Techstrong Gang – January 27, 2025
Alan, Mike, Mitch, Sulagna and special guests Chris Blask and Tracy Ragan dive into the implications recent executive orders issued by President Trump will have on cybersecurity before discussing whether sanctions are an effective method for punishing cybercriminals.
Then, the gang turns its attention to the latest cloud outage, this time involving the Bitbucket continuous integration/continuous delivery (CI/CD) service provided by Atlassian.
Transcript
Hey, everyone. Happy Monday. Can you believe there's controversy surrounding the new administration already?
You are watching Techstar Gang. Hi everyone. Happy Monday.
It's Alan Shimel for Text Strong and you'll watching Text Strong Gang. We've got a full, uh, usual gang lineup and some as usual, three different segments here on Text on Gang. We're doing something a little different.
I don't know how you're watching it, where you're watching it, when you're watching it, but we're, we're dividing up the segments so that if you don't have time to watch the whole 40 or 45 minutes show, you can grab just the individual segments up on Text Drunk tv, and soon on our OTT, uh, app. So, you know, however you want to consume the gang, we'll try to make it consumable. Let me introduce you to who we have of kicking off this wonderful week on the Gang with us.
I think first we're gonna go out to see and, and, uh, grab our cybersecurity expert as well as nautical, uh, I don't know, nautical Admiral Chris Pirate. Resident Pirate. That's a good word for one and only Chris Blask.
Chris, I know it's cold out on the seas today. I hope, I hope you're staying warm. Uh, we're doing good.
My life Don is with me. We've sailed down from Melbourne, Florida. We're down in Riviera Beach in Palm Beach County, and about three days sailed from you in Boca Raton.
Well, I'm looking, hopefully it'll warm up by then. Uh, my boat's going in on the 28th, so try to get here before then, if you could. I'm working on it.
All right. It's, uh, it's going in for its annual physical, I guess, um, with Chris. Thanks for joining us.
Let me next go out to Colorado, where one of our studies, future VP analyst, Mitch Ashley is hunkered down. Hey, Mitch, how are you, Matt? I'm doing well.
I'm, I'm a little landlocked co. So I, I can't volunteer to be on Chris's boat ship, whatever you call it, but I'm, I'm there with you in spirit. Chris, hang tight.
All right. Now you, you're kind of landlocked now for sure. Next, um, let's go from Colorado to the mountains of New Mexico for our, uh, friend Tracy Ragan, CEO of Deploy Hub, uh, c CD Foundation.
Is it Tech Leader or, I don't even know the title. Title. I'm busy.
You are, you are one busy, busy girl. Always. Yeah.
Hey, Tracy, how are you? I'm fine. We are starting to warm up here after last week being absolutely freezing.
Um, and yes, I'm on the board of the Technology Oversight Committee at the CD Foundation and on the open SSF, uh, governing board, uh, around open source securities. Absolutely. In addition to deploy Hub Aurelius, submitting a whole bunch of speaking proposals and a lot of other great things.
Welcome. Uh, next is, is actually, is she still our newest gang member, or has someone come in behind her already? Mike, I think she's still the newest one so far, but you know that that may only be, uh, for a little while.
All right. She's is, she also is the editor for Text and ai gestalt it, and really knows her AI stuff as well. And I'm still working on her name 'cause it usually takes me three months to get people's names right.
Langa, Sala. Saha. So tell your last name.
Yeah. Yes, it's Soha Saha. Right.
Sona, welcome. It's good to see you. Thank you.
It's good to be on the show. It's, uh, Palm 24 Degrees here in Ohio. Woo.
Which play a long shot better than the subzero temperatures we had earlier this week. Yeah, So, well, it was 47 here today, so, wow. That makes me feel a little, it doesn't really make me feel better.
I still feel cold. Um, but I'll talk more about that in a second. But let me introduce our last gang member for today, certainly not least.
He's the chief content officer here at, uh, tech Strong and Mike Vizard. Hey, Mike, how are you? I'm well.
I have a question for you and Chris. So like, are you getting ready to put together like a boat race for pinks? Are you gonna, like, you know, Trade for for res right boat?
Race for res? Mm-hmm. Mm-hmm.
I was think we call it a regatta. I was gonna say yes. Robert Regatta.
Yes, I we're a Flotilla. Yeah. We actually, we're Gonna move, we're a flotilla, or look, we could be a fleet.
We're the, uh, AI fleet. We're about to take in about $500 billion in capital, and we're gonna build out some capital ships here and, uh, we'll go from that. Um, but, you know, an interesting thing about the weather.
So I, you know, I, my car is supposed to be an intelligent car, and, you know, down here in Florida, we don't put the heat on. You know, my car is set, you know, climate control when not driving in today, all of a sudden I notice the, the, um, steering wheel started heating up. I started getting hot air blowing into my neck over here.
The seat warmers went on. I didn't turn anything on it just, you know, it just figured out it was really cold out. You better do something for this guy.
Um, and I, I said, now that's ai. That is what we want out of this thing. I didn't ask for it, but I needed it, and I got it.
So, kudos to BMW on their intelligent driving machines. And that sounded like the story of the frog in the pot, right? Pretty much.
Anyway, all right, let's jump into things, Mike. We're gonna run it over to you. You know, Donald Trump's been in office about a week now, and hard to believe.
No one's noticed any kind of controversial actions on any part. All of a sudden now we've got one. What do we got, Mike?
So, there's been some executive orders issued related to cybersecurity, and in particular, they seem to have replaced the people on the cybersecurity review board, but it's not quite clear to me at least that they're getting rid of it, or if they're just gonna put some other folks on there yet. But some folks are saying, this is just political business as usual, and other folks are all upset saying, this is a signal that cybersecurity is being quote unquote politicized. Chris, I know you're closer to this than I am.
What's going on here? So, as, as, as you know, I've been spending the last half a decade or, or a little more, uh, focusing on supply chain, right? And I noticed in the, in the Security Boulevard article, um, in the, in the, in the content, uh, back, back content for this show that, uh, you know, that's, you know, so that's called out and it's, and it remains 14 0 28 now, 14 0 27 and 14 0 29 are gone.
And when 14 0, 20, uh, eight came out the, the SBO m uh, executive order in May of 2021, I was working with Unisys, I think at the time, and involved with cisa. And then the s om, uh, um, activities was Department of Commerce. Before that actually, and I did a map, uh, across time across presidential administrations.
You look at supply chain executive orders, and across the Obama and Trump and Biden at that point, Biden administrations, they lined up remarkably well. Right? You know, different administrations may have different motivations.
I think during the first Trump administration, it was more punitive, nationalistic, let's, you know, punish China, for example, you know, and to, to grossly to typify that. However, the executive orders about supply chain were not 90 degrees or up, you know, 270 degrees from existing executive orders. So I can't help seeing all of this as, uh, you know, the, the two, uh, executive orders 14 0 28, and the one that just came out recently, uh, that I had heard was going to survive the transition and has as being more artifacts that show that a new administration like a CEO in a huge company can say, I wanna do this.
Then you turn to the people who actually work there and say what is possible. So while we're dealing with decisions coming from this given source, we all are familiar with, they're not really varying as far as you would think, from the existing path down this, down, these, these, these, you know, but in cybersecurity at large, in the supply chain, uh, security. So I'm, I, I'm relatively okay with, you know, things to date.
We'll have to watch this day to day and quarter to quarter, make sure it's guided properly and the efforts to date, you know, our, you know, continue and move forward, forward. But I no panic yet, Ellen. I raised my head.
I'm trying, I'm trying to, I'm trying to be a rule follower over the next four years. I don't want find myself in a deportation, camper, anything. Um, so I've got a few problems with this on a few different levels, and Chris, I appreciate your myopic view of focusing in on just how this is gonna relate to supply chain security.
But I think there are bigger issues here. First of all, as a political science major, it kind of makes me sick to my stomach to see this current state of the American government. And, and I'm not gonna just blame Donald Trump and the Trump administration.
This has been going on, quite frankly, since the Obama administration. We've substituted democracy for executive orders. Our constitution is pretty clear about what roles the three branches play.
And all of a sudden, because of the, the lack of political will, the inability to compromise, the inability to reason, and, and, you know, come to decisions the way this country has been governed for 200 plus years, we've, we've, we've substituted that with these eos, which I really think the Supreme Court will continue, that we, we can't have an imperial presidency, I don't care who the president is. Eos need to be limited in, in what they can do, because it should be the will of the people. It should be the congress, the legislature who, who is okaying these things.
That's their job. And in, and by them abdicating in their inability to get their act together. We've tossed it into the executive branch and made an imperial presidency.
It's wrong, and it's gonna wind up as a bad thing for the American people. So that at a very high level, that that's that. Secondly, as it relates to cybersecurity in general, yes, they kept some of these in here.
There are plenty of books on the law that they haven't rescinded either. That doesn't mean they're gonna enforce them, that just means they're there. Now, the fact of the matter is, we, I think over the last five, six years, going back to the first Trump administration even, right, uh, Chris who, who, Chris, who was in charge of csa, Chris, um, he spoke for us at ours, Chris Krebs from Chris Krebs, and those folks through and through the Biden administration.
For the first time in a long time, I really felt the federal government understood how to handle on cyber and what the challenges were and what, how government, 'cause government can't do it alone, how government could work with private industry to make a difference. And I, I felt like we were making progress, even though they were mostly executive orders coming out of the Biden administration, and I wasn't a fan of it. Then as an eo, I'd rather see Congress act, um, at least there I was hearing the right things.
I thought the right people were involved. You know, a week or two ago, we, we were on here and we were talking about the loss of am Uran, right? Amit Uran from Tenable at 54 years old, and what a shame it was.
When you look at Amit's career, he, he scaled great heights in private industry and cybersecurity net witness, RSA, uh, tenable, right? But really, it, it, some of his best work was, and he worked for the Bush administration setting up, what, what really, in many ways was the precursors to cease c in a lot of our cybersecurity government infrastructure. It was done not in a politicized way.
We didn't throw out the old review board or, or, you know, there are people who are experts. This is should not be politicized, and I appreciate them Not rescinding things doesn't mean they're gonna enforce them, but there are people there doing a good job. Until you show me that they're gonna bring people on to do a good job and not turn the whole world from Twitter into x call, call me, call me doubting Thomas, you, you know, I want to, Alan, it seems like we've entered this era, and not, not, not just Trump, but all of us have thought about, well, whatever politicians say in the campaigns, we know they can't do most of that, right?
That they don't have the right Congress in place, or they may not, or who knows if they could actually legally do that. Um, and while those things still may be true, the approach now is, I'm just gonna put it all out there. I'll put, we will see what is legal as it goes through.
We'll see what people let go by. Um, but it's a way of, um, you know, promises made, promises kept, doesn't matter whether actually happened, I initiated an action. And in part, a lot of what's happening is just kinda introducing the chaos of we're gonna change all this.
We're getting rid of that. Who knows whether, whether we can or not. So it's this huge, um, you, you remember the, the pickup sticks game where you kind of tossed them all down and then you had to kind of figure out how to pick 'em up without disrupting the whole pile?
Well, we're just disrupting the pile while we're picking 'em up, too. And, uh, yeah. On purpose.
And that's, that's the purpose, is to just shake it up constantly. And, uh, I, you know, it's interesting. Where will we end up with all this, whether it's the cybersecurity rules or, you know, doing, uh, Stargate, uh, whatever might be it.
It's, I'm, I'm just curious where we're gonna end up with, so when, once we see what reality really is, it may take years to find out if that could happen meantime, you know, they've taken some actions that may have been not been allowed. And do they get retrenched or just ignored or what? It's, it's really unsettling.
Well, I feel like it's, it's a frustrating, it's frustrating for me because when I look at something like this, I, I think of a book called The Logic of Failure Making Decisions and not Walking them all the way down as far as you can to see where they're gonna take you. And if we look at the, this one, and, and the one that was, uh, you know, thrown out was in particular around ai. Now, if we look right now at how government writes software, um, they use open source and they probably will use open source LLMs.
Why? Because it would take them years and years and years to write all of the open source and LLMs internally and own that IP themselves. It doesn't happen.
So what we end up with then is a, basically, if we think of Trump being a CEO of the, um, the, you know, the DOD and the DOE for software development, we have somebody who has said, we don't need to regulate ai. We don't need to look at this. We're gonna let OpenAI and we're gonna let Meta, and we're gonna let these companies define the processes themselves, which may not be as important as should, as it should be for something like Weapons Systems.
And I can promise you that the software engineers at the Army writing this, uh, their weapons systems, they're not trying to write all of this themselves. So the US government depends heavily on open source and, and, and cots and companies like OpenAI and Meta to develop the software that we rely on. And we have a CEO that has said, let's make it a wild west.
We don't care. But they only see it from the perspective of we don't wanna hinder the growth and the development of ai, which I understand, but it's sort of like when DevOps started hitting the market and everybody started doing it, they was like, oh, this is gonna be too expensive and too time consuming. And then they realized it was the one thing that got their software out the door faster.
So if we take the logic of failure and we walk down this path, what we're seeing is actually we're shooting ourselves in the foot by not regulating and not clearly stating what we need from these companies in terms of protections around this very new technology. Chris. Yeah.
So, you know, I'm trying to think of an analogy here. I'm gonna use climate and weather, right? You know, so, you know, the last three years I've been building in some of these boats up and down the coast.
I have 60 years experience in with Florida. And in the last three years, I've both seen myself and spent a lot of time with people who lived their entire lives. Right here can tell you the differences.
I can see it, the climate has changed, but weather is what you deal with every day, right? And, and you have to worry about both at the same time. And, you know, since we're all sort of talking about weather, I'll try to talk about climate a little more.
And just as you know, this, these conditions going on, Alan, right now, you know, this is unusual. Florida January weather, this is not typical, but it is what it's, and I've managed to use those conditions to remove the vessels, achieve goals, and keep things going. And I don't see that ending.
I don't think we're likely to end up in these, you know, desert earth, you know, climate disaster. I think we have a lot of challenges. It's gonna be a mess generations after us.
I, I feel for them. But I think we'll figure it out similar to this, right? You know, I'm not overwhelmingly happy with the current conditions in this space.
Um, however, I think that there's opportunities even in this to get some things done. As you said, Alan, you know, I've, I've worked with the beltway an awful lot. I respect everybody who works there, but it's got its own problems.
I work with big corporations, respect those folks too. They have their big own problems. Sometimes when it rams into a wall, you put it back together differently.
So there's a certain flavor of that to this, you know, that will create a lot of bad weather, I think. Uh, but I think we can navigate through it. And 5, 10, 15 years now, we may say, you know, that train wreck actually helped us change the way we were doing things somehow in positive ways.
So that, that's the, let's burn it to the ground, then we'll start and hope it comes back better. Okay? But it's Not that, again, it isn't that bad.
It's an interesting, that's an interesting philosophy. You know, a lot of, a lot of people get hurt when they burn it to the ground, Chris. Oh yeah.
Storms, storms, you know, kill people all the time. But, you know, again, we're talking presidential, uh, policies and so forth and, and, and the beltway, and I've seen 30 years everything develop the national Infrastructure Protection plan, the sector coordinate councils, the information sharing systems around that they're not really going anywhere, right? Those are good things that are going in the right direction, right?
But the, the program that Phil Engler of the healthcare Isec and I have been running in partnership with cisa, is now starting to propagate through the information sharing community, whether or not, you know, Washington does anything. So we always had to be ready for these big powers like the US federal government to be, uh, fickle and transitory and build the things we're building into everything. So it's not dependent on one massive power, powerful organization to fix everything or screw it up.
Alright? So Now, absolutely. Long then, go Ahead.
Yeah, so I too agree with that. Um, but, uh, I'm glad that, uh, the executive orders that Biden couldn't place some of them, the supply chain, for example, uh, those are still untouched and hopefully we are moving in the right direction. Where I'm slightly concerned about is, uh, the, uh, the rollback things that are happening with companies going back meta, for example, and also the, uh, the hiring freeze that's happening across agencies.
'cause that is going to impact the staffing. And as a result, probably it'll, uh, halter the investigation that's going on with the hacking incidents that's been happening lately. And also, Christie, norm said, uh, to DHS that, you know, if she's confirmed that she's going to keep the department, uh, out of the efforts of combating disinformation and misinformation, and that is kind of like, um, I don't know.
I'm not sure about that. I don't know, uh, how that is going to pan out, especially with companies already seeing that, you know, they have a free ring to, you know, go back and self-police and, um, that is definitely, and, and mostly they just make it look like they're promoting, um, free speech and stuff like that. But, uh, this can go in a very wrong direction unless, uh, you know, guardrails are put in place.
Again, I'm gonna give you a little bit in Nebraska logic here. Experience, uh, well, I didn't live on a farm, lived around farms. And when you plow over fill, you turn it over, um, the first thing that comes up is weeds.
That's the first plant to rise out of the ground. 'cause it's the most hearty and growing. So when you burn things to the ground, you better be planting what you want to come up, because something's gonna arise.
It's kinda like culture. You, whether you, you intentionally derive what you want to have. You have a culture, it's, you get things that are gonna come up.
So I think that to me, the, the, what I don't agree with about the, just burn it all down, and let's see what comes back, is you're gonna get a lot of crap, you know, a lot of stuff that shouldn't be there either. And it may worse. That was Heartland knowledge, you know, home fun.
I love that, man. Good Nebraska. Be careful.
I wanna, I wanna get to Tracy for a second here though. So, so will the industry respond and fill this void? Can we do that?
Or is it just gonna be chaos? I think that, uh, I think that the European Union will, um, begin to be where we look to, for the, the guardrails around AI in particular. Um, I believe that we will go through a, a phase of chaos if there's not, uh, clear guidance, uh, from the federal government.
Uh, and I don't think it's a, it's a, you know, it's a train that's going as fast as it possibly can. If you look at the amount of money that's going into things like Space Force, which is, you know, Trump's baby, he created Space Force, um, and all of the, think about all the startups that are trying to push, um, you know, AI technology and satellites just in that alone, they are going to be consuming the, um, open source LLMs and the open source supply chain that Trump has said we don't need to regulate. So it is a big risk.
This is a, this is a big risk, but I wanna point out that Trump likes to, he's a, he's a, a hot topics guy. He goes into the hot topic store and he pulls off the shelf all the things that people are really talking about. And that's why if he had said, we, you know, we're gonna disband the sbam regulation, who would care?
Nobody, nobody, none of his voters really understand what an SBO is. But boy, AI is either something really cool that Elon Musk is doing, um, and that's the stuff he's gonna focus on Because he's a Hey, when the National Inquirer is the newspaper of record for your country, it says something. Yes, we gotta take a break though.
We're 25 minutes in here. I gotta jump to the next, uh, segment. Obviously we'll be revisiting this.
I have a feeling over the days, weeks, and months ahead, God help us. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. All right, folks, we're back. And our next story is also cybersecurity related, but the federal government is now issuing sanctions directly against certain cyber criminals that are out there, or at least alleged cyber criminals.
And we've been issuing sanctions for a long time. And Alan, I know you're are resident legal, legal, but is this gonna be an effective way to combat cyber criminals? Does this actually like disturb them or are they just kind of gonna look at it and go, wow, thanks for the notoriety.
You know, look, look what a great job sanctions have done in shutting down the Russian economy, right? You wanna talk about paper tigers? Look, what a great job.
You know, I mean, he, here's the problem with the sanctions. After a while, you become like the boy who cried wolf, right? So when, when, what, what gives the bite to our sanctions to make people other, you know, for people to say who gives a flying whatever, right?
It's because generally the world works on the dollar, and generally the world works through the US banking system. So when we put sanctions into place, that's the, that's the teeth of the tiger, right? You can't trade in dollars and you can't go onto our banking system, which controls the world.
But the problem is, the more we do with sanctions and do that, the more other parts of the world say we gotta get off the dollar. We, we can't be held hostage where the US is the sole, uh, you know, judge of who's sanctioned or not. And so you get things like this whole brick alliance, right?
Brazil, Russia, India, uh, China, and everyone else who's joined it. And make no mistake, this isn't the Warsaw PAC taking on NATO when we were younger. This is a, a, a, a organized attempt to get out from US dominance of the financial center sector to get off the dollar, to get away from the US banking system so that the, any sanctions we put in, whether it's against an individual, an oligarch in Russia, or a Chinese cybersecurity hacker, or the PLA itself, and they're, you know, hacking, uh, divisions, they will, they will con they will decrease in effectiveness the more we use them.
So my advice is use them judiciously, use them, we, we, where it makes sense, where it's gonna do something, sanctioning some Chinese individual who, who's a hacker. And I'm not saying they're not, and I'm not saying we shouldn't do things. I think there are other things to do besides sanctions.
I think there's a time and a place for offensive security operations that we don't need to publicize and, and you go do that kind of thing. Um, but to, to just throw sanctions up to show you did something just weakens our whole ability to, to have these sanctions have, have any kind of teeth. And, and I, so my long answer, Mike, no, they don't make a difference.
So in some ways, some ways, so, so this could be just an elaborate plot to get us to standardize on the Trump crypto coin instead of the dollar, right? Is that where the, I don't know if he's capable of elaborate. He doesn't do elaborate.
Well, like Tracy says, he's more of a, a, a national Enquirer or kind guy. It's either play in three di dimensional chess or checkers, one or the other, which is One or the other. So Chris, is there an effective mechanism for punishing individuals who commit these crimes that live in other countries and places that we can't reach and frankly may not care if they can't get add access to a dollar?
Yes. And since this is a tech show, I've, I've queued up in my head an example from the, uh, the CA working group, you know, that we're working on right now. So ISACs information sharing analysis centers are these brokers of sensitive information between public and private sector partners.
And there's a whole bunch from dozens and dozens these days. org is hundreds and hundreds of, of cyber emergency response team to do similar things. And what we've done in the working group is develop a process to help organizations like this develop a control architecture, is what we're talking about here.
A control architecture allows you to put some structure around what your defenses are. And in the, in the s bum sharing space, you know, we have a couple artifacts of, of of definition. We're dealing with the discovery, access or transport three different things of a da bomb, of a software bill material.
And each of those, as a different actor, you have different considerations, right? So we find, uh, organizations saying, I don't know what to do with this. But you walk through it and you say, all right, what I want is to hold the directory or hold the repository.
I have these, and therefore I put these controls around that. So this, you know, we're, we're resuming all the way back, you know, to seeing the earth from orbit Yeah. Sanctioned in the world.
Yeah, no, that's not actually one of those, you know, intelligently, sometimes sanctioned. Look, I was a Reagan Republican, you know, as in my early, you know, free market person in my early political life, I, I don't like sanctions. Like, but sometimes you have to say you are not playing fair, do the thing.
But to your point, Alan, if you just say that all the time, then in the words of the Great American philosopher Bruce Springsteen, right? You end up like a dog that's been beat too much, right? Spend half your time discovering up.
So yeah, it loses all this effectiveness if it's just a spam approach, that's not a control architecture, that's a grenade. Yeah. And we have to acknowledge where we are in the, um, in the world right now.
Our, as Alan pointed out, our sanctions don't really have that. They don't really have teeth anymore. Do, do people really, really, does an individual really, really care?
I, I don't believe they do. I don't believe that person's well to the us but Tracy, If you were a US citizen or a Western European or European citizen, perhaps they would care. Even maybe someone in the Middle East.
But if you're in China, If you're in China, why would you care? So, I mean, so we have to, I think we have to, we, and the government's not good at pivoting. We all know that.
And maybe to Chris's points, this is trying to be a pivot. Um, but I think we have to look at what other tools that we can use as opposed to just sanctions. We have to broaden our, our scope.
You know, maybe we can build a fortress around them so they can, you know, that particular company, any of their servers are blocked in. That would be a problem. There's gotta be other ways to do this.
There's gotta be more, um, you know, covert ways of, uh, solving this problem as opposed to just sanctions. And, you know, sanctions is a tool. Go ahead and slap 'em on that person or that company, but as it really gonna impact them, it just depends on who they are as you point out.
So to that point, just to take it to your previous comment about the ultimate logic flow, um, do we need to punish the institutions that allow these in individuals to transact in other currencies? And, you know, if you're gonna have a sanction, how far do you go with the enforcement thereof, right? Because there are banks in those countries that are letting these guys, well, you know, for lack of a better phrase, deposit Ill-gotten gains.
So how far do you go with that sanction? Or can I just think that it's, it's sort of like squeezing the balloon, right? And some something's gonna pop out somewhere there, there's no way to really contain it.
And, and if completely, and if there's anything we've learned over the last 10 years where, you know, sanctions, wherever we've used them as, they only work to a point. And we're only willing to go to a certain point of how far to enforce, enforce them. You know, you could some do something draconian that might be, um, might be more effective, but it also might be intolerable.
So I, I just think we put too much reliance on sanctions. They're, they're more, oftentimes they're just political to send a message the routes around it, whether, you know, getting whatever goods, AI, chips through other paths that shouldn't be going into a certain country. Country, you know, there, there's black markets, there's always ways people find things, find things ways to what they want or to make money.
And, uh, so it's, it's a, I think it's futile to think this is solves our problem. It's only a, a small part of what we would do. Yeah, we're, you know, we have a shield of a sword.
And right now the sanction sword is a little tiny knife. It's a dagger. And we need to figure out the shield.
That's, yeah, it's a dagger at best. We need to a butter knife maybe, but we need to figure out better, better shields. And this goes back to the previous conversation, is what we, you know, when we start taking, um, down regulations around tools that are going to be used by so many different companies and in so many different areas of, uh, of expertise like weapons, um, we're gonna open up ourselves for more of these.
And the shield is better right now than the sword or the butter knife as we're all I get, All I heard is do something draconian and a picture of Donald Trump just popped into my head, right? Mean, let, Let's end it right there. We're gonna take the break, we're gonna come back.
We've got another block to go over here about Bitbucket lessons learned as if we haven't learned any lessons yet. Lessons you're watching Textron Gang, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back in.
There was yet another outage this time involving Bitbucket and their, uh, CI/CD platform that's managed by Atlassian out of the cloud. And I'm, I feel like, you know, I don't really want to call out Atlassian and Bit Buck just specifically for this because what I'm trying to drive at here is it seems like these outages are happening more often or are we just more aware of them? Tracy, we moved everything in the cloud and now it seems like maybe it's not as robust and as reliable as we imagined.
Yes. Um, you know, I feel for all of those folks who had to suffer the outage on the 21st because when last time, um, GitHub had a similar problem, I can promise you I stormed around the office with my hands on my hips and I was so frustrated 'cause I was trying to get some code out the door. And it can be extremely frustrating.
And, you know, we don't think about, um, at least we at Deploy Hub, we don't necessarily think about building redundant systems to GitHub and certainly not to Bitbucket. So as DevOps engineers, we are very reliant on these cloud-based tools, especially version control. Uh, and you know, in all of our work that we're doing now, I think, no, it's still there in all the work we're doing now in, in DevOps, we're talking more and more about pushing DevOps up to the cloud.
SLSA says have a distributed build system, don't have them local. Push everything up, push everything up so it's not local and it can be better controlled. So when these systems go down, it's literally stops development, it stops us in our tracks.
And I don't think we have a good alternative. I really don't, you know, building these redundant systems where you could switch over from the cloud to something local isn't simple. It's extremely difficult because of the fact that we're updating it so often.
Now, I'm always kind of poo-pooing AI and DevOps, but not so much in platform engineering, right? So I feel like this problem, I believe it had to do with a, um, a database, um, being full or something of that sort, could possibly have been caught and stopped using AI in platform engineering. So I think what we have to do is consumers start pushing back on the people who are telling us, we're gonna, you know, pay us the money, we will support you, you don't have to worry about it.
And when it comes down, we need to push back. They should be doing a better job. Now, there are companies I know that have their local versions of Git.
Um, they have everything local and they're not impacted by it. And I think if you're a big company, you probably wanna go down that road. But for the smaller companies, you know, we're talking, you know, 500 million and less, we're gonna rely on those call providers to keep to, to keep us healthy.
And I'm really looking forward to seeing how AI can help predict potential failures so that platform engineers can fix it before it, it does fail. You know, it's, it's a, it's a trade off, right? Um, maybe you wouldn't be able to do all those things for yourself that a provider like, you know, Bitbucket or whatever service, we're setting that up and maintaining it.
And while it's painful when an outage happens, you one outage, okay, I get it happens. And uh, you know, certainly they're, uh, uh, you know, quality organization like Atlassian, it's gonna take measures to figure out not only how do they avoid that, that database overflow condition to, to uh, you know, be able to scale it further. You learn from those lessons.
That's what your SREs are also, you know, focused on and platform engineering. But I also look at it as, you know, if you had to run all that yourself, you may not have all those services. So are you trading off I can get a lot more done or do many more things because I'm using a service in the cloud than I could have myself or, you know, do I go with less and, and do my own thing, which also comes with my own maintenance and all of the other things to it.
So, you know, I, yeah, I feel for the providers, you know, when I'm the one affected, like you talk about Tracy, you know, you marsh around the room and I think they, what they should do when there's an outage, they should do the same thing now like they do in a, a sports event. You know, when when the signal feed gets cut off to the Steelers game, they switch over to the Patriots game. I'm just kidding.
And, and I love when they do that 'cause I'd much rather not watch my Steelers, but, um, and you're right Mitch, we As a small company, we couldn't do it. No. And we couldn't do everything we do.
And that's the point. That was the whole point behind the cloud, right? Atlassian's gonna do a much better job of hosting Bitbucket than you ever will.
Way AWS Google and Microsoft, they're gonna do a much better job and they pour and they have many more resources to pour in to building an infrastructure to host your applications and securing your applications and doing everything they do. But here's the underlying truth that all of us live by and, and we don't acknowledge it. We're all just zebras in the herd and one day the lion comes for you.
That's it. Alright, I'm gonna wrap up, I'm gonna wrap us up here. We got in on time about Zebras in Nebraska, but okay, well, there're on.
No, well, there might be zebras in the lions, but anyway, um, happy Monday everyone. We've got a great lineup of Textron TV behind us, so stay tuned for that. Uh, we'll be back tomorrow with a lot more Textron gang.
And until then, this Alan Shimel on behalf of our gang here today. Have a great day. We're out.



