in all the Sands classrooms instead of chairs for people to, to sit.
We used to tell people we were the company with the big balls. Um, and it worked. We, we had a good time there.
Then, you know, the reason I really got into DevOps was the same reason you shifted left, which is you realize if we could get the security problems in the code when they're coding it before it's deployed, it's a hell of a lot easier and cheaper to fix there then, you know, trying to kind of stick your finger in the d**e of, of, you know, uh, well once it's already out there. So I, I appreciate the, the, the journey. You talked a little bit about kind of the mission of Secure Code Warrior and, and how it came about, but of course that was like 2015, it's grown since then, right?
The world has changed a little since then. We're gonna talk about AI because how could you not talk about ai? Of course everyone has an AI strategy, but talk a little bit, Peter, how the, how the market has changed and how the mission of Secure Code Warrior may be has expanded since 2015, right?
What's going on? Yeah, so there's probably like two big things that I've seen happening over the world with my customers is that is first of all that everybody is writing code these days. Like software development is not anymore, like the gigs that our, some are sitting in certain departments, but everybody, everybody has the ability to build an application.
And I think with ai, that's even go to accelerate even faster. So the definition of who is a software developer is kind of a changing from people that are full-time writing code. But nowadays it's also, uh, people that are, uh, analysts, financial analysts in companies, they can write code data analysts who can write codes like anyone has the ability to start using Python and JavaScript to kind of build, build applications.
I think what is going to happen is with AI and the, the ability of AI to generate applications, think about the vibe coding, like even more people are going to be able to build and deploy applications in seconds. Like, I'm not sure if you saw the announcement of Open AI yesterday. Um, they released something, uh, the, uh, uh, agent, SAK, where I think in minutes you can deploy an application into production.
And so my opinion will have more people building applications than ever before. I thought you were gonna say the, the announcement of them maybe taking up to a 10% stake in a MD with warrants and, and buying all these chips and the week before, the a hundred billion dollar deal with, with Nvidia and stuff like that. Open AI is certainly, you know, in, in the news all over, but you bring up something that's very important.
At the end of the day, we talk about hardware, and hardware is cool and sexy. Again, it wasn't sexy for a long time, but the real test for success will be are people using the software, right? NVIDIA's secret sauce is Cuda and all that whole software ecosystem they've built around using GPUs.
Open AI is on a similar quest of getting the developers, the AI developers, the AI engineers to use their software. But of course, Peter, as we've seen, security isn't always top of mind with these things, right? A lot of times it's it's the end of the train rather than the front.
Yeah, and I think like if you, if you look at the, the, the different models that are out there today, um, they, they have evolved a lot in their abilities to build code. Like if you would think at, um, chatt PT two years ago, even 12 months ago, they weren't like the level of coding they could provide were really junior level coding like an intern. They could code like an intern.
They were now 12 months later and the ability to build code is much, much better and much, much higher now. And I would say they probably match the level of a senior or a principal developer, uh, that you can build COVID. I think, however, from a security perspective, we are still, we're still kind of behind where I think we're still at that junior intern level where the code that is being generated by these different models often still has mistakes in it that shouldn't be there, and it's not, it's kind of normal because they've been trained on publicly available data, and of course there's a lot of bad sample and bad coding patterns available on the, on the internet.
Now, I do think that is going to change over time. It's gonna take us maybe another 12 or 24 months, maybe 36 months to get the, the security of those models are their ability to generate secure code to get that up to scratch. But I think at the moment we're still kind of faced with, there's different models that have different level of security competencies in coding in Java or COBOL or any of those coding languages.
Agreed. I know, I have to agree with you. Um, now there's another school of thought, Peter, that says, you, you need AI to fight AI kind of thing, right?
So, you know, the bad guys are using ai, uh, in, in every way imaginable to make their malware better, to find more vulnerabilities, to improve their phishing attempt at ransomware. Everything. What secure Code Warrior are you doing?
So our belief is that if you take a developer that knows about the dangers of working with AI that knows about secure coding and secure coding patterns, and you combine that human with a great LLM, like an LLM that is good in, uh, secure code generation in Java or in c or in c plus plus or whatever you use, if you have that combination in our organization, you will get the productivity gains that everybody is hoping for, which means much more code, much more faster and more secure. We also think that the opposite is true, right? Take a developer that is not aware of the danger that, uh, or the, the pitfall of an LLM and that is maybe not aware about some of the insecure coding patterns and secure coding patterns, and you combine that developer with an LLM that is maybe not as strong in secure coding in a certain coding language, I think we will create the complete opposite effect of what we want.
We'll have 10 times the amount of code with 10 times the amount of technical debt and misery in it. And I think we, we want to be able to change that. We wanna make sure that everybody kind of falls into that first category where you have a great view that knows the dangers of ai ai and you combine that with an LLM that knows about secure code generation in different coding languages because that's the productivity gain I think that everybody is looking for.
Yeah, I, I agree with you. I agree with you, Peter. I, I, you know, I, I did text Strong Gang today, had a few more conversations today, this whole week, and I think, you know, we were both around, as you said, the early two thousands.
com bubble as you were as well. Are we in an AI bubble? Peter, are, you know, are we out in front of our skis a little bit in, in terms of what the hype is and the amount of money being tossed in here, right?
Are we thinking enough about security? Is the functionality there, right? I I saw a, a Twitter post or ex post whatever the other day.
Um, if you look at the amount of money just in the US being invested in ai, it's roughly the size of Singapore's economy, but if you look at the amount of revenue being generated, it's roughly the size of Somalias economy, but there's a little disparity here. Well, I think you've answered the question yourself, right? I think I, I, I think there is opportunity, right?
There's absolute opportunity and I think everybody is trying to kind of get into a get in it. Does that mean that things are going to explode and blow up and maybe lots of companies will go down because of ai, most likely, but like all of these investors are making bets, and I'm sure that some of them will work out and some of them won't. Um, e so yes, you could, you could, like, what I see is opportunity.
There's an absolute big opportunity for AI to disrupt existing technologies, disrupt the way on how we work today. Um, and yeah, this may be a little bit of over investment, but I'm sure that'll, that'll correct themselves over time Is people are always willing to soak up extra running, right? That, that's for sure.
Um, Peter, beyond the, the trust agent and ai, what else is in store with Secure Code Warrior? Thanks for us, it's really important with SEW Trust Agent AI to kind of stay on that pathway of how can we help the future developer, right? And the future developer is one that is either using AI as a, uh, as a pair programmer, so somebody that kind of sits in the ID with them and kind of helps them providing code snippet, providing guidance, providing advice on help to build things up to the developer that is white coding, which is the one that just sends the instruction to the LLM and it builds an application for itself.
And we to stay very close to that developer and making sure that, um, we release features and tools that will help them to enable safe adoption of AI within our organization. What was really surprising to me is that if you ask the question to any size of an organization, how much of your code today is being assisted or written by an LLM, very often they don't know the answer. Um, they, they, they might have a rough idea, but they can't really show data or really, really tell me, well, 20% of our code is written being written by chat pt, and 10% is being written by deep seeq.
That visibility is not there. And I think with SEW Trust H ai, we're hoping to provide the CISO with that visibility so they can actually see, um, which applications are being modified by which, which type of LLM and and, and who is the developer using those LM. So it's basically the link between developers, ai, and the real software applications, and that you can kind of see that link and then also control and governance some of those, uh, aspects of it.
Fair enough. Peter, we didn't mention what's the website for Secure Code Warrior? com.
I, it's too long. We need to shorten it to SEW io, but we'll, we'll figure that that out. com.
com. Yeah. Um, and I assume people can get all the information on the SEW Trust agent there?
Yes, we have our, our, our product demos or videos. Um, it's, it's all on the website. So if, uh, yeah, it's definitely there.
How long are you in the states for? Um, I'm only here for about three days, but I am back in about two weeks. Like, one of the downsides of building a company out of Australia is that you have to be in the place where your customers are, which is the us And so I am very offering, doing the lag between Sydney, LA, Sydney, San Francisco, Sydney, Dallas.
It's, uh, unfortunate every, every month, month, and an app or so, You know what? But you do get to live in near Sydney. I love it there.
One of my favorite places in the world. Peter, thanks for coming up here on Techstrong TV and, and giving us the latest scoop on what's happening with Secure Code Worry, the SEW Trust agent, the state of the AI and security market, continued success, and we'll see you soon, I hope. Awesome.
Thank you very much, AAM. Thank you. We're gonna take a break here on Tech Drunk tv.
We'll be back in just a moment. Hey everyone, welcome back here to Text Drug tv. You know, uh, we were talking in the Green Room.
My next guest is from Space Lift, and I usually see Space Lift at every single cube con we go to. My friend Dmitri Vlado is CMO, I know Dmitri for several companies that he's been with, and we always say, oh, we've gotta cover Space Lift, we gotta cover Space Lift. And I never get a chance to talk to anyone from Space Lift.
Well, now I finally got a chance I want to introduce you to, and I'm gonna do my best to get this name right, Maron Walinski Wachinski, co-founder, chief r and d Officer Space Lift. Martin, say it Marin, say it right for me. Ky You know, it's my, my tongue just doesn't go that way, but I try.
Marin, a pleasure to have you on here. As I mentioned, we've been wanting to do more with Space Lift for a long time. Exciting company, exciting story.
But before we get into Space Lift, let's hear your exciting story, right? You're a co-founder here. What, what, what was your passion?
What, what drove you to co-found Space Lift? I will admit that I'm a completely accidental co-founder. I'm a a software engineer by heart and a DevOps person.
I've spent seven years at Google being an SRE mostly, and it was like a backend of the backend. It was tape storage, cold storage. So like imagine it's, you never get talked to unless someone is in real trouble and the only place they can retrieve the data from is your tape that is probably in the vault somewhere.
It's a very, very kind of like not in the spotlight, uh, sort of thing. I did, uh, spend some time in Facebook being building clusters that was more, uh, customer facing, but I'll say as an engineer myself, I was then, um, consulting for tech companies mainly in Europe around, uh, cloud native, um, infrastructure, moving to cloud, adopting cloud, scaling cloud. And I essentially, you know, I love Terraform, I love HashiCorp Technologies, I love Terraform, but one thing that was missing is the, the multiplayer mode for Terraform.
It felt like it's an amazing product when you're just using it on your laptop. If you're using it with a, with with a friend that you can col collaborate on Slack with, then it's probably okay-ish. The moment you scale to a team and then to a company that falls apart entirely, it's essentially single product.
And what we're building with Space Lift is a multiplayer mode for Terraform and other technologies like that. Absolutely. And, and that was one of the, one of the not, you know, and, and I'm not knocking, that's a bad word to use.
I'm not knocking Terraform, Terraform was an, is an amazing tool, but there were things that there were functionality that it needed and, and, but you know, that's tremendous opportunity, right? In this case, space lifts opportunity for those who are not familiar with how this story progresses, terraforms open source. So you wanna build additional functionality, you could build additional functionality, and under the open source licensing, you, you can contribute that back to the, to the project and, and, and everyone could use it, right?
Um, then of course the licensing changed a little bit there, and the, the industry, the community kind of, uh, pushed back on the licensing changes. You know, it wasn't truly true open source anymore. And the whole open tofu, right fork came out here.
And, and that again, gave everyone opportunity to contribute and, and build a, build a better mouse trap, if you will. Martha, and I know Space Lift was one of the key drivers behind the Open Tofu Fork. And you know, of course Open Tofus now part of, uh, CNCF right?
Fast growing. And, you know, I wrote an article a couple weeks back, look, there's probably, there's a place in the market still for Terraform, and there's a space in the market for open tofu and, you know, it's a big market out there. Yes.
I guess my question to you then is though, open Tofu terraform, what makes Space Lift special? Where's the special sauce in space Lift Beyond Teams? Sure.
Um, so both Open Tofu and Terraform are essentially cl I, they're single player, they're meant to be, right? Run on on your computer, maybe in a ci, but they don't necessarily provide the sort of guardrails. They don't provide a, uh, the coordination collaboration layer.
The beauty of Space Lift is that it provides a uniform layer on top of many technologies. So we do support Terraform, we do support Open Tofu, we support Lummi Cloud formation, Kubernetes, you name it. And there is a, there is a uniform layer of, for example, policy as code.
And that policy as code layer allows you to define your rules and what can go through, what can't go through, under what circumstances. And not only that, but the policy S code layer also involves coordination. So you can declaratively specify certain processes like how code goes from your, your source control into a particular deployment, right?
Where, which way it goes, right? So this is something that is truly shining at scale. And that's the thing, like Space Lift is all about, scale is all about control.
It's is all about visibility and auditability, Terraform is a really nice tool, and so is is Open Tofu. Um, but they're essentially cli and they're not designed to work on a scale where people are using them. You could build something on top of a generic CICD.
So, you know, we onboard a lot of customers coming from GitHub actions. We onboard a lot of customers from Jenkins. And to be fair with you, what we're doing at Space Lift is not rocket science, right?
Can you build something similar for your company? You can. Is it normally your job?
No. You're probably, you know, you're probably having a lot of different things to, to walk on. And you're essentially buying something that is, is good, is proven, is supported, gives you good user experience, and gives you good guarantees that it'll stay up, it'll be up, it will, um, be updated, et cetera.
There is no magic in what we do at Space Lift. We're just doing a multiplayer mode very, very, very well. I love it.
I think you're being humble though too. So Space lift is, is, it's a platform, right? But, um, you know, and, and so once you have a platform that allows you to interact with projects and products and, you know, one off like this kind of thing, but really, you guys talk a lot about the, the dual approach, if you will.
Um, talk to us about what we mean by that. Uh, is, is that what we launched today? Or you want to talk about intent, right?
Or Yeah, Well, I, I, I'd like to get into that yes. In the whole agent AI piece of all that, but the twin path is, is kind of it. Yeah.
So I think there's, the, the, um, IAC story is, is an interesting one because there isn't really a middle ground in provisioning infrastructure when you think about this. There are two, like, technically it should be a spectrum, but there are two extremes, and we don't have a spectrum. The, the, the extremes are I click on things on a console and it's kind of like, it's fast, but it's absolutely non repeatable.
It's not traceable. You, you have no idea what's happening. Uh, even my colleague will not know I get a database in 30 seconds, but, you know, it's, if someone forgets about it, there it is, right?
And the, the opposite end of the spectrum is full ceremony. Now imagine you're a new engineer on a team, and you're asked to provision an RDS database on AWS. So now first thing you need to do is maybe you don't know Terraform.
You need to learn Terraform, you need to e relearn HCL, but you're not even halfway there. You need to then go to the provider and learn the provider itself, right? Let's say you learn the provider, you know, the APIs of the provider, and now in, in order to get an RDS database up, you're gonna have like, uh, 10 different resources maybe, and then you need to learn about those 10 different resources.
And then you're not done. You need to write the HCL code. And then for Terraform, you need to set up like a storage backend, like, uh, you know, some S3 bucket to, to store that some CICD pipeline.
You'll plan, you'll review, you'll look at the pr, you'll apply, you'll probably do it a few times because maybe the first time it doesn't work because you're, you're pretty new. Honestly, for someone like a, a, a senior engineer that's a couple of hours of work for a junior engineer or for someone who's maybe senior, but in some other area, like a senior data scientist, that's a few day project just to get that audience database done properly. Right?
And as I said, there's a spectrum of like, we, we can do it fast and stupid or we can go full ceremony. And my feeling is that there shouldn't be like just two extremes. There should be options on the spectrum that allow you to do things that are in, in a way that are not stupid, but they don't necessarily involve all that much, all that, that many steps and all that much knowledge that you have to master to even be able to do very simple things properly.
And this is where we're, uh, positioning our new product intent. This is essentially a way of circumventing or short circuiting the whole proper workflow. So if we, if, if intent my will to get an RDS database is on the left and that the RDS database existing is on the right, and there's the whole set of steps that I need to, to do to get there, then we're, and you know, it, it kind of involves translating your intent into ultimately A-W-S-A-P-I calls so that you provision your database, we're short circuiting that we're taking your intent, and we're translating into in, into an a, uh, A-W-S-A-P-I call.
And how we do it is essentially we expose an MCP server that proxies open tofu providers. There, there is a very rich ecosystem that we are co-founders of, of, of all the providers. And now we can short circuit your intent through an LLM to an MCP server, directly to an API call.
And it feels like magic. It's extremely fast. And the beauty of it is that it generates the exact same state as Terraform would, minus all of the other steps.
Fantastic. Hey, Morrison, I, I gotta do a little housekeeping here. We didn't get into how do people engage with Space Lift?
I'm not Entirely sure. That's through the website. Okay.
So best through the website, through GitHub. What, what's the best way to engage with Space Lift? io.
Um, if you're interested in any technical details, you can read our documentation and there's always an option to sign up for a product, uh, free trial. And if you, uh, prefer more handholding, there's always an option to request a demo on the website. And that is probably the best way to engage with us as a company Company.
Excellent. And a, as I said before, you were Space Lift was one of the people, but you know, one of the companies, you know, supporting the, the fork with Open Tofu. So talk a little bit about open source.
You know, you, you, you guys support a lot of open source tools, open tool for, uh, Lummi Ansible, right? These, these are all tools that, you know, have open source components. I talk about spa, you know, and that, and then listening to your background, I'm not surprised, right?
Coming Google and Meta and stuff, you know, big open source supporters. How's, you know, the relationship between the open source community and Space Lift still? Yeah, so I am a strong believer in Open Source as a good business.
I, it's not just like a, um, an ethical choice. Of course it is an ethical choice, but I do believe that having open standards is a good way of running a business because you, that's taking Terraform into account for open Tofu. Like sometimes people would say, oh, you're supporting Open Tofu, but you are building on, like, you're building a competitor to Open Tofu, or Open Tofu is a competitor to you.
It, it isn't like you can't compare a single player tool to an enterprise platform. They, they're not competing with one another. And in fact, the, the ability of people to use Open Tofu for free turns it into a standard that we benefit from, because then this being a standard, we can support the standard, we can meet community where they are.
And by our sponsorship of Open Tofu, we can affect, you know, the, we can touch a lot of that, that, that community. We get to events. Uh, we are a well-known brand.
It gives us the visibility, it gives us, uh, uh, uh, credentials to be able to talk to open Tofu users. So I, I personally believe that it's a great way of selling products. I know it is difficult, but I don't think any other option is, is much easier.
'cause the alternative would be to try to design your own protocol or try to design your own closed ecosystem. And then honestly, like, people are not idiots. People understand that they're, you are trying to log them in, and most of the time they will be extremely cautious and wary of, of stepping into a completely closed ecosystem.
The beauty of Space Lift being built on top of Terraform being built on top of PMI or Open Tofu is that you can get in very fast and you can get out very fast. And that's a good thing, right? Because it, it makes your expectations very clear.
It allows you to be kind of courageous with, with adopting Space Lift, it's not a decision for life. So it is easier to make, it's not a massive undertaking to migrate your stuff to Space Lift because you are already using the same standards that we're building on top of. So you're using Terraform, then a migration to, to Space Lift is an, is a lift and shift, and that's exactly what we did with Intent.
Like we are using the community, uh, project. We're using Open tof, we were sponsoring Open Tofu, we are using pmi, so we want to give back and with intent, there are two reasons why you want to do this. First, as I said, standards, standards are good for everyone.
Otherwise, everyone builds their own little closed Private Card and private, private thing and, and everyone is unhappy. Um, standards allow everyone to grow together. And competition is good.
It's actually like, it's lifting all of us, right? Even to a point, like, we can copy from our co competitors, they can copy from us. It's good for Everyone, right?
I agree with you. I, I think what it does, it establishes a floor that everyone can build off of. Yep.
And what's nice is it, it's a common foundation, right? And then it, it's up to the individual companies to see where they go. It's kind of like evolution, right?
Uh, Darwin and Evolution, and, you know, we all start from here, but this one focuses on this. This one focuses on that. And, and that's what makes, you know, a field of a thousand flowers, right?
All growing in the same field. And, and it's an important thing. I want to mention again, you guys will be in Atlanta at CubeCon.
Uh, I think it's November, I forget the date, November 14th or something like that week. Um, look forward to seeing you there. Maron, thank you for making it on the Techstrong tv.
This won't be the last time. We'd love to continue hearing more about Space Lift in the weeks and months ahead. Thank you for having me, Alan.
Pleasure. We're gonna take a break here on Tech Drunk tv. io you said, right?
Correct. Space Lift io. Go check them out.
We're gonna take a break. We'll be back in a little bit here on Techstrong tv. Hello and welcome to the latest edition of the Techstrong AI Leadership Insights series.
I'm your host, Mike Biard. Today we're with Jake Burns, who's an executive in residence for AWS, and we're having a little chat about a subject that's near and dear to everybody's heart, where to run these AI workloads, the cloud on premise, somewhere in between. Jake, welcome to the show.
Thank you, Mike. Glad to be here. Yeah, I think one of the challenges that you see from folks out there is they're trying to figure out, uh, well, if I have data on premise, can I move it in the cloud?
Or does, uh, the old school rule apply? I should just bring the compute to where the data already is. Uh, I think that you should, um, you should bring the compute to the data where the data is, but your data being in the cloud gives you so many advantages to use these cloud-based, uh, AI systems.
And the reality is that moving data to cloud has become a lot easier, um, recently. So there's, uh, there's faster networking, there's other tools available that can help get your data to the cloud. Um, and you don't necessarily need to bring all of it, um, in order to take advantage of these tools.
So, uh, just like everything else gets started now, uh, the best time to do it was yesterday. The best next best time is today. And the sooner you get started, the sooner all your data will be there.
But, uh, I definitely believe that having your data in a secure environment, which the cloud, uh, provides, um, is, gives you the advantage of being able to use inference in the cloud. And I think that you have the best, latest and greatest, uh, inference with the test guardrails and the latest models in the cloud as well. So it's a natural fit.
Mm-hmm. And to your point about that, I feel like if I'm not involved today, it is gonna be hard to catch up because a lot of people will have, uh, a lot more experience than I do, and they'll be much more competitive. So there is a cost of falling behind, right?
Oh, absolutely. Uh, I would say the opportunity cost here of falling behind is, uh, greater than anything I've seen before. Hmm.
So is there some way to think about where these workloads should go by some sort of pattern they exist or some sort of, uh, metrics that we're able to track or observe? Or is this all gonna be trial and error because, well, it's all brand new? Uh, I think both.
I think trial and error is good. And I think, again, those who are experimenting today are the ones who are figuring it out the fastest and they'll be kind of writing the future. Um, you know, I've run, I've run, uh, AI models, um, locally and I've run them in the cloud.
And, um, it's, it's very difficult, um, to, to have enough, um, to, to be able to invest enough in the hardware necessary to do, to do those local, um, implementations. I do see perhaps some value in it, but I also think that, um, you know, we, we went through this with cloud where there was this kind of debate between is it more secure to run workloads on premises versus in the cloud? I think to some degree that debates still going on, although I think in my mind it's settled and I think in most people's minds, um, the cloud, uh, when you don't know much about it can sound scary, but the more you learn about it, and this has been my experience working with customers, uh, you know, CISO will go from dead set against cloud to being our biggest advocate once they learn kind of, um, the way the cloud works and the way you have to think about it differently in order to implement security.
But then the far greater capabilities you have with security and privacy, and I think that's true with AI as well. And it's a, a process. We're still going through an education process, we're still going through.
I also think it depends on how you do the math. If you do the cost of the cloud, but you're not including the cost of running your own data centers as savings, well, that's one issue. And if you're thinking that your existing data centers are kind of a sunk cost that you're gonna leverage, well, you might be in for a rude awakening when you gotta go buy a bunch of new servers that have GPUs in it, right?
Absolutely. Yeah. And then also these GPUs, um, you know, there's the refresh cycle on-prem, you know, and maybe you got a three or five year cycle.
The refresh cycle for these, uh, cutting edge GPUs is just, uh, far faster than that and speeding up. We don't know how fast that's going to get. So trying to keep up with that, I think is gonna be, uh, a major challenge for those who try to do it not in the cloud.
If you leave it up to the cloud providers, then well, it's cloud provider's problem, and that's, uh, a good thing to outsource, uh, just always having access to the most powerful hardware and the most powerful models. And every data scientist I talk to seems to wanna always have access to the latest and greatest. It turns out we talk about this GPU shortage, but the reality is a little nuanced.
It seems like most of the data science teams just turn their nose up at the older GPUs. So there may be plenty of 'em, it's just they don't want to use it. That's true.
Everyone wants to use the greatest, uh, out there because everyone wants to have that competitive advantage. And, uh, those, the competitive advantage versus having something that's just one generation old, which might be three months old at this point. Um, it's, it could be, uh, uh, a huge difference in the type of results you get.
Mm-hmm. We hear people talking a lot about small language models, and some folks are saying, well, they're gonna use those in conjunction with inference, and that'll make maybe the whole cost equation more reasonable, and you might actually get better results because, well, a small language model is trained on a narrow base of data. Is that a reasonable set of assumptions, and is that something people should be thinking about?
I am, yes. I'm actually a proponent of small language models and I think they don't get enough attention. Um, but then I'd also say that, um, you, the cloud could be very advantageous, uh, for those because it allows you, uh, essentially when you're using a small language model, a lot of the power comes from being able to specialize it for your particular workload and your particular preferences.
And so you still need considerable resources to train those models. You're just basically, um, taking the, um, the, uh, the expense and the time and the resources required from the inference to the training, um, in my, in my opinion. So, um, you know, bedrock, Amazon Bedrock, for example, you know, does model distillation, which can allow you to create, uh, like smaller models based off of these most powerful models.
And you may wanna do that, um, that cycle very rapidly. Um, in fact, you should. So I still think there's a role for cloud for that.
Um, but of course they are, those models can run on-prem on lower hardware, so then it gives you that freedom as well. Right. Do I also need to factor in, you know, the laws of physics here?
Because I think sometimes the, uh, inference engine wants to be closer to the foundational model rather than, say, a wide network away, or four or five network hops away and that will matter to my performance in my application. Is that something to think through? Oh, yeah, absolutely.
Um, latency is a big issue. Um, you know, especially when you're talking about use cases that require real time responses. Um, so like, you know, assistance or customer service agents, things like that.
Um, even sentiment analysis where you want like on calls, um, you know, we have contact center as a service, uh, Amazon Connect, which doesn't, again, it doesn't get enough, uh, a love in my opinion, but the customers that use it see, uh, a lot of value from some of the ai, um, um, tools that are in there, like being able to tell, um, in real, real time, uh, what your customers are, what their pain points are, um, that's a very difficult thing to, uh, develop yourself. So to have an out of a box solution like that, um, is super, uh, super useful. Um, to, to your original question though, um, I think that, uh, that, uh, insight is one of the primary reasons why cloud migration is so uh, critical today.
Um, because, uh, assuming you want to take advantage of all of these capabilities in the cloud, then you want to have your data, uh, live very close to where you run the inference. So if you're gonna take advantage of something like Amazon Bedrock and, and have all of those things outta the box and have kind of the latest and greatest available to you at all times, um, you want it where your data lives, and then you also want your data to be secure, because it's my opinion that, um, in the ne in the next, in the near future, one of the most important things is going to be securing your data because your data is going to give you the competitive advantage over others. You know, because the models are becoming commoditized to, to a degree.
Um, being able to run those models against your proprietary data is what's gonna give you the, the real value that you're looking for. Is this, to a certain degree, maybe a rehash of the debate over data gravity. And I'm asking that question because some folks will say, well, I'm putting all my data in the cloud and I'm gonna have a big data lake.
And other folks are saying, well, all my important data is running in my on-premise environment, because that's where it's driving my mission critical application. So maybe before we have a conversation about workloads and infrastructure, do we need to have a conversation about, well, where is the data gonna be in the first place? I think so, and I think we should have the conversation at the same time.
Um, uh, another observation of mine, and this is kind of my, my passion at the moment, and my mission at the moment is that migrations, um, can happen very rapidly. And I think that most migrations that I observe happen far too slowly, and there's a lot of reasons for that. And, um, it's something that I talk a lot about, um, and, and, and work, uh, most of my work is around that nowadays, but, uh, migrations can happen very rapidly.
Uh, when I was a customer way back in the day, uh, almost 10, 10 years ago now, uh, I did a rapid, uh, accelerated migration, uh, to AWS, uh, as a customer and was able to go all in in 17 months. And if I was to do it over today, uh, knowing what I know now and with the tools available today, I think we could do it in maybe three months. So migrations don't have to take a lot, a lot of time.
Uh, it can be very rapid. All right. There is an old school way of thinking about data migrations.
It starts with a phrase that says, nothing good happens when you move data. Have we gotten better at this? I mean, 'cause a lot of folks, you know, seeing people's careers get trashed over trying to move databases, nevermind entire warehouse warehouses.
Yeah. So it's interesting because there's so much nuance to this. Two things could be true at the same time.
So, uh, it's what you say is absolutely true, and I'm seeing this, um, uh, far more than, than I'd like to, uh, where people are struggling to migrate their data, but it's actually, um, uh, quite easy. I think it's a skills issue, um, uh, education issue and a best practice kind of issue. So, like, for example, uh, when I was migrating, there weren't the, uh, you know, the A AWS snowball, uh, family of services, uh, which essentially is just like a huge disc array that you could put in your data center, copy all your data, and have it shipped to Amazon and, uh, AWS data center, and then have it, uh, ingested into your, into your environment.
That is a super fast way to get your data into the cloud that I think is very much underutilized. Mm-hmm. So as you kinda look at all of this, what's your best advice to folks?
Or the converse of that is what just makes you shake your head a little bit and say, you know, folks, we could be a little bit smarter than that. Uh, so much. Uh, so I would say, um, focus on the pro like your pain points and the opportunities that you can't solve today.
Uh, I see, uh, kind of an anti-pattern with, with AI right now, uh, with agen ai, uh, specifically now is, it's kind of like a, a problem looking for, you know, uh, a solution looking for a problem. But most organizations, all organizations have problems today. We can't go, we can't do these things that we want to do, or we're having these specific problems.
Um, the, the best way to learn how to use these things is to solve a real problem that you'll have. So start small of course, and then work your way up. Um, do it in a safe way.
Do it with enterprise grade tools. Uh, you really don't want to be using consumer grade tools to do these things as an enterprise because of privacy and security and guardrails and all of those things. So I think if you do that and the organizations that do that are seeing a lot of success, uh, there's a real divide right now, which is really interesting.
Um, there are companies who are very much behind the curve on this, and then there are other organizations that are doing things that, um, are incredible that just blow my mind. So it's, uh, it's, it's kinda a tale of two cities and, uh, I think you really wanna be in that forward looking one, um, but do it safely, of course. Hmm.
I think there's also folks out there that think that maybe they wanna build the perfect architecture before they get started, and uh, maybe good enough always beats perfect, but do we need to just kind of go forward? 'cause the truth of the matter is we're all kind of learning together at the same time. Absolutely.
Spot on. So one of the biggest problems that I've seen and, and I've been, uh, uh, working on cloud migrations for about a decade at this point. And so yeah, I'm seeing the same thing with ai.
One of the biggest problems is, uh, trying, waiting till you have a perfect plan. And then what ends up happening is you never have a perfect plan. So it just becomes, preparation becomes procrastination, and then you fall even further behind.
If you do happen to put together what you think is a perfect plan, by the time you implement it, that plan is gonna have to change anyway. So I'm not saying there's no value in planning, of course there is, but you want to get, um, you want to do iter, do it iteratively. And do you learn generally by doing, uh, not by planning.
Um, so doing is the best way to get ready. All right, folks. I believe it's one of the laws of nature that says it's easier to change the direction of something that's in motion, and it is something that is sitting still, and that's true with ai.
Hey Jay, thanks for being on the show. My pleasure. Thanks for having me.
All right. ai Leadership Inside series. You can find this episode and others on our website.
We invite you to check those all out. Until then, we'll see you next time. Hey everyone, it's Alan Shimmel.
Welcome back. You know, it's been an amazing couple days here at Qualys Rock Con. We're Rock Con Risk Operations Conference, and we know, but all good things come to an end.
This is gonna be our last interview here this year, but we've saved the best for last in some way. Let me introduce you to April Lenhardt. If you are a, uh, a text drunk TV aficionado.
You might have seen April talk at our, uh, RSA coverage. Last, I guess it was last May, was RSA or April, something like that. Yes, sir.
It was April and April, but, um, April, first of all, welcome back to Text Drunk tv. Thank you. Great to have you, uh, for the, you know, not, I was kidding about the aficionados.
Most people have no idea you were on in April, or not of course, but tell them a little bit about your background and and what you do here at Qualys. Yes. So I've, in cyber threat intelligence for about a decade.
I started as an intelligence analyst, actually. Mm-hmm. And my goal at Qualys is to bring cyber threat intelligence to the fore.
And really what that means is we have a threat research unit of over 120 analysts. And my goal is to make sure that that work is really shown really clearly to all of our customers. Absolutely.
And, and you know, I, I'm not going to embarrass you or anything, but the, the Callis research team has actually won a couple of awards lately. PO Pony, PO Pony Pony Awards. Pony Awards, yes.
Uh, as well as other awards and stuff. I mean, they're really doing some phenomenal work and, you know, awards are nice, but the work they do is actually really good, important kind of stuff. So it, so it is important, you know, April, I, I was, uh, started a security company in 2001 venture backed security company, and we were in vulnerability management network access control.
And I remember going to, at the time, I think it was still called Citibank, it wasn't Citi yet, it was Citibank, but talking to one of their global CIOs had three global CIOs. And he told me that it took them 90 to 120 days from the day of a patch Tuesday release to actually apply to remediate. Yeah.
And I remember thinking to myself, that's crazy. 90. 'cause even back then, 90 to 120 days was forever.
Right. But he said, you know, they would rather make sure they don't break anything else, then rush to fix even the most serious vulnerability. It's when I knew security had issues, we had issues.
Now that GAP is, you know, commonly referred to today as the, uh, meantime to remediation. Right, right. And, and a and a lot of our security metrics and, and how we measure performance of security teams are built around at MTTR talk.
Talk to me a little bit about MTTR, how your work at Qualys helps that and what Qualys is doing to kind of close that gap. It's not, let me just say a friend, I don't think anyone waits 90 to 120 days anymore, but what do we do? You know, what is the average gap and what are we doing to close it?
To your point about qualysis threat research unit being exceptional, one of the statistics that I'm really proud of and that I was happy that I just got to talk about during my talk is that 20% of all Qualys customers are able to actually remediate CSEC Kev vulnerabilities before they hit csec kev. That's great. And so one of the big things with that is that the remediation time is low because of how quickly we are able to kind of enumerate these vulnerabilities.
One of the big ways that True lens, which is the product that I'm working on, is able to help that remediation, is by really helping you triage what is the most important things to remediate. So we're all surrounded by a plethora of different alerts, different metrics, some that are not super actionable. Right.
And so my goal is to really help kind of, kind of funnel the different things that you could potentially action to say, Hey, what of these are relevant to your industry, to your business? And then from that, say, Hey, these are the specific things that you need to work on. And from there, you remediation time can go away down if you are really focusing on the things that really specifically matter to you.
One of the other things that we're doing is we're able to give a view into the industry that you're in and say, what is the average remediation time? So instead of just looking across all of any industry, uh, any vertical, and you know, how well is is an oil and gas company doing compared to a mom and pop shop, compared to a finance institution, we can specifically say, if you are a large size oil and gas company, how well are you remediating compared to your peers? Because you might think that you're doing great because you remediated this one vulnerability in 15 days.
And come to find out your peers all remediated it in three days. Right. So then you might need to know, okay, hey, I gotta change how we're doing this.
But if you don't have those statistics, you can't really change because you're, you're not really sure what you're, you're going against. Right. Absolutely.
And so this is a big way to, to be able to, to change how you remediate. Absolutely. I got a hard question for you.
So how do we, how do you take MTTR? How do you take those sets of statistics and feed it into the rock to deliver to a, an executive and say, look, because we've lowered our me, um, our mean time to remediation by 20%, we've lowered our risk by, uh, x percent. How, where does, you know, is that even possible?
And how does that get done within the Qualys kind of product suite? That's a great question. So we, we incorporate meantime to remediation in two ways.
The first is kind of, uh, for every individual vulnerability, we want to provide a meantime to remediation. So we're able to get on a very granular level, what is your MTTR and what is everyone else's MTTR? Yep.
We are also able to say kind of at the, at the bird's eye view, at the very strategic level, how are you doing with your remediation versus how are others doing? So you're able to say, you know, taking aside one or two vulnerabilities, um, actually looking at everything, what does that look like? And those are statistics that you can share with the board, with different stakeholders, with investors, and those are things that you can, you can really incorporate into that workflow.
I love it. I want to turn from MTTR to MTTD mean time to detection. Mm-hmm.
Well, let's first, you know, I love throwing acronyms at, at the audience, but let's, I said it's mean time to detection, but what does that actually mean When you're thinking about meantime to detection? Think of from when a vulnerability is, is first introduced to our system. So when are we, when is the vulnerability first, first acknowledged as a vulnerability to, when on your systems do you say, Hey, this asset is associated, um, with, with a problem?
When do you know that there is a vulnerability? When is there risk introduced? Um, this is a really critical metric because you need to know, Hey, um, has this been sitting on my system for years?
Or was this only a problem, you know, a couple hours ago? Very important to know. Absolutely important to know.
Now, how, how do we, how do we measure that to quality? So, because to a certain, you know, to a certain extent, well, it depends on what kind of threat intel you're getting, how vigilant you are, how well, you know, the whole, I mean, everything. And some of it is pure dumb luck, I think, too.
How do you, how do you quantify for the luck and quantify for all these things and say, okay, because you're using Qualys, your MTTD is lowered somehow. There are definitely certain aspects where if you're looking at espionage actors, if you're looking at these really long dwell time actors, you are going to then have them, of course, associated with TTPs where they will use vulnerabilities that will be in the system for a long time. Right.
But if you're looking on average, if you're looking at, uh, zero day vulnerabilities, if you're looking at kind of what we see typically in, in the daily news, the most critical thing is being able to run scans and detect these things as quickly as possible. And with Qualys, we have such a robust system, we are able to really give you kind of as small of a delta as possible, um, from from when you are first, from when we first know about it to when it's detected. And that's, that's really kind of the critical timing that we're looking at.
When we say timing is everything, or we're looking at those metrics, that's what we're looking at. I agree with you. I agree with you.
One last topic I want to throw, and that's ai. It's changed everything this year. How's it changing what you're doing?
It's changing what we're doing in a big way. So we are leveraging ag agentic ai, where you can ask questions like, Hey, I see all these different risks and vulnerabilities. Help me triage what to do next.
Um, what, you know, Qualys, what do you see in the system in terms of the assets that I need to look at first? And then when you have the system, how do you incorporate it with all the other products? So now, instead of kind of having to do all of these disparate pieces alone, we are able to say, Hey, let's, let's automatically using Agen ai, be able to connect with all the other products you're using in the ecosystem.
And then say, okay, what do we now do to, to be able to triage this? How do we evaluate risk? What does that look like?
Again, across different industries and also within my own system, what do I need to focus on first? So agent AI is really being leveraged strongly by Qualys as a way for us to continue improving our systems and as a way for organizations to help mature their own cybersecurity posture. Got it.
I got it. If I had to ask you sitting here next year, how much more AI agent AI is going to be, you know, not, not, uh, it's gonna be a bigger piece of, this is, I guess the conclude the, the feeling, but is it going to 10 x your, your team and, and your stuff, or you know what I mean? How, how, how?
Yes, it's big, but we're still scratching the surface, is what I'm saying. We're still scratching the surface. Our, at least on the product side, what our plans are really are to try to run as quickly as possible, but as safely as possible.
Absolute. We are a security company, right? Absolutely.
Um, but to try to incorporate as many different uses and as many different ways, um, that we can help companies be able to leverage threat intelligence and be able to mature their own organizations. Um, and again, to, to do it in a way that is possible, probable safe. We love it.
April, I know you ca literally came off the stage, came here. I want to thank you. Thank you for all the work you do.
It's been a great Qualis rock on, and you've been a great guest to end it. Thank you so much for having April. Maybe we'll see you at RSAA couple months March this year For sure.
All righty. Hey, that's gonna wrap up our Qualys Rock on coverage here in Houston. We hope you've enjoyed it.
If you missed any of the live feed, uh, we'll, we'll have the on demand by next, I don't know, early next week. But until then, this is Alan Shimmel on behalf of Qualys and Techron Techstrong tv, we're out. Bye-bye.
Hey, everyone. We're back here live in Houston for Qualys Rock on conference day two. We've been just talking to a bunch of different people already this morning.
We got started early. Hope you're enjoying it. Our next guest, Richard Cyan, you nailed it.
Well, it's not my first time interviewing you, but Okay. If, if you follow along at home, I actually spoke to Richard last year in San Diego for, uh, quality security conference, QSC Richard, if I'm not mistaken. You had just joined around then, wasn't it?
Yeah, I've been here maybe 20 months. I feel like I'm a baby. You know, it's in months.
You Yeah. The time. Yeah.
Not making, I, and I do remember a little of your story, but no one at home is gonna remember it. Right. Why don't we, let's start there.
Give us your, you know, a little bit of your journey to being a quality in about 20 months. Sure. Great.
Well, actually, this is my second stint. I am in a boomerang about 20 years apart. So actually when I started Ed, ed and I were both Midland engineers.
I remember he'd show up in cargo, uh, shorts and T-shirts. Yeah. Uhhuh.
Yeah. And then I went on to do this serial CISO thing, GE Twilio Lending Cloud. I've been a Chief risk officer in the insurance space.
Mm-hmm. Um, and I've written a few books, but summed and I stayed friends. And when he started on this journey, this new vision on the Risk Operations Center, and more specifically ETM or enterprise True Risk Management as a platform, he called me up and said, Hey, would you like to join the team?
And I was like, this is great. Can't wait. And here I am now.
That's fantastic. It is a great story. Now, your official title is not Chief Risk Officer.
It is not Chief Risk Technology Officer, and we owe Summed the thanks for that great title. He Came up with that, He came up with a title, and I think the emphasis really is 'cause 'cause of my background on risk, um, first and foremost, helping to bring, I guess, the world, particularly CISOs, along on this risk focused journey. But at the same time, I have a role in helping define technology as well.
So being a voice for a reason, I suppose, to the world on the risk side, but also helping to guide some of the product as it relates to wrist as well. So I do both those things. I love it.
Yeah, it's great. And you know what been around a while, you, you learn that you want something that kind of plays to your strength. Right?
Right. And this is a, just, just like a great role that plays to your strengths and, and it's good when, you know, things come together like that because at the same time, they're, you know, Qualys is the risk operations company now, right. This conference is the Risk Operations Conference.
So it all, it all fits together nicely. You know, you like to see that in life. I'm, I'm pretty excited.
I'm like a dog with two tails. I can be more excited. So, Absolutely.
Richard, you are present, you presented here. Yes. And, um, why don't, you know, people watching this live at home probably aren't here by definition, unless, you know, at Quantum they could be in both places, but as soon as we would know they were, then they wouldn't be, um, spending a lot of time with some quantum people lately.
Yes. Anyway, talk to us about what you spoke about. Sure.
Um, the title of my talk was Risk Yoga. So I was the day two keynote, so risk yo Yoga, turning Strategy into Measurable Action. And so, yeah, I didn't wear any yoga pants, by the way.
Uh, okay. I, I taunted people and told them I might do it. Uh, but yeah, it was an opportunity to relax and, uh, I, I suppose play with the audience.
I actually, uh, there was a yoga theme throughout, but I ended up asking a lot of questions and people would answer. And I would use that to, I, I suppose instruct them in, uh, new postures as it were to use a yoga theme and how to, how to think about risk perhaps in ways that might be new to a security practitioner or security leader. And, um, I guess it went, it went well.
It seems like good feedback. People are still here, so I didn't scare anyone off, but yeah. All Right.
It was enjoyable. Um, so yeah, I'm gonna come back to the, to the quantum thing. Even we can't know everything.
'cause like almost by definition, once you know it, you don't know it. Right, right. It changes it.
How do you, Mr. Yoga professor or instructor, how do you, cybersecurity especially today seems almost about uncertainty by definition. Yes.
So if it's about uncertainty, how can we have any certainty? Right? Right.
It's very, you know, is the cat in the box or not? Right? How, how, what's your advice Sure.
To grasshopper out there right. About how to deal with this? That's A great question.
So, you know, it's when we're uncertain about something, that's actually when we measure, and the more uncertainty there is, the more measurement there is. When you stand a lot to lose, when there's high stakes and you, there's a lot of uncertainty. That's actually where measurement comes from.
If you think about statistics, right? When statistics came about, because someone had small and messy data, and they still had to make a bet. In fact, one of our main statistics today comes from the Guinness Brewery.
It was actually considered part of their intellectual property where they're using very small amounts of data to make forecasts about crop yields, things that go into beer and whatnot. And so small, messy data to make better forecasts. That's the same thing today.
Even with ai, in many cases you think, oh, we have all the data. Well, we, we have sensing and artificially intelligent adversaries. On one side, we have a business that's digitally and AI transforming on the other.
And here we are in the middle. So there's, we're just surrounded by uncertainty. And the stakes are large.
I mean, just look what happened with Jaguar Land Rover. You think about Marks and Spencers we're talking hundreds of millions of billions of dollars of impact. So the question is, if we were gonna say, well, it's, if we say it's immeasurable, if someone were to say that to me, what they're saying is all possibilities are equally plausible to me.
They're gonna say, uh, we could be hacked a hundred percent of the time all the time, or maybe it happens 0% of the time. So, well, what do you do in that case? Well, you say, well, since I, I'm so uncertain as a security leader, you know what I'm gonna do?
I'm gonna spread two little butter across way too much bread. Right? It's a Tolkien quote.
Um, but there's a sun Sue quote, uh, from this that's really great. He says, he who is everywhere is weak everywhere. So the idea is that a general who's gonna deploy forces everywhere ends up being weak everywhere.
So in the case of security, while we have a lot of uncertainty, we wanna measure so that we can take those resources. Again, we stand in the middle here. We got, again, sentient, artificially intelligent, bad guys here.
We got digital and AI transformation here, by the way, who typically has 10 to a hundred x the budget that we have. And here we are in the middle. We have to measure to focus our resources.
Sorry I went a little long, but that was kind of the gist of my talk. You're a treasure man. I, I could listen to you all day talk about this.
It is great. So I think you've outlined the problem and the, and the environment that we're dealing with. Now, some may say, look, you gotta fight fire with fire.
Right? You got the AI stuff here. You got this transformation, which is AI powered here.
I gotta have AI here too. Yes. What do, is that the answer?
Well, I mean, I don't know if you, when we say, is that the answer? I mean, is that the answer to all of our security drama and dilemma? I would say I always look for the magic bullet, but I I, there's no Santa Claus either.
Very good. Yeah, no agree. So, um, yes, we have to use ai.
Um, here's something that's distinctive about Qualys. We're using ai. We also happen to have about 120 to a hundred, somewhere between 120 and 150 researchers, not just researchers, award-winning security researchers.
They just won two pony awards, uh, back at Defcon. Yep. This, they've, they've done this two or three other times as well.
So we have this elite team. What you wanna be able to do is take that team, use them to actually do reinforcement learning with your AI models on somewhat of a continuous basis. Then obviously, bringing in all that massive amount of data from, in our case, enterprise to risk management.
You want to have all of that working together. So it's not just AI by itself, but you want the AI plus the human expert discernment to work together. So this is, this is one of the reasons why I'm here, is because I think this is part of the, I I guess it's the data or AI or measurement moat that Qualys has.
Is that an opportunity to work with just what I'd call a, a cesspool of security iq. And these guys bring that together with AI and data to make, make a big difference. So it takes the people and the AI together.
So it, it's, you're not even talking human in the loop. You're talking a true partnership. Like a si almost like a sidebar.
They're putting on this, you know, I don't know. Yeah. Argument.
Don't see how that will get killed over here. Yeah, we might, I mean, so that's human enhancement. Yeah.
Yeah. Right. And, and that may be, you know, something we're gonna see coming down here, but I, I think right now we're still in that partnership phase.
Well, look, AI does what AI does. Yes. And we're going to use, it's a tool.
Yeah. Like every other tool humanity's used since, you know, homoerectus or something. But we also have to recognize that there are certain things that the human still has to do.
Yeah. That, you know, it's, it's gonna take a human. Right.
And, and I think that's where we are today. Now we're seeing the rise of agent AI become much more prevalent. Even the generative ai ai, you talk to some of these people who are really into ai, they'll tell you generative AI is yesterday's news.
Right. Right. How's that changed the equation?
Well, So that might be marketing people. I mean, gen so generative models by the way, not to get overly nerdy, but generative models are a thing. And so the idea where you could have some learning off some data, and based on that the model can then extrapolate, make inferences, and even generate new data, new scenarios, that's a generative process.
So that doesn't go away ever. No, No. I, I think that's table stakes.
Yeah. For the age. 'cause without it, the agents can't operate, they're not autonomous, they're just APIs.
Yeah. So yeah, just a, some assumptions in the modeling there. But yeah, genetic ai, the idea that it, you can have composable models that, um, and we use this word autonomous, right?
Um, I think that, you know, it's autonomous with constraints, right? You, you, you want it to make reasoned, uh, inferences and then take deterministic and safe actions. Yep.
Right? And so again, when I go back to this idea of that we have all these researchers, we can look at things like Mitre attack paths, right? We can look at the combination of attack paths and controls.
By the way, the combination of attack paths plus controls, plus exposure, that's a mathematically, uh, massive. Like we humans cannot reason over that complexity. Great.
We have AI for that, but AI is only gonna be as good as the assumptions that are put in underlying it. So again, I wanna go back to the idea that it's really, maybe you call it human in the loop, perhaps you call it reinforcement learning. But for us, and again, this is where I think it's a Qualys distinctive, is that we have this elite set of humans, these researchers, award-winning researchers, bringing them together with massive amounts of data.
We have this giant data lake, right? Bringing that together with a agent. AI becomes the sort of scenario where you can start saying, okay, this is how you can start looking at not only just the deterministic action you can take or have the models take patch this, lock this, but also start saying, alright, given your environment, given these attack paths, given these adversaries, here's how we can start rank ordering.
How you go about purchasing controls, how you go about making investments. At what rate do you roll those out, given your financial constraints, what's the most optimized approach you can take so that you avoid spreading too little butter across too much bread, but you start focusing on the risks that matters. So that's, that's why I'm here.
That's why I'm excited about what quals is doing. Absolutely. Hey, last question.
I'm gonna go off the reservation a bit. Sure. Okay.
I mentioned quantum a few times. Sure. Quantum and security post, you know, post quantum cryptography, and there there's been a lot of buzz around, Hey, we need to be getting ready for quantum.
It may be three years out, five years out, maybe more. Right. Not much more.
Right. Um, what do you, in your role at Qualys, this is kind of something on your, on your desk, right? Yeah.
Yeah. What are you, what are you thinking? What are you seeing on that?
So it is kind of interesting with actually, with, with what's happened with crypto most recently, but I, as I looked at it, there's something like one, maybe 50%, if not one third of crypto will be completely exposed. I think there's more recent changes where they're saying, well, okay, we're having some protection here. You know, again, I'm not, not a crypto expert.
Don't claim you. No, I get it. Not even on tv, even though it is his tv.
Mm-hmm. Um, but I think as a risk leader, we do need to be thinking about that. So what's, what is plausible in terms of, you know, in, in fact, even thinking about the future, I'll say this, and I talked about this on my talk, uh, I'm gonna kind of go off the reservations, but prediction markets.
Are you familiar with prediction markets? Yeah, sure. Big thing ties to crypto as well, but people making bets, like prediction markets significantly outperformed, uh, the pollsters in the last election.
The presidential election. Yeah. Great.
Where they failed, by the way, was on, uh, forecasting could be the next Pope. By the way, people are betting on the Pope thing, Uhhuh. So it's kind of interesting.
Oh, they bet on that. Whatever it is, right? But the idea of taking that same approach, all right, so given what we know about crypto, given what we know about the current state of the world, how can we, how can we start measuring and creating really that that's already modeling.
How can we think in a, you know, relatively mathematically unambiguous way that retains our uncertainty without obscuring what certainty we do have, make the best bets. That is what risk management should be doing. Sure.
And yes, I am thinking about that stuff. I'm thinking a lot more though, uh, right now about AI and what that means. Yeah.
Than crypto. Well, I, I think it, and I think AI becomes the force multiplier, or maybe it's the other, maybe when Few Day does come and we do have Quantum combined with AI though, right. I think those the two volatile, you know.
Right. Get crazy. Sounds Like more employment.
I don't know. More security, Job security. Yeah.
For security teams. Well, if they don't replace us with AI robots or humanoid, whatever physical AI is. Right.
Right. Calling it Richard, thank you so much. Thank you so much, Allen.
On Over. Alright, pleasure. Likewise.
This guy's great. Do check him out. Your books are still out there too, and everything else, it's getting a little loud here, but I'm hoping you could hear us.
We're live at, uh, quais Rock on. We'll be back in a moment. Hey, everyone, it's Alan Schell, and welcome to another episode of Control Alt Deploy.
Control. Alt Deploy is a, uh, a podcast series that we've been doing with our good friends over at Oakland Text now for more than six months, I think. And we discuss different areas around DevOps, that SecOps software development and deployment, CICD testing, et cetera.
But really with an eye towards, you know, what, what's happening in the space. And of course, the biggest thing happening in the space is probably ai, uh, as it's taking a, a, an effect on everything. So in today's episode, we're gonna look at AI and the role of, and, and the role it's playing in testing, automated testing, continuous testing, whatever you want to call it.
I'm really happy to be joined for this episode. And it is just me and him. This one, I know many of the others, we've done big panels, but this is a one-on-one with Yev Sayers.
Yev is the, uh, a DM Chief architect at OpenText. Yav, welcome to Control Alt Deploy. How are you?
I'm Doing great at text for having me, Alan. My pleasure. Yana, before we jump into what we want to talk about around testing and ai, give people, it's, I, I gave them your title, but what do you actually do over at OpenText?
And tell us a little bit about your journey. Uh, sure. So, so thanks again, uh, Alan, for having me.
So I've been in, uh, OpenText for the, uh, last, uh, 20 years in different engineering position, uh, as a developer, as an engineer, uh, running internally our DevOps, uh, uh, platform implementation. And, uh, I'm now running our application delivery management, uh, technology and innovation. And a lot of my focus is on, uh, on ai, how to utilize ai, uh, both in our products, both in our own DevOps implementation, in testing, uh, and, uh, very excited about it and opportunities around it.
Absolutely. Thanks for joining me today, YAV. Um, Siana, we were talking before we started recording, we, we actually had a good talk we should have recorded that we'd know with the podcast, right?
com in 20 13, 12 years ago, almost 13 years ago now, testing was always one of the poster childs for DevOps success, right? With DevOps, we, we did much more automated testing, much more continuous testing. And, you know, and that old adage of freeing up the human to do higher level work, instead of doing the same mundane, running those mundane tests over and over, it freed up the human to almost be more of a test architect, if you will, right?
Mm-hmm. The human, the, the human, he or she, right? The human would, would write the script for the test coverage, right?
What do we want a test? And then we can automate the actual running of the test. And then, you know, based upon test results, again, humans would get involved, remediation, uh, whatever needed.
You know what, depending what came out of the test, and it, it made a huge difference. I don't know how long you're doing or been involved in, in, in the space, but you remember before there was a DevOps and it wasn't so automated, right? Mm-hmm.
The life of a tester was, was kind of really, you know, doing the same thing over and over and over a lot. Again, it made it, it made it better, and our testing got better, right? With automated testing, we, we had better coverage.
We, we tested more. You know, I guess the real question is, did it make our software better? Mm-hmm.
That's, that's a great question. That's The question. Um, but now AI's kind of changed the game.
So I've set the table. Why don't you explain to the audience how AI is kind of changing that game? I, I, I think that, uh, what we're seeing, especially in the software, uh, delivery industry is, uh, a significant, uh, shift, uh, once, uh, uh, AI and especially large language model were, uh, recently introduced.
And it started mainly by adopting a code assistant, whether that's, uh, co-pilot, uh, uh, or, or others. And, uh, I think where we are today is that, uh, many organization, uh, including ourselves, realize that it's, it's great to have a code assist, but then you, uh, then you have kind of an influx of new code, and, but eventually your outcome isn't just generating code, is it? It's having new capabilities or feature or delighting your users and, and customers.
And, uh, the rest of your DevOps pipeline or, or value delivery, uh, may introduce bottlenecks. So just generating more and more code, uh, isn't, uh, uh, isn't eventually improving your, uh, your outcomes. Uh, so, um, uh, uh, I think kind of the, the maturity here, or the evolution here is, uh, to see how you can now leverage AI across that, uh, value stream across that, uh, DevOps pipeline.
So it's not just generating more code, it's actually making sure that what you're building is at the right quality, both by meeting the business goals, the business expectation, and also validating that it's secured, that it's performance, that it meets the enterprises, uh, requirements, uh, uh, and, uh, uh, and controls. Uh, so it is a, it is a matter of maturity. It's a matter of evolution.
But, uh, I think that now the way we are looking at, at AI is how can we inject and leverage AI at every step in the software delivery lifecycle from the planning to delivery beyond just coding and coding assistant? And clearly, uh, we are a large enterprise. Uh, there are no controls, regulations, risks that we need to manage.
And being able to, uh, make the most of code assistance, that actually means you need to add these guardrails through AI across the lifecycle. You cannot just look on the coding part. You have to look on testing, you have to look on security.
You have to look on how you validate eventually, uh, uh, I'd say the outputs of your code assistant, of your copilot and alike. Agreed. Agreed.
Um, let me, let me get, let me talk on behalf of the humans out here, though. What do you think the role of the human is in this new way, or this AI enabled or empowered way of doing testing? Is there a place for humans?
I think that's a fair question. It is a fair question. And, and, and, and I think, as you know, uh, uh, as we were looking back into, uh, uh, previous, uh, technology, uh, enhancements and disruption, whether that's around, uh, uh, the shift to or from manual to automated testing, uh, the production of, uh, mobile and mobile application, et cetera, eventually also hear the role of the tester will, will evolve.
It has to evolve. I don't think that, uh, uh, humans are, uh, obsolete. Uh, I don't think that the human, uh, uh, testing is obsolete.
There is still a role here for the human, and, and we'll discuss that in a, uh, in a second, but it definitely has to change. Uh, the way we're looking at it is, you know, eventually testing evolves to become more q quality engineering. Uh, that means that, uh, the current tester would need to know how to best utilize, uh, the new tools, the new capabilities of AI across that life cycle.
And that means, for example, uh, when you're looking on, you know, your requirements or the design, uh, how to best utilize AI to better plan, to better design, to identify risks earlier in the lifecycle. Uh, so if you have now, uh, a new feature being designed or, or planned validating that there are no missing aspects in the requirements may have validated that there are no ambiguity in the definition, uh, doing earlier in the life cycle, threat modeling, utilizing AI to identify security risks upfront, et cetera, uh, we think that this is a key area where, uh, the quality engineer, uh, can level up and leverage AI to look across that software delivery lifecycle beyond just testing. Testing is a key, is a key part of it is a key control.
But beyond that, so you can, early in the life cycle, do that shift left to identify risks, uh, identifying a big in the design, in the planning, et cetera, that then becomes a better input eventually also for code assistant and the like. Uh, and then the QA engineer is the one that is responsible to validate eventually that output, that output from that, uh, DevOps cycle when you get a business goal, a business requirement, validating that it was actually met and defining which tools, how you utilize AI to put these controls, to put these validations in the steps in the life cycle. So we do see that evolution from the shift from manual to automated testing and up to autonomous testing.
Yeah. Eventually the tester or the qa, the QA engineer, uh, to come and define the methodologies, the practice of the tooling that he's going to inject into that lifecycle to control the agents, to control the agent that are going to build potentially more and more of the software. Sure.
So, hey, I, I, I've had this discussion with people before. So if we're going to use agents to build the software, then we're going to use agents to test the software, then we're going to use agents to remediate or re, you know, re recode or, you know, re remediate the, the, from the test results, validate the test results, remediate the test results. Where is the human in the loop?
Mm-hmm. So it's, it's a, it's a great question. Uh, and, and, and I think here again, it's not, uh, uh, black and white.
Uh, I think it really depends on the domain. It it depends on the, the, the maturity of the organization and, uh, you know, the, uh, the criticality of the, the application and the software. Then, yeah, there could be cases where it's a relative simple application, uh, that follows a pattern.
And yeah, you could, through a vibe coding, uh, uh, get a, a great outcome or a good enough outcome. But in many cases, especially when you are looking on large enterprises, uh, and large scale applications, uh, it's, it's more complex than that. Uh, so, uh, in that case, yeah, I still see engineers, humans, but leveraging AI and assistant to augment them, whether that's in the planning phase, whether that's in the development phase, in the testing phase, in the deployment phase, et cetera, uh, to, uh, uh, accelerate the delivery to actually improve quality by better validating or earlier identifying the risks and concerns and mitigating that upfront, uh, and, uh, uh, validating the outcomes or say the outputs of the agents.
So I don't see in that these scenarios, especially if you're looking on financials, healthcare, et cetera, uh, a more, let's say, a critical application mission, critical application, kind of, uh, just, uh, uh, uh, fading out. Uh, so I do see a more leverage of ai, but then empowering the human, rather, replacing the humans in that, uh, in that scenario. And, uh, and, and I think there is a, uh, an another factor here.
I mean, there is, uh, up to a certain scale where you can know, uh, uh, offload to an ai, uh, agent. Uh, there are many cases where, uh, you know, an ai a an AI agent can't yet, uh, uh, tell you, uh, what is the real human experience of an application? How does it make you feel?
Uh, that's something that you will still need in many of these scenarios, uh, to have the human and a human in the loop, not just to develop, not just to, uh, utilize the agents, but really to provide the human aspect, the human experience. Eventually, we are the ones that are experiencing the applications, experiencing the software, and, uh, that's something that the agent cannot yet replace. And I don't see that happening in the, uh, in the near future.
I agree. I, I don't, I agree. I don't disagree at all with that.
Wanted to, you know, a lot of what we're seeing in the end of, in, in the media now, right? This report that says 95% of, or 90% of ai, uh, programs, projects are not contributing to the bottom line. Mm-hmm.
Uh, another, another study said, uh, 80% were deemed not successful. We've seen other studies where, and this is kind of counterintuitive, 70% of the IT workers are saying, or 75, more than 75%, like critical mess, 77% are using ai, but two thirds don't trust it, but they use it anyway. And when we think specifically about testing yano to use a tool that you don't trust, is, is that the case?
First of all? Is that that valid? Do you know?
And I think it is, I think a lot of people are using ai, but they don't trust ai. Right? And what does that mean for the quality of the code that's being passed on via testing right now?
That, that's, that's a valid concern. And, and actually, uh, we do see that as in, in, in, in many organizations becoming a, potentially an inhibitor for utilizing, uh, a ai. Uh, and that's why my point that was that, you know, in one hand you see more and more usage in one hand of code assist, but a lot of concern that is being introduced, a lot of risk that being introduced on what is the output of these code assistant, what is the quality of the code generate, uh, the security of that code, et cetera.
So you, you have to, you, you have to control that. And again, the, the, the, the more mission critical the application here is, uh, uh, uh, the more, uh, a large enterprise is, the higher the risk is. So you have to counter that, or you have to balance that.
And part of that balancing act is also validating it, having the proper testing and tooling in place, uh, putting the proper still code reviews, human in the loop code scanning, test automation, autonomous testing, as we discussed, to mitigate that risk. And, and still it's there. I mean, you still have that, that risk.
And I would say it's more than risk. You, you have here new challenges that you didn't have before. So traditionally, uh, when you are looking on the traditional applications, they were pretty deterministic, right?
You had an expected outcome or expected behavior of the application. Now, with the introduction of, uh, uh, of AI and large language model that are being injected or becoming part of the software, they're becoming less deterministic. And that requires different practices on how you test, how you validate, how you measure the quality and the experience of these applications.
And it requires taking more statistical, uh, approaches, uh, creating baselines using techniques like, uh, LLM as a judge and so on. So also, the way you test and validate your applications has to evolve in order to meet the new technology of introduction of AI within applications. So it's, uh, to kind of, uh, uh, uh, a closure to your question, yeah, there is more, I'd say, risk that is being introduced.
I think that some of that is acceptable. I mean, we're, all of us are using GPT. All of us know that there could be hallucinations, and we accept that.
And we're, I wouldn't say, uh, uh, uh, necessarily, uh, happy with it, but we are, we accept it. We, we know how to adjust to it and how to handle it. Uh, with that in mind, um, uh, you do need to put, to put in place the right controls, the right validations, the right, I'd say, uh, uh, balancing, uh, uh, uh, uh, tooling, processes, et cetera, in order to still be able to provide enterprise grade applications to your customers, end users, and so on.
And, uh, that requires also introducing, uh, new methodologies and practices, especially when you are coming to test and validate AI powered applications. Fair, fair. So, Janni, let me, let me move from the, you know, from the hypothetical to the real mm-hmm.
And I'm asking you now on behalf of OpenText. Yep. Where does the rubber meet the road?
Have you rolled out products around this already? Are people using the mm-hmm. What's the experi been like?
Yeah, Definitely. Uh, we have, uh, uh, we have introduced a, a, a variety of, uh, uh, I'd say, uh, uh, smart assistant, we call them aviators. Uh, so we have our, uh, our own, uh, uh, DevOps, uh, avior testing aviators that are, we're using that internally and also with our customers, using that to generate tests to identify risk and mitigate that by generating tests, whether this could be manual tests or automated tests.
We know how to, for example. And we're using that, not now a lot, uh, uh, improve our planning. So we're using our aviators to identify earlier risks, to do threat modeling, uh, to identify, uh, ambiguity in the requirements and improve that.
Uh, we are using our own aviators, uh, for validating our security, uh, for, as I mentioned, generating tests, uh, for planning, uh, breaking features into user stories, into tasks, and so on. Uh, so, uh, uh, a variety of, uh, uh, uh, of aviator of smart assistance that are being used in every step in the software delivery, uh, lifecycle. Uh, we're measuring that continuously, both the, the success, both the usage, meaning to what extent, uh, uh, or how many tests were generated in a, for an AVIOR versus the human generated test.
And, uh, our at least, uh, uh, experience is that, uh, the trending is very, very positive. Meaning we do see more and more shift towards, for example, tests being generated more by AI versus the human. So that's one measure that we're looking at.
Uh, same goes with, you know, uh, uh, uh, the agile planning with, uh, user story definition, with requirement definition, et cetera. Uh, we're measuring that shift from human driven activities to agent driven activities, and to what extent that is actually being, uh, being adopted. And I'm, I'm, I'm happy or confident to say that no, we're getting these feedback also from our customers.
So that's kind of the feedback loop we're operating in. Uh, each new agent we introduced, uh, we validate with our partners, uh, with our customers, we were getting that early feedback, and then we evolve accordingly, and it looks very, very promising. Excellent.
Excellent. Where can people get more information on that yev? So you can, you can look on, uh, uh, uh, on OpenText website, look for DevOps, uh, the DevOps aviator.
Uh, you'll find more information, demos, uh, references, et cetera. Absolutely. And then, you know, we only have a minute or two left, but I, I want to, as if we're not looking forward enough, I re, I wanna spend the next minute or two looking maybe a little more forward, right?
So now we are, like you said, we're getting our heads around the risk of using ai. We're getting comfortable with agent AI mapping out our test, uh, coverage and, and platform, uh, you know, uh, protocol and stuff. Where do you see this going?
I think that, uh, uh, I, I, I envision eventually a shift or an evolution to, uh, uh, uh, I would say a, an autonomous delivery team. So if today we have, uh, you know, uh, uh, a performance engineer, a functional tester, a security expert, uh, uh, a product owner, an engineer, software engineer, collaborating together to, uh, to deliver a business goal, uh, I believe that, uh, with, uh, the evolution of ai, we'll see a collaborative team of humans and agents, uh, to achieve a joint goal. And, uh, I, I, I think that this is, uh, uh, you know, this is evolving as we speak, uh, and we see more and more, uh, smarter agents augmenting humans.
And in some cases, yeah, you can offload the activity to agents to be delivered, whether that's fixing a defect, implementing a new feature, or a complete, uh, uh, a complete application that's not that far, uh, farfetched. And, uh, beyond that, I also see or envision, you know, more adaptive applications. So applications that are changing their behavior on the spot based on human feedback as they are being consumed, as they are being used.
And just think of it, that what does it mean to have this kind of, uh, uh, ever living software and application that is continuously changing, uh, based on as they're being used? Sure. By us.
That's a totally different ballpark to what we're common to use today. That's almost like evolution right before your eyes, right? Because yeah, as it changes with the humans, you know, it, it's, uh, I was talking to someone the other day about this.
It's such an exciting time to be involved in technology with this right now, because the, the window for innovation, the, the possibilities are probably greater than they've ever been. I mean, I, you know, I was around when we, the internet went commercial, right? And, and wow, what a, that just opened up so many things connecting the world.
And every business would have a place on the web and, and all of these things, right? This is maybe even bigger than that. So, I agree, interesting times.
Jan, if thanks, thank you for being our guest here on Control Alt Deploy, and thank you for all the work you're doing at OpenText. Good luck to you. And thank you for listening in on our conversation today.
We hope this is giving you a little bit of a peek into how AI and, and Agen AI generator of AI ml are all playing into today. And tomorrow's changing landscape for, for testing software. This is now Shimel on behalf of Techstrong and OpenText, thanks for listening.
He slicked back my hair. Greed is good. Greed is what made America great.
Gordon Gecko coming at you on Textron Gang. Hey, everyone, happy Thursday. Wow.
Thursday, man, this week's flying by. I'm Alan Shimmel, welcome to the Textron Gang. We've got another, uh, Rockham Soum line up of, of topics to cover today on the Gang, and we've got our favorite Rockham SOCOM gang members to, to talk about it with.
Uh, let me introduce you to Terry Robinson, Garima Boal, John Swartz, and of course, Mike Fazar. Ladies and gentlemen, welcome. Thank you for, for coming on.
It's good to see you all. Um, Mike, you know, the pigs at the trial, as some might say, So, so let me set this a little bit for you. So John has an article up on Textron one AI that you should all check out, but it's really talking about from his perch in Silicon Valley about how the whole ethos of the Valley has fundamentally changed.
And it seems it's taken a while. I mean, I think I've observed this trend happening maybe in the last decade, but it's now just full throttle, and seems like John, that all these companies that care out there is, um, you know, how much money they can make. And it's all about the almighty dollar.
And I think the customer's getting lost in this conversation. But walk us through what you're seeing. Yeah, you know, it, so it all hit home for me last week at Dreamforce when Mark Benioff stuck his foot in it.
Um, he got caught by the New York Times. Uh, he basically was advocating for the National Guard to come in and clean up San Francisco, which is the site of Dreamforce. And, you know, uh, coincidentally, he's done this the last three years, and he uses it.
He uses the show as kind of a perch to get what he wants. And New York Times also did a report that the reason why he was so pro National Guard is that Salesforce had put a bid into the, into es to, uh, use Asian force. So it was motivated as much by money as it was by politics.
In a sense. Politics is almost secondary to this, the pure greed that's going on. And I, and I remember yesterday, uh, Mike and I were just talking about this a little bit, and, uh, with apologies to Paul Simon and Joe DiMaggio, where have you gone, bill, if you will?
What happened to this kind of ideal of the garage, you know, startup, um, discovery, uh, you know, you make products to make money. I'm not gonna, I'm not gonna fight or push back on that. I, I totally understand that, but I think we've actually reached a point now where it almost, we were in an era where the apps were almost incremental to the point where they were silly, but they were about convenience, about making money and about getting more data from the customer, which became part of the product.
And I think we, as Mike has said, we've come full throttle, full circle. This has been moving this in this direction for quite a long time. I think it was underscored by Benioff, who subsequently apologized.
But I, I, I consider that a hollow apology, honestly. And I, I just think of this, this valley and the fact that they are so ingrained with the government, it's all a money grab. AI is huge.
I understand that, but everything's gone by the wayside in terms of ethics, integrity, the customer. Um, maybe I, I might throw it back to Mike about what he mentioned about the product and how things have changed from kind of some of these foundational companies that were here and how they address the customer base to where we are today. Yeah, I mean, capitalism is a good thing and always has been.
So I don't think anybody's arguing against that in particular, but it does feel like in their Throws of competition with each other and what they perceive to be threats, they've kinda like turned inward to the point where, um, you know, it's all about how much data we can pull, and maybe we're gonna own the future of AI and all these other things. And that's an interesting theory. But I also think that they're gonna misread the politics of the situation as well.
I mean, the short term, you know, greed is good, I guess, but longer term, if it's perceived that AI is costing people jobs, and Amazon was talking about laying off like 600,000 people over the next few years, you know, people are gonna start looking for folks to blame. They're gonna find those guys in the, in the AI world and start pointing their finger at them. And more of them are gonna vote for folks like the guy who's running for mayor in New York City.
So that's, I mean, oh, let, Alan, lemme just point in one thing. I'm sorry, Alan, I'll get outta the way. But there's this, this common refrain, actually, it's growing, it's growing into a chorus out here, and people are noticing this.
And they've been talking about, there've been other folks who have written about this. I, I, I've heard secondhand. Um, and I did go to lunch with a guy who was in the semiconductor industry who's been around forever.
He worked at Fairchild, he worked at a MD, he worked at Actel. And he said, look, I mean, this is nothing new here. But I think what happens, what has changed is there's more money and there's more power at stake, and it absolutely has corrupted people.
Sorry, Alan, Chuck. No, don't be sorry. I'm, say your piece, John, I need a little time to step up onto my soapbox.
Anyway. So let me, let me address a couple of things here. First of all, my friends, welcome to the Oligarchy 'cause, make no mistake, what we're living in is a tech bro, oligarchy, a vital piece of the Trump Coalition is the Peter Field led brotherhood that went down in Silicon Valley that corrupted what was one of the greatest innovation engines in the history of mankind.
Okay? That's what went down here. Lemme tell you something.
I've been in tech for 35 plus years. Mike, John, you have two. Terry Greer, you're younger, but you've been around, right?
What attracted us to Silicon Valley, what attracted us to tech was the meritocracy of it. Whether you are white, black, male, female, non-binary, or whatever you want. Whe whether you come from India and Bangladesh or, or, or Idaho, if you had a good idea and you were talented, you could go into that garage like was and Steve Jobs or Bill Gates and, and, and Paul Allen or, or Hewlett and Packard for that matter, or countless others like Larry Ellison and all these other, you know, people who are now in the tech, bro, oligarchy.
And, and if you have a good product at the right time, and you got good marketing, you could live the American dream, right? Why did, when I was coming outta school, you had a choice. You go work on Wall Street and you get like a $800,000 Christmas bonus and go buy yourself a red Ferrari.
Or you go work for a startup and you get some options. And look, nine outta 10 startups didn't have such great exits. But if you got your golden ticket and you were on that 10th startup, man, those options made you a tech millionaire.
I've, I lived that dream for 25, 30 years, did the IPO thing, did all that stuff. And the beauty of it, it wasn't just Silicon Valley, it started spreading to places like Austin, Texas and Boulder, Colorado, Boston was always a big tech haven. New York, everybody down here in Miami, they keep in South Florida, they keep dream dreaming of Silicon Beach and Silicon Island and silicon this, and, but no one ever recreated Silicon Valley.
It was the envy of the world. And the politics of Silicon Valley were for every man. Mark Benioff apologized because one of his main board members, who's kind of the dean of Silicon Valley, chastised them in, in public and said, what happened to you?
You piece of garbage, right? And then all of a sudden he made that half-hearted kind of, uh, apology. But the, the real Silicon Valley would, this is, this is disgusting to them.
This is not what's, this is tech, bro, oligarchy, plain and simple. I always have a feeling with these guys, and this is not to undermine what goes on out there and all the brilliant ideas and all the hard work, but you talked about meritocracy too. There's a sense, at least to me, that they haven't earned their riches like this, this is not earned, you know, stuff.
This is convenience, this is influence. This is, you know, who you know, and, uh, being, yeah, It's an oligarchy. That, that's how an oligarchy functions.
It's, it's all, you know, and it is a brotherhood. Make no mistake about it. It's tech bros.
The greed is the point. I mean, too, it's like, you know, it's the greed stupid, right? To borrow from the Clinton campaign.
But, uh, yeah, it's just, I've been around as long as you have, uh, Alan, and, and I, I remember a lot of those people fondly in silicon, uh, valley, and a lot of the personalities and, you know, they'd be abrupt and crusty and, you know, and everything else. But there was a lot of respect for them and what they were doing. And I, it's hard to find that right now.
Um, you know, you're in San Francisco, and I would just love to get your opinion on this. 'cause you know, I lived out there for a decade, and I feel like everybody beats up on the town because of the Tenderloin district that sits around the convention center. And, you know, the Tenderloin District has always been, you know, neighborhood ever since, you know, the gold rush and maybe the days of Jack London.
But if I go around the rest of San Francisco and I'm up in Pacific Heights, and I'm in the Outer Richmond and the sunset, it's still a nice town. And so it's not like, you know, we have this kind of emergency crisis that people keep painting about that particular city, or am I wrong, right? Yeah, you're totally right.
You're Totally, totally right. This is, I mean, the fact that Mark be Benioff, who's a fourth generation San Franciscan, by the way, and he talks about this quite a bit, the fact that he plays into that narrative, which is off. And by the way, go to any major city in the United States, and you're gonna find home speech.
Absolutely. I'm sorry, I'm sorry. I go to see my son in San Diego.
The problem there is as bad as it is anywhere. And, and I love San Diego, but here's the point, though, in San Francisco, he plays into this caricature, this, this stereotype, which is totally inaccurate. And he does this as, as kind of a, a way to hold the city hostage.
And I think there was a, there's a fair amount of pushback this time around. And he, he, he stuck his foot in, as I said earlier, and that led to Ron Conway, who does have a conscience. He's the angel investor who was on the board.
He's just like, what's the matter with you? And he walked away, and I think Benioff maybe be as he accumulated billions and billions, and he became more like his mentor Larry Ellison, who has always been this way. By the way, Larry Ellison was the epitome.
He was the Gordon Gecko of Silicon Valley before there was a Gordon Gecko. And, and I think that whole persona has permeated. I think it also is being pushed by people like Mark Andreessen.
Yes. Who, who is among the worst offenders on so many levels, not just, I mean, in terms of, uh, I won't go into it because I don't want to get us in trouble, but he has said some really horrible things and, and he truly believes in them. Um, you know, these, these guys were all those, yeah.
Sorry. You know how bad this has gotten. All these guys, they're making Microsoft look good.
Yeah, exactly. That's what I was gonna say too. So, so the mediocrity of Microsoft now is, is now, now they're the leaders in ai.
And that says so much to me about the state of things. But again, it's with them, it's, it's ba But here's the deal, John, the leaders in AI today are not the leaders. 'cause they're out innovating.
They're the leaders because they're out tech broing, And they're also investing Money. Well, the circular jerk, right? The circle jerk of investment that we see going on between these five or six different companies.
Right? I've never thought I'd ever hear that with the blessings, the blessings of, of the contractor in the White House building, building his grand ballroom. That's, that's the other point I was gonna get to these guys are hand in hand with, with Trump.
But just to, to point out the hypocrisy of these guys, these guys are like, uh, uh, Zeig, right? They just adapt to whoever's in office. Remember that famous photo of, of Obama flanked by jobs and Zuckerberg?
Now you can, you can just insert Trump and you would have Tim Cook on one side and Zuckerberg on the other, and Sam Altman and Ellison and all the rest of this crew. All of 'em. So I, I gotta tell you the truth I expected of Larry Ellison and Benioff is his evil disciple like Lucifer.
And, uh, you know, uh, I, Tim Cook hurt me, uh, because I thought Tim Cook had, that's Like a dagger. Yeah. Yeah.
I think, you know what? I thought Tim was better than that. I think there's, I think he, I think, uh, he's near the end and I think he's gonna be retiring fairly soon.
He's gonna turn 65 in a few days. And I think he's probably tired of it. But yeah, you're right.
It pained me to see him sell outs, Bend the knee like That. I, I thought he would hold outs, You know, so, So there is, there is a conversation happening around dining room tables today, and it goes something like this, little Johnny or Little Jane just got back from college and can't find a job, especially in computer science or any of these other places. And they're starting to ask questions about, well, what are these tech bros up to here?
Because it doesn't look good for, you know, their aspirations for that American dream that Alan was talking about. And, you know, their mindsets are starting to change, and you're gonna see some interesting things in the next couple of years. I hope so.
I think so. I, I really, really hope so. I, I, I, you know, it is, uh, it, it it's just, it, It's, you know, you know, if there is a, if there is a change, and I'm saying this in terms of the government, watch these guys pivot as hard as possible and pretend like this never happens.
Yeah. But the damage, they, they will try, they'll try to reinvent themselves like they always do. But you know what?
The public's not as stupid as they think we are. Well, not all of the public and, you know, not all of it. Yeah, some are, but it's just the damage is done too.
So how do you get off the track? You know, even with regime change. And, and also don't underestimate that large swaths of this world who are not in the tech world already resented the way the tech world operates, right?
It was taking good jobs. It was, you know, replacing taking away jobs. And, you know, a lot of them would say they had it coming, they have it coming, right?
Because, you know, there's, there's so much, you know, you, you talk, so I live here in south Florida. It's not a poor area where I live, but you know, it, it's, it's very common to say, oh, where, how'd that guy buy that house? Oh, he's a tech millionaire.
He's one of those tech billionaires, right? And it's one of four houses he owns. And, you know, and they say it not with admiration, but with resentment.
And, and there will, and you know what, Mike, you brought up the mayoral race in New York. I think that's a perfect example of it. People are saying, enough, we, what, what about us?
What about us? Right? We're not a tech bro.
You know, what's interesting about that though too, is that was a sentiment, I think, among Maga until the tech bros started going Trump's way. Yeah. I think they really felt that way.
And, you know, now they're all in with the tech bros. But I wouldn't make that assumption. I think that there's a significant portion of the right that also is asking these questions.
Oh, No. Yeah. I think that, Yeah, there's a, there's a certain bi there's a, a bipartisan, um, agreement in, in Congress, especially about the power of, of big tech and about its morals and about its technology.
I mean, there, there, from the extreme right to the extreme left, there seems to be a general distrust. And that's a one of the few common grounds they share is, is the fact that Bing tech is just, can't be trusted, Can't live with 'em, can't live without 'em. Hey, let's take a break here.
We're gonna come back and, and talk about a another war. This one about browsers. You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black clerk, digital executive protection, defending the new attack surface your personal life. All right, folks, we're back and we've talked about this forthcoming browser war, and now it's actually here, at least in my opinion, we see OpenAI is now pulled out their browser and they're going after Google. And of course there's been other choices out there, but at least in, in my opinion, OpenAI is the most credible player in this space.
And we'll see how this plays out. But Garima, you've been following this. What's your take?
I'm more conscious than thrilled. And I'll tell you why. com as well, uh, regarding this topic, AI browser race when Comet was about to launch, right?
And there was a lot of buzz around, you know, uh, how the, uh, the Comet browser would, uh, integrate AI and AI agents. Now we see the similar challenge, uh, coming up from OpenAI. 5 billion users of Google through their, uh, browser, which they're, they call Atlas.
And they are trying to leverage, uh, 800 million users, which they have on charge GPT, right? But you know, the caution or the concern I have, I will point out a few features from the Atlas browser, and then probably we can discuss how do you feel about this whole challenge? So the first, uh, feature I was, uh, uh, investigating this, that they are putting browser memories and data retention, which means that, uh, browser memory would be storing context for personalized in interactions, and of, of course, they will have controls for Optane Optout and all that, right?
Another aspect is AI training of browser data. Now, how this training would happen, of course, uh, you need user behavior data. You need, uh, data for interactions and how this is playing around.
And of course, the controls will be there. But think about this. The user con consent and control has complexity to it, right?
So what features you will be opting out, which features you want to log out, uh, and you what kind of mode you have. And I think there is another sensitivity to this that, uh, these all whole, uh, you know, emerging tech integration into browsers is susceptible to, uh, security risks, right? So those will be a lot of vulnerabilities introduced through prompt injections.
Another area which I wanted to also highlight was, um, AI literacy and comfort gap. And this is again, uh, what we have discussed in the first, uh, part that, you know, this technology is, is hitting a larger masses, a user base, which is probably not that tech savvy, right? So we'll have to ensure that people understand the implications of opting and opting out, right?
How, uh, AI centric design of Atlas would work. And think about these things like if there is reduced traffic on authentic, uh, websites, for example, because there is algorithm, make intervention of agents, uh, putting you to different kind of websites and maybe chosen websites or personalized content or context, right? How the biases would be built.
And, you know, not everybody would be represented in that bias, right? So things like that is a lot of, uh, concerns I have on the table. And of course, now, Mike, you would ask me that, you know, where these discussions are taking place, how can I be part of this discussion and how I can build a governance around it?
But I, I have to say this as a technologist, that, uh, we need to lead this, right? We need to lead this independent oversight. And, um, like media houses, like yours, uh, tech strong TV plays an important vital role in this oversight.
Because if we do not bring regular external point of view or multi-stakeholder evaluation or systematic oversight of these AI applications, I think we will remain blindfolded. And that is what would be needed. And of course, I don't have a straightforward answer.
Maybe, you know, you guys have more insights into how the Silicon Valley is thinking about it or how, you know, the more developed countries would take, uh, the space and say, okay, we, uh, own the space and we build an audit mechanism. We o uh, build an, um, uh, accountability mechanism into all this. So it is also subject to kind of seeing how all this plays around.
I am quite skeptical about this whole thing be just because of the fact that it is hitting the masses. You know, we have seen this whole technology revolution, uh, in let's say critical infrastructure area or defense area, or mining area, which we probably are not concerned that much about, right? Because it doesn't hit like 8 billion people, but browsers, everybody's using it.
And one more thing I want to kind of highlight, that if you work for the government and you start using these browsers, how your identity will be mapped and what kind of data is, is being pulled out of your, uh, browsers is also, uh, subject to kind of, you know, consideration. So let me just summarize that big tech is experimenting on millions of people without any regard to the implications thereof, Alan. Well, but, but you know what?
This, we've seen browser wars before, right? Internet Explorer, Netscape, Mozilla, uh, Google, uh, Chrome, chromium based, you know, seems to have one in the day. This one's a little different though, right?
I, and, and I'm gonna bring you back to when Google, uh, launched the Chromebooks, right? The promise of Chromebooks is you could go buy a device for $300, $250, and instead of running Mac Os or Windows, you really didn't care what os you ran, it ran, it all ran through the browser. The browser was the interface, the browser was the ux.
This is that battle on a whole new level. 'cause what we're talking about is not just the browser, we're talking about the new ux. How are you going to interact with your world, right?
The idea of running apps outside the browser on your device probably gonna go away. You could run the apps right on the browser and the way you, it, it may not be typing. You may talk to it, you may, you know, the whole in human computer interaction here is changing.
And it may not be a browser window in terms of what we normally think of as a browser window. It may just be a talking head that I talk to and it pops stuff on the screen for me or whatever, right? This is, I mean, is it a little, am I being a little farfetched?
Maybe, but not that far. Not that far. And so, you know, the, so the, the, the, the spoils of this war are huge, right?
To the winner goes the spoils. I think you're going to see, now Google has the incumbents chair, but it's the old way. So they're gonna want to do incremental, start building AI into my search results and, and this kind of thing.
I think open AI, perplexity, they're all gonna try something. But I think there's a tremendous opportunity here for something just totally revolutionary new that does away with the hu the the traditional human computer conduit of interaction and using AI more like spot check One difference, which, uh, you'll feel yourself, right? I mean, come was launched a few days back, right?
So I was also curious and inquisitive to try it out. I went into their like, uh, website multiple times, but I didn't download it. Why was that?
Because I didn't have the trust, Right? I could do this with Google. I do this with Chrome because they have built that trust.
And until, and unless I see registries of AI model, which they are using Explana, uh, explanation of, uh, you know, how these agents work, uh, some kind of explanatory reports which are out there, I wouldn't, because, you know, ignorance is bliss. I always say that, you know, people who don't know would try and use it, but people who actually understand that how the data, user interaction, user behavior is kind of recorded and used on in the leverage of these big tech companies, I think we'll be very, very conscious about it. So let me throw some metrics.
I think, well, there's two things. First of all, I'm gonna let Alan go first and see how it goes. Well, let Me go ahead.
90% of developers use ai. 40% don't trust it, but 90% still use it. But go ahead, Mike, That's for hobby court, not for production.
And the second thing about this is, you know, I'm open to using a different browser and I've been using Google Chrome forever, but the current Google Chrome experience is crap. And so I'm like willing to think about something else here. You know, what was that?
Like, somebody has an article or a book out talking about how, you know, the big tech is running down the, I believe the technical term they use is and acidification of the web. And, and that's what we're getting these days. So if the browser kind of gives me a better experience, you know, I'm hoping it does.
I, but I agree with Karima. I, I know for certain they did not think through the security issues. So I'll just wait to see what Alan experiences and, you know, in six months I'll come back.
I can't wait to use it and I'll let you know, right? Um, but that's, It's be interesting to see. They, they, they Will we'll be booking our airline tickets as Ellen is booking from, uh, this website, which is using for years, right?
So we'll know about it. We, it's, this is how you know your data. It's gonna be ing they around.
Go ahead, John. It's Gonna be interesting. What?
Oh, yeah, sorry. There's gonna be interesting what they do with, with Atlas. I mean, they refer to it as an AI browser agent.
And I wonder how Johnny I, and that whole IO acquisition plays into this. Like maybe that's a mechanism or delivery of some sort. But I also think that open ai, it's an uphill battle.
I mean, as, as bad as, or as mediocre as the Google experiences, they've embedded the AI agents across Gmail, docs search Chrome, Android. So it's quite a, it's quite a task, but you're, it's, it's gonna be interesting. I also think, I wonder if Perplexity ends up becoming part of another company like Apple, for instance, and that shakes things up.
But I'm, I mean, I'm all for some al alternatives to Chrome. I also will point out one more alternative, which is in making is confidential ai. Because some of us who are more aware of the technology revolution, I think we will pivot into some kind of a confidential models for, uh, in using these kind of industrialized applications and for the larger masses who don't care how this user interaction and how the data is being captured.
Maybe the, this is the answer to that, that question, but for me, I think I'm leaning towards some kind of a movement for confidential ai. Kareem is reading my mind 'cause that will be a topic next week. So we'll come back to that.
Alright, on that note then, let's take a break here and come over, come back to our C block today, which is, uh, regarding face facial recognition, that, that's been a controversial one. You're watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back.
And as Alan alluded to, facial recognition technology is going to court. There's a lawsuit that's aimed at the Dolans who own, um, Madison Square Garden and the New York Knicks and the New York Grangers. And I think they have a piece of the liberty.
And, um, the at issue here is apparently, at least according to the suit, um, the Dolans have what amounts to an enemies list that they don't wanna have in the garden. And they are using facial recognition to enforce that. And the suit says that's part of a larger cultural issue that is at the heart of that particular lawsuit.
But Terry, you wrote this story up on Security Boulevard. Is this gonna become the test case for facial recognition and how we use it and don't use it? It maybe, I mean, New York lawmakers had sort of raised the alarm last year about this.
They had heard tell that the facial recognition, uh, technology wasn't being used as advertised by Madison Square Garden, which, you know, ostensibly was to protect the garden. And all the fans who come in from some sort of attack, you know, terrorist attack or some untoward activity, um, I don't think much happened between the time that the lawmakers sent their letter out last year and the time that this suit really started gaining some, some traction. But, but maybe it should be the test case for, um, how it's used.
Uh, of course, it's just also something is really rotten at Madison Square Garden in their security, you know, department overall. And, and maybe just in the, the business of the garden, because the guy that brought this suit really was bringing a suit, uh, you know, first and foremost about disability discrimination because, um, basically the head of security there and, and, and other people were using private information about his health condition, he's diabetic, um, you know, to bully him and, uh, and, and sort of publicize it in the workplace. And, you know, I, they called him old and weak.
He's 49, by the way. Um, and, and diabetics. So I mean, 40 nines hardly old, um, these days.
But, um, in filing that suit, all of this other stuff came out about their security practices and, uh, the mishandling of, of, uh, data. So yes, you're right. Madison Square Garden has an enemy's list.
Um, it's pretty interesting because that could include, you know, guests, lawyers, customers, sports fans who might have former players, Former players, Charles Oakley, former player, Charles Oakley. Yeah. And, And soon to be Terry Robinsons And soon to be Terry Robinson who might have expressed frustration about the Knicks losses.
Come on Now, you know, who doesn't follow the Knicks and express some, you know, frustration on that part. I mean, they've done pretty good the last couple of seasons, but it's, it, it, you know, the list was fairly broad of what they looked at. So you wear a t-shirt, you know, you, they recognize your face.
Um, there was one woman who was targeted who is transgender, and she was, you know, targeted for no other reason than her gender identification. It wasn't as if she had done something. James Dolan was being accused of sexual harassment by, you know, another woman.
And this guy that filed the suit had been asked, uh, by the head of security to record, you know, phone conversations that could be used to, uh, dissuade and intimidate her going forward. And that's where he drew the line. He said, Nope, not going to, you know, not gonna do it.
Um, the guy who filed the suit, by the way, um, you know, was the, he's not like some low level employee. He was the VP of shared security services. So he was up the food chain.
Well, Let, let me say this. First of all, if the Dolans would put as much energy into the building winning franchises as they do into this crap, maybe we wouldn't have be sitting here that the last time the Knicks won a championship was my Bar Mitzvah in 1973. Okay?
And the Rangers when, you know, mark messier before he went out the door. But that being said, are the Dolans any different than the president telling the Department of Justice go indict this one, he's an on my enemies list. We live in a country where having an enemies list is, is okay.
It's okay. Yeah. It's a okay.
Yeah. Right. When Nixon did it, they wanted, they ran them outta town.
Nope. Today it's, it's, We had morals, then we had principles. Now it's, but they're my enemies and I'm, and this is my toy, and I'm going to use my toy the way I want's, whether it's the Department of Justice or Madison Square Garden Security Team.
Right. Well, so it's no longer that, that kind of thing. An n enemy's list is no longer a deal breaker for politicians, for, you know, business people at the top of the heap.
It's, you know, it used to be, it Would be, again, welcome to the oligarchy. Exactly. We, and I'm sure there are other owners, other owners are watching and wondering, maybe we should do the same thing.
I, I wouldn't discount, I wouldn't just count Joe Laker from doing it for the Warriors. I, I, you know, it's, I I think the Warriors put a good, a good product on board. Well, they do.
I know I do. But I just think They go to a ws An enemy or perceived, you know, the enemy's list thing has become so prevalent and so pervasive that I could see it used in limited cases. Not, not to the extent maybe the Knicks, but to a shorter, shorter extent.
Well, I, and, and then it's not just public sports. It's it's everywhere. It's, it's everywhere.
It's the whole bit. It's the workplace, you know? Well, which is also part of this.
But Yeah. Um, yeah, A shame That that's who we'd become or that's the direction we're heading in. We're, and we're comfortable with it.
Not us, we're not comfortable with it, but I'd still like to see the next win. I, I, I, I confess I do have a list. It's called the Text Strong Gang Friends List.
And it's very nice and it's opening, welcoming, and everybody should come. Yeah. We like that kind of list.
That's a good list to have. All right. Very.
It was like a badge of honor to be on Nixon's enemy list, wasn't it? Back in the day. Yeah, it was then.
Right. So I'm may consider that's to bed of honor to be on other enemies list. Yeah.
Charles Oakley's not losing, no sleep over it. Awoke. All right.
I think we're gonna call a, a wrap on this version of Text and Gag. It was, it was a little controversial and heated today, folks. Um, as usual, we've got Text Drunk TV coming up.
Watch that. If you're not watching this on the live stream, I hope you enjoyed it on YouTube or the OTT channel or however you got it. We do this every day from nine 30 till about 10 15.
So Eastern Time that is in the us so check us out there, gang members. Thank you. We'll be back tomorrow with our Friday text on Gang.
But for now, enjoy text on tv. Hey everyone, welcome back here to Tech Shark tv. You know, I, when I first saw the time we were recording this interview, I felt bad for my, my, uh, guest here today.
He's a friend of mine. He's been on Techstrong TV over the years, a couple of, more than a couple of times, but he's based kind of on the other side of the world a bit. And it's usually, you know, to have him on in the middle of the day means it's the middle of the night, but he's in California today, so it, it all works out.
Let me introduce you to Peter d Dan Hu, uh, Peter, of course is the CEO Chairman and co-founder for Secure Code Warrior. Peter, welcome back to Techstrong tv. It's great to have you.
Oh, thanks so much for having me. I'm very grateful to be here in, uh, nice sunny California. Uh, a good 40 hour flat from Australia, but I'm happy to be here.
It it, did you say 40 hours? 14, sorry. 14 0, 14, yeah, that's about right.
'cause we're about five hours from five to six hours from California here, and it's about 19, 20 hours though. You know, there aren't that many nonstops to nonstop. You gotta go up to like New York, and there is a Qantas, I think, that goes into Sydney nonstop, and that's about a 20, 21 hour flight or something like that.
Um, I've taken it, it's a long flight. That's a long flight, but it is nonstop. Anyway, Peter, I'm glad that we don't have you up in the middle of the night.
I, I appreciate you coming on. For people who maybe this is their first time seeing you and maybe even hearing about Secure, secure Code Warrior, let's start about kind of your journey. What led you, what path did you take to co-found and, you know, lead Secure Code Warrior?
Yeah, so long story, like I started in cybersecurity in the early two thousands. Like I was mostly on the offensive side of cybersecurity. I co-founded the Hacker Conference, Bru Con, uh, over in Europe, um, and I think after and teacher for the Sand Institute.
And my goal was always to kind of teach people how to break into systems. Now, having done that for about 15 years, in 2015, I realized that I need to help the people that are actually building the software, because very often it allowed me to, allowed me on my team to break in, to steal data, to do what all these malicious backers are doing. And we were always being able to kind of draw it back down to a problem in the software.
Like somebody or something kind of wrote a piece of software and they were using the wrong library. They were losing load function calls, and as a result, somebody was able to exploit this weakness and gain access and all prior access to a system. And that's why I said, okay, I need to stop teaching people how to hack and I need to start helping people how to build software in, uh, in a secure way.
And, and that's how Secure Code Warrior was founded in 2015. And our whole mission, uh, is and still is today, is to help software developers to build code in the most secure way as possible. Excellent.
You know, in many ways I kind of mimicked my own journey a little bit, right? I, uh, got into security in the late nine, late 1990s, late nineties. I remember Sand's Institute, my good friend Steven Northcut, I don't know if you were there when Steven was there.
I'm still friends with Steven on Facebook. It's communicated with him all the time. And those were the heydays.
I mean, sands was where you went to learn security. We didn't have cybersecurity majors coming outta college and stuff like that. You went to Sands and it wasn't cheap, but it was great courses and they had great conferences around the courses.
I had co-founded still Secure back then. And, you know, we were a big, big supporter. We used to buy those big blow up like yoga balls and put 'em in all the Sands classrooms instead of chairs.
So people to, to sit always tell people we were the company with the big balls. Um, and it worked. We, we had a good time there.
Then, you know, the reason I really got into DevOps was the same reason you shifted left, which is you realize if we could get the security problems in the code when they're coding it before it's deployed, it's a hell of a lot easier and cheaper to fix there than, you know, trying to kind of stick your finger in the d**e of, of, you know, uh, well once it's already out there. So I, I appreciate the, the, the journey. You talked a little bit about kind of the mission of Secure Code Warrior and how it came about, but of course, that was like 2015.
It's grown since then, right? The world has changed a little since then. We're gonna talk about AI because how could you not talk about ai?
Of course, everyone has an AI strategy, but talk a little bit, Peter, how the, how the market has changed and how the mission of Secure Code Warrior maybe has expanded since 2015, right? What's going on? Yeah, so there's probably like two big things that I've seen happening over the world with my customers.
And that is, first of all, that everybody is writing code these days. Like a software development is not anymore like the gigs that our, some are sitting in certain departments, but every bar, everybody has the ability to build an application. And I think with ai, that's even going to accelerate even faster.
So the definition of who is a software developer is kind of a changing from people that are full-time writing code. But nowadays it's also, uh, people that are, uh, analysts, financial analysts in companies, they can write code data analysts or can write code like anyone has the ability to start using Python and JavaScript to kind of build, build applications. I think what is going to happen is with AI and the, the ability of AI to generate applications, think about the vibe coding, like even more people are going to be able to build and deploy applications in seconds.
Like, I'm not sure if you saw the announcement of Open AI yesterday. Um, they release something, uh, the, uh, agent SAK, where I think in minutes you can deploy an application into production. And so my opinion will have more people building applications than ever before.
I thought you were gonna say the, the announcement of them maybe taking up to a 10% stake in a MD with warrants and, and buying all these chips and the week before, the a hundred billion dollar deal with, with Nvidia and stuff like that. Open AI is certainly, you know, in, in the news all over, but you bring up something that's very important. At the end of the day, we talk about hardware, and hardware is cool and sexy.
Again, it wasn't sexy for a long time, but the real test for success will be, are people using the software, right? NVIDIA's secret Sauce is Cuda and all that whole software ecosystem they've built around using GPUs. Open AI is on a similar quest of getting the developers, the AI developers, the AI engineers to use their software.
But of course, Peter, as we've seen, security isn't always top of mind with these things, right? A lot of times it's it's the end of the train rather than the front. Yeah.
And I think like if you, if you look at the, the, the different models that are out there today, um, they, they have evolved a lot in their abilities to build code. Like if you would think at, um, chat TPT two years ago, even 12 months ago, they weren't like the level of coding they could provide were really junior level coding like an intern. They could code like an intern that were now 12 months later and the ability to build code is much, much better and much, much higher now.
And I would say they probably match the level of a senior or a principal developer, uh, that you can build COVID. I think, however, from a security perspective, we are still, we're still kind of behind where I think we're still at that junior intern level where the code that is being generated by these different models often still has mistakes in it that shouldn't be there. And it's not, it's kind of normal because they've been trained on publicly available data, and of course there's a lot of bad sample and bad coding patterns available on the, on the internet.
Now, I do think that is going to change over time. It's gonna take us maybe another 12 or 24 months, maybe 36 months to get the, the security of those models or their ability to generate secure code to get that up to scratch. But I think at the moment we're still kind of faced with, there's different models that have different level of security competencies in coding in Java or COBOL or any of those coding languages.
Agreed. I know, I have to agree with you. Um, now there's another school of thought, Peter, that says, you, you need AI to fight AI kind of thing, right?
So, you know, the bad guys are using ai, uh, in, in every way imaginable to make their malware better, to find more vulnerabilities, to improve their phishing attempts have ransomware, everything, what Secure Code Warrior doing. So our belief is that if you take a developer that knows about the dangers of working with AI that knows about secure coding and secure coding patterns, and you combine that human with a great LLM, like an LLM that is good in, uh, secure code generation in Java or in C Sharp or in c plus plus or whatever you use, if you have that combination in our organization, you will get the productivity gains that everybody is hoping for, which means much more code, much more faster and more secure. We also think that the opposite is true, right?
Take a developer that is nowhere aware of the danger that, uh, or the, the pitfall of an LLM and that is maybe not aware about some of the insecure coding patterns and secure coding patterns, and you combine that developer with an LLM that is maybe not as strong in secure coding in a certain coding language, I think we will create the complete opposite effect of what we want. We'll have 10 times the amount of code with 10 times the amount of technical debt and misery in it. And I think we, we want to be able to change that.
We wanna make sure that everybody kind of falls into that first category where you have a great view that knows the ages of ai ai and you combine that with an LLM that knows about secure code generation in different coding languages because that's the productivity gain I think that everybody is looking for. Yeah, I, I agree with you. I agree with you, Peter.
I, I, you know, I, I did text Strong Gang today, had a few more conversations today, this whole week, and I think, you know, we were both around, as you said, the early two thousands. com bubble as you were as well. Are we in an AI bubble, Peter, are, you know, are we out in front of our skis a little bit in, in terms of what Beat Pipe is and the amount of money being tossed in here, right?
Are we thinking enough about security? Is the functionality there, right? I I saw a, a Twitter post or ex post whatever the other day.
Um, if you look at the amount of money, it just, in the US being invested in ai, it's roughly the size of Singapore's economy, but if you look at the amount of revenue being generated, it's roughly the size of Somalia's economy, but there's a little disparity here. Well, I think you've answered the question yourself, right? I think I, I, I think there is opportunity, right?
There's absolute opportunity and I think everybody is trying to kind of get into, get in it. Does that mean that things are going to explode and blow up and maybe lots of companies will go down because of ai, most likely, but like all of these investors are making bets, and I'm sure that some of them will work out and some of them won't. Um, so yes, you could, you could, like, what I see is opportunity.
There's an absolute big opportunity for AI to disrupt existing technologies, disrupt the way on how we work today. Um, and yeah, this may be a little bit of over investment, but I'm sure that'll, that'll correct themselves over time Is people are always willing to so up extra running, right? That, that's for sure.
Um, Peter, beyond the, the trust agent and ai, what else is in store with Secure Code Warrior? For us, it's really important with EW Trust Agent AI to kind of stay on that pathway of how can we help the future developer, right? And the future developer is one that is either using AI as a, uh, as a pair programmer, so somebody that kind of sits in the ID with them and kind of helps them providing code snippet, providing guidance, providing advice on helper, build things up to the developer that is wide coding, which is the one that just extend the instruction to the LLM and it builds an application of itself.
And we to stay very close to that developer and making sure that, um, we release features and tools that will help them to enable safe adoption of AI within our organization. What was really surprising to me is that if you ask the question to any size on an organization, how much of your code today is being assisted or written by an LLM, very often they don't know the answer. Um, they, they, they might have a rough idea, but they can't really show data or really, really tell me, well, 20% of our code is written being written by chat pt, and 10% is being written by deep seek.
That visibility is not there. And I think with SEW Trust HI, we're hoping to provide the CSO with that visibility so they can actually see, um, which applications are being modified by which, which type of LLM and and, and who is the developer using those LN. So it's basically the link between developers, ai, and the real software applications, and that you can kind of see that link and then also control and governance some of those, uh, aspects of it.
Fair enough. Peter, we didn't mention what's the website for Secure Code Warrior? com.
I, it's too long. We need to shorten it to SEW Doo, but we'll, we'll figure that out. com.
com. Yeah. Um, and I assume people can get all the information on the SEW Trust agent there?
Yes, we have our, our, our product demos, our videos, um, it's, it's all on the website. So if, uh, yeah, it's definitely there. How long are you in the states for?
Um, I'm only here for about three days, but I am back in about two weeks. Like, one of the downsides of building a company out of Australia is that you have to be in the place where your customers are, which is the us. And so I am very offering, doing the lag between Sydney, LA, Sydney, San Francisco, Sydney, Dallas.
It's, uh, unfortunate every, every month, month, and an app or so, You know what? But you do get to live in near Sydney. I love it there.
One of my favorite places in the world. Peter, thanks for coming up here on Techstrong TV and, and giving us the latest scoop on what's happening with Secure Code Worry, the SEW Trust agent, the state of the AI and security market continued success, and we'll see you soon, I hope. Awesome.
Thank you very much, Alan. Thank you. We're gonna take a break here on Text Drunk tv.
We'll be back in just a moment. Hey, everyone, welcome back here to Tech Shark tv. You know, uh, we were talking in the Green Room.
My next guess is from Space Lift, and I usually see space lift at every single cube con. We go to my friend Dmitri Vlado, the CMO, I know Dmitri for several companies that he's been with, and we always say, oh, we've gotta cover Space Lift, we gotta cover Space lift. And I never get a chance to talk to anyone from Space Lift.
Well, now I finally got a chance. I want to introduce you to, and I'm gonna do my best to get this name right, Marson Walinski Hinky, co-founder, chief r and d Officer Space Lift. Martin, say it Marson, say it right for me.
You know, it's my, my tongue just doesn't go that way, but I try Mar a pleasure to have you on here. As I mentioned, we've been wanting to do more with Space Lift for a long time. Exciting company, exciting story.
But before we get into Space Lift, let's hear your exciting story, right? You're a co-founder here. What, what, what was your passion?
What, what drove you to co-found Space Lift? I will admit that I'm a completely accidental co-founder. I'm a a software engineer by heart and a DevOps person.
I spent seven years at Google being an SRE mostly, and it was like a back end of the backend. It was tape storage called storage. So like, imagine it's, you never get talked to unless someone is in real trouble and the only place they can retrieve the data from is your tape.
It was probably in the somewhere. It's, it's a very, very kind of like not in the spotlight, uh, sort of thing. I did, uh, spend some time in Facebook being building clusters that was more, uh, customer facing, but I'll say as an engineer myself, I was then, um, consulting for our tech companies mainly in Europe, around, uh, clouds native, um, infrastructure, moving to cloud, adopting cloud, scaling cloud.
And I essentially, you know, I love Terraform, I love HashiCorp Technologies, I love Terraform. But one thing that was missing is the, the multiplayer mode for Terraform. It felt like it's an amazing product when you're just using it on your laptop.
If you're using it with a, with with a friend that you can col collaborate on Slack with, then it's probably okay-ish. The moment you scale to a team and then to a company that falls apart entirely, it's essentially single product. And what we were building with Space Lift is a multiplayer mode for Terraform and other technologies like that.
Absolutely. And, and that was one of the, one of the knock, you know, and, and I'm not knocking, that's a bad word to use. I'm not knocking Terraform, Terraform was an, is an amazing tool, but there were things that there were functionality that it needed and, and, but, you know, that's a tremendous opportunity, right?
In, in this case, space Lifts opportunity for those who are not familiar with how this story progresses, uh, terraforms open source. So you wanna build additional functionality, you could build additional functionality and under the open source license saying you, you can contribute that back to the, to the project and, and, and everyone could use it, right? Um, then of course the licensing changed a little bit there, and the, the industry, the community kind of, uh, push back on the licensing changes, you know, it wasn't truly true open source anymore, and the whole open tofu, right fork came out here and, and that again, gave everyone opportunity to contribute and, and build a, build a better mouse trap, if you will.
Martha, and I know Space Lift was one of the key drivers behind the Open Tofu Fork, and you know, of course, open Tofu is now part of, uh, CNCF right? Fast growing. And, you know, I wrote an article a couple weeks back, look, there's probably, there's a place in the market still for Terraform, and there's a space in the market for Open Tofu, and, you know, it's a big market out there.
Yes, indeed. I guess my question to you then is though, open Tofu Terraform, what makes Space Lift special? Where's the special sauce in space Lift beyond Teams?
Sure. Um, so both Open Tofu and Terraform are essentially CI they're a single player. They're meant to be, right?
Run on on your computer, maybe in a ci, but they don't necessarily provide the sort of guardrails. They don't provide a, uh, the coordination collaboration layer. The beauty of Space Lift is that it provides a uniform layer on top of many technologies.
So we do support Terraform, we do support Open Tofu, we support Lummi Cloud formation, Kubernetes, you name it. And there is a, there is an, a uniform layer of, for example, policy as code. And that policy as code layer allows you to define your rules and what can go through, what can't go through, under what circumstances.
And not only that, but the policy as code layer also involves coordination. So you can declaratively specify certain processes like how code goes from your, your source control into a particular deployment, right? Where, which way it goes, right?
So this is something that is truly shining at scale, and that's the thing, like Space Lift is all about, scale is all about control. It's, it's all about visibility and auditability, Terraform is a really nice tool, and so is is Open Tofu. Um, but they're essentially cli and they're not designed to work on a scale where people are using them.
You could build something on top of a generic CICD. So, you know, we onboard a lot of customers coming from GitHub actions. We onboard a lot of customers from Jenkins.
And to be fair with you, what we are doing at Space Lift is not rocket science, right? Can you build something similar for your company? You can, is it normally your job?
No. You're probably, you know, you're probably having a lot of different things to, to work on, and you're essentially buying something that is, is good, is proven, is supported, gives you good user experience, and gives you good guarantees that'll stay up. It'll be up, it will, um, be updated, et cetera.
There is no magic in what we do at Space Lift. We're just doing a multiplayer mode very, very, very well. I love it.
I think you're being humble though too. So space lift is, is, it's a platform, right? But, um, you know, and, and so once you have a platform that allows you to interact with projects and products and, you know, one off site like this kind of thing, but really, you guys talk a lot about the, the dual approach, if you will.
Um, talk to us about what we mean by that. Uh, is, is that what we launched today? Or you want to talk about intent, right?
Or Yeah, well, I, I, I'd like to get into that, yes. And the whole agent AI piece of all that, but the twin path is, is kind of it. Yeah.
So I think there's, the, the, um, IAC story is, is an interesting one because there isn't really a middle ground in provisioning infrastructure when you think about this. There are two, like, technically it should be a spectrum, but there are two extremes, and we don't have a spectrum. The, the, the extremes are I click on things on a console and it's kind of like, it's fast, but it's absolutely non repeatable.
It's not traceable. You, you have no idea what's happening. Uh, even my colleague will not know I get a database in 30 seconds, but, you know, it's, if someone forgets about it, there it is, right?
And the, the opposite end of the spectrum is full ceremony. Now imagine you're a new engineer on a team, and you're asked to provision an RDS database on AWS. So now first thing you need to do is maybe you don't know Terraform.
You need to learn Terraform, you need to e relearn HCL, but you're not even halfway there. You need to then go to the provider and learn the provider itself, right? Let's say you learn the provider, you know, the APIs of the provider, and now in, in order to get an RDS database up, you're gonna have like, uh, 10 different resources maybe, and then you need to learn about those 10 different resources.
And then you're not done. You need to write the HCL code. And then for Terraform, we need to set up like a storage backend, like, uh, you know, some S3 bucket to, to store that some CICD pipeline.
You'll plan, you'll review, you'll look at the pr, you'll apply, you'll probably do it a few times because maybe the first time it doesn't work because you're, you're pretty new. Honestly, for someone like a, a, a senior engineer that's a couple of hours of work for a junior engineer or for someone who's maybe senior, but in some other area, like a senior data scientist, that's a few day project just to get that audience database done properly, right? And as I said, there's a spectrum of like, we, we can do it fast and stupid or we can go full ceremony.
And my feeling is that there shouldn't be like just two extremes. There should be options on the spectrum that allow you to do things that are in, in a way that are not stupid, but they don't necessarily involve all that much, all that, that many steps and all that much knowledge that you have to master to even be able to do very simple things properly. And this is where we're, uh, positioning our new product intent.
This is essentially a way of circumventing or short circuiting the whole proper workflow. So if we, if, if intent my will to get an RDS databases on the left and the RDS database existing is on the right, and there's the whole set of steps that I need to, to do to get there, then we're, and you know, it, it kind of involves translating your intent into ultimately A-W-S-A-P-I calls so that you provision your database, we're short circuiting that we're taking your intent, and we're translating into in, into an a, uh, A-W-S-A-P-I call. And how we do it is essentially we expose an MCP server that proxies open tofu providers, that there is, um, very rich ecosystem that we are co-founders of, of, of all the providers.
And now we can short circuit your intent through an LLM through an MCP server directly to an API call. And it feels like magic. It's extremely fast, and the beauty of it is that it generates the exact same state as Terraform would, minus all of the other steps.
Hmm. Fantastic. Hey, Morrison, I, I gotta do a little housekeeping here.
We didn't get into how do people engage with Space Lift? I'm not entirely Sure what, that's the website. Okay.
So best through the website, through GitHub. What, what's the best way to engage with Space Lift? io.
Um, if you're interested in any technical details, you can read our documentation and there's always an option to sign up for a product, uh, free trial. And if you, uh, prefer more handholding, there's always an option to request a demo on the website, and that is probably the best way to engage with us as a company. Excellent.
And a, as I said before, you were Space Lift was one of the people, but you know, one of the companies, you know, supporting the, the fork with Open Tofu, talk a little bit about open source. You know, you, you, you guys support a lot of open source tools, open Tofu, uh, Lummi Ansible, right? These, these are all tools that, you know, have open source components.
I talk about spa, you know, and, and that, and it, listening to your background, I'm not surprised, right? Coming Google and Meta and stuff, you know, big open source supporters. How's, you know, the relationship between the open source community and Space Lift still?
Yeah, so I am a strong believer in Open Source as a good business. I, it's not just like a, um, an ethical choice. Of course it is an ethical choice, but I do believe that having open standards is a good way of running a business because you, let's taking Terraform into account for open tofu, like sometimes people would say, oh, you're supporting Open Tofu, but you are building on, like, you're building a competitor to Open Tofu, or Open Tofu is a competitor to you.
It, it isn't like you can't compare a single player tool to an enterprise platform. They, they're not competing with one another. And in fact, the, the ability of people to use Open Tofu for free turns it into a standard that we benefit from, because then this being a standard, we can support a standard, we can meet community where they are, and by our sponsorship of Open Tofu, we can affect, you know, the, we can touch a lot of that, that, that community.
We get to events. Uh, we are a well-known brand. It gives us the visibility, it gives us, uh, uh, uh, credentials to be able to talk to open Tofu users.
So I, I personally believe that it's a great way of selling products. I know it is difficult, but I don't think any other option is, is much easier. 'cause the alternative would be to try to design your own protocol or try to design your own closed ecosystem.
And then honestly, like, people are not idiots. People understand that they're, you're trying to log them in and most of the time they will be extremely cautious and wary of, of stepping into a completely closed ecosystem. The beauty of Space Lift being built on top of Terraform being built on top of PMI or Open Tofu is that you can get in very fast and you can get out very fast.
And that's a good thing, right? Because it, it makes your expectations very clear. It allows you to be kind of courageous with, with adopting Space Lift, it's not a decision for life.
So it's as easier to make, it's not a massive undertaking to migrate your stuff to Space Lift because you are already using the same standards that we're building on top of. So you're using Terraform, then a migration to, to Space Lift is an, is a left and shift. And that's exactly what we did with Intent.
Like we are using the community, uh, project, we're using Open tof, we were sponsoring Open Tofu, we are using pmi, so we want to give back and with intent, there are two reasons why we want to do this. First, as I said, standards, standards are good for everyone. Otherwise, everyone builds their own little closed Private Card and private, private thing.
And, and everyone is unhappy. And standards allow everyone to grow together. And competition is good.
It's actually like, it's lifting all of us, right? Even to a point, like, we can copy from our co competitors, they can copy from us. It's good for Everyone, right?
I agree with you. I, I think what it does, it establishes a floor that everyone could build off of. And what's nice is it, it's a common foundation, right?
And then it, it's up to the individual companies to see where they go. It's kind of like evolution, right? Darwin and Evolution, and, you know, we all start from here, but this one focuses on this, this one focuses on that.
And, and that's what makes, you know, a field of a thousand flowers, right? All growing in the same field. And, and it's an important thing.
I wanna mention again, you guys will be in Atlanta at CubeCon. Uh, I think it's November, I forget the date. November 14th or something like that week.
Um, look forward to seeing you there. Maron, thank you for making it on the Techstrong tv. This won't be the last time.
We'd love to continue hearing more about Space Lift in the weeks and months ahead. Thank you for having me, Alan. Pleasure.
We're gonna take a break here on Tech Drunk tv. io you said, right? Correct.
Space Lift io. Go check them out. We're gonna take a break.
We'll be back in a little bit here on Techstrong tv. Hello and welcome to the latest edition of the Techstrong AI Leadership Inside series. I'm your host, Mike Biard.
Today we're with Jake Burns, who's an executive in residence for AWS, and we're having a little chat about a subject that's near and dear to everybody's heart, where to run these AI workloads, the cloud on premise, somewhere in between. Jake, welcome to the show. Thank you, Mike.
Glad to be here. Yeah, I think one of the challenges that you see from folks out there is they're trying to figure out, uh, well, if I have data on premise, can I move it in the cloud? Or does, uh, the old school rule apply?
I should just bring the compute to where the data already is. Uh, I think that you should, um, you should bring the compute to the data where the data is, but your data being in the cloud gives you so many advantages to use these cloud-based, uh, AI systems. And the reality is that moving data to cloud has become a lot easier, um, recently.
So there's, uh, there's faster networking, there's other tools available that can help get your data to the cloud. Um, and you don't necessarily need to bring all of it, um, in order to take advantage of these tools. So, uh, just like everything else get started now, uh, the best time to do it was yesterday.
The best next best time is today. And the sooner you get started, the sooner all your data will be there. But, uh, definitely believe that having your data in a secure environment, which the cloud, uh, provides, um, is, gives you the advantage of being able to use inference in the cloud.
And I think that you have the best, latest and greatest, uh, inference with those best guardrails and the latest models in the cloud as well. So it's a natural fit. Mm-hmm.
And to your point about that, I feel like if I'm not involved today, it is gonna be hard to catch up because a lot of people will have, uh, a lot more experience than I do, and they'll be much more competitive. So there is a cost of falling behind, right? Oh, absolutely.
Uh, I would say the opportunity cost here of falling behind is, uh, greater than anything I've seen before. Hmm. So is there some way to think about where these workloads should go by some sort of pattern they exist or some sort of, uh, metrics that we're able to track or observe?
Or is this all gonna be trial and error because, well, it's all brand new? Uh, I think both. I think trial and error is good.
And I think, again, those who are experimenting today are the ones who are figuring it out the fastest and they'll be kind of writing the future. Um, you know, I've run, I've run, uh, AI models, um, locally and I've run them in the cloud. And, um, it's, it's very difficult, um, to, to have enough, um, to, to be able to invest enough in the hardware necessary to do, to do those local, um, implementations.
I do see perhaps some value in it, but I also think that, um, you know, we, we went through this with cloud where there was this kind of debate between is it more secure to run workloads on premises versus in the cloud? I think to some degree that debate's still going on, although I think in my mind it's settled and I think in most people's minds, um, the cloud, uh, when you don't know much about it can sound scary, but the more you learn about it, and this has been my experience working with customers, uh, you know, CISO will go from dead set against cloud to being our biggest advocate once they learn kind of, um, the way the cloud works and the way you have to think about it differently in order to implement security. But then the far greater capabilities you have with security and privacy, and I think that's true with AI as well, and it's a, a process.
We're still going through an education process, we're still going through. I also think it depends on how you do the math. If you do the cost of the cloud, but you're not including the cost of running your own data centers as savings, well, that's one issue.
And if you're thinking that your existing data centers are kind of a sunk cost that you're gonna leverage, well, you might be in for a rude awakening when you gotta go buy a bunch of new servers that have GPUs in it, right? Absolutely. Yeah.
And then also these GPUs, um, you know, there's the refresh cycle on-prem, you know, and maybe you got a three or five year cycle, the refresh cycle for these, a cutting edge GPUs is just, uh, far faster than that and speeding up. We don't know how fast that's going to get. So trying to keep up with that I think is gonna be, uh, a major challenge for those who try to do it not in the cloud.
If you leave it up to the cloud providers, then well, it's cloud provider's problem, and that's a, a good thing to outsource, uh, just always having access to the most powerful hardware and the most powerful models. And every data scientist I talk to seems to wanna always have access to the latest and greatest. It turns out we talk about this GPU shortage, but the reality is a little nuanced.
It seems like most of the data science teams just turn their nose up at the older GPUs. So there may be plenty of 'em, it's just they don't want to use them. That's true.
Everyone wants to use the greatest, uh, out there because everyone wants to have that competitive advantage. And, uh, those, the competitive advantage versus having something that's just one generation old, which might be three months old at this point. Um, it's, it could be, uh, uh, a huge difference in the type of results you get.
Mm-hmm. We hear people talking a lot about small language models, and some folks are saying, well, they're gonna use those in conjunction with inference, and that'll make maybe the whole cost equation more reasonable and you might actually get better results because, well, a small language model is trained on a narrow base of data. Is that a reasonable set of assumptions and is that something people should be thinking about?
I am, yes. I'm actually a proponent of small language models and I think they don't get enough attention. Um, but then I'd also say that, um, you, the cloud could be very advantageous, uh, for those because it allows you, uh, essentially when you're using a small language model, a lot of the power comes from being able to specialize it for your particular workload and your particular preferences.
And so you still need considerable resources to train those models. You're just basically, um, taking the, um, the, uh, the expense and the time and the resources required from the inference to the training, um, in my, in my opinion. So, um, you know, bedrock, Amazon Bedrock, for example, you know, does model distillation, which can allow you to create, uh, like smaller models based off of these most powerful models.
And you may wanna do that, um, that cycle very rapidly. Um, in fact, you should. So I still think there's a role for cloud for that.
Um, but of course they are, those models can run on-prem on lower hardware, so then it gives you that freedom as well. Right. Do I also need to factor in, you know, the laws of physics here?
Because I think sometimes the, uh, inference engine wants to be closer to the foundational model rather than, say, a wide network away, or four or five network hops away and that will matter to my performance in my application. Is that something to think through? Oh, yeah, absolutely.
Um, latency is a big issue. Um, you know, especially when you're talking about use cases that require real-time responses. Um, so like, you know, assistance or customer service agents, things like that.
Um, even sentiment analysis where you want like on calls, um, you know, we have contact center as a service, uh, Amazon Connect, which doesn't, again, it doesn't get enough, uh, a love in my opinion, but the customers that use it see, uh, a lot of value from some of the ai, uh, um, tools that are in there, like being able to tell, um, in real, real time, uh, what your customers are, what their pain points are, um, that's a very difficult thing to, uh, develop yourself. So to have an out of a box solution like that, um, is super, uh, super useful. Um, to, to your original question though, um, I think that, uh, that, uh, insight is one of the primary reasons why cloud migration is so uh, critical today.
Um, because, uh, assuming you want to take advantage of all of these capabilities in the cloud, then you want to have your data, uh, live very close to where you run the inference. So if you're gonna take advantage of something like Amazon Bedrock and, and have all of those things outta the box and have kind of the latest and greatest available to you at all times, um, you want it where your data lives, and then you also want your data to be secure, because it's my opinion that, um, in the, in the next, in the near future, one of the most important things is going to be securing your data because your data is going to give you the competitive advantage over others. You know, because the models are becoming commoditized to, to a degree.
Um, being able to run those models against your proprietary data is what's gonna give you the, the real value that you're looking for. Is this, to a certain degree, maybe a rehash of the debate over data gravity. And I'm asking that question because some folks will say, well, I'm putting all my data in the cloud and I'm gonna have a big data lake.
And other folks are saying, well, all my important data is running in my on-premise environment because that's where it's driving my mission critical application. So maybe before we have a conversation about workloads and infrastructure, do we need to have a conversation about, well, where is the data gonna be in the first place? I think so, and I think we should have the conversation at the same time.
Um, uh, another observation of mine, and this is kind of my, my passion at the moment and my mission at the moment is that migrations, um, can happen very rapidly. And I think that most migrations that I observe happen far too slowly, and there's a lot of reasons for that. And, um, it's something that I talk a lot about, um, and, and, and work, uh, most of my work is around that nowadays, but, uh, migrations could happen very rapidly.
Uh, when I was a customer way back in the day, uh, almost 10, 10 years ago now, uh, I did a rapid, uh, accelerated migration, uh, to AWS, uh, as a customer and was able to go all in in 17 months. And if I was to do it over today, uh, knowing what I know now and with the tools available today, I think we could do it in maybe three months. So migrations don't have to take a lot, a lot of time.
Uh, it can be very rapid. All right. There is an old school way of thinking about data migrations.
It starts with a phrase that says, nothing good happens when you move data. Have we gotten better at this? I mean, 'cause a lot of folks, you know, seeing people's careers get trashed over trying to move databases, nevermind entire warehouses.
Yeah. So it's interesting because there's so much nuance to this. Two things could be true at the same time.
So, uh, it's, it, what you say is absolutely true, and I'm seeing this, um, uh, far more than, than I'd like to, uh, where people are struggling to migrate their data, but it's actually, um, uh, quite easy. I think it's a skills issue, um, uh, education issue and a best practice kind of issue. So, like, for example, uh, when I was migrating, there weren't the, uh, you know, the A AWS snowball, uh, family of services, uh, which essentially is just like a huge dis array that you could put in your data center, copy all your data, and have it shipped to Amazon and, uh, AWS data center, and then have it, uh, ingested into your, into your environment.
That is a super fast way to get your data into the cloud that I think is very much underutilized. Hmm. So as you kinda look at all of this, what's your best advice to folks?
Or the converse of that is what just makes you shake your head a little bit and say, you know, folks, we could be a little bit smarter than that. Uh, so much. Uh, so I would say, um, focus on the pro like your pain points and the opportunities that you can't solve today.
Uh, I see, uh, kind of an anti-pattern with, with AI right now, uh, with agen ai, uh, specifically now is, it's kind of like a, a problem looking for, you know, uh, a solution looking for a problem. But most organizations, all organizations have problems today. We can't go, we can't do these things that we want to do, or we're having these specific problems.
Um, the, the best way to learn how to use these things is to solve a real problem that you'll have. So start small of course, and then work your way up. Um, do it in a safe way.
Do it with enterprise grade tools. Uh, you really don't want to be using consumer grade tools to do these things as an enterprise because of privacy and security and guardrails and all of those things. So I think if you do that and the organizations that do that are seeing a lot of success, uh, there's a real divide right now, which is really interesting.
Um, there are companies who are very much behind the curve on this, and then there are other organizations that are doing things that, um, are incredible that just blow my mind. So it's, uh, it's, it's kinda a tale of two cities and, uh, I think you really wanna be in that forward looking one, um, but do it safely. Of course.
I think there's also folks out there that think that maybe they wanna build the perfect architecture before they get started and uh, maybe good enough always beats perfect, but do we need to just kind of go forward? 'cause the truth of the matter is we're all kind of learning together at the same time. Absolutely.
Spot on. So one of the biggest problems that I've seen and, and I've been, uh, uh, working on cloud migrations for about a decade at this point. And so yeah, I'm seeing the same thing with ai.
One of the biggest problems is, uh, try waiting until you have a perfect plan. And then what ends up happening is you never have a perfect plan. So it just becomes, preparation becomes procrastination, and then you fall even further behind.
If you do happen to put together what you think is a perfect plan, by the time you implement it, that plan is gonna have to change anyway. So I'm not saying there's no value in planning, of course there is, but you want to get, um, you wanna do it, do it iteratively, and you learn generally by doing, uh, not by planning. Um, so doing is the best way to get ready.
All right, folks. I believe it's one of the laws of nature that says it's easier to change the direction of something that's in motion, and it is something that is sitting still, and that's true with ai. Hey Jay, thanks for being on the show.
My pleasure. Thanks for having me. All right.
ai Leadership Inside series. You can find this episode and others on our website. We invite you to check those all out.
Until then, we'll see you next time. Hey everyone, it's Alan Shimmel. Welcome back.
You know, it's been an amazing couple days here at Qualys as Rock Con. We're Rock Con Risk Operations Conference and we know, but all good things come to an end. This is gonna be our last interview here this year, but we've saved the best for last in some way.
Let me introduce you to April Lenhardt. If you are a, uh, a tech drunk TV aficionado. You might've seen April talk at our, uh, RSA coverage.
Last, I guess it was last May, was RSA or April, something like that. Yes sir. Maybe it was April and April, but, um, April, first of all, welcome back to Text Junk tv.
Thank you. It's great to have you, uh, for the, you know, not, I was kidding about the aficionados. Most people have no idea you were on in April, or not of course, but tell them a little bit about your background and and what you do here at Qualys.
Yes. So I've been in cyber threat intelligence for about a decade. I started as an intelligence analyst actually.
Mm-hmm. And my goal at Qualys is to bring cyber threat intelligence to the fore. And really what that means is we have a threat research unit of over 120 analysts.
And my goal is to make sure that that work is really shown really clearly to all of our customers. Absolutely. And, and you know, I, I'm not going to embarrass you or anything, but the, the Caris research team has actually won a couple of awards lately.
PO Pony Porn. Pony Pony Awards. Pony Awards, yes.
Uh, as well as other awards and stuff. I mean, they're really doing some phenomenal work and Yeah. You know, awards are nice, but the work they do actually really good important kind of stuff.
So it, so it is important, you know, April, I, I was, uh, started a security company in 2001 venture backed security company. And we were in vulnerability management network access control. And I remember going to, at the time, I think it was still called Citibank, it wasn't Citi yet, it was Citibank.
But talking to one of their global CIOs, they had three global CIOs and he told me that it took them 90 to 120 days from the day of a patch Tuesday release to actually apply to remediate. Yeah. And I remember thinking to myself, that's crazy.
90. 'cause even back then, 90 to 120 days was forever. Right.
But he said, you know, they would rather make sure they don't break anything else than rush to fix even the most serious vulnerability. That's when I knew security had issues. We had issues.
Now that GAP is, you know, commonly referred to today is the, uh, meantime to remediation. Right? Right.
And, and a and a lot of our security metrics and, and how we measure performance of security teams are built around at MTTR talk. Talk to me a little bit about MTTR, how your work at Qualys helps that and what Qualys is doing to kind of close that gap. It's not, let me just say a friend, I don't think anyone wait 90 to 120 days anymore, but what do we do?
You know, what, what is the average gap and what are we doing to close it? To your point about qualysis threat research unit being exceptional, one of the statistics that I'm really proud of and that I was happy that I just got to talk about during my talk is that 20% of all Qualys customers are able to actually remediate CSEC Kev vulnerabilities before they hit csec Kev. That's great.
And so one of the big things with that is that the remediation time is low because of how quickly we are able to kind of enumerate these vulnerabilities. One of the big ways that True lens, which is the product that I'm working on, is able to help that remediation is by really helping you triage what is the most important things to remediate. So we're all surrounded by a plethora of different alerts, different metrics, some that are not super actionable, right?
And so my goal is to really help kind of, kind of funnel the different things that you could potentially action to say, Hey, what of these are relevant to your industry, to your business? And then from that, say, Hey, these are the specific things that you need to work on. And from there, your remediation time can go away down if you are really focusing on the things that really specifically matter to you.
One of the other things that we're doing is we're able to give a view into the industry that you're in and say, what is the average remediation time? So instead of just looking across all of any industry, uh, any vertical, and you know, how well is, is an oil and gas company doing compared to a mom and pop shop compared to a finance institution, we can specifically say, if you are a large size oil and gas company, how well are you remediating compared to your peers? Because you might think that you're doing great because you remediated this one vulnerability in 15 days.
And come to find out your peers all remediated it in three days. Right? So then you might need to know, okay, hey, I gotta change how we're doing this.
But if you don't have those statistics, you can't really change because you're, you're not really sure what you're, you're going against. Right? Absolutely.
And so this is a big way to, to be able to, to change how you remediate. Absolutely. I got a hard question for you.
So how do we, how do you take MTTR? How do you take those sets of statistics and feed it into the rock to deliver to a, an executive and say, look, because we've lowered our me, um, our mean time to remediation by 20%, we've lowered our risk by, uh, x percent. How, where does, you know, is that even possible?
And how does that get done within the Qualys kind of product suite? That's a great question. So we, we incorporate meantime to remediation in two ways.
The first is kind of, uh, for every individual vulnerability, we want to provide a mean time to remediation. So we're able to get on a very granular level, what is your MTTR and what is everyone else's MTTR? Yep.
We are also able to say, kind of at the, at the bird's eye view, at the very strategic level, how are you doing with your remediation versus how are others doing? So you're able to say, you know, taking aside one or two vulnerabilities, um, actually looking at everything, what does that look like? And those are statistics that you can share with the board, with different stakeholders, with investors, and those are things that you can, you can really incorporate into that workflow.
I love it. I want to turn from MTTR to MTTD meantime to detection. Mm-hmm.
Well, let's first, you know, I love throwing acronyms at, at the audience, but let's, I said it's meantime to detection, but what does that actually mean When you're thinking about meantime to detection? Think of from one of vulnerability is, is first introduced to our system. So when are we, no.
When is the vulnerability first, first acknowledged as a vulnerability to, when on your systems do you say, Hey, this asset is associated, um, with, with a problem. When do you know that there is a vulnerability? When is their risk introduced?
Um, this is a really critical metric because you need to know, Hey, um, has this been sitting on my system for years? Or was this only a problem, you know, a couple hours ago? Very important to know.
Absolutely important to know. Now, how, how do we, how do we measure that to quality? So it 'cause to a certain, you know, to a certain extent.
Well, it depends on what kind of threat intel you're getting, how vigilant you are, how well, you know, the whole, I mean, everything. And some of it is pure dumb luck, I think, too. How do you, how do you quantify for the luck and quantify for all these things and say, okay, because you're using Qualys, your MTTD is lowered somehow?
There are definitely certain aspects where if you're looking at espionage actors, if you're looking at these really long dwell time actors, you are going to then have them, of course, associated with TTPs, where they will use vulnerabilities that will be in the system for a long time. Right. But if you're looking on average, if you're looking at, uh, zero day vulnerabilities, if you're looking at kind of what we see typically in, in the daily news, the most critical thing is being able to run scans and detect these things as quickly as possible.
And with Qualys, we have such a robust system, we are able to really give you kind of as small of a delta as possible, um, from, from when you are first, from when we first know about it to when it's detected. And that's, that's really kind of the critical timing that we're looking at. When we say timing is everything, what we're looking at those metrics, that's what we're looking at.
I agree with you. I agree with you. One last topic I want to throw, and that's ai.
It's changed everything this year. How's it changing what you're doing? It's changing what we're doing in a big way.
So we are leveraging agentic ai where you can ask questions like, Hey, I see all these different risks and vulnerabilities. Help me triage what to do next. Um, what, you know, Qualys, what do you see in the system in terms of the assets that I need to look at first?
And then when you have the system, how do you incorporate it with all the other products? So now, instead of kind of having to do all these disparate pieces alone, we are able to say, Hey, let's, let's automatically using Agen ai, be able to connect with all the other products you're using in the ecosystem. And then say, okay, what do we now do to, to be able to triage this?
How do we evaluate risk? What does that look like? Again, across different industries and also within my own system, what do I need to focus on first?
So agent AI is really being leveraged strongly by Qualys as a way for us to continue improving our systems and as a way for organizations to help mature their own cybersecurity posture. Got it. I got it.
If I had to ask you sitting here next year, how much more ai agentic AI is going to be, you know, not, not, it's gonna be a bigger piece of this as I guess the colu the feeling, but is it going to 10 x your, your team and, and your stuff, or, you know what I mean? How, how, how? Yes, it's big, but we're still scratching the surface, is what I'm saying.
We're still scratching the surface. Our, at least on the product side, what our plans are really are to try to run as quickly as possible, but as safely as possible. We are a security company, right?
Absolutely. Um, but to try to incorporate as many different uses and as many different ways, um, that we can help companies, uh, be able to leverage threat intelligence and be able to mature their own organizations. Um, and again, to, to do it in a way that is possible, probable safe.
We love it. April, I know you ca literally came off the stage, came here. I want to thank you.
Thank you for all the work you do. It's been a great Qualys rock on, and you've been a great guest to end it. Thank you so much for having April.
Maybe we'll see you at RSAA couple months March this year, for Sure. All righty. Hey, that's gonna wrap up our Qualys Rock on coverage here in Houston.
We hope you've enjoyed it. If you missed any of the live feed, uh, we'll, we'll have the on demand by next, I don't know, early next week. But until then, this is Alan Shimmel on behalf of Qualys and Tech, strong Tech, strong tv, we're out.
Bye-bye. Hey, everyone. We're back here live in Houston for Qualys Rock on conference day two.
We've been just talking to a bunch of different people already this morning. We got started early. Hope you're enjoying it.
Our next guest, Richard Cy, You nailed it. Well, it's not my first time interviewing you, but Okay. If, if you follow along at home, I actually spoke to Richard last year in San Diego for, uh, quality security conference, QSC Richard, if I'm not mistaken.
You had just joined around then, wasn't it? Yeah, I've been here maybe 20 months. I feel like I'm a baby.
You know, you, it's in months. You Yeah. The time.
Yeah. He's not making, I, and I do remember a little of your story, but no one at home is gonna remember it. Right.
Why don't we, let's start there. Give us your j you know, a little bit of your journey to being equality in now 20 months. Sure.
Great. Well, actually, this is my second stint. I am in a boomerang about 20 years apart.
So actually, when I started, ed, summed and I were both Midland engineers. I remember he'd show up in cargo, uh, shorts and t-shirts and uhhuh. Yeah.
And then I went on to do this serial CSO thing, GE Twilio Lending Cloud. I've been a Chief Risk officer in the insurance space. Mm-hmm.
Um, and I've written a few books, but summed and I stayed friends. And when he started on this journey, this new vision on the Risk Operations Center, and more specifically ETM or enterprise True Risk Management as a platform, he called me up and said, Hey, would you like to join the team? And I was like, this is great.
Can't wait. And here I am now. That's fantastic.
That it is a great story. Now, your official title is not Chief Risk Officer. It is not.
It's Chief Risk Technology Officer, and we owe Ed the thanks for that great title. He came up with that. He came up with the title.
And I think the emphasis really is 'cause 'cause of my background on risk, um, first and foremost, helping to bring, I guess, the world, particularly CISOs, along on this risk focused journey. But at the same time, I have a role in helping define technology as well. So being a voice for a reason, I suppose, to the world on the risk side, but also helping to guide some of the product as it relates to risk as well.
So I do both those things. I love it. Yeah, it's great.
It, you know what been around a while, you, you learn that you want something that kind of plays to your strength. Right? Right.
And this is a, just, just like a great role that plays to your strengths. And, and it's good when, you know, things come together like that, because at the same time, they're, you know, Qualys is the risk operations company now, right? This conference is the Risk Operations Conference.
So it all, it all fits together nicely. You know, you like to see that in life. I'm, I'm pretty excited.
I'm, I'm like a dog with two tails. I can be more excited. So, Absolutely.
Richard, you are present, you presented here. Yes. And, um, why don't, you know, people watching this live at home probably aren't here by definition.
Right. Unless, you know, a quantum, they could be in both places, but as soon as we would know they were, then they wouldn't be. Um, I've been spending a lot of time with some quantum people lately.
Yes. Anyway, talk to us about what you spoke about. Sure.
Um, the title of my talk was Risk Yoga. So I was the day two keynote, so risk yo Yoga, turning Strategy into Measurable Action. And so, yeah, I didn't wear any yoga pants, by the way.
Okay. I taunted people and told them I might do it. But yeah, it was an opportunity to relax and, uh, I, I suppose play with the audience.
I actually, uh, there was a yoga theme throughout, but I ended up asking a lot of questions and people would answer. And I would use that to, I, I suppose, instruct them in, uh, new postures as it were to use a yoga theme and how to, how to think about risk, perhaps in ways that might be new to a security practitioner or security leader. And, um, I guess it went, it went well.
It seems like good feedback. People are still here, so I didn't scare anyone off, but yeah. Okay.
All right. It was Enjoyable. Um, so yeah, I'm gonna come back to the, to the quantum thing.
Even we can't know everything. 'cause like, almost by definition, once you know it, you don't know it. Right?
Right. It changes it. How do you, Mr.
Yoga professor or instructor, how do you, cybersecurity especially today seems almost about uncertainty by definition. Yes. So if it's about uncertainty, how can we have any certainty?
Right? Right. It's very, you know, is the cat in the box or not?
Right? How, how, what's your advice Sure. To grasshopper out there right.
About how to deal with this? That's a great question. So, you know, it's when we're uncertain about something, that's actually when we measure.
And the more uncertainty there is, the more measurement there is. When you stand a lot to lose, when there's high stakes and you, there's a lot of uncertainty. That's actually where measurement comes from.
If you think about statistics, right? When statistics came about, because someone had small and messy data, and they still had to make a bet. In fact, one of our main statistics today comes from the Guinness Brewery.
It's actually considered part of their intellectual property, where they're using very small amounts of data to make forecasts about crop yields, things that go into beer and whatnot. And so small, messy data to make better forecast. That's the same thing today.
Even with ai, in many cases, you think, oh, we have all the data. Well, we, we have sensing and artificially intelligent adversaries. On one side, we have a business that's digitally in AI transforming on the other.
And here we are in the middle. So there's, we're just surrounded by uncertainty. And the stakes are large.
I mean, just look what happened with Jaguar Land Rover. You think about Marks and Spencers we're talking hundreds of millions of billions of dollars of impact. So the question is, if we were gonna say, well, it's, if we say it's immeasurable, if someone were to say that to me, what they're saying is all possibilities are equally plausible to me.
They're gonna say, uh, we could be hacked a hundred percent of the time all the time. Or maybe it happens 0% of the time. So, well, what do you do in that case?
Well, you say, well, since I, I'm so uncertain as a security leader, you know what I'm gonna do? I'm gonna spread too little butter across way too much bread. Right?
It's a Tolkien quote. Um, but there's a sun Sue quote, uh, from this that's really great. He says, he who is everywhere is weak everywhere.
So the idea is that a general who's gonna deploy forces everywhere ends up being weak everywhere. So in the case of security, while we have a lot of uncertainty, we wanna measure so that we can take those resources. Again, we stand in the middle here.
We got, again, sentient, artificially intelligent, bad guys here. We got digital and AI transformation here, by the way, who typically has 10 to a hundred x the budget that we have. And here we are in the middle.
We have to measure to focus our resources. Sorry, I went a little long, but that was kinda the gist of my talk. You're a treasure man.
I, I could listen to you all day talk about this. It is great. So I think you've outlined the problem and the, and the environment that we're dealing with.
Now, some may say, look, you gotta fight fire with fire. Right? You got the AI stuff here.
You got this transformation, which is AI powered here. I gotta have AI here too. Yes.
What do, is that the answer? Well, I mean, I don't know if you, when we say, is that the answer? I mean, is that the answer to all of our security drama and dilemma?
I would say, I always look for the magic bullet, but I I, there's no Santa Claus either. Very good. Yeah.
No agree. So, um, yes, we have to use ai. Um, here's something that's distinctive about Qualys.
We're using ai. We also happen to have about 120 to a hundred, somewhere between 120 and 150 researchers, not just researchers, award-winning security researchers. They just won two pony awards, uh, back at Defcon.
Yep. This, they've, they've done this two or three other times as well. So we have this elite team.
What you wanna be able to do is take that team, use them to actually do reinforcement learning with your AI models on somewhat of a continuous basis. And obviously, bringing in all that massive amount of data from, in our case, enterprise to risk management. You want to have all of that working together.
So it's not just AI by itself, but you want the AI plus the human expert discernment to work together. So this is, this is one of the reasons why I'm here, is because I think this is part of the, I I guess it's the data or AI or measurement moat that Qualys has. Is that an opportunity to work with just what I'd call a, a cesspool of security iq.
And these guys bring that together with AI and data to make, make a big difference. So it takes the people and the AI together. So it, it's, you're not even talking human in the loop.
You're talking a true partnership. Like a si almost like a sidebar. They're putting on this, you know, I don't know.
Yeah. Argument. See on that, that we'll get killed over here.
Yeah, we might. I mean, so that's human enhancement. Yeah.
Yeah. Right. And, and that may be, you know, something we're gonna see coming down here, but I, I think right now, we're still in that partnership phase.
Well, look, AI does what AI does. Yes. And we're going to use, it's a tool.
Yeah. Like every other tool humanity's used since, you know, homoerectus or something. But we also have to recognize that there are certain things that the human still has to do.
Yeah. That, you know, it's, it's gonna take a human. Right.
And, and I think that's where we are today. Now we're seeing the rise of agent AI become much more prevalent. Even the generative ai ai, you talk to some of these people who are really into ai, they'll tell you generative AI is yesterday's news.
Right. Right. How's that changed the equation?
Well, So that might be marketing people. I mean, gen so generative models, by the way, not to get overly nerdy, but generative models are a thing. And so the idea where you could have some learning off some data, and based on that, the model can then extrapolate, make inferences, and even generate new data, new scenarios, that's a generative process.
So that doesn't go away ever. No, no. I, I think that's table stakes.
Yeah. For the age. 'cause without it, the agents can't operate.
They're not autonomous, they're just APIs. Yeah. So, yeah, just a, some assumptions in the modeling there.
But yeah, genic ai, the idea that it, you can have composable models that, um, and we use this word autonomous, right? Um, I think that, you know, it's autonomous with constraints, right? You, you, you want it to make reasoned, uh, inferences and then take deterministic and safe actions.
Yep. Right? And so, again, when I go back to this idea of that we have all these researchers, we can look at things like Mitre attack paths, right?
We can look at the combination of attack paths and controls. By the way, the combination of attack paths plus controls, plus exposure, that's a mathematically a massive, like you, we humans cannot reason over that complexity. Great.
We have AI for that, but AI's only gonna be as good as the assumptions that are put in underlying it. So again, I wanna go back to the idea that it's really, maybe you call it a human in the loop, perhaps you call it reinforcement learning. But for us, and again, this is where I think it's a Qualys distinctive, is that we have this elite set of humans, these researchers, award-winning researchers, bringing them together with massive amounts of data.
We have this giant data lake, right? Bringing that together with Ag agentic AI becomes the sort of scenario where you can start saying, okay, this is how you can start looking at not only just the determinist action, you can take or have the models take patch this, block this, but also start saying, alright, given your environment, given these attack paths, given these adversaries, here's how we can start rank ordering. How you go about purchasing controls, how you go about making investments, at what rate you roll those out, given your financial constraints, what's the most optimized approach you can take so that you avoid spreading too little butter across too much bread, but you start focusing on the risk that matters.
So that's, that's why I'm here. That's why I'm excited about what Quals is doing. Absolutely.
Hey, last question. I'm gonna go off the reservation a bit. Sure.
Okay. Sure. I mentioned Quantum a few times.
Sure. Quantum and security post, you know, post quantum CRI cryptography, and there, there's been a lot of buzz around, Hey, we need to be getting ready for quantum. It may be three years out, five years out, maybe more.
Right. Not much more. Right.
Um, what do you, in your role at Qualys, this is kind of something on your, on your desk, right? Yeah. Yeah.
What do you, what are you thinking? What are you seeing on that? So, it's kind of interesting with actually what, with what's happened with crypto most recently.
But I, as I looked at it, there's something like one, maybe 50%, if not one third of crypto will be completely exposed. I think there's more recent changes where they're saying, well, okay, we'll have some protection here. You know, again, I'm not, not a crypto expert.
Don't claim you. No. You get it.
Not even on tv, even though it is a tv. Mm-hmm. Um, but I think as a risk leader, we do need to be thinking about that.
So what's, what is plausible in terms of, you know, in, in fact, even thinking about the future, I'll say this, and I talked about this on my talk, uh, I'm gonna kind of go off the reservations, but prediction markets. Are you familiar with prediction markets? Yeah, sure.
Big thing ties to crypto as well, but people making bets, like prediction markets significantly outperformed, uh, the pollsters in the last election. The presidential election. Yeah.
Great. Where they failed, by the way, was on, uh, forecasting could be the next Pope. By the way, I, people are betting on the Pope thing, right?
Uhhuh. So it's kind of interesting. Oh, they bet On that.
Whatever it is, right? They're gonna, they're, but the idea of taking that same approach, all right, so given what we know about crypto, given what we know about the current state of the world, how can we, how can we start measuring and creating really, that's, that's already modeling. How can we think in a, you know, relatively mathematically unambiguous way that retains our uncertainty without obscuring what certainty we do have, make the best bets.
That is what risk management should be doing. Sure. And yes, I am thinking about that stuff.
I'm thinking a lot more though right now about AI and what that means. Yeah. Than crypto.
I, I think, and I think AI becomes the force multiplier, or maybe it's the other, maybe when few day does come, and we do have Quantum combined with AI, though, right? I think those, they're too volatile, you know? Uh, crazy.
Sounds like More employment. I don't, more security, Job security, yeah. For the security teams.
Well, if they don't replace us with AI robots or humanoid, whatever physical AI is. Right. Right.
Calling it, Richard, thank you so much. Thank you so much, Alan. Over.
Pleasure. Likewise. This guy's great.
Do check him out. Your books are still out there too, and everything else, it's getting a little loud here, but I'm hoping you could hear us. We're live at, uh, quais Rock.
We'll be back in a moment. Hey, everyone, it's Alan Shemel, and welcome to another episode of Control Alt Deploy. Control.
Alt Deploy is a, uh, a podcast series that we've been doing with our good friends over at Tex now for more than six months, I think. And we discuss different areas around DevOps, that SecOps software development and deployment, CICD testing, et cetera. But really with an eye towards, you know, what, what's happening in this space.
And of course, the biggest thing happening in this space is probably ai, uh, as it's taking a, a, an effect on everything. So in today's episode, we're gonna look at AI and the role of, and, and the role it's playing in testing, automated testing, continuous testing, whatever you want to call it. I'm really happy to be joined for this episode.
And it's just me and him. This one, I know many of the others, we've done big panels, but this is a one-on-one with Yev Sayers. Yev is the, uh, a DM Chief architect at OpenText.
Yev, welcome to Control Alt Deploy. How are you? I'm doing great, and thanks for having me, Alan.
My pleasure. Yana, before we jump into what we want to talk about around testing and ai, give people, it's, I, I gave them your title, but what do you actually do over at OpenText? And tell us a little bit about your journey.
Uh, sure. So, so thanks again, uh, Alan, for having me. So I've been in, uh, OpenText for the, uh, last, uh, 20 years in different engineering position, uh, as a developer, as an engineer, uh, running internally our DevOps, uh, uh, platform in innovation.
And, uh, I'm now running our application delivery management, uh, technology and innovation. And a lot of my focus is on, uh, on ai, how to utilize ai, uh, both in our products, both in our own DevOps implementation, in testing, uh, and, uh, very excited about it and opportunities around it. Absolutely.
Thanks for joining me today, Jan. If, um, Siana, we were talking before we started recording, we, we actually had a good talk, we should have recorded that. com in 20 13, 12 years ago, almost 13 years ago now, testing was always one of the poster childs for DevOps success, right?
With DevOps, we, we did much more automated testing, much more continuous testing. And, you know, in that old adage of freeing up the human to do higher level work, instead of doing the same mundane, running those mundane tests over and over, it freed up the human to almost be more of a test architect, if you will, right? The, he, the human, he or she, right?
The human would, would write the script for the test coverage, right? What do we wanna test? And then we can automate the actual running of the test.
And then, you know, based upon test results, again, humans would get involved, remediation, uh, whatever needed. You know what, depending what came out of the test, and it, it made a huge difference. I don't know how long you're doing or been involved in, in, in the space, but you remember before there was a DevOps and it wasn't so automated, right?
Mm-hmm. The life of a, a tester was, was kind of really, you know, doing the same thing over and over and over a lot. Again, it made it, it made it better.
And our testing got better, right? With automated testing, we, we had better coverage. We, we tested more.
You know, I guess the real question is, did it make our software better? Mm-hmm. That's, that's a great question.
That's The question. Um, but now AI's kind of changed the game. So I've set the table.
Why don't you explain to the audience how AI is kind of changing that game? I, I, I think that, uh, what we're seeing is, especially in the software, uh, delivery industry, is, uh, a significant, uh, shift, uh, once, uh, uh, AI and especially large land wind model were, uh, recently introduced. And it started mainly by adopting a code assistant, whether that's, uh, copilot, uh, uh, or, or others.
And, uh, I think where we are today is that, uh, many organization, uh, including ourselves, realize that it's, it's great to have a code assist, but then you, uh, then you have kind of an influx of new code. And, but eventually your outcome isn't just generating code, is it? It's having new capabilities or feature or delighting your users and, and customers.
And, uh, the rest of your DevOps pipeline or, or value delivery, uh, may introduce bottlenecks. So just generating more and more code, uh, isn't, uh, uh, isn't eventually improving your, uh, your outcomes. Uh, so, um, uh, I think kind of the, the maturity here, or the evolution here is, uh, to see how you can now leverage AI across that, uh, value stream across that, uh, DevOps pipeline.
So it's not just generating more code, it's actually making sure that what you're building is at the right quality, both by meeting the business goals, the business expectation, and also validating that it's secured, that it's performance, that it meets the enterprise's, uh, requirements, uh, uh, and, uh, uh, and controls. Uh, so it is a, it is a matter of maturity. It's a matter of evolution.
But, uh, I think that now the way we are looking at, at AI is how can we inject and leverage AI at every step in the software delivery lifecycle from the planning to delivery beyond just coding and coding a system? And clearly, uh, we are a large enterprise. Uh, there are no controls, regulations, risks that we need to manage.
And being able to, uh, make the most of code assistance, that actually means you need to add these guardrails through AI across the lifecycle. You cannot just look on the coding part. You have to look on testing, you have to look on security.
You have to look on how you validate eventually, uh, uh, I'd say the outputs of your code assistant, of your copilot and a like, Agreed. Agreed. Um, let me, let me get, let me talk on behalf of the humans out here, though.
What do you think the role of the human is in this new way, or this AI enabled or empowered way of doing testing? Is there a place for humans? I think that's a fair question.
It is a fair question. And, and, and, and I think, as you know, uh, as we were looking back into, uh, uh, previous, uh, technology, uh, enhancements and disruption, whether that's around, uh, uh, the shift to or for manual to automated testing, uh, the production of, uh, mobile and mobile application, et cetera, eventually also here, the role of the tester will, will evolve. It has to evolve.
I don't think that, uh, uh, humans are, uh, obsolete. Uh, I don't think that the human, uh, uh, testing is obsolete. There is still a role here for the human, and, and we'll discuss that in a, uh, in a second, but it definitely has to change.
Uh, the way we're looking at it is, you know, eventually testing evolves to become more q quality engineering. Uh, that means that, uh, the current tester would need to know how to best utilize, uh, the new tools, the new capabilities of AI across that life cycle. And that means, for example, uh, when you're looking on, you know, your requirements or the design, uh, how to best utilize AI to better plan, to better design, to identify risks earlier in the lifecycle.
Uh, so if you have now, uh, a new feature being designed or, or planned validating that there are no missing aspects in the requirements, may have validated that there are no ambiguity in the definition, uh, doing earlier in the life cycle, threat modeling, utilizing AI to identify security risks upfront, et cetera, uh, we think that this is a key area where, uh, the quality engineer, uh, can level up and leverage AI to look across that software delivery life cycle beyond just testing. Testing is a key, is a key part of it is a key control. But beyond that, so you can, early in the life cycle, do that shift left to identify risks, uh, identifying a bigot in the design, in the planning, et cetera, that then becomes a better input eventually also for code assistant and the like.
Uh, and then the QA engineer is the one that is responsible to validate eventually that output, that output from that, uh, DevOps cycle when you get a business goal, a business requirement, validating that it was actually met and defining which tools, how you utilize AI to put these controls, to put these validations in the steps in the GL cycle. So we do see that evolution from the shift from manual to automated testing and up to autonomous testing. Yeah.
Eventually the tester or the qa, the QA engineer, uh, to come and define the methodologies, the practice of the tooling that he's going to inject into that life cycle, to control the agents, to control the agents that are going to build potentially more and more of the software. Sure. So, hey, I, I, I've had this discussion with people before.
So if we're going to use agents to build the software, then we're going to use agents to test the software, then we're going to use agents to remediate or re, you know, re recode or, you know, re remediate the, from the test results, validate the test results, remediate the test results. Where is the human in the loop? Mm-hmm.
So it's, it's a, it's a great question. Uh, and, and, and I think here again, it's not, uh, uh, black and white. Uh, I think it really depends on the domain.
It it depends on the, the, the maturity of the organization and, uh, you know, the, uh, the criticality of the, the application and the software. Then, yeah, there could be cases where it's a relative simple application, uh, that follows a pattern. And yeah, you could through a vibe coding, uh, uh, gate a, a great outcome or a good enough outcome.
But in many cases, especially when you are looking on large enterprises, uh, and large scale applications, uh, it's, it's more complex than that. Uh, so, uh, in that case, yeah, I still see engineers, humans, but leveraging AI and assistant to augment them, whether that's in the planning phase, whether that's in the development phase, in the testing phase, in the deployment phase, et cetera, uh, to, uh, uh, accelerate the delivery to actually improve quality by better validating or earlier identifying the risks and concerns and mitigating that upfront, uh, and, uh, uh, validating the outcomes or say the outputs of the agents. So I don't see in that these scenarios, especially if you're looking on financials, healthcare, et cetera, uh, a more, let's say, a critical application mission, critical application, kind of, uh, just, uh, uh, fading out.
Uh, so I do see a more leverage of ai, but then empowering the human, rather, replacing the humans in that, uh, in that scenario. And, uh, and, and I think there is a, uh, an another factor here. I mean, there is, uh, up to a certain scale where you can know, uh, uh, offload to an ai, uh, agent.
Uh, there are many cases where, uh, you know, an ai a an AI agent can't yet, uh, uh, tell you, uh, what is the real human experience of an application? How does it make you feel? Uh, that's something that you will still need in many of these scenarios, uh, to have the human, and the human in the loop, not just to develop, not just to, uh, utilize the agents, but really to provide the human aspect, the human experience.
Eventually, we are the ones that are experiencing the applications, experiencing the software, and, uh, that's something that the agent cannot yet replace. And I don't see that happening in the, uh, in the near future. I agree.
I, I don't, I agree. I don't disagree at all with that. Wanted to, you know, a lot of what we're seeing in the end of, in, in the media now, right?
This report that says 95% of, or 90% of ai, uh, programs, projects are not contributing to the bottom line. Mm-hmm. Uh, another, another study said, uh, 80% were deemed not successful.
We've seen other studies where, and this is kind of counterintuitive, 70% of the IT workers are saying, or 75, more than 75%, like critical mess, 77% are using ai, but two thirds don't trust it. Yeah. But they use it anyway.
And when we think specifically about testing yav to use a tool that you don't trust, is, is that the case? First of all, is that that valid? Did you know, and I think it is, I think a lot of people are using ai, but they don't trust ai.
Right? And what does that mean for the quality of the code that's being passed on via testing right now? That, that's, that's a valid concern.
And, and actually, uh, we do see that as in, in, in, in many organizations becoming a, potentially an inhibitor for utilizing, uh, a ai. Uh, and that's why my point that was that, uh, you know, in one hand you see more and more usage in one hand of code assist, but a lot of concern that is being introduced, a lot of being introduced on what is the output of these code assistant? What is the quality of the code they generate, uh, the security of that code, et cetera.
Oh, yeah. So you, you have to, you, you have to control that. And again, the, the, the, the more mission critical the application here is, uh, uh, uh, the more, uh, large enterprise is, the higher the risk is.
So you have to counter that, or you have to balance that. And part of that balancing act is also validating it, having the proper testing and tooling in place, uh, putting the proper still code reviews, human in the loop code scanning, test automation, autonomous testing, as we discussed, to mitigate that risk. And, and still it's there.
I mean, you still have that, that risk. And I would say it's more than risk. You, you have here new challenges that you didn't have before.
So traditionally, uh, when you're looking on the traditional applications, they were pretty deterministic, right? You had an expected outcome or expected behavior of the application. Now, with the introduction of, uh, uh, of AI and large language model that are being injected or becoming part of the software, they're becoming less deterministic.
And that requires different practices on how you test, how you validate, how you measure the quality and the experience of these applications. And it requires taking more statistical, uh, approaches, uh, creating baselines using techniques like, uh, LLM as a judge and so on. So also, the way you test and validate your applications has to evolve in order to meet the new technology of introduction of AI within applications.
So it's, uh, to kind of, uh, uh, uh, a closure to your question, yeah, there is more, I'd say, risk that is being introduced. I think that some of that is acceptable. I mean, we're, all of us are using GPT.
All of us know that there could be hallucinations, and we accept that. And we're, I wouldn't say, uh, uh, uh, I'm necessarily, uh, happy with it, but we are, we accept it. We, we know how to adjust to it and how to handle it.
Uh, with that in mind, um, uh, you do need to, to put in place the right controls, the right validations, the right, I'd say, uh, uh, balancing, uh, uh, uh, uh, tooling, processes, et cetera, in order to still be able to provide enterprise grade applications to your customers, end users, and so on. And that requires also introducing, uh, new methodologies and practices, especially when you are coming to test and validate AI powered applications. Fair, fair.
So, Yanni, let me, let me move from the, you know, from the hypothetical to the real mm-hmm. And I'm asking you now on behalf of OpenText. Yep.
Where does the rubber meet the road? Have you rolled out products around this already? Are people using the mm-hmm.
What's the experiment been like? Yeah, Definitely. Uh, we have, uh, uh, we have introduced a, a, a variety of, uh, uh, I'd say, uh, uh, uh, smart assistant, we call them avior.
Uh, so we have our, uh, our own, uh, uh, DevOps, uh, avior testing aviators that are, we're using that internally and also with our customers, using that to generate tests to identify risk and mitigate that by generating tests, whether this could be manual tests or automated tests. We know how to, for example. And we're using that, not now a lot, uh, uh, improve our planning.
So we're using our aviators to identify earlier risks, to do threat modeling, uh, to identify, uh, ambiguity in the requirements and improve that. Uh, we are using our own aviators, uh, for validating our security, uh, for, as I mentioned, generating tests, uh, for planning, uh, breaking features into user stories, into tasks and so on. Uh, so, uh, uh, a variety of, uh, uh, uh, of aviator of smart assistance that are being used in every step in the software delivery, a life cycle.
Uh, we're measuring that continuously, both the, the success, both the usage, meaning to what extent, uh, uh, or how many tests were generated in a to an AVIOR versus the human generated test. And, uh, our at least, uh, uh, experience is that, uh, the trending is very, very positive. Meaning we do see more and more shift towards, for example, tests being generated more by AI versus the human.
So that's one measure that we're looking at. Same goes with, you know, the agile planning with, uh, user story definition, with requirement definition, et cetera. Uh, we're measuring that shift from human driven activities to agent driven activities, and to what extent that is actually being, uh, being adopted.
And I'm, I'm, I'm happy or confident to say that no, we're getting this feedback also from our customers. So that's kind of the feedback loop we're operating in. Uh, each new agent we introduced, uh, we validate with our partners, uh, with our customers.
We were getting that early feedback, and then we evolve accordingly, and it looks very, very promising. Excellent. Excellent.
Where can people get more information on that? You know, So you can, you can look on, uh, uh, uh, on OpenText website, look for DevOps, uh, the DevOps aviator. Uh, you'll find more information, demos, uh, references, et cetera.
Absolutely. And then, you know, we only have a minute or two left, but I, I want to, as if we're not looking forward enough, I, we, I wanna spend the next minute or two looking maybe a little more forward, right? So now we are, like you said, we're getting our heads around the risk of using ai.
We're getting comfortable with AgTech AI mapping out our test, uh, coverage and, and platform, uh, you know, uh, protocol and stuff. Where do you see this going? I think that, uh, uh, I, I, I envision eventually a shift or an evolution to, uh, uh, uh, I would say a, an autonomous delivery team.
So if today we have, uh, you know, uh, a performance engineer, a functional tester, a security expert, uh, uh, a product owner, an engineer, software engineer, collaborating together to, uh, to deliver a business goal, uh, I believe that, uh, with, uh, the evolution of ai, we'll see a collaborative team of humans and agents, uh, to achieve a joint goal. And, uh, I, I, I think that this is, uh, uh, you know, this is evolving as we speak, uh, and we see more and more, uh, smarter agents augmenting humans. And in some cases, yeah, you can offload the activity to agents to be delivered, whether that's fixing a defect, implementing a new feature, or a complete, uh, uh, a complete application that's not that far, uh, farfetched.
And, uh, beyond that, I also see or envision, you know, more adaptive applications. So applications that are changing their behavior on the spot based on human feedback as they are being consumed, as they are being used. And just think of it that what does it mean to have this kind of, uh, uh, uh, ever living software and application that is continuously changing, uh, based on as they're being used?
Sure. By, that's a totally different ballpark to what we're common to use today. That's almost like evolution right before your eyes, right?
Because yeah. As it changes with the humans, you know, it, it's, uh, I was talking to someone the other day about this. It's such an exciting time to be involved in technology with this right now, because the, the window for innovation, the, the possibilities are probably greater than they've ever been.
I mean, I, you know, I was around when we, the internet went commercial, right? And, and wow, what a, that just opened up so many things connecting the world. And every business would have a place on the web and, and all of these things, right?
This is maybe even bigger than that. So I agree, interesting times. Jan, if thanks, thank you for being our guest here on Control Alt Deploy.
Thank you for all the work you're doing at OpenText. Good luck to you. And thank you for listening in on our conversation today.
We hope this has given you a little bit of a peek into how AI and, and agentic AI generator of AI ml are all playing into today. And tomorrow's changing landscape for, for testing software. This is Shimel on behalf of Techstrong and OpenText.
Thanks for listening.