Understanding Labor Day and Cybersecurity Challenges | TSG Ep. 914
Alan, Mike, Tracy Ragan, Jack Poller and Stacy Thayey dive into the latest cybersecurity accusations being leveled at firms in China before delving into the degree to which creating a new class of cyber privateers might help improve cybersecurity.
Then the gang takes a look at an architecture-as-code framework developed by Morgan Stanley that is now being advanced by the FINOS Foundation.
Transcript
Hey everyone. Hope you had a great Labor Day. You're watching Text Strum Gang.
Hi everyone, it's Alan Hummel. Welcome to today's Text Gang. You know, normally I would say Happy Monday, but we're actually took Monday off for Labor Day and it's a good time to reflect really on labor day's, not just about sales, hot dogs and barbecues and shopping.
I wrote an article on it, I think we discussed it actually on Friday's show, but it, it bears repeating just real quickly. Labor Day celebrates the American laborer and the organized labor movement who stopped women and children from being burned down in factories, gave us a five day work week, paid vacation times, pensions. A lot of it is being eroded ready for our eyes.
I was gonna say, where is that stuff? Yeah, So, you know, on, in commemoration of Labor Day, we should remember people died for those not rights, but people died for those privileges. People died for those benefits to get them for us, and we shouldn't be so quick to send them away.
So that's my, my labor message for today. Um, happy Tuesday to you. We've got a great show with great people to talk about our, uh, three, three different sections.
Let me introduce you to our gang members for today. First of all, we've got Jack Poller, Dr. Stacy Thayer, and the one and only Tracy Regan.
Um, if you couldn't tell, Mike and I are together today. We are up in New York at a top secret location, I would tell you, but might be violating national security laws. But we are together working, uh, on planning new world domination for Textron.
Uh, but we're here for Textron Gang Mike, so we've got a China syndrome today. Yeah. Um, I guess, you know, there was a statement put out last week by, uh, the F-B-I-N-S-A and, and a who's who of cybersecurity agencies from around the world calling out a couple of companies that were aiding in cyber attacks from China and attributing those back to the salt typhoon attacks specifically.
Jack, I know you follow this, but I can't quite get around in my head the following. Um, are we just calling out stuff now that we've known all along, or has there been an uptake in these actual attacks and is there something going on here that's more malicious than it was previously? Uh, I Think It's much more calling out what we've known because they're still successfully attacking us, and it's really kind of, um, from the security perspective, a little annoying.
You would think that these three Chinese companies that have been called out and a lot of the other salt typhoon attacks would be maybe leveraging very sophisticated zero day attacks, but that's not the case. They're actually leveraging five well-known CVEs, well-known vulnerabilities, the youngest of which is 14 months old, and the oldest of which is seven years old. And I read a little bit about this last week that if you are running some of these literally end of life Cisco routers either patch 'em or get rid of 'em at this point because, you know, they're still vulnerable.
You know, like I said, it's not a sophisticated attack that's leveraging something we don't know about. We've known about this stuff for years and years and years. I think what we're doing now is trying to raise the level of understanding that this isn't just some script kitty doing random things that's random, maybe not damaging, maybe not critical.
This is state actors doing state sanctioned and probably paid for by the state attacks against what they view as an adversary, which is us. And I think that we have to take that very seriously, and we're not right now, you know, I'm trying to get my head around this as well from, uh, maybe I'm just too old, but I seem to remember Alan, that, you know, we see, Are you referring to old and brought me up? There you go.
So I gotta call hr. I I, I do seem to remember back in my memory somewhere that, you know, Henry Kissinger and Richard Nixon went to China and we were all gonna be best buddies on all this stuff. And, uh, they were gonna buy our goods and we buy their goods.
And yet we seem to be more adversarial all these years later. So what's your assessment of the state of the relationship? I know we give as good as we get, but um, it seems like we're working across purposes here.
Are you asking Jack or myself? You, well, look, I friends, spy on friends number one. Right?
Uh, and that, that happens no matter the relationship, us, uk, us, Israel, you know, us Saudi na name a a espionage, and knowing what was really you, you everyone's doing is part of it. Um, but I do think, especially with China, and I hate to say it even out loud, but the fact of the matter is we've been slipping into a Cold War type of relationship with the Chinese now probably for 25 years. Right.
Maybe more. And the interesting thing that kind of distinguishes it from a previous Cold War with the Soviet Union, was it the Soviet Union? You know, there were, the world was divided into two camps, and neither the train char meet, there was very little commerce between the two, you know, Soviet and US block.
Where in China it's very funny because it, it, it, you know, on the face, the we are each, each other's biggest trading partners or we were, I assume we're still very close to it. And, and we've also moved from a bipolar world, as dysfunctional as that sounds, to a multipolar world where, you know, you have the eu you have centers of commerce, centers of spheres of influence, you know, in multiple points in the world. So can you blame the Chinese for doing what they do?
Yes and no, because they will tell you, well, this, this is not officially government sanctioned activity, but, but there's a bit of a wink, wink, non nod in providing these people cover. Mm-hmm. And, and so, you know, if you want to conti and now you know where I stand politically on tariffs and, and all of these other things, but from a political point of view, I think you gotta put some teeth in to saying, Hey, you gotta bring your dogs to heal, I think, right?
Yeah. You're not North Korea, this, this shouldn't be what, what we're doing here. Right.
Stacy? You know, it's interesting, I think I'm hearing more business executives kind of wrap their heads around this conversation, and they're getting well, to be frank Gu off. And what they're noticing is that their intellectual property is being stolen, and now that IP is then being put into a product that is made in China, that's taken over, you know, entire world markets.
It's not just the fact that they stole the IP and sold it in China. They're actually using that now to sell into Africa, Europe, and everywhere else. And us companies are saying, Hey, you know, we're gonna go broke if this keeps going up.
Yeah. I mean, uh, was it now drawing a a blank? Of course.
But with, with ai, when their ai, we, we were all excited that, you know, we had touch CPT and then they came out with something that was faster and better, and it felt, I remember people saying, well, they take what we have and then streamline it and put workers and labor on it. And, uh, it ends up being easier to sell and, and contributing to their economy. And so I can imagine that is frustrating.
And I think, you know, to Alan's point, there's been this, this cold war, if you will, that everybody's trying to figure out, is it a cold war? What are we calling it? What are the rules of this?
How does this work? And then how does that impact us? And we don't know because we're not defining it.
Mm-hmm. Jack, what do we do about all this? Well, you know, I think we have to take a multi-pronged approach, right?
I'm a belt and suspenders guy, and we have to look at both, how do we discourage the attacks as well as how do we prevent them? And I, you know, I'd love to sit here and bash China and call out China, but part of the responsibility is on our side for not fixing the problems that we have today. We know how to fix these, these particular attacks.
At least we know how to prevent them. And we're not doing that. And that's a problem.
So I'm calling out the people who should be fixing this and aren't one thing. Um, geopolitical things are, it's a very complex relationship. And yes, we are frenemies with China.
We're their biggest trading partner, they're our biggest trading partner. But at the same time, the communists have a completely different view of intellectual property than capitalists do. And that is the, the root of the issue here is the different views of intellectual property and who owns what.
Jack, I'm, I'm going to take exception with that. I don't think they have a very different view. I think when it's their ip, they yell bloody murder if you use it.
You know what I mean? It's, it's, Well, what I meant was the word that it's the, the state, the state views, all intellectual property is owned by the state in communism, which means that from their perspective, if it's theirs, hands off, if it's yours, it's okay. It's fair game for us to go get it, which is a little bit different.
I think the point is, We're not all playing by the same rules here, right? And that's, I mean, it's like our politics. Democrats are Republicans, they have a whole different rule book.
So we have to, you know, I, I think that the bigger the, the bigger problem as Jack keeps pointing out is we have to, you know, we can either be defensive or offensive, uh, and we can spend a lot of time being, um, offensive, but we're not doing anything defensively. I just read, I just watched that, uh, show on Katrina. Spike Lee did a documentary, uh, and it was interesting because beforehand people were talking about how they'd been told about these before, and they wrote it out.
They wrote it out, they wrote it out. And I feel like cybersecurity, were in that phase. There's a lot of noise.
We're gonna ride it out. We're gonna ride it out, and we should just be lucky that salt typhoon isn't acid rain. Acid rain was a similar attack against routers, uh, in Ukraine that brought down their communication system.
So China's being polite, let's just put it that way. We, they could do so much more with some of these nefarious DBEs that we're deciding not to address. And that is, it is a conscious decision not to pursue and spend money on fixing some of these, uh, issues because it costs money.
Nobody wants to go replace all their routers, which isn't probably that big of an expense, but it's an expense that's not getting pushed through at the higher levels. So maybe it's gonna require a corporate, uh, acid rain, and, you know, acid rain has turned into acid poor. So that's, we we're still, uh, dealing with that at these edge devices on the government side.
Um, but we have to get, we have to get our act together. We have to start fixing these things. Um, and we have to, uh, do better at understanding what ones are critical and what we really have to address.
Even if it means replacing hardware, so be it. Right? We have to get to it.
Uh, and then if we wanna try to do some more offensive work and play in the same games that China's playing, then, then we can do that. We were doing that in the two thousands, right? Zero day vulnerabilities were a big market, uh, and that we did nothing.
But that was an offensive tactic. And we really haven't dug into defensive tactics. And, uh, you know, it, it bothers me every time we, I see these 'cause we can fix them so dumb.
That's, I think another differences. There's, oh, I'm sorry, go ahead. Fundamentally, between these, these different countries, the way that we treat people and the way that other countries treat people, workers especially, and that's one thing I think whenever we go or try to go toe to toe with China, the labor laws and the labor rules and the way that they run things is completely different from the way that we do things.
And so, again, we're not playing by the same rules. We don't know what the rules are. And therefore, PI think different countries are willing to go to different lengths and different strategies, whether it be, you know, SBS, cyber espionage, whatever it may be.
Again, going back to what, what are the rules? How do we, how do we keep up and defend? They see, I'm happy to have you bring Labor Day back into our conversation.
It's how started true for you. But let me, let me throw something out at you. The US and China don't exist in a worldwide vacuum.
As I mentioned, it's a multipolar world. Look at China's relation attitude, cyber work, let's say against the EU or Russia, right? Russia is theoretically an ally of theirs.
They have this strategic relationship that will last forever, as they say. Um, where, you know, the EU has issues with China's cyber work, but the EU to, to the point Jack you were making, I think has clearly more clearly enunciated, uh, EU wide priorities in terms of security and privacy and what they will tolerate there. Now, I, I don't know enough about China EU hacking to be an expert, but it seems like they, they might have a better, a better approach to it.
And maybe it's because there's not as big a competition between China and EU as there is between China and the us. I'm gonna go a step further, and I'm gonna go back to Kissinger and Nixon, and maybe it's time to unravel this agreement and just say, look, I don't think you can, I think you can move a lot of manufacturing that's occurring in China, other countries, it's a big world out there, and there are other places to go. And maybe it's time to have that conversation with them and say, look, if this is how it's gonna play out, then you know, we're gonna take our marbles and go home followers do it.
I'll, I'll, I I think there's a lot there, but I think that's veering in, I'll, I'll sort of bring it back towards a little bit more cybersecurity. And I'll say part of the difference is the, probably the only country that has a bigger target on its back from a cybersecurity perspective than the US is Israel. And there is a reason why the ma vast majority of the new cybersecurity technologies coming out of Israel, right?
And it's, you know, it's an existential crisis for the country among many other existential crises. I would not be surprised if the same tactics and techniques that China's using against the United States are being used against Israel or other countries, right? So we are in this situation with China because we have a very big target on our back, right?
And there's a lot of economic and political muscle that China is throwing around for a variety of reasons. And a lot of this, these cyber attacks are probably tangential to the cyber target, but much more government directed for strategic things that, you know, we could spend hours and hours going down that rabbit hole of what China really wants to get and what United States wants to get and how they're doing it. Um, and there's a lot of arguments there, here or there.
But regardless of the whys, the reality is that it is happening. Knowing that it's happening, we should be proactive in defending against it and in working to stop it and prevent it, and possibly becoming more offensive ourselves. So let me combine, Jack, what you are saying with Mike, what you're saying.
I don't think it's realistic Tanglement is what you're talking about. Mm-hmm. Tanglement, I, I don't think is a realistic option because we don't have the wherewithal to think that far down the road.
'cause that's gonna be a 10 year or more. Took us, kind of, took us 30 years to get in this, It'll take us 25 to get out, and we don't have that kind of view. However, I do think we could do a better job of meeting with the Chinese.
And you know what, and I think every administration has tried to do this to say, Hey, let's, but the Biden administration really tried. Yes, we know we're competitors, but we're not enemies necessarily. And let's try to frame where we compete and where, where we should draw a line and say that's, that's just unacceptable.
And supporting cyber, you know, hackers, it's one thing for cyber espionage. You want to, you know, you're trying to steal the plans for the next great fighter plane. That stuff's been going on before there was computers.
But hacking for, you know, for some of these things that they're doing just for economic gain, for, for inducing chaos and heartache, that has to be offline. You, you've gotta have clear boundaries of what is sort of, and there has been that in, in, in espionage and the way intelligence agencies around the world work. There is a protocol that's followed.
We need to better have a better protocol. China, you cannot support just these hacker groups. Uh, you know, when you look at, you know, the access of evil, North Korea, Iran, China, Russia, where a lot of that, the hacking comes from that are, if not state sponsored, state tolerated, we need to make sure these states do not tolerate these groups.
I think we've been delusional, we flat out about it, and we keep treating cybersecurity as if it's not attached to any political or economic agenda. When it's actually the manifestation of the political and economic agenda. It's time to wake up.
It's all ours do. Okay? Mm-hmm.
Well, I think that we have to go back to, if, if we're talking about, you know, Nixon, we can talk about Reagan and he told us all the trust, but what verify. So let's go back to fixing our routers, please. Yeah.
I mean, and, and of course, look, you know, let's not let people off the hook on that. We need to fix. And Jack, the, the statue cited aren't new.
It's been this way a long time. 80% of attacks take place or incidents take place against well-known attack factors. Not, not some new shiny zero day or, you know, new, new surface.
It's, it's just taking care of basic hygiene and security people have been yelling for this for years. Anyway, we're gonna take a break here. Let's come back and talk about our next, uh, topic.
You're watching Textron Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey folks, we're back and we're talking about a little more cybersecurity, but this time it's an interesting idea maybe, or it could be crazy, we'll find out in a minute. But there is a representative in Arizona who's proposing a bill that would enable the creation of, well, for lack of a better phrase, cyber privateers.
The idea is that just like we did back in the turn of the century or 17 hundreds, we hired essentially pirates to go after pirates. And so that question then becomes, can we now hire vigilantes cybersecurity folks to go after the bad folks? Stacey, what could go wrong?
What could go wrong? Well, first off, I wanna put on my marketing hat and, and I suppose tip it to whoever found that and said here, pirates, right? I mean, that's all in itself when I read it.
Um, well, and I think just, just what we were just talking about. So now what we're saying is that let's go beyond these groups, find individuals, find people with skills and appoint them to, and, and essentially endorse them to be able to perform cyber attacks or to be work as individuals, to work as possibly as vigilantes. I mean, does what I look at that and then I say, well, does that encourage that behavior?
So now is it, does that encourage that cold war? Are we tapping just individuals and saying, okay, you are okay, you're outside the government, you're not associated with an entity, but you're a darn good hacker, so go for it. I mean, is it, is it become that simple?
And to me, I see a lot of risk. We so what can go wrong? A lot, A lot.
And, uh, you know, I think calling it cyber private tears and, and bringing out the history of it. And there's psychologically when we know this has been done before and you put a neat name on it and you put lipstick on that pig, but when you take the lipstick off, it's still a pig. And that's, that's what I see here, is that there's a lot of risk.
I mean, is there a lot of gain to be looking at the private sectors for talent? Sure. But it's a slippery, slippery slope.
Well, I look at the, the risk and say that the risk is really not who's doing the activity, but whether you're choosing to do the, uh, offensive activity or not. Right? We, you know, yes, we stopped issuing letters of mark back in the, uh, mid and mid 19th century, but we never stopped using privateers to, uh, take either offensive or defensive actions.
We have a long history of using, uh, you know, mercenary organizations and third party contractors in our military operations. That's never stopped. We've just never felt that we needed to give them a different legal cover to give them a legal protections than they would get now with the letters of mark that, or that they had with letters of mark.
But if we choose to do offensive actions, then, you know, I think that that's really the question is, does the US government wanna really partake in very, and I have very active campaign of offensive actions. And if they do, then it's a question of what actions are we taking? I'm trying to figure out, I'm trying to figure out how this might actually work.
'cause like back in the day, the privateer would commandeer the other nation ship, and then they would get that as their reward essentially, and they would sell that. And so how do you pay privateers that you're gonna pay them for stealing intellectual property from other countries? Or are they just gonna be contractors?
Well, I wonder can, I mean, how, how close is this? Is this akin to a military operation where you're now drafting folks, drafting cybersecurity professionals? I mean, you know, a couple hundred years ago we were grabbing our bayonets and hitting the, the fields.
We don't do that nowadays. So is this just the modern warfare? And now we're drafting cybersecurity professionals, Drafting warfare?
Why are you drafting them? We're not drafting anxiety. Well, I think it's, I forcibly draft you in here, whether you want to come or not, this might of the willing and the army of the paid, but let me, let me just weigh in here.
I appreciate invoking the swashbuckling, sir. Privateers preying on Spanish Galleons, the, the Caribbean. Yes.
That's not what this is guys, this is not, this is not a, uh, I'm sorry. I'm sorry. Stop.
Uh, this is not swashbuckling privateers preying on Spanish gallions in the Caribbeans in the 17 hundreds. There's another name here, not privateers. It's called vigilantes.
Yeah, it's called vigilantism. They take the matters into their own hands, and we're giving them a license to do so. Right?
This is wrong. It's wrong. You want to, you want to draft, and, and again, draft's the wrong word.
You wanna hire cybersecurity people to go after cyber farms and hacking farms and all of these things. Fine. You pay them.
They, they have to abide by the rules. This, especially under the present administration of giving people, what are they calling of Jack letters of mark, or, well, That, that's what it was originally called. And I think, you know, let's, let's be clear here.
When we, when the United States and other countries issued letters of Mark, there were very specific rules that the privateers obeyed by, one of which was they brought their spoils back to the government, which would then decide how those were distributed, right? So it wasn't just a free for all. So that's, is that really how you think it were?
No, I Only did a minimal amount of research here. So I can, I'll claim, I'll feign ignorance to the best of my ability. I I will, I will give you the story of Captain Kidd, who was originally a privateer, and then he went out and, uh, apparent full Blown private.
Yeah, Well, you know, took those letters and Mark and then, you know, started sacking every ship he could find and eventually was hung by the British, I believe, right? Yeah. No, but Barr, Like I said, we separate, Separate Out the, The, let's ask, we'll come to you Chase.
Sorry, real Quickly, just separate out the decision to be, to go offensive with who's going offensive, right? There's sort of two different things. If we decide to go offensive, then the question is, does the United States government have the talent to do so?
Or are they hiring outside talent in one form or another? It's a different way of looking at, And right now the, uh, the US government, they can hire, they could build their own, uh, group of people to go after these farms, and they probably already have. So why do we need a private, uh, why do we need to create an industry?
That is the question here. Do we really wanna create an industry of people who are hacking? Because when do they start going after, instead of going after these farms in Russia or China, wherever they might be?
When do they start going after private companies for whatever reason that the government says you can do so? It's a, it's a dangerous slope. I don't really believe that we should have people in the private sector performing illegal acts In Army.
And this Is illegal. And, and let's be clear, these, it's not gonna be Jack and Stacy and Tracy who get these letters to Mark. It's gonna be the Halliburtons, the black, what's the other, some of these companies that have sort of military operations and they already have cyber operations.
Yes. Right? Gov The government already has this, so we do not need private.
Yeah. They exist in this shadowy world. I think we're being naive.
If we think we can control this, you know, they're gonna bring all their booty back to us. I think the government will disavow any knowledge of their actions, and this tape will self-destruct in five seconds. Yep.
Mission It impossible. I, I just, you know, and, and look to be fair, this, 'cause you know how I feel, you know about the administration, this doesn't seem to be coming from the executive branch or an executive order, at least from the article. This is, uh, this is a, a, uh, a Republican congressman from Arizona, relatively, I think a newcomer who's, I would Actually argue that, that, that our current administration doesn't want this because there's a very significant lack of control.
And that's very scary. You know, how they hate not having control. Okay.
But so, you know, look, I think we've given this guy his 15 minutes of faith, it's time to move on. I don't know, I think, you know, showing up in Mar-a-Lago with bags of booty, you never know what I have. Well, I Want get the boot from I have with the, I don't think they're gonna be getting bags of booty Flying in with the rope.
Hi, captain Parrot on my, now on my shoulder. Rol Flynn and Douglas Fairbanks. Here we go.
There we come. Alright. You're watching Text Young Guy.
Stick to, we'll be right back. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of Security Bloggers Network. Hey folks, we're back and we're gonna geek out for a minute. Morgan Stanley has released and made available to other folks.
A architecture is code platform, I think called calm. And they're saying to folks, Hey, use this. Share it.
We battle tested it. And, um, if we want help us maintain and actually extend this thing, Tracy, we've been talking about, you know, infrastructure is code for a while and everything else is policy is code. Is this a new idea to you?
And, you know, what do you make of all this? Well, first of the, you know, this is a project that came out of os, which is a foundation under the Linux Foundation. Uh, so it's kind of not surprising that that, that that is who has created this, this group of, uh, uh, you know, financial people who get together and talk about these topics.
Uh, and it's really an extension of what we're seeing in platform engineering. Uh, the idea of, uh, GI ops took off like crazy. Now we kind of have GI Arc and there are pieces of architecture that go unattended to, let's just put it that way.
Documentation is one of them. Uh, oh. This project, this project makes an effort to pull together, um, architecture and see it in a different way.
Uh, you know, it goes beyond just like a terraform. It's, it's, it's looking at it from the perspective of automation of repeatability and not having the need for one person to ha have knowledge of everything. You know, it, there were, there was a point in time before we had continuous integration and continuous delivery, CICD pipelines that you had build meisters, now you have architecture meisters.
So we're moving away from this with the, with the platform engineering teams. Um, the, there, it, it has several projects in it. It has first calm, um, which is kind of the core of the product, but then it has other pieces.
It has a, a, a ui, it has its dock generator, uh, and it, uh, has A-A-C-L-I, so you can integrate it into your automation workflows. So it's, it's, it's not surprising that it's here. I'm actually kind of, kind of surprised it took so long.
Uh, but it is the next kind of, the next iteration of DevOps or platform engineering, or whatever you wanna call it. And in Fin Os in the financial industries, they have more requirements for tracking how the architecture is built, understanding even the tiniest little configuration that you might have to tweak. So it doesn't surprise me, it's come out of this group.
Uh, I've been on some of these calls and the, you know, Morgan Stanley, they're pretty progressive and how they build out their, um, their development lifecycle. Uh, but it's not just Morgan Stanley who's been working on it. The Enos group has been really supporting it.
And so kudos to the Linux Foundation and Enos and Morgan Stanley for bringing it to the, to the masses, so to speak. And I would encourage any of the platform engineers to get involved in the project because it may have some work yet to do to make it completely usable across different industries. I know that they've made an effort to make it that, but I'm guessing there's still some work to do on it.
I Don't disagree. I, I, first of all, look, kudos to Morgan Stanley for donating this to, I think it was actually to the finops Foundation, which is part of Linux Foundation, right? Um, so it's good to see, you know, to all too often we see vendors who developed open source code donated to the LF or the daughter foundations and, you know, look, it took it off their books, but they're still using it.
They still might be dominant in it and they're gonna make money from it. This is much more, at least on the surface, just doing the right thing and, and sharing it with the community capital. You know, Morgan Stanley's not the only one.
Capital One has been really big. Spotify is the same. Spotify, there are certain companies that really do, you know, take that open source mantra to heart.
And I'm glad, you know, kudos to Morgan Stanley for doing this. com, but this really extends beyond DevOps. There's a finops element to it.
There's, there's a platform engineering element to it as well. Angle it, it's about, you know, making, making architecture is code, as the article talks about, right? We, we have everything is code today.
Why not architecture? So, uh, I just think this is a win-win all around. And architecture is hard to track.
Changes are hard to track in architecture. Uh, just like in, in deployments. That's why GI UPS took off the way it did because it's easier to track changes if you can version it.
So now we'll be able to version architecture and then generate documentation for it, which is huge. It really is. It'll save a lot of time, a lot more than AI is doing for this space.
A lot more. Jack, I've always been amazed about how much infrastructure hardware is in an organization that nobody seems to know about, and it just seems to get left off a table somewhere. And you would think that all these large companies would have a handle on that.
But from your perspective, what's the fundamental problem? Uh, it is incredibly difficult to track moving targets in a large enterprises and hardware you'd think is a very stable thing, but it's not. It's a very much a moving target.
And organizations just struggle when there are so many people involved, so many devices involved, so many things involved, and these things live forever. That's, you know, as we were talking about in the earlier segment that the, the Cisco routers have been end of life, but still vulnerabilities. There's for a lot of stuff you don't want to get, you have capital invested in it.
Capital has a five-year depreciation for some things, 20 years for others. What do you get rid of when if you get rid of it, what do you do with it? Right?
Do you have sensitive data stored on it? Is there sensitive data stored in the firmware in the hardware, right? How you, so what do you do with this stuff?
It's easier just to leave it in place and let it sit there and then it gets forgotten. Or somebody says, oh, I can reuse that for some other project. Well, how do I, instead of convincing my boss to go spend 15 K, I've got 15 K of hardware here, I can just go reuse.
And, you know, that's part of it. And then architecture, this is all about architecture, and architecture is a lot the same way, is, Hey, I need to make a tweak here, right? We, this is something, you know, the world has changed since we just architected this two years ago.
We need to make a change here, but how do we track that change throughout and how do you version control that change and, and document it and who knows about it? And there's, you know, many, many moons ago when I was slinging code, just understanding the institutional knowledge that's in everybody's head was hard. How do you get people to document it?
If you have architecture as code, that's a way to manage some of this stuff. And then you don't have, especially in the financial, uh, industry, you don't just have one architecture. You have, you know, I I, I used to work at, uh, discover Card owned by Morgan Stanley and just at Discover Card we probably had 40 or 50 different, um, you know, gold installs for our hardware, right?
And we had to track all that and track changes in that. And that was for different development teams and different end users, different devices That this, this article talks about that, uh, Morgan Stanley had 1,400 internal deployments. I mean, that's, no, people can't even fathom.
How do you, nobody can hold 1400 of anything in their head to understand what's going on. You just can't, you know, there's these, Imagine how sort of that, Yeah, but I still don't get it. There are databases and documents and things that could be tracked.
And it's not like, you know, four people snuck in in the middle of the night and installed a bunch of new servers. Or is it, uh, yes, it's Actually, yeah, exactly like that. It's exactly like that.
The, there's an entire industry, computer industry. So one of my first jobs was working for Novell, and Novell got started. They, they really got successful when they realized that it's very hard to sell corporate IT folks who were at that time buying mainframes or super mini computers.
It's a lot easier to go to a departmental guy and say, Hey, you can afford this out of your departmental discretionary budget. Just go buy a little server and put it in a quarter and nobody will ever know. And that's how Novell built its original NetWare business.
And a lot of companies still do that. To this very day we have this thing called shadow it, which is all about people just plunking a credit card down for a cloud service, and all of a sudden that somebody did a, a test case on their personal credit card, that now is super critical to the lifeblood of the company. That's how these things happen.
I mean, am I wrong, Stacy or Tracy? No, no. So this is, so I think, Jack, we had an episode about, uh, mainframes not too long ago.
So did you just describe the original sin and we just trace it back to NetWare? Is that where this is? I'll blame it on the GE and Provo.
Absolutely. Uh, no doubt. Um, can we theoretically apply Tracy AI to all this in architecture is code stuff and maybe we can get our arms around this thing.
Finally, what do you think? Is there hope? I don't see, right now I don't see a reason for it, right?
It's because we have, um, AI doesn't mean we have to use it serious. I was, I was really working hard not to mention AI the entire time. Well, you know, you know, maybe we can, you know, once this gets going, maybe we can have AI generate, you know, calm files if that's what they're gonna be called.
But we don't need it right now. What, what we need is, uh, better management of our architecture and better management of our networks and being able to see what changed. And we don't need AI to do that just yet.
I really, you know, AI is great, but we don't need to apply it to every single problem. It doesn't solve every single problem. And in fact, it could create more and don't get me on small language models because if we try to use an LLM to generate one of this, it's gonna lie.
It's gonna lie. No doubt. So Jack, can't we just have a simple solution here?
I mean, if you plug something in the network, shouldn't it just automatically just phone home to somebody and say, Hey, there's a new thing on the network, but this is the simple solution. This is what it phones home to eventually. Mm-hmm.
Right. That's the, I think that's the point, is you need to have defined a structure and a way to handle information that's coming at you in one form or another, whatever the information is. In this case, it's all about the architecture of your environment and the architecture of your applications.
If something's phony home to tell you that, Hey, I've just, I've just been installed and I've, now I'm able to do this and I fit into the architecture here, it can own home right now, but the information it gives you is gonna fall on the fall out of the internet onto the ground and disappear forever, right? That's, it needs to go somewhere and do something. We need to do something with that information.
And when we start putting it in Git, it becomes available to everybody, not just somebody who has a front end to a tool that's doing it, right? It really democratizes the data across all teams because you can go find it. And oftentimes it's the development team that's troubleshooting some of this stuff and they not, they're, they may not be doing, making architecture changes.
So there's a communication gap. So having it and GI makes it super accessible and easy to do a a diff between two files to see what might have been impacted. Yeah, Dis it's just easy.
Yeah. Yeah. It distributes the knowledge.
I mean, I think a lot of times what happens, especially, you know, when you get into legacy software and things like that, you've got turnover in companies and one person comes in, gets all organized around, it leaves, someone else comes in, it gets shifted to the side, you know, whatever these things happen. But when then you've got an organized place to put it or you've got a process for it in a workflow, it becomes easier for those turn for that turnover for people to, to jump in. I'm predict that GI ops that, that this, that come is gonna make a change, um, in the same way as GI Ops did.
It's gonna be a very big conversation within the platform engineering teams. And it's gonna, it, it, there's gonna be a lot of conversation around it. It's gonna get some, it's gonna get some time.
Guys, I, I had a question on this though, and Tracy, you're probably the best person to answer this, why finops, there are a lot of good found do foundations than the lf. Is it financial, the Morgan Stanley? So they, they're more closely aligned with the finops Foundation.
Those, Yeah. Interesting enough. Um, there more of the financial industry is contributing open source code into the Linux Foundation in general, including, you know, the CD foundation, the, um, you know, the CNCF obviously.
But there is a re there is a very specific reason why this would be important to finops, uh, to the, to the financial, uh, community in particular. They do have more much stricter requirements to manage these components and understand change. Uh, there used to be no, i I, I cut my teeth in the financial industry and there were few industries that had change management groups.
It was the financial industry and insurance, uh, that had change management groups and auditors who were asking questions about, uh, these exact topics. So it's not surprising it was born in this industry because it, this is the industry that is more particular about how things are moving through their development lifecycle and how, in particular their architecture's being changed because they have had security people on staff and, and taken serious for a very, very long time. And change management started in the financial industry.
This is where we started thinking about how to track, how, what the difference between two binaries or the difference between two network configurations. They're very, very particular about it. And they're, they take it very serious, much more than telecom, much more than the, uh, retail or healthcare or transportation or any, even, even the, even the, the private sector.
They're very serious about change and tracking change. And they have been doing quite a bit of work in this area within many groups within the Linux Foundation. Got it.
I think this is way overdue and it's not a good look for it. Imagine if you would, that you're a CIO and you go to that executive board meeting and you wind up saying to somebody the equivalent of, yeah, we have hardware and software floating around on the corporate network that we're not sure where, who owns it, where it is and what it is. It's 2025 for crying out loud.
This is not a good look for it. And then maybe we should all get our act together. 'cause if somebody's gonna ask some hard questions real soon Yeah, it's way overdue.
Way overdue. Yeah, no doubt. Hey, we're about at, well, we're probably over time, gang, thank you so much for the lively discussion today.
Great stuff, Mike. Thank you as always. Thank you for watching.
We have a full text from TV line up immediately following as usual. Um, and we'll be back tomorrow with even more great gang. Well, I, yes, we will be back tomorrow, Wednesday.
Wednesday. God willing. Until then though, on behalf of the Gang and Text Fund, have a great day everyone.
We're out.


