The Rise of AI in DevSecOps: Automating Security & Managing Risk | TSG Ep. 947
Guest host Jon Swartz is joined by Ira Winkler and Fred Wilmot to explore how AI is transforming DevSecOps, from automating remediation to managing vulnerabilities across the entire software development lifecycle.
The panel highlights that 75% of IT professionals already use AI, with another 13% planning to adopt it soon. The conversation dives deep into the benefits and risks of AI integration, including trust, complexity, and security challenges, while calling out the marketing bias often found in industry surveys. The gang emphasizes the importance of balancing automation with human oversight and ensuring reliable, transparent data in the evolving AI-driven security ecosystem.
Transcript
Hey there, survey says, widespread adoption of AI to improve DevSecOps. You're watching Textron Gang. Welcome to Textron Gang.
It's Friday, the week is finally over. I'm John Schwartz. I just got back from Las Vegas at Oracle AI World, and I'm spending the day at Dreamforce.
Uh, I had to spend most of the day there, so it's been a long week. And I'm with us. Uh, we have two great guests.
We usually have on Thursdays, we have Ira Winkler, the czar of, uh, cybersecurity. And Fred Wilman, who is our DevSecOps expert. Mike, uh, Baard is still in Europe as far as I know, and Alan is somewhere in Texas.
I think he's driving north. That's the latest I've heard. Um, in any event, I'm back in Silicon Valley and we're gonna start off with the survey that Mike Baard wrote about in Dev DevOps on our website.
He, uh, looked at a global survey of about a thousand IT professionals who are responsible for application security, and he found that, and it found that three quarters are using AI with another 13% considering adoption. This is like a very interesting term of events and it's something that Fred knows a lot about. And I'm gonna turn it over to Fred and maybe we can riff, especially between Fred and Ira about this topic.
Um, Fred, what did you, what'd you make of it? Well, I think, um, first thing is, you know, a thousand folks, probably not statistically significant in the DevSecOps universe, but what I would say is, uh, this illustrates the point we think we already know. We've been talking about a lot.
50% of the universe has adopted AI in some capacity. 50% of those folks are using it effectively. In this case, uh, what we're talking about is how do we rely on a software development lifecycle to get to a place where we're managing vulnerabilities in the software development lifecycle, not the deployment lifecycle.
So when we think about the statistics of what happens and the, and the, and the notion of what is the faith in AI versus regular engineering developers, right? Some of the metrics we use to gauge engineering, uh, quality, right, is the number of vulnerabilities, uh, that, that our code ships with the rate of fixing our vulnerabilities in code we've deployed. And you know, here what we're doing is we're talking about sort of enacting another set of developments, uh, requirements that may or may not think about the code practices of whatever organization I happen to be at.
So what's interesting about it is that the theory that AI produces more of vulnerabilities is a good one. Um, but the important part of that is that the rate of change with the current construct is people are adopting it anyway because the requirements are such. So they may not trust it, but they might implement it in this particular case.
And so what they're doing is they're also starting to orchestrate other ways to use AI to automate the process flow of determining what they need to remediate. So let's imagine today, and Ira, IRA and I, we'll talk about this, right? Uh, let's imagine today that most companies have, I don't know, 10,000 vulnerabilities, right?
Broadly distributed of that. There's a small percentage of really critical ones of that. There's a larger percentage of ones that might be high from a a, a, a criticality perspective.
A lot of those don't get patched for any number of reasons, but the critical moments of those are what if those could be passed before they became what they are? And do we need to have the persistence of those types of exploitable vulnerabilities, something be, become part of our operational security problems? So my advocacy here will be this, right?
We have tracked over the last two weeks, uh, 10 different, um, ODAY exploits dropped in five or six different products. Uh, that's almost one every other day. And at more than half of those are CEEs.
So keeping pace with what the rest of the universe is doing from an adversary perspective, it almost doesn't matter whether or not you, you trust ai, the simple scalable problem of not being able to patch as much in production as you really like to, you have already, we don't do a great job at hygiene. Why not? Is really the question.
Yeah, because I would actually have to add to that because usually I'm critical of people using the term ai say they're using ai. 'cause it says like 77% of people used AI as developers. I mean, frankly, it's a hundred percent at this point, right, exactly.
Don't realize. Exactly. Yeah.
I mean, I set my alarm with AI by saying at my wake up alarm for 8:00 AM and people are not understanding how it's embedded in what they're doing. But in this case, what I'm looking at and reading, assuming it's correct, is that they're actually using tools which are automating the patching of software, reducing the likelihood of vulnerabilities and so on. Because a lot of vulnerabilities, again, a little tweak here and there, you know, makes a big difference between a major crash and like a, a perfect program.
And so in this case, what they're doing is assuming the tools actually work, we are really going ahead and using ai. And I hate, again, AI use Dr. Evil quotes.
I know in ways it's supposed to be used, and that's the most critical factor that we need to understand. We're using it in ways that, again, it's a mathematical algorithm to fix the software and people are using it to speed up fixing of software. You know, can I, should I draw any conclusions?
There's this one statistic that is kind of jumps out at me. It was that a third of these people who were told said that more than half of the, their application security issues identified by al AI tooling are now acted upon without human review. How is that, is that fairly significant, or does that surprise you at all?
If, if you said that was 75%, I'd be shocked. But again, let's look at this backlog of vulnerabilities, right? If, let's imagine there's 10,000, okay, at least half of those are easy, obvious, simple, not intrusive, right?
In the way of code. So I would think about that as, okay, the lowest hanging fruit is easily gathered, and that's probably exactly what's happening here for things that we know, but it's the process of remediation that's painful, right? When it's already, uh, when it's already pushed out into production.
So I think that's a healthy statistic. Uh, i, I, I agree that it's probably the right sort of metric, the difference between, you know, 50% and 80% is really significant. I think that's gonna be the interesting point there.
Uh, I rev I'm gonna ask you again, and I, again, I know you, I know I, I know about your fix, I know you about your AI fixation and, and I agree with you on many, on many levels. Um, did, did, does. So in a sense, can I just ask a question that this is something that always goes through my mind whenever we talk about security and as kind of like a last measure with the whole issue of, of ai and based on some of these survey responses, um, is it, is it, is it, is it going to make, is it gonna make the job of security professionals easier?
Or is it gonna add more headaches in the, in, in, in the immediate, in the immediate term. So in the first place, I hate surveys because a lot of surveys are done for marketing purposes. Yeah.
This was, I mean, I'm not saying, I'm not gonna say that about this survey, but they're always self-serving and they're almost always self-serving. And they're provided by a company that's selling something to solve the problem that they bring up. You are, right.
Well, well, I don't necessarily disagree with that, but so most surveys, they ask people questions that are poorly defined. Like again, saying, do you use AI in softening software security? Or to do whatever the answer is?
Yes, no matter what. The answer should be a hundred percent given how AI is embedded in just about everything we're doing, because AI is really parts of many infrastructures to begin with, but they need to better define what they mean by ai. They need to better define what type of ai.
In this case, when I read the report, you know, I was like, okay, they're actually using AI in the right ways when they're talking about, okay, automated patching of software. That is not something that is a nebulous function of ai. And again, I do think a lot of surveys are causing problems and everybody's all of a sudden saying, wow, everybody's using ai.
I should be using it too. Or nobody's using ai, I shouldn't be using it. Again, the fundamental question I keep coming back to is what are they describing regarding AI in the case?
And I care more about a function than I care about the word ai. If they're talking about automated patching, by definition, that's gonna be some form of AI algorithm embedded within a software tool that they're using. And so I wish they would say, are you using automated patching as opposed to using ai?
Because AI right now is just a buzzword that's poorly applied and interpreted by people who have no idea what AI means, right? Alright. That, that seems to be applying to a lot of the companies.
They were doing some of these conferences. I'm not, I'm not going to specifically finger, uh, Oracle or Salesforce, but I mean, it's just, it just, uh, you know what I mean? It's just like it, these used to be called, uh, Oracle Cloud World.
Now it's Oracle AI world. I mean, I, I, my eyes glaze at these things. Hey, Fred, do you have any, uh, final thoughts on this?
Uh, we we're gonna move on to the next topic, but I wanna let you get the final word in. Yeah, just real quick. I think the, the, the way that we talk about this is, is also the way, the way that we talk about our concerns about ai, right?
And I'll use IRA's, AI quotes in here. It's the same way we talk about some of the things that are, if, if we were a VP of engineering at any company, right? If we're saying that some of the concerns we have about AI is integration complexity, okay?
That's every tool on the planet, uh, 46% lack of trust and results, 36%, okay? As a architect, I might find that to be also concerning about my junior devs poor explanation of security findings. That's every product in the market, international, or excuse me, skills gaps, right?
Again, junior developers and, uh, regulatory or compliance concerns accounts for 33%. So that sounds like a very normal distribution to me of the same sort of, uh, shenanigans that I would have, right? As a CISO at, you know, said company with a VP of ENG that would have the dialogue about where's making the fix?
And here's the critical part. Security folks aren't fixing these vulnerabilities, right? That's never really the way that it works.
Always engineers. And so when we think about that, that's important to understand that we're also crossing over some of the capability places that normally we would have infighting about. So I think if we have normal statistics and we have this conversion that's happening here, I think it's terrific.
You know, uh, despite our kind of, uh, hesitancy around surveys and our, our wariness, I think this one was an interesting one. And, um, it bears, bears watching. So, um, enough on that, uh, we're gonna be coming back with a field report from Ira on cruise con, uh, in a second.
I can't wait to hear what happened on the, on the, on the water. Uh, we'll be back in a moment. You've Earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions. Your home life included that work. You are protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. We're back with the, uh, B block.
And, uh, IRA was just on a cruise con, which I, I'm very always interested in this. So this is something that you organize. Maybe you can tell us a little bit about when it happened.
I think you're at an airport right now. Are you, are you co are you returning home or are you going somewhere else? I'm just trying to figure out the logistics of your travels.
Um, nah. Yeah, cruise con ended, um, uh, it was October, well, the last one, cruise Con West happened October 2nd through sixth. And now I am flying to Minneapolis to speak at an isaka event today.
So I just happened to be at the airport and I rushed to the airport and of course found out my flight's an hour late. So anyway, um, ah, dear. And I could have taken this from the sanctity of my home anyway.
Um, yeah, but Cruise Con, the way I came up with it was, you know, I was, I've been chief security architect at Walmart, chief Security strategist at hp, and in those position positions, you get invited to events most people don't know existed. Like some people might see, for example, the teammate events because they promote those and you know, where they're sitting in a mud bath in the Florida Keys. And anyway, what happened was, the thing about those events is content kind of Okay, content, sometimes original, like for example, wing Capital, awesome events bring in top people from, you know, top companies like running their ai, running their economics groups and stuff like that.
But what I tried to do was, I mean, I'm sitting around in the desert with these Fortune 100 CISOs and I'm thinking, we are the last group of people that need something like this. You know, for all practical purposes, fortune 100 CISOs make a lot of money. They have all the resources in the world, but they also have access.
Like, you know, I used to joke I could pick up a phone and get like the CEO of Microsoft on the phone. Probably true, but not that I would ever do it. But what I thought what needed to happen is to recreate these events for the average cybersecurity professional so that they can grow and not just take advantage of this if they hit the pinnacle of the career.
So I created essentially a retreat style event where I bring in top speakers who usually speak at some of those events, and I put them in an area that's kind of like a nice a-list area, in this case, Royal Caribbean cruise ships. And we, you know, and the content is there, but more important, it's the networking that happens and, you know, so people are like developing long-term friendships because you have nowhere else to go. I mean, it sounds bad, but it's good.
So what are the rules? Can I can interject. I have to interject.
One of the rules I have as a reporter, and as the, I'm speaking as a reporter, never go on a boat. So I was offered once a couple of times to go on Larry Ellison's yachts, but even, even as much as I was curious about the idea as a press, as a reporter, you can't get off. You're trapped.
But in the case of your case, uh, these are folks who wanna be together, who wanna network, who want to have some, uh, relative serenity from the chaos of a trade show. Well, just for example. I mean, the vendors don't have, if the vendors are aggressive, we can kick them off, you know, or kick them out.
Exactly. And that's one thing. And frankly, a vendor on this, if they have five days to network and get to know, get, develop a quality connection.
And if they can't do that, they shouldn't be a vendor. But, you know, so they don't have to be aggressive, frankly, they're, they enhance the experience by buying people more drinks and stuff like that. And just to the point on the next, on Cruise Con 2026 in February, we're gonna have Chris Inglis talking about the first time that I know of Edward Snowden's incidents and treason.
And that's gonna happen on Cruise Con 2026 on a boat. And if reporters want to come, they have to get on that boat. Now.
That's where that's worth going on. Okay. Yeah.
So we have that. But, you know, fundamentally, I mean, we have a retreat style that began with a C de in this case, a deputy CISO asked me anything. 'cause the first one, and, and the next one we're gonna have a CISO asked me anything.
But the feedback we got was that it was awesome, and we had to redo the event, you know, redo the panels. But the feedback was that for the first one, ciso, these hearing from these Fortune 100 CISOs was great, but the, a little bit of the information wasn't relatable. So I went with Deputy CISOs on the Cruise Con West as it was known, and people got a lot of good insight on how to get to that level in their career.
And then we had the, the next day was, um, Bob, uh, sorry, I'm so bad with names. Bob BigMan, who was the former CSO of the CIA, and we had him talking about, you know, when these people leave the government, they do more work than when they were at the government frequently. And he was talking about from doing assessments and stopping nation state attacks, what works and what doesn't.
And frankly, a lot of the things we think work don't, and a lot of the things we think are a waste of time are the most valuable things. And that's what Bob highlighted. Then we went on and we had people, for example, like Tim Youngblood, talk about Agent ai.
We had, um, John, John, what did he, what before you, what did you think of AG Agentic ai? Because I, I'm starting to get so many different opinions about it, good and bad. Well, AG agentic AI is the way things are gonna go, whether you like it or not, like we spoke about in the last block, everybody's using things, but even what was happening with automated patching of code is essentially agentic ai, where an AI does a function without, per se, too much human intervention.
And these things are gonna happen. They happen all the time. A self-driving vehicle is essentially just one massive agentic AI and a lot of other things like, you know, essentially it's an AI doing calculations and making decisions.
I'm oversimplifying it, but also being able to enact on the dis or act on the decisions without a manual intervention. And these things are happening and they're gonna continue to happen. So that's one thing.
And then we went on, we had, um, ironically, and we'll talk about a little bit in the next session with like Will I am, but we had Dan Meacham, who's the CSO of Legendary Entertainment, and you know, he, in other words, he's, he's actually the CSO, so he does the red carpet security along with all like the transmission back of like, you know, dailies and stuff like that to the studios and editing pods and things. And, you know, he was telling us a little bit about hanging out with Tom Cruise and stuff like that, who he says is an awesome person. But he was talking primarily about how he made a cybersecurity program of Profit Center.
'cause during the pandemic, when they didn't have movies to secure, he ended up taking his team and using AI Dr. Evil quotes, um, to start to see where pirated merchandise is being sold. And then he start, had his team start tracking down the pirated merchandise, and then they went at, legally went after the people, and they're making millions of dollars for legendary entertainment, taking it down, merchandising piring for both their studio and ironically others.
So, you know, he spoke about that. We had, uh, I, the, the most engaged session, ironically, 'cause at my time at Walmart, it was pro, I always thought what made Walmart's program exceptional was project management and how everything was controlled, monitored and stuff like that. So I had, um, co-author on my book, you Can't Stop Stupid Tracy, who's like a guru with project management, give it.
And she's like, I hate you because it's the most boring subject ever. But she had more questions than Dan Meam had about Mickey movies. So that gives you the idea of some of these mundane topics that are really so critical.
They kind of come to life actually too, when you bring people together who are the experts, and they ask interesting questions of one another that maybe they kind of think outside the box of what they normally the box they're normally in. Well, the, the problem I will, well, the issue is, is that when you get together and you actually want to talk practicality, these mundane topics like, you know, Bob, big Man's presentation on vulnerabilities, mundane topics are more important on how do we perfect the mundane to make our cybersecurity programs the best they can be. So anyway, besides this Jar Beason spoke on, you know, personal branding, I'm gonna embarrass myself.
'cause it's hard to remember all the other people that I had, um, at any given time. But, you know, we had, I mentioned John, is this Yeah, go ahead. Is this gonna be available for people to Oh, yes.
Good question. Thanks for the, so yeah, actually, ironically with Techstrong, Alan sent a film crew over, or a camera crew, as I should call it. We don't do film, and we're doing Cruise Con virtual, I think it's November 6th.
So hopefully you'll be able to get the link there. And I think we offer that for free. So people will have all these sessions, except for one, one of the more interesting ones was, oh, Ammar Ammar iv, who used to be the lead hacker, not the person who ran 8,200, but the actual Hands-on Hacker for 8,200.
He spoke about APTs and he gave a session, which he wasn't sure how much was classified and how much wasn't classified. So he didn't want that one recorded. So anyway, that's, um, an example of what we're having with the exception of Amer's thing.
But again, Textron go to Cruise Con Virtual, and eventually it'll be pointing to that hopefully tomorrow when I, or by, by the time this airs when I get the link. Hey, and we are doing cruise. Yeah, go ahead.
Oh, no, I was gonna say, I we're kind of running outta time, but I wanted to say you did a really good job of in, of getting me interested in this because I, I really don't know. I hear a lot about it. No, I'm serious.
I hear a lot about it. And my, my eyes usually glaze over, not not about Cruise Con, but just like a lot of these events, there's too many conferences and we're in the middle of conference season. This sounds though, really useful and interesting.
I mean, I, I would like to find out more about what all these folks have to say and their experiences. com and see the 2026, and if you go by, well, Friday the 17th, probably until the end of the weekend probably, but, you know, west 25 will get you a 25% discount. But, you know, really, I mean, I'm not a fool when I put this together.
CISOs of Fortune 100 companies can get away with having a mud bath in the Florida Keys. The average person who I'm trying to get is not, is gonna have a much harder time. And so what I did was I purposefully created content that you could get nowhere else.
And I called in favors, I called in friends, I, I attend so many events, I know you know who the best are, and that's who I've recruited for these events. All right, that sounds good. Uh, uh, again, um, thank you for the, for the field report.
I, we, we appreciate it and we're gonna move on. You mentioned Will I am, and so we're gonna move on to the next segment and talk about, uh, he does, he does, uh, of several, several interviews a year. I talked with him last year at Dreamforce, and I did again this year.
He has some interesting insight into AI generated content, music and regulation. And we'll talk about that in the next segment. So we'll be right back.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group. Welcome back on a Textron Gang of Will.
I am is a fixture at the Dreamforce Show in San Francisco. Last year, I was lucky enough to talk to him about AI among other things. This year I wanted to talk to him about content and, um, his thoughts on generated music actors, et cetera.
He seemed generally open to that idea, uh, but he kind of pulled the, the, the conversation back and wanted to talk more about how as amazing and as awesome, pretty awesome as he says AI is and what it can do. His big fear is that the social media business model is gonna be applied in the agent space, which he says is gonna lead to all sorts of, and I, I can't really, I can't say what he said, but it starts with the letter F and ends with, ends with letter K. He says, we know, we know what happened with social media.
I'm, I'm afraid if unchecked, this is gonna lead to human greed. It already has, that will once again f it up. And, um, it, it, it's interesting, he, he also made a prediction about where we're gonna be by the year 2030 in terms of what we can do, how, how much more, um, interacted, interactive we will be with the, the content.
We'll be part of the content. So what I wanted to do is, I, I'm interested in both of your opinions, but especially I wanted to start with Fred, because Fred knows a lot about music based on conversations we have before the show. He's our music guy up in Seattle.
And I'm wondering, given your thoughts and your expertise in, in the creative side, and, and I I'm sure you probably know a fair amount about Will I am, what, what do you, what do you think of kind of his thoughts and where do you, where do you think the content is going in terms of generation? That's a great question. It's a really cool, uh, construct to, to sort of discuss.
I think we're gonna start to see, so, you know, today we already have the music genome. We already have the, I can match beats on, you know, pick your platform, Spotify, apple Music, uh, Bandcamp, uh, I guess I should say, uh, what was that? One starts with a p that's still around, but shouldn't be.
Uh, when you look at, uh, Pandora, when you look at all of the ways that music is constructed together today, it's really not a creator's market anymore. So you've got some diversity in how, you know, like Bandcamp for example, and SoundCloud and some other things are allowing, you know, direct interactions there with the concern of the likeness and the iteration. The feedback loops are, oh, I like the sound of that particular thing.
If I say those words out loud, right? In essence, AI gin me up 15 songs, it sounds somewhat similar to this based on a thing that I liked and produce that for me, give it back to me. And so I believe what's gonna happen is you're gonna start to see a lot of the flooding of what sounded like the pop top 40 right?
In the last 20 years. And you're gonna get an ecosystem of adjacency here. And the interesting question will be like, what is new and different?
And can you do new and different anymore? Right? They don't make music like they made it in the seventies, it's not possible to do that again.
And now, right? Are we going to simplify the context of what music streams are and music and artistry, or is it going to become overly complex, but easily imitable? Those are the questions that I have.
I think it'll be interesting to see what happens. So there, there, uh, I I'm gonna, I'm gonna ask you, uh, IRA a question, but there was a guy, I was on a podcast, it was a couple years ago. There's a guy who used to tour with Pink Floyd.
He played saxophone and like Ira, I forgot his name. Uh, I think his last name is Page, I think it's Scott Page. But anyway, we were talking about the creation of music and he told me that he had heard music that was created through AI that he thought was as good as anything he'd ever heard.
The only downside he said were the lyrics. He said they were really simplistic and pretty cliche written. But, um, I'm just wondering, IRA, do you think, and maybe Fred, you can mention, you can weigh in, we're gonna see like a new kind of, and I, I mentioned this to to, to Will.
I am, and he kind of scoffed it, but whatever, I'll, I'll mention it to you. Are we gonna see like in the a IH, like something like the Monkeys or the Wiggles, like some prefab group that was created out of, out of nothing, uh, where these are not even humans, they're just avatars or creations and that, that become hugely popular? Um, I think we will, but I think there's a factor, like with the, the, the monkeys and other bands like that, like in Sync is an example.
I think part of the issue is, is that these bands Yes, you, you know, we have, I forgot the name of the, the the new female actress that they have. That's all completely ai. Oh, Lily Norwood.
Yes. Yeah, Lily. So we have, yes.
So we can talk about her. The reality though is, and you know, I was joking 'cause I give these presentations making fun of ai and you know, some of the headlines I pull up, like I now have an AI boyfriend. The reason that's critical is that with these ais people or teenage girls don't have the impression they could ever meet these people in real life, you know, and there is something about going to see them in person.
There is something about it that's gonna be missed. You look at a lot of these people and you know, some of them kind of mediocre. I recently went to, my wife took me to a Billie Idol concert, and frankly, you know, getting an appreciation for that, there's nothing like a live show, a great deal of money, millions of potentially with Taylor Swift, billions of dollars is generated because of in-person shows that you're not gonna have until at some point they, maybe they create robots or something.
There's an right, remember they did that one era of like Fred Wright with that, the holograms, like Yeah, yeah. Images on, on stage. I mean, I'm not sure how successful that was or is we Well, they are.
That and homage bands as well, right? Like Freddie Mercury were on stage and uh, you know, the Yeah, I was thinking of Freddie Mercury exactly right. Mike Jackson, so on, so forth.
But it's, you're, you're missing a certain aspect of the business of this. You're not gonna have these artists going out and well, I guess maybe will have these fake interviews. 'cause I see them interviewing that stupid robot that they were having a while ago.
I can't remember it, like from the, from X machine of the same face type of thing. But, um, you, there's a certain element that's gonna be missing. Yes, you can create music, but there's, it's still a business.
And until they cut segments of the business out, they're still gonna prefer live people, in my opinion. So, So let me, let me counter that. All right.
I agree with you, but the notion of what Live People is can be different, right? So, uh, if, if you are, uh, daft Punk fan, okay, there's a movie that Daft Punk did that was about a producer, okay? That went to some place out in the universe and captured this amazing talent, right?
And brought it back to Planet Earth and, you know, fully put these folks in chains metaphorically and made them do the thing, right? The viability of producers creating produced music that have the same capabilities of, you know, like 98 Degrees and Backstreet poise and the K-pop bands that are out today, I believe that's a hundred percent viable. All they've gotta do is go get Milli Vanilli or go get, you know, so on and have them play the role in whatever concert, in whatever capacity.
And that's it, right? The money is in the shows now because the money isn't in the music, and all you've gotta do is get enough music, attach ability in order to have to show, to generate that revenue. And you might not even need artists to do that anymore.
That's my worry. Well, I, I, in some cases I agree, I still don't know what was wrong with Milli Vanilli. I mean, I know that's gotta be like a blame, blame it on the rain.
But, but, but I mean, the fact is you got people who got up, gave people an experience, the music was real. Maybe those people on stage were lip syncing, but people paid for an, you go there to pay for an experience, it's like, oh gee, I was fooled. Like, get a life, you know, you felt good at some point, you know, sometimes I also think, I mean, the sphere maybe is part of this, maybe I'm wrong, but this idea that you perform and people I know who have seen U2 or the Eagles at at the sphere tell me that the experience, the music is fine.
It's good. They, they love the bands obviously, but it's, they are like little props on a stage of, of a much larger entertainment. And I wonder if that is some somewhat of the appeal why?
I mean, the Eagles are still playing. I was just in Las Vegas, they're playing through the end of January. Um, and, and I know, I know they have a huge, huge fan, fan base, but I also wonder if that also brings in this new generation of fans, folks who may not normally know anything about the bands.
Well, I think you're gonna, I mean, so here's the issue. What are you, what is this entertainment for? And part of it is the sphere could have done this without the Eagles themselves, just using your example.
Yeah. But the reality was people want to go to see them. I mean, I was in Las Vegas, this is gonna, okay, so I was in Las Vegas to see, and it just happened, I was walking by the park, MGM where they have the arena, and I see all these like 40 ish, you know, all these women like lined up and I'm like, what are you lined up for?
And then they go the Jonas Brothers. And I'm like sitting there thinking, oh my God, this is pathetic. But you know, then I end up going to Billy Idle with my wife.
I don't know, which is more pathetic. But the reality was that people wanted the experience of seeing these people live. And we need to accept that, that there is some element of people wanting a connection.
Yes. People wanting their fantasy. And you, and if you know it's not real, you're not gonna have, sorry I'm stereotyping, but you know, it's true.
You're not gonna have these teenage girls and women fantasizing over an AI the same way they are mm-hmm, mm-hmm. About getting the Beatles and passing out when they hear them sing or see them in person or whatever. Even though I think that was fake.
But we need these experiences. People want to have this connection that I don't think is gonna go away anytime soon. Yeah.
You know, you actually, I'll give you a little prop. So I saw Billy I twice, and I believe his song Eyes Without A Face was Song of the Year. One year I, I believe he wrote it.
So, I mean, you know, he, he's a talented guy. But I think we, I, you know, I actually, I think we're running out of time. Uh, I, God, this is weird.
We started talking about DevOps and AI tools and now we're talking about and Cruise Billy I and in between we were talking about, uh, the CIA, this was a, is, uh, varied a conversation I think I've been a part of, uh, in this show since I've been here. So I wanna thank you guys. You guys are, uh, you have a wealth of knowledge and that's what I find so interesting about you two guys.
You know a lot about a lot of different things. You have very interesting, insightful opinions and that's what make the, makes the world go around. So, um, thank you for your insight today.
Uh, I'm John Sorts. Um, it's been a long week. A lot of trade shows this week.
We're so happy it's over. Um, and, uh, we have a lot of programming and a lot of it, a lot of the, uh, content that Mike produced from Amsterdam and Barcelona, his series of interviews is out there as well as Alan's trip to Houston and Qualis. So stay tuned for that on Techstrong tv.
Um, for now, that's it. We're out. And uh, have a great weekend.


