AWS re:Inforce Highlights Security, Identity, & Automation | Tech Field Day News Rundown: June 25, 2025
At AWS re:Inforce 2025, AWS introduced key security upgrades, including expanded identity tools, enhanced code and threat detection with Inspector and GuardDuty, and easier deployment through improved WAF and firewall features. New CISO Amy Herzog emphasized identity security, while AWS reinforced its focus on automation, secure development, and ecosystem collaboration. This and more on the Tech Field Day News Rundown hosted by Tom Hollingsworth and Alastair Cooke.
Time Stamps:
0:00 – Cold Open
0:24 – Welcome to the Tech Field Day News Rundown
1:36 – Simbian Launches First LLM Benchmark for SOC Performance
6:33 – Record-Breaking 7.3Tbps DDoS Attack Hits Cloudflare Client
11:56 – Qualcomm Acquires Alphawave
15:51 – QuantumCTek Unveils Affordable 1,000+ Qubit Control System
21:12 – Teradata Brings AI Platform to On-Premises Data Centers
26:08 – Chinese Hackers Build Hidden Network Using Fake LAPD Certificates
30:01 – AWS re:Inforce 2025 Highlights Security, Identity, and Automation
38:55 – The Weeks Ahead
42:08 – Thanks for Watching the Tech Field Day News Rundown
Transcript
Symbian launches, S-O-C-L-L-M. Benchmarks, big DDoS hits CloudFlare. Qualcomm acquires alpha wave more qubits.
Teradata builds an AI factory Chinese LA PD certificate hacking. And we're gonna take a look at some of the news from AWS reinforce in this episode of the Tech Field Day Rundown. Hey everyone, welcome to the Tech Field Day rundown.
It is June 25th, and we hope that you are enjoying perhaps a snack that was purchased thanks to a gift card. 'cause it's National Gift Card Day. Who knew there was a day dedicated to that?
That wasn't Christmas, but speaking of Christmas, you know what today is? It's six months until Christmas. Did you know that there's a name for that day?
It's National Leon Day. And why? Well, because Leon is no l spelled backwards, but do you know what?
Law spelled backwards is Al. And that's my co-host for this episode, Al Cook. Al, welcome to the show.
Thank you. And it's a great pleasure to be here. Uh, we, uh, here in New Zealand, being in the Southern hemispheres tend to have Christmas parties this time of year because it's the coldest time of year for us.
So we have what we call midwinter Christmas parties. Of course, all of your Christmas parties in the are in the middle of the winter, but ours are often at the beach. Yes.
One of the things that always blows my mind is while I'm sitting up here freezing, opening Christmas gift, you guys are having barbecues and being outside and complaining about how hot it is. But you should never complain about how hot the news is on the rundown because we, of course, are bringing you some of the latest and greatest news. And we're gonna start that off with a story about Symbian because they've introduced the AI S-O-C-L-L-M leaderboard, which is a whole lot of acronyms to describe the first benchmark that will measure how well AI language models perform real world security tasks in a security operation center.
They tested this on a lot of realistic scenarios, as well as models from OpenAI, Google, and others. And they completed between 61 and 67% of tasks when supported by a solid framework. Now you're probably wondering why they did that.
Well, Ian's goal is to show where AI really helps, and that's speeding up routine work and not replacing human analysts. The approach focuses on transparency, real world testing and helping companies choose the right AI tools based on performance, cost and value. Not that dreaded AI hype that we keep hearing a lot about.
Al, do you feel like this leaderboard is gonna help people pick the right models and the right tools, or is this just something that someone's gonna figure out how to gain so they can get to the top of it? Well, I think it's, it's important to recognize that that symbian is, is talking mostly about the value of the framework you put around the model. And it's, it's their framework, of course, to put around the, the model that makes the most sense.
Uh, the reason that they emphasize this is that, that what they found was that the l and MU used makes relatively little difference to its success at dealing with the kill chains that, uh, with sets of logs from kill chains that they were showing it. So they tried both reasoning models as well as just generic large language models and saw very little difference between them. But what they did see is if you just feed the raw data straight to the LLMs, you get terrible results.
You need to put frameworks around how the data is being fed into the LLM, and you definitely need to put some guardrails around what the LLM is providing back in response. And so the, the interesting part was that it really didn't make so much difference, which lm you used so much as how you used it. Who would've think that you could use a tool badly by not thinking about how you're going to use it?
Uh, really is interesting to see that 61 to 67% of, uh, required tasks were autonomously completed by the models. It definitely highlights the fact that yeah, humans are definitely gonna be involved. But what I see for using LMS here is just dealing with a huge amount of data that happens when an attack is underway and they fed through a variety of different types of attacks.
Uh, when an attack is underway, the the problem is that you get a deluge of information and working out which information is significant and which information is just repetition or is, uh, is a secondary consequence. This is the kind of place where an LLM can be hugely beneficial. Just seeing those correlations between the events, seeing the, the different behaviors and identifying what's the truth part of it.
So reducing the, the cognitive load for the specialist human being who's going to do the, the final decision because hopefully we as humans are getting above that two thirds rate, 67% that, uh, was the high watermark here. Hopefully we're doing a better job of responding to security events and, and taking a look at it, one of the other elements that was highlighted was cost. That F an LLM is going to give you a slightly better response.
Maybe it's going to get from 67 to 69 or 75%, but it does it at twice the cost. So a higher RESO resolution rate, but at a vastly higher cost, that's probably not a good business decision. Good business decision is probably to have, uh, a human involved and take the slight reduction in the accuracy of the results at that vast reduction in cost.
So it's, it's kind of nice to see some real world things in here. Uh, some, some thinking that maybe the, the latest and most shiny LLM, these new reasoning models aren't necessarily going to be the be beyond be all and end all of making things better for you. Um, it's nice to see just some benchmarking too, some real world feed, some real data in and use a consistent set of data to take a look at how the results work.
What will be interesting will be to see these resolution rates changing over time. And so seeing whether improving frameworks around them, improving the RRMS and then working with larger and smaller LMS is going to provide better responses. I'd like to see a cost dimension here as well.
Uh, rather than just a straight what percentages were resolved, uh, what was the, uh, dollars per item resolved kind of view would be really beneficial to us as well. Something else that's really beneficial to us is the ability to cope with massive DDoS attacks and cloud failure has reported their largest ever DDoS attack. 4 terabytes of data in three quarters of a minute.
That's a huge amount of data. Now, this kind of attack, uh, with that briefness, it's typically as a connection list. So this was, uh, mostly UDP flood attacks, uh, was a bit of, um, there was a bit of UDP reflection going on as well in order to up the volume of attack without necessarily having to have a, a much larger botnet.
Um, there's some really interesting fun stuff in this. It's a return of Mariah, Mariah botnet was being used to, to launch this and to, uh, assemble together the servers that we're sending requests to over 34,000 ports on the target system. Uh, DDoS attacks continue to grow.
It's one of the realities is as we get better at protecting against these volumetric attacks and, and, uh, flow rate attacks, we basically see larger and larger attacks being launched against us. Um, what should we expect Tom, in the future of these multi terabit attacks, Chaos, panic, and disorder? My three favorite horsemen of the internet apocalypse, this is the problem that I have with these growing DDoS attacks, is that just like a Von Neumann machine, everything you add to the system just amplifies more and more and more.
I literally, months ago, we were talking about some of the very first attacks to hit two or three terabits per second sustain, and now we're talking about seven in a very short time. And this is overwhelming the ability of the systems that we have put into place to cope with it. I mean, that's literally the reason why CloudFlare was built, right, was to prevent massive surges in traffic from being able to take systems offline.
And now we're at the point where not even CloudFlare can take care of that. And I know what you're probably saying to yourself, well, Tom, there's a lot of companies, companies out there that are telling me that they can sell me DDoS protection, you know, Arbor Networks, Nokia, um, you know, literally companies that have been founded to prevent this problem from happening. I'd argue that you're absolutely right.
They are very good at detecting certain kinds of DDoS attacks. For example, you'll notice that in the article that we linked in, one of the reasons why this was successful was because it was effectively a UDP flood. TCP floods.
Sin floods don't happen nearly as much anymore because systems are set to detect a massive number of incoming sins and drop them. And so we never get to that point where the system is left holding open sockets for connections that will never come. So the attackers figure out a countermeasure for the countermeasure, and that's where UDP comes in.
And when you consider that a large portion of traffic on the internet is starting to move towards UDP, all you've gotta do is fire up a web browser made by Google that uses quick, and you'll know that most of it is UDP. Now you'll see that this is not easy to combat because unlike TCP, which is very ordered and regimented and polite, UDP is none of those things. Um, if TCP is somebody calling you on the phone, UDP is somebody driving past you and shouting at the top of their lungs as they drive away, not so bad unless it's a parade of people doing that and completely blocking anyone's ability to get to you.
The other problem that I have with this, of course, is Mariah, uh, I think that it in the future when we're all old and gray and our kids are learning about this stuff, the Marai botnet is gonna go down in history as one of the biggest face palm events that we could have possibly seen. Who knew that releasing a whole bunch of very capable IOT devices on the internet with a hardcoded backdoor that can't be removed was gonna end up being this consequential to traffic and knocking sites offline and things like that. I mean, we don't even have the luxury of these being run by Intel Atom processors where they effectively have an expiration date when the system crashes.
These things are gonna be around for a while. I mean, I'm not saying that someone needs to find a way to create software that would create a race condition inside the CPU of a Mariah camera cause it to overheat and possibly SL itself and get knocked offline. I'm not saying that at all, because that would be bad.
I'm just saying if it happened, it might be helpful, allegedly. But don't do that because that would be bad. I think we're gonna have to start finding ways to get more creative about the way that we have to maybe fight these UDP floods, uh, because the next attack's probably gonna be on the order of 12 terabits per second and transfer 60 terabits of data in that short amount of time.
And woe be to the CloudFlare customer that is on the receiving end of that because that ladies and gentlemen is a tidal wave that nobody can hold back. So I hope that we can solve this before we have to get really creative in how we solve things. 4 billion in an effort to boost their AI data center business.
Alpha Wave specializes in high speed connectivity that will strengthen Qualcomm's processors and help expand their place in the cloud and AI markets. Of course, this is a proposal because the deal won't likely close until early of 2026, but it does have strong support from Alpha Wave's board and shareholders. It also marks a key step in Qualcomm's efforts to grow beyond smartphones and into the data center and AI computing space.
And we've heard about this a lot because as a lot of AI data centers start shifting towards arm architecture, traditional arm stalwarts like Qualcomm really wanna bite at that Apple because it will give them a diversified business portfolio in order to avoid the constant treadmill of phone upgrades and potentially, uh, alienating suppliers and, uh, partners in the space as we've seen between Apple and Qualcomm over the last few years. Al, do you think that Qualcomm acquiring Alpha Wave is gonna help them get that AI dollar? I think that's very clearly the objective here is that, uh, there, there is an arms race going on to own the probably second player space in, uh, AI data centers would acknowledge that Nvidia currently holds the the top place there.
Uh, but there is quite a lot of movement around around behind that. So, uh, Qualcomm have their hexagon npu, uh, that would be very assistive here in, um, building out their, their, uh, platform for AI in the data center along with their, uh, our own, uh, CPUs, uh, say arm based CPUs, very power efficient and uh, very easy to scale outwards to lots of cores without, again, huge power loads. So yeah, they seem like a really good thing to see in, uh, AI data centers.
Additionally, also in in AI inside laptops, we've seen the Qualcomm, uh, co-pilot PCs turn up maybe not as warm a reception to those as we would've liked, or at least that Qualcomm would've liked to have seen. But definitely AI in the data center is a big growth space. Uh, alpha wave themselves, uh, they chose, their board chose to take an all cash offer.
They interestingly declined to take something that was shares in Qualcomm, which was definitely on the board apparently. 4 billion for a a London based company, nice to see. Uh, that does offer quite a, a premium on the current price for, uh, Alf worth, uh, 96% premium on the current price and does, as you say, need to get regulatory approval.
And also also, uh, shareholder approval needs to hit 75% shareholder approval for this to go ahead as well. But it is definitely aimed at data center compute, getting connectivity between large numbers of CPUs and uh, and, and accelerators in large data centers. Does this mean we, we will see a new architecture maybe not using Infinity Band and ethernet for connectivity?
Unlikely, we'll likely to see this end up with a whole lot of ethernet connectivity around, but possibly this connectivity that from Alpha Wave is gonna be really good for scaling out a single system with large numbers of NPUs and, and large numbers of arm calls alongside it, and then providing ethernet for connectivity beyond. So it'll be interesting to see it progress, assuming it does actually go ahead and, uh, it will be interesting to see whether Qualcomm can take away some of the market share that is being held by Nvidia or whether they're going to be scrapping with VMD and, uh, Intel for being the second player in that market. Chinese company Quantum Ctech has launched the Ezq engine version two.
It's a powerful and affordable quantum control system that can support over a thousand qubits that's nearly getting to a large enough size to be useful and is 10 times more efficient than its earlier version built using Chinese hardware costs less than a similar foreign system and is being tested for use for up to 5,000 qubits. Hmm. It's already performed well on a 504 IC quantum computer and could help the company compete with global leaders like IBM Quantum CT is also working on a system to manage 10,000 qubits aiming to push ahead in the race for commercial quantum computing.
Founded in 2009, the company went public in 2020 and continues to invest heavily in research despite operating at a continuing loss, as you might expect with such a, a high cost early stage development. Tom Quantum is, is all very cool and wonderful, and larger numbers of qubits is great, but don't we have some problems with error correction and getting reliable results out of these larger collections of qubits? Al you nailed it, and I think that's one of the things that they're trying to solve here.
But before we get to that, whether or not they totally realized what they did by naming this thing quantum ctech, really as in ctech astronomy, too many secrets, uh, you sneaker fans will know what I'm talking about. Um, it, it really matters here because this system is designed to control quantum computers to increase their resolution, provide better error correction, and effectively make them into a force multiplier. 'cause we've talked about this a number of times on the rundown when there's a new quantum, uh, release of, you can give it all the horsepower in the world, but if you can't fix the error resolution problem, you don't really have much.
It's, uh, like I said before, it's like giving, uh, someone a Ferrari with no breaks, all the power in the world, but no control. And that's what we're looking at here, is this system is designed to provide that control. By enhancing the resolution, you are going to have errors that fall out.
You're gonna effectively multiply the capabilities of those qubits, which means the system runs more efficiently and provides better results. Hmm. Where have I seen a Chinese system built on other research that is cheaper and provides better results for less investment?
If you said deep seek, you win the prize. That is exactly what's going on here, is that a company is looking at development that's been going on, they see the need and they build around it. China is doing a very good job of building quantum computers.
They are competing with IBM. We know that because they are, you know, the, the cubic counts are going up and we're hearing about their successes. But again, it's not just about raw horsepower.
And so this to me is kind of like the mated horse in this particular covered wagon, if you wanna call it that. By having bandwidth and error correction, I'm making the whole system better overall. And that means that people can really start developing for these systems knowing that their reliable outputs aren't gonna be wasted in this.
I mean, when you look at some of the specs of those IBM quantum computers that are out there, what is it? Condor processor has like 1100 qubits, but how many of them are dedicated for error correction? And, and the fewer error correction bits you have, the better the data you get out of the system.
And remember, every one of the qubits that you use for error correction is effectively wasting resources because in order for it to be a, uh, data point that you can measure, it has to be super cooled and liquid helium is not cheap. Uh, eventually we'll get to a point where we won't have to do that anymore, but I don't know when that's gonna be on the horizon. And when you look at some of the way far out crazy stuff, like the Microsoft quantum computer that we talked about months ago, like this to me is more in the realm of reality because A, the numbers look right, but B, the people doing the development are focusing on the problem, which is good data, not the perceived problem, which is just how fast it can go.
Like for example, if you've ever measured firewall throughput, you know, you get this crazy number of packets, but they're all 64 bytes because that's the smallest packet size that can go through the firewall. Well, what happens if I'm playing video streams? How many packets is that?
Well, we don't know. We've never tested it. That's funny.
'cause that's a real world application. And that's the thing here is I wanna see how this system performs in a real world application. Because it's one thing to say, you know, Q Engine is the best and it works really well on these workloads that we've already used before.
So we know that the answer's right when we do it, throw something at it that you don't know what the outcome is gonna be. And that should be a real measure of how well it tests out. But again, something to keep an eye on.
Remember kids, make sure you're implementing those new quantum resistant encryption protocols sooner rather than later. So you're not left holding the bag whenever this thing goes live. Teradata has expanded its AI factory platform to work with on-premises data centers, giving organizations, especially the ones in highly regulated industries, more control and lower costs when they end up building the inevitable AI applications.
This platform includes tools for managing data, AI models and integrations with services like those found in Nvidia, making it easier for IT teams to deploy AI without fully relying on the cloud. Al we've seen a lot of buzz from people who are wanting to build AI into their things, but they can't get around that pesky regulator. Is this going to be a way for Teradata to break up in that market and just run with it?
Absolutely, and I think there's, there's a few drivers for bringing the actual production part of AI on premises. We know the cloud is a great place, as they say it's a great cloud, is a great place to, to try and to fail, but it can be an expensive place to try and succeed. And so we definitely see large language models being developed on, on the cloud, particularly ones that are using open sources for all of their data, at least allegedly open sources.
And that's what we see for all of the foundation models. But those foundation models are not what organizations are using to build their AI applications to gain AI insights within their business applications. Uh, fine tuned models and then inference being run from those fine tuned models as the way to actually generate business value, often that fine tuning and definitely the inference uses a whole lot of data, which is proprietary and highly valuable within the organization.
As you say, Tom is often highly regulated and it's, these are the drivers from retaining that data on premises where you've got physical control of where it is. And there's a stronger perception also that you can stop leakage back into the original AI model because of course that that model's running on your premises. You can control whether the data you feed it is being used to train it somewhere.
Certainly whether it's being used be, uh, the data you feed it is being used to train it for your competitors, as might happen if you feed your data into an open source model out in the public location. So running on premises, uh, or at least within your own tenancy in a cloud seems to be a, a good methodology. And particularly we, we see far more use of AI inference desired to be run on premises.
One of the things we saw quite frequently in AI infrastructure field day events here at Tech Field Day is that this is hard work. Building the infrastructure to run AI at any large scale is, is really hard work. There's a bit of work to be done to get it to work for just one use case.
But when you start looking at addressing 30, 40, 50, a hundred, 200 use cases in within your organization, you're talking about building a fully multi-tenant, highly scalable infrastructure for running inference. And this is where the challenges really mount up. And it's against this backdrop that Teradata is taking their AI factory, which historically has been part of their advantage cloud service and saying, well, you can deploy that out on premises.
We can reduce the load required of the effort required by your in-house team to get to that multi-tenant, multi-use case AI infrastructure whilst retaining all of your data on premises. Whether that's purely because you need it there for performance reasons. If you're u using realtime updating data, well the closer your computers, your inferences to where that data's being generated, the lower latency you can achieve for that realtime data, um, or whether it is truly just about compliance about we're not allowed to store this elsewhere.
And talking to somebody about sovereign clouds last, uh, a couple of days ago, and the idea that you might actually have to be certain that all of your cloud data was within the same, uh, sovereign space. I know in France, a French company has to retain all of its, uh, data about its French operations on French soil. These are all challenges that are much harder to fulfill, to achieve when you're using public cloud.
Uh, if you know you've physically got it within a data center that is in your Leon, uh, location, then you can absolutely be certain it's within, within France. So yes, I think this is definitely about easing that on ramp, making it simpler to get started, to get beyond a couple of simple use cases of AI and get widespread AI adoption within your organization. Teradata isn't the first one to offer an AI factory on premises.
I'm sure they won't be the last, but if you are highly committed into Teradata, if it's the way you store the majority of your business data, then their AI factory seems like a very good way to work. Because being data centric, thinking very clearly about what data you have that is gonna bring value, uh, through your AI is gonna be central to this. There's been another secret hacking campaign, uh, likely from a Chinese group and it's infected over a thousand old routers and iot devices.
We were just talking about, Mariah, this could be the new one. Uh, most of these devices are in the US and Asia, and these devices are running on a, um, or forming together a hidden network called Lap Dogs that helps attackers hide and launch cyber attacks. The attackers use special malware pretending to be from the Los Angeles police, the LAPD, so maybe it should be the L lap D OGs rather than the lap dogs, uh, to get deep control of these devices.
This network could be used, uh, to disrupt important systems in the future. It could be an attack vector against infrastructure. Uh, experts warn to watch for strange encrypted connections coming from home devices to catch these attacks.
I can't see many people's home networks being able to identify these devices. And if it's iot and old routers, well, so these things have infinite lifetime or can we get them to burn with fire? Um, well maybe I'm, I mean, allegedly we could potentially do that.
I thought this is kind of brilliant, that effectively what they're doing is they're trying to create a foothold into a network that's standard security hacking parlance. They are, you know, uh, escalating privilege for the local user account. If it has enough privileges to drop things into the Etsy folder, it'll do that.
And then the system will just reboot. Um, the whole thing with it. Using the certificate from the LAPD purporting to be from the LAPD was kind of neat.
Uh, you know, it's, uh, who, who wants to question whether or not law enforcement's putting something on my machine that I think is, is kind of where it's coming from. Also, that's why the system got its name lap dogs. 'cause you know, LAPD Lab Lab D Lab, oh hey, remember last week when we talked about unifying that naming convention thing?
Uh, yeah, that gives people that are, uh, failed poetry writers a a little less motivation to be cute and creative. Um, but anyway, the other thing that I thought was kind of interesting from this article is who they think is behind it. Again, we don't know this for sure, but you know how it is when all signs point to Yes.
Thank you. Magic Hayball. Uh, it's one of the typhoon groups, uh, specifically I think they said this one's probably Volt Typhoon, uh, which was a new one that I wasn't aware of.
Uh, I hopefully that Volt Typhoon and Salt Typhoon, uh, won't, uh, join together to create Captain Typhoon, which of course for all of us nineties kids would be the ultimate form of a hacker, uh, with the, you know, crystal body and green hair and everything. Um, now this, this means that there's an escalation, right? Is they are trying to do what they did in the hacking campaign that we first heard about late last year where they got a foothold into networking devices.
Now they're trying to do it with systems that process that data as opposed to transiting that data. It's the thing that people do. They want a foothold into the system.
They want to be able to decipher things going through it. And by creating the secure connection and effectively having the system dial out through 4 43 or what have you, it's uh, it's pretty hard to, uh, look at that encrypted traffic and do something about it. So beyond the lookout kiddos, if the LAPD starts dropping certificates on your machine and you don't live in la you might be a really good idea to double check that.
And I'm hoping that whatever certificates that they're using that are invalid or can be revoked will be revoked very soon by whoever issued them or if they're self signed. Uh, simply because this, this is that escalation phase, right? Once that certificate's on your system, they can do anything they want with it.
And there's not a whole lot you can do to stop that. So I hope somebody is paying attention at the wheel here. We wanted to take a closer look at an event that happened last week that several of our future group folks were taking part in, and that is the annual Amazon Web Services Security Conference, also known as AWS Reinforce for 2025.
AWS introduced some new key security upgrades, including expanded identity tools, enhanced code and threat detection, along with their inspector and guard duty tools, as well as easier deployment through improved web application firewall and just plain old firewall features. Uh, new ciso, Amy Herzog, no relation to the deep voiced guy, um, emphasized in identity security as being a key component while AWS in general reinforced its focus on automation, secure deployment and ecosystem collaboration. Now, Al you and I weren't there because, well, we were focused on some other things, but there's an excellent writeup on the futureum Group website that we wanted to highlight.
What were some of your big takeaways from reinforce based on the excellent writing from Fernando and Krista and Mitch? Well, I think it, it's just a continuing sharpening of the pencil, uh, keeping things very focused on security At A-W-S-A-W-S has always, uh, believed security was very important. Uh, even though they give you plenty of tools to remove security from yourself as a, as a customer.
Um, that's a, an interesting part of that shared responsibility model. I've always been a fan of, uh, AWS inspector. Uh, when I was teaching the AWS training courses, it was one of the things I always demoed was let's just scan over everything you've got and see what vulnerabilities are here and let's better yet build that into the automation system that you're gonna use to build out your infrastructure.
Put it in your CICD pipeline. Um, I like that guard duty is getting some more capabilities. Guard duty is the, the real time analytics, and it was one of the first places that I saw, uh, observing what's going on with DNS as being used as a way of identifying threats, uh, that are within your organization.
Of course, that's a pretty well known technique these days to identify whether, uh, data's being exfiltrated by DNS or whether, uh, requests are being sent back to command and control through DNS. But guard duty is getting more awareness of other parts of infrastructure, being able to see in real time things like, uh, the, uh, Kubernetes EKS service logs and being, getting more insight about what's supposed to be happening and what's actually looks like threats going on. So it's nice to see continuing improvements in there.
Uh, there's some challenges around configuring web application firewall and CloudFront and, uh, the network firewall and getting things consistent and happy together. And the more of that that can be automated. And that's one of the things we see in here is threat feeds being sent in, uh, to the network firewall, not just web application firewall.
Uh, we also saw in some improvements to AWS Shield, which is AWS's DDoS protection, um, or another string of the DDoS protection components that AWS has. I think all good, great improvements to see continuing work in there. Um, seems, seems to be really positive stuff.
Um, Tom, you are much more deeply in the weeds of the networking security elements here. Um, what do you see in this? I saw Amazon's attempt to try to show their users that they do care about security because the lack of security, or in some cases the lack of tools to prevent me from shooting myself in the foot could potentially drive customers off of the platform.
And we've seen this time and time again, how many times have we talked about a story here on the rundown, or have you seen something published online of misconfigured permissions on an S3 bucket or some kind of weird access policy that allowed people to jump into the, the squishy center of your VPC? And then the next thing you know, they, they own everything. These are not hard problems to solve, and I know they're not hard problems to solve because we solved them.
We solved them years ago by creating robust perimeter security by allowing things like VPNs. But the key is that we hardened the perimeter before we started building the squishy center. And that is a opposite relation that you have in cloud platforms like AWS you wanna build the squishy center first because that's where the value is.
And we'll, we'll worry about fixing it later, we'll protect it later, which is the why that we all tell ourselves, we'll, we'll do the hard stuff later as long as it just works. And then that becomes, well, I don't wanna break it because if I break it then someone's going to yell at me. And too much of our system is relying on this so we'll, we just won't worry about it.
And then guess what? You're on the news and you don't really want be on the news for stuff like this. I think that Amazon realizes that the majority of their customers are not security gurus.
And so they need to make this as simple as clicking a button. So making easy to deploy web application firewalls is a great start. I can remember seeing some of the very first web application firewalls, like, I wanna say it was back when I was a delegate at Tech Field Day and we saw Menos right after they got bought by Juniper.
I was like, man, that's a really cool thing, really powerful, really complicated. We've distilled the essence of what a web application firewall can do down now so that it's a lot easier to deploy. But you've gotta bridge that gap.
And the gap is if they're so easy to deploy, why aren't you deploying them on your systems? And I think that that is a challenge that Amazon is gonna continue to have. They can do everything for you.
They can make it easy to deploy. They can make the buttons green and red and make you click on them, but you have to be the one to do it, just like you have to be the one to secure your S3 buckets to do all of the things. And if you don't do those things well, Amazon's not gonna take the blame for you because all the tools are there, but all it takes is going to a provider like, um, I don't know, a Microsoft or a Google where all of those things are automatically done for you.
And now it's like, well, guess what? I don't really care. Go for it.
Uh, we'll just move all of our secure workloads over here and we'll let the stuff we don't really care about running AWS 'cause it's kind of cheap. And I like this Route 53 tool. So I, I don't know, maybe at the end of the day Amazon will keep a few more customers, but with a new CISO in the house, they have to be iterative on this.
They have to be ready to create user friction to provide better security. And look, I know, and you know, that creating friction with users is the fastest way to get security disabled, but in this particular case, lack of friction is going to cause people to slide right into those news articles where everything keeps getting owned and shared and stolen and nobody wants that. And if you get embarrassed enough, you'll move off of that platform.
I mean, Al do you, do you think that people are willing to pay a little more to be a little more secure? I think smart people are definitely prepared to pay a little more, but I think you, you've really hit the, um, hit the nail on the head when when you talk about it being essentially lazy, you've got to make your product work for the people who are lazy or the other way to look at it, the people who are busy doing something else. And so I think this is where AWS is a little bit being bitten by the way they've structured the organization, their two pizza teams builds a service and has free freedom and autonomy to do their own thing.
Doesn't make it easy to unify everything. Doesn't make it easy to bring all of the pieces of that security solution together. And you've gotta make it easy.
You've gotta make the security thing easy. So not sure that I agree about, um, adding more friction. I think you're actually reducing friction when you make it easy to build the security in.
But if you force people to have a hard time building in the security, yeah, that's when you're gonna fail. You. You've gotta make building security on top of whatever your application is.
Simple, seamless, easy to deploy without just allowing any, any, any, any, any. Well let's hope for the best because if it doesn't pan out, uh, Amy Herzog may be out and we may be forced to listen to keynotes from Werner Herzog, which honestly would be really cool to hear, but really soul crushing because anything that man says is just dour. But you know what's not is upcoming field day events.
'cause we try to keep those happy and cheerful and bring you lots of cool stuff. The next one's coming up in just a couple of weeks because I'm gonna be back in Silicon Valley for networking field day. We have, uh, great presentations coming up from companies like C Packet and h HP Aruba Networking.
com and check out the full list of people who are gonna be presenting and the full lineup of delegates. There's several new names on that list, you're not gonna wanna miss them. Then we're gonna skip ahead another month 'cause I hear it gets hot in the summer, but we are gonna be in Cleveland, Ohio of all places on August 19th and 20th for Tech Field Day Extra.
It's Share Cleveland. That's right. It's gonna be a real quick drive for my friend Steven FoST to head up and talk about all the cool things happening at Share Cleveland.
There'll be more details to come on the Tech Field Day website and then we're jumping into my favorite month of the year, September Al what have you got coming up? Well, once the temperatures start to even off a little bit and it's a little more tolerable to be up in the Northern Hemisphere in September, I have AI infrastructure Field Day returning and it's already starting to fill up just like the last AI infrastructure field day got massive. Uh, so we have Broadcom and Mirandas, we have, uh, my other screen, uh, we also have Hammer Space and Satra already signed up and that's making us for a, a good event when we're quite a way out from it.
So I'm looking forward to having another massive event and lot of fun back in the Valley area. And of course a couple of weeks after that, Tom, you get the baton back for Security Field Day again. I do, we are gonna be talking about more great security things because you know it's gonna be post black hat and everyone's gonna have all their stuff sorted out.
They're gonna want to talk to us. We actually have our first presentation from a company called Square X. You can read more about what I thought about Square X's, interesting browser security techniques if you head over to my LinkedIn page.
But we will be expecting more great companies to join up there very soon. com and uh, check those out as they are listed. And you might wanna do that for all of the other things that we've got going on because I can tell you for a fact there's at least two more things that are gonna be listed on the website very soon that you're not gonna wanna miss.
But I'm not gonna tell you what they are because in the industry we call that a tease, but we won't tease you because you know that we'll be back next week with more great tech Field day rundown news action. And you're probably thinking to yourself, well Tom, I don't wanna miss that because if I do I'm gonna be heartbroken and I'm gonna have to listen to a lot of Werner Herzog novels. Don't go that far.
All you gotta do is subscribe to our YouTube channel so you get notified whenever we publish a new video. Or you can check out our podcast feed where you can listen to the dult tones of my voice and Alistair's as well on, uh, your favorite podcast application of choice, maybe when you're out, uh, mowing the Yard, or in Al's case, uh, we're using the snowblower. I don't know if they snow in the southern hemisphere, but you can also, uh, check out the other great stuff that we published on the Future and Group website, including some of the articles that we linked here today, as well as Techstrong It where we publish a lot of the great coverage from the events that we've been doing.
We've got some new posts going up that you're gonna wanna check out some perspectives that we have on some great things. And don't forget to tune in next Wednesday afternoon for the next episode of The Rundown, when we'll be one week closer to Christmas, no matter if that's warm or cold for you. But we'll also have all of the great stuff that happened from the news, probably some coverage of HP Discover since that's going on this week.
We'll, uh, round up that news and be with you then. But until then, for myself and for Al and all the great other people that do the Tech Field Day rundown, stay cool everyone, unless you're in the northern nor uh, Southern Hemisphere, in which case, stay warm and we'll see you for the next rundown.