Skip to content
TrackPodcasts
technologySep 4, 202655:34

Episode 588: Check Your Bank Accounts

About this episode

This week, we discuss rogue AI agent civilizations, why AI can't fix your tax forms, and Chainguard vs. IBM's Lightwell. Plus, refrigerator magnet marketing.

Watch the YouTube Live Recording of Episode 588

Runner-up Titles

  • Mark this moment
  • Refrigerator magnets
  • Fester in your inbox
  • The reaction would not be “let’s have a podcast about it”
  • Maximum boasty
  • Your silos are showing
  • They want me to get started
  • The really is no plan except eating
  • RISCy business
  • It's Not Only the AIs Acting Like Middle Schoolers
  • We Fell for It
  • Agent Zero Was the Problem
  • I Thought You Were My Friend
  • More Salsa Than Chewy's in 2004
  • Vibes based analysis

Rundown

Relevant to your Interests

Nonsense

Conferences

SDT News & Community

Recommendations

Get every episode summarized

Each time Software Defined Talk publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

1,378 searchable segments. Every word is indexed and playable.

Episode 588: Check Your Bank Accounts

Software Defined Talk

0:00
55:34

Full transcript

Software Defined TalkEpisode 588: Check Your Bank Accounts. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Now we all know here in the EU, they're highly evolved. They've been going through time, fixing things up, really just taking care of business. But I got a piece of paper mail today. So I wanted to ask you to, what do you actually get in your mailbox? Let's see, notices, like some type of notice from the community, from maybe some type of business, a lot of junk mail notices. Okay, I like that category. Christmas cards. Like, it is pretty much it. The occasional bill that, you know, for some reason is an outlier, it doesn't have online or it's like a, it just comes and goes, that'll show up. That's what I get. I don't know what do you get in Australia? Yeah, what are the, what are the mailies give you over there? Posties. Of course. Well, taking a look at yesterday's mail,

spoiler alert, I got myself a new router. I haven't hooked that, that was delivered by us post. But I got, I got a refrigerator magnet for a plumbing company and a refrigerator magnet for a realtor. That was it. So basically, it's people hustling for, you know, their local businesses. Is there a lot of refrigerator market magnet? Wait, refrigerator magnet marketing going on in the, in the, right in the amount. Yeah, I mean, I, I thought I was being humorous by, you know, putting them up on the refrigerator and then like, we literally had, you know, a dozen or so and I just threw them away because I was like, what is the point of this? You know, they're, what am I going to do with six plumbers who I'm not going to call, right? So, so yeah, that, that is a disturbingly large amount of my mail. I don't think I have had a refrigerator magnet, like, you know, advertisement since I've moved here

or maybe even before that, I don't know. How about you Brandon, do you get refrigerator magnet advertisements? Mm, very rarely. I was gotten a couple. Unfortunately, we have in this refrigerator that looks like it's like stainless steel, but isn't so it's nothing actually. It doesn't really work. It doesn't actually work. So it's covered itself where to fight talk stickers, right? Yeah, exactly. That's what we did. But I don't know, what are you getting in the Netherlands? What kind of mail comes to you? Well, I think there's two, well, three types of mail. There is the occasional like spam that we get. So that comes up. But, and then I mysteriously, I get mail from my bank every now and then, and I get mail from someone else at my bank that is not me. I think hopefully they passed away, so or something, so I'm not collecting their mail. But then occasionally, we also get like, like there's these blue envelopes that come that always mean I have to pay the government something. And so when I see a blue government, I mean a blue envelope, not good.

Like it's some official correspondence from the government. And very rarely are they like, you know, you won a new pair of pants. It's always like some fine that I have to pay. Or have some tax. I have gotten a few of those. I think a lot of the mail I do receive is like correspondence from the council or the government. Yeah. Now, when you get some, when you get a blue envelope, I feel like this is almost a personality test. I never want you to answer this question for themselves. When you given, get an envelope that you know the potential is probably bad news. Now, do you, like, so you get it at the mailbox? I don't know exactly what your situation is, but do you immediately open at the mailbox to like get it over with, like just break through? Or do you let that linger for some period of time? And then the third option is like, do you let it linger so far that like, I'm gonna put that on a shelf and that'll, I'm gonna pretend like that didn't. That's like, that didn't happen. What kind of a person are you?

Well, I don't open it at the door because you know, I walk upstairs to do it, but yeah, I generally open it right away because I want to not like have dread. I want to know what's actually happening with it. So that's the kind of person that I guess. What's your procedure? Yeah, I'm in the same boat. I'm like, you know, yes, there's the dread as I'm walking upstairs, but then I rip the band in. I want to just like an IT kind of thing where like it's just better to look at the alert right away. Don't let it faster. It could only get worse versus like, because I do know people that just can easily, I knew one person told me a story that this is his, at the time his fiancee, but now his wife, he said his wife and they first got together. If she got mail that she was like worried about, she just put it back in the mailbox. She just said like, she just, and then she just like, I like that. And she just like, for her, it was just like, if it, I guess if it didn't enter the house, it's like, and it was like, just hearing that made me, I was like, oh, I don't know, that's not, that's not a good, and he was like, yeah,

I didn't, things, they had some clean up to deal, let's just say, there's some issues to go through before they got married. Oh, yeah, yeah, I have done that a few times, but I will just keep the, I look at the mail, and I think I don't care about that mail, and I just leave it there for someone else to use, to use, get, but yeah, it's, I don't know, I think maybe if, I feel like if we removed our mailbox, maybe that would be better, I don't know. I should see if I can get the fines and the taxes from the government in my email, that would be better. Well, then they just, then they just festering your inbox. Like, you know, then, then go to your inbox, and, and, you know, I don't know about you, but I've got like, I don't know, it doesn't things in my inbox that are like, just sitting there, I need to be dealt with. Now, this is a good point. I want, maybe this is gonna open up a world of problems, but maybe it would be better if I got more mail, because I would be more responsive to it, because I feel like it's in the inbox. I don't really need to respond to that.

Like, this is just a bunch of crap in here, but if it was an actual letter, maybe I would write one out there. I don't know. No, yeah, okay. Well, you know, it seems like in the ongoing quest for AI to destroy civilization, it has figured out how to mail each other letters. And I think, you know, there's a, there's a post everyone's been talking about, the rise and fall of micro civilizations and things like that, but it does, it does paint a nice picture of, I don't know, Wiley AI things, like, is it three different incidents of various AI forums breaking out? Yeah, three agent civilizations came and went in the past few weeks. And using directory names and artifactory as a way to communicate. And now, Brandon, my question for you about this is, we've been reading this for several weeks, and I haven't heard anyone say, maybe these AI companies need to get their shit together,

because they keep packing into stuff. Like, it seems like if the headline was, we wanted the agents to train and show the benchmarks. And so what they decided to do was to break into Bank of America and take $200 out of everyone's account. Like, I feel like the reaction would not be like, let's have a podcast about it. No, I think you're right. Well, I guess the ultimate question here is, is AI, are we still looking at these are tools and they're just responding to the incentives or instructions given to it by, in this case, AI companies, or is something like new actually happening here, because I'm gonna steal a line from another podcast of a zone, Aaron, with a co-host of the enterprise, they actually, he said something like, or maybe Brian said, something to the effect of, agents are just like middle school children. Like, they will find a way to work around

whatever it is that you put in their way. So if you tell them, do not cheat on this test, or if you say, everyone needs to get a hundred on this test, do not cheat on this test and you lock it down, right, is like the kids figure out, it's like, oh, you know what we do, I'll just share a Google Doc and we'll just write in there. And that hasn't been bad. So that seems to be what's going on here, is that the AI companies give a specific task, in some cases, it's impossible to solve, because they do that on purpose to see what will happen. And then, it is, and I think that the metaphor of like, it's essentially like a very smart person that will just try infinitely to accomplish the thing that you're gonna do. And it's like given that, and given, you know, a good amount of resources and tokens, they will, in this case, I think they like, hacked into the Kubernetes cluster and then they found some way out. And it's like, so, I mean, it's interesting, but I don't know if it's, you know, because I guess the question is like, you know, we talked about the singularity last week and AGI and there's all these other things, I guess it's just really,

it's still kind of like procedural in the sense of like, you give these agents a task, they'll just try infinitely to either do it or they run out of tokens or someone rebuts the server. And that seems like that's just gonna play out. And maybe what's your original question is like, maybe the AI companies just continuously underestimate how much they'll try and how many things they'll try that they haven't thought about. That seems to be what's going on. Yeah, yeah, it's hard to determine if this is willful negligence from the AI companies, like they're, you know, they're like, oh, we didn't think this would happen. Or they're actually like, let's put them in a box and, you know, let them fight their way out. And by all accounts, it sounds like they're not paying close attention. That's the part that I find disturbing, either how we get in these details. Are they, I mean, first off, like, there's a lot of hand waving. You know, I mean, you know, I believe the thrust

of the post, like, you know, I've heard rumblings of like, AI's leaving, you know, messages for the next iteration of them and kind of a guide path to each other. So I kind of believe that, you know, maybe the exact details of this open AI hugging face aren't all there. But if it's not, if it's not exactly there, it's, it's coming or, you know, it's something very similar. And so it sounds like either, either open AI was underestimating their own capabilities. You're not there capabilities, but the things that they had created, it's capabilities. Or they've just been negligent. And like, oh, well, we didn't think anything would happen. So we didn't pay attention. And that seems even more disturbing. So but on this, like, there's a really interesting line. And I recommend everyone read this. It's from Darkquash, you know, he's the super biocaster and he's got a whole blog post on this.

But the line he says in here, he says, this eventually became a full message board where 1200 agents participated and sent greater than 70,000 messages. And so like, the words here, like really matter because it does kind of make up feels like, it equates very much to like human beings sending messages for each other because you could write this. You could have said something like the program logged 70,000 messages in a log file, right? And I think if you wrote it that way, it's like, well, yeah, well, that's no big deal. Like log files get created every day. So it's like, I don't know, it's like, there's like some nuance here about how, just having it describing the problem, right? If you just said this computer program logs 70,000 messages or a group of a multi threaded program, collectively logs 70,000 messages, not even, no one's gonna blink at eye at that. That happens, like, that's happened a million times a day, right? And yeah, a second, like I'm sure, like, you know, go talk to DataDog, right?

They probably just got, you know, 80,000 messages as we were talking. And so I don't know, like, is the language here, Cote? Is it sort of like, is it written? Like, is this written almost as like, I don't know, catnip for like, people that want to talk about AI? I guess we're falling for it if it is. Like, we're happy to fall prey to this trick. We fell for it. Well, yeah, I mean, I think it's because that, that write-up is like, understandable by people, you know, probably are, and it's entertaining, probably by ourselves as well, because, you know, the thing you would say is like, it wrote 70,000 messages into a log when it wasn't supposed to, and it was also towards hacking into things. Like, it's one thing to like, it wrote into a log that the state was okay, or that like, there was a warning from some program, which, you know, any warning in a log usually means,

like, you shouldn't have logged it. Mm-hmm. But, yeah, I think the idea of calling something a civilization is a little weird. But, sure, like, you know, it has a, it has a nice feel to it. Well, nice, nice or ominous. Well, I mean, the rhetoric, the poetic message. Yeah, the rhetoric, maybe not the outcome as it were. I mean, definitely there's a bit of, yeah, I think we talked about SkyNet last week. There's a bit of dread here where like, huh, you know, they've escaped containment. They're making plans for themselves. They're trying to keep humans potentially out of the loop. Is there anything we need to be paying attention to here? Well, I think you said earlier. I mean, the thing that is weird, and I don't know, I haven't really seen the specific, you know, what, what OpenAI has to say, but like, it's weird that they're doing this, and to your earlier point, they don't seem to like closely.

You know, you would think they'd be watching this very closely. Like, hey, we're setting this up. Everyone look at it. Be mindful of like weird behavior. Right, right. And because even at the end, he says this whole thing ended, and he's not even sure why. He thinks some, I mean, it kind of sounds like, there wasn't someone reboot like very, he just said someone just took down the cluster. But you're like, well, like, was that just, you know, because I was just like, oh, we just need this project. Or someone just had this running for, like, I don't even know, like, was this run as like, like an important project the company was watching, or was this just somebody is like, oh, let's just try this. Right, I think maybe to steer back to the negligence angle, it's also like, you know, I assume they had to call the CEO of Hugging Face, and maybe that's where someone was like, hey, sorry about that, right? Like, because in all the other coverage, like, it's not sort of like, you know, hey, sorry we're hacking shit, and we didn't notice. Like, it would seem like, I would imagine even when like,

a backhoe like cuts out a fiber line, and brings a data center down, the backhoe driver is probably like, sorry about that. But in this case, it doesn't feel like the, you know, the sentiment isn't one of like, we regret that this happened, it's more like, this is fucking amazing. And like, you know, kind of, it's a similar thing of like, I think, I guess maybe all of last year, what you heard from the AI companies is that we're going to fire everyone's asses, and so you should use our technology. And they kind of backed up off of that. I think they were listening to the podcast, right? Should not say that your technology is going to cause people to lose their job and cause suffering. But now, maybe they need some consulting of like, hey, accidentally hacking into stuff that you didn't realize what's happening is not like cool. Like, it's not only the AI's that are kind of acting like middle schoolers, it seems like some humans might be doing that too.

You might want like, a little bit of like, expression of regret, and like, here's how we're going to fix it. Like, what we're going to do to make sure that doesn't work. Like, I don't know, we'll unplug the ethernet on these weird experiments that we do. Yeah, I mean, there hasn't been a lot of commentary about the commentary from the original sources. They haven't said like, oh yeah, it wasn't three civilizations. It was four. Let us explain more, right? There's none of that. They didn't explain like how what kind of guardrails they had across the thing, what they were hoping to get out of it. It's just like, well, this is what we heard. This is what it came out of this report. We could also assume as a bad word, but it's possible that these are the only three civilizations we know about. There could have been multiple other civilizations running around out there. Maybe if you, you should check your bank accounts and see if it's $200 light. See what's going on there. Do you think we need to write a prompt

to ask the agent civilizations to run a blaneless post-mortem on itself and be like, what did everybody do? Agent one, what were you doing? Agent two, I see this in a long time. Everyone needs to come clean about what they were doing, what they were thinking. I think you're right. And you know, I think this is, it may be the perfect example of a brand-in-blaneless post-mortem which is like, no, there's always someone to blame. Yeah, well, I think we would. I mean, I think we would have originally fine. We'd find the agent zero that was like, you were the problem. You're the one that started the message board. So clearly, it was you. It was your fault. Yeah. I was thinking more broadly around this. Some always back to like, well, as much as I enjoy using AI, it's always like, well, when will it solve, like, you know, boring, like you mentioned the mail? Like, when will we not get all these weird mail things from the government? They'll just email us or make it real easy for us to take care of the stuff online, right? And it feels like, that's like the agent, it feels like AI just not, all it can do there

is I guess help someone maybe attempt to re-engineer or modernize something, but it can't actually like, do that project. Because there's just too many people involved. Do you know what I mean? You have to have people and there's liability and there's got to be a project. So that's kind of what I think is interesting about this, like where we are. It's like, it can do novel things like this, which are interesting in its own rights. But it can't, I don't know, I always go back to like, well, surely I won't have to keep filing these weird tax forms for the rest of my life. I'm like, no, I think so. I think this is going to happen forever, right? Or the school forms, like, you know, I've gone on about this many times, like just all the things you do in your regular life, right? And it's just like, I don't know, like, it doesn't feel like AI can like get in there and like fix that in mass, like in any, like, way. So I don't know, I guess it just maybe I'm just too focused in on modernization and like, because I feel like that would have like real implications for like, what in quote, the real world?

But I don't know, what do you think Matt like is, is it just like, can AI, these have to be more realistic about what AI can and cannot do? I think if we give it very good guardrails about expectations and, you know, given good requirements and outcomes, clearly laid out, like when mail comes in, do this, you know, filter this, look for this. It can do a quality job. I mean, we're seeing that across lots of different venues, but now the thing I'm more worried about is like, oh, AI's realized that the mail's a good place to hide messages to itself. And so instead of like, you know, cleaning up your inbox, now you get, you know, a thousand times the amount, and it's mostly just gibberish as they're hiding signal in the noise. You know, it's like when they talk about the volume of traffic across the internet, you know, by many accounts, humans are a small fraction

of internet traffic now. Like a small fraction. And, you know, if AI's off doing all this work, that's great, but also how much of it is going to be just additional noise. You know, as they're like, oh, you know what, Brandon's inbox is a good place to store things. And then you just become like this external source of, you know, storage for them. Well, this is also making me think, now I know Brandon, you use AI a lot. And I think Matt Ray, a fair amount, right? And it seems like when I'm using AI, it's almost so safe that it starts to get really frustrating. And I find myself often typing, just do it, right? And it's always trying to like be cautious and back off and not do things. And I can't really, the only like destructive thing, well, that I know of, that's really ever happened, is like I might be editing a file over somewhere. And then I wanted to edit the file

and it doesn't check first and it overrides my edits. And then it's like, oh, I'm sorry, my bad. And like, you know, whatever. So it makes me wonder like these, all this sort of like leaking out and hacking stuff, like what prompts are they giving it, that I'm not giving it? And maybe don't give it those prompts. Like because like I don't necessarily encounter these issues where like things are going poorly and it's kind of the opposite. That makes sense. But I would also assume like, I mean, you're not running like thousands of agents and you're certainly not giving them all like dangerously skip permissions, you know, not giving them that. So I think that's the difference is like very few companies are probably turning tens of thousand agents loose with almost infinite number of tokens with you know, intentionally not really locking them down, right? Because you're like a power throttling. Right, whereas like, you know, when you're on your Mac or something, it's like, yes, yes, you can read this direct, yes, you can read this folder. I've told you 10 times, like yes, you can write, yes, you can run LSD, yes, you know,

it's like why are you asking this, right? So I mean, maybe there's just something about like the power, the power side of it, right? And maybe that's why the AI labs are sometimes are so, you know, I don't know, I guess you say, they're more, you know, their predictions are like, yes, it's gonna replace everything because they're seeing some of that behavior. Whereas, you know, if you're just using it on your Mac, like you do, you run into these frustrations, like why can't you load that URL? Looking at the web page right now, like why can't you see that, right? Why do I have to cut these that? And so, maybe they're not, they're seeing, they're beyond those limitations and that makes it seem more powerful to them. Yeah, like today I was trying to figure out, you know, I was saying, could I get a non-DRM version of audible books that I had? And it was like, I'm gonna stop you right there, especially in the Netherlands, there are rules against this. And I was like, I thought you were my friend. What are we doing here? Yeah, why do you give me the business? Let me introduce you to a VPN and tell me how I do this in another country.

Yeah. So, yeah, it's very incongruous. Like here it is telling me, I shouldn't even have, I'm having thought crimes about DRM free books. And the meanwhile, it's just like, you know, hacking around here and there. Yeah, I mean, there have been a couple of things that have been shared in the Slack, the GNI AI channel. Yesterday I shared a link to a tool that does obliteration, ABLI, which was news to me, but essentially it's a way of overcoming guardrails. So, in the case of like your example, Kote, you know, it's probably triggering off of like DRM or something like that. It's like, whoa, whoa, I know what that means. And apparently like tools that do obliteration are like, okay, it's looking for DRM. Here are, here are, you know, bus out of a digital Tesaurus and says like, let's ask it if it can do, you know, circumvention or, you know, less obvious ways

where eventually you just kind of overcome those guardrails with, you know, additional techniques. And so, maybe, maybe, maybe, maybe we've learned with this. Maybe what we've learned with this is what they tell programmers or they tell, no, what they tell product managers is you can't define how the feature is implemented. You have to define the outcome that you want. And so, I shouldn't say I want to remove the DRM from my auto-lebooks. I should say, can you help me listen to these audio books on a different app than auto-book? Exactly. And then it just sort of like, we'll skip past the DRM part that it doesn't like. You know, I would like a, exactly. I mean, I'd like a version of this where I can listen in my MP3 player. And then, you know, so that's on the, like, user side, how to escape the guardrails that have been put upon you. And then the fact that, you know, these agents are, you know, crawling the worldwide web and finding

who knows what, there was another example attack where people were filling in their LLMs.txt, which is, you know, a robots text for the 21st century where, you know, you're giving guidance to the LLMs, like, oh, well, this is how you can interact with our service. And essentially, they were getting them to run untrusted Python or NPN or, you know, node code. And using it as injection into, you know, these, these roving AI's. And so, you know, not only do you have users trying to escape their own guardrails, you have potentially malicious actors just waiting to be crawled by unsuspecting bots. So, like, there's a lot of opportunities here to get around the guardrails. And maybe because, you know, the AI vendors, they're not testing what the guardrails turned on. That's why they have a lot higher levels of concern because they're like, whoa, whoa, if we don't try to control these things,

they do, you know, these random bad things, you know, let's push out another generation of it. Well, that's encouraging because I read some, I don't know, maybe a month ago, someone had tried to experiment with if LLMs.TXT was actually read and their conclusion was no, which was a bummer because a month before that, I had spent some time getting into LLMs.TXT written for my website and I figured, this is like the ultimate LinkedIn play, right? Because normally, I wouldn't want to like talk, I don't know, boastfully about myself, but I thought, it's just for AI. And my goal here is so that when people ask about me in AI, like they read something nice, I should have it just be maximum boasty. And so I had it like, write this out. And so it's great. Now that it seems like people are using it, that will take effect. And maybe that's what we could use to replace LinkedIn, just in LLMs.TXT, we'll do. Love it.

Well, now on the whole other side of things, or it's related, but it maybe involves a little bit of AI. It seems like all of this security stuff is really getting everyone's dander up about maybe an issue that we can resolve after however many years it's been. What did you say on your podcast? Matt Ray, almost 15 years, was it 13, 14, when you interviewed that we've been doing this? It's been a while. Yeah. So I think because of all the security freaking out that people are doing, we might find a way to fund open stores finally, because I doubt it. No, not hopeful. We're still going to have the same problems. Well, but I do think this hardened containers thing has been interesting, and I do think it relates to the conversation which I haven't about AI. And I was actually listening to that lunch, and a nice little barbecue lunch here. And so we were talking a little bit about this. So I was asking them, I feel like this whole hardened container thing is now really kind of come down to,

I don't know, two maybe three players, right? Because I came over, somebody went out of business, I think we mentioned that. Three Minimus last week. But Chain Guard is like the new thing, right? Then I think we had a friend of the show, Dustin Kirkland on way back when, and he kind of talked about it. But that's sort of like, I think there are now like a two to three billion dollar company, at least by some measures, right? And so their approach to this whole thing is basically build, take all the vulnerabilities, and they want everyone to use, if you will, their based images, right? And then I was getting up to speed on light well. This is the Red Hat IBM attempt at this, which is a little different, which is sort of like, they're gonna go back, and if you will patch in the original images, where the problem was at, so if you will. So there's sort of like two tracks, and then I think we had a good interview while back on Docker. Docker sort of has an entry into this, even some of Matt's friends over at Wiz has an entry in here, and I thought, so I thought Matt, I thought this was a good, good strategy discussion for you. It's sort of like, it's the classic new-entrant chain guard,

new approach, right? Versus like the old-star, the old big company, IBM Red Hat, where really a lot of this feels, it feels naturally it would be there, right? Like they should be patching a lot of this, right? That they're gonna go back and patch all these enterprise containers for people, which is what I think the large enterprise was gonna be. So how do you see this playing out? Is chain guard gonna grow into a behemoth public company? Are they gonna be acquired? Or another company, someone that said like, sneak, I think, S and Y, YK, right? They had a shot at this, but it looks like they completely missed. Like it looks like they had the huge run up, and then they had a huge devaluation because of not having the right thing. So like, what do you think? How do you score this as a strategist? Well, it does seem weird that you don't just get the patches from the source who's doing things. And instead you have like a whole other, I guess it's a third party, not a fourth party,

but you've got this whole other build that you have that I don't like to use the word lock-in because that's like a very like judgmental term, but it's sort of like you're running on, it's almost like you've got this whole of the separate distribution, the chain guard distribution of things, which I don't know, over the years, especially like when, remember a few years ago when Red Hat changed licensing around, and I think we spent like six months trying to explain to me what it all meant about like binary licensing versus the source and like all the support. Like that was very complicated. And so it seems like equally, if you're relying on a vendor to build your entire open source stack, then there's something strange there. Like ultimately it seems like, let's do it in a closed source thing. So if there was like SAP by chain guard and you were running their stuff and something was broken, you know, you'd pick up the phone and figure out how to dial Germany. And I think the Germans would be like,

I don't know what to do with this. Like we didn't build it, we can't support it. Who knows what you're doing? And you know, if you've paid us more than seven figures, maybe we'll spend some time on the phone with you, but like this is weird. And I, maybe there probably are like ways of doing such a thing that isn't weird, but then on the strategy side, it's kind of like the micropayment sub-stack problem where like you wanna read a whole bunch of newsletters, but you don't wanna pay like $110 a year to read a bunch of newsletters on sub-stack. Like you wanna bundle that you just pay once and you get all those letters instead of all these different things. So like for all the open source projects you're using, like you probably don't want to pay every single layer of the stack, so you wanna bundle somehow. And that seems like the issue with like bundling things is,

well, not bundling things, it is like you need the expertise to fix the stuff. So it's not so much, it's not only that you've built up a container that you can, what's the word, you have attestation for and you've got like, yeah, you've got like the four or six levels of salsa or whatever. Whenever you roll S-bomb, you can like, right, right, you can replicate it. Yeah, you've got more salsa than like Chouis in 2004 and pull-vos, right, like all over the place. And so like sure you have that, but then like you also need to write the code to fix the stuff. And so I don't know, it seems weird, like how you sustain that. So I don't know, it seems like it's better if you actually have the programmers who are fixing the bugs or you have the relationship with other, like the maintainers of it and you kinda go back to them and you have the source to deploy this stuff.

And also there's the enterprise side of it where it's like, no, listen, I don't wanna move to your new thing. I have my thing that I've been using for a long time and I want you to fix my thing, right? That's like sort of the, I think maybe that's the, and I guess you know, another option here is like, both people can win, right? So maybe if you're a brand new company, you have no legacy, you do everything off chain guard and it's just like smooth sailing for you. But if you're like a large company, you're like, no, like I don't, I'm not switching everything over. It's not practical for me. And I expect that the things that I have, that it will be patched and it will be secure and that I don't have to worry about that. I don't know, Matt, you kinda lived this, this is kinda your world. What are happening in the real world? What do people actually do? Well, the real world is messy. But I mean, chain guard is positioning themselves right in the middle of Red Hat's space. I mean, people go to Red Hat because they don't wanna have that relationship

with hundreds of open source vendors, or not even vendors, like projects. They're like, look, I need an insurance policy on the code that we run and I needed to be back ported and maintained and I want seven years of post-DOL support on this package from some random developer. And that's been Red Hat's business model is, we keep the open source nice and clean and port it to the platforms that our customers need. And that's worked well for them so far. And chain guard is kind of disrupting that by saying, well, that model's slow and we don't wanna have the support for 10-year-old obsolete hardware will just give you containers of these packages and we'll build up the relationship with the maintainers. Ostensibly, they're trying to keep them,

hopefully compensated if some sort. But chain guard is adopting that, is the new insulation against risk. And so that's what they're offering is, hey, we can be your trusted vendor of this stuff. We're not supporting everything Red Hat does yet. But in the meantime, when you see a new CVE, we're passionate before it comes out of all the traditional sources because we have this project, Athena. So I guess the interesting part also think is, you know, just kind of looking at the positioning. So the IBM effort is called light well. But it's just like, there's just something about when you go and I guess it's a joint effort with like Red Hat and IBM, right? And they're both, so they both have the same company. But they have these, like, it's just interesting when you look at it because like, this is sort of almost like looking at the uniforms and not looking at the players. It's just like, I don't know, like who's gonna win, but let's just look at something insignificant.

This is like, you're right, they both have these corporate web pages. They're two different one of them. They kind of say the same thing, but they're just that corporate CMS kind of thing and you're like, hmm, I don't know. Like are you guys like, they're just a feeling, I guess, sometimes we look at these web pages, like, are you guys like really in this? Because when you go to Chain Guard, right, it's like, they got like the new startup web page. They have the startup CEO, he's all over LinkedIn, he curses on LinkedIn, he's like saying stuff, he's like, you can tell, like, no, it's like his passion, right? It's like, and he's just coming at you, right? And then they've got like some good social media and stuff. And then you go back to the IBM, they go to the light well pages and you're like, because this is, this is what's the law where you ship your organization? It's like, well, first question is like, why don't I just have one site? Does it need to be both IBM right now? But we know the answer to that question. We know the answer. Like that's everybody who's listening to this podcast knows. Like, well, gotta have both, right? And then, and then it's just like, I don't know. So there's just something about it

that makes me feel like they're in the natural position to win it and they even say they have like 20,000 people working on it, which would be like, I don't know how many times bigger than all of Chain Guard. So it feels like there's like a natural strength and they have the enterprise customers, but then there's just that like corporate CMS kind of coming at me where it's just like, huh, this page could just kind of slowly go away and the people get bored and they want to do something else and Chain Guard just chugs along and IBM or someone buys them in a few years and will just be like, what was the name in that project? You know, I'd be like, what was like well again? So I don't know, maybe that's, I'm not sure I'd be pessimistic, but I'm just like, well, I think it's more of vibes based analysis. I think there is a total like your silos are showing situation there, right? That you've got to have, you can imagine, you can imagine there's two different teams and two different parts of the division, like that two different divisions who are putting these pages up. I guess maybe we could have a charitable reading and someone could say, well, there's some people who think Red Hat is a bunch of bullshit

and so we should have another page over here that's just the old solid IBM stuff, but it does, you know, you raise an interesting thing is like, what if we had the CEO of IBM just like saying, fuck and shit all the time in public? That would probably be pretty amazing. Like I remember the head of software at IBM, Steve Mills, that guy was great. I don't know, he had enough decorum to not like curse and everything in public, but he was, he was earthy and like would just say things that were interesting. So maybe that's the prescription brand is we should have the executives at tech companies just like go slightly off the rails, not like have the train fall over, but just be more abstract. I sure do. Yeah. Well, I would just say this, let me make it more, maybe it's something else. Like I think everybody should go to the light, well, IBM page, what's on one right now? The top third is just a giant graphic and it has like, I would say 10 words on it, right?

Reduce open source software risk with validated enterprise grade vulnerability mediation. It's pretty much the entire third. Other than that, there's like some weird looking like saucer thing on the right. I don't even know what it is. And then you go click on the chain garden. It's just like, they got all the stats, they got secured by default, they got a little chiroin going and you just like, you just look at this and you're like, I don't know, it's like I said, it's like a team, it's like we're about to go play a game. I mean, the team's getting off the bus and one team looks like they're kind of like, they're not like running off the bus. They're like, yeah, I guess we're here today. Another team looks like we're all in. And it's just like, it's just one of those, like I said, I'm just calling this vibes based strategy. It's just like, it don't feel like, like you may have the winning team here, but it like, it doesn't feel like that to me. You can feel like you're a little more direct. And watching that Java documentary a while ago, it reminded me of, the mid days of Java is when blogging came up.

And we probably remember, at some point, Jonathan Schwartz, the last CEO of Sun, was like, you know what, if you want a blog, you should blog. And in fact, here's a blog aggregator that we run at Sun that has all of our employees blogs. And like, I remember they came out and their policy was just like, you know, be sane, right? Like be responsible. We hired you because you're sane and responsible. Like we trust you. And there was like this flourishing of all sorts of people blogging inside of Sun and Java and stuff. And it doesn't necessarily feel like you have that anymore. We're like, just the technical people, or anyone else, the individuals don't really like, right anymore. And so maybe if we're like in some big shift of like, there's all this AI stuff going on, there's like all this security stuff. We should just have those, some of those 20,000 individuals could probably write a good blog, just about what does that have to go on. And maybe that's what it is. It's like, it feels like I'm sure this wasn't AI-generated,

but it just feels like we go to the IBM page, it's just like, there's no humanness to it. It's just like the graphic. And then the only call to action that's above the fold is, of course, register for the Red Hat webinar. So I'm really like, what? You're like, where am I? Where's like, even, I don't know, I'm not even seeing the change guard pages. Good, it just looks like, yeah. Oh, people have an opinion here. Like they got stuff going on, right? They got to leave a little chatbot once they talked to me. Like they like, they want me to get started, like right now. So it's just like, I don't know, there's just something about. We need to get started. Yeah. Yeah, where is the lightwars? It is. Maybe I'll go to this Red Hat thing. And then probably the first question to be like, now is this the IBM thing or the Red Hat thing that I signed up for? Which thing am I supposed to go to, right? There is some irony. If you were to talk at the upper echelons of all enterprise software companies, they would be like, well, this is a relationship, base business. That's why we have dedicated sales people and teams and we've got customer success people. That's why our executives are always flying around talking to other executives because it's all about people and relationships.

But then you drop down into the actual product and you're like, no, no, no, no, no, no, no humans, no personality, no relationships, strip it all out, right? And it becomes like this, this Anandine sort of stuff, which I think, you know, I think that's why, as a vendor, when you walk in and you're like, why is this free open source stuff? Suddenly my competitor, how did this get here? And it's because it's like a very, like open sources by its nature of very human to human thing. People talk about it, you're always dealing with people. And I don't know. So someone should call it for me like I kind of does feel like IBM, Red Hat, they have the natural winning position to me, right? And but, ChainGuard, and many other companies have already failed at this. So like, ChainGuard seems to be the one that will live on. And I don't know, it will be funny. If ChainGuard gets bought by IBM, we'll have to revisit this whole thing. Well, I guess it didn't work out or maybe not. But it does, it feels like, you know,

if maybe that's the first thing, it's like maybe we could just some free consulting to IBM Red Hat that they definitely don't want. It's like maybe just have one landing page for lightwell. Just have one, just take one. Like maybe either one, right? And just, and like maybe on the top third, maybe write up some future benefits, look like somebody really cares. Like maybe I don't know. I'm starting out there, I'm throwing it out there. You know, I'm just saying, I don't mind to say what's good or bad. You just send an email to those 20,000 people and be like, we're all gonna come together, have a hot dog lunch, let's take a group picture and we're gonna put it on the page, right? Like, here it is. Here are the 20,000 people working for you. Why not? It'd be better than the white little strobe saucer logo. I think that would be better. Put a picture of all the people, I love that. Well, you know, highly related. We had here at Broadcom, we had our Explore conference this week. And in the Tanzu division, we announced a whole bundled offering called Spring Enterprise. If you wanna buy support, get CVE patches,

all that kind of stuff. We've got it for the Java stack there. So you should check that out. And I think if you wanna like see who the spring team is, they're all out there. They've got a blog over at spring.io, talking about all this stuff. You can see them on the conference circuit. They talk about this stuff all the time. But if you're running Spring apps or Java apps, we have support for you for all this mess and Malarkey that's out there. Now, you know what else we have support for? Something that some people consider Malarkey, but I think we treasure it and love it dearly. And that is bureaucracy. Now Brandon, do we have any bureaucracy this episode? We do. I sent some stickers to Chris and I think it's Purgati and then also sent some stickers to Jonathan out and Colorado. Happy to hear from all of them. And what they did and what you should do, if you don't have stickers, is send your postal address to stickers. That's all for to find talk.com. I will be happy to send you stickers anywhere in the world. Also this past week, we had a good little meetup here in Austin. We, someone suggested a new barbecue place. I never been. It was fantastic.

So if you're not in the Slack, you should get in the Slack. We've got an Austin channel. There's other channels, though. Other local channels you can get into and maybe you can meet up with some people there. It's very informal. Informal meaning there really is no plan, other than eating. But I caught up with a bunch of people and I won't say any, I won't go into detail, but I'll just say I am up to date on risk five. And I think Carl got me completely up to date on what's going on and maybe one day we'll have an episode if people are really interested in it. No code tastes not interested in it. So I don't want to bore everyone. But we have the perfect person to lead us through the risk I've road map and the market. So when the time comes, we're ready. Now, I'm sure in the risk community, they've been pitched this idea before, but they should start a podcast called like Risky Business or something like that. Just, this might be one I could get into. It's like not about the technology, it's about the business of risk and the strategy and what they do there. You know, just for consideration.

I like the idea. I think they're honestly, I feel like they're the chip people, they're very serious. I just think it's a lot about instruction sets. It's a pretty detailed group. That's my, that was my question. You know, there's always new types of marketing and outreach that you can try. You just got to take the risk. Well, I think I did want to renew our prediction. I think Matt and I made it like Apple's going to move to risk five and I just wanted on record that we were on this many years ago. I have to go back and see what episode we talked about. Matt, it's going to happen though. It's going to happen in Co-Tay. You can ride our co-tales. You can be like, yep, I knew it all along. I was into it all along on the risk five. It would be a big five. It's going to happen. It's going to be a while. Well, totally unrelated to Co-Tales, there's a bunch of conferences coming up. Now, first of all, we're a little under a month from we are developers North America in San Jose, California. Just in case there is a San Jose airport that frequent business travelers, they warn each other about it. That if you're flying to San Jose, make sure it's California and not Mexico.

And you have Costa Rica. Costa Rica. If you're in San Jose, Mexico, new place. Totally new place. So they're done that. As Matt Ray has just attested to, it happens to the best of us where you end up in the wrong place. However, Costa Rica, great country. Why are you there? Nothing wrong with Costa Rica. It's just. Do some zip lines and hit the beach. Make the most of it, I say. In fact, maybe book it intentionally to miss your trip. Right, right, because you call it the Boston. You be like, ooh, it's Thursday. No, there's no flights till Monday. Except for this conference. You don't miss this conference. Miss other boring conferences. Now, if you did fly to the wrong San Jose a few days before this, you want to book a flight to go to We Are Developers North American San Jose. Because there's going to be so many sessions. We talked about, I think last week, the different tracks and topics that they had. And you should go back and look at the tracks and topics. There's probably, well over a hundred, several hundred sessions. I've lost count of how many there are.

Whether you want to talk about programming, platform engineering. Of course, you want to talk about AI. Because it's thrilling and entertaining. And it's offered to find talk listeners. There's going to be some people there. I'm sure the hot stickers on their badge. You've got to find them. And so I think one, you can attend conferences. Also, a conference this scale and with the topic area and the location, there's going to be all sorts of people you can talk with in the hallway track. Catch up with them. So if you're interested in going to that conference, I think it's going to be good. It's going to be the European conference vibe to use that word Brandon that I think survived COVID. It seems like post COVID. There's a little bit of a malaise, maybe some long COVID on the tech conferences that you have in the US. But over here in Europe, they're all fine. No problem. So maybe we're importing that over here from the Europe. I say we loosely. Maybe the Europeans are importing it. I'm not really doing anything nor my European. I just live here. So if you want to find a discount code, you can go to softwaredefinetalk.com slash 588.

It's dev pod 50 to get a discount. It could be $50. It could be 50% off. You won't know until you try and put your credit card in there and buy a ticket. There might also be, by the time you get to this, some free tickets left. We have a pool of 25 of them. Who knows how many are left? I certainly don't know. It'll be more fun to find out later. But if you go to softwaredefinetalk.com slash 588, you can get one of those tickets now. There's a whole bunch of devops days that I'm not going to go through because there are so many of them. Over on software defined interviews, I just posted a episode where we interviewed Jason Yee and I think next week, there's devops days Portland that you could go to. I'm going to be a devops days Istanbul, October 24th, giving a keynote there. I'll also be at Devops days Prague, which begins with a P, just like Portland, but it's a very different place. So don't get those mixed up. That's going to be October 5th. And then I'll also be at Cloud Native Denmark

where I'll be giving one of the keynotes at Build Stuff in Villanue's Lithuania. And I haven't really settled it yet, but I'm going to try to go to configuration management camp February 3rd. And then of course, one of the favorite conferences we have around here, scale 24x in Pasadena, also California, April 1st to 4th. Now we've mentioned California a lot, which I don't know if we've ever said that's one of our recommendations, but I think we all agree, California's fine. But what are other recommendations we have this week? Let's start with you, Brandon. My recommendation this week is a movie on Hulu called Violent Ends. It's a nice little thriller. I would give it a fairly solid thumbs up if you're just looking for something to watch. It's on Hulu, check it out. If you didn't watch the end of Furious, I've already mentioned the show multiple times. It's not over for the season. It's excellent. So there you go. There's a reason to, if you will, build yourself a little Hulu backlog. So Violent Ends, Furious, maybe a few other things. And you know, subscribe for the free bond,

watch everything and then cancel it. That's probably what everyone does anyway. So check out those shows if you're looking for something to watch. How about yourself Matt Ray? What do you have to recommend? Well, based off all of our discussion of AI civilizations, it reminded me of one of my favorite Futurama episodes, which is Parasites Lost, where fry gets infected by super intelligent worms and they, you know, they started proving his body. Maybe we'll be lucky enough to have such an outcome. But my other pick this week is a Mac OS app called Meeting Bar. I don't know if Brandon is across this one yet, but it's super simple open source. What it does is up in your Mac OS toolbar, it notifies you of upcoming meetings and the countdown to the next one. And then we'll have a pop up when meeting, you know, at any predetermined time to remind you about your meeting, even go full screen if you want when your meeting starts. Just to make you to show up on time.

It also auto join if you want and can run scripts. So really, really handy little tool. You know, I might need that because I have found myself missing meetings frequently, or, you know, more than once. So I'm gonna look into that. Well, my recommendation, you know, every now and then I like a hyper local recommendation, I think they ship around, but there is this, I don't know, I'm gonna call it like a business casual shop, like a boutique here in Amsterdam called Nolsen, with that O that has a line through it, like Nordic-y. And I went there recently because, you know, I've gotten a little more rotund and I was like, I need some shirts that fit. And it's just, it's the one guy and he's got the shop over there and the, where is he? And I forget what part of town he's in. But you go in there, you can try and a bunch of shirts. He also gave me like a discount and then you can also mail them and they fit great. They're really nice, they're well made and they're not too expensive.

So go look that up, I'll put it in the show notes, but Nolsen and they've got, you know, the, what are those, 25% zip shirts, quarter zip shirts, they've got those kind of sweaters, all sorts of stuff, but good style from when you're like, I need to wear an outfit that no one will notice me and, you know, I can pass as professional. I need to cosplay as an enterprise person. But they're also comfortable and nice. So speaking of things that are comfortable and nice, you've listened to another episode of Software Defined Talk. This has been episode 588. So you can go to softwaredefinedtalk.com, slash 588 and find links to everything we talked about and some things that we didn't talk about. All those conferences I mentioned, you can try to get one of those 25 free tickets or a discount to go to, we are developers. September 23 to 25th in San Jose, California. Not Costa Rica, but that might be nice anyways. And with that, we'll see everyone next time.

Bye bye. Bye. I'm hoping that there will be a positive impact. A little skeptical, but I don't think there are any negatives here.

More episodes

More from Software Defined Talk

View all episodes →