1
00:00:05,120 --> 00:00:08,440
Welcome to Crying Out Cloud, the
podcast that'll make you laugh, 

2
00:00:08,440 --> 00:00:11,720
cry, and reconsider all of your 
cloud security fears. 

3
00:00:12,080 --> 00:00:14,800
I'm Eden. 
I'm here with my amazing Co host

4
00:00:14,800 --> 00:00:17,000
AMI Tai. 
Hello. 

5
00:00:17,560 --> 00:00:20,560
Today we have a super special 
guest that we're super excited 

6
00:00:20,560 --> 00:00:22,800
to have on Liz Rice. 
Welcome. 

7
00:00:23,680 --> 00:00:26,840
Hi, thanks for having me. 
You have a very cool background,

8
00:00:26,840 --> 00:00:30,840
much cooler than ours. 
I guess I've got, well, I don't 

9
00:00:30,840 --> 00:00:33,960
have anywhere else to put on my 
music stuff other than in my 

10
00:00:33,960 --> 00:00:36,120
office. 
And then I've got a few hosters 

11
00:00:36,120 --> 00:00:38,960
and things. 
And my, my favorite thing at the

12
00:00:38,960 --> 00:00:42,960
moment is this EB that I was 
given in Peru. 

13
00:00:42,960 --> 00:00:49,960
It was really nice. 
I was doing a AKCD Peru event 

14
00:00:49,960 --> 00:00:55,000
and some people there gave me 
this very nice Peruvian EB. 

15
00:00:55,000 --> 00:00:57,280
So that was really cute. 
Love it. 

16
00:00:58,920 --> 00:01:02,400
So let's introduce you to our 
guests who may not know you. 

17
00:01:02,800 --> 00:01:07,080
Liz is the Chief Open Source 
Officer at Isovalent, which is 

18
00:01:07,080 --> 00:01:10,840
now part of Cisco and formerly A
prominent member of the CNCF 

19
00:01:10,840 --> 00:01:14,800
Board, having chaired their 
Technical Oversight Committee. 

20
00:01:15,080 --> 00:01:19,640
She is a world renowned expert 
on EBPF container and Kubernetes

21
00:01:19,640 --> 00:01:23,760
security and we are super 
thrilled to have you on and to 

22
00:01:23,760 --> 00:01:26,320
get to learn from your well of 
knowledge. 

23
00:01:26,760 --> 00:01:28,880
Oh, that's very kind. 
It's a pleasure to be here. 

24
00:01:30,000 --> 00:01:31,440
Yay, where are you calling us 
from? 

25
00:01:32,000 --> 00:01:36,360
I am in the outskirts of London,
in a borough called Enfield. 

26
00:01:37,360 --> 00:01:41,280
So we like to kick off episodes 
with guests with a section 

27
00:01:41,280 --> 00:01:45,200
called Cloud Confessions, and 
that is to get to know our 

28
00:01:45,200 --> 00:01:49,400
guests a little bit beyond the 
serious security questions. 

29
00:01:49,400 --> 00:01:51,280
Are you up for some Cloud 
Confessions? 

30
00:01:51,640 --> 00:01:56,240
OK, let's let's give it a whirl.
So we learned via the Internet 

31
00:01:56,240 --> 00:01:59,320
that you're an avid biker. 
What is your favorite place to 

32
00:01:59,320 --> 00:02:02,960
ride? 
My favorite ride in the world is

33
00:02:03,280 --> 00:02:06,920
to a place called Jodrell Bank. 
Jodrell Bank has this incredible

34
00:02:06,920 --> 00:02:10,240
radio telescope. 
It's it's just the nicest bit of

35
00:02:10,240 --> 00:02:12,000
engineering. 
And sometimes you're there and 

36
00:02:12,000 --> 00:02:15,560
you can see them turning the 
radio telescope and they've got 

37
00:02:15,560 --> 00:02:17,680
a really nice cafe there. 
So it's a great place to ride. 

38
00:02:17,680 --> 00:02:19,400
So that's my favorite. 
Ride amazing. 

39
00:02:20,760 --> 00:02:27,160
OK, in note of the music stuff 
in the background, we actually 

40
00:02:27,160 --> 00:02:29,080
listened to your music on 
SoundCloud. 

41
00:02:29,080 --> 00:02:31,800
It was in the background as we 
were for the episode. 

42
00:02:33,120 --> 00:02:34,240
There's a lot of instruments 
there. 

43
00:02:34,240 --> 00:02:35,880
Do you play all of these 
instruments? 

44
00:02:36,680 --> 00:02:39,920
Yes, pretty badly. 
But yes, I mean, I'm, I'm 

45
00:02:39,920 --> 00:02:43,440
mediocre at lots of instruments,
but I'm pretty OK at the 

46
00:02:43,440 --> 00:02:46,520
production and kind of editing 
stuff and putting stuff 

47
00:02:46,520 --> 00:02:47,760
together. 
So yeah. 

48
00:02:48,000 --> 00:02:51,720
Speaking of that, you you did a 
blog post A deep composer which 

49
00:02:51,720 --> 00:02:54,640
is a cool tool on AW that. 
Was a while ago. 

50
00:02:54,960 --> 00:02:56,880
Yeah, yeah. 
It was a while ago, but we've 

51
00:02:56,920 --> 00:02:58,720
read it as it's very 
interesting. 

52
00:02:58,720 --> 00:03:01,400
How do you feel about 
incorporating Like AI and these 

53
00:03:01,400 --> 00:03:03,600
tools into your creative 
process? 

54
00:03:06,000 --> 00:03:11,360
I do worry about AI taking away 
the fun of creativity. 

55
00:03:12,840 --> 00:03:16,040
I think it could be potentially 
a really nice tool. 

56
00:03:16,040 --> 00:03:21,720
And you know, I, I wouldn't want
to completely dismiss using AI 

57
00:03:21,720 --> 00:03:24,520
and particularly, you know, if 
I'm editing bits of music quite 

58
00:03:24,520 --> 00:03:27,760
often I'm doing some pretty 
repetitive, tedious, you know, 

59
00:03:27,760 --> 00:03:29,760
chopping out bits of noise or 
something. 

60
00:03:30,080 --> 00:03:33,320
And I wouldn't mind using AI to 
do that, but I would want to be 

61
00:03:33,320 --> 00:03:36,680
in control of the creative side 
of it. 

62
00:03:37,880 --> 00:03:42,160
I do use AI quite a lot at the 
moment for research. 

63
00:03:42,240 --> 00:03:48,520
You know, if I want to find out 
something, I'm finding AI to be 

64
00:03:48,520 --> 00:03:51,640
a really good way of giving me 
the kind of doing the groundwork

65
00:03:51,880 --> 00:03:54,920
and then I'm going to check what
it says. 

66
00:03:55,160 --> 00:03:59,120
So I feel like AI is going to be
very exciting and is going to 

67
00:03:59,120 --> 00:04:02,240
change a lot of things in the 
world. 

68
00:04:02,600 --> 00:04:06,880
But from a creative perspective,
I do not want the entire world 

69
00:04:06,880 --> 00:04:10,320
to be full of just AI generated 
art and AI generated music 

70
00:04:10,320 --> 00:04:15,840
because the fun thing is humans 
doing it and the personalities 

71
00:04:15,840 --> 00:04:18,800
involved in it. 
So you mentioned on your website

72
00:04:18,800 --> 00:04:22,640
that you do live coding in your 
From Scratch conference talks. 

73
00:04:23,200 --> 00:04:29,600
So we were curious what that is 
like, how that works, and what 

74
00:04:29,600 --> 00:04:33,440
do you think makes makes that 
style effective? 

75
00:04:33,800 --> 00:04:36,800
Yeah. 
So I, I think quite a few people

76
00:04:36,800 --> 00:04:39,280
will have seen me doing 
container from scratch or 

77
00:04:39,280 --> 00:04:42,880
debugger from scratch, putting 
those talks together. 

78
00:04:43,080 --> 00:04:47,560
I, I really enjoy putting those 
together because first of all, 

79
00:04:47,560 --> 00:04:49,560
you have to really understand 
what you're doing. 

80
00:04:49,720 --> 00:04:52,040
Secondly, you kind of have to 
edit it down. 

81
00:04:52,040 --> 00:04:55,600
You have to figure out what are 
the really important things that

82
00:04:55,600 --> 00:04:59,320
I'm trying to get across that I 
want to write the code for and 

83
00:04:59,320 --> 00:05:02,520
what are the things that are 
just, you know, implementation 

84
00:05:02,520 --> 00:05:06,720
detail that don't really matter 
to understanding the concepts 

85
00:05:06,720 --> 00:05:12,680
that I'm trying to explain. 
So putting my style into the 

86
00:05:13,600 --> 00:05:16,880
editing what is actually in and 
out of the code. 

87
00:05:17,360 --> 00:05:21,240
And then also just practicing a 
lot the actual typing and you 

88
00:05:21,240 --> 00:05:23,760
know, things like autocomplete 
can really help there, but I 

89
00:05:23,800 --> 00:05:27,000
always want to actually do the 
thing. 

90
00:05:27,000 --> 00:05:29,520
I don't want to just press a 
button, have it type it in for 

91
00:05:29,520 --> 00:05:32,000
me. 
Maybe that's me being silly, but

92
00:05:32,160 --> 00:05:35,480
I, I like, I quite like the 
Jeopardy as well. 

93
00:05:35,480 --> 00:05:39,440
I think audiences like the, you 
know, what if it doesn't work? 

94
00:05:39,560 --> 00:05:40,920
Yeah. 
And sometimes, you know, the, 

95
00:05:41,000 --> 00:05:44,400
you can the audience, if they're
paying attention, they can tell 

96
00:05:44,400 --> 00:05:45,960
you, you know, you've made a 
typo. 

97
00:05:46,000 --> 00:05:49,440
And then that gives it a bit of 
audience participation. 

98
00:05:49,440 --> 00:05:52,920
That is fun. 
We recently, we recently hosted,

99
00:05:52,920 --> 00:05:56,800
hosted AACTF during which we 
when we were revealing the 

100
00:05:56,800 --> 00:06:00,640
answers, I had to type command 
lines. 

101
00:06:01,440 --> 00:06:04,160
And it was incredibly stressful 
because I was like, I made a 

102
00:06:04,160 --> 00:06:06,320
typo. 
And then someone was like, you 

103
00:06:06,320 --> 00:06:08,280
missed, you missed a letter. 
You missed a letter. 

104
00:06:08,440 --> 00:06:09,840
That's why it's not working. 
You missed a letter. 

105
00:06:09,840 --> 00:06:12,320
And I was like, Oh my God. 
That's why they put me only in 

106
00:06:12,320 --> 00:06:15,920
charge of the music for it 
turning on and off the. 

107
00:06:18,400 --> 00:06:20,600
Music. 
So you are a published author, 

108
00:06:20,720 --> 00:06:23,880
which is something we want to 
talk about also a bit later, But

109
00:06:23,880 --> 00:06:25,640
first something we were curious 
about. 

110
00:06:26,360 --> 00:06:29,840
You published a book about EBPF 
that has AB on the cover, which 

111
00:06:29,840 --> 00:06:32,000
makes sense to us. 
But you also published a 

112
00:06:32,000 --> 00:06:35,320
different book about container 
security that has a a fish on 

113
00:06:35,320 --> 00:06:38,840
the cover. 
So we were wondering why? 

114
00:06:39,080 --> 00:06:41,600
What type of fish is this and 
how does it relate to container 

115
00:06:41,600 --> 00:06:45,680
security? 
So the publisher is O'Reilly and

116
00:06:46,040 --> 00:06:50,080
they're quite well known for 
having these animal images on 

117
00:06:50,080 --> 00:06:53,360
the cover of the books. 
And they actually go out and 

118
00:06:53,360 --> 00:06:58,160
find, I'm going to say like 18th
or 19th century books. 

119
00:06:58,160 --> 00:07:01,040
And they have these, you know, 
illustrations in and they 

120
00:07:01,040 --> 00:07:03,800
they're all unique. 
You know, every book that they 

121
00:07:03,800 --> 00:07:07,080
do has a unique animal print on 
it. 

122
00:07:07,080 --> 00:07:12,360
And then they colourize them. 
And because they're not kind of 

123
00:07:12,640 --> 00:07:17,880
drawn from scratch, they're 
sourced from these old animal 

124
00:07:17,880 --> 00:07:21,000
images. 
They don't have like a infinite 

125
00:07:21,000 --> 00:07:23,880
number of different images to 
choose from. 

126
00:07:24,080 --> 00:07:27,480
Plus also if they let authors 
choose what they want, then we'd

127
00:07:27,520 --> 00:07:30,280
all be there going like, I want 
a panda, No, I want a panda, No,

128
00:07:30,320 --> 00:07:33,240
I want, you know what I mean? 
Everybody would want the cute 

129
00:07:33,920 --> 00:07:37,480
things. 
So they pretty much say you 

130
00:07:37,480 --> 00:07:41,720
don't get a choice, You can. 
I mean like with the B, they've 

131
00:07:41,720 --> 00:07:45,200
obviously tried pretty hard to 
find something relevant. 

132
00:07:46,120 --> 00:07:49,560
And the answer for the fish on 
the container security book is 

133
00:07:49,560 --> 00:07:54,000
that it's an armoured catfish, 
so the armor is supposed to 

134
00:07:54,000 --> 00:07:56,440
represent hardening and 
security. 

135
00:07:59,360 --> 00:08:02,560
You participated. 
I, I don't know your extent of 

136
00:08:02,560 --> 00:08:08,280
participation in a documentary 
about EBPF, which was really 

137
00:08:08,280 --> 00:08:10,440
cool. 
And I actually have all of the 

138
00:08:10,480 --> 00:08:14,200
different people we've engaged 
with, which are a lot of people 

139
00:08:14,200 --> 00:08:16,680
in the security world. 
We've never seen a documentary 

140
00:08:17,400 --> 00:08:21,080
as an angle of like education 
and awareness. 

141
00:08:21,760 --> 00:08:24,240
What was it about? 
What was the experience like? 

142
00:08:24,520 --> 00:08:27,440
Yeah. 
So we worked with this team who 

143
00:08:27,440 --> 00:08:31,840
had previously done a 
documentary about Kubernetes and

144
00:08:31,840 --> 00:08:34,880
I think there was another since 
it may be Envoy that they had 

145
00:08:36,000 --> 00:08:39,120
previously done documentaries 
for that they've done through 

146
00:08:39,120 --> 00:08:42,760
the CNCF. 
And we thought actually the 

147
00:08:42,760 --> 00:08:48,000
story behind ebpf is a really 
interesting story and there's 

148
00:08:48,000 --> 00:08:51,360
some, you know, interesting 
people and some characters from 

149
00:08:51,360 --> 00:08:54,360
lots of different organisations.
It would be cool to get this, 

150
00:08:54,880 --> 00:08:59,440
you know, recorded plus the, I 
don't know the production 

151
00:08:59,440 --> 00:09:03,200
quality, you know, for all of 
these documentaries we've been 

152
00:09:03,200 --> 00:09:05,480
so impressed by. 
So we really wanted to work with

153
00:09:05,480 --> 00:09:07,040
them and they did such a great 
job. 

154
00:09:07,040 --> 00:09:12,800
I really, we watched, we had a 
screening of the documentary. 

155
00:09:13,000 --> 00:09:16,400
I had seen it, you know, a, a 
draft of it a couple of times 

156
00:09:16,400 --> 00:09:19,840
before, but we had a proper 
screening at a cube con, I think

157
00:09:19,840 --> 00:09:23,880
it was in Chicago. 
And you know, we had a packed 

158
00:09:23,880 --> 00:09:27,200
room full of people watching it.
It was like the premiere and and

159
00:09:27,200 --> 00:09:28,520
it was so much fun. 
It's. 

160
00:09:28,840 --> 00:09:31,080
Interesting. 
Like it really immortalizes the 

161
00:09:31,760 --> 00:09:34,200
the the the process. 
It's like you, you something 

162
00:09:34,200 --> 00:09:37,280
people can watch like 50 years 
from now, like as a, as a piece 

163
00:09:37,280 --> 00:09:39,920
of history about, about computer
science and computer security. 

164
00:09:40,400 --> 00:09:43,800
Yeah, and I think ebpf is one of
those really game changing 

165
00:09:43,800 --> 00:09:46,400
technologies. 
So it's nice, you know, that 

166
00:09:46,680 --> 00:09:51,400
people like Alexei and Daniel, 
who were the original creators 

167
00:09:51,400 --> 00:09:56,640
of IT, get to tell their story, 
you know, and really, you know, 

168
00:09:56,680 --> 00:10:01,480
emphasize their place and the 
place of ebpf in the evolution 

169
00:10:01,480 --> 00:10:04,520
of software and the evolution of
particularly infrastructure 

170
00:10:04,520 --> 00:10:08,160
software. 
OK, Ready for the most famous 

171
00:10:08,160 --> 00:10:11,920
question on the podcast? 
It's the it's the one that comes

172
00:10:11,920 --> 00:10:15,800
back and back again. 
If you were a vulnerability, 

173
00:10:15,920 --> 00:10:17,760
what type of vulnerability would
you be? 

174
00:10:18,600 --> 00:10:21,080
You see, I don't want to say I'm
going to be a remote code 

175
00:10:21,080 --> 00:10:23,680
execution, although I would be 
quite good at typing it in 

176
00:10:23,680 --> 00:10:27,480
really quickly. 
You know, I can, I can type in 

177
00:10:27,480 --> 00:10:30,360
my my remote code execution 
live. 

178
00:10:32,280 --> 00:10:35,480
Yeah, but I bet, I imagine 
everybody says that. 

179
00:10:36,200 --> 00:10:39,520
Well, I think that's like the 
the thing that everybody wants 

180
00:10:39,520 --> 00:10:41,720
and then people try to be 
original and then they say 

181
00:10:41,720 --> 00:10:44,720
different things so that that 
one might be free. 

182
00:10:45,800 --> 00:10:48,440
Well, in that case, that's me. 
I'm going to come into your 

183
00:10:48,440 --> 00:10:51,040
system and type in a command 
from stage. 

184
00:10:51,120 --> 00:10:54,680
Really fast. 
You might be a race condition. 

185
00:10:55,760 --> 00:10:59,200
There's an idea, yeah. 
You've passed the cloud 

186
00:10:59,200 --> 00:11:02,720
confessions. 
We've graduated to the serious 

187
00:11:02,720 --> 00:11:04,200
questions. 
Are you ready? 

188
00:11:04,560 --> 00:11:08,080
OK. 
Your title is chief Open Source 

189
00:11:08,080 --> 00:11:11,120
Officer. 
Can you tell us what that role 

190
00:11:11,120 --> 00:11:13,560
entails and how you how you got 
there? 

191
00:11:14,160 --> 00:11:17,920
Like a lot of titles, it's, you 
know, we kind of made it up, but

192
00:11:18,720 --> 00:11:24,160
we really wanted to emphasize 
the importance of open source to

193
00:11:24,720 --> 00:11:26,920
I surveillance, to the whole I 
surveillance team. 

194
00:11:27,400 --> 00:11:32,440
And you know, we really built 
our business on top of the BPF 

195
00:11:32,480 --> 00:11:35,800
and the Cilium project and now 
Tetragon as well. 

196
00:11:36,120 --> 00:11:42,360
You know, the open source 
projects are important to, you 

197
00:11:42,360 --> 00:11:44,760
know, so many members of the 
team, you know what they're 

198
00:11:44,760 --> 00:11:49,880
passionate about. 
And we really believe in being 

199
00:11:49,880 --> 00:11:53,360
able to provide, you know, 
enterprise distributions of 

200
00:11:53,360 --> 00:11:58,000
those tools. 
And we want to make sure we are 

201
00:11:58,000 --> 00:12:02,680
doing the right thing by those 
open source communities. 

202
00:12:02,680 --> 00:12:06,800
And, and you know, Psyllium is 
owned by the CNCF. 

203
00:12:06,800 --> 00:12:09,880
It's not a nice surveillance 
project anymore, but we invest a

204
00:12:09,880 --> 00:12:15,120
huge amount into it. 
We, we always want to be doing 

205
00:12:15,120 --> 00:12:18,960
the right thing by the community
and balance that against the 

206
00:12:18,960 --> 00:12:21,760
business. 
So in a lot of ways, what I and 

207
00:12:21,760 --> 00:12:26,600
my team do is make sure that 
we're providing those guard 

208
00:12:26,600 --> 00:12:29,720
rails to the engineering team 
and maybe the, you know, the 

209
00:12:29,720 --> 00:12:33,920
tension between proprietary 
software and open source. 

210
00:12:33,920 --> 00:12:38,480
We can be there to advocate for 
doing the right thing for the 

211
00:12:38,480 --> 00:12:40,840
open source project, but without
getting in the way of the 

212
00:12:40,840 --> 00:12:45,280
business side of things. 
We also do a lot in terms of 

213
00:12:46,640 --> 00:12:49,840
evangelizing that technology and
trying to encourage other people

214
00:12:49,840 --> 00:12:55,080
to use, you know, whether that's
ebpf or Cillium or Tetragon, how

215
00:12:55,080 --> 00:12:59,600
powerful the open source could 
be for whatever it is that 

216
00:12:59,600 --> 00:13:02,040
whatever problems they need to 
solve, you know, and for some 

217
00:13:02,040 --> 00:13:06,040
people, those open source 
projects will give them all that

218
00:13:06,040 --> 00:13:08,840
they need and they don't need an
enterprise solution. 

219
00:13:08,840 --> 00:13:13,160
And that's great, but maybe one 
day they do need, you know, 

220
00:13:13,160 --> 00:13:16,720
they, they need somebody on the 
end of a phone to shout out if 

221
00:13:16,720 --> 00:13:20,640
something goes wrong or they 
need some enterprise specific 

222
00:13:20,640 --> 00:13:24,120
features. 
And they already know and trust,

223
00:13:25,040 --> 00:13:27,360
you know, they know the 
technology, they know the team, 

224
00:13:27,360 --> 00:13:30,160
they've, they've worked with us 
in the open source world. 

225
00:13:30,160 --> 00:13:34,560
So it's, I think open source can
be a really powerful way of 

226
00:13:35,280 --> 00:13:39,760
showing off your technical 
expertise as a team. 

227
00:13:40,200 --> 00:13:43,720
So you were previously on the on
the CNCF board. 

228
00:13:45,120 --> 00:13:49,160
So for those not familiar, we 
wanted to ask what is the CNCF? 

229
00:13:49,160 --> 00:13:52,200
What do they do and how can 
people benefit from their work? 

230
00:13:52,280 --> 00:13:55,520
Yeah, sure. 
So CNCF stands for Cloud Native 

231
00:13:55,520 --> 00:14:00,240
Computing Foundation. 
It's a foundation within the 

232
00:14:00,240 --> 00:14:02,960
family of Linux Foundation 
foundations. 

233
00:14:03,280 --> 00:14:05,920
How many times can I say the 
word foundation in one sentence?

234
00:14:05,920 --> 00:14:15,040
And it's an entity that exists 
to be a neutral owner of open 

235
00:14:15,040 --> 00:14:18,640
source projects, so for cloud 
native, specifically cloud 

236
00:14:18,640 --> 00:14:21,960
native related projects. 
And the Linux Foundation 

237
00:14:21,960 --> 00:14:25,360
obviously was originally set up 
to be the neutral home for Linux

238
00:14:25,360 --> 00:14:29,160
itself. 
And the idea is that by being a 

239
00:14:29,160 --> 00:14:36,520
neutral owner, no one company 
can dictate the future of these 

240
00:14:36,880 --> 00:14:41,360
projects. 
Lots of companies can get 

241
00:14:41,360 --> 00:14:46,040
involved, obviously being 
sponsors and members and helping

242
00:14:46,040 --> 00:14:52,960
the foundation to be successful.
But really it's there to make 

243
00:14:52,960 --> 00:14:58,280
sure that there is a neutral 
ground so that you know, if 

244
00:14:58,280 --> 00:15:01,840
you're a user and you're 
consuming a project like 

245
00:15:01,840 --> 00:15:07,480
Kubernetes or Psyllium or Envoy 
or any of the 200 whatever, plus

246
00:15:07,480 --> 00:15:11,560
projects from the CNCF, you know
that you're never going to be 

247
00:15:11,560 --> 00:15:14,560
held over a barrel by one 
particular vendor. 

248
00:15:15,040 --> 00:15:18,040
You might well work with vendor,
you might well work with 

249
00:15:18,040 --> 00:15:22,320
multiple different vendors for 
different projects, but you know

250
00:15:22,320 --> 00:15:26,480
that if push comes to shove, 
there are other ways of 

251
00:15:26,480 --> 00:15:28,520
consuming basically that 
software. 

252
00:15:29,120 --> 00:15:32,040
You know, if for whatever 
reason, you know, I mean, we, we

253
00:15:32,040 --> 00:15:35,320
saw this when, when Cisco 
acquired Isovalent, there were 

254
00:15:36,160 --> 00:15:38,680
naysayers, let's say, who 
thought, oh, you know, that'll 

255
00:15:38,680 --> 00:15:42,160
be the end of cilium, you know, 
because Isovalent won't want to 

256
00:15:42,240 --> 00:15:44,760
invest in it anymore because, 
you know, and actually couldn't 

257
00:15:44,760 --> 00:15:47,480
be further from the trees. 
Cisco have been incredible 

258
00:15:47,640 --> 00:15:51,760
supporters of us continuing to 
do, you know, what's worked for 

259
00:15:51,760 --> 00:15:53,480
us before continues to work for 
us now. 

260
00:15:53,480 --> 00:15:57,960
We continue to do a ton of 
investment in open source 

261
00:15:58,160 --> 00:16:02,920
cilium, but if, you know, if 
Cisco for whatever reason had to

262
00:16:02,920 --> 00:16:05,600
decide if they didn't want us to
invest, the cilium project would

263
00:16:05,600 --> 00:16:08,040
still be there. 
And I think, to be honest, the 

264
00:16:08,040 --> 00:16:10,720
likelihood would be loads of 
people who work on cilium would 

265
00:16:10,720 --> 00:16:14,680
want to carry on working on it 
because they've put so many, you

266
00:16:14,680 --> 00:16:18,600
know, years of their life into 
it, into building that project, 

267
00:16:18,600 --> 00:16:20,200
and they really want it to be 
successful. 

268
00:16:21,240 --> 00:16:24,320
But yeah, thankfully Cisco been 
super supportive about 

269
00:16:24,560 --> 00:16:27,760
continuing to do that. 
It also feels like it's it's 

270
00:16:27,760 --> 00:16:30,880
sort of a stamp of approval in 
some cases for for some of these

271
00:16:30,880 --> 00:16:32,080
projects. 
Yeah, definitely. 

272
00:16:32,080 --> 00:16:37,120
So the CNCF gives these maturity
levels where essentially if you 

273
00:16:37,120 --> 00:16:41,480
get a graduated project, that's 
saying to an end user, this is, 

274
00:16:41,680 --> 00:16:45,400
you know, widely adopted, it's 
got good practices, it's got 

275
00:16:45,400 --> 00:16:51,000
things like, you know, security 
processes for the project so you

276
00:16:51,000 --> 00:16:57,600
can have some level of comfort 
and, and confidence in using 

277
00:16:57,600 --> 00:17:01,360
that project. 
Let's shift a little bit and 

278
00:17:01,360 --> 00:17:05,400
talk about EBPF. 
For those who aren't familiar, 

279
00:17:05,400 --> 00:17:11,880
can you explain what it is? 
And also for everyone, what 

280
00:17:11,880 --> 00:17:15,560
makes it revolutionary relative 
to how things were done before 

281
00:17:15,560 --> 00:17:17,280
it existed? 
Yeah. 

282
00:17:17,760 --> 00:17:22,359
So we say the letters EVPF and 
everybody expects that to be an 

283
00:17:22,359 --> 00:17:25,640
acronym. 
It used to be an acronym, but we

284
00:17:25,640 --> 00:17:29,560
now consider it to be a stand 
alone term because the P and the

285
00:17:29,560 --> 00:17:32,680
F stood for packet filtering and
people got confused and thought 

286
00:17:32,680 --> 00:17:34,840
that it was really about packet 
filtering. 

287
00:17:34,840 --> 00:17:39,240
And it's about so much more than
packet filtering now that we can

288
00:17:39,240 --> 00:17:44,200
just forget the acronym. 
It's what it actually is, is a 

289
00:17:44,360 --> 00:17:49,400
technology for running programs 
within the kernel. 

290
00:17:49,600 --> 00:17:53,520
So you can change the way that 
the kernel of an operating 

291
00:17:53,520 --> 00:17:58,320
system behaves by loading in 
programs dynamically. 

292
00:17:59,080 --> 00:18:03,240
So just to make sure, let's 
explain what the kernel is. 

293
00:18:03,240 --> 00:18:07,080
The kernel is the bit of the 
operating system that interfaces

294
00:18:07,080 --> 00:18:10,640
with hardware. 
So if you've got a program 

295
00:18:10,640 --> 00:18:13,640
that's going to write to a file 
or send and receive a network 

296
00:18:13,640 --> 00:18:18,480
message or put something on the 
screen or anything that 

297
00:18:18,800 --> 00:18:21,760
accessing memory, all of these 
things have to actually be done 

298
00:18:21,760 --> 00:18:25,120
by the kernel. 
And your application code will 

299
00:18:25,120 --> 00:18:29,840
make what's called system calls 
to ask the kernel to do these 

300
00:18:29,840 --> 00:18:32,760
things. 
And the kernel is also 

301
00:18:32,760 --> 00:18:36,320
coordinating different 
applications that might be 

302
00:18:36,320 --> 00:18:40,200
running on that machine. 
So what that means is the kernel

303
00:18:40,200 --> 00:18:43,200
is involved whenever you're 
doing anything like accessing a 

304
00:18:43,200 --> 00:18:47,960
file or sending network messages
or accessing memory, and the 

305
00:18:47,960 --> 00:18:50,920
kernel knows about all of the 
different applications that are 

306
00:18:50,920 --> 00:18:56,800
running on that machine. 
So by using EVPF to either 

307
00:18:57,320 --> 00:19:03,720
instrument or even change the 
behaviour of the kernel, we can 

308
00:19:03,800 --> 00:19:08,520
instantly get visibility and 
control over all of those 

309
00:19:08,520 --> 00:19:12,560
applications. 
And that happens dynamically. 

310
00:19:12,560 --> 00:19:17,040
So even an application that's 
already running ebpf gets 

311
00:19:17,240 --> 00:19:20,360
visibility into it straight 
away, which is incredibly 

312
00:19:20,360 --> 00:19:25,040
powerful because it means if you
load a new observability tool 

313
00:19:25,160 --> 00:19:29,200
onto that machine, you don't 
have to restart the applications

314
00:19:29,200 --> 00:19:31,720
on that machine. 
This they're immediately 

315
00:19:32,200 --> 00:19:38,720
observable through that tool. 
Plus the fact that it's in the 

316
00:19:38,720 --> 00:19:42,680
kernel means you don't have to 
sort of transition between user 

317
00:19:42,680 --> 00:19:45,120
space and kernel. 
So it can be incredibly 

318
00:19:45,800 --> 00:19:50,480
lightweight, incredibly 
efficient compared to talling 

319
00:19:50,480 --> 00:19:54,520
that's come before, where you 
might be able to observe 

320
00:19:54,520 --> 00:19:57,160
something in the kernel, but 
you'd have to send something to 

321
00:19:57,160 --> 00:20:02,920
user space to keep track of it. 
With ebpf, we can do the, we can

322
00:20:02,920 --> 00:20:04,840
store information within the 
kernel. 

323
00:20:04,840 --> 00:20:07,800
We don't have to do that kind of
expensive transitioning between 

324
00:20:07,800 --> 00:20:11,400
kernel and user space, and that 
makes for much more efficient. 

325
00:20:11,840 --> 00:20:15,360
Tooling. 
And what are you excited about 

326
00:20:15,400 --> 00:20:18,840
in terms of the future plans for
ABPF, where we're going? 

327
00:20:20,280 --> 00:20:27,800
So there are things that are new
in the kernel that are really 

328
00:20:27,800 --> 00:20:31,000
cool. 
One of which I love is a thing 

329
00:20:31,000 --> 00:20:34,560
called netkit. 
And netkit is an example of 

330
00:20:34,560 --> 00:20:36,880
being able to bypass bits of the
network stack. 

331
00:20:37,040 --> 00:20:42,120
The end result is that you can 
do networking from containers 

332
00:20:42,600 --> 00:20:49,080
with 0 overhead, so you're in 
normal but or prior to to net 

333
00:20:49,080 --> 00:20:55,600
kit if you have a an application
running in a container. 

334
00:20:56,080 --> 00:21:00,120
Typically, we deliberately 
isolate the networking for a 

335
00:21:00,120 --> 00:21:04,200
container from the host 
networking, and that has 

336
00:21:04,200 --> 00:21:08,040
traditionally meant you have a 
virtual network connection 

337
00:21:08,040 --> 00:21:10,800
between the host and the 
container. 

338
00:21:11,680 --> 00:21:16,480
And even though it's virtual, 
you're sort of running a network

339
00:21:16,480 --> 00:21:20,400
stack at either end of that 
virtual connection as if it were

340
00:21:20,520 --> 00:21:24,040
a physical connection. 
So until now, there's always 

341
00:21:24,040 --> 00:21:28,480
been a bit of overhead for 
container networking to 

342
00:21:28,480 --> 00:21:32,720
transition over that virtual 
connection, but with Netkit 

343
00:21:33,320 --> 00:21:37,160
essentially just bypasses it. 
So you still have the isolation 

344
00:21:37,160 --> 00:21:40,440
of the network stack in the 
container, but there is no 

345
00:21:40,480 --> 00:21:44,840
overhead involved because we can
transition packets straight from

346
00:21:45,800 --> 00:21:48,040
the host to the container and 
vice versa. 

347
00:21:48,640 --> 00:21:54,880
And that I think is, well a will
make, you know, containerised 

348
00:21:54,880 --> 00:21:57,960
deployments much more efficient 
from a networking point of view.

349
00:21:58,320 --> 00:22:03,000
And it will, you know, it will 
save CPU, it will save latency, 

350
00:22:03,000 --> 00:22:06,880
it will be, you know, better 
performance all round. 

351
00:22:07,640 --> 00:22:11,480
I suppose that could also be 
used to perhaps as a mitigation 

352
00:22:11,480 --> 00:22:15,560
against malware that uses ebpf 
as well. 

353
00:22:15,760 --> 00:22:17,520
Right exactly if you. 
Have like a white list. 

354
00:22:17,520 --> 00:22:22,400
Exactly that, yeah. 
It's clear to everyone, I think 

355
00:22:22,600 --> 00:22:25,960
that open source has had a 
hugely positive impact on the 

356
00:22:25,960 --> 00:22:29,320
industry. 
And I think like on, on computer

357
00:22:29,320 --> 00:22:32,960
science and, and, and society 
to, to, to a large degree. 

358
00:22:34,040 --> 00:22:37,400
But we do see every once in a 
while concerns about security 

359
00:22:37,400 --> 00:22:39,640
aspects. 
Usually they come up whenever 

360
00:22:39,640 --> 00:22:43,120
there's like a big supply chain 
attack in the news and then 

361
00:22:43,120 --> 00:22:46,360
everybody's like, oh, it's it's 
the fault of open source. 

362
00:22:46,360 --> 00:22:51,400
Or like the, there's the, the 
XKCD comic with the, with the 

363
00:22:51,400 --> 00:22:55,240
guy in Nebraska maintaining his 
this project that that always 

364
00:22:55,240 --> 00:22:57,680
shows up. 
Yeah. 

365
00:22:58,200 --> 00:23:01,640
So I think like one, one of the 
the relatively recent big ones 

366
00:23:01,640 --> 00:23:04,200
was the ex Util's supply chain 
attack. 

367
00:23:05,000 --> 00:23:07,920
And I think it, it sort of 
turned out that one of the big 

368
00:23:07,920 --> 00:23:13,080
factors there was basically the 
fact that it was a nearly single

369
00:23:13,080 --> 00:23:18,600
maintainer project and the, the 
maintainer was very like burned 

370
00:23:18,600 --> 00:23:24,440
out, which was probably one of 
the factors that, that led to 

371
00:23:24,440 --> 00:23:26,800
the success of the, of the 
social engineering attack 

372
00:23:27,680 --> 00:23:29,920
against them. 
So I think like that, I think 

373
00:23:29,920 --> 00:23:33,040
that was, that was very 
interesting to us because of 

374
00:23:33,040 --> 00:23:35,680
like the human element of, of 
cybersecurity. 

375
00:23:37,480 --> 00:23:41,040
So we were curious like as, as 
someone who is an advocate for 

376
00:23:41,040 --> 00:23:45,880
open source and, and as as a 
chief open source officer, do 

377
00:23:45,880 --> 00:23:52,040
you think that those things are 
culturally solvable or do you 

378
00:23:52,040 --> 00:23:56,160
think we should be approaching 
them more from a monetary 

379
00:23:56,480 --> 00:24:00,120
perspective, from a, from an 
engineering perspective? 

380
00:24:00,120 --> 00:24:04,680
Like what sort of things do you 
think can be done to prevent the

381
00:24:04,680 --> 00:24:06,920
next supply chain attack like 
that? 

382
00:24:07,240 --> 00:24:10,160
You know, there's no getting 
away from the fact that humans 

383
00:24:10,160 --> 00:24:15,440
are flawed and prone to, you 
know, doing making mistakes. 

384
00:24:16,200 --> 00:24:18,880
I guess another example that's 
just come up in the last sort of

385
00:24:18,920 --> 00:24:23,600
week or so is this attack on, I 
don't know if it's got a name 

386
00:24:23,600 --> 00:24:31,280
yet, but it's, you know, the 
user sees a web page that looks 

387
00:24:31,280 --> 00:24:35,120
like it's Cloudflare and it 
basically says copy and paste 

388
00:24:35,120 --> 00:24:39,320
this command, execute it in the 
terminal. 

389
00:24:39,640 --> 00:24:42,840
And, you know, I know someone 
who knows someone who did 

390
00:24:42,960 --> 00:24:47,720
exactly that because they're 
sort of in a semi technical role

391
00:24:47,720 --> 00:24:50,320
and they're very used to people 
telling them what to run and 

392
00:24:50,320 --> 00:24:55,760
they don't necessarily always 
know exactly what command, you 

393
00:24:55,840 --> 00:24:58,920
know, and it looked legit. 
So they ran it and, you know, 

394
00:24:58,920 --> 00:25:02,640
terrifying things happen. 
It's human. 

395
00:25:04,160 --> 00:25:09,080
I think all we can do as a 
security industry is try to find

396
00:25:09,480 --> 00:25:13,320
tooling that can stop the if 
something is trying to 

397
00:25:13,360 --> 00:25:18,040
exfiltrate data, I think we're 
better off trying to catch that.

398
00:25:18,280 --> 00:25:21,760
It's going to be easier to 
identify here is suspicious 

399
00:25:21,760 --> 00:25:26,200
looking network traffic, here is
suspicious looking, you know, 

400
00:25:26,520 --> 00:25:33,320
executables running, rather than
to try and pretend that we're 

401
00:25:33,320 --> 00:25:37,320
going to be able to solve all 
human behavioural problems. 

402
00:25:37,680 --> 00:25:40,840
More a defence in depth approach
basically. 

403
00:25:40,840 --> 00:25:43,120
Exactly. 
A defence in depth approach. 

404
00:25:43,680 --> 00:25:48,680
You know, really if we can 
concentrate I think a bit more 

405
00:25:48,680 --> 00:25:52,040
on the sort of ultimate effect 
of the attack rather than 

406
00:25:52,040 --> 00:25:55,720
thinking that we're always going
to be able to prevent the 

407
00:25:55,720 --> 00:26:00,160
attack, the more we can really 
look at the, you know, does it 

408
00:26:00,160 --> 00:26:06,320
matter if malicious executable 
lands on my machine if that 

409
00:26:06,320 --> 00:26:09,360
cannot be executed, do. 
You think we should be 

410
00:26:09,480 --> 00:26:13,920
discouraging projects that have 
like a small amount of authors? 

411
00:26:13,920 --> 00:26:18,080
No, for lots of reasons. 
First of all, you know, just 

412
00:26:18,080 --> 00:26:23,000
because it's open source, you 
know, it means that people can 

413
00:26:23,000 --> 00:26:24,920
see it. 
But we have no idea what's 

414
00:26:24,920 --> 00:26:26,920
happening in the world 
proprietary software. 

415
00:26:27,240 --> 00:26:30,440
And just because a piece of code
is proprietary doesn't mean to 

416
00:26:30,440 --> 00:26:33,680
say that it's got any more 
people paying attention to it 

417
00:26:34,040 --> 00:26:39,320
than an an open source project. 
So I, I think the distinction 

418
00:26:39,320 --> 00:26:42,760
between open source and and 
proprietary is pretty spurious. 

419
00:26:42,760 --> 00:26:45,520
We just don't have the data 
about proprietary code in the 

420
00:26:45,520 --> 00:26:47,000
way that we do about open 
source. 

421
00:26:47,720 --> 00:26:51,360
Should we discourage projects 
that have small number of 

422
00:26:51,360 --> 00:26:52,880
maintainers? 
I would say absolutely not, 

423
00:26:52,880 --> 00:26:55,760
because how do people learn? 
How do people get stuff out 

424
00:26:55,760 --> 00:26:59,520
there? 
You know, one of the things that

425
00:26:59,520 --> 00:27:07,040
foundation owned projects try to
do is encourage there to be more

426
00:27:07,040 --> 00:27:08,960
people involved and and to 
encourage. 

427
00:27:09,040 --> 00:27:12,200
Like once it reaches, once it 
reaches, once it gets traction. 

428
00:27:12,640 --> 00:27:15,160
Exactly. 
And, and to encourage things 

429
00:27:15,160 --> 00:27:22,440
like providing A pathway for 
people to get involved in 

430
00:27:22,440 --> 00:27:25,960
projects, which, you know, a lot
of people when they're writing a

431
00:27:25,960 --> 00:27:28,920
piece of code, their main 
interest is solving a problem 

432
00:27:28,920 --> 00:27:33,000
with code and their, their main 
interest may not be teaching 

433
00:27:33,000 --> 00:27:34,280
other. 
People, enterprise support. 

434
00:27:34,600 --> 00:27:37,840
Project. 
Yes, definitely not support. 

435
00:27:39,240 --> 00:27:43,520
Another way to also start I 
think thinking about this is 

436
00:27:43,520 --> 00:27:47,520
looking at like incorporating AI
tooling into their work. 

437
00:27:49,080 --> 00:27:52,160
What are your thoughts on like 
vibe coding and AI assisted 

438
00:27:52,160 --> 00:27:55,480
coding in general I. 
Think this is a really fast 

439
00:27:55,480 --> 00:27:58,880
moving space and perhaps by the 
time this podcast has even gone 

440
00:27:58,880 --> 00:28:01,400
out it might have changed and my
opinion might have changed. 

441
00:28:01,760 --> 00:28:05,880
But I think there is some 
really, there is some really 

442
00:28:05,880 --> 00:28:12,680
useful AI assistants out there. 
So I don't want to dismiss it or

443
00:28:12,680 --> 00:28:14,760
imply that we shouldn't be using
it. 

444
00:28:15,160 --> 00:28:20,080
But we are also seeing a lot of 
AI slot contributions to open 

445
00:28:20,080 --> 00:28:24,800
source projects. 
There are far more contributions

446
00:28:24,800 --> 00:28:28,920
than I am happy with where 
somebody has basically picked an

447
00:28:28,920 --> 00:28:33,640
issue pointed and some kind of 
AI coding tool at it and it's 

448
00:28:33,640 --> 00:28:36,800
created something that looks 
plausible. 

449
00:28:36,800 --> 00:28:38,680
And it might actually be quite 
complicated. 

450
00:28:38,680 --> 00:28:40,600
There might be quite a lot of 
code to review. 

451
00:28:41,040 --> 00:28:46,400
There's typically some really 
beautifully documented PR, and 

452
00:28:46,400 --> 00:28:50,040
the problem is the person who's 
written written the code or used

453
00:28:50,120 --> 00:28:54,000
AI to write that code maybe 
doesn't actually understand 

454
00:28:54,000 --> 00:28:57,200
fully what it is that they're 
trying to contribute, and they 

455
00:28:57,200 --> 00:29:00,440
don't necessarily fully 
understand the consequences of 

456
00:29:00,440 --> 00:29:05,880
those changes. 
And they've created work for the

457
00:29:05,880 --> 00:29:08,040
maintainers of that project who 
have to review it. 

458
00:29:08,600 --> 00:29:12,760
It's work for them to push back 
to the contributor and say, you 

459
00:29:12,760 --> 00:29:15,480
know, why have you why have you 
done it like this? 

460
00:29:15,480 --> 00:29:18,680
Or did you consider that? 
Well, actually, they didn't 

461
00:29:18,680 --> 00:29:21,560
consider anything at all that AI
did all the considering. 

462
00:29:21,920 --> 00:29:25,720
And ultimately, I imagine that 
there will be a is doing a bit 

463
00:29:25,720 --> 00:29:30,280
of this sort of work between 
themselves and, and helping to 

464
00:29:30,280 --> 00:29:34,720
figure out whether something is 
worth committing or not at this 

465
00:29:34,720 --> 00:29:36,000
point. 
And this is where I'm really 

466
00:29:36,000 --> 00:29:38,280
very much in the, this is going 
to change really fast. 

467
00:29:38,280 --> 00:29:44,000
But I have seen some terrible, 
terrible, you know, PRS where 

468
00:29:44,000 --> 00:29:47,920
maybe AI has even written in a 
comment going, this is where the

469
00:29:47,920 --> 00:29:53,360
implementation would go. 
And the person making that 

470
00:29:53,360 --> 00:29:56,280
submission has not even spotted 
that comment. 

471
00:29:56,520 --> 00:30:00,640
And, you know, it's just 
overhead. 

472
00:30:00,640 --> 00:30:04,920
And one of the risks of this 
kind of AI contribution is 

473
00:30:04,920 --> 00:30:07,760
burning out maintainers who have
better things to do than 

474
00:30:07,760 --> 00:30:10,600
reviewing the work of AIS. 
First of all, listening to you 

475
00:30:10,600 --> 00:30:13,680
explain things, is it? 
You're so articulate and so good

476
00:30:13,680 --> 00:30:16,920
at explaining concepts that my 
next question is actually even 

477
00:30:16,920 --> 00:30:18,400
more relevant than when we 
wrote. 

478
00:30:19,960 --> 00:30:21,680
And it's about the books you've 
written. 

479
00:30:22,040 --> 00:30:26,400
And I think also it's also quite
on point because we're talking 

480
00:30:26,400 --> 00:30:27,920
about AI. 
That might change in a week. 

481
00:30:27,920 --> 00:30:30,240
And when you write a book, it's 
it's quite static. 

482
00:30:31,360 --> 00:30:35,600
Can you tell us what topics your
books do cover and how you kind 

483
00:30:35,600 --> 00:30:39,840
of keep them relevant in this 
very ever evolving landscape? 

484
00:30:40,400 --> 00:30:45,520
Yeah, so my container security 
book, I have just written the 

485
00:30:45,520 --> 00:30:48,160
second edition. 
It's going, it's in production 

486
00:30:48,160 --> 00:30:54,000
right now and it's about 5 years
since it was published. 

487
00:30:54,240 --> 00:31:00,200
When I wrote it, I was really 
very deliberate about trying to 

488
00:31:00,200 --> 00:31:04,000
talk about the concepts that I 
felt were pretty fundamental and

489
00:31:04,000 --> 00:31:08,000
that wouldn't change very much. 
You know, a container is a 

490
00:31:08,000 --> 00:31:09,280
container. 
It's going to be made of 

491
00:31:09,280 --> 00:31:13,680
namespaces. 
In that five years there is, you

492
00:31:13,680 --> 00:31:16,720
know, an extra namespace. 
So, you know, like the second 

493
00:31:16,720 --> 00:31:18,360
edition needed to talk about 
that. 

494
00:31:18,600 --> 00:31:22,360
The way that we do C groups, 
which is another sort of aspect 

495
00:31:22,400 --> 00:31:25,280
of containerisation has changed 
quite a lot. 

496
00:31:25,280 --> 00:31:30,200
So that was worth updating. 
The C groups still do the same 

497
00:31:30,200 --> 00:31:34,520
thing, which is kind of limiting
resources that are available to 

498
00:31:34,520 --> 00:31:39,360
a given container. 
So the concept was still, you 

499
00:31:39,360 --> 00:31:43,240
know, reasonably the same, but 
the actual examples needed to 

500
00:31:43,240 --> 00:31:46,560
change quite a lot for the the 
V2 implementation. 

501
00:31:46,880 --> 00:31:48,880
Loads of new things have been 
invented. 

502
00:31:48,880 --> 00:31:52,880
So, you know, five years ago, we
haven't really started talking 

503
00:31:52,880 --> 00:31:56,640
about supply chain security yet.
So that was a whole new thing 

504
00:31:56,640 --> 00:31:59,720
that I needed to bring in with. 
You know, there were things in 

505
00:31:59,720 --> 00:32:04,600
the CICD pipeline that related 
to what we ultimately called 

506
00:32:04,600 --> 00:32:08,240
supply chain security. 
But yeah, that's moved on a huge

507
00:32:08,240 --> 00:32:11,280
amount. 
I think there are lots of things

508
00:32:11,280 --> 00:32:17,040
in technology and in life that 
there's a concept that you can 

509
00:32:17,960 --> 00:32:22,480
grasp and then you can, you can 
map that into the future. 

510
00:32:22,840 --> 00:32:26,960
You know, the, as things evolve,
you can take that concept with 

511
00:32:26,960 --> 00:32:29,800
you and carry it forward. 
And it can be a useful mental 

512
00:32:29,800 --> 00:32:33,600
model, and doesn't always matter
if it's not precisely, you know,

513
00:32:33,600 --> 00:32:36,200
If the examples aren't precisely
right, that's not really the 

514
00:32:36,200 --> 00:32:39,280
point. 
Well, we will link to your books

515
00:32:39,280 --> 00:32:42,440
if our listeners would like to 
give them a look, which we 

516
00:32:42,440 --> 00:32:44,720
highly recommend. 
What a joy to have you on the 

517
00:32:44,720 --> 00:32:46,680
podcast. 
Thank you so much for coming. 

518
00:32:47,280 --> 00:32:49,280
Oh, it's delightful. 
Thank you for having me. 

519
00:32:49,800 --> 00:32:53,720
If you enjoyed the show, be sure
to subscribe and share a link to

520
00:32:53,720 --> 00:32:56,520
the podcast, but not your cloud 
keys. 

521
00:32:57,120 --> 00:33:00,200
And as always, your cloud 
security strategy is making you 

522
00:33:00,200 --> 00:33:02,960
cry. 
Don't worry, just cry out of 

523
00:33:02,960 --> 00:33:03,160
cloud.
