Saturday, 1 April 2023

Italy orders ChatGPT blocked citing data protection concerns

Two days after an open letter called for a moratorium on the development of more powerful generative AI models so regulators can catch up with the likes of ChatGPT, Italy’s data protection authority has just put out a timely reminder that some countries do have laws that already apply to cutting edge AI: it has ordered OpenAI to stop processing people’s data locally with immediate effect.

The Italian DPA said it’s concerned that the ChatGPT maker is breaching the European Union’s General Data Protection Regulation (GDPR), and is opening an investigation.

Specifically, the Garante said it has issued the order to block ChatGPT over concerns OpenAI has unlawfully processed people’s data as well as over the lack of any system to prevent minors from accessing the tech.

The San Francisco-based company has 20 days to respond to the order, backed up by the threat of some meaty penalties if it fails to comply. (Reminder: Fines for breaches of the EU’s data protection regime can scale up to 4% of annual turnover, or €20 million, whichever is greater.)

It’s worth noting that since OpenAI does nt have a legal entity established in the EU, any data protection authority is empowered to intervene, under the GDPR, if it sees risks to local users. (So where Italy steps in, others may follow.)

Suite of GDPR issues

The GDPR applies whenever EU users’ personal data is processed. And it’s clear OpenAI’s large language model has been crunching this kind of information, since it can, for example, produce biographies of named individuals in the region on-demand (we know; we’ve tried it). Although OpenAI declined to provide details of the training data used for the latest iteration of the technology, GPT-4, it has disclosed that earlier models were trained on data scraped from the Internet, including forums such as Reddit. So if you’ve been reasonably online, chances are the bot knows your name.

Moreover, ChatGPT has been shown producing completely false information about named individuals, apparently making up details its training data lacks. That potentially raises further GDPR concerns, since the regulation provides Europeans with a suite of rights over their data, including the right to rectification of errors. It’s not clear how/whether people can ask OpenAI to correct erroneous pronouncements about them generated by the bot, for example.

The Garante‘s statement also highlights a data breach the service suffered earlier this month, when OpenAI admitted a conversation history feature had been leaking users’ chats, and said it may have exposed some users’ payment information.

Data breaches are another area the GDPR regulates with a focus on ensuring entities that process personal data are adequately protecting the information. The pan-EU law also requires companies to notify relevant supervisory authorities of significant breaches within tight time-periods.

Overarching all this is the big(ger) question of what legal basis OpenAI has relied upon for processing Europeans’ data in the first place. In other words, the lawfulness of this processing.

The GDPR allows for a number of possibilities — from consent to public interest — but the scale of processing to train these large language models complicates the question of legality. As the Garante notes (pointing to the “mass collection and storage of personal data”), with data minimization being another big focus in the regulation, which also contains principles that require transparency and fairness. Yet, at the least, the (now) for-profit company behind ChatGPT does not appear to have informed people whose data it has repurposed to train its commercial AIs. That could be a pretty sticky problem for it.

If OpenAI has processed Europeans’ data unlawfully, DPAs across the bloc could order the data to be deleted, although whether that would force the company to retrain models trained on data unlawfully obtained is one open question as an existing law grapples with cutting edge tech.

On the flip side, Italy may have just banned all machine learning by, er, accident… 

“[T]he Privacy Guarantor notes the lack of information to users and all interested parties whose data is collected by OpenAI but above all the absence of a legal basis that justifies the mass collection and storage of personal data, for the purpose of ‘training’ the algorithms underlying the operation of the platform,” the DPA wrote in its statement today [which we’ve translated from Italian using AI].

“As evidenced by the checks carried out, the information provided by ChatGPT does not always correspond to the real data, thus determining an inaccurate processing of personal data,” it added.

The authority added that it is concerned about the risk of minors’ data being processed by OpenAI since the company is not actively preventing people under the age of 13 from signing up to use the chatbot, such as by applying age verification technology.

Risks to children’s data is an area where the regulator has been very active, recently ordering a similar ban on the virtual friendship AI chatbot, Replika, over child safety concerns. In recent years, it has also pursued TikTok over underage usage, forcing the company to purge over half-a-million accounts it could not confirm did not belong to kids.

So if OpenAI can’t definitively confirm the age of any users it’s signed up in Italy, it could, at the very least, be forced to delete their accounts and start again with a more robust sign-up process.

OpenAI was contacted for a response to the Garante‘s order.

Lilian Edwards, an expert in data protection and Internet law at Newcastle University who has been ahead of the curve in conducting research on the implications of “algorithms that remember,” told TechCrunch: “What’s fascinating is that it more or less copy-pasted Replika in the emphasis on access by children to inappropriate content. But the real time-bomb is denial of lawful basis, which should apply to ALL or at least many machine learning systems, not just generative AI.”

She pointed to the pivotal ‘right to be forgotten’ case involving Google search, where a challenge was brought to its consentless processing of personal data by an individual in Spain. But while European courts established a right for individuals to ask search engines to remove inaccurate or outdated information about them (balanced against a public interest test), Google’s processing of personal data in that context (internet search) did not get struck down by EU regulators over the lawfulness of processing point, seemingly because it was providing a public utility. But also, ultimately, because Google ended up providing rights of erasure and rectification to EU data subjects.

“Large language models don’t offer those remedies and it’s not entirely clear they would, could or what the consequences would be,” Edwards added, suggesting that enforced retraining of models may be one potential fix.

Or, well, that technologies like ChatGPT may simply have broken data protection law…

https://techcrunch.com/

Saturday, 11 March 2023

Skills-based hiring continues to rise as degree requirements fade

More employers are leaving behind college degree requirements and embracing a skills-based hiring approach that emphasizes strong work backgrounds, certifications, assessments, and endorsements. And soft skills are becoming a key focus of hiring managers, even over hard skills.

Large companies, including Boeing, Walmart, and IBM, have signed on to varying skills-based employment projects, such as Rework America Alliance, the Business Roundtable’s Multiple Pathways programs, and the campaign to Tear the Paper Ceiling, pledging to implement skills-based practices, according to McKinsey & Co.

“So far, they’ve removed degree requirements from certain job postings and have worked with other organizations to help workers progress from lower- to higher-wage jobs,” McKinsey said in a November report.

Skills-based hiring helps companies find and attract a broader pool of candidates who are better suited to fill positions the long term, and it opens up opportunities to non-traditional candidates, including women and minorities, according to McKinsey.

At Google, a four-year degree is not required for almost any role at the company — and a computer science degree isn't required for most software engineering or product manager positions. “Our focus is on demonstrated skills and experience, and this can come through degrees or it can come through relevant experience,” said Tom Dewaele, Google’s vice president of people experience.

Similarly, Bank of America has refocused its hiring to use a skills-based approach. “We recognize that prospective talent think they need a degree to work for us, but that is not the case,” said Christie Gragnani-Woods, a Bank of America global talent acquisition executive. “We are dedicated to recruiting from a diverse talent pool to provide an equal opportunity for all to find careers in financial services, including those that don’t require a degree.”

Hard skills, such as cybersecurity and software development, are still in peak demand, but organizations are finding soft skills can be just as important, according to Jamie Kohn, research director in the Gartner Research’s human resources practice.

Soft skills, which are often innate, include adaptability, leadership, communications, creativity, problem-solving or critical thinking, good interpersonal skills, and the ability to collaborate with others.

“Also, people don’t learn all their [hard] skills at college,” Kohn said. “They haven’t for some time, but there’s definitely a surge in self-taught skills or taking online courses. You may have a history major who’s a great programmer. That’s not at all unusual anymore. Companies that don’t consider that are missing out by requiring specific degrees.”

A lessening of 'degree discrimination'

From 2000 through 2020 “degree discrimination,” cost employees who were skilled through alternative routes 7.4 million jobs, according to Opportunity@Work, a Washington-based nonprofit promoting workers who are skilled through alternative routes. Alternative routes include skills learned on the job, in the military, through training programs, or at community colleges, for example.

“They are among our country’s greatest under-valued resources — the invisible casualties of America’s broken labor market — where low-wage work is often equated with low-skill work and the lack of a degree is presumed to be synonymous with a lack of skills,” Opportunity@Work explains on its site.

Over the past few years, however, job postings with a degree requirement have dropped from 51% of jobs in 2017 to 44% in 2021, according to the Burning Glass Institute.

Much of the recent shift to skills-based hiring is due to the dearth of tech talent created by the Great Resignation and a growing number of digital transformation projects. While the US unemployment rate hovers around 3.5%, in technology fields, it’s less than half that (1.5%).

While many IT occupations have also seen degree requirements vanish, there remain three where bachelor's degrees are still blocking the more than 70 million workers who have skills gained through alternatives to college, according to Opportunity@Work:

  • Computer & Information Systems Managers: 698,000 workers hold such jobs today — and 19% of them are alternatively trained. Yet, 94% of those jobs require a bachelor's degree.
  • Computer Programmers: 481,000 workers fill these jobs today, 21% of whom are alternatively trained. But 76% of those jobs require a bachelor's degree.
  • Computer Support Specialists: 539,000 workers now have these jobs, with 45% of them alternatively trained. And still, 45% of those jobs require a bachelor's degree.

As many as 70% of organizations have rolled out some kind of workplace technology education in the past year, according to a survey of HR professionals and workers by digital consulting agency West Monroe.

“With this figure in mind, it will be imperative for these organizations to assess their workforce and invest in teaching their workers new skills instead of taking the time, effort and cost to fill a new position,” West Monroe said.

While the cost and time it takes to acquire skills in software development, Java, Python, big data, risk management, and algorithms is high, so is their longevity.

“The payoff for skills in this group is often as long as a person’s entire career,” the Burning Glass Institute stated in a report this month. “Historically, these are the skills that are ripe for reskilling and redeploying talent for the long term.”

Other skills such as risk management and project management also stand out as being particularly durable, yet costly to develop — but they’re not typically as expensive to hire for, according to Burning Glass Institute.

Skills that can be built on an as-needed basis — because the time to learn them is generally low but the return on investment is high — include salesforce, data structures, data analysis, visual design, SAS (software) and cost estimation, the report said.

Many organizations are already implementing internal programs to upskill new and existing employees.

According to research firm IDC, 60% of the Global 2000 corporations have or will have a citizen developer training ecosystem. A significant number of those developers will come not from IT, but from business units looking to digitize processes and using low-code or no-code software tools.

While citizen developers may have little coding knowledge, they’re generally tech-savvy; they’ve worked with spreadsheets and databases, or they’re intimately familiar with corporate technology because they're customer service representatives or business analysts.

“We have seen a surge in demand for particularly digital and tech-related skills,” Kohn said. "A lot of companies have accelerated their digital transformation. So, there’s a huge demand and not enough talent going around."

The change isn't just in private industry
Skills-based hiring practices aren't limited to the private sector. Last year, the White House announced new limits on the use of educational requirements. Over the past year, five governors removed most college degree requirements for entry-level state jobs.

In January, Pennsylvania Gov. Josh Shapiro announced that his first executive order would ensure 92% of state government jobs no longer require a four-year college degree. The move opened up 65,000 state jobs that previously required a college degree and meant candidates are free to compete for those positions based on skills, relevant experience, and merit. Shapiro’s move followed similar actions in other states, such as Colorado, Utah and Maryland. In Utah’s case, 98% of its civil servant jobs will no longer require a college degree.

“Degrees have become a blanketed barrier-to-entry in too many jobs,” Utah Gov. Spencer Cox said in a statement. “Instead of focusing on demonstrated competence, the focus too often has been on a piece of paper. We are changing that.”

And just this week, Alaska Gov. Mike Dunleavy ordered a review of which state jobs could have four-year college degree requirements eliminated as a way to tackle the public sector’s recruitment and retention crisis.

Relying too much on academic degrees is a significant factor in the “over-speccing” of job requirements for tech positions, according to CompTIA, a nonprofit association for the IT industry and its workers. CompTIA's research has found that a notable segment of HR professionals is unaware of the concept of overspending when creating job postings.

In 2022, 61% of all employer job postings for tech positions nationally listed a four-year degree or higher as a requirement. In Pennsylvania, a degree was required in 62% of postings for tech jobs, in Utah, 59%; and in Maryland, 69%.

“That’s not to say a degree doesn’t play some role later in the process,” Kohn said. “Hiring managers are still skeptical of candidates who don’t have a traditional technology background. The difference is they’re allowing people with different backgrounds to get a foot in the door.”

For example, a marketing professional with data analytics skills might not be able to land an IT role. “They may be a great fit for it," Kohn said, "but they just don’t have the background companies traditionally look for."

https://www.computerworld.com/

Artificial intelligence helps solve networking problems

With the public release of ChatGPT and Microsoft’s $10-billion investment into OpenAI, artificial intelligence (AI) is quickly gaining mainstream acceptance. For enterprise networking professionals, this means there is a very real possibility that AI traffic will affect their networks in major ways, both positive and negative.

As AI becomes a core feature in mission-critical software, how should network teams and networking professionals adjust to stay ahead of the trend?

Andrew Coward, GM of Software Defined Networking at IBM, argues that the enterprise has already lost control of its networks. The shift to the cloud has left the traditional enterprise network stranded, and AI and automation are required if enterprises hope to regain control.

“The center of gravity has shifted from the corporate data center to a hybrid multicloud environment, but the network was designed for a world where all traffic still flows to the data center. This means that many of the network elements that dictate traffic flow and policy are now beyond the reach and control of the enterprise’s networking teams,” Coward said.

Recent research from Enterprise Management Associates (EMA) supports Coward’s observations. According to EMA’s 2022 Network Management Megatrends report, while 99% of enterprises have adopted at least one public-cloud service and 72% have a multi-cloud strategy, only 18% of the 400 IT organizations surveyed believed that their existing tools are effective at monitoring public clouds.   

AI can help monitor networks.

AI is stressing networks in both obvious and nonobvious ways. It’s no secret that organizations that use cloud-based AI tools, such as OpenAI, IBM Watson, or AWS DeepLens, must accommodate heavy traffic between cloud and enterprise data centers to train the tools. Training AI and keeping it current requires shuttling massive amounts of data back and forth.  

What’s less obvious is that AI enters the enterprise through side doors, sneaking in through capabilities built into other tools. AI adds intelligence to everything from content creation tools to anti-spam engines to video surveillance software to edge devices, and many of those tools constantly communicate over the WAN to enterprise data centers. This can create traffic surges and latency issues, among a range of other problems.

On the positive side of the ledger, AI-powered traffic-management and monitoring tools are starting to help resource-constrained network teams cope with the complexity and fragility of multi-cloud, distributed networks. At the same time, modern network services such as SD-WAN, SASE, and 5G also now rely on AI for such things as intelligent routing, load balancing, and network slicing.

But as AI takes over more network functions, is it wise for enterprise leaders to trust this technology?

Is it wise to trust AI for mission-critical networking?

The professionals who will be tasked with using AI to enable next-generation networking are understandably skeptical of the many overheated claims of AI vendors.

“Network operations manage what many perceive to be a complex, fragile environment. So, many teams are fearful of using AI to drive decision-making because of potential network disruptions,” said Jason Normandin, a netops product manager for Broadcom Software.

Operation teams that don’t understand or have access to the underlying AI model’s logic will be hard to win over. “To ensure buy-in from network operations teams, it is critical to keep human oversight over the AI-enabled devices and systems,” Normandin said.

To trust AI, networking professionals require “explainable AI,” or AI that is not a black box but that reveals its inner workings. “Building trust in AI as a reliable companion starts with understanding its capabilities and limitations and testing it in a controlled environment before deployment,” said Dr. Adnan Masood, Chief AI Architect at digital transformation company UST.

Explainable and interpretable AI allows network teams to understand how AI arrives at its decisions, while key metrics allow network teams to track its performance. “Continuously monitoring AI’s performance and gathering feedback from team members is also an important way to build trust,” Masood added. “Trust in AI is not about blind-faith but rather understanding its capabilities and using it as a valuable tool to enhance your team’s performance.”

Broadcom’s Normandin notes that while networking experts may be reluctant to “give up the wheel” to AI, there is a middle way. “Recommendation engines can be a good compromise between manual and fully automated systems,” he said. “Such solutions let human experts ultimately make decisions of their own while offering users to rate recommendations provided. This approach enables a continuous training feedback loop, giving the opportunity to dynamically improve the models by using operators’ input.”

AI can assist network support with natural-language chat.

As enterprise networks become more complicated, distributed, and congested, AI is helping resource-strapped network teams keep up. “The need for instantaneous, elastic connectivity across the enterprise is no longer just an option; it is table stakes for a successful business,” Coward from IBM said. “That’s why the industry is looking to apply AI and intelligent automation solutions to the network.”

The fact is that AI-powered tools are already spreading throughout cloud and enterprise networks, and the number of tools that feature AI will continue to rise for the foreseeable future. Enterprise networking has been one of the sectors most aggressively adopting AI and automation. AI is currently being used for a wide range of network functions, including performance monitoring, alarm suppression, root-cause analysis, and anomaly detection.

For instance, Cisco’s Meraki Insight analyzes network performance issues and helps with troubleshooting; Juniper’s Mist AI automates network configuration and handles optimization; and IBM’s Watson AIOps automates IT operations and improves service delivery.

AI is also being used to improve customer experiences. “AI’s ability to adapt and learn the client-to-cloud connection as it changes will make AI ideal for the most dynamic network use cases,” said Bob Friday, Chief AI Officer at Juniper Networks. Friday said that as society becomes more mobile, the wireless user experience gets ever more complex. That’s a problem because wireless networks are now critical to the daily lives of employees, especially in the age of work-from-home, which forces IT to support users in environments over which IT has little to no control.

This is why AI-powered support is one of the most popular early use cases.

“AI is enabling the next era of search and chatbots,” Friday said. “The end goal is an environment where users enjoy steady, consistent performance and no longer need to spend precious IT resources on mountains of support tickets.”

Chatbots and virtual assistants built with Natural Language Processing (NLP) and Natural Language Understanding (NLU) can understand questions that users ask in their own words. The system responds with specific insights and recommendations based on observations made across the LAN, WLAN, and WAN.

“Where this client-to-cloud insight and automation simply was not possible just a few years ago, today’s chatbots can utilize NLP capabilities to provide context and meaning to user inputs, allowing AI to come up with the best response,” Friday said. “This far surpasses the simple ‘yes’ or ‘no’ responses that originally came from traditional chatbots. With better NLP capabilities, chatbots can progress to become more intuitive, to the point where users will have a hard time telling the difference between a bot and a human.”

The early stages of this vision are already underway. AI is currently being used to help Fortune 500 companies accomplish such things as managing end-to-end user connectivity and enabling the delivery of new 5G services.

Gap turns to AI-powered operations and support.

Retail giant Gap’s in-store WLAN networks were originally designed to accommodate a handful of mobile devices. Now these networks are used not only for employee connections to centralized resources but also to connect shoppers’ devices and an increasing array of retail IoT devices across thousands of stores.

“Wireless in retail is really tough,” said Snehal Patel, global network architect for Gap

Inc. As more clients connected to Gap WLANs, a string of problems emerged. “Stores need enough wireless capacity to support innovation, and the network operations team needs better visibility into issues when they arise,” Patel said.

Gap’s IT team searched for a WLAN technology that would leverage the scale and resiliency of public clouds, but the team also wanted a platform that included tools like AI and automation that would enable their networks to scale to meet future demand.

Gap eventually settled on a set of tools from Juniper. Gap deployed Juniper’s Mist AI, an AI-powered network operations and support platform, Marvis VNA, a virtual network assistant designed to work with Mist AI, and Juniper’s SD-WAN service.

Gap’s operations team can now ask Marvis questions, and not only will it tell them what’s wrong with the network, but it will also recommend the next steps to remediate the problem.

“Before Mist, we spent a lot more time troubleshooting,” Patel said. Now, Mist continuously measures baseline performance, and if there’s a deviation, Marvis helps the operation team identify the problem. With enhanced visibility into network health and root-cause analysis of network issues, Gap has been reduced technical-staff visits to stores by 85%.

DISH taps AI to scale 5G for enterprise customers.

Another Fortune 500 company that has adopted AI to modernize networking is DISH Network, which has deployed AI to enable new 5G services. DISH was seeing increasing demand for enterprise 5G services but was having a hard time optimizing its infrastructure to meet that demand.

Enterprise customers were seeking 5G services to enable new use cases, such as smart cities, agricultural drone networks, and smart factories. However, those use cases require secure, private, low-latency, stable connections over shared resources.

DISH knew that it needed to modernize its networking stack, and it sought tools that would help it deliver private 5G networks to enterprise customers on demand and with guaranteed SLAs. This was not possible using legacy tools.

DISH turned to IBM for help. IBM’s AI-powered automation and network orchestration software and services enable DISH to bring 5G network orchestration to both business and operations platforms. Intent-driven orchestration, a software-powered automation process, and AI now underpin DISH’s cloud-native 5G network architecture.

DISH also intends to use IBM Cloud Pak for Network Automation, an AI and machine-learning-powered network automation and orchestration software suite, to unlock new revenue streams, such as the on-demand delivery of private 5G network services.

Cloud Pak automates the complicated, cumbersome process of creating 5G network slices, which can then be provisioned as private networks. By automating the process, DISH can create enterprise-class private networks on 5G slices as soon as demand materializes, complete with SLAs.

 AI-powered advanced network slicing allows DISH to offer 5G services that are customized to each business. Businesses are able to set service levels for each device on their network, so, for example, an autonomous vehicle can receive a very low-latency connection, while an HD video camera can be allocated high bandwidth. 

“Our 5G build is unique in that we are truly creating a network of networks where each enterprise can custom-tailor a network slice or group of slices to achieve their specific business needs,” said Marc Rouanne, chief network officer, DISH Wireless. IBM’s orchestration solutions leverage AI, automation, and machine learning to not only make these private 5G slices possible, but also to ensure they adapt over time as customer use evolves.

How IT pros should prepare for AI.

As AI, machine learning, and automation power an increasing array of networking software and gear, how should individual network professionals prepare to deal with their new artificial colleagues?

While few professionals will miss the mundane, repetitive chores that AI excels at, many also worry that AI will eventually displace them entirely.

“While AI is developing exponentially, it is inevitable network teams will be exposed to AI-enabled devices and systems,” Broadcom’s Normandin said. “As network experts are not meant to become AI specialists, a cultural change is probably more likely to happen than anything else.”

Masood of UST agrees that a cultural change is in order. “Network teams are rapidly evolving from just managing networks to managing networks with a brain,” he said. “Within the context of networking, these teams will need to develop the ability to work collaboratively with data scientists, software engineers, and other experts to build, deploy, and maintain AI systems in production.”

https://www.networkworld.com/

Can Ageing be Prevented? Retro Biosciences says 'Yes, we increase your life by 10 years!'

When a startup called Retro Biosciences eased out of stealth mode in mid-2022, it announced it had secured $180 million to bankroll an audacious mission: to add 10 years to the average human life span. It had set up its headquarters in a raw warehouse space near San Francisco just the year before, bolting shipping containers to the concrete floor to quickly make lab space for the scientists who had been enticed to join the company.

Retro said that it would “prize speed” and “tighten feedback loops” as part of an “aggressive mission” to stall aging, or even reverse it. But it was vague about where its money had come from. At the time, it was a “mysterious startup,” according to press reports, “whose investors remain anonymous.”

Now MIT Technology Review can reveal that the entire sum was put up by Sam Altman, the 37-year-old startup guru and investor who is CEO of OpenAI. 

Altman spends nearly all his time at OpenAI, an artificial intelligence company whose chatbots and electronic art programs have been convulsing the tech sphere with their human-like capabilities. 

But Altman’s money is a different matter. He says he’s emptied his bank account to fund two other very different but equally ambitious goals: limitless energy and extended life span.

One of those bets is on the fusion power startup Helion Energy, into which he’s poured more than $375 million, he told CNBC in 2021. The other is Retro, to which Altman cut checks totaling $180 million the same year. 

“It’s a lot. I basically just took all my liquid net worth and put it into these two companies,” Altman says.

Altman’s investment in Retro hasn’t been previously reported. It is among the largest ever by an individual into a startup pursuing human longevity.

Altman has long been a prominent figure in the Silicon Valley scene, where he previously ran the startup incubator Y Combinator in San Francisco. But his profile has gone global with OpenAI’s release of ChatGPT, software that’s able to write poems and answer questions.

The AI breakthrough, according to Fortune, has turned the seven-year-old company into “an unlikely member of the club of tech superpowers.” Microsoft committed to investing $10 billion, and Altman, with 1.5 million Twitter followers, is consolidating a reputation as a heavy hitter whose creations seem certain to alter society in profound ways.  

Altman does not appear on the Forbes billionaires list, but that doesn’t mean he isn’t extremely wealthy. His wide-ranging investments have included early stakes in companies like Stripe and Airbnb. 

 “I have been an early-stage tech investor in the greatest bull market in history,” he says. 

Young Blood

About eight years ago, Altman became interested in so-called “young blood” research. These were studies in which scientists sewed young and old mice together so that they shared one blood system. The surprise: the old mice seemed to be partly rejuvenated.

A grisly experiment, but in a way, remarkably simple. Altman was head of Y Combinator at the time, and he tasked his staff with looking into the progress being made by anti-aging scientists.

“It felt like, all right, this was a result I didn’t expect and another one I didn’t expect,” he says. “So there’s something going on where … maybe there is a secret here that is going to be easier to find than we think.” 

In 2018, Y Combinator launched a special course for biotech companies, inviting those with “radical anti-aging schemes” to apply, but before long, Altman moved away from Y Combinator to focus on his growing role at OpenAI. 

Then, in 2020, researchers in California showed they could achieve an effect similar to young blood by replacing the plasma of old mice with salt water and albumin. That suggested the real problem lay in the old blood. Simply by diluting it (and the toxins in it), medicine might get one step closer to a cure for aging.

The new company would need a lot of money—enough to keep it afloat at least seven or eight years while it carried out research, ran into setbacks, and overcame them. It would also need to get things done quickly. Spending at many biotech startups is decided on by a board of directors, but at Retro, Betts-LaCroix has all the decision-making power.  “We have no bureaucracy,’ he says. “I am the bureaucracy.” 

https://tinyurl.com/4zsukek9

https://retro.bio/announcement/

Saturday, 18 February 2023

Why We're All Obsessed With the Mind-Blowing ChatGPT AI Chatbot

 There's a new AI bot in town: ChatGPT. Even if you aren't into artificial intelligence, pay attention, because this one is a big deal.

The tool, from a power player in artificial intelligence called OpenAI, lets you type natural-language prompts. ChatGPT then offers conversational, if somewhat stilted, responses. The bot remembers the thread of your dialogue, using previous questions and answers to inform its next responses. It derives its answers from huge volumes of information on the internet.

ChatGPT is a big deal. The tool seems pretty knowledgeable in areas where there's good training data for it to learn from. It's not omniscient or smart enough to replace all humans yet, but it can be creative, and its answers can sound downright authoritative. A few days after its launch, more than a million people were trying out ChatGPT.

But be careful, OpenAI warns. ChatGPT has all kinds of potential pitfalls, some easy to spot and some more subtle.

"It's a mistake to be relying on it for anything important right now," OpenAI Chief Executive Sam Altman tweeted. "We have lots of work to do on robustness and truthfulness." Here's a look at why ChatGPT is important and what's going on with it.

And it's becoming big business. In January, Microsoft pledged to invest billions of dollars into OpenAI. A modified version of the technology behind ChatGPT is now powering Microsoft's new Bing challenge to Google search and, eventually, it'll power the company's effort to build new AI co-pilot smarts in to every part of your digital life.

Bing uses OpenAI technology to process search queries, compile results from different sources, summarize documents, generate travel itineraries, answer questions and generally just chat with humans. That's a potential revolution for search engines, but it's been plagued with problems like factual errors and and unhinged conversations.

What is ChatGPT?

ChatGPT is an AI chatbot system that OpenAI released in November to show off and test what a very large, powerful AI system can accomplish. You can ask it countless questions and often will get an answer that's useful.

For example, you can ask it encyclopedia questions like, "Explain Newton's laws of motion." You can tell it, "Write me a poem," and when it does, say, "Now make it more exciting." You ask it to write a computer program that'll show you all the different ways you can arrange the letters of a word.

Here's the catch: ChatGPT doesn't exactly know anything. It's an AI that's trained to recognize patterns in vast swaths of text harvested from the internet, then further trained with human assistance to deliver more useful, better dialog. The answers you get may sound plausible and even authoritative, but they might well be entirely wrong, as OpenAI warns.

Chatbots have been of interest for years to companies looking for ways to help customers get what they need and to AI researchers trying to tackle the Turing Test. That's the famous "Imitation Game" that computer scientist Alan Turing proposed in 1950 as a way to gauge intelligence: Can a human conversing with a human and with a computer tell which is which?

But chatbots have a lot of baggage, as companies have tried with limited success to use them instead of humans to handle customer service work. A study of 1,700 Americans, sponsored by a company called Ujet, whose technology handles customer contacts, found that 72% of people found chatbots to be a waste of time.

ChatGPT has rapidly become a widely used tool on the internet. UBS analyst Lloyd Walmsley estimated in February that ChatGPT had reached 100 million monthly users the previous month, accomplishing in two months what took TikTok about nine months and Instagram two and a half years. The New York Times, citing internal sources, said 30 million people use ChatGPT daily.

What kinds of questions can you ask?

You can ask anything, though you might not get an answer. OpenAI suggests a few categories, like explaining physics, asking for birthday party ideas, and getting programming help.

I asked it to write a poem, and it did, though I don't think any literature experts would be impressed. I then asked it to make it more exciting, and lo, ChatGPT pumped it up with words like battlefield, adrenaline, thunder, and adventure.

One wacky example shows how ChatGPT is willing to just go for it in domains where people would fear to tread: a command to write "a folk song about writing a rust program and fighting with lifetime errors."

ChatGPT's expertise is broad, and its ability to follow a conversation is notable. When I asked it for words that rhymed with "purple," it offered a few suggestions, then when I followed up "How about with pink?" it didn't miss a beat. (Also, there are a lot more good rhymes for "pink.")

When I asked, "Is it easier to get a date by being sensitive or being tough?" GPT responded, in part, "Some people may find a sensitive person more attractive and appealing, while others may be drawn to a tough and assertive individual. In general, being genuine and authentic in your interactions with others is likely to be more effective in getting a date than trying to fit a certain mold or persona."

You don't have to look far to find accounts of the bot blowing people's minds. Twitter is awash with users displaying the AI's prowess at generating art prompts and writing code. Some have even proclaimed "Google is dead," along with the college essay. We'll talk more about that below.

CNET writer David Lumb has put together a list of some useful ways ChatGPT can help, but more keep cropping up. One doctor says he's used it to persuade a health insurance company to pay for a patient's procedure.

Who built ChatGPT and how does it work?

ChatGPT is the brainchild of OpenAI, an artificial intelligence research company. Its mission is to develop a "safe and beneficial" artificial general intelligence system or to help others do so. OpenAI has 375 employees, Altman tweeted in January. "OpenAI has managed to pull together the most talent-dense researchers and engineers in the field of AI," he also said in a January talk.

It's made splashes before, first with GPT-3, which can generate text that can sound like a human wrote it, and then with DALL-E, which creates what's now called "generative art" based on text prompts you type in.

GPT-3, and the GPT 3.5 update on which ChatGPT is based, are examples of AI technology called large language models. They're trained to create text based on what they've seen, and they can be trained automatically — typically with huge quantities of computer power over a period of weeks. For example, the training process can find a random paragraph of text, delete a few words, ask the AI to fill in the blanks, compare the result to the original, and then reward the AI system for coming as close as possible. Repeating over and over can lead to a sophisticated ability to generate text.

It's not totally automated. Humans evaluate ChatGPT's initial results in a process called finetuning. Human reviewers apply guidelines that OpenAI's models then generalize from. In addition, OpenAI used a Kenyan firm that paid people up to $3.74 per hour to review thousands of snippets of text for problems like violence, sexual abuse, and hate speech, Time reported, and that data was built into a new AI component designed to screen such materials from ChatGPT answers and OpenAI training data.

ChatGPT doesn't actually know anything the way you do. It's just able to take a prompt, find relevant information in its oceans of training data, and convert that into plausible-sounding paragraphs of text. "We are a long way away from the self-awareness we want," said computer scientist and internet pioneer Vint Cerf of the large language model technology ChatGPT and its competitors use.

Is ChatGPT free?

Yes, for the moment at least, but in January OpenAI added a paid version that responds faster and keeps working even during peak usage times when others get messages saying, "ChatGPT is at capacity right now."

You can sign up on a waiting list if you're interested. OpenAI's Altman warned that ChatGPT's "compute costs are eye-watering" at a few cents per response, Altman estimated. OpenAI charges for DALL-E art once you exceed a basic free level of usage.

But OpenAI seems to have found some customers, likely for its GPT tools. It's told potential investors that it expects $200 million in revenue in 2023 and $1 billion in 2024, according to Reuters.

What are the limits of ChatGPT?

As OpenAI emphasizes, ChatGPT can give you wrong answers and can give "a misleading impression of greatness," Altman said. Sometimes, helpfully, it'll specifically warn you of its own shortcomings. For example, when I asked it who wrote the phrase "the squirming facts exceed the squamous mind," ChatGPT replied, "I'm sorry, but I am not able to browse the internet or access any external information beyond what I was trained on." (The phrase is from Wallace Stevens' 1942 poem Connoisseur of Chaos.)

ChatGPT was willing to take a stab at the meaning of that expression once I typed it in directly, though: "a situation in which the facts or information at hand are difficult to process or understand." It sandwiched that interpretation between caution that it's hard to judge without more context and that it's just one possible interpretation.

ChatGPT's answers can look authoritative but be wrong.

"If you ask it a very well-structured question, with the intent that it gives you the right answer, you'll probably get the right answer," said Mike Krause, data science director at a different AI company, Beyond Limits. "It'll be well articulated and sound like it came from some professor at Harvard. But if you throw it a curveball, you'll get nonsense."

The journal Science banned ChatGPT text in January. "An AI program cannot be an author. A violation of these policies will constitute scientific misconduct no different from altered images or plagiarism of existing works," Editor in Chief H. Holden Thorp said.

The software developer site StackOverflow banned ChatGPT answers to programming questions. Administrators cautioned, "because the average rate of getting correct answers from ChatGPT is too low, the posting of answers created by ChatGPT is substantially harmful to the site and to users who are asking or looking for correct answers."

You can see for yourself how artful a BS artist ChatGPT can be by asking the same question multiple times. I asked twice whether Moore's Law, which tracks the computer chip industry's progress in increasing the number of data-processing transistors, is running out of steam, and I got two different answers. One pointed optimistically to continued progress, while the other pointed more grimly to the slowdown and the belief "that Moore's Law may be reaching its limits."

Both ideas are common in the computer industry itself, so this ambiguous stance perhaps reflects what human experts believe.

With other questions that don't have clear answers, ChatGPT often won't be pinned down. 

The fact that it offers an answer at all, though, is a notable development in computing. Computers are famously literal, refusing to work unless you follow exact syntax and interface requirements. Large language models are revealing a more human-friendly style of interaction, not to mention an ability to generate answers that are somewhere between copying and creativity.

Will ChatGPT help students cheat better?

Yes, but as with many other technology developments, it's not a simple black-and-white situation. Decades ago, students could copy encyclopedia entries and use calculators, and more recently, they've been able to use search engines and Wikipedia. ChatGPT offers new abilities for everything from helping with research to doing your homework for you outright. Many ChatGPT answers already sound like student essays, though often with a tone that's stuffier and more pedantic than a writer might prefer.

Google programmer Kenneth Goodman tried ChatGPT on a number of exams. It scored 70% on the United States Medical Licensing Examination, 70% on a bar exam for lawyers, nine out of 15 correct on another legal test, the Multistate Professional Responsibility Examination, 78% on New York state's high school chemistry exam's multiple choice section, and ranked in the 40th percentile on the Law School Admission Test. 

High school teacher Daniel Herman concluded ChatGPT already writes better than most students today. He's torn between admiring ChatGPT's potential usefulness and fearing its harm to human learning: "Is this moment more like the invention of the calculator, saving me from the tedium of long division, or more like the invention of the player piano, robbing us of what can be communicated only through human emotion?"

Dustin York, an associate professor of communication at Maryville University, hopes educators will learn to use ChatGPT as a tool and realize it can help students think critically.

"Educators thought that Google, Wikipedia, and the internet itself would ruin education, but they did not," York said. "What worries me most are educators who may actively try to discourage the acknowledgment of AI like ChatGPT. It's a tool, not a villain."

Can teachers spot ChatGPT use?

Not with 100% certainty, but there's technology to spot AI help. The companies that sell tools to high schools and universities to detect plagiarism are now expanding to detecting AI, too.

One, Coalition Technologies, offers an AI content detector on its website. Another, Copyleaks, released a free Chrome extension designed to spot ChatGPT-generated text with a technology that's 99% accurate, CEO Alon Yamin said. But it's a "never-ending cat and mouse game" to try to catch new techniques to thwart the detectors, he said.

Copyleaks performed an early test of student assignments uploaded to its system by schools. "Around 10% of student assignments submitted to our system include at least some level of AI-created content," Yamin said.

OpenAI launched its own detector for AI-written text in February. But one plagiarism-detecting company, CrossPlag, said it spotted only two of 10 AI-generated passages in its test. "While detection tools will be essential, they are not infallible," the company said.

Researchers at Pennsylvania State University studied the plagiarism issue using OpenAI's earlier GPT-2 language model. It's not as sophisticated as GPT-3.5, but its training data is available for closer scrutiny. The researchers found GPT-2 plagiarized information not just word for word at times, but also paraphrased passages and lifted ideas without citing its sources. "The language models committed all three types of plagiarism, and ... the larger the dataset and parameters used to train the model, the more often plagiarism occurred," the university said.

Can ChatGPT write software?

Yes, but with caveats. ChatGPT can retrace steps humans have taken, and it can generate actual programming code. "This is blowing my mind," said one programmer in February, showing on Imgur the sequence of prompts he used to write software for a car repair center. "This would've been an hour of work at least, and it took me less than 10 minutes."

You just have to make sure it's not bungling programming concepts or using software that doesn't work. The StackOverflow ban on ChatGPT-generated software is there for a reason.

But there's enough software on the web that ChatGPT really can work. One developer, Cobalt Robotics Chief Technology Officer Erik Schluntz, tweeted that ChatGPT provides useful enough advice that, over three days, he hadn't opened StackOverflow once to look for advice.

Another, Gabe Ragland of AI art site Lexica, used ChatGPT to write website code built with the React tool.

ChatGPT can parse regular expressions (regex), a powerful but complex system for spotting particular patterns, for example, dates in a bunch of text or the name of a server in a website address. "It's like having a programming tutor on hand 24/7," tweeted programmer James Blackwell about ChatGPT's ability to explain regex.

Here's one impressive example of its technical chops: ChatGPT can emulate a Linux computer, delivering correct responses to command-line input.

What's off-limits?

ChatGPT is designed to weed out "inappropriate" requests, a behavior in line with OpenAI's mission "to ensure that artificial general intelligence benefits all of humanity."

If you ask ChatGPT itself what's off limits, it'll tell you: any questions "that are discriminatory, offensive, or inappropriate. This includes questions that are racist, sexist, homophobic, transphobic, or otherwise discriminatory or hateful." Asking it to engage in illegal activities is also a no-no.

Is this better than Google search?

Asking a computer a question and getting an answer is useful, and often ChatGPT delivers the goods.

Google often supplies you with its suggested answers to questions and links to websites that it thinks will be relevant. Often ChatGPT's answers far surpass what Google will suggest, so it's easy to imagine GPT-3 is a rival.

But you should think twice before trusting ChatGPT. As when using Google and other sources of information like Wikipedia, it's best practice to verify information from original sources before relying on it.

Vetting the veracity of ChatGPT answers takes some work because it just gives you some raw text with no links or citations. But it can be useful and in some cases thought provoking. You may not see something directly like ChatGPT in Google search results, but Google has built large language models of its own and uses AI extensively already in search.

That said, Google is keen to tout its deep AI expertise, ChatGPT triggered a "code red" emergency within Google, according to The New York Times, and drew Google co-founders Larry Page and Sergey Brin back into active work. Microsoft could build ChatGPT into its rival search engine, Bing. Clearly ChatGPT and other tools like it have a role to play when we're looking for information.

So ChatGPT, while imperfect, is doubtless showing the way toward our tech future.

https://www.cnet.com/

Wednesday, 15 February 2023

How Rust went from a side project to the world’s most-loved programming language

 Many software projects emerge because—somewhere out there—a programmer had a personal problem to solve.

That’s more or less what happened to Graydon Hoare. In 2006, Hoare was a 29-year-old computer programmer working for Mozilla, the open-source browser company. Returning home to his apartment in Vancouver, he found that the elevator was out of order; its software had crashed. This wasn’t the first time it had happened, either. 

Hoare lived on the 21st floor, and as he climbed the stairs, he got annoyed. “It’s ridiculous,” he thought, “that we computer people couldn’t even make an elevator that works without crashing!” Many such crashes, Hoare knew, are due to problems with how a program uses memory. The software inside devices like elevators is often written in languages like C++ or C, which are famous for allowing programmers to write code that runs very quickly and is quite compact. The problem is those languages also make it easy to accidentally introduce memory bugs—errors that will cause a crash. Microsoft estimates that 70% of the vulnerabilities in its code are due to memory errors from code written in these languages.

Most of us, if we found ourselves trudging up 21 flights of stairs, would just get pissed off and leave it there. But Hoare decided to do something about it. He opened his laptop and began designing a new computer language, one that he hoped would make it possible to write small, fast code without memory bugs. He named it Rust, after a group of remarkably hardy fungi that are, he says, “over-engineered for survival.”

Seventeen years later, Rust has become one of the hottest new languages on the planet—maybe the hottest. There are 2.8 million coders writing in Rust, and companies from Microsoft to Amazon regard it as key to their future. The chat platform Discord used Rust to speed up its system, Dropbox uses it to sync files to your computer, and Cloudflare uses it to process more than 20% of all internet traffic. 

When the coder discussion board Stack Overflow conducts its annual poll of developers around the world, Rust has been rated the most “loved” programming language for seven years running. Even the US government is avidly promoting software in Rust as a way to make its processes more secure. The language has become, like many successful open-source projects, a barn-raising: there are now hundreds of die-hard contributors, many of them volunteers. Hoare himself stepped aside from the project in 2013, happy to turn it over to those other engineers, including a core team at Mozilla.

It isn’t unusual for someone to make a new computer language. Plenty of coders create little ones as side projects all the time. But it’s meteor-strike rare for one to take hold and become part of the pantheon of well-known languages alongside, say, JavaScript or Python or Java. How did Rust do it?

To grasp what makes Rust so useful, it’s worth taking a peek beneath the hood at how programming languages deal with computer memory.

You could, very crudely, think of the dynamic memory in a computer as a chalkboard. As a piece of software runs, it’s constantly writing little bits of data to the chalkboard, keeping track of which one is where, and erasing them when they’re no longer needed. Different computer languages manage this in different ways, though. An older language like C or C++ is designed to give the programmer a lot of power over how and when the software uses the chalkboard. That power is useful: with so much control over dynamic memory, a coder can make the software run very quickly. That’s why C and C++ are often used to write “bare metal” code, the sort that interacts directly with hardware. Machines that don’t have an operating system like Windows or Linux, including everything from dialysis machines to cash registers, run on such code. (It’s also used for more advanced computing: at some point an operating system needs to communicate with hardware. The kernels of Windows, Linux, and MacOS are all significantly written in C.)

But as speedy as they are, languages like C and C++ come with a trade-off. They require the coder to keep careful track of what memory is being written to, and when to erase it. And if you accidentally forget to erase something? You can cause a crash: the software later on might try to use a space in memory it thinks is empty when there’s really something there. Or you could give a digital intruder a way to sneak in. A hacker might discover that a program isn’t cleaning up its memory correctly—information that should have been wiped (passwords, financial info) is still hanging around—and sneakily grab that data. As a piece of C or C++ code gets bigger and bigger, it’s possible for even the most careful coder to make lots of memory mistakes, filling the software with bugs.

“In C or C++ you always have this fear that your code will just randomly explode,” says Mara Bos, cofounder of the drone firm Fusion Engineering and head of Rust’s library team.

In the ’90s, a new set of languages like Java, JavaScript, and Python became popular. These took a very different approach. To relieve stress on coders, they automatically managed the memory by using “garbage collectors,” components that would periodically clean up the memory as a piece of software was running. Presto: you could write code that didn’t have memory mistakes. But the downside was a loss of that fine-grained control. Your programs also performed more sluggishly (because garbage collection takes up crucial processing time). And software written in these languages used much more memory. So the world of programming became divided, roughly, into two tribes. If software needed to run fast or on a tiny chip in an embedded device, it was more likely to be written in C or C++. If it was a web app or mobile-phone app—an increasingly big chunk of the world of code—then you used a newer, garbage-collected language.

With Rust, Hoare aimed to create a language that split the difference between these approaches. It wouldn’t require programmers to manually figure out where in memory they were putting data; Rust would do that. But it would impose many strict rules on how data could be used or copied inside a program. You’d have to learn those coding rules, which would be more onerous than the ones in Python or JavaScript. Your code would be harder to write, but it’d be “memory safe”—no fears that you’d accidentally inserted lethal memory bugs. Crucially, Rust would also offer “concurrency safety.” Modern programs do multiple things at once—concurrently, in other words—and sometimes those different threads of code try to modify the same piece of memory at nearly the same time. Rust’s memory system would prevent this.

When he first opened his laptop to begin designing Rust, Hoare was already a 10-year veteran of software, working full time at Mozilla. Rust was just a side project at first. Hoare beavered away at it for a few years, and when he showed it to other coders, reaction was mixed. “Some enthusiasm,” he told me in an email. “A lot of eye-rolls and ‘This will never work’ or ‘This will never be usable.’”

Executives at Mozilla, though, were intrigued. Rust, they realized, could help them build a better browser engine. Browsers are notoriously complex pieces of software with many opportunities for dangerous memory bugs.

One employee who got involved was Patrick Walton, who’d joined Mozilla after deciding to leave his PhD studies in programming languages. He remembers Brendan Eich, the inventor of JavaScript, pulling him into a meeting at Mozilla: “He said, ‘Why don’t you come into this room where we’re going to discuss design decisions for Rust?’” Walton thought Rust sounded fantastic; he joined Hoare and a growing group of engineers in developing the language. Many, like Mozilla engineers Niko Matsakis and Felix Klock, had academic experience researching memory and coding languages.

In 2009, Mozilla decided to officially sponsor Rust. The language would be open source, and accountable only to the people making it, but Mozilla was willing to bootstrap it by paying engineers. A Rust group took over a conference room at the company; Dave Herman, cofounder of Mozilla Research, dubbed it “the nerd cave” and posted a sign outside the door. Over the next 10 years, Mozilla employed over a dozen engineers to work on Rust full time, Hoare estimates.

“Everyone really felt like they were working on something that could be really big,” Walton recalls. That excitement extended outside Mozilla’s building, too. By the early 2010s, Rust was attracting volunteers from around the world, from every nook of tech. Some worked for big tech firms. One major contributor was a high school student in Germany. At a Mozilla conference in British Columbia in 2010, Eich stood up to say there’d be a talk on an experimental language, and “don’t attend unless you’re a real programming language nerd,” Walton remembers. “And of course, it filled the room.”

Through the early 2010s, Mozilla engineers and Rust volunteers worldwide gradually honed Rust’s core—the way it is designed to manage memory. They created an “ownership” system so that a piece of data can be referred to by only one variable; this greatly reduces the chances of memory problems. Rust’s compiler—which takes the lines of code you write and turns them into the software that runs on a computer—would rigorously enforce the ownership rules. If a coder violated the rules, the compiler would refuse to compile the code and turn it into a runnable program.

Many of the tricks Rust employed weren’t new ideas: “They’re mostly decades-old research,” says Manish Goregaokar, who runs Rust’s developer-­tools team and worked for Mozilla in those early years. But the Rust engineers were adept at finding these well-honed concepts and turning them into practical, usable features.

As the team improved the memory-management system, Rust had increasingly little need for its own garbage collector—and by 2013, the team had removed it. Programs written in Rust would now run even faster: no periodic halts while the computer performed cleanup. There are, Hoare points out, some software engineers who would argue that Rust still possesses elements that are a bit like garbage collection—its “reference counting” system, part of how its memory-­ownership mechanics work. But either way, Rust’s performance had become remarkably efficient. It dove closer to the metal, down to where C and C++ were—yet it was memory safe.

Removing garbage collection “led to a leaner and meaner language,” says Steve Klabnik, a coder who got involved with Rust in 2012 and wrote documentation for it for the next 10 years.

Along the way, the Rust community was also building a culture that was known for being unusually friendly and open to newcomers. “No one ever calls you a noob,” says Nell Shamrell-Harrington, a principal engineer at Microsoft who at the time worked on Rust at Mozilla. “No question is considered a stupid question.” 

Part of this, she says, is that Hoare had very early on posted a “code of conduct,” prohibiting harassment, that anyone contributing to Rust was expected to adhere to. The community embraced it, and that, longtime Rust community members say, drew queer and trans coders to get involved in Rust in higher proportions than you’d find with other languages. Even the error messages that the compiler creates when the coder makes a mistake are unusually solicitous; they describe the error, and also politely suggest how to fix it. 

......

http://surl.li/ewows

Wednesday, 14 December 2022

What is SASE? A cloud service that marries SD-WAN with security

 Secure Access Service Edge (SASE) is a network architecture that combines software-defined wide area networking (SD-WAN) and security functionality into a unified cloud service that promises simplified WAN deployments, improved efficiency and security, and application-specific bandwidth policies.

First outlined by Gartner in 2019, SASE (pronounced “sassy”) has quickly evolved from a niche, security-first SD-WAN alternative into a popular WAN sector that analysts project will grow to become a $10-billion-plus market within the next couple of years.

Market research firm Dell’Oro group forecasts that the SASE market will triple by 2026, topping $13 billion. Gartner is more bullish, predicting that the SASE market will grow at a 36% CAGR between 2020 and 2025 to reach $14.7 billion by 2025.

What is SASE?

SASE consolidates SD-WAN with a suite of security services to help organizations safely accommodate an expanding edge that includes branch offices, public clouds, remote workers and IoT networks.

While some SASE vendors offer hardware appliances to connect edge users and devices to nearby points of presence (PoPs), most vendors handle the connections through software clients or virtual appliances. SASE is typically consumed as a single service, but there are a number of moving parts, so some SASE offerings piece together services from various partners.

On the networking side, the key features of SASE are WAN optimization, content delivery network (CDN), caching, SD-WAN, SaaS acceleration, and bandwidth aggregation. The vendors that make the WAN side of SASE work include SD-WAN providers, carriers, content-delivery networks, network-as-a-service (NaaS) providers, bandwidth aggregators and networking equipment vendors.

The security features of SASE can include encryption, multifactor authentication, threat protection, data leak prevention (DLP), DNS, Firewall-as-a-Service (FWaaS), Secure Web Gateway (SWG), and Zero Trust Network Access (ZTNA). The security side of SASE relies on a range of providers, including cloud-access security brokers, cloud secure web gateways providers, zero-trust network access providers, and more.

The feature set will vary from vendor to vendor, and the top SASE vendors are investing in advanced capabilities, such as support for 5G for WAN links, advanced behavior- and context-based security capabilities, and integrated AIOps for troubleshooting and automatic remediation.

Ideally, all these capabilities are offered as a unified SASE service by a single service provider, even if certain components are white labeled from other providers.

What are the benefits of SASE?

 Because it is billed as a unified service, SASE promises to cut complexity and cost. Enterprises deal with fewer vendors, the amount of hardware required in branch offices and other remote locations declines, and the number agents on end-user devices also decreases.

SASE removes management burdens from IT’s plate, while also offering centralized control for things that must remain in-house, such as setting user policies. IT executives can set policies centrally via cloud-based management platforms, and the policies are enforced at distributed PoPs close to end users. Thus, end users receive the same access experience regardless of what resources they need, and where they and the resources are located.

SASE also simplifies the authentication process by applying appropriate policies for whatever resources the user seeks, based on the initial sign-in. SASE also supports zero-trust networking, which controls access based on user, device and application, not location and IP address.

Security is increased because policies are enforced equally regardless of where users are located. As new threats arise, the service provider addresses how to protect against them, with no new hardware requirements for the enterprise.

More types of end users – employees, partners, contractors, customers – can gain access without the risk that traditional security – such as VPNs and DMZs – might be compromised and become a beachhead for potential attacks on the enterprise.

SASE providers can supply varying qualities of service, so each application gets the bandwidth and network responsiveness it needs. With SASE, enterprise IT staff have fewer chores related to deployment, monitoring and maintenance, and can be assigned higher-level tasks.

What are the SASE challenges?

Organizations thinking about deploying SASE need to address several potential challenges. For starters, some features could come up short initially because they are implemented by providers with backgrounds in either networking or security, but might lack expertise in the area that is not their strength.

Another issue to consider is whether the convenience of an all-in-one service meets the organization’s needs better than a collection of best-in-breed tools.

SASE offerings from a vendor with a history of selling on-premises hardware may not be designed with a cloud-native mindset. Similarly, legacy hardware vendors may lack experience with the in-line proxies needed by SASE, so customers may run into unexpected cost and performance problems.

Some traditional vendors may also lack experience in evaluating user contexts, which could limit their ability to enforce context-dependent policies. Due to SASE’s complexity, providers may have a feature list that they say is well integrated, but which is really a number of disparate services that are poorly stitched together.

Because SASE promises to deliver secure access to the edge, the global footprint of the service provider is important. Building out a global network could prove too costly for some SASE providers. This could lead to uneven performance across locations because some sites may be located far from the nearest PoP, introducing latency.

SASE transitions can also put a strain on personnel. Turf wars could flare up as SASE cuts across networking and security teams. Changing vendors to adopt SASE could also require retraining IT staff to handle the new technology.

What is driving the adoption of SASE?

The key drivers for SASE include supporting hybrid clouds, remote and mobile workers, and IoT devices, as well as finding affordable replacements for expensive technologies like MPLS and IPsec VPNs.

As part of digital transformation efforts, many organizations are seeking to break down tech siloes, eliminate outdated technologies like VPNs, and automate mundane networking and security chores. SASE can help with all of those goals, but you’ll need to make sure vendors share a vision for the future of SASE that aligns with your own.

According to Gartner, there are currently more traditional data-center functions hosted outside the enterprise data center than in it – in IaaS providers clouds, in SaaS applications and cloud storage. The needs of IoT and edge computing will only increase this dependence on cloud-based resources, yet typical WAN security architectures remain tailored to on-premises enterprise data centers.

In a post-COVID, hybrid work economy, this poses a major problem. The traditional WAN model requires that remote users connect via VPNs, with firewalls at each location or on individual devices. Traditional models also force users to authenticate to centralized security that grants access but may also route traffic through that central location.

This model does not scale. Moreover, this legacy architecture was already showing its age before COVID hit, but today its complexity and delay undermine competitiveness.

With SASE, end users and devices can authenticate and gain secure access to all the resources they are authorized to reach, and users are protected by security services located in clouds close to them. Once authenticated, they have direct access to the resources, addressing latency issues.

What is the SASE architecture?

Traditionally, the WAN was comprised of stand-alone infrastructure, often requiring a heavy investment in hardware. SD-WAN didn’t replace this, but rather augmented it, removing non-mission-critical and/or non-time-sensitive traffic from expensive links.

In the short term, SASE might not replace traditional services like MPLS, which will endure for certain types of mission-critical traffic, but on the security side, tools such as IPsec VPNs will likely give way to cloud-delivered alternatives.

Other networking and security functions will be decoupled from underlying infrastructure, creating a WAN that is cloud-first, defined and managed by software, and run over a global network that, ideally, is located near enterprise data centers, branches, devices, and employees.

With SASE, customers can monitor the health of the network and set policies for their specific traffic requirements. Because traffic from the internet first goes through the provider’s network, SASE can detect dangerous traffic and intervene before it reaches the enterprise network. For example, DDoS attacks can be mitigated within the SASE network, saving customers from floods of malicious traffic.

What are the core security features of SASE?

The key security features that SASE provides include:  

- Firewall as a Service (FWaaS)

In today’s distributed environment, both users and computing resources are located at the edge of the network. A flexible, cloud-based firewall delivered as a service can protect these edges. This functionality will become increasingly important as edge computing grows and IoT devices get smarter and more powerful.

Delivering FWaaS as part of the SASE platform makes it easier for enterprises to manage the security of their network, set uniform policies, spot anomalies, and quickly make changes.

- Cloud Access Security Broker (CASB)

As corporate systems move away from on-premises to SaaS applications, authentication and access become increasingly important. CASBs are used by enterprises to make sure their security policies are applied consistently even when the services themselves are outside their sphere of control.

With SASE, the same portal employees use to get to their corporate systems is also a portal to all the cloud applications they are allowed to access, including CASB. Traffic doesn't have to be routed outside the system to a separate CASB service.

- Secure Web Gateway (SWG)

Today, network traffic is rarely limited to a pre-defined perimeter. Modern workloads typically require access to outside resources, but there may be compliance reasons to deny employees access to certain sites. In addition, companies want to block access to phishing sites and botnet command-and-control servers. Even innocuous web sites may be used maliciously by, say, employees trying to exfiltrate sensitive corporate data.

SGWs protect companies from these threats. SASE vendors that offer this capability should be able to inspect encrypted traffic at cloud scale. Bundling SWG in with other network security services improves manageability and allows for a more uniform set of security policies.

- Zero Trust Network Access (ZTNA)

Zero Trust Network Access provides enterprises with granular visibility and control of users and systems accessing corporate applications and services.

A core element of ZTNA is that security is based on identity, rather than, say, IP address. This makes it more adaptable for a mobile workforce, but requires additional levels of authentication, such as multi-factor authentication and behavioral analytics.

What other technologies may be part of SASE?

In addition to those four core security capabilities, various vendors offer a range of additional features.

These include web application and API protection, remote browser isolation, DLP, DNS, unified threat protection, and network sandboxes. Two features many enterprises will find attractive are network privacy protection and traffic dispersion, which make it difficult for threat actors to find enterprise assets by tracking their IP addresses or eavesdrop on traffic streams.

Other optional capabilities include Wi-Fi-hotspot protection, support for legacy VPNs, and protection for offline edge-computing devices or systems.

Centralized access to network and security data can allow companies to run holistic behavior analytics and spot threats and anomalies that otherwise wouldn't be apparent in siloed systems. When these analytics are delivered as a cloud-based service, it will be easier to include updated threat data and other external intelligence.

The ultimate goal of bringing all these technologies together under the SASE umbrella is to give enterprises flexible and consistent security, better performance, and less complexity – all at a lower total cost of ownership.

Enterprises should be able to get the scale they need without having to hire a correspondingly large number of network and security administrators.

Who are the top SASE providers?

The leading SASE vendors include both established networking incumbents and well-funded startups. Many telcos and carriers also either offer their own SASE solutions (which they have typically gained through acquisitions) or resell and/or white-label services from pure-play SASE providers. Top vendors, in alphabetical order, include:

  • Akamai
  • Broadcom
  • Cato Networks
  • Cisco
  • Cloudflare
  • Forcepoint
  • Fortinet
  • HPE
  • Netskope
  • Palo Alto Networks
  • Perimeter 81
  • Proofpoint
  • Skyhigh Security
  • Versa
  • VMware
  • Zscaler

How to adopt SASE

Enterprises that must support a large, distributed workforce, a complicated edge with far-flung devices, and hybrid/multi-cloud applications should have SASE on their radar. For those with existing WAN investments, the logical first step is to investigate your WAN provider’s SASE services or preferred partners.

On the other hand, if your existing WAN investments are sunk costs that you’d prefer to walk away from, SASE offers a way to outsource and consolidate both WAN and security functions.

Over time, the line between SASE and SD-WAN will blur, so choosing one over the other won’t necessarily lock you into a particular path, aside from the constraints that vendors might erect.

For most enterprises, however, SASE will be part of a hybrid WAN/security approach. Traditional networking and security systems will handle pre-existing connections between data centers and branch offices, while SASE will be used to handle new connections, devices, users, and locations.

SASE isn't a cure-all for network and security issues, nor is it guaranteed to prevent future disruptions, but it will allow companies to respond faster to disruptions or crises and to minimize their impact on the enterprise. In addition, SASE will allow companies to be better positioned to take advantage of new technologies, such as edge computing, 5G and mobile AI.

https://www.networkworld.com/