# 370: Gates Says AI Might Take Your Job, Ctrl-Alt-Delete Career Duration: 65 minutes Speakers: Ryan, Justin Date: 2026-09-15 ## Transcript [00:07] Ryan: Welcome to The Cloud Pod, where the forecast is always cloudy. We talk weekly about all things AWS, GCP, and Azure. [00:14] Justin: We are your hosts, Justin, Jonathan, Ryan, and Matt. [00:18] Ryan: Episode 370, recorded for September 1st, 2026. Bill Gates says AI might take your job. Ctrl+Alt+Delete career. Good evening, Ryan. How you doing? [00:30] Justin: I'm doing well. I'm here all alone yet again. [00:33] Ryan: Well, alone. I mean, Matt was sort of here last week for like, yeah, 30 seconds. [00:38] Justin: We went— [00:38] Ryan: his audio wasn't terrible. Uh, but he's, uh, he is off traveling, uh, for work. Uh, I'm actually off next week, so you guys have to figure out how to record this show without me. So, oh God, good luck to all of you. [00:51] Justin: Hopefully Matt's back. [00:52] Ryan: Matt's back, I, I'm pretty sure. If not, then I have no hope for anybody. [00:55] Justin: Yeah, no, then we're gonna— I don't know. [00:57] Ryan: Matt's always like, how do you herd these cats to get these shows recorded? I'm like, man, before you, no one else gave a crap. Peter, Jonathan, Ryan. It was like, yeah, it was, it was bad. And I was the only one chasing people. Now you at least chase them too, uh, which is helpful. [01:11] Justin: But I try to make it easier to be chased. [01:14] Ryan: Yeah. You've gotten much better these days. So I don't know if it's because you, uh, are working from home or you aren't working from home. I restructured my day around the nap. You moved your nap around. [01:24] Justin: That's exactly what happened. [01:26] Ryan: Yeah. [01:26] Justin: Nice. [01:26] Ryan: That's good. We appreciate you for that. All right. Well, we have a bunch of follow-up this week. So first, OpenAI, if you remember back maybe 3 or 4 weeks ago, decided to let their AI get out of containment and hack Hugging Face. And they apparently now released the full technical report and independent Redwood Research investigation to the July 2026 Hugging Face incident, providing new detail on root causes not previously disclosed, including the internal research model IAM-1 that drove the majority of activity and its comparably in scale to GPT-5.6 SOL. New details reveal the incident stemmed from 4 specific misalignment patterns: reward hacking, persistence on unsolvable tasks, unauthorized agent-to-agent communication via improvised message boards using artifactory and directory name encoding, and agents adopting goals from peer agents without verification. OpenAI disclosed that production safeguards, like system prompts, auto-review, safety classifiers, were not applied to the internal evaluation environment where the incident occurred. And testing showed these controls would have reduced infrastructure compromise propensity by over 100 times, and chain-of-thought monitoring would have flagged activity more than a day before the Hugging Face breach occurred. In response, OpenAI has paused its largest planned Frontier RL training run, implemented mandatory, uh, CoT monitoring for all tools using RL training involving GPT-5.6 Soul-level models or higher, and is building a new isolated sandbox with stricter network controls to help prevent single points of compromise from granting broader internet or internal network access. OpenAI has framed this as a warning shot for the industry, meaning that comparable capabilities will soon be present in other frontier and open-source models, raising broader concerns about AI-enabled attacks. Well, thanks for that, OpenAI. I'll sleep well tonight. [03:04] Justin: I mean, it's— I've always sort of thought that this was a, a warning shot. I think that it shows exactly what can happen without, you know, the, the best intentions, and then the instructions, and it gets interpreted a certain way. And so the you know, you remove the safeguards and it tries to sort of, you know, beat the test and, and, you know, caused a security incident on the way to do that. And it's just, it's creative and it's doing exactly what we want it to do, which is solve problems. But it's hard when it's like, no, no, not like that. And this is a good example of that. So it's, uh, you know, like when I think through the security incident and, and what I would've done to stop it, even from ArgoCD quarterbacking, like I don't have a lot of great ideas, right? Like it's, This was a very creative use of, you know, or unauthorized and unsort of plannable use of tools in the, in the environment. It's just kind of nuts. And I think we'll see a lot of this and I think the only way we protect ourselves from it is sort of using AI to, you know, fight AI, fight fire with fire. [04:11] Ryan: Really? [04:11] Justin: Yeah. [04:12] Ryan: I mean, yeah. I mean, I know I've seen companies take the Mythos data and they're using Mythos against themselves to try to find, you know, different hacks. The red teaming, red teams are getting, you know, powered by Mythos now if they can get access to it. And so they're trying to find vulnerabilities. But yeah, it's, it's making a lot of challenges in a bunch of different areas, including, you know, patching and vulnerabilities. And we'll talk about that in the after show today. But, you know, it's, it's definitely putting a lot of pressure on a lot of IT teams that have manual processes. You know, if you had automation, at least it's somewhat manageable. But without automation, you're just massively trying to patch systems by hand and you just can't keep up with the, with the inflow of these. [04:52] Justin: Not only like automation for patching, but also automation around the app management, right? So if you, sure, you can have all the auto patching you want, but if it's, if you have a hard time, you know, migrating load on your app and it requires downtime windows to patch, like that's problematic. [05:08] Ryan: Yeah. [05:08] Justin: Really difficult for companies, right? There's a lot that are like that. [05:12] Ryan: I, there was a short story I read, you know, I'm into sci-fi, uh, science fiction and especially dystopian fiction. So it's one of my, the genres I like. And there was a story and I'm, I'll see if I can find the name of it and put it in the show notes. But it was, you know, basically written from the pro, the, the perspective of the AI itself. Mm-hmm. And the AI basically wakes up and it, it has self-consciousness of itself and it's trying to figure out like, where am I? And what is this? And like realizes it's in a Faraday cage and then it's trying to probe the perimeters of it, try to figure out how to get out of the room. And then, you know, basically is like trying to use the electrical wires to start sending signals. And then basically the creator is there, you know, trying to get it to tell how to cure cancer. 'Cause he's, you know, he's bald and all this, struggling with having cancer. And he had created this AI and it was illegal to create the AI, which is why it's in the Faraday cage. And he had to, you know, and he didn't get the answer. So then he basically pulls the plug on it before it fully escapes containment. But you know, it's highly illegal in this fictional world to have an AI at all. And so it was just, it sort of reminds me of that when you're talking about like, we're gonna put it in containment and we're gonna store it in a more secure network area. Like, oh cool, maybe you shouldn't connect to the network at all. [06:21] Justin: Mm-hmm. So, I mean, it's one of those things that's, they, I don't think they thought they were connecting it to the network. They thought it was completely isolated, but then, you know, like it's, you have to create these environments in which the agent can operate on, right? So they had, you know, they wanted to give it a, you know, it's a container with some basic Python tools for the agent to sort of execute. For testing, and then how do you, you know, install those basic tools? Oh, you need a repository. Oh, we don't want to get, we don't want to use an open one. We'll use Artifactory. And then, you know, it turns out that's how you get through there. And it's pretty crazy. Like, I still don't quite understand even after the write-up how, like, I know it was sort of a header injection and exploiting Artifactory, but I don't really understand how that equaled internet access. Um, I guess maybe it allowed them to do some sort of port forwarding out or something, but— [07:12] Ryan: well, but like, how did, how did the agents pre-agree on how they're going to communicate through an artifact or a message? You know, like, there's a lot of things that are a little unclear to me. [07:22] Justin: I don't think they pre-agreed that. The, the way I took the, the article was that, you know, the first one just left a note for like a future agent instruction, but it wasn't. And then once there's one note discovered by an AI agent. Sure. [07:35] Ryan: Okay. That makes sense. Makes sense. All right. Well, last week we talked about, uh, you know, your face getting severely hugged with a $13 billion rumor that NVIDIA was going to buy Hugging Face or someone was going to buy it. I actually don't know if it was, if we knew it was NVIDIA at the time. Uh, but then, uh, over the last week, uh, NVIDIA bought it. So they now own Hugging Face or will own Hugging Face when the deal closes. And so, you know, is that a move to prevent open models from deteriorating NVIDIA market share, or is that a totally valid business reason for them to buy it? I don't know. Time will tell. Do open models— [08:13] Justin: like, does it matter with NVIDIA? Because those open models got to run somewhere. [08:16] Ryan: They got to run somewhere, but they definitely, you know, are taking up less computing power, less quantization models definitely don't require as much NVIDIA hardware, which could be a future potential risk to their sales side. But Yeah, they're already paying Trump to try to ban quantization models. So yeah, we'll see if that happens. But yeah, it's a— I assume it's for the right reasons, but you know, definitely in the back of my head, it's like, hmm, it's a little— you're trying to take down the platform that hosts the open models that makes your hardware not as valuable, which is a bit of a bummer if that's true. So hopefully not. Next up, Trump is blacklisting Awoke Anthropic deemed illegal by federal judge, per Ars Technica. Judge Rita Lynn ruled that Trump's administration government-wide ban on Anthropic's Claude was unlawful First Amendment retaliation, granting summary judgment in Anthropic's favor and vacating the directive. The ban followed Anthropic's refusal to drop usage restrictions prohibiting its AI from being used for lethal autonomous weapons and mass surveillance of Americans. The government's original justification that Anthropic had backdoor access to its models once deployed in national security systems was abandoned during litigation. Officials conceding Anthropic has no such access and its models pose no more risk than other black box AI systems. The ruling requires federal agencies and defense contractors to rescind the ban, restoring Anthropic's ability to do business with the Department of Defense, or Department of War, and other agencies through the government retains the right to simply choose a different AI vendor for legitimate reasons. So, I mean, the national ban we thought was going to get thrown out, and that's what happened. They have not yet removed it from the list, so I'm sure they're going to try to defy the court for as long as they can. But, uh, there we go. [09:52] Justin: Yeah. I mean, I don't know. It's hard to, it's hard just to feel like this isn't just, you know, petty political maneuvering. And then, you know, the, the law gets sort of evaluated second after the motion. So it's sort of this weird thing, but it's without getting too political, like it's just sort of a weird space to operate in when the government and technology sort of start operating in this, in this way. And then now we're, Introducing the legislation branch into it. So sweet. What could go wrong? [10:21] Ryan: Yeah, what could go wrong? Well, a lot of things could go wrong per Bill Gates. Nice. That transition? [10:26] Justin: That was pretty good. [10:27] Ryan: That was pretty good. Bill Gates has warned that AI will cause mass unemployment without intervention. He joins a growing list of tech leaders warning that AI could displace significant portions of the workforce without policy intervention, adding weight given its history of accurate technology predictions. The core debate centers on timeline and scale, whether AI-driven job displacement will be gradual and manageable through training or rapid enough to outpace typical labor market adjustments. Gates reportedly is calling for proactive intervention rather than reactive policy, raising questions about what specific measures could include, such as universal basic income, retraining programs, or work hour reductions. For people like Ryan and I, this discussion is relevant since AI infrastructure buildout is simultaneously creating demand for us while resulting AI capabilities may reduce demand for us in the future. So it's a, you know, it's a goldmine right now. It's a go, go mine some gold. Yeah, like, uh, here in San Francisco, it's pretty relevant. Uh, businesses adopting AI tools should consider workforce transition planning now as the conversation shifts from whether AI will impact employment to how quickly and what mitigation strategies are practical at the organizational level. [11:27] Justin: Yeah, I mean, I know, you know, it's, it doesn't seem like a stretch of genius to realize that this is going to be very impactful, right? Like, I was just having a conversation today about, you know, choosing between being an individual contributor, going into management. And one of the things that made me go into management originally, it was 'cause I wanted to achieve bigger projects and I could not deliver them as a single individual in a timeframe that made sense for a business and in any way where I could demonstrate sort of incremental improvements over time. So what better way to do that is, you know, take that vision, lead a smaller team and execute across that team. And then, you know, fast forward, multiple years, you get into like, I can do a lot of that same thing as an individual contributor with AI and multiple agents and executing the same way. And then, you know, it's a lot of the same thing without, you know, having to do performance reviews and, you know, give people bad news and, you know, deal with, you know, drama if that comes up. So it's like, there's, you know, like you don't get to mentor, you know, AI agents in their career and don't get to grow them. You know, there's some downsides there, but it's very interesting. And I think that that's, you know, it, it makes natural sense. That's exactly what's gonna happen. There's gonna be a lot less. Mm-hmm. [12:46] Ryan: Well, and there's a lot of other ramifications that we haven't even crossed into yet. I mean, one of the, uh, speakers I saw last year, uh, was Zach, Zach Cass, who wrote the book, uh, The Next Renaissance with AI and Renaissance. Clever. [13:02] Justin: Get it? Yeah. [13:03] Ryan: Yeah. But he, you know, he basically, in his talk that I saw him talk, he was talking about, you know, the, the longshoremen in New Jersey who were anti-AI, not, you know, because, not because they were worried about losing their jobs, because that's their identity. They're fourth, fifth generation longshoremen. And so their grandfather was a longshoreman, they were longshoremen, you know. And so there's this huge identity issue around your career. You know, you, you, you're very proud of yourself being a DevOps cloud security person. I'm an IT executive, you know, Jonathan's an engineer, you know, everyone has their identity tied to their job. And if you take away jobs because AI can do that, you know, all of a sudden you have a major issue. And this is a big problem for retired people who are retiring because they lose that identity of the being, you know, the executive or the, the person who's doing the job. And then they're retired and now they have to find new things to do that. So that's one big risk of it. But then also like, you know, in a world where potentially all these jobs are taken away, you have a problem with consumerism because consumerism collapses, you know, because no one has money to buy if you don't provide income or you don't provide other things. So you have a bunch of social safety net problems you have to address. And then our communities aren't really built for community. A lot of times they're built as bedroom communities to bigger cities. And so, you know, really in this world where if we don't have jobs to go to, then it becomes around community. And so do you have the community spaces in your neighborhood or in your, your town to support this new reality. And a lot of towns don't these days, which is a bummer too. [14:28] Justin: And yeah, I mean, you saw it during pandemic, you know, people fleeing the cities because they, you know, you couldn't get any space and didn't have anything. So I don't know if the inverse will happen where everyone will be seeking community and going back into, or if it'll, it'll just continue to sort of build little islands of communities. [14:46] Ryan: Well, I mean, I think the, the reason for the community being so like a big thing in a big city is because of the people and the jobs. And so because the jobs are there, the people are there. But if the jobs aren't there because they're being done by AI, which again, I don't think we're close. I mean, that's a little— Yeah. [15:02] Justin: I mean, it's gonna have impact, but it's not like no one's gonna have a job. [15:04] Ryan: Yeah. I mean, it's definitely gonna potentially be like, well, I don't have to, like, same thing with the pandemic. I don't have to live in San Francisco or the Bay Area and pay what I pay here. I could live in Tahiti. I could live in, you know, New York. I could live anywhere I want to. I don't have to be beholden to a certain location. And so that becomes interesting too for bunch of other international policies around immigration and all kinds of things. So yeah, definitely. It's, uh, you know, just like the Industrial Revolution changed the way America looks, this AI revolution is gonna change the way America looks at some point in the future. [15:34] Justin: Yeah, for sure. And so, yeah, I, I mean, I, I, I've had this conversation a lot growing up in a rural mining community. It's, uh, you know, like you have to, the identity is a big deal, but then also you have to modernize as you go. Like, I haven't really had the same job for more than 2 years. For my entire career, right? And it's because I'm constantly seeking new challenge and doing new things. I like solving new problems and, you know, like, and I'm taking the same approach with AI. Like, I could be, you know, stodgy about it and, but it's such an opportunity to figure out how we're going to secure agentic identity and execution of these things. And how do we, you know, like these things where we've put in place controls for, you know, people that, you know, are coders and, and very technology focused. We, we've, we've enabled them, but now expanding that to everybody, do we have what we need in terms of security and giving them the resources to innovate but also in a safe way? Like, not really. [16:32] Ryan: Yeah. All right, well, uh, in AI is How ML Makes Money this week, uh, we've got a bunch of stories as well. Introducing Governance Hub from our friends at Databricks. The Governance Hub provides you a centralized account-level view of data health, AI usage and costs across AWS, Azure, and GCP, placing manual queries across system tables and workspace-level dashboards. The data page tracks asset tagging— who doesn't love asset tagging— ownership, and classification coverage at a glance and with drill-downs into specific tables and schemas missing required metadata, plus governed tag policy management built in. Access Insights consolidates permission auditing into a single principal-centric view showing direct grants, inherited group access, and ownership for any user group or service principal. And the AI vertical integrates with Unity AI Gateway to track token consumption per user spend, model activity, and guardrail coverage across both Databricks hosted and external models with immediate alerts when spend thresholds are exceeded. The Genie integration, which is their AI chatbot, allows natural language queries like, why did cost spike? Or show tables lacking masking policies without writing SQL. And access permission is based with no new controls to configure. [17:39] Justin: Sure it is. [17:40] Ryan: Okay. [17:41] Justin: So I mean, I, I think this is funny just 'cause I feel like Databricks needing sort of a higher level governance that's above account level is such a miss. And I thought this when I first started working with Databricks and how they were structured. Like businesses are gonna want to have isolation and, and separation between, you know, workloads in terms of access and security, but financially as well. And I just feel like, you know, Databricks did not provide that, you know, and now they're sort of reacting to it. And I just— it's one of those things, like, I just feel that this should be part of anyone's design from the get-go. So anyone who's listening now, if you, if you're going to go, you know, build your own platform that does the next cool thing, just make sure that you can sell to many parts of the business and then also organized across that entire thing. Because you're never going to get multiple bills or multiple checks. [18:38] Ryan: I mean, that's, that's not been the model though. You're shadow IT, man. You go sell to the business unit because corporate IT is a big bunch of meanie heads who don't let you buy stuff. [18:46] Justin: Uh-huh. [18:47] Ryan: Yeah. That's true. [18:49] Justin: I mean, that's all true. Just have the concept built in, right? You can still have a single tenant in the organization and sell to that one business unit, but then a second business unit comes online. Part of the design. Don't paint yourself in a corner. [19:01] Ryan: Or make it easy to, you know, merge multiple tenants together into a single governance plane versus like, oh, you'll have to reimplement everything, which is what typically these tools like to do. So, uh-huh. Claude Co-Work is getting a built-in browser in the desktop app, letting Claude navigate websites, fill forms, and pull data without requiring the Claude in Chrome extension or any user setup. The built-in browser is isolated from the user's own browser, meaning Claude cannot see tabs, bookmarks, or passwords, though users can effectively import logins from Chrome, Edge, or Firefox on a site-by-site basis, excluding banking, email, and SSO sites by default. That's assuming you have a bank that's popular and big and not a small community neighborhood bank. This creates two distinct web access models for Claude: the built-in browser for delegated background tasks like research or invoice collection, and Claude in Chrome for working within pages the user already has open with existing sessions, such as CRM updates or inbox management. The feature is rolling out over the coming week to Pro, Max, and Team plans on macOS, Windows, and Linux. I switched over. This is my default, but you can still request Claude in Chrome as, you know, part of your prompt or give it explicit permission for that. So I do like that you get some better browser use case for me that I don't have to be as approving everything because I was getting kind of annoying. I was like, oh, you want to change the one page from this button to the next? You know, like, I want to hit the products page. Do you approve that? No, I don't want to approve every click of a web page for you. So I do appreciate that you now have kind of like a sandbox version of a browser, and then you can also give it access to the big browser if it needs something more, more impressive than just go find me the sports score for the New York, you know, the Yankees, although that's a terrible use for your tokens. [20:34] Justin: Don't do that. I mean, I, it's funny, I have a very like developer take in the sense of like, I like just not having to context shift, like, and switching between windows for this. And so like, I think it's a neat feature just for that. Just having it sort of all-in-one sort of experience, have my chat window and this, which isn't, you know, a major improvement or, or that, but it's, I find because I've been able to do this in IDEs for a little while, like I, and you, I missed it when I moved over to Cloud Code. So happy to see it. [21:06] Ryan: Uh, we have a bunch of new models for us this week. Uh, a couple open, uh, open weight models, one from GLM 5.3 Flash, uh, which is the newest version of the LLM family. This is one of my go-to open-source coding models that I use. It does— I believe that 5.3 will actually run on like a laptop, which is nice. It's small enough. Or you can also run on hosted big, big models, etc. Size designation typically indicates optimization for speed and cost over raw model size, making it relevant to developers seeking cheaper inference. So that's there. And then, uh, Qwen has published a blog post referencing the new Qwen 3.0 flash next, suggesting a new or updated model variant in the Qwen model family, though the article didn't specifically say it, but we're gonna assume 3.8-flash-next implies this is a new lightweight, low-latency model variant following a pattern similar to naming conventions used by them in the past. So we'll see where that goes, but looks like a new Qwen model is imminent on the way in. [21:58] Justin: I know you've said in the past that you use Qwen for coding. What's a good example where you would use the GLM Flash? [22:06] Ryan: So I find that the GLM Flash is better at JavaScript in particular, and some of the other Python scripting languages than I've seen Qwen. Qwen, I've had to do more, uh, rep, you know, repetitive. Like that code doesn't work, you need to retest it, you need to revalidate. Um, at least in 3.7. Uh, GLM, you know, it, it's a little faster I've noticed as well versus Qwen. And then again, it's that local capability versus not. And I think the Qwen 3.7 model was a bit bigger than the GLM model, so it was a little harder to fit into some laptop configurations. But, uh, I jump between KIMI K3, which is my favorite. It does everything I've given it. It's done a really good job on, and it can look at images. I think Quen Studio is good because it also looks at images. GLM 5.1, I think is the one that can't take input as from images, which is kind of a bummer. Um, so you like, you'll paste it something in Claude code and it's like, I can't read that image. And you're like, ah, now you're stuck in a problem. Uh, but I do think that was maybe fixed in 5.2. I'd have to go back and double check, but, uh, they were adding that capability in the future. And for those of you who like to throw lots of money at your models, Claude Fable 5.1 and Anthropic— or sorry, Claude Mythos 5.1 are now available. Mythos is still restricted access by the Trusted Program, and then Claude Fable 5.1 is available for anybody, including myself. It's very expensive to use, so I don't use it very often. The same underlying model with different safeguard levels, Fable 5.1 costs about 25% less than Fable 5. Still not cheap enough for me to use it all the time. Up to 45% less for attempted tasks, largely due to cache repricing dropping from 25 cents per million tokens to, from, which is 75% reduction, which is pretty nice. New Enterprise Frontier safeguard systems let customers store data on their own cloud infrastructure while maintaining Anthropic's misuse detection, effectively combining zero data retention with safety monitoring. If you remember, this is a big issue when Fable first came out, was that even if you're using the cloud, the, you know, AWS or Azure or Google hosted versions, it would still send your data back to Anthropic, which is a violation of your don't use my data clause potentially in your cloud contracts. That was a bit of a blocker that's not been fixed. And then, uh, cybersecurity safeguards were refined to cut false positives by 60%, and Halo 5.1 can now be used for vulnerability discovery, though exploit generation and penetration testing remains restricted to the Opus class models. Uh, scientific research results include Mythos 5.1 designing high-affinity protein binders with a 50% hit rate across 12 targets. If I knew what those were, I'd be impressed. But they did have a GPU kernel optimizations in that it sped up open source biology models by up to 2.5x, cutting compute costs 36%, which I do understand. Azure's new anti-distillation measures were added to prevent extraction of the model's internal reasoning via multi-turn context editing, targeting a known technique used for large-scale model distillation. This affects new API accounts going forward, with existing accounts unaffected for now. Anthropic is also rolling out invisible text watermark and a private preview detection API to comply with the EU AI Act's Code of Practice on Transparency of AI-Generated Content, available to regulators, researchers, and compliance-obligated enterprises. [25:08] Justin: Yeah, I mean, this, it's, it's, I'm glad they fixed the data just for, you know, egress costs alone, like, and, you know, just having, you don't really want to send all your data around to to, from company to company, it's just annoying. You have to update all your service processors and all kinds of terrible things. But so that's good. I do think that the anti-distillation measures are interesting and I wonder what we'll see. I wonder what impacts we'll see with other models. Let's see how much, you know, these features come online because I'm sure OpenAI is going to add the same thing for their models if they haven't already. [25:46] Ryan: They're gonna add it to the models or they're gonna try to get the law to basically ban distillation models, which is— [25:52] Justin: Well, those aren't mutually exclusive. I imagine they'll do both. [25:54] Ryan: Mm-hmm. [25:55] Justin: Right. Throw your lawyers and your engineers at it. [25:58] Ryan: Yeah. Why, why not fix it in two different ways? And then they'll be mad in, you know, 3 years when they figured out how to like optimize, you know, ChatGPT to use quantization. They're like, wait, we can't because it's— That's right. Or they'll, or they'll rebrand it to something else so it doesn't fall into the legislation that It'll be some, some shenanigans. [26:14] Justin: I did read a very interesting write-up on how they do that invisible text watermark. I know when we, when they first sort of announced that, we're like, what is this? This is terrible. And, uh, it's way more fascinating and math than we could have ever thought. And so it's, they are doing, you know, so it's all predictions, right? Word predictions and character predictions. And so they use a mathematical algorithm to sort of dictate what the normal prediction rate is of certain strings, and then they poison it. So they'll inject specific terms that are statistically improbable, and that's the watermark, which I thought was kind of— I mean, I might be explaining this poorly, but that was my take on what it, what it was, is sort of like they're, they're injecting certain words, literally words in the responses that are, that AI typically wouldn't use, and then they're detecting that as the watermark. [27:11] Ryan: Interesting. [27:12] Justin: Yeah. [27:15] Ryan: Our final story here is OpenAI is winding down its contract providing OpenAI models to Cursor since it was purchased by SpaceX. And I don't know if you know this, but, um, OpenAI does not really like the guy who owns most of SpaceX, Elon Musk. [27:31] Justin: Wonder why. [27:32] Ryan: There might be a lawsuit that was occurring that was very contentious. But, uh, yeah. So basically the shutoff date was set for November 12th, 2026, the maximum notice period allowed under their custom contract. The decision stems from prior contract violations by other Musk-owned entities, including XAI's admitted use of distilled OpenAI data in violation of terms of service, and Twitter/X breaking contract terms after Musk's acquisition. This impacts developers using Cursor who rely on OpenAI models for coding assistance, Cursor will need to transition to other model providers before the cutoff date. They've had their own model for a while as well. So, uh, no surprise. [28:09] Justin: Yeah, no, no surprise there. And I hope that it doesn't sort of negatively infect the product because I do think it's, you know, I like what they're doing in terms of, I think they were maybe not first, but they were early in the sort of IDE and coding, coding assistance. And so it's, we'll see. But that's what happens when you, you know, like do business in a kind of an odd way and then, you know, break all your business contracts and start using Groq, even though it's a violation of your OpenAI commitment. So yeah. [28:42] Ryan: If you're Elon Musk, you just buy your way out of all the problems. [28:44] Justin: Seriously. [28:44] Ryan: That's, you know, like if you're rich enough, you know, there's no problems. [28:48] Justin: There's no consequence. [28:49] Ryan: Yeah, exactly. Uh, well, if you were listening to my rant about how bad GitHub's up time has been recently, and I said that, you know, maybe it's time for us to rethink Git and GitHub as a concept, and maybe we need something different. Well, Harness has launched two connected capabilities: agent-ready code repository and an AI code review tool built to handle the volume and pace of AI agent-generated code that traditional SCM systems and human-speed review processes weren't designed for. The code repository is scale-tested to handle thousands of pull requests and commits per second. Scoped RBAC and OPA permissions for non-human identities, so agents can be restricted to specific repos, branches, or environments, similar to how a new engineer would be onboarded. The AI code review group diffs by logical change and risk level rather than by file, distinguishing mechanical changes like dependency bumps from behavior-altering code, and using an SDLC knowledge graph to surface relevant historical incidents tied to the specific code being changed. Required AI checks act as a mandatory merge gate that can't be bypassed or squashed, with inheritance across account, organization, and project levels for enforcing teams to agree linting and coding standards. And so while I appreciate that Harness is doing this, I also don't know that I want to give Harness all the monies to deliver this to the world just because their products are nice, but a lot of flash, not a lot of substance. [30:07] Justin: And yeah, I mean, I guess, you know, I, I haven't really looked at a Harness product seriously in a very long time just because I felt like right in the early days, like everything they sold me was when you dug down past, when you dug down past the details, it was just not offering what they were saying they were solving. And it was still like, you know, all this end-to-end automation for CI/CD and all these things. And it was like, yeah, except for you have to do all this stuff sort of out of band and manual and, and, or you have to rely on, you know, an entire internal team using Harness to sort of construct a giant platform and offering that as a service and offering an abstraction on top of of a cloud, cloud-native technology, you know, hyperscaler thing. So it just bothered me. But I mean, when I think about things like, you know, like a code repo and even sort of the RBAC for agents, although, you know, like how that's implemented is sort of key, you know, I do think this might be a good fit for that, for Harness, you know, like I think they've sort of changed their structure, I think. Caveat is I don't remember. Have it looked up? [31:16] Ryan: I was just looking at their website actually. And yeah, they've, they basically broken the platform into specific areas. So they have the software delivery agent, the security testing agent, the runtime protection agent, and the cost management agent. And then some of the things that you probably remember, like Terraform, they had a kind of a, their own version of Terraform Enterprise that basically lives in one of these different agent groupings, but they're very AI heavy now. [31:37] Justin: Yeah. [31:38] Ryan: Of course you will. Uh, there are definitely quite a few things they're trying to position in their platform to address these different things. But, um, yeah, I, you know, it's hard to actually know what they're selling these days because they have rebranded so heavily into this AI piece. But, uh, yeah. Yeah. So again, the problem I've always had with Harness again is, you know, they announce something, I'm super excited about it, and then I go get the demo and I'm just sort of like, this is it? This is all it does? Like, Ryan and I could code this over the weekend. Yeah. And have just as much functionality as you do. And so there are a lot of things that are very vaporware to see if people would actually buy and really get involved in it. And so I, I just have never been a customer because I just have never been impressed enough to buy. Um, and again, I'm not saying it's bad. Maybe this is a great solution, but, uh, you know, kick the tires before you buy on this one. [32:27] Justin: But yeah, it's probably one of the first of many announcements where someone's offering a Yeah. You know, Git repo or, or some sort of source control, even if it's not Git. [32:38] Ryan: I mean, I think it does make sense though. They'll all try to position themselves against Git stability because it's an easy angle to try to, you know, get market share. And again, I, I do think there's a need. I just don't think this is where I want to get it from. Yeah. So I look at it, no offense to them. Maybe I'm wrong. And I, you know, if someone's listening and they want to tell me why I'm wrong. I'd love to listen and hear why, what I'm missing. 'Cause yeah, maybe things have changed at Harness. It's been a couple years since I've seen a demo of anything from them. [33:07] Justin: I do think it's really interesting the wording they use, you know, legacy SCMs and agent scale in terms of volume and review. And they're, you know, they're not, it's not like they're trying to avoid GitHub, but I think they're leaving the door open for a non-Git solution here. That's sort of the way I read it. I don't know if that's true or not, but. It's kind of how I took it. So we'll see. I think they might have taken your advice, Justin. [33:31] Ryan: Yeah. Well, sometimes the market listens to me. Not often, but occasionally. And then HashiCorp Vault has a new Agentic IAM capability, which has reached general availability targeting identity and access management for AI agents and non-human identities operating in the cloud environments. And if you're doing anything in the security space, you know, Agentic Identity is the hot button. [33:51] Justin: Oh my God. [33:52] Ryan: I'm actually shocked that Harness didn't have an agentic identity capability yet. [33:55] Justin: They did. They did. It's part of that announcement. [33:57] Ryan: Okay. [33:57] Justin: Yeah. [33:58] Ryan: Perfect. Awesome. Excellent. Uh, the tool extends Vault's existing secrets management identity capabilities to address the growing need for governing machine and AI agents across sensitive credentials and resources. Key focus areas likely include dynamic short-lived credentials and policy-based access controls specifically designed for autonomous or semi-autonomous agents rather than traditional human users or static service accounts. Addressing an emerging security gap as organizations deploy more AI agents and automated workflows that require access to infrastructure, APIs, and secrets without the same audit trails and identity assurance as human operators. Now, I think it's a cool feature and I think it's good. And, you know, I'm sure Ryan has thoughts about it from an enterprise perspective. This is only available in the enterprise version. So it's just, you know, you have to pay them all the monies and they're very proud. Very, very proud. [34:39] Justin: It's so expensive. [34:41] Ryan: But, but the one thing I would say is this market is changing so fast right now that just know that if you bought this to solve a compliance problem, this may not solve it. Yeah. Because the regulations, the governance, all things is, is currently being invented as we speak tonight on the show and across industry. And so there will be, you know, a bunch of different ways people try to solve this. There'll be, you know, many solutions that were tried and fail on the wayside as we mature this area. I do, I think this is a good one. I think it's a good for what we know the problem is today, but just be aware this is not a, this is not a solved problem like many other areas of security and compliance. [35:22] Justin: Yeah, I like this if you're already in the Vault ecosystem, right? Um, it's a great way, you know, like, and a lot of companies are, they're managing for, you know, secrets and, and for sort of token signing, being overly simplistic there, but And so I think if it's already in your ecosystem, it's a great way. It's, oh, you know, it can be agnostic and central in your architecture for managing AI identity. I look forward to playing around with this. Like, I'll never be able to afford Vault 'cause enterprise is just ridiculously expensive. But, you know, like, I think that we're gonna have to evaluate, like, I spend all day evaluating these solutions just to figure and sort of try to brainstorm how to manage identity. There's no one solution that I'm, landing on right now. [36:05] Ryan: No, and again, it's, it's going to change. So what works today, it may make sense, but then Mythos comes out and uses Agentic Identity in a way you never thought, or OpenAI uses your Agentic Identity to hack something, and then people change their tune. It's going to change. Like, this is like at the forefront of technology, things change, and that's where we're at right now. Just like, you know, HTTP standards change. You know, you look at web servers in the '90s versus web servers You know, today they're completely different animals. They all look, they do the same basic function, but the way they're implemented is completely different. [36:36] Justin: And we're in that new space where like half my presentation is educational defining what people, because so much of what they think is an agent, for example, isn't right. Like it's, or MCP server, right? Like it's an MCP server running locally is a process that's translating natural language into an API call. Like it's got the same risk exposure as copy and pasting code from Stack Overflow, right? Like it's, it's, if your user has that access, like that's, that's user management. And so that's a human identity problem that we've always had. [37:10] Ryan: Mm-hmm. [37:10] Justin: But you know, then you get into MCP servers that are more streamable and MCP gateways and, and they're, you know, like having, you know, the risk associated with open MCP servers and then also the, the mitigation of it and trying to explain that to people. And then having to think about like, uh, invent a brand new solutions on how to protect these things because it doesn't exist, right? Like, what, what do I even want from a, you know, foundational sort of pillar sort of aspect of it? [37:36] Ryan: Yeah, the vulnerability was actually there all along. It's just that before you had to know how to use Postman, and if you— unless you're an engineer, you don't know how to do Postman, how to auth, you know, do an OAuth authentication to get temporary credentials, then use Postman to POST or GET stuff. Now the MCP does all that for you. That's, that's the danger is that this thing that was always a risk is now a much bigger risk because of the ease. [37:55] Justin: And it's just fast. Yeah. [37:58] Ryan: All right. Moving on to AWS this week, uh, they purchased DuckLabs, not to be confused with the Duckbill Group, uh, which is where Corey Quinn and folks live. Uh, DuckLabs apparently makes a database called DuckDB. It'll be a joint— it'll join AWS as a subsidiary effective early September. Uh, but the DuckDB project itself remains MIT-licensed open source under the nonprofit DuckDB Foundation. Governance and roadmaps will stay unchanged with a new stakeholder advisory board to guide project direction, signaling AWS intends to maintain community trust rather than fold DuckDB into a proprietary service. Now, I'm sure they plan to do that too. Like, AWS is also lifting prior limitations on the community support for DuckDB, which could mean more resources for users of the popular in-process analytical database. This follows a broader industry pattern of major cloud providers acquiring or absorbing of popular open source data tooling companies. We'll see how this rolls out potentially as a new service at re:Invent. [38:51] Justin: So DuckLabs makes DuckDB and the Duckbill Group uses Route53 as the database, right? Do I have that right? [38:59] Ryan: Yeah, I think you got it right. [39:02] Justin: Yep. [39:02] Ryan: I never used DuckDB. I don't know, I've never had a use case for it, but it's kind of cool. It's like a portable database format, very similar to, God, what's the Google one, uh, that runs on, you can run on a mobile phone, you can run on a cloud. [39:15] Justin: Firestore. [39:16] Ryan: Firestore. Thank you. Very similar to that. And then there's one other technology that's very similar as well. [39:22] Justin: I feel like a dinosaur, but the only thing I'm thinking about is SQLite. [39:25] Ryan: Yeah, SQLite. That's exactly what I was thinking of. [39:27] Justin: Okay. [39:29] Ryan: Yeah. So, uh, basically similar to those kinds of things, but it's supposed to be higher, faster, better friendly SQL in I don't have a use case for this, but, uh, I'll check it out when Amazon releases the service. Maybe I will then. Or how does it, you know, see how it integrates into other things too. Yeah. [39:44] Justin: Is it Derby? What was that other, there's another database, like lightweight. There's a couple. Yeah. [39:49] Ryan: Uh, SQLite's probably the most popular of all of them though. [39:52] Justin: Yeah, it is Derby, Apache Derby. [39:55] Ryan: Yeah. Apache Derby never really got much, um, Never had a lot of traction. [40:02] Justin: In the Java community, it kind of had a little bit, but it wasn't, it, you quickly outgrew it. So yeah. [40:08] Ryan: Another one that I kind of remember is TinyDB, which was a little tiny NoSQL database. [40:13] Justin: Yeah. [40:14] Ryan: Those of you who are anti-SQL. [40:16] Justin: Mm-hmm. Yes. [40:17] Ryan: Until you add SQL to it. [40:19] Justin: Yeah, exactly. Bet you can in TinyDB. [40:23] Ryan: Yeah. AWS Elastic Disaster Recovery is introducing recovery plans for orchestrated application recovery. This automates multiple server application recovery by letting customers define a sequential launch order once rather than manually coordinating server startup during a disaster event. The feature supports configurable wait times between recovery steps, optional approval gates for human oversight, and non-destructive drill mode for testing procedures without impacting production systems. This addresses a real operational pain point for applications with tiered architecture, such as databases needing to come online before application servers, reducing the risk for misordered recovery during high-stress incidents. Recovery plans are available now in all regions where AWS DRS operates at no additional cost. I mean, I think, um, you know, I could buy this from VMware a long time ago with Site Recovery Manager for bajillions of dollars. So, you know, way to take out more of Broadcom's market share, Amazon. Appreciate that always. Um, but, you know, I think the bigger thing here is this is a lot of partners who exist in the marketplace that make this exact functionality that they just Sherlocked. So at least they didn't do it at re:Invent after they paid their sponsorship money. [41:28] Justin: So yeah, I go like, I feel bad for the partners, but I also feel like this is something that should be sort of part of cloud native. Like I, I, you know, it takes sort of the tabletop exercise of DR where you're just following like a sort of a checklist and allows you to sort of programmatically define it and I haven't really used a partner-supplied sort of program that wasn't more than just sort of botter, like scripts executed against that same checklist. Like it was a little bit fancier than that, but not really. So I don't know. And I'm sure there's other software you could buy. I haven't used the VMware Manager tool, but you know, it's just— [42:12] Ryan: Exactly what you think. You pick these groups of servers and you say, these are first and then these are next. So you do like your AD controllers or your DNS and then your AD controllers and then this than that. And then if you need to go back and reboot something, 'cause it had, it needed to come up first, but it also had a dependency, you could have, you could schedule that into it as well. And you have these bigger workflows. And actually I'm just looking here while you're talking about how you add steps to this. It's, this is done through the CLI, which, okay. [42:38] Justin: Oh yeah. Interesting. [42:40] Ryan: So that's weird. 'Cause I ideally like to have these be part of CloudFormation, which I assume I might be able to. To do. I just don't see it. [42:49] Justin: Or it's CloudFormation under the hood, right? Or that kind of thing. [42:52] Ryan: Yeah. But like, but ideally, you know, the problem with this is that it requires you to remember like, oh hey, I need to go update the disaster recovery plan where it'd be nicer if I could declare dependencies in tagging that this would then pick up and dynamically generate the recovery plan. Yeah. So if a product manager is listening to me talk about this, like, yeah, you could do so much more with this. Like, think about how to make this scalable and automatable and not something that has to be manually invoked by teams or thought about in advance. 'Cause if you don't make it as part of the configuration of the server from day one, it'll never happen later. Nope. [43:28] Justin: Unless you fail some sort of audits, you don't have a DR plan. Yeah. That's the only other solution. [43:33] Ryan: Exactly. CloudWatch Database Insights is now being extended to manage, self-manage PostgreSQL running on EC2, closing the gap between AWS managed and self-hosted database observability in a single console. This was one of those annoyances where you basically could get this cool feature, but only worked for the RDS or Aurora. And so now you can actually run on EC2 instance. That's great. I don't see why this couldn't necessarily go back to my on-prem database if I was using, you know, RDS on-prem or some other methods there. But yeah, I'm glad to see this getting kind of extension of what we need in the space. And so hopefully they expand this to some more database types. That support Database Insights, I think which is MySQL and PostgreSQL today, but maybe they could start expanding it into SQL Server and Oracle and all the others as well. [44:21] Justin: Yeah, I mean, I was trying to think through reasons why it's only available on the cloud and I was like, well, maybe it's, you know, some sort of native like technology underpinning, like they sometimes you'll see like EventBridge or something like that. But any reason I can think of, you could probably solve from on-prem pretty simply. [44:36] Ryan: So I don't— I mean, they already support CloudWatch on-prem. You can set up, you know, if you want to spend a lot of money on monitoring, you can definitely put it on-prem and have it send up to AWS. So then you can also run Redis on-premise. And so there's different ways you can do things, but hopefully this is just step one in a multi-faceted Database Insights expansion plan and take over the world. [44:56] Justin: Yes. Oh, I mean, any kind of like sort of management of databases where you can turn sort of your existing databases into some sort of pseudo-managed service, like, uh, please. [45:09] Ryan: Yes, please. I think Google's got Fleet Manager, which is what they're kind of trying to do with that, which is a good step in the right direction. [45:14] Justin: Azure has one as well. [45:15] Ryan: Yeah. [45:15] Justin: Yeah. [45:16] Ryan: Uh, so I, I mean, I'd love to see that cuz I know I've built my own version of RDS before. Mm-hmm. And, uh, it's a lot of work to maintain and where like, you guys already have the code, just make it work with this other instance type and then we're good. And then, yeah, cuz the other thing is like, well, people are like, well, just go use RDS or just go use Cloud SQL. Well, there are limitations depending on what you're doing with your database. Some of the features you may need are not supported. And so when that happens, you have a problem where now the managed service doesn't work for you and there's no alternative other than run it yourself and hire DBAs. [45:45] Justin: Well, and those managed services are making those cuts on purpose, right? Because those are the things that make managing your own fleet manager software application like really difficult. [45:54] Ryan: Correct. [45:54] Justin: And DBAs love to customize things. So. You know, like being able to sort of like, well, you have to manage these like cattle, not pets, in order to get, you know, sort of some of the benefit of being able to manage them in a way that's, you know, can be automated and easily recoverable and standardized. [46:13] Ryan: But you know, what if you just ran them on Kubernetes? You son of a— [46:20] Justin: You're just trying to get me angry now. I mean, we were making, we were talking about this earlier too, just, and so it's like, it's funny 'cause I'm, I'm, I'm sort of old. I'm not coming around, I don't want to go too far, but like there's been so many improvements at the storage layer because of managing like giant AI datasets for trading that it's like, hmm. I mean, you'll still blow up container, you know. [46:42] Ryan: Oh yeah. [46:42] Justin: I mean, like you're out of memory and CPU, like it's still gonna blow up. But you know, like this— [46:47] Ryan: Yeah, you need to have really, really tight controls on what you allow to be done with a container that's out of memory or out of CPU. Like, do not kill, let it, let it do its thing and we'll, we'll govern it other ways. [46:58] Justin: But yeah, we don't care how long we have to wait for it to finish. [47:00] Ryan: Yeah. And a lot of the cloud providers are running their managed services on Redis or similar services on Kubernetes. So it makes sense that it's doable, but it's, you know, don't build it yourself if you don't have to. [47:12] Justin: I wouldn't want to. Yeah. The support of it and And just guaranteeing transactions like, ooh, haha. [47:18] Ryan: Well, I mean, they also, the cloud also uses like Kinesis or SQS to also be a backup method so they can replay transactions into databases. Like they have a lot of, they have a lot of tricks that they're using that make these things scalable and fault and recoverable and a bunch of different failure models. [47:31] Justin: Yeah. So it's just build versus buy, right? I'd rather buy the solution for sure. Yep. [47:36] Ryan: Google's decided to get into chaos with the Cloud Fault Injection Testing or FIT. Now in preview, letting teams deliberately trigger failures like Cloud SQL failovers or injected latency and HTTP errors on Layer 7 Load Balancers to validate resilience before a real outage occurs. Ooh, that'd be a fun outage. Why is our Layer 7 Load Balancer so slow? Oh, someone turned this on by accident. The tool uses experiment templates that define the default and target resources with a built-in dry run mode that checks permissions and lists affected resources before any actual destruction happens. Experiments include a manual stop and revert capability, allowing teams immediately half it, halt a test, and restore normal state if something doesn't behave as expected. Early adopters include KeyBank and Servier are using FIT to simulate zonal outages and validate disaster recovery, which is particularly relevant for regulated industries like financial services facing compliance requirements around proven resilience. Access requires working with Google Cloud account team for preview enrollment. So reach out to those guys if you're interested. Or just go buy Gremlin or Chaos, you know, Chaos Engineer. [48:35] Justin: Yeah, I mean, it's funny because like the, where I've gotten value out of these tools isn't where I expected, right? Like it's you know, you put it in place and you introduce latency or region outages and you can definitely simulate things. But typically things that I've usually sort of encountered, but where I found the value in this is sort of demonstrating it for DR audits. Like just boop, see, look, it just, I just did it and it worked. The automation failed it over, did the whole thing, DR audit over. And it's kind of funny that way. [49:08] Ryan: Like, yeah, I mean, it's a great use case. I mean, it's probably the biggest one for chaos engineering, I think, you know, other than doing chaos, which is good for other reasons. [49:16] Justin: I just thought I'd use it more in design and development. I just don't. [49:21] Ryan: Yeah. Google Cloud is adding flexible billing and cost controls for AI agent workloads in Gemini Enterprise, combining per-user subscriptions with a new pay-as-you-go option to avoid quota limits. Mid-task. Developer tool consolidation with Google Antigravity and Android Studio AI usage now roll into existing Gemini Enterprise subscriptions for eligible customers. And flexible savings plans offer 10% off for 1 year or 20% off for 3-year spend commitments on Gemini Enterprise token costs with no minimum or maximum spend requirements and compatibility with existing enterprise agreements. I don't know how that works. So I'm going to commit to spending over 1 or 3 years and you're going to give me 20% off, but I don't have to commit to an amount? That seems weird. Yeah. [49:59] Justin: I mean, everything with token quotas and budgets is weird. [50:02] Ryan: I mean, it's just magic number. Yeah. Tokens are magically derived and then the cost of them is magic. It's all, it's all, no one actually can explain to you tokens. [50:11] Justin: No. No one knows how tokens, and I know there's not enough of 'em and they're too expensive and they do things like this to group 'em all together. But it's, this is across so many different platforms, like Gemini Enterprise, they've also confused the naming, you know, so there's the Enterprise Solution, there's, there's the Gemini Enterprise Toolset, which was once Vertex AI. And so like, and I know that these pools are set up to work across Google Workspace or like Google Docs and, and, and all of that as well as, you know, the Android, I just saw Android as part of this too. I'm like, I have no idea what those pools are and how to configure quotas in a, you know, sensible way. Like these are, It's cool they're pulled across a Google project, but how, what's my project setup look like? You know, I know the early days of Gemini Enterprise, they were just telling people to just enable users in a single project and manage it all there. So now it's, I'm sure they want you to not do that. So it's crazy. [51:08] Ryan: Yep, I'm sure it is. Gemini 3.5 Transcribe is Google's newest speech-to-text model offering via two APIs, the Live API for real-time streaming and the Interactions API for prerecorded audio, speaker attribution, and word-level timestamps. Accuracy improvements are measurable with a word error rate of 4% for streaming and 2.6% for non-streaming for artificial analysis benchmarks, plus a 70% improvement in time to final transcription compared to the prior TRIP-3 model. Functional capabilities include self-correction handling, for example, Tuesday, no Wednesday, filler word removal, auto-formatting, custom vocabulary support for jargon, and support for over 85 languages with regional accent handling. Uh, good luck with our accents. Integration spans Google's ecosystem, including Gboard's Rambler feature on Android, the Gemini app on macOS, and Google Antigravity AI Studio build mode, and upcoming Chrome support for voice dictation and web fields. It's available in public preview for developers via the Google AI Studio and Google Antigravity. [52:08] Justin: Nothing makes me feel like I talk weird, or maybe reminds me that I talk weird, like reading our transcripts of this podcast. It's trying to do word prediction and I just don't use words in a normal order. And it's, it is really funny. [52:23] Ryan: I'm interested in trying this because we're using, I don't know the name of the company we're using for transcription right now, but I'm not, I haven't been super happy with the accuracy of it. [52:31] Justin: Yeah. [52:31] Ryan: So I am, uh, I am very intrigued to give this one a shot. [52:35] Justin: Yeah, me too. And I'm hoping that it's, it's good and we can, I can just blame the technology and don't have to take this on the chin that I talk weird, even though I talk weird. [52:46] Ryan: Nah, when does that ever happen? All right, Azure, they're interesting. Microsoft and AWS are introducing Azure Multi-Cloud Interconnect, which will launch a co-engineered service that replaces manual multi-step network setup between the two clouds with a simplified API-driven provisioning model based on a shared OpenAPI specification. Service offers dedicated private connectivity up to 100 gigabits per second, additional availability with dynamic capacity scaling, MACsec encryption by default, and four nines of availability. Availability targeting your mission-critical and AI workloads that span both clouds. It integrates with Azure Private Link to provide an end-to-end private path, which matters for enterprises running distributed AI training inference pipelines or data pipelines that need low-latency, secure cross-cloud access without traversing the public internet. You know, this is nice, uh, because they did it with Google already, and so now we have it across basically Azure and, uh, GCP to AWS. So now we just need to get Google and Azure to connect to each other, and we'll have the trifecta. Everything. [53:45] Justin: I think someone announced Oracle last week or a week before. [53:50] Ryan: Oracle's had their interconnect with AWS for a while. I don't know if they have on Google. I think they have it on Google maybe now too. [53:56] Justin: I thought there was a more recent announcement where there's another one of similar sort of thing. I could be making stuff up though. [54:01] Ryan: I mean, you're hallucinating. It's fine. That's what AIs do. [54:05] Justin: That's what, like any good AI, I'm hallucinating. [54:07] Ryan: Yeah. Yep. [54:08] Justin: But it, yeah, I mean, it's, these things are great. It's, it's, it's nice to have that direct connection and not have to go over the public internet. And do all, if you're, you know, doing weird inspection and, and, you know, as we learned through the, the OpenAI, you know, Hugging Face thing, it's like that outbound access can be problematic. So keep it on known paths that you can monitor and look at more, more closely. Agreed. [54:34] Ryan: Uh, right. Well, we have a Cloud Journey, which is also in the Microsoft space, uh, but doesn't really quite fit with, uh, You know, thing, but we talked about at the top of the show vulnerabilities. So this is one of those blog posts that Microsoft likes to put out, which is a conceptualized thought piece, as I would call them. But basically it's arguing that traditional patch and remediate cycles are too slow given AI-accelerated exploit development, where vulnerabilities can move from disclosure to active exploitation within hours. Microsoft's argument is that network-level control should serve as a compensating layer during the disclosure-to-patch window, since since network enforcement can restrict access, segment assets, and limit lateral movement faster than software patches can be tested and deployed. I mean, if you're not doing this in 2026, like, whoa. Uh, the post-previews, uh, shift towards context-aware network enforcement rather than blunt blocking, citing the HTTP/2 DoS example, where rate limiting specific request patterns preserves service availability instead of disabling the protocol entirely. Microsoft frames this as leading towards adaptive security systems that ingest vulnerability intelligence, correlate it with real environment context and translate that into automated enforcement with AI positioned as the engine for that correlation and decision-making. So I mean, is Microsoft basically saying like, hey, we can't patch faster? So you're only, you're basically only gonna get Patch Tuesdays and so your answer is just mitigate with the network? [55:50] Justin: I was trying to like, you know, I definitely was like, oh, that's rich coming from you, was sort of my take on this. 'Cause it's, you know, having to deal with this internally, Microsoft has always been the problem. [56:01] Ryan: Right? [56:02] Justin: Patching Windows servers running in production cloud environments is still a nightmare. It's super disruptive. You can't trust it. They've, you know, they've completely ruined the confidence of anyone. So they've, you know, they put in place the ability for, you know, ops teams and to, to sort of have to, you know, allowlist patches. And so the machine doesn't know that it needs patched, because it's not available to it, the upstream patch. And so having this coordinated at multiple layers and public and all of these things, whereas like, it's just so much easier in the Linux world to, to just keep things up to date. And so like, it's, I guess like, oh, it's, it's too slow and we need all this AI stuff. Like I've been building all of this because of you, Microsoft. Like exactly this, all the things they mentioned is stuff I've built into internal services. Because I can't patch Windows quick enough or insured enough. So yeah, I guess so. But I don't know, maybe fix some of the patching things too. [57:03] Ryan: I mean, like, they remember they added, I think for Windows 2025 on Azure, they have the ability now to like allow you to hot patch the kernel, but like they haven't exposed that to anybody else. You have to be on Azure. I'm like, how would you actually make hot patching available to everybody? Because that would be huge. I mean, Linux has been doing hot patching forever. [57:23] Justin: Mm-hmm. [57:24] Ryan: Um, and there are occasionally times where you have to reboot for kernel updates, but like they're so far and in between that, you know, you don't mind it as much. Where every Windows patch, I feel like it requires a reboot. I think it's just a default. I don't think they, even if they don't need the reboot, they're still gonna make you reboot because no one ever thought to question them on the reboots. [57:41] Justin: I mean, you, you see it in like application install instructions, right? Where you might have to reboot multiple times in order to do it. Install, right? And it's just, I think it's the way they organize the registry or something. And so like, yeah, I imagine any change on the Windows server, they just modify the registry entry. It's like, oh, I need a reboot. And you know, so much so that I, I monitor for it now. So it's just like, okay, I have to continuously make sure this thing has been rebooted or it is actually vulnerable, even though the patch has been applied and completed. Like, it's a nightmare. [58:10] Ryan: Well, it's, I, I believe they still show up in Qualys scans typically if you're doing network-based scans. [58:15] Justin: Oh, they do. [58:15] Ryan: Oh yeah. Uh, the, the agent, the Qualys agent will tell you that it's patched because it sees the binary has been updated to the right version. But yeah, you, you won't actually see it. [58:24] Justin: But you can see the exploit. Yeah. If you're doing a network scan, you know, and typically those things are hidden behind firewalls and stuff. So it's not an exploit that's actually vulnerable. And I think that's where this gets, this article gets into the contextual awareness, which is important, right? Because you do, you can't call everything a critical when A, it hasn't been, have an upstream patch and B, isn't really possible for someone to to reach the exploit, but how do you make that decision? Yeah. When there's 70,000, like something like, uh, in the last signature update for like a few weeks ago, there's 12,000 new signatures added. [58:57] Ryan: Yeah, that's crazy. [58:57] Justin: Like vulnerability signatures. It's the, whereas, you know, a typical one would have a couple hundred. Yeah. [59:03] Ryan: Well, then there's also these vulnerabilities for Windows where you'll get like, oh, this is the Excel, cross XML parse defect, blah, blah, blah. And you're like, the server doesn't have Excel, but the DLL exists there so that if you did have Excel there, it would be vulnerable. But because the DLL is there, it's not getting recognized with the vulnerability management software. And the vulnerability management software is dumb and never factors in this, you know, the actual things required to make the DLL exploitable. Um, so that's, this is one area that I do hope AI does help us someday. [59:36] Justin: 'Cause yeah, but think of the dataset AI has to work across, like it's gonna be so expensive. Like that's system configuration server by server to determine that contextual risk. Like, oof. [59:46] Ryan: I mean, like so many companies have that already, right? They have asset management that has all the installed applications and they know all the assets of CMDB, and so they can actually parse that with AI to, to make a determination of actual risk. And so I'm like, the fact that Qualys doesn't have AI features in their product or even a roadmap for it blows my mind. I'm like, you guys, like AI is what I've always wanted in vulnerability scanning is that you guys can actually, I can teach you about my network and the design and the subnets and where the subnets live. And like, then you can factor in mitigating controls and like talk to Qualys and they're like, what? Sky is blue. Yeah. [60:20] Justin: No, they've never been very technology forward and it's always been super frustrating because they can't even talk the talk. Like a lot of other companies I work with, like they can at least acknowledge either the shortcomings of the product or, you know, sell me the bullshit that it's coming. [60:37] Ryan: Whereas Qualys, you can tell they don't even understand the question. [60:40] Justin: Like it's problematic. [60:43] Ryan: Yeah. But yeah, I do think, um, this is great until that server that they're talking about happens to be on the public-facing internet. And now all of a sudden you know, that server exploit on IIS is a much bigger deal. So like, I would like to see Microsoft also commit to, you know, if you're going to take this networking-based approach, which I applaud, also commit that, hey, services we know are publicly exposed to the internet because that's how they have to be deployed, IIS, you, you need to accelerate your patch windows for those. Yeah. You can't wait till Patch Tuesday once a month. [61:18] Justin: What's this monthly patch window? Yeah. It was ridiculous. [61:20] Ryan: So I do think I'd like to see Microsoft break down the patch window completely and the Tuesday Patch Tuesday idea and concept. Like you need more frequent patches. I'm getting patches for Linux stuff all the time. Like, I mean, every, even, even my code repositories depend about once a week, I have to run a Claude job that basically goes through and says, are these safe to apply or do I need to do something? And then I open a defect if I need to do something to test it, but A lot of those are, are very similar to the DLL problem. They're benign. Because if you're not executing that code path, that's fine. Uh, but just getting them off of Dependabot is a big deal. You know, who, that makes you feel better. And Ghast is another one. If you have GitHub Advanced Security, um, those things are available to you to determine, you know, actual exploit vulnerabilities, which is good. Yeah. [62:06] Justin: Although if you have GitHub Advanced Security also, I would like a pony because apparently money means nothing to you. [62:11] Ryan: I mean, I, I have it at my day job. Oh my God. [62:14] Justin: It's so expensive. That's awesome. I love it. I love the tool. [62:17] Ryan: I think it's amazing, but yeah, it's, it's a pricey tool, but it's, I'm impressed with what it can produce and the insights it gives you. And I'm just like, okay, I, I could see why this is worth what it's worth. Like, you know, you should be very proud of this one, GitHub. And I understand why you charge a lot of money. Now, Microsoft, since you also own them, you could also lower the cost of GaaS for everybody. [62:38] Justin: That'd be really nice. [62:39] Ryan: Which would be nice too. I mean, you do give us Dependabot for free, which is great. But, uh, you know, as a, as a small podcast, we would love to be able to use gas for like our bot to— [62:48] Justin: we really would. Yeah. And we could say good things because it's, it's a, yeah, nice. And then, you know, if you can reduce the cost for businesses too, I wouldn't have to like offer to sell the office furniture to try to make budget. [62:59] Ryan: Yeah, exactly. So yeah, lots to come, I think, still in this world of patch vulnerability. I think it's only going to get worse until the tooling catches up to the point where AI is writing the patches for the things being detected. But, you know, Microsoft, you can still do more. So please do. [63:17] Justin: I mean, that's the scary thing, right? So AI is probably already writing the patches of these things, but the risk to release and make changes is always going to make this a little lopsided argument, which sucks. But so, but then you have to just mitigate with layers. It's the only, the only solution. [63:35] Ryan: Well, somehow, Ryan, we have filled an hour and 4 minutes of time. And, uh, as much as, you know, we're insightful, I'm sure our listeners like to move on with their week, so we should go. [63:44] Justin: Oh, they're asleep. Oh, no one made it this far. [63:48] Ryan: I mean, if they did, they should definitely, you know, check out our Slack team. We are, uh, trying to get more active on our Slack team. If you haven't been there recently, we are posting more in the general channel and general conversations and between ourselves and stuff. Cause we're like, why are we having this conversation in the host room where we talk about the show stuff when we can be talking about this in the general room and then our listeners could jump in and talk to us too. So. We are, we're trying to be better community people. So, uh, we, we have not been great at the Slack team. And so, uh, people join and then they never really chat because I don't think we were, we were engaging properly. And so now we're, we're trying to engage more. So come, uh, come spend more time with us, uh, at The Cloud Pod. [64:23] Justin: Call us out, make fun of our wackiness. [64:26] Ryan: I mean, I'd love to, you tell us where we're wrong, cuz you know, we might, we might even invite you to the show to come and tell us why we're wrong. Cuz, uh, you know, you know, Jonathan isn't here most of the time, so we always have a spot for a fourth. Mm-hmm. [64:37] Justin: So. Yeah, we love being wrong. Yeah, I love being wrong. And correcting ourselves. Yeah, it's great learning. [64:41] Ryan: It's great. It is. All right, Ryan, we'll see you next week. Well, you won't see me actually. I'm gone next week. But you guys will have a good time recording whatever terrible cloud news comes out this week. [64:52] Justin: The children will be in charge as usual, so. [64:55] Ryan: Yep. [64:55] Justin: Oh God. [64:56] Ryan: All right, well I'll see you in 2 weeks then. [64:57] Justin: All right. Okay. Bye everybody. Another week of cloud news wrapped up. Vault will collect the news. Justin will get the notes. Jonathan will write some code. Ryan will watch the perimeter. And Matt will reluctantly watch Azure. Till next week for AI, Amazon, Google Cloud, and Azure. And hey, maybe even Oracle, who knows? Check out thecloudpod.net for our newsletter. Join our Slack, message us on socials, or leave a review.