WEBVTT

00:00:03.840 --> 00:00:06.240
Welcome to the Azure Security Podcast, where

00:00:06.240 --> 00:00:08.779
we discuss topics relating to security, privacy,

00:00:09.039 --> 00:00:11.480
reliability, and compliance on the Microsoft

00:00:11.480 --> 00:00:16.519
Cloud Platform. Hey, everybody. Welcome to episode

00:00:16.519 --> 00:00:19.059
129. This week, it's myself, Michael, with Sarah.

00:00:19.420 --> 00:00:21.820
And our guest this week, probably has no introduction,

00:00:21.920 --> 00:00:24.500
but it's John Saville, here to talk about what's

00:00:24.500 --> 00:00:26.940
kind of top of mind for John. But before we get

00:00:26.940 --> 00:00:29.179
to our guest, let's take a little lap around

00:00:29.179 --> 00:00:31.140
the news. Sarah, why don't you kick things off?

00:00:31.579 --> 00:00:33.969
Well, I... I'm going to do the really obvious

00:00:33.969 --> 00:00:37.170
news, well, for the time we're recording for

00:00:37.170 --> 00:00:39.829
me, which is last week it was Microsoft Build.

00:00:40.609 --> 00:00:43.829
You may have seen this person's face in the keynote.

00:00:43.850 --> 00:00:46.210
If you didn't, obviously you should go and watch

00:00:46.210 --> 00:00:50.149
that. But in all seriousness, I was showing MDash,

00:00:50.250 --> 00:00:53.450
which we're hoping to have an episode on soon,

00:00:53.549 --> 00:00:55.770
actually, if I can grab one of them. They're

00:00:55.770 --> 00:00:59.310
just very busy at the moment. MDash is our code

00:00:59.310 --> 00:01:03.100
scanning. harness it's very cool it's currently

00:01:03.100 --> 00:01:04.900
in a private preview when we're recording this

00:01:04.900 --> 00:01:07.680
but you can sign up and request access keep an

00:01:07.680 --> 00:01:10.609
eye out it will go public preview in GA hopefully

00:01:10.609 --> 00:01:12.909
in the not too distant future. There were also

00:01:12.909 --> 00:01:15.590
some other sessions at Build around managing

00:01:15.590 --> 00:01:18.689
your agent estate with Agent 365, which obviously

00:01:18.689 --> 00:01:21.250
has a security aspect. So all the sessions are

00:01:21.250 --> 00:01:24.670
now up on YouTube. So if you were not there,

00:01:24.709 --> 00:01:26.709
if you weren't lucky enough to go to Build, you

00:01:26.709 --> 00:01:29.430
should go check those out because they're all

00:01:29.430 --> 00:01:32.349
online now. That's it for me this time, Michael.

00:01:33.430 --> 00:01:36.109
And make sure everyone spots the little Easter

00:01:36.109 --> 00:01:39.239
eggs about your dogs, right? Ah, yes. Yes. Okay.

00:01:39.299 --> 00:01:43.180
So if you watch my demo, the M -Dash demo, see

00:01:43.180 --> 00:01:45.980
if you can see the Easter eggs for my dogs and

00:01:45.980 --> 00:01:49.920
my shadow demoer's daughter. There are some Easter

00:01:49.920 --> 00:01:52.560
eggs for her too, because that's what we do.

00:01:53.180 --> 00:01:55.500
Well, some benign Easter eggs in the corner.

00:01:56.219 --> 00:01:58.099
I always add Easter eggs to things like that,

00:01:58.140 --> 00:02:00.040
always. Just little subtle things. Oh, you have

00:02:00.040 --> 00:02:03.579
to. Yeah, you have to. You have to. As long as

00:02:03.579 --> 00:02:05.680
it doesn't, it's only in the corner. And there

00:02:05.680 --> 00:02:07.819
were a few people who found them unprompted.

00:02:07.819 --> 00:02:10.020
They were like, Team Grayson. And I was like,

00:02:10.099 --> 00:02:13.360
yeah, of course. Like, Team Grayson. And they

00:02:13.360 --> 00:02:14.919
were like, Sarah, you put your dogs in your demo.

00:02:15.080 --> 00:02:17.599
I was like, of course I did. Like, what kind

00:02:17.599 --> 00:02:19.840
of a question? Of course I did. If I can, I will.

00:02:20.699 --> 00:02:23.960
All right. So as to my news, first of all, I

00:02:23.960 --> 00:02:26.259
have a new book coming out. It will be available

00:02:26.259 --> 00:02:29.319
about the first or second week of July this year.

00:02:29.740 --> 00:02:32.379
It is called Threat Driven Software Development.

00:02:32.919 --> 00:02:35.120
I've talked a little bit about this in the past

00:02:35.120 --> 00:02:37.639
on the podcast, or at least hinted at it. It's

00:02:37.639 --> 00:02:39.139
quite different to other books that I've written.

00:02:39.240 --> 00:02:42.039
It still focuses on software engineering and

00:02:42.039 --> 00:02:44.699
software security and so on, but it pulls in

00:02:44.699 --> 00:02:46.919
information at Microsoft around the Secure Future

00:02:46.919 --> 00:02:49.419
Initiative, as well as... Microsoft Security

00:02:49.419 --> 00:02:52.879
Development Lifecycle, or the SDL. However, every

00:02:52.879 --> 00:02:56.379
chapter looks at whatever the topic is through

00:02:56.379 --> 00:02:59.860
the lens of threat intel. So one of the co -authors

00:02:59.860 --> 00:03:02.340
we've had on this podcast before is Sherrod DeGrippo.

00:03:03.069 --> 00:03:05.849
And she wrote some flavor text at the start of

00:03:05.849 --> 00:03:08.030
every chapter called the Threat Intel Perspective.

00:03:08.129 --> 00:03:11.650
Then after that, the three of us, myself and

00:03:11.650 --> 00:03:14.969
Sean Hernan and Lee Holmes, would then go and

00:03:14.969 --> 00:03:17.569
write the actual technical content. Sherrod also

00:03:17.569 --> 00:03:20.189
has a chapter on Threat Intel, like modern Threat

00:03:20.189 --> 00:03:22.169
Intel, right at the very beginning, again, to

00:03:22.169 --> 00:03:25.159
really set the tone of the book. The other two

00:03:25.159 --> 00:03:27.479
news items that I have, both of them are to do

00:03:27.479 --> 00:03:29.500
with post -quantum cryptography. The first one

00:03:29.500 --> 00:03:32.379
is that Azure SQL Database now supports transparent

00:03:32.379 --> 00:03:35.680
data encryption, AES wrapping keys using managed

00:03:35.680 --> 00:03:39.189
HSM, as you're probably well aware. In a post

00:03:39.189 --> 00:03:41.409
-quantum world, RSA and elliptic curve become

00:03:41.409 --> 00:03:43.729
essentially destroyed. And we now have to look

00:03:43.729 --> 00:03:46.150
for alternate methods. And the symmetric way

00:03:46.150 --> 00:03:48.469
of doing that is to use AES key wrapping. So

00:03:48.469 --> 00:03:50.490
that's available. There's also an asymmetric

00:03:50.490 --> 00:03:53.009
way of doing it, MLChem, but that's not available

00:03:53.009 --> 00:03:55.189
just yet. So yeah, AES key wrapping is available

00:03:55.189 --> 00:03:58.150
in managed HSM. The other one, which is really

00:03:58.150 --> 00:04:01.349
cool, this came out at Build, is that we've now

00:04:01.349 --> 00:04:04.169
got a version of S -channel in Windows, Windows

00:04:04.169 --> 00:04:09.610
11. that supports MLChem on TLS 1 .3. So MLChem,

00:04:09.650 --> 00:04:11.650
if you listen to our last podcast that I did

00:04:11.650 --> 00:04:15.110
with Jack Richens, was on MLChem. Well, all sorts

00:04:15.110 --> 00:04:16.790
of post -quantum stuff, but MLChem was the big

00:04:16.790 --> 00:04:18.449
one, which is the key encapsulation mechanism

00:04:18.449 --> 00:04:22.550
that is now available in Windows 11. You have

00:04:22.550 --> 00:04:25.810
to enable it, though. So you have to call set

00:04:25.810 --> 00:04:32.240
TLS ECC curve and then the actual hybrid. group,

00:04:32.240 --> 00:04:34.019
and that will then turn it back on. So I'm going

00:04:34.019 --> 00:04:35.720
to write a blog post on this in the next few

00:04:35.720 --> 00:04:37.319
weeks. But yeah, it's great to see that it's

00:04:37.319 --> 00:04:39.800
available now in Windows 11, and eventually will

00:04:39.800 --> 00:04:41.980
be in Windows Server as well. So a couple of

00:04:41.980 --> 00:04:43.420
post -quantum announcements there. There's a

00:04:43.420 --> 00:04:46.160
lot of headway being made by Microsoft, and it's

00:04:46.160 --> 00:04:48.279
good to see these things coming out. All right,

00:04:48.399 --> 00:04:49.939
let's turn our attention to our guest. As I mentioned

00:04:49.939 --> 00:04:51.920
at the top, our guest this week needs absolutely

00:04:51.920 --> 00:04:56.279
zero introduction, but it is John Saville. John,

00:04:56.360 --> 00:04:58.060
welcome to the podcast. We'd like to take a moment

00:04:58.060 --> 00:05:01.040
and introduce yourself to our listeners. Thank

00:05:01.040 --> 00:05:03.540
you. Firstly, thrilled to be on the show. And

00:05:03.540 --> 00:05:05.620
it's nice to talk to you both. A bit intimidating

00:05:05.620 --> 00:05:10.120
talking to both of you. But I've been a Microsoft

00:05:10.120 --> 00:05:13.000
fan, I guess, since I was 18. Like I've been

00:05:13.000 --> 00:05:15.639
doing this stuff for over 30 years now. It was

00:05:15.639 --> 00:05:18.939
a hobby and I was lucky enough that my hobby

00:05:18.939 --> 00:05:22.259
turned into a job. But my current role is I'm

00:05:22.259 --> 00:05:24.420
the CTO for America's Markets and Industries.

00:05:24.699 --> 00:05:27.040
But I think if anyone does know me, they know

00:05:27.040 --> 00:05:28.930
me because of the YouTube channel. I've been

00:05:28.930 --> 00:05:31.689
sort of focused on that for maybe like seven

00:05:31.689 --> 00:05:34.850
or eight years now. And just, it's my way of

00:05:34.850 --> 00:05:37.569
learning and my way of trying to help other people

00:05:37.569 --> 00:05:40.230
like give back. And so it's just a lot of fun

00:05:40.230 --> 00:05:43.610
creating content to help people understand something.

00:05:43.810 --> 00:05:45.230
Because I think if you understand something,

00:05:45.370 --> 00:05:47.430
you're not scared of it anymore. And if you're

00:05:47.430 --> 00:05:48.949
not scared of it, you'll go and use it and take

00:05:48.949 --> 00:05:51.790
advantage of it. So that's just something I enjoy

00:05:51.790 --> 00:05:54.009
doing. I think it's more than that, though. I

00:05:54.009 --> 00:05:57.129
mean, the number of... people who have asked

00:05:57.129 --> 00:05:59.089
a question and my response is always, well, just

00:05:59.089 --> 00:06:01.750
go and watch one of John's videos. It's 15 minutes,

00:06:02.009 --> 00:06:05.670
20 minutes, and I'll answer the questions. I

00:06:05.670 --> 00:06:08.629
love the format of your videos in front of the

00:06:08.629 --> 00:06:11.490
electronic whiteboard, diagramming things out.

00:06:11.689 --> 00:06:15.250
And there's something that really irks me, not

00:06:15.250 --> 00:06:16.910
about you, there's something that really irks

00:06:16.910 --> 00:06:18.889
me about people who do technical presentations,

00:06:18.970 --> 00:06:22.290
and that is they assume the people watching you

00:06:22.290 --> 00:06:25.959
know a whole bunch of stuff. And you go at it

00:06:25.959 --> 00:06:28.279
as an angle of assuming that people don't know

00:06:28.279 --> 00:06:32.319
what you're about to talk about. And look, don't

00:06:32.319 --> 00:06:34.560
get me wrong. People who know this stuff, can

00:06:34.560 --> 00:06:37.319
John just like, just get, just get to the concept

00:06:37.319 --> 00:06:41.699
of the point, you know, but the other 97 % are

00:06:41.699 --> 00:06:43.879
like, thank you for explaining that stuff to

00:06:43.879 --> 00:06:46.660
me. Right. Because you've got to build upon baseline

00:06:46.660 --> 00:06:48.480
knowledge. Right. So I love your videos. I think

00:06:48.480 --> 00:06:50.879
they're awesome. And the benefit I have is I'm

00:06:50.879 --> 00:06:53.410
not that smart. And so it works out really well

00:06:53.410 --> 00:06:56.050
for me. So I have to try and how did I understand

00:06:56.050 --> 00:06:58.889
it? And then I try and like replay the steps

00:06:58.889 --> 00:07:00.649
and the layers of knowledge I had to do to get

00:07:00.649 --> 00:07:03.189
there. So it's very natural for me to do it that

00:07:03.189 --> 00:07:06.819
way. So, John, I've had an actual conversation

00:07:06.819 --> 00:07:09.879
where someone said to do this, you would need

00:07:09.879 --> 00:07:13.660
John Saville level knowledge. So you've actually

00:07:13.660 --> 00:07:18.220
become like a rating of knowledge. Now, what

00:07:18.220 --> 00:07:20.019
they were saying, though, it was a very low level

00:07:20.019 --> 00:07:22.100
of knowledge. You're interpreting it the wrong

00:07:22.100 --> 00:07:25.480
way. It was just a John Saville level of knowledge

00:07:25.480 --> 00:07:27.240
to get this one. So I want to ask you an honest

00:07:27.240 --> 00:07:30.160
question of you. Honest question. How much do

00:07:30.160 --> 00:07:33.600
you learn? preparing for the videos because whenever

00:07:33.600 --> 00:07:36.379
i write write anything whether it's a blog post

00:07:36.379 --> 00:07:39.879
whether it's a book i learn a lot researching

00:07:39.879 --> 00:07:42.620
to be able to put it into into some form that

00:07:42.620 --> 00:07:45.459
can be understood by more people so do you learn

00:07:45.459 --> 00:07:48.300
a lot while you're doing the videos oh i do no

00:07:48.300 --> 00:07:50.920
i mean so i mean what i said is very true like

00:07:50.920 --> 00:07:52.860
part of the content is yes i create stuff because

00:07:52.860 --> 00:07:54.899
i want to help people like to me it's my way

00:07:54.899 --> 00:07:56.480
of giving back a little bit it's why i don't

00:07:56.480 --> 00:07:59.339
monetize the channel but I learned a phenomenal

00:07:59.339 --> 00:08:01.339
amount because if you want to explain something

00:08:01.339 --> 00:08:03.279
to someone and if you want to be able to explain

00:08:03.279 --> 00:08:06.240
it in a way they can digest, you have to really

00:08:06.240 --> 00:08:08.779
understand it. You have to go to a level of understanding

00:08:08.779 --> 00:08:11.980
way beyond what you're actually teaching so you

00:08:11.980 --> 00:08:14.319
can try and frame it the right way so someone

00:08:14.319 --> 00:08:16.319
can take the concept and do something useful

00:08:16.319 --> 00:08:20.319
with it. So no, I do not know most of what I

00:08:20.319 --> 00:08:22.600
cover at the start. I have to go and learn it

00:08:22.600 --> 00:08:25.060
and play with it and break the thing. And then,

00:08:25.139 --> 00:08:27.920
yeah, I learned a massive amount doing the videos.

00:08:28.319 --> 00:08:30.160
Do you find bugs along the way? I always find

00:08:30.160 --> 00:08:32.440
bugs. I have found bugs along the way. It's funny,

00:08:32.519 --> 00:08:34.139
especially funny enough with some of the Entra

00:08:34.139 --> 00:08:37.279
stuff. A lot of, I do stuff early on with the

00:08:37.279 --> 00:08:39.500
Entra things. And then other times I've found

00:08:39.500 --> 00:08:41.580
sites like, this is not working right. It's like,

00:08:41.679 --> 00:08:44.320
oh yeah, don't mention that. And then they'll

00:08:44.320 --> 00:08:46.179
go and we'll work on that. It'll be fixed by

00:08:46.179 --> 00:08:49.440
the time you release. Okay. All right. So let's

00:08:49.440 --> 00:08:51.220
get stuck into the actual content. Now we're

00:08:51.220 --> 00:08:53.080
talking about your YouTube channel, which by

00:08:53.080 --> 00:08:54.480
the way, we will put a link in the show notes.

00:08:55.670 --> 00:08:59.830
If no one's ever heard of it. Yeah, right. So

00:08:59.830 --> 00:09:03.169
the topic of this episode is John Saville's top

00:09:03.169 --> 00:09:06.029
of mind. So let's just start with, I want to

00:09:06.029 --> 00:09:08.090
tell everyone, by the way, we really don't have

00:09:08.090 --> 00:09:10.049
an agenda. We're just going to talk about stuff.

00:09:10.450 --> 00:09:13.750
So let's see how this goes. So let's just go,

00:09:13.769 --> 00:09:16.110
let's start off with, you know, what's top of

00:09:16.110 --> 00:09:17.470
mind? Like what are customers talking to you

00:09:17.470 --> 00:09:20.200
about? What sort of, you know, is really... sort

00:09:20.200 --> 00:09:22.000
of bugging you right now? What's, you know, what,

00:09:22.039 --> 00:09:24.159
what things are changing that are of real interest

00:09:24.159 --> 00:09:25.679
to you? You know, so what's really, what really

00:09:25.679 --> 00:09:28.899
is number one top of mind right now? Yeah. I

00:09:28.899 --> 00:09:30.759
mean, what's interesting about when, so my role

00:09:30.759 --> 00:09:33.299
changed beginning of the year and I have a lot

00:09:33.299 --> 00:09:35.799
more customer conversations now with like the

00:09:35.799 --> 00:09:38.419
leadership and what's concerning to them. And

00:09:38.419 --> 00:09:41.019
obviously as you would expect, AI is kind of

00:09:41.019 --> 00:09:44.299
on every conversation we ever do. But what is

00:09:44.299 --> 00:09:48.059
really interesting, it's not just AI, it's about

00:09:48.059 --> 00:09:52.740
trusting. what AI is doing. And so we've moved

00:09:52.740 --> 00:09:56.620
into this new shift in thinking that in the past

00:09:56.620 --> 00:09:59.620
with software, hey, we had test harnesses, we

00:09:59.620 --> 00:10:02.840
had test scripts, input A, do we get output B?

00:10:02.940 --> 00:10:05.460
We're good. Like it doesn't work with AI because

00:10:05.460 --> 00:10:07.620
suddenly it's this creative thing. And this non

00:10:07.620 --> 00:10:11.299
-deterministic nature is massively concerning

00:10:11.299 --> 00:10:15.899
to every customer because there's the element

00:10:15.899 --> 00:10:19.690
of security and AI introduces a whole new set

00:10:19.690 --> 00:10:22.350
of security concerns. Like, yes, all the other

00:10:22.350 --> 00:10:24.909
stuff we always think about still applies, but

00:10:24.909 --> 00:10:28.730
now you have the prompt injections and the jailbreaking

00:10:28.730 --> 00:10:31.169
and the hallucinations and the reasoning faults

00:10:31.169 --> 00:10:34.110
and all these other things. But they're super

00:10:34.110 --> 00:10:37.009
concerned about trusting what the thing is actually

00:10:37.009 --> 00:10:40.750
outputting. And that is something that we're

00:10:40.750 --> 00:10:42.629
constantly trying to help the customers understand

00:10:42.629 --> 00:10:45.429
in terms of how do you trust what this creative

00:10:46.670 --> 00:10:49.970
intelligence is generating, but also making sure

00:10:49.970 --> 00:10:52.210
it's staying within what you need it to stay

00:10:52.210 --> 00:10:55.929
within in terms of security policies and other

00:10:55.929 --> 00:10:59.950
guardrails. So that is the number one thing that's

00:10:59.950 --> 00:11:03.610
keeping customers up right now is how do we control

00:11:03.610 --> 00:11:07.940
this AI thing? And that is great for me to be

00:11:07.940 --> 00:11:10.620
on this show is like, I know what I think about.

00:11:10.759 --> 00:11:13.940
And I know we talk about evaluations and we talk

00:11:13.940 --> 00:11:16.320
about governance and we talk about permissions.

00:11:16.399 --> 00:11:19.259
But like, what do you see? I mean, that's kind

00:11:19.259 --> 00:11:22.200
of interesting to me is like, how do you answer

00:11:22.200 --> 00:11:24.659
that question with customers? Like, hey, how

00:11:24.659 --> 00:11:30.519
do you trust the agents? I don't. And that's

00:11:30.519 --> 00:11:33.980
why you have to have things like least privilege.

00:11:34.509 --> 00:11:36.210
And that's why you have to have a whole bunch

00:11:36.210 --> 00:11:38.710
of other guardrails in place, assuming that the

00:11:38.710 --> 00:11:41.190
AI is going to go all wonky. I don't. I mean,

00:11:41.210 --> 00:11:43.889
I think if you look at some of the very earliest

00:11:43.889 --> 00:11:47.049
incarnations of OpenCore, you know, people were

00:11:47.049 --> 00:11:49.129
just running it without regard for any security

00:11:49.129 --> 00:11:51.830
boundaries, any guardrails whatsoever. And, you

00:11:51.830 --> 00:11:53.610
know, it got a bad name for itself, right? Because

00:11:53.610 --> 00:11:55.389
it could do anything. Well, if it's running as

00:11:55.389 --> 00:11:57.690
you with no other guardrails in place, then sure,

00:11:57.850 --> 00:11:59.850
then it matured, you know, and then we saw changes

00:11:59.850 --> 00:12:02.679
and so on and so forth. I don't trust it. I don't

00:12:02.679 --> 00:12:04.059
trust it at all. I don't mean that in a really

00:12:04.059 --> 00:12:06.480
cynical way. Perhaps I'm just too old to trust

00:12:06.480 --> 00:12:09.360
input of any kind. It's just an input problem,

00:12:09.580 --> 00:12:11.799
again. It's actually harder than that, right?

00:12:11.860 --> 00:12:14.000
Because in the old days, with SQL injection,

00:12:14.200 --> 00:12:16.279
for example, we know how to mitigate that with

00:12:16.279 --> 00:12:19.340
parameterized queries. But with prompt injection,

00:12:19.700 --> 00:12:22.000
it's not as easy as that. There is no single

00:12:22.000 --> 00:12:25.039
solution to validate the input. Don't get me

00:12:25.039 --> 00:12:27.080
wrong, we have a whole bunch of guardrails that

00:12:27.080 --> 00:12:30.289
can take the input and check. you know, if it

00:12:30.289 --> 00:12:33.049
thinks it's good or bad, but even then you don't

00:12:33.049 --> 00:12:35.649
really know using AI to, to, to check AI. And

00:12:35.649 --> 00:12:38.730
so that's why I just run absolutely everything,

00:12:38.789 --> 00:12:40.570
you know, least privilege and a whole bunch of

00:12:40.570 --> 00:12:42.850
other guardrails read only where possible as

00:12:42.850 --> 00:12:45.570
opposed to read, right. Which is just least privilege.

00:12:45.970 --> 00:12:47.850
You know, that's where things like low, you know,

00:12:47.850 --> 00:12:51.149
identities come into play as well. Well, I think

00:12:51.149 --> 00:12:52.570
that's, I mean, that's the super interesting

00:12:52.570 --> 00:12:54.950
thing. I think initially with the AI people just

00:12:54.950 --> 00:12:58.450
like, Oh, great, it's intelligent, you do all

00:12:58.450 --> 00:13:00.570
these things, you give it all this access. And

00:13:00.570 --> 00:13:03.210
I think they forgot about a lot of kind of the

00:13:03.210 --> 00:13:06.889
zero trust and the defense in depth. And I think

00:13:06.889 --> 00:13:08.710
a lot of companies are coming back to that now,

00:13:08.789 --> 00:13:10.990
which is why suddenly companies care, to your

00:13:10.990 --> 00:13:14.429
word, the identity. It isn't just, hey, it should

00:13:14.429 --> 00:13:16.529
always just run with my permissions. And if we

00:13:16.529 --> 00:13:19.710
think about autonomous agents and AI teammates

00:13:19.710 --> 00:13:24.370
as we go in the future, the identity is also

00:13:24.370 --> 00:13:27.450
saying that, everyone is talking about and what

00:13:27.450 --> 00:13:29.690
is the right way of doing it and how you secure

00:13:29.690 --> 00:13:31.990
it. And that's one of the things I enjoy talking

00:13:31.990 --> 00:13:34.450
about. So identity has always been a passion

00:13:34.450 --> 00:13:37.649
of mine. Like I loved the, I was an AD guy and

00:13:37.649 --> 00:13:39.990
then what was the Azure ID and the Entra ID.

00:13:40.669 --> 00:13:44.610
But I like the agent ID and the agent user ID

00:13:44.610 --> 00:13:48.750
stuff because to me, it's supernatural. Like

00:13:48.750 --> 00:13:53.649
if you think of humans, And we're used to the

00:13:53.649 --> 00:13:55.870
idea of we're given the mentor identities and

00:13:55.870 --> 00:13:57.950
we have conditional access and we have the risk

00:13:57.950 --> 00:14:00.950
detections. And we've built up a pretty strong

00:14:00.950 --> 00:14:03.309
set of capabilities and we understand it. Like

00:14:03.309 --> 00:14:06.289
companies understand it. So I don't understand

00:14:06.289 --> 00:14:09.049
why you'd want to do something different for

00:14:09.049 --> 00:14:12.230
agents, which fundamentally are going to be doing

00:14:12.230 --> 00:14:15.350
a very similar thing to humans. And so why recreate

00:14:15.350 --> 00:14:18.549
a wheel? To me, it makes a lot more sense that

00:14:18.549 --> 00:14:20.990
you've got something you trust in already. You've

00:14:20.990 --> 00:14:23.330
got skills around. You just have to tweak it

00:14:23.330 --> 00:14:27.289
a little bit. Like Sarah, if Sarah works 24 -7,

00:14:27.490 --> 00:14:32.009
I'll be suspicious. If Sarah downloads 500 documents

00:14:32.009 --> 00:14:35.529
in a minute, I'll be suspicious. But hey, we

00:14:35.529 --> 00:14:37.529
just tweak the behavior of what we expect a little

00:14:37.529 --> 00:14:40.149
bit. And I think we can take the same solution.

00:14:41.600 --> 00:14:43.259
Obviously, I'm a Microsoft person. I've always

00:14:43.259 --> 00:14:46.519
been a Microsoft fan, but I genuinely like the

00:14:46.519 --> 00:14:49.100
approach of just extending what we're doing with

00:14:49.100 --> 00:14:52.919
Entra to agents, extending what we do with Purview

00:14:52.919 --> 00:14:57.480
to agents. To me, it makes a lot of sense for

00:14:57.480 --> 00:15:01.440
the organization. I think one of the things that

00:15:01.440 --> 00:15:04.840
is very obvious to me having conversations with

00:15:04.840 --> 00:15:08.460
folks, though, is that obviously with Purview

00:15:08.460 --> 00:15:11.019
and Entra, we've had all this stuff. a lot of

00:15:11.019 --> 00:15:13.759
these controls in the non -agentic, non -AI field

00:15:13.759 --> 00:15:16.700
for a while, but people haven't always done them

00:15:16.700 --> 00:15:19.399
super well because they're difficult and they

00:15:19.399 --> 00:15:22.299
take a while. And so now what I find is one of

00:15:22.299 --> 00:15:24.120
the biggest things, which I think is a good thing,

00:15:24.179 --> 00:15:27.139
is that a lot of folks are... particularly with

00:15:27.139 --> 00:15:29.059
data security, because I feel like data security

00:15:29.059 --> 00:15:30.820
was always something people were just like, ah,

00:15:30.879 --> 00:15:32.240
we'll get back to that. We'll get back to that.

00:15:32.360 --> 00:15:34.539
Like, you know, we're going to label it later.

00:15:34.679 --> 00:15:37.139
It's too big a job. Now people are realizing

00:15:37.139 --> 00:15:40.379
that they can't really, well, they can do AI

00:15:40.379 --> 00:15:44.440
without doing it, but it increases the risk because

00:15:44.830 --> 00:15:47.870
AI is really good at finding data that you shouldn't

00:15:47.870 --> 00:15:49.789
have access to and haven't protected way more

00:15:49.789 --> 00:15:53.610
than human manually. And suddenly people are

00:15:53.610 --> 00:15:55.450
like putting more focus on stuff that's been

00:15:55.450 --> 00:15:57.750
kicked. The can's been kicked down the road for

00:15:57.750 --> 00:16:00.529
years, which I think is a good thing. I know

00:16:00.529 --> 00:16:03.289
it adds more stuff on people's plates to do,

00:16:03.450 --> 00:16:06.129
but I think long -term will be a good thing.

00:16:06.230 --> 00:16:08.009
I don't know. What do you think, John? You've

00:16:08.009 --> 00:16:11.159
talked to way more customers than me. So it sounds

00:16:11.159 --> 00:16:13.059
like you're saying security through obscurity

00:16:13.059 --> 00:16:15.740
is not a good corporate strategy. I don't know.

00:16:15.840 --> 00:16:19.600
It sounds like that's not the answer. No, it

00:16:19.600 --> 00:16:24.120
might not be. No, I mean, you're right. It comes

00:16:24.120 --> 00:16:27.460
up every time because with AI, we've kind of

00:16:27.460 --> 00:16:30.779
accepted now, I think, the fact that... the quality

00:16:30.779 --> 00:16:33.000
of the data drives the quality of the outcome.

00:16:33.299 --> 00:16:35.259
Like we used to have garbage in, garbage out.

00:16:35.340 --> 00:16:38.120
With AI, it's the garbage in, colorful different

00:16:38.120 --> 00:16:41.480
shapes of garbage, but it's garbage all the same.

00:16:41.779 --> 00:16:44.960
And so suddenly every company, to your point,

00:16:45.039 --> 00:16:48.139
is putting a semantic index over their corporate

00:16:48.139 --> 00:16:51.480
sort of data structures. So suddenly I can find

00:16:51.480 --> 00:16:54.120
everything. And so those over permission sites,

00:16:54.559 --> 00:16:56.539
those, all those things suddenly get found out.

00:16:57.240 --> 00:16:59.759
But also, if they want a really good AI application,

00:17:00.220 --> 00:17:02.259
it has to be able to talk to all of the data.

00:17:02.639 --> 00:17:05.400
And so suddenly they're putting these data virtualization

00:17:05.400 --> 00:17:08.319
layers in their company that they either shortcut

00:17:08.319 --> 00:17:11.279
or mirror, but everything is suddenly available,

00:17:11.559 --> 00:17:15.180
which is great for the AI to work. But it's actually

00:17:15.180 --> 00:17:17.640
an opportunity for the company to suddenly get

00:17:17.640 --> 00:17:21.200
a handle on the data because for once, there's

00:17:21.200 --> 00:17:24.289
now an endpoint. that the data governance can

00:17:24.289 --> 00:17:27.410
talk to. So suddenly I can find the stuff, I

00:17:27.410 --> 00:17:30.009
can classify the stuff and I can protect it.

00:17:30.289 --> 00:17:32.490
Whereas in the past, it was just all siloed.

00:17:32.490 --> 00:17:36.089
So I think to your point, AI has introduced a

00:17:36.089 --> 00:17:38.789
new problem and surfaced. It's not a new problem.

00:17:38.890 --> 00:17:40.569
It's surfaced a problem that's been there for

00:17:40.569 --> 00:17:43.609
a really long time. But fortunately, the technologies

00:17:43.609 --> 00:17:46.369
we have to put in place to make AI work like

00:17:46.369 --> 00:17:49.230
that data virtualization layer is also the way

00:17:49.230 --> 00:17:51.200
we can kind of solve it. because suddenly the

00:17:51.200 --> 00:17:54.240
data governance can see all the data and actually

00:17:54.240 --> 00:17:58.200
start to protect it. So yes, it's a whole new

00:17:58.200 --> 00:18:00.599
set of problems, but it's a problem that had

00:18:00.599 --> 00:18:03.380
to be solved anyway. So I don't know. I think

00:18:03.380 --> 00:18:05.200
it's a good thing in the end that it'll actually

00:18:05.200 --> 00:18:07.359
get fixed and then it fixes it for the humans

00:18:07.359 --> 00:18:10.359
as well. I have a take on the obscurity thing.

00:18:10.960 --> 00:18:14.079
I don't mind security through obscurity as long

00:18:14.079 --> 00:18:17.180
as it's not your only defense. That's, you know,

00:18:17.200 --> 00:18:20.309
slowing an attacker down is fine. But yes, it

00:18:20.309 --> 00:18:23.130
can't just be your only defense. That's my take

00:18:23.130 --> 00:18:25.130
on it. Well, I guess we found it was the only

00:18:25.130 --> 00:18:27.049
solution for some companies because it was just

00:18:27.049 --> 00:18:28.910
as soon as it found it, it's like, hey, I can

00:18:28.910 --> 00:18:31.069
read everything. Absolutely, absolutely. Not

00:18:31.069 --> 00:18:34.390
the best day. So John, what is next on your hit

00:18:34.390 --> 00:18:37.769
list of things that are top of mind for customers?

00:18:38.230 --> 00:18:40.529
I don't know if it's always top of mind for customers,

00:18:40.609 --> 00:18:42.809
but it's something that always comes up as something

00:18:42.809 --> 00:18:46.009
they should be doing. And it's that fundamental,

00:18:46.309 --> 00:18:48.549
like we talked about least privilege. And one

00:18:48.549 --> 00:18:51.309
of the huge challenges I think people still struggle

00:18:51.309 --> 00:18:54.509
with is just that authentication and strong authentication.

00:18:55.170 --> 00:18:58.950
And I think Passkeys, like I'm a big fan of the

00:18:58.950 --> 00:19:02.170
Passkeys. I just did a video on now we have Passkey

00:19:02.170 --> 00:19:04.549
registration campaigns that we've kind of got

00:19:04.549 --> 00:19:09.170
in Entry ID. And I would love to see like a greater

00:19:09.170 --> 00:19:13.150
adoption of Passkeys because I think for the

00:19:13.150 --> 00:19:17.589
average user, It adds so much protection for

00:19:17.589 --> 00:19:20.890
them. Like, to me, the two biggest things is,

00:19:20.930 --> 00:19:23.210
yes, they're technically easy to use. And yes,

00:19:23.230 --> 00:19:25.930
it's a strong auth. But the proximity element

00:19:25.930 --> 00:19:28.509
of it to stop people getting tricked to go and

00:19:28.509 --> 00:19:30.430
authenticate some bad actors. Like, hey, I'm

00:19:30.430 --> 00:19:32.609
the help desk. Just going to check this. Give

00:19:32.609 --> 00:19:34.930
me your code. And then the fact that it will

00:19:34.930 --> 00:19:37.690
only work against the legitimate domain that

00:19:37.690 --> 00:19:40.750
it was given for. So I can't be tricked to do

00:19:40.750 --> 00:19:44.720
something slightly similar. To me, I really think

00:19:44.720 --> 00:19:48.559
there needs to be a great push on getting these

00:19:48.559 --> 00:19:51.740
passkeys adopted. And I know we've sort of recently

00:19:51.740 --> 00:19:53.960
added support for the synced passkeys now within

00:19:53.960 --> 00:19:57.359
the ecosystem. So, hey, I can put it in my iCloud

00:19:57.359 --> 00:20:00.759
keychain or the Google password manager. And

00:20:00.759 --> 00:20:03.579
I know that terrifies some sort of corporate

00:20:03.579 --> 00:20:07.740
identity, sort of people that the key is now

00:20:07.740 --> 00:20:11.789
not in a place. That key is now... floating.

00:20:11.890 --> 00:20:13.970
And one of the things we talk about is, well,

00:20:14.029 --> 00:20:15.210
with conditional access instead of applying,

00:20:15.630 --> 00:20:18.849
I could still lock down the use to be a sort

00:20:18.849 --> 00:20:22.509
of a healthy device, the managed device. I don't

00:20:22.509 --> 00:20:24.849
know what you see. So like from a passkey perspective,

00:20:24.950 --> 00:20:26.789
again, I'm trying to learn from you guys on this

00:20:26.789 --> 00:20:30.509
call. Like, how do you position the confidence

00:20:30.509 --> 00:20:35.369
in a synced passkey where device bound is lovely?

00:20:35.470 --> 00:20:37.769
I know it only lives in this one place if it's

00:20:37.769 --> 00:20:40.940
synced. how do you have that conversation around

00:20:40.940 --> 00:20:44.779
well yes it exists in multiple places but hey

00:20:44.779 --> 00:20:48.960
we can still trust it because of x well i'll

00:20:48.960 --> 00:20:51.420
say that i think the conversations i've had with

00:20:51.420 --> 00:20:53.599
past keys which are probably not as extensive

00:20:53.599 --> 00:20:57.200
as you two is that i feel like it's a bit deja

00:20:57.200 --> 00:20:59.500
vu because do you remember when we first started

00:20:59.500 --> 00:21:03.779
doing mfa and you would get pushback from People

00:21:03.779 --> 00:21:06.039
being like, it's too hard. I don't want to do

00:21:06.039 --> 00:21:10.099
it. And it's holding up our workflow. And for

00:21:10.099 --> 00:21:12.099
particular, and then that sort of went away over

00:21:12.099 --> 00:21:14.460
time. But you'd still have certain groups of

00:21:14.460 --> 00:21:18.200
kind of users who would still kind of hold out

00:21:18.200 --> 00:21:21.359
about wanting to use MFA. And I feel like we've

00:21:21.359 --> 00:21:23.920
almost got past that now. But I'm seeing it kind

00:21:23.920 --> 00:21:27.839
of start again with passkeys almost. Because

00:21:27.839 --> 00:21:31.640
passkeys are a little bit, sometimes they're

00:21:31.640 --> 00:21:37.380
fiddly to set up. I find. And for someone like

00:21:37.380 --> 00:21:39.680
me, I'm going to like, because I'm stubborn and

00:21:39.680 --> 00:21:42.799
I'm like, no, I will make this work because that's

00:21:42.799 --> 00:21:46.380
me. But for a lot of user bases, they're just

00:21:46.380 --> 00:21:49.740
like, no, this is too hard. And so I think we've

00:21:49.740 --> 00:21:52.480
got like that adoption challenge again that we

00:21:52.480 --> 00:21:55.720
saw with MFA, at least for certain types of user

00:21:55.720 --> 00:21:58.029
groups. And I'm sure we'll get through it with

00:21:58.029 --> 00:21:59.750
time. I'm not sure I have like a magical answer.

00:21:59.869 --> 00:22:02.190
I feel like it's just same as we did with MFA.

00:22:02.269 --> 00:22:04.089
It's going to take a bit of time and education.

00:22:04.690 --> 00:22:09.650
And of course, listening to what the gotchas

00:22:09.650 --> 00:22:11.569
are. I mean, I can tell you that on my phone

00:22:11.569 --> 00:22:14.839
for ages, I made a passkey on my Gmail. And it

00:22:14.839 --> 00:22:17.039
wouldn't work. And it kept saying I would try

00:22:17.039 --> 00:22:18.859
and log in and it would be like, no, no, no.

00:22:19.000 --> 00:22:21.140
And I was like, I know how to make a passkey.

00:22:21.200 --> 00:22:23.400
How dare you? And it turns out that there was

00:22:23.400 --> 00:22:25.339
something after I did some research. And when

00:22:25.339 --> 00:22:28.660
I say research, I asked AI, obviously. The iPhone

00:22:28.660 --> 00:22:31.839
defaults to using different stores. And because

00:22:31.839 --> 00:22:34.700
the passkey was somewhere else. But it doesn't

00:22:34.700 --> 00:22:37.059
explicitly say that anywhere. It just says, oh,

00:22:37.079 --> 00:22:39.180
your passkey isn't working. And I remember being

00:22:39.180 --> 00:22:42.160
really grouchy because I was like. I think I

00:22:42.160 --> 00:22:44.920
can do a passkey or I hope I can make a passkey

00:22:44.920 --> 00:22:48.140
that works. And it took me a little while, but

00:22:48.140 --> 00:22:50.480
I'm the kind of person who will go and dig into

00:22:50.480 --> 00:22:52.420
it and understand. And there's a lot of user

00:22:52.420 --> 00:22:55.380
bases. And if we think we want everybody to use

00:22:55.380 --> 00:22:58.700
passkeys, which we do, I'm like a tiny proportion

00:22:58.700 --> 00:23:01.799
of a user base that would go and try and troubleshoot

00:23:01.799 --> 00:23:04.539
it myself because I'm a stubborn so -and -so.

00:23:04.960 --> 00:23:08.039
And so I guess. Yeah, that would be my thing,

00:23:08.059 --> 00:23:09.700
I think, about capacity is there's going to be

00:23:09.700 --> 00:23:12.180
a bit of like adoption friction again. So it's

00:23:12.180 --> 00:23:13.779
going to take a little while. But I don't know,

00:23:13.799 --> 00:23:15.700
Michael, what do you think? Yeah, I think the

00:23:15.700 --> 00:23:17.460
number one question I get is how is it different

00:23:17.460 --> 00:23:21.240
from MFA? And I just keep it really simple with

00:23:21.240 --> 00:23:23.220
people and just say it's essentially. And John,

00:23:23.259 --> 00:23:25.859
you correct me here if I'm wrong, but I'd sort

00:23:25.859 --> 00:23:27.480
of simplify things a little bit. It's like essentially

00:23:27.480 --> 00:23:30.819
fishing resistant MFA. It's still MFA. It's just

00:23:30.819 --> 00:23:33.920
something that's. stronger than mfa to your point

00:23:33.920 --> 00:23:37.099
it can be tied to a domain and uh and it's phishing

00:23:37.099 --> 00:23:39.460
resistant is that a fair comment or am i yeah

00:23:39.460 --> 00:23:41.480
no i i think we can call it that when we talk

00:23:41.480 --> 00:23:43.779
about like authentication strengths in entra

00:23:43.779 --> 00:23:47.559
we have phishing resistant mfa and we have pass

00:23:47.559 --> 00:23:50.299
keys in there because to your point it it's supposed

00:23:50.299 --> 00:23:52.440
to be able to protect the user from being tricked

00:23:52.440 --> 00:23:55.940
they can't authenticate some remote person and

00:23:55.940 --> 00:23:58.259
they can't click on a fake domain because it

00:23:58.259 --> 00:24:01.960
won't let it so i i I think it's a great thing

00:24:01.960 --> 00:24:03.819
that anything that adds protection to the user,

00:24:03.859 --> 00:24:06.460
because in the movies we see the hacking and

00:24:06.460 --> 00:24:08.779
the hacking is always, hey, they're dropping

00:24:08.779 --> 00:24:12.220
a payload into something or other and it's exploiting.

00:24:12.440 --> 00:24:14.140
Really, most of the hacking is they're phoning

00:24:14.140 --> 00:24:16.240
up Bob and it's like, hey, I'm from the IT. I'm

00:24:16.240 --> 00:24:18.480
just checking. You've been hacked. Do this. And

00:24:18.480 --> 00:24:22.259
if we can stop the users being able to be tricked,

00:24:22.420 --> 00:24:25.839
that closes probably a massive portion of the

00:24:25.839 --> 00:24:28.339
attack surface that's real. I don't think there's

00:24:28.339 --> 00:24:31.200
that many people really dropping these worm payloads

00:24:31.200 --> 00:24:34.700
to go and hack into X, Y, and Z. It's Bob is

00:24:34.700 --> 00:24:38.039
really the problem. Bob in IT. Yeah, it's funny

00:24:38.039 --> 00:24:39.759
you should bring that up. Like my two recommendations

00:24:39.759 --> 00:24:42.940
to sort of normal human beings outside of IT

00:24:42.940 --> 00:24:45.619
are one, use passkeys for your normal, like at

00:24:45.619 --> 00:24:48.119
least for anything that you care, like really,

00:24:48.279 --> 00:24:51.170
really care about. like, you know, your bank

00:24:51.170 --> 00:24:52.769
or anything like that. Just set up passkeys for

00:24:52.769 --> 00:24:55.170
everything. And the second one is use your cell

00:24:55.170 --> 00:24:57.690
phone and Apple Pay or, you know, Google Pay

00:24:57.690 --> 00:25:01.130
or whatever when you're buying gas as opposed

00:25:01.130 --> 00:25:03.130
to using a credit card, as opposed to swiping

00:25:03.130 --> 00:25:05.470
a credit card, you know, from a skimming perspective.

00:25:06.170 --> 00:25:08.809
You know what's really funny on that? So my parents

00:25:08.809 --> 00:25:11.329
came to stay recently, and they are fairly technically

00:25:11.329 --> 00:25:14.529
illiterate for people in their age bracket. But

00:25:14.529 --> 00:25:17.710
they will not, I discovered, particularly my

00:25:17.710 --> 00:25:20.210
dad, I discovered when they came to stay with

00:25:20.210 --> 00:25:23.029
me, my dad will not use Apple Pay. And I was

00:25:23.029 --> 00:25:24.970
like, why? He's like, oh, I don't think it's

00:25:24.970 --> 00:25:27.130
secure. And I was like, Dad, it's fine. In fact,

00:25:27.150 --> 00:25:31.230
it's probably better. And he was like, oh, no,

00:25:31.349 --> 00:25:34.230
no, no, no. And I was like, oh. So I was trying

00:25:34.230 --> 00:25:36.809
to educate him. I was like, honestly, dad. Also,

00:25:36.990 --> 00:25:38.789
then you don't have to carry cards around and

00:25:38.789 --> 00:25:40.970
they can't be skimmed and blah, blah, blah. And

00:25:40.970 --> 00:25:42.650
I was explaining it to him. He wasn't having

00:25:42.650 --> 00:25:46.509
it. And I would say that luckily my parents do

00:25:46.509 --> 00:25:48.130
not listen to this podcast. I would not call

00:25:48.130 --> 00:25:51.950
my parents Luddites as far as tech goes in general.

00:25:52.089 --> 00:25:56.430
And I was really surprised. So Apple Pay all

00:25:56.430 --> 00:25:59.660
the way or whatever. Electronic wallet. Everything

00:25:59.660 --> 00:26:02.299
is scary. If you don't understand it, it's scary

00:26:02.299 --> 00:26:04.920
and it can be compromised. It's just, hey, if

00:26:04.920 --> 00:26:06.640
you can get people to understand. Twice I've

00:26:06.640 --> 00:26:09.279
had my credit card stolen from gas stations,

00:26:09.359 --> 00:26:11.440
like doing that skimming thing when I was younger.

00:26:12.539 --> 00:26:15.839
I've had my card details used, but it hasn't

00:26:15.839 --> 00:26:19.720
been at petrol stations, by the way. Gas stations.

00:26:20.420 --> 00:26:23.140
In my adopted country, it's a gas station now.

00:26:23.279 --> 00:26:27.440
That's right. But I've definitely had my card

00:26:27.440 --> 00:26:31.240
details stolen. Someone bought flights in Japan,

00:26:31.380 --> 00:26:34.619
budget flights in Japan on my card once. I have

00:26:34.619 --> 00:26:38.720
no idea how they got my number, but there's so

00:26:38.720 --> 00:26:42.779
many ways, right? I will not buy gas from a gas

00:26:42.779 --> 00:26:44.579
station that doesn't allow me to use my phone.

00:26:45.210 --> 00:26:46.750
I just, it's just not worth the risk. I mean,

00:26:46.750 --> 00:26:47.829
the fact that you've got something that can read

00:26:47.829 --> 00:26:51.089
a credit card outside, unprotected, accessible

00:26:51.089 --> 00:26:53.869
to the bad guys so easily. I just don't. If I

00:26:53.869 --> 00:26:56.029
have to, if I absolutely can't, like, again,

00:26:56.130 --> 00:26:58.990
I'm on E for enough. I will choose the gas pump

00:26:58.990 --> 00:27:02.829
that is closest to the shop or whatever is associated

00:27:02.829 --> 00:27:05.769
with the gas station in the hope that they haven't

00:27:05.769 --> 00:27:07.970
put a skimming device. I always check. I don't

00:27:07.970 --> 00:27:09.549
know about you guys. I always wiggle and see

00:27:09.549 --> 00:27:12.990
if anything moves. Wow, Michael. And you know

00:27:12.990 --> 00:27:16.210
what? I just remembered as well. Obviously, for

00:27:16.210 --> 00:27:18.289
people who might remember, I did live in the

00:27:18.289 --> 00:27:22.150
US for a year. I forgot. So for those of you

00:27:22.150 --> 00:27:24.069
who have not been to my side of the world, and

00:27:24.069 --> 00:27:26.390
actually quite a lot of places in Europe, there

00:27:26.390 --> 00:27:29.390
is a difference about buying petrol, gas, whatever

00:27:29.390 --> 00:27:32.809
you want to call it, is that we don't... always

00:27:32.809 --> 00:27:36.049
have card machines outside at the pump you go

00:27:36.049 --> 00:27:38.950
in to pay and you pay after you have put the

00:27:38.950 --> 00:27:41.490
petrol in which I know shocks many Americans

00:27:41.490 --> 00:27:44.809
because in theory you could drive off except

00:27:44.809 --> 00:27:48.130
we don't because we're good people well most

00:27:48.130 --> 00:27:51.190
people are so we don't have that same problem

00:27:51.190 --> 00:27:53.089
in Australia because you have to go in to pay

00:27:53.089 --> 00:27:56.849
like there are no card machines at the pump the

00:27:56.849 --> 00:28:00.059
things you cover in this podcast And I've learned

00:28:00.059 --> 00:28:03.019
E for enough. That's a new one on me as well.

00:28:05.940 --> 00:28:08.440
That's the, that's the eternally optimistic side

00:28:08.440 --> 00:28:11.920
of me. All right. I think we've done pass keys

00:28:11.920 --> 00:28:16.480
to death. Everyone use pass keys. Yeah. But we

00:28:16.480 --> 00:28:18.220
didn't ask, no, you know, John, we didn't answer

00:28:18.220 --> 00:28:20.079
the question about what, you know, what, what

00:28:20.079 --> 00:28:23.079
feedback have we heard about potentially having

00:28:23.079 --> 00:28:26.380
roaming pass keys between devices? Personally,

00:28:26.480 --> 00:28:28.940
I've not heard anybody complain about them. A

00:28:28.940 --> 00:28:32.920
lot of people, certainly outside of IT, the normal

00:28:32.920 --> 00:28:34.559
question I get is, what the heck is a passkey?

00:28:35.000 --> 00:28:37.500
So I haven't got past that door yet. But from

00:28:37.500 --> 00:28:40.039
a corporate perspective, I mean, if people don't

00:28:40.039 --> 00:28:42.160
want it, then my guess is it's policy. You can

00:28:42.160 --> 00:28:44.319
turn it on or turn it off. It's just a policy.

00:28:44.539 --> 00:28:46.680
Yeah, there you go. It's easy to turn it off.

00:28:47.420 --> 00:28:49.019
I think some people have got scared of it, but

00:28:49.019 --> 00:28:51.019
not a valid. Some people, you do want to know

00:28:51.019 --> 00:28:52.799
exactly where the PASC is at all times, but for

00:28:52.799 --> 00:28:54.339
a lot of people, you don't need that level. And

00:28:54.339 --> 00:28:56.339
again, conditioner access still applies. It's

00:28:56.339 --> 00:28:58.960
still done at the actual authorization to use

00:28:58.960 --> 00:29:02.079
it for a thing. So yeah, I don't think it's as

00:29:02.079 --> 00:29:05.420
big a problem as people make out. Yeah. All right.

00:29:05.480 --> 00:29:09.640
So what's number three top of mind for John Saville?

00:29:10.089 --> 00:29:12.450
From a nerdy perspective, and I think it's becoming

00:29:12.450 --> 00:29:14.750
a very real perspective, I think the quantum

00:29:14.750 --> 00:29:16.470
thing, and obviously because this is security.

00:29:16.890 --> 00:29:20.789
Oh, here we go. I'm ducking out here because

00:29:20.789 --> 00:29:23.509
this is Michael's baby. I did not pay John to

00:29:23.509 --> 00:29:26.009
say that. Do you know, I spent a whole, but I

00:29:26.009 --> 00:29:28.230
did a video on what is quantum computing. And

00:29:28.230 --> 00:29:30.849
you talk about learning stuff. Like, I had no

00:29:30.849 --> 00:29:33.609
clue. It was a good video, man. And that video

00:29:33.609 --> 00:29:37.579
must have been some of the... hardest research

00:29:37.579 --> 00:29:39.579
because i'm not that smart i'm not that good

00:29:39.579 --> 00:29:42.299
at math and everything you look at quantum math

00:29:42.299 --> 00:29:44.920
comes into it at a certain point but i think

00:29:44.920 --> 00:29:48.440
it it's fascinating and you look at the behaviors

00:29:48.440 --> 00:29:50.500
it's like well that's impossible how can if you

00:29:50.500 --> 00:29:52.339
measure it it collapses like how does it know

00:29:52.339 --> 00:29:55.920
i looked at the thing like how can it transmit

00:29:55.920 --> 00:29:59.720
state over infinite distance it like but i think

00:29:59.720 --> 00:30:02.680
from a entanglement perspective and what we just

00:30:02.680 --> 00:30:04.640
announced the build so you talked about the build

00:30:04.640 --> 00:30:10.299
stuff so the myrana 2 and qubits kind of the

00:30:10.299 --> 00:30:13.660
quantum version of the thing we were getting

00:30:13.660 --> 00:30:16.980
milliseconds of durability for the things suddenly

00:30:16.980 --> 00:30:21.059
we're at 20 seconds now a thousand fold increase

00:30:21.059 --> 00:30:25.259
to me and that that's massive and we're now saying

00:30:25.259 --> 00:30:30.309
hey 2029 scalable quantum computer. So if we

00:30:30.309 --> 00:30:34.369
think about quantum is fantastic from a, hey,

00:30:34.450 --> 00:30:36.210
there are things you cannot model with a classical

00:30:36.210 --> 00:30:37.970
computer because of the way the combinations

00:30:37.970 --> 00:30:41.349
and the dependencies between them. Suddenly I

00:30:41.349 --> 00:30:44.369
can model like real world and solve medical things

00:30:44.369 --> 00:30:47.690
and find new materials. But it also suddenly,

00:30:47.789 --> 00:30:49.789
the thing you mentioned at the start about, okay,

00:30:49.829 --> 00:30:53.869
the new capabilities we're adding, our old sort

00:30:53.869 --> 00:30:57.660
of asymmetric encryption, that relies on some

00:30:57.660 --> 00:31:00.380
math things are really hard to solve, like longer

00:31:00.380 --> 00:31:02.059
than, I think it's like history of the universe

00:31:02.059 --> 00:31:04.740
thing. Suddenly there are these algorithms in

00:31:04.740 --> 00:31:07.640
quantum that nudge you to the right answer, I

00:31:07.640 --> 00:31:12.319
think in minutes. And so if in three years, potentially,

00:31:12.319 --> 00:31:17.339
we now have this way to break what most of our

00:31:17.339 --> 00:31:21.160
communication kind of relies on, I think the

00:31:21.160 --> 00:31:24.059
post -quantum cryptography stuff, and even today,

00:31:24.220 --> 00:31:27.759
stopping people just, storing the data they can't

00:31:27.759 --> 00:31:31.359
decrypt, but then harvest it later, it becomes

00:31:31.359 --> 00:31:33.740
a really real thing. And I can't remember the

00:31:33.740 --> 00:31:35.220
name of the technology. I know it's based on

00:31:35.220 --> 00:31:37.480
lightsabers and warp cores. Like there's two

00:31:37.480 --> 00:31:40.339
things that we kind of do that I forgot the exact

00:31:40.339 --> 00:31:42.240
terms for it. Well, I remember I did the video

00:31:42.240 --> 00:31:44.059
and I was holding a lightsaber because I know

00:31:44.059 --> 00:31:46.160
it's sort of the crystal that would get the lightsabers

00:31:46.160 --> 00:31:49.140
to work, the code name. But I think... Oh, crystals

00:31:49.140 --> 00:31:51.559
Kyber? Yes, Kyber. Yeah, that's it. And then

00:31:51.559 --> 00:31:55.910
the warp core stuff. But like, I think... it's

00:31:55.910 --> 00:31:59.069
not being taken seriously by enough companies

00:31:59.069 --> 00:32:01.390
today that this really is around the corner.

00:32:01.549 --> 00:32:03.730
I think people said, no, is this 50 years away

00:32:03.730 --> 00:32:05.990
or it's a hundred years away. And it's really

00:32:05.990 --> 00:32:09.190
not like there were things that I think everyone

00:32:09.190 --> 00:32:10.849
should be thinking about today. It's like, does

00:32:10.849 --> 00:32:13.230
that traffic have to be on a public network today?

00:32:13.309 --> 00:32:15.390
Or can I keep this within a private network?

00:32:15.490 --> 00:32:18.569
So someone can't harvest the thing. And what

00:32:18.569 --> 00:32:21.029
work am I doing for my services to start looking

00:32:21.029 --> 00:32:22.890
at the post -quantum cryptography stuff? Like

00:32:22.890 --> 00:32:27.309
I, I think it's a really real, that people are

00:32:27.309 --> 00:32:28.730
going to leave till the last minute and then

00:32:28.730 --> 00:32:31.990
be like, oops. And I know that's Michael. So

00:32:31.990 --> 00:32:34.089
I was excited. So I was like, oh, okay. I know

00:32:34.089 --> 00:32:36.779
Michael's into this stuff. And it's like. And

00:32:36.779 --> 00:32:38.819
I know we're doing a lot of work on it as Microsoft.

00:32:38.960 --> 00:32:40.799
I'm curious, what are your thoughts on that?

00:32:41.440 --> 00:32:43.599
So you talk about the Majorana 2 chip. What's

00:32:43.599 --> 00:32:45.440
fascinating about that is not just the fact that

00:32:45.440 --> 00:32:47.859
it exists, but like I was going to say, the quantum

00:32:47.859 --> 00:32:49.660
increase, but I figured that would be a dad's

00:32:49.660 --> 00:32:53.019
joke, dad joke. But the huge increase, like you're

00:32:53.019 --> 00:32:55.200
saying, durability of the qubits is, and that's

00:32:55.200 --> 00:32:56.960
in a short amount of time. So give it another

00:32:56.960 --> 00:32:59.059
four or five years, right? I mean, we're going

00:32:59.059 --> 00:33:01.359
to make even more leaps and bounds. I'm going

00:33:01.359 --> 00:33:03.140
to throw something at you two right now, and

00:33:03.140 --> 00:33:04.619
I hope you're sitting down because this, which

00:33:04.619 --> 00:33:07.150
I know you are, but this is going to, when i

00:33:07.150 --> 00:33:12.369
say this you're going to be blown away and obvious

00:33:12.369 --> 00:33:15.690
at the same time quantum computers actually model

00:33:15.690 --> 00:33:19.930
the real world our current computers do not like

00:33:19.930 --> 00:33:21.549
at the end of the day when you go all the way

00:33:21.549 --> 00:33:24.440
down to the minutiae of the quantum world we're

00:33:24.440 --> 00:33:26.680
just modeling the quantum world that's all we're

00:33:26.680 --> 00:33:29.279
doing and because we're doing it natively it's

00:33:29.279 --> 00:33:32.220
incredibly efficient um but also the fact that

00:33:32.220 --> 00:33:34.099
you have to your point you know we have these

00:33:34.099 --> 00:33:37.180
qubit things where they can all hold all the

00:33:37.180 --> 00:33:39.519
values at the same time with a probability and

00:33:39.519 --> 00:33:41.700
then the and then you observe them and then it

00:33:41.700 --> 00:33:43.380
collapses and then you have a higher probability

00:33:43.380 --> 00:33:45.759
of one of the qubits being a specific set of

00:33:45.759 --> 00:33:47.160
or some some of the qubits having a specific

00:33:47.160 --> 00:33:49.299
set of values and you run that multiple times

00:33:49.299 --> 00:33:52.279
and it's all it's basically just an averaging

00:33:52.279 --> 00:33:55.359
out of the probabilities of the results that

00:33:55.359 --> 00:33:58.039
you get. But it's just modeling the real world.

00:33:58.119 --> 00:34:00.539
That's all it really is. But to your point, you

00:34:00.539 --> 00:34:03.200
know, yes, RSA, elliptic curve, Diffie -Hellman,

00:34:03.240 --> 00:34:05.359
all these, the asymmetric algorithms essentially

00:34:05.359 --> 00:34:08.659
get, you know, become incredibly weak. because

00:34:08.659 --> 00:34:11.239
quantum computers are very good at sort of algorithms.

00:34:11.599 --> 00:34:13.739
So, for example, factoring large numbers, which

00:34:13.739 --> 00:34:16.639
is the root of RSA, or the mathematical problem

00:34:16.639 --> 00:34:19.579
that's hard in RSA is very easy with quantum

00:34:19.579 --> 00:34:21.400
computers. And they've got discrete logarithms

00:34:21.400 --> 00:34:23.840
with elliptic curve and so on. Those functions,

00:34:23.960 --> 00:34:26.159
those sort of algorithms are very easy to model

00:34:26.159 --> 00:34:29.699
in quantum computing and they're very efficient.

00:34:30.199 --> 00:34:33.739
With AES, which is symmetric, there is a speedup

00:34:33.739 --> 00:34:37.619
called Grover's algorithm. But it's still basically

00:34:37.619 --> 00:34:40.280
brute force. It's not an algorithm. It's just

00:34:40.280 --> 00:34:42.980
brute force of checking keys. But there is a

00:34:42.980 --> 00:34:45.400
speed up from Grover's algorithm that came out

00:34:45.400 --> 00:34:48.059
in the mid -90s. So yeah, it's a fascinating

00:34:48.059 --> 00:34:49.980
area. And to your point, John, you're seeing

00:34:49.980 --> 00:34:51.659
a lot of customers sort of... what seems to be

00:34:51.659 --> 00:34:53.840
like waiting to the last minute. Think Y2K. How

00:34:53.840 --> 00:34:55.880
many people waited to the last minute for Y2K?

00:34:56.380 --> 00:34:59.019
Virtually nobody. And do we have any real problems

00:34:59.019 --> 00:35:02.699
once 2000 rolled over? No, because people had

00:35:02.699 --> 00:35:05.119
done the work. You can't wait until the last

00:35:05.119 --> 00:35:07.960
minute. And I really want to point something

00:35:07.960 --> 00:35:11.039
else out. And that is from my perspective, from

00:35:11.039 --> 00:35:13.300
the customer calls that I get, the customers

00:35:13.300 --> 00:35:17.139
that really care. really care like they really

00:35:17.139 --> 00:35:19.300
want to know what our plans are what we're doing

00:35:19.300 --> 00:35:21.440
what the industry's doing and we're sort of looking

00:35:21.440 --> 00:35:23.300
at their plans as well for rolling things out

00:35:23.300 --> 00:35:25.639
they know that no one can do all of this overnight

00:35:25.639 --> 00:35:28.300
it does take time because it's very very layered

00:35:28.300 --> 00:35:30.679
you got to get all the the substrate done and

00:35:30.679 --> 00:35:32.000
then you got to build on top of that substrate

00:35:32.000 --> 00:35:34.360
and you know for example you got to get the low

00:35:34.360 --> 00:35:36.800
-level crypto in place. That's all in place in

00:35:36.800 --> 00:35:38.960
Windows and Linux now. In Windows, there's a

00:35:38.960 --> 00:35:40.800
thing called SimCrypt. Then on top of that, you've

00:35:40.800 --> 00:35:43.980
got things like TLS, TLS 1 .3 with MLChem for

00:35:43.980 --> 00:35:46.059
doing the key encapsulation. Then on top of that,

00:35:46.119 --> 00:35:47.420
you've got the applications that are now going

00:35:47.420 --> 00:35:49.500
to take advantage of all of these things. And

00:35:49.500 --> 00:35:52.820
to your point, John, if you can do something

00:35:52.820 --> 00:35:56.340
where you don't have to go over a public network,

00:35:56.519 --> 00:35:58.579
even better, right? Because that way it's not

00:35:58.579 --> 00:36:01.079
being exposed for Harvest Now, Decrypt Later.

00:36:02.159 --> 00:36:04.489
I could keep going, but I won't. No, I mean,

00:36:04.530 --> 00:36:06.630
and it's interesting to hear your thought on

00:36:06.630 --> 00:36:09.929
it because to your point, like I've maybe had

00:36:09.929 --> 00:36:12.949
two customers actually ask seriously about it

00:36:12.949 --> 00:36:15.670
this year and it should be a lot higher because

00:36:15.670 --> 00:36:19.429
I think there really is a, I don't know, a denial

00:36:19.429 --> 00:36:22.309
going on about that it is coming and it's real.

00:36:22.809 --> 00:36:25.289
I feel like it's because I haven't had a ton

00:36:25.289 --> 00:36:28.550
of chats about it with people. I feel like it's

00:36:28.550 --> 00:36:31.690
one of those, oh yeah, but it's a bit like. You

00:36:31.690 --> 00:36:34.849
know, back in the day, I feel like, again, we've

00:36:34.849 --> 00:36:37.409
mostly moved past this when people would say,

00:36:37.650 --> 00:36:40.369
oh, but why would someone hack me? You know,

00:36:40.409 --> 00:36:42.510
why would someone hack me? I'm so small. I'm

00:36:42.510 --> 00:36:45.369
just this. And the answer is because they can

00:36:45.369 --> 00:36:47.989
and you're on the Internet. So you expose yourself.

00:36:48.170 --> 00:36:50.250
And we also know now that threat actors will

00:36:50.250 --> 00:36:53.190
actually purposely go for like smaller businesses

00:36:53.190 --> 00:36:55.150
because they know their protections tend to be

00:36:55.150 --> 00:36:57.989
less and it's less effort. But I feel like it's

00:36:57.989 --> 00:37:01.750
a bit of that mindset that, oh, yeah. We'll be

00:37:01.750 --> 00:37:04.789
fine. It still ages off. And even if it does

00:37:04.789 --> 00:37:07.730
become a thing, who would hack us? It's like

00:37:07.730 --> 00:37:12.710
almost like conscious naivety, like sort of.

00:37:12.960 --> 00:37:15.019
I don't know how else to call it, like sort of

00:37:15.019 --> 00:37:17.820
being like mindfully kind of like, it's not us,

00:37:17.960 --> 00:37:20.079
we'll be fine. And I think it comes back to that

00:37:20.079 --> 00:37:22.039
thing. I think a lot of people don't really understand

00:37:22.039 --> 00:37:24.659
it. And it seems like there's movies out, the

00:37:24.659 --> 00:37:27.739
quantum, like it seems like pure science fiction.

00:37:27.760 --> 00:37:29.519
It's like, this is not real. Like this is not

00:37:29.519 --> 00:37:31.440
going to happen. And so it's just like, I'm not

00:37:31.440 --> 00:37:33.880
going to think about it. It won't impact me if

00:37:33.880 --> 00:37:35.300
I don't think about it. But it's just not the

00:37:35.300 --> 00:37:37.239
case. Like we really think we're a few years

00:37:37.239 --> 00:37:40.519
away from this knocking on the door. And I think.

00:37:41.000 --> 00:37:44.260
It's critical people really start to look at

00:37:44.260 --> 00:37:46.599
their services, their apps, their capabilities

00:37:46.599 --> 00:37:50.159
and plan. To your point, Michael, we have it

00:37:50.159 --> 00:37:52.539
now in our library. You can start to use and

00:37:52.539 --> 00:37:54.599
look at these things now and start planning for

00:37:54.599 --> 00:37:56.400
it. Go and discover where you're doing encryption

00:37:56.400 --> 00:37:58.360
and start thinking about how you're going to

00:37:58.360 --> 00:38:00.579
address it. Yeah, that's the first thing is you've

00:38:00.579 --> 00:38:02.099
got to know where you're doing crypto. Right.

00:38:02.900 --> 00:38:04.400
I mean, you've got to know where it is everywhere.

00:38:04.579 --> 00:38:06.940
And that's the first thing. I've actually been

00:38:06.940 --> 00:38:08.559
working on a few things. So the problem is some

00:38:08.559 --> 00:38:10.920
of it you can do statically and some of it you

00:38:10.920 --> 00:38:13.440
need to do dynamically. So there's no one single

00:38:13.440 --> 00:38:15.079
way of determining where you're using crypto.

00:38:15.460 --> 00:38:16.900
One of the things that's really hard inside of

00:38:16.900 --> 00:38:19.920
Azure is we're very dynamic. It's an incredibly

00:38:19.920 --> 00:38:24.099
dynamic backend. And so we've done our crypto

00:38:24.099 --> 00:38:26.840
inventory work at the backend, but it's incredible.

00:38:27.019 --> 00:38:29.579
It changes every day. But yeah, to your point,

00:38:29.639 --> 00:38:31.440
you've got to know where you're doing crypto.

00:38:32.300 --> 00:38:34.659
And if you're doing any kind of key wrapping

00:38:34.659 --> 00:38:38.739
or key exchange with asymmetric algorithms, that's

00:38:38.739 --> 00:38:42.480
the big issue right now. And that's why TLS 1

00:38:42.480 --> 00:38:46.699
.3 has to be used everywhere because once everybody

00:38:46.699 --> 00:38:49.780
has the post -quantum algorithms, they can essentially

00:38:49.780 --> 00:38:52.139
just turn them on. And as I mentioned at the

00:38:52.139 --> 00:38:54.519
top of the podcast, We now have a version of

00:38:54.519 --> 00:38:56.500
Windows 11 that has S Channel, which does the

00:38:56.500 --> 00:39:00.679
TLS support, and it has the post -quantum. It's

00:39:00.679 --> 00:39:02.519
in preview, but you can start kicking the tires

00:39:02.519 --> 00:39:06.320
on it right now. Very important. Yeah. Don't

00:39:06.320 --> 00:39:09.519
wait. Let's sort of wrap up this episode, bring

00:39:09.519 --> 00:39:12.199
it to a close. Otherwise, we will be here forever.

00:39:12.380 --> 00:39:15.059
We'll have to get you back on for John's Thought

00:39:15.059 --> 00:39:18.119
version 2 in like six months or a year to see

00:39:18.119 --> 00:39:22.860
what's changed with customers. John, we always

00:39:22.860 --> 00:39:26.179
ask our guests a couple of questions, which is,

00:39:26.199 --> 00:39:28.300
what does a day in the life of John Salvo look

00:39:28.300 --> 00:39:31.760
like? It is highly consistent and highly boring.

00:39:31.880 --> 00:39:35.079
So every day I get up at 3 .30, I work out from

00:39:35.079 --> 00:39:41.500
4 to 7, then 7 till sort of 4 or 5 work, then

00:39:41.500 --> 00:39:46.460
family time, go out in the woods and try and

00:39:46.460 --> 00:39:49.380
get a bit of nature in, and then... Go to bed.

00:39:49.500 --> 00:39:53.440
And the workday is customer meetings. Sometimes

00:39:53.440 --> 00:39:55.800
I'm traveling for customer things, meeting with

00:39:55.800 --> 00:40:00.059
product groups. I am lucky. My job is for the

00:40:00.059 --> 00:40:01.860
most part my hobby as well. So I'm always learning.

00:40:01.960 --> 00:40:04.800
Like to me, staying curious, like I'm still as

00:40:04.800 --> 00:40:06.579
curious as I've ever been. I'm still trying to

00:40:06.579 --> 00:40:10.239
learn stuff and find out what this thing is and

00:40:10.239 --> 00:40:13.559
what this thing can do. And I still love to be

00:40:13.559 --> 00:40:16.480
challenged and find new things. For most days,

00:40:16.539 --> 00:40:19.460
it's a good, happy, positive day. That's pretty

00:40:19.460 --> 00:40:21.199
cool. And I can confirm, by the way, because

00:40:21.199 --> 00:40:23.519
I have been on work trips with John, that he

00:40:23.519 --> 00:40:27.340
does indeed work out for three hours. And I've

00:40:27.340 --> 00:40:30.039
also talked to you at times in my afternoon where

00:40:30.039 --> 00:40:33.199
most people would be asleep. So I can confirm

00:40:33.199 --> 00:40:35.780
that John really does get up that early to work

00:40:35.780 --> 00:40:39.920
out. It is true. And then the last question is,

00:40:40.079 --> 00:40:43.159
so the last thing that we ask our guest, John,

00:40:43.219 --> 00:40:46.909
is, For our listeners, if you wanted to leave

00:40:46.909 --> 00:40:50.010
them with a final thought, what would it be?

00:40:50.750 --> 00:40:53.550
Honestly, I think in this day and age more than

00:40:53.550 --> 00:40:59.050
ever, it's just keep an open mind and be curious.

00:40:59.170 --> 00:41:02.969
I think today it's the most important thing.

00:41:04.150 --> 00:41:07.150
Don't be afraid of something and so then close

00:41:07.150 --> 00:41:08.929
your mind and say, I'm not going to look at that

00:41:08.929 --> 00:41:11.070
thing, know what I'm doing today is the right

00:41:11.070 --> 00:41:13.929
thing. You're quickly going to... become irrelevant

00:41:13.929 --> 00:41:18.070
so i think if you keep an open mind and look

00:41:18.070 --> 00:41:20.269
at everything that's out there some of it's not

00:41:20.269 --> 00:41:23.590
going to be anything useful but if you take a

00:41:23.590 --> 00:41:25.869
look try the thing out i think that's how you

00:41:25.869 --> 00:41:28.530
stay ahead and that's how you stay relevant and

00:41:28.530 --> 00:41:31.170
informed so just be curious and keep an open

00:41:31.170 --> 00:41:33.110
mind i think that's that's the key to success

00:41:33.110 --> 00:41:35.230
in this day and age yeah i really couldn't have

00:41:35.230 --> 00:41:37.309
said it better i mean just stay curious i think

00:41:37.309 --> 00:41:40.789
it's just So important, really important to just

00:41:40.789 --> 00:41:43.409
little silly things that just interest you. And

00:41:43.409 --> 00:41:45.409
I think it makes you a more well -rounded person.

00:41:46.250 --> 00:41:48.389
John, thank you so much for joining us this week.

00:41:48.489 --> 00:41:51.010
I always learn something from my guests and this

00:41:51.010 --> 00:41:53.190
was absolutely no exception. So it was an absolute

00:41:53.190 --> 00:41:55.809
pleasure having you on the podcast. Thank you

00:41:55.809 --> 00:41:58.230
for having me. It was a lot of fun. And as Sarah

00:41:58.230 --> 00:42:00.349
said, hopefully we can have you back in six or

00:42:00.349 --> 00:42:04.380
12 months. Version 2. And to all our listeners,

00:42:04.539 --> 00:42:06.260
we hope you found this episode of use and of

00:42:06.260 --> 00:42:08.920
interest. Stay safe, and we'll see you next time.

00:42:09.159 --> 00:42:11.280
Thanks for listening to the Azure Security Podcast.

00:42:11.739 --> 00:42:14.679
You can find show notes and other resources at

00:42:14.679 --> 00:42:19.280
our website, azsecuritypodcast .net. If you have

00:42:19.280 --> 00:42:22.460
any questions, please find us on Twitter at AzureSecPod.

00:42:23.360 --> 00:42:27.059
Background music is from ccmixter .com and licensed

00:42:27.059 --> 00:42:28.760
under the Creative Commons license.
