Techstrong Gang – July 11, 2024
Alan, Mike, Mitch, Bonnie and Jon delve into the implications of an apparent failure by the Cyber Safety Review Board to fully review the SolarWinds attack in 2021.
Then, the gang dives into why more progress hasn’t been made in the realm of Industrial DevOps before highlighting the need for increased circularity to achieve sustainability goals.
Transcript
Hey, everyone, welcome. You know, there's nothing like a good cybersecurity coverup to get the blood flowing. We will find out, though, is this one feature a deep throat?
Is it real? We're also gonna be looking at the rise of industrial DevOps and a, a quick look and see in, uh, sustainability. All that, and more on Techron Gang.
Happy Thursday, everyone in Allen Shael here, four Textron gang. You know, I, I've gotta tell you before I get into everything, I really was reflecting on it this morning. I love doing Textron Gang.
You know, it, it, it kind of sets the tone for the day. I, I hope you folks at home have as much fun watching it as we do here. Uh, recording it.
It, it's, it's really a lot of fun. Um, anyway, as I mentioned in the opening, we've got a juicy cybersecurity coverup to co to discuss the rise of industrial DevOps and product circularity in the age of sustainability, featuring, uh, a video and some work that our own Bonnie Schneider's done. But before we jump into that, let me introduce you to who we have on board with the gang today.
Uh, as usual, I'll start with our remote workers and we're gonna go, you know, shifting left from west to east. We'll start with our editor, John Schwartz, who's out there in the valley. Hey, John, welcome.
Hi, it's good to be here again. Nice to have y'all with us all. Well with you, John.
Yeah, Everything's great. Uh, it's a beautiful Thursday morning. Absolutely.
Excellent. So, moving, as I said, west to East, stopping off. Next in the Rocky Mountains.
It's Mitch Ashley, our CTO, and, uh, Futurum, CTA. Hey, Mitch, everything. Well welcome.
You know, it's, um, I love, I love the smell of a good cybersecurity, uh, theory, uh, hack in the morning. So yes, Little nap pods. There's always a cover up.
It smells like nap pod smells like Victor Forever, right? Excellent, excellent. And then moving here to our, uh, tech Strong headquarters and studio.
Let me introduce our in-person, gang members. To my immediately immediate left is our, uh, echo Insights sustainability editor and analyst, Bonnie Schneider. Hey, Bonnie.
Welcome. Thanks, Alan. Good to be here.
Thank you. And to Bonnie's left, to my far left back home in Boca. Um, well for now anyway, our Chief content officer, Mike Ard.
Hey, Mike. Hey, how you doing? I, I'm, I'm missing 18 minutes of tape here somewhere.
Yeah. Wow. Rosemary Woods, Robert Ball reference.
Was it Rosemary Woods? You said? Mike, I'm gonna turn it around.
Robert. All the three people out there know that reference. There you go.
Showing your aging it count. Count up the movie. Think it was 18 minutes, wasn't it?
Just No, 18 and a half minutes or something. It was 18 and a half. Yeah.
John shows his age a little too there. Oh, yeah. Always Uhhuh.
The plumbers are at work, but, you know, plumbers, is it, is it really a coverup? I, I don't know. So that, let me just quickly say, this wasn't a Security Boulevard article, so I'm not swearing on my, I'm not putting my name on the line here.
But what do we got, Mike? So the details are as follows, and they are murky. So a couple of weeks ago we were talking about Brad Smith from Microsoft and his testimony, uh, in front of Con Congress about, um, a breach that happened involving a flaw in Microsoft software that was allegedly found by Chinese hackers.
That same flaw apparently is related to the infamous SolarWinds attack back in the day. And way back in 2021, president Biden created the Cyber Safety Review Board, and its first mission was to generate a report on the SolarWinds attack and what that meant for the public. Um, a funny thing happened on the way to delivery of the report.
They didn't write the report. And what they instead wound up doing is, uh, investigating Log four J Shell and a few other things that happened along the way, um, and never did this report. And as such people are saying, you know, because this board never actually did the actual work, we never discovered the original Microsoft flaw that the Chinese were using as well as the, apparently the Russians or whoever else was using this.
And so it's question of did somebody kinda abandon their task and job? 'cause that's what they were specifically ordered to do at the same time, to be fair, well, it turns out that this committee that's set up well, it doesn't have a full-time. Staff doesn't have any budget, doesn't have any subpoena power either.
So you, it might be understandable why given those resource constraints, they decided to go do something else. 'cause they're saying that the industry did all this SolarWinds reporting, and that was quote unquote good enough. And there was an investigation by the GAO who said, uh, yeah, I guess, you know, you mentioned, uh, SolarWinds in this Log four J report.
So that counted and, but now there's a lot of, is this article over here in ProPublica where it details all the machinations that went on, but there were folks who are questioning if they had stayed on their original mission and plan, would've found this flaw involving Microsoft much sooner, and we wouldn't have this current crisis that we're at. So it's a continuing story. So I'll start with you, but, you know, what's your take on this misadventure?
Yeah, this is, I'm here from the gov. I'm here to help. I'm from the government and I'm here to help.
This is what happens when you think the government's gonna try to ride rough shot over, you know, technology and cybersecurity. And especially, you know, you, you, you set up a board with no budget, no authority, no responsibility, and then b***h and moan after the fact that, that to me is just ridiculous. But the bigger issue for me is I don't think their lack of covering the, um, their lack of covering SolarWinds is what led to this Microsoft thing being so widespread.
Right? I, I, I don't think that's the connection, Frankly. I, I don't think the timelines add up.
I don't think the actual, you know, what we know about the Microsoft vulnerability and, and, and what we know about the SolarWinds vulnerability, it, it just doesn't add up to that. Did they not do their job as their job or their volunteer position was, was set out to be Yes. Mm-Hmm.
So disband it, but let's not blame the, the world, the Microsoft situation on Them. One added detail to that where, uh, apparently a Microsoft employee discovered this vulnerability a long time ago and alerted the company, and that was at the root of the Brad Smith testimony, where basically they ignored that because for whatever procedures that Microsoft had set up, um, the exacts at the company basically weren't paying attention to the security alerts coming from their own people. Mitch, um, if we abandon this board, what should be the role of the government in doing this?
And, um, you know, to Alan's point, one of the ironies of this thing is, you know, Congress is pulling people up in front of it to, uh, give them a hard time in the case of Microsoft about their security issues, de deservedly so. But they're not actually funding anything to go investigate these issues either. So, you know, they're not, they're kind of talking on both ends of their mouth.
Maybe. Well, first remind me, remind me when Congress came from the security industry from cyber, anybody, you know, cap three, Isn't it? Is it also true that the vice chair of this, this committee was, is a top security executive at Google too?
Yeah. The, the volunteers, yeah. The board is made up of some folks from industry too, and that adds another level of complexity.
I, I don't, I don't think We want to have a congressional committee to hold every cyber attack significant one or not. Um, every, every vendor accountable for what happened in that cyber attack. I mean, the vulnerability was known.
The, the issue here is the vulnerability was known, right? Um, uh, Uh, The attackers exploited it to get into the build process of creating software that did a good job of hiding themselves. So if they took up too much CPU or too much resource, they kind of back things down and, and stay hit, stayed hidden for a while.
And, and most people think of this as a supply chain attack as how the, the malware got distributed through updates and the Orion software from SolarWinds. Um, but the real, the real story is how they got into the build process, into the kind of platform that, that the framework that's built on the building, the software, because that's sort of where the, the crown jewels are, if you will. Uh, I, I, I don't give a lot of service to, you know, let's bash another congressional committee that didn't do their job.
How many do we have that, that if maybe a few have, most haven't, I'm not really worried about that. You know, if you, you, if you, uh, task Brian Krebs to, to, to lead something, you know, someone from our industry, um, uh, then great. That would be fantastic.
I think things would get done and there'd be a good voice for it. Ultimately, what it ended up was kind of throwing Microsoft under the table anyway, or at least calling 'em on the carpet about their culture of security and security issues. And I, I think that's, that's the thing we needed to have happen.
So don't look, look a gift result in, in the math, right. You know, just take, take what you get and move on. I'd rather focus on to your, your original question, Mike.
I've, I've written about this and, and a little bit on LinkedIn. I, I think we are in a cyber war three world war cyber war already. It's already happening, and we're living it.
And, you know, it's, it's just the next thing away. As soon as our power gr grid goes down and isn't recoverable for some period of time, water supply gets polluted. There's so many ways that if someone wants to bring down another country, ours included, um, that there's so many vulnerabilities, and I, and I think we need a secretary of cyber defense.
It needs to be not just a commission or a board. I think it needs to be, it's as important as our military strategy of what our cyber defense, um, not just strategy, but execution is, and not that, you know, another cabinet seat solves the problem, but it sure puts somebody up there that we can hold accountable and the government, and that's who I would hold accountable. See, but when you, when you, when you have a cabinet position, that's just the, the type of the iceberg, literally Mm-hmm.
Right. They need a full department underneath them that, that gets it all done. Exactly.
And you, you can do this. I think if we look at where our, if you look at where our cyber defenses or our cyber accountability is, now it's split between Homeland Security and DOD, right? And assuming if you want to make the claim that NSA and some of the other three letter agencies fall under DOD, right?
CIA, that you know, what you need to do is maybe pull parts from DOD, pull parts from Homeland Security and make a Department of Cybersecurity, and then you could have a Secretary of cybersecurity. But you know what, Mitch? Hello Boomer.
That sounds real sixties to me. And, you know, we're gonna have the health human services and, and you know, I, I don't know if creating, if we need to create a cabinet level secretary and a full department underneath it, it solves, excuse me, solves the issue here. I think the issue here is much more, we need a, a, a great partnership between industry technology companies and the government as, as you know, as well as our critical infrastructure kind of stuff that works in partnership to make sure this stuff happens.
Right? Well, you know, that's the issue. Yeah.
I'm sorry, Go ahead, John. You, you mentioned, you, me, I'm sorry. You mentioned this partnership between government and industry, and in a sense, there have been attempts to do that.
I think Schumer was trying to do that with ai, which would entail some type of security, and that's kind of going nowhere. Uh, lack of funding among other things. Staffing.
What's interesting to me though, um, yeah, I, I, Mitch kind of Mitch, Mitch is bringing this up, and it always goes back to this digital Pearl Harbor scare tactics we've heard, and there is a element of, of reality to it that what, what made SolarWinds, um, attractive as a target, right, was that it served the government in thousands of American companies. And it makes me wonder about what just happened with OpenAI, where we didn't know about a breach. They claim it was, it was minor only after the New York Times reported on something that happened more than a year ago.
Uh, they also seem to be a target rich because of the data and who they work with. It's, it just makes me think about what's going on here. Absence the cyber equivalent of the National Transportation Safety Boards, we're gonna have more of these incidents, and maybe they're gonna involve AI companies beyond something like a SolarWinds, which could go even further.
So that's my con my concern. And, you know, I'm not gonna bash the government, but I mean, they're trying, but it just doesn't seem to be gaining any traction. So I maybe we do need some sort of zr Sorry, Bonnie.
Oh, no, I was just gonna say, I think it, it depends on where the eyes are, you know, and what, where the focus is of, of the, of the moment. And then, then it kind of grows and, and feeds on itself. One of the things that I see coming into it is, um, all of these, uh, damaging events that we're seeing from extreme weather, just exposing how vulnerable infrastructure is just, uh, the other day we had the third Avenue bridge in Manhattan, um, not be able to work anymore because it was under heat duress.
So the infrastructure is raging all around us, and that's only setting up the stage even more in a vulnerable way for cyber attacks. So I think there'll be a, a combination of things that will bring this to the forefront. And I also think that sometimes when something like this happens, especially if the government is involved and there's some, you know, they miss, maybe they miss something and there, there's a level of embarrassment there.
Somebody has to get blamed for it. I think you're on to the core issue there. It's the transparency.
So let me get this straight. We found the time to go after Log four J, which, you know, everybody and his brother was looking for, and hadn't been actually shown to maybe be in a major breach yet, but we ignored the, uh, SolarWinds incident, which involved lots of government agencies getting hacked, and maybe those agencies didn't do the right thing, and their software supply chains were not properly secure. And maybe it was just convenient not to go look at that end of it, because, you know, we didn't have quote unquote enough resources, even though that was our charter.
Something doesn't smell right. Mm-Hmm. I agree.
Well, by the way, I'm, I'm gonna be under heat duress this afternoon, Alex, so, Okay. But anyway, that's about No, to your, to your question. So it wasn't that solar, and it wasn't that the government wasn't doing its job customers of SolarWinds, let's say, doing that.
This is, this is malware getting into code that that soda wounds unknowingly was distributing. Um, and, and this is the shared trust model, right? Uh, we, we, we trust that the people that we work with are applying security measures and, and don't get hacked.
And, but when they do, if it's not, if it's more than just stealing secrets, like in the case of OpenAI is, which is what got stolen last year in, in this case, it's dis a, a vehicle for distributing malware because you use our product. And that's what was so damaging about this. Again, the underlying part of this is how did a, that was a distribution network, and it was a sort of perfect example of a company to, if you can get in their supply chain, their distribution chain to customers, you, you can really do something pervasive.
It goes back to if you can, but you, if you could also get sort of the head of the river where this whole starts back in the DevOps and the, the software development process, now you're really, you've got access. And I think that's what we missed talking about SolarWinds. So this is that we, everybody talked about SolarWinds a lot, but they talked about the distribution supply chain issue.
They didn't talk about the problem in the, in the, uh, workflow in the, in the tool chain where the attack actually got it and sat there and, uh, and injected this malware. You know, the scary thing to me always with these incidents is that the companies will tell you what they know, but of often they don't know everything, right? With open ai, I mean, they're, again, I'll bring them up.
They keep downplaying, oh, it's just a, a community message board. That's what they know of, and that's what always what bothers me is that it goes far beyond that. I'll bet they know a lot more than that would be my guess, Jen.
Yeah, I know. Knowing how Those things go, This excuse if we're not gonna publicly disclose it because it, it doesn't involve our customers or our partners. I, I just never buy that.
That involves secrets. That's pretty, pretty substantial. Yeah.
You know, I, I've been in the cyber industry for damn near 30 years, and there's always been a very strong feeling in the cyber industry that if we police ourselves, we could keep the government out of our business. And in the case of SolarWinds, I, I will say, from what I've seen there was, there was postmortem's ad infin here, right? Mm-Hmm mm-Hmm.
I, the last thing I think we needed was yet some cyber safety board that's going to give me one more rehash of, of how this malware was injected into the SolarWinds code base, and then what flowed from there to Microsoft and any, I, I mu and, and you know, where I am politically, but I'd much rather have the industry policing itself than, than try to make the government, the sheriff here, If you wanna go that route, than the industry needs to do a better damn job than they have been doing. And some Independent, it's uneven And some independent body independent needs to certify whatever the heck it is. We're saying that actually happened, because otherwise we're kind of asking the, so-called Fox to guard the hen house here, and not everybody's gonna come clean unless they have to testify in some way that is sworn.
Otherwise, you know, there'll be a lot of sins of omission at the very least. Well, there's been some changes in disclosure requirements, right? So you're supposed to now disclose within four days, I believe it is, of an incident, uh, being discovered.
I'm not sure what, they're not clear on what the criteria is. What when do you know that they then have to disclose, but then what do you have to disclose? This goes back to the open AI example.
Like, we don't think it was that big of a deal, you know? And then that, that of course breeds the coverup conspiracies, and they, yes, they did cover up at least, you know, how serious it was. Is it more serious?
We don't know. Um, I, I, I think the, some of the unevenness is what do you have to disclose? Because it's really left up to each organization and what they feel is in their best interest for them and their customers, particularly their bus business.
I, I think, I, I agree with you Alan, uh, commission after the fact. I mean, we're still debating, you know, who killed Kennedy at this point from commissions after, Well, after all, it was you and me. I know I was, I was on the second grassy knoll behind the bush.
And, uh, and, uh, he's just Giving you a little rolling stunts. There you go. So, commissions, government commissions are not the way to do it by the time that commission happens.
We are so far down the pike from the event happening and all the things that could have happened since, which is a good example of this, of, of what happened with Orion and SolarWinds. So it, it, what I'm afraid of, and I'm, I'm not going to be the Armageddon person, but is it gonna take a Cyber nine 11 for us to, to step up and then really do something serious about this comprehensive? Probably usually when it comes, and you may Get, you may get the government you don't want, right?
When it comes to cybersecurity, that's usually what ha does have to happen. Somebody has to be affected directly and has to be almost horrific. I, I, I disagree.
I think we're getting far too inured to all these attacks. And I cannot remember the number of times that somebody has said to me, by, darn, this is gonna be a wake up call, right? And everybody rolls over and hits The news, oh, the, we haven't had a nine 11 level attack.
We've had solar, wind stuff we did on Netflix. They, they show what that Would look like. That would, it makes for great drama, great show.
Look, I see business here. Maybe we could do independent boards as a service. Somebody IB aas s You know, it's a shame too, because there are tons of people working in the government who are awesome security experts, but clearly they're not working on this review board.
Maybe we need a Defcon style bo wall of shame, the sheep for people like EP the Wall of Sheep. Anyway, look, we're, we're, we're way over on this one, but it was a juicy, it's a juicy story. We would love a good cover up.
Um, but let's hope you know that something good comes out of this. Let's take a break here on the Gang, though. We're gonna come back and let's talk about a subject I haven't spoken about in a while.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com where the world meets DevOps. All right, and we're back.
And we're talking about a topic, well, it's been a long time since we actually discussed this in any meaningful way, but there's a new report out from coppi Automation talking about how, um, code that doesn't get properly deployed or misconfigured is costing manufacturing companies $126 million per shutdown. This seems like a rather large number, and I can't help but wonder, it's not like we haven't been talking about these concepts for a decade. So let's start with you, Alan, but, you know, what's your sense of, I feel like when I look at DevOps, everybody gets into to like a desktop, but even in mobile and ENG and now all these industrial systems, we haven't made the same level of progress.
I don't feel, Um, I don't know. I, I honestly, I don't necessarily agree. I, I think the problem with industrial, we, we've made a lot of progress in industrial DevOps, as we call it.
I think the issue is, we started, so, you know, a lot of the industrial stuff that we're DevOps saying was so 1950s, and so relatively simple binary open on, off on open close kind of stuff, you know, and we, we've added some automation, we've added, you know, some additional functionality, but it's, you know, it, there's a difference between industrial DevOps and iot, right? Let's not confuse the, the two. And, um, there's only so much you can do with some of these industrial systems, I believe is, is the answer.
So It's ironic DevOps the whipping boy here. It's ironic because where did DevOps come from? You know, Toyota Manufacturing and a lot of the lean principles and all of the, so much quality, so much of what we do in DevOps came from that industry.
Uh, I think part of one of the points you're making, Alan, is that it, it's different if you're set up a new factory and you're using latest equipment and secure supply chains and all that kind of stuff. But there's an awful lot if you travel, you know, to different, uh, manufacturing places. I mean, I've seen, you know, computers that are the PKI warehouse sitting under some manager's desk in a, in a factory.
You know, it is not, it is not the most modern conditions. There is an equity across all of this. So I remember when early in my career, I worked for UDS and a friend of mine was the DBA on some GM systems.
And it was a serious matter if, if, if the database or the system was down for an hour, they started calling the next shift not to come in, right? And, and it cost them then it was like a million dollars an hour or something like that. It, it's big money when the line goes down.
So I think the point of this article was saying, yeah, it's industrial DevOps, but we also have security issues being introduced in the software that we're leasing. And that's a lot of what's causing this problem back to security, You know, you know, oh, Lucidworks came out with a study, I'm sorry, Mike, there was another study that came out Wednesday from Lucidworks. They talked to 2,500 AI decision makers, and they found that manufacturer's enthusiasm, uh, for AI and spending drop significantly.
And one of the main reasons was security as well as accuracy concerns. And so, just, just to kind of double up what you said, there's, there's this in embrace of, of new technology because they feel they have to do it, then the repercussions and the consequences have reared back or made them think twice about making this investment and security as the main reason I'm scratching my head 'cause are business leaders thinking that this is a, just a cost of doing business, or how many, um, shutdowns at 125 million a throw do I have to have before I kind of wake up and go, maybe I should replace those systems? 'cause it's actually cheaper to replace those systems than it is to suffer the shutdowns.
Well, one time is an issue. Systemic is a bigger, much bigger problem, right? When you recognize something, we've gotta do something about, let's get to the root cause of it.
I can't speak 'cause you know, I'm not in those discussions in those executive suites and manufacturing. But if it really costs money on the bottom line and it's significant, people will push back and say, we gotta do something different. But maybe that's towards John's point is like, you know, we have to be careful what we do.
Let's not go ahead rush into AI or, you know, what do we do about data privacy and security concerns. So it's hard for me to say, 'cause I'm not having those discussions, at least not today. Yeah.
I, I actually have, uh, thought about that AI issue because there, you know, there's an old joke about ai. It's one thing to be wrong, it's another thing to be wrong at scale. So imagine a manufacturing line that just goes haywire because there's, you know, an AI model that suddenly says we need, you know, half a million, half a million gallons of yogurt, you know?
Mm-Hmm. Yogurt's on sale tomorrow. Um, I mean with that, you know, that, that, I don't know if that's a bit of an oxymoron, an old joke about ai, don't get stuck me there, but look, you know, the rise of industrial DevOps.
com. Someone did a survey on it, we shine a spotlight on it, and all it's old is new. Um, I don't know, I think I, I've given it everything I got on this one.
Well, what is it about best practices for Dell Ops that makes it so uneven? Because there are none. No, seriously.
Look, you know, when we first launched the DevOps Institute, we were very careful not to use the term best practices. We used the term emerging practices. And the reason for it is DevOps, unlike other frameworks and other technology kind of movements, it was never a manifesto or a definition or, you know, it was, it was short on those kinds of things.
But, you know, I've spoken to Patrick Dubo, the man who coined the term about this, and my friend John Willis and Damon Edwards and a lot of the early DevOps folks. And that was done on purpose so that DevOps wouldn't be shackled with prior notions or prior expectations that it would find its own way and, and allow it to evolve. And that's just what's happened, right?
No matter what gets out there. Platform engineering, SRE, all of these things, ML ops, AI ops, gen ai, DevOps is, is highly adaptable because it's kind of squishy in that regard, right? There's no skeleton.
Maybe in the case of industrial, that's part of the problem. 'cause these outfits are used to, you know, here's my process. It runs this way all the time.
Follow the blue blueprint. And we, given that level of flexibility and openness, they can't wrap their heads around, well Here's, here's what the irony of it is. If, if you think about improving security is the same process as the secure is improving quality.
And where does quality to QM come from, right? So much of the manufacturing world. And so it's that iterative, you know, incrementally improving, just improving and recycling and cycling.
Again, improving security of our applications. You would think coming from that environment, in that engineering quality, meth methodology, mindset of manufacturing, if that can be more strongly kind of move over into the security or software quality part of it, that's how you fix this, right? So I think there of any industry, I would think they're well equipped to address this in, in this issue themselves.
I agree. I agree. But also you gotta realize sometimes you just don't want to take a square peg and make that round haul fit it.
Maybe DevOps isn't the right tool for all of those use cases. It's possible. On that note, let's take a break.
We're gonna be back with our third segment today, which is product circularity. In the age of sustainability, you are watching tech strung Ag Cloud native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud native. Now Hey, we're back here on text Sean Gang. So for our next segment, we wanna feature, uh, a recent, uh, echo insights that our own body Schneider did here on product circularity in the age of sustainability.
Barney set it, set it up for us. Oh, thanks Alan. You know, it's, uh, it's interesting.
HP has really been a leader in terms of hardware and sustainability, and one of their newer iterations is called HP Renew Solutions. So I spoke with, uh, grant Hoffman, who is the senior vice president, um, and general manager of brand new solutions to talk about how this all works. Because I know most of us might know circularity logically means from beginning of a product to the end of life, but what happens in between and how can we extend that whole product lifestyle?
So that's what, uh, grant shared with me in this clip. So if you're an HP customer and you have units that you would like to move along, maybe you got some sitting in your closet, or you just have some old devices, you can absolutely send us a list. We'll send you the value for those devices, and then you send them back.
And then we take care of those devices. We have a very exciting program called the HP Certified Refurbished Licensing Program. So these are folks that do their own refurbishment.
It's a very large industry today. If they meet HP's quality standards, we'll back them with an HP warranty. And basically it gives peace of mind to our customers and definitely protects our brand over on the circular market.
So bringing it kind of full circle, so to speak, back into each of these categories, renew solutions, whether it's the hardware category, whether it's the services or programs for us, for us, each of these are taking HP devices all the way from new, all the way through the end of life. So for us new sales all the way through EOL, that's the way we're supporting circularity. That's great.
Now, I know you have an ambitious goal for 2030. It sounds like you're well on your way to achieving it, but can you explain that? Yes, very, very true.
So yeah, 75% circular, uh, circularity by 2030. And so, uh, before Renew Solutions was announced, which was just less than a year ago, HP had been on this journey and done some absolutely amazing things. And they continue to do, and that's everything from ensuring like paper-based packaging or derived from recycled or certified sources.
We have everything from reducing to single use package, uh, single use plastic packaging. Uh, we're also increasing the overall recycled plastic in the devices just to name a few. Then Renew Solutions comes into the mix.
We're supporting everything from PCs and printers and hybrid gears. It's embedded in the culture of HP and our opportunity, you know, in the, in the community of brand new solutions to help drive the sustainability is, uh, is amazing. And we absolutely 100% are gonna make the world a better place for future generations.
So HP's product refurbishing, um, ability to license and give credit to really independent contractors that can take a look at the product and certify it, I think is, is groundbreaking because it will just open up the scope for more people to repair their devices and to get them refurbished. And what HP Renew Solutions is encouraging folks to do is go through your stuff. Do you have an HP laptop?
It's, that's, you know, you're done with it. We'll, we'll send, you know, we'll send it to us and we will make use of it. So I, I think it's a great idea and I think it's gonna catch on with a lot of other tech companies.
So are they taking this to recycle it and taking the parts apart and reusing it? Or are they gonna send it back to me with like, you know, new equipment inside it that I don't see, You really have both options and they're, they're going to, they might take yours and then sell it to me and say, we certify this has been refurbished, or it can come back to you as well. But they're also allowing independent, um, re repair institutes.
I I would imagine to make those repairs. It's gonna, it everyone is working in, in sync to give this laptop the longest length of life that they can. And they're also doing it globally, which is really interesting.
Recycling all the material and allowing people, um, maybe that wouldn't have access to the latest models. Maybe they, they can use the refurbished one. So it's a, it's a global effort with hp.
Are there other PC companies, Bonnie, that are, that are doing this? Or is HP kind of in a sense of pioneering this field? Well, HP is, I think more known particularly for the heart printers and, and, and, and laptops and things like that.
But yes, it's, that whole movement of Repairability is definitely catching on. Um, we're seeing, um, Google backing legislation in Oregon that's, um, for the right to repair for people and be able to do that. And even Apple, which was an opponent of, of Right to repair for so long is now, uh, moved into the direction of making their parts available, um, making repair guides available.
And that holds true for Dell as well. Um, and Microsoft, of course, a a leader in that, in that space. So it's really allowing people and to get maximum life outta their computer because in the end it reduces electronic waste.
So it's, it's good for the consumer but also good for the planet. So I have a bias, and my bias is kind of like somebody's bias about used cars versus new cars. And when I get a new laptop, I always think about it in terms of, well, this thing is gonna need to be able to run software for the next two to three years.
So I'm always like, they get the most amount of machine I can get for the dollars I have on the assumption that I'm gonna own it for two to three years. And so I will shy away from older equipment. 'cause I'm gonna assume that that isn't gonna be able to run the next wave of software coming out because well, developers, you know, they just keep running exponential amounts of code regardless of whether it could be more efficient or not.
And so is, is this a cultural issue or that we have at play here? Not just a technical issue. I think also it depends on like who the customer is.
Some, someone like you, Mike, you're gonna be ahead of the, the game or, uh, when it comes to tech, but there's possibly some consumers that are looking for, they're fine with it, you know, if it's a refurbished model and, and maybe they're gonna keep it for a year or two and it'll go on to the next person. So I'm actually, I fall into that category. So I have two PCs, I have a new one, thank you, Alan, uh, from Dell.
And then I have an older one, which is ancient from HP that I, that still has some sort of value. And so this is something I would consider because I don't want to pay for a second laptop and I, but I don't want to discard this. So in a sense, I'm just thinking about what the financial investment on my part's gonna be.
So look, first of all, you see this in other electronics, right? If you go on Amazon and look at any of their Echo devices or you know, any of the Amazon, they sell refurb for not enough of a discount versus new in my opinion, but they sell a lot of refurbed equipment. Part of it is the American culture of, and Mike, you, you know, you stood up right there and stepped in it.
I'm a, I want, I want the newest best as fastest. I'm a victim of marketing. You are.
You, you've been marketed too, but how many people, how many of your friends out there you talk to and they say, oh, I have a problem with my phone. Let me see your phone if I can fix it for you. Oh, you're running a, an iPhone eight, that's great.
This like, did you get this out of a museum or you want to donate it to a museum? You know, I've got an iPhone 15 here, I don't quite remember what the eight did, but a lot of people in this world don't require the iPhone 15. The iPhone eight or nine works just fine for them as long as I can replace the battery.
And that's what this is about. These tech vendors and Apples really guilty of this. They used to make it really hard to replace the battery.
Yeah. Mm-Hmm. It was, you were better off throwing out the phone and you sell carrier would give you a new one if you signed for a two year contract.
And, and the heck with it. And, and then what I always felt, or what I always thought was happening is that Apple then takes that iPhone eight, puts a new battery on it and sells it in Malaysia or somewhere, you know, uh, uh, uh, where they, there's a real market for that. You see it with automobiles, right?
In Singapore. In Singapore, you're only allowed a certain amount of automobiles the government allows on the island. And all automobiles must be seven years or newer.
Once it's seven years older, you must get rid of that car. What do they do? They ship these cars onto big giant, you know, freighters and they sell 'em in Indonesia and a bunch of the other, you know, uh, countries in, in the Asia Pacific region where you can get away with having a 10 or a 15-year-old car that, you know, that's supply chain, that's economics.
The fact that we're doing it now in, in laptops makes perfect sense to me. It's not gonna appeal to the Mike ards of the world. Well, If I can steampunk my machine, I'd be interested.
I could like you, if I could get like a Blackberry thumb wheel smashed onto an Android phone, I mean now we're talking, I would use that. There You go. There's one thing also I wanted to mention, it kind of ties into what we're talking about earlier, is that certain states in the US and of course in the European Union are starting to create laws and mandates for the manufacturers to, to supply, um, parts.
Things like batteries in the eu Mm-Hmm. And also repair guides, resources, tools. Um, some of the states that are looking at that legislation include New York, Minnesota, and California right now.
And I mentioned Oregon and then some of the tech companies are backing it. So it's interesting to see how it'll evolve. I Back the no, no, no serviceable parts label, right?
We would find on, on, I think it's a good thing to open up the ecosystem of people who can repair it, whether it's end users or not in some cases. Could, it could be. Um, uh, what's interesting in, because I worked in iot commercial and, and retail for a while in the security part of the world and, and really got a chance to realize that understand better that lifecycle.
There's the lifecycle of a product and then there's the real lifecycle of a product, right? How how many, um, Lenovo laptops are sitting, you know, inside a cabinet in an oil well in Texas that are monitoring the SCADA system and you know, it's running NT from whatever version back when products stay around for a long time, much longer than than manufacturers expect their life to. So that iPhone eight, you know, by the way, it stopped being updated at iOS, whatever version that they said, we'll only go backwards so far.
So you, you kinda have these tiers of yes, there's the published, uh, lifecycle end of life when this is gonna be going away, and then there's sort of the aftermarket end of life of how long it really lives and, and is it serviceable at that point, or it just frankly is replaceable or it lives until it dies and then you've gotta replace it, you know, wait till the thing falls over and it dies. Now Alan and Mike and I don't live in that world. We live in, I was just gonna say Mitch physician heal thyself.
Yeah, I'm, I'm the, uh, I will be the hypocrite, the biggest hypocrite of that. Yeah, absolutely. Mike and I, I'll, I'll, I'll, I'll stand up and say hello.
My name is Alan and I'm a new tech freak too. Um, I mean this is my new iPad 11. There you go.
See I took my iPad 10 and that's now my spare iPad. And then my iPad air three or four, which isn't that old. I donated to our video team here to use as a teleprompter when we're on the road.
That's because your kids are gone now. High cycle Your hand me downs go to the production, It's the hand me down. You Don't have enough confidence in your 11 to totally give up your 10.
No, no. Well, I, my, my house has multiple floors and sometimes I don't feel like, oh no, downstairs. So I have one, a downstairs machine and an upstairs machine.
This is a first world problem if I ever heard. Wow. Well that's what I said.
Hello, my name Ellen. You know, John wanted a new laptop. He, I said, Mac or Windows?
He said Windows. I said, whoa, that's an easy one. And you know, we had a, that same day he had the, uh, a new Windows machine.
Yeah, but Wait, it's just a, but, but you know, just going back, so what Bonnie's what's interesting about what Bonnie's reporting to me also is that there are a vast majority of people who are not the Mitch's, mikes and the world. No, they're not power users Is what we used to call ourselves. Well, they can't afford it, right?
So this is an alternative for them, which is nice. And it's, it's something they can go to because I live in the Valley and it's all about product end the year, right? Yeah.
Somebody always, they size you are sized up not just on your income or your vocation, but the i the phone you carry and if it's not an IPhone does Matter. Oh God, yes. Um, especially with the iPhone.
This, this Is why you guys are driving Teslas out there, right? Exactly. Yeah, exactly.
I mean, it's, it's acy. I mean, it has to be the latest and the greatest. And if not, you're somehow diminished as a human being.
How, you know what, my God, that is pretty shallow, but again, guilty. Hey, we're gonna, we're gonna wrap up today's text on gang. Just as a reminder, as always, we have a full lineup of Textron TV following this.
So please go check that out. Stay with us. There's a lot of great content on there.
There's some great interviews and segments from some of the virtual events we've been doing. We'll be back tomorrow with another great Textron gang. I'm, I'm out though, I'm on vacation for the next week guys, but there's enough people in this gang to carry on without me.
And, uh, we'll have more good stuff with you tomorrow. So for now, this is on behalf of Mike and Be, be Bonnie and Mitchell and John. I feel like I'm singing a folk song there.
Um, this is Alan Shival. We're out for Textron Gang.



