This episode is also available as a podcast, search for “Open Source Security” on your favorite podcast player.

Episode Transcript

Josh Bressers (00:00) Today, open source security is talking to Erik Möller Director of Programs at the Sovereign Tech Agency. I’m really excited, Erik’s here to talk to us. the Sovereign Tech Agency is I I think one of my favorite programs like on the planet for open source right now. So Erik, why don’t you just, you know, welcome to the show. Tell us who you are and and a little bit about the Sovereign Tech Agency for anyone who might not know.

Erik Möller (00:20) Yeah, great to be here, Josh. I’ve been involved in open source for quite some time. Probably my journey started in like the early 2000s when as a student I got very involved in editing Wikipedia and got sucked into that a lot and eventually joined the board of directors and finally became the deputy director of the Wikimedia Foundation in 2008.

worked there for seven years, helped build up the organization in San Francisco. And after that, I worked for quite some time for the Freedom of the Press Foundation, which builds open source technology for journalists and whistleblowers, and then decided to move back to Germany and found that they were…

for a director of programs at the Sovereign Tech Agency and that’s the role that I’ve been in since April of this year only so I’m still pretty new

Josh Bressers (01:20) Nice.

Erik Möller (01:20) to the agency but yeah what the agency is set up to do is to invest on in critical open source infrastructure on behalf of the German taxpayer and so to really treat it as something that we are

just treating as nice to have, but as something that is a must have investment for governments to make, to think less about open source and the language of grant making, and it would be great if more projects applied for funding through these or those mechanisms, but to think about it more.

through the lens of infrastructure, just like we do invest in roads and bridges, not as an optional investment that we can choose not to make, but everyone understands that if you don’t invest in roads and bridges, then at some point you don’t have them anymore. And that sort of understanding isn’t quite there yet in most contexts when it comes to open source software and other critical based technologies that we rely on.

And that’s kind of what the Sovereign Tech Agency is trying to address. And we do so by directly investing in the development of some of the most critical software components on the planet that are used incredibly widely. Things like curl that are used by everyone who’s developing a website or building a component that

needs to use something like libcurl to access the web. So it’s in everything. And if it breaks, if it has a security vulnerability, it has impacts across a very vast ecosystem of users who rely on it. And so what we do is we basically advertise the fact that we are accepting applications from open source projects that are in this sort of space of critical.

structure and then we evaluate them according to our criteria and we also scout out applications, components, libraries

Josh Bressers (03:31) Nice.

Erik Möller (03:32) that sort of might meet these criteria but might not think to apply for our investment and then we may approach them ourselves and say hey did you know that

this is available to you as an option, is this something that would help your project? So it’s both trajectories, the sort of receiving applications and responding to them and looking for projects and investing in them. And that is called the Sovereign Tech Fund. It’s our flagship program. The organization used to be just called the Sovereign Tech Fund, but that was sort of the first instrument and the sort of name of the whole thing, but then it actually became a real organization.

and it’s on right under the name Sovereign Tech Agency and it’s doing more things now.

Josh Bressers (04:16) Holy cow, that’s a lot to unpack, Erik. I I love it. So I want to start with what I think is the most important aspect of what you’re doing. And and it’s amusing that you used roads and bridges as your analogy because you’re not just funding open source in Germany, you’re funding open source everywhere. Right. So like the the person receiving your funds need not reside in Germany. And I must say,

Like the idea of like Germany going and working on French roads and bridges amuses me to no end when I I you said that in my mind. But

Erik Möller (04:48) Hahaha!

Josh Bressers (04:49) I know, right? But but

Erik Möller (04:51) I mean, that’s

a weird way to think about it, right? Because the one thing that we all learned since the internet came to us in the 90s is that now we have this ability to connect and collaborate globally. And all these projects that we benefit from so much in many ways would not have been possible without that kind of collaboration. If you look back at the early history of Linux and how

Linus back in the day, like, announced it on like a usenet group and found collaborators that way, and who then started to spread all over the world. And that’s kind of how it should be, right? Is that these projects are distributed, they are open, and that’s in the name. So anyone from anywhere at any time should be able to participate. so applying those traditional lenses of national

to these open based technologies makes no sense whatsoever. There are ways in which we do have to think about of course the specific local needs of specific geographies and that has to be incorporated into the design architecture of software. But that’s very different from saying we’re gonna fund the German open source project. It would be like how does that help a German company if the component that

doesn’t happen to be in the very narrow set of projects that sort of meet some kind of weird geographic criteria. That wouldn’t make any sense. it’s always been our position that we have to sort of look at open source as something that is inherently global and distributed and what is much more important in assessing whether it should be invested on is sort of that question of like what happens when it breaks, you know? And is there already a lot

ecosystem of funders that is investing in this this thing because they all don’t want it to break or are we just relying on like the proverbial maintainer in Nebraska or the less proverbial maintainer in like Berlin or Cologne? Like are we relying on like one individual to keep that critical piece of infrastructure going and if that’s the case you know like that indicates a pretty clear structural gap and that’s the sort of area where

investments need to be made, but not just where there’s like this whole maintainer, but also where, you know, there’s like, there might be a corporate ecosystem behind it, but they have a very specific set of focus areas. Maybe they are focused on things that benefit a particular vendor ecosystem or

that benefit their specific corporate needs, but there’s like shared public interests that aren’t addressed. So we look at it through these multiple lenses, like what’s the actual situation of a particular open source projects? Where does it sit in the stack? And does it have the support that it needs to function in the public interest?

Josh Bressers (07:52) Yeah, yeah, I I love that. And I mean, so y I I’ll let you can address this maybe, but but when you explain this, I feel like this is very forward thinking of the German government to be doing this because and and maybe it shouldn’t be, you know, that’s certainly one of the topics to discuss. But I feel like I I’m not aware of anyone else doing something like this. I mean you might be because you’re more plugged into this environment than I am, but this this feels

Normal, right? Like this is critical infrastructure. Every country on the planet, every business on the planet relies on this software. And yet, like as you mentioned, you know, the the single maintainer in Nebraska problem, like it it a shocking amount of our like literal critical infrastructure on the planet now relies on like random people who are definitely overworked. They keep telling us they’re overworked, and we almost other than you guys, I feel like no one’s doing anything about it, which is just mind boggling to me.

Erik Möller (08:51) Yeah, I think it’s beginning to change in good ways. And I feel like a big factor in that change has been sort of the very clearly established need for digital sovereignty. And that’s something that governments around the world are truly waking up to. And there reasons they’re waking up to it now, right? Like the Trump administration is exercising pressures in new ways in its trade relationships with countries around the world.

which is making them aware that they are very, very dependent on a specific combination of the United States and that access to technologies can be limited or cut off. The recent example of like access to anthropic models being restricted through export control mechanisms is like a good case study and where every government in the world is gonna just look at this and go like, holy moly, like.

anything we rely on here can be cut off at any point in time. That’s not a good place to be in. And so that sort of has helped reinforce a sense of urgency, I feel, governments in Europe and around the world that they need to take charge of their sovereignty in the sense of not, like again, not this sort of

simplistic notion of a nationalist IT plan, even though you might find here or there political parties and actors advocating for that. No, it’s more about strategic interdependence, this realization that you can’t go alone, which means you have to figure out who do you work with, are your partners, and how do you make sure that you’re not locked in to a commercial or non-commercial relationship or…

And so that awareness is growing. It’s growing certainly fastest in the context of AI and there’s been a lot of movement in the European Union to sort of build sovereign AI capabilities.

But it’s also in the context of, for example, the use of software and public administration and the general economic dependency on these US big tech companies. So there are initiatives across Europe now to build like sovereign stacks for these particular needs. And there is greater support, including at the level of the European Union’s overall open source strategy and investing in critical infrastructure as well. So what you say?

say about this being very rare and very unusual absolutely was true when we started, it’s beginning to change.

Josh Bressers (11:29) Nice. Okay, so I mean tell me about that change because you mentioned the European Union is doing s are are there other countries starting to create the equivalents of the sovereign tech agency? Or what is that starting to look like on in the at least in Europe?

Erik Möller (11:43) So I’m going to throw a term at you that is fairly typical for the complexity of the European Union, but there is something called European Digital Infrastructure Consortia now, EDICS. This is a new legal instrument that has been established basically to let a bunch of European countries work together. And the idea is just, you know, it’s hard to get every single member state in the European Union to agree on…

what to have for lunch, let alone anything this complicated. So it’s often useful to sort of just get a bunch of countries together and just get going. And the EDIC is like a legal tool that allows countries to do that. They can basically work together multilaterally and…

There is now such an edict that’s called the Digital Commons Edict, which is very worth checking out. And basically, countries like France, the Netherlands, Germany, Luxembourg, Italy are participating through that to pool their resources and make joint investments and shared concerns in this digital sovereignty area. And one of the instruments we’re piloting through that is

European Union sovereign tech fund. So the idea there is to basically see if the instrument that we have now established in Germany can also be used multilaterally with concerns from more member states and stakeholders being taken into account in the funding priorities. And potentially also ultimately if this pilot is successful at

scale of funding. So there are efforts like that where countries are coming together and recognizing, okay, this kind of base technology is really important. It also matters to the stacks that they are putting together for say, open source and public administration. That’s not really our primary area of work. Like we don’t really do focus on like, hey, we build the Google Docs alternative or whatever. But a lot of the

sovereign stack efforts in Europe are focused on that. But when you then look beneath that, if you look at what goes into building like an open source alternative to say, Microsoft 365 or Google Docs that empowers Europe to be independent in its adoption of these tools, then you still find like these same kinds of base technologies that do fall within our mission.

I’m one of

does a ton of work and that’s incredibly important and might be under maintained. And so there are connecting points there. And the shared understanding again that this stuff cannot just be left to its own devices. It needs care, attention, and a recognition of the important work that maintainers have already been doing where a little investment can often have incredible leverage.

Josh Bressers (14:48) Yeah, yeah, for sure. Okay, so let’s talk about that then. What is how do you decide what gets investment? ‘Cause I know like obviously in a perfect world we’d love to say all open source projects should get investment, but you have to draw a line somewhere. You have limited resources, so you have to pick and choose. Like how do how do you how do you pick a favorite child, so to speak, right?

Erik Möller (15:09) Yeah, great question. with the Sovereign Tech Fund, we sort of very early on established a set of criteria that guide much of our work. And what we look at there is stuff like the overall criticality of the infrastructure, which to me to us means

like if it fails, what goes wrong and how widely is it used in practice? Like is something that people are advocating should be used or is something that already is in a hundred thousand or million different places? And does it have, like I mentioned earlier, already like…

significant support to address the key maintenance needs behind it. So as an example, there’s a lot of work that has to happen now to make encryption in a lot of different contexts post quantum safe. And if that work isn’t done, basically every day that passes is a day where data can be harvested potentially for decryption leader.

separate and so mitigation should happen now and there are certainly lots of industry efforts to migrate the kinds of components that the industry relies on but then there might be other efforts that don’t have that level of support libraries that are in a lot of components a lot of systems that also need to be post quantum safe where nobody’s paying for that and so sorting that out like where do we

and like have real leverage and where is the work not already being done but needs to be done urgently that’s kind of what our criteria are designed to do.

Josh Bressers (16:51) Nice, that makes a lot of sense. And then you mentioned earlier that projects can apply for funding and you also go seek them. So let’s just start with the apply. Like what does an application look like if a project is interested in something like this?

Erik Möller (17:04) Yeah, it’s basically what you would expect. You explain the impact that the software has on the world, you basically describe what is it precisely that you want to undertake. Like I said at the beginning, we don’t give grants. So what we can do in the course of the application is work with the

the developers of the application of the component and to figure out like, okay, so what are you actually going to do? For something like the post quantum example, okay, have you already settled the core questions around which algorithms do you need to implement? Do you have the necessary expertise to do that implementation? Do you need help? Are you gonna engage subcontractors to do some of this work? And what timeline are

So these are service agreements that ultimately come out of this. And so you kind of have to imagine it like, say you’re a freelancer and you’re negotiating a contract with a client. That’s sort of the process that follows after the application goes in. And if we agree that in principle the project is sort of falls within the scope of what we would invest in, then we figure out, well, what does that actually look like? What kind of contract can we come to an agreement on?

And it’s really not that different with scouted projects. They go into the same pipeline. It’s just that with the scouted projects, we sort of make the first move. And with the applications, the maintainers make

Josh Bressers (18:46) Okay.

Erik Möller (18:46) the first move. But in both cases, then we sort of have to go into that scoping stage. So it’s not super exciting. It is the sort of normal work of negotiating a contract that ultimately happens.

Josh Bressers (18:59) Okay. Okay, but th but you’re negotiating essentially like a contract to accomplish a specific task versus a here maintainer, here’s some money, just keep working on what you’re doing.

Erik Möller (19:14) That’s right. I mean, we have other programs, as I mentioned in the beginning. most recently, we’ve launched cohorts in both our Fellowship and Standard Networks program. In the Fellowship program, we engage with individual maintainers to essentially give them a longer term contract under which they can

do for instance software development or community management work and those scopes of work are negotiated with a bit more latitude than what I just described where they may describe higher level goals that they want to pursue in the course of their fellowship in the scope and it’s not as sort of heavily milestone based as when we go through this Sovereign Tech Fund because the fellowship is also designed for us to sort of have a mutual feedback loop a little bit more.

throughout the term of a fellow working with us and then make adaptations as needed. And the standards network, which is a new pilot program that we’re running, is designed to bring open source maintainers into the standardization processes and standard development organizations, SDOs like the W3C, the IETF and ISO. And the problem that we’re trying to solve here is that

Participating in science development takes a lot of time and effort.

It’s something that for maintainers who are already overstretched is pretty hard to fit into the the schedule.

Josh Bressers (20:51) Yes.

Erik Möller (20:51) There’s also the cost of travel to meetings and the complexity of these standards bodies and how they work, sort of navigating the various different kinds of bureaucracy that exist. And so the goal here is to essentially address the financial impediment by saying, okay, you’re getting a fixed amount of money every month on the assumption that you’re spending about 10 hours a week on this.

this work, give or take my change over the course of your engagement.

And we also pay for your travel, we pay for your membership in these standards bodies if you need it. And we help you with mentoring and support throughout the contract. And

Josh Bressers (21:33) Nice

Erik Möller (21:33) so that’s a way to facilitate active involvement of open source maintenance and standards work. And as an example of that, you know, one of the members of the cohort is, his name is Casper. He works on

the charging stack for electric vehicles and there’s an open source package called Everest which is pretty relevant and exists under the Linux Foundation umbrella and it’s projects like that that obviously really need to be brought into the relevant standardization processes

Josh Bressers (22:11) Yeah, yeah.

Erik Möller (22:12) and that’s precisely what he’s doing through

Standards Network participation and that’s really something that’s very exciting for us to be able to ensure that the public interest is represented when these incredibly important standards are being written.

Josh Bressers (22:31) Okay,

I want to clarify something and correct me if I get any of this wrong. But a lot of people, I suspect a lot of listeners don’t understand how a lot of the the process works for these standards bodies. And so this one, I’m actually the extremely excited about sovereign tech agency tackling this because I think it’s a huge deal. But so oftentimes it’s large corporations that drive the standards bodies. There’s you you generally have to join some sort of organization.

And you have to pay thousands of dollars generally. U usually, you know, for if you’re like an individual, if you’re a corporation, it’s you know, tens or hundreds of thousands. These meetings, there might be some online, but I would say the vast majority of what like in in the room where it happens, so to speak, you have to actually go somewhere and sit in in a conference room without windows for hours and hours and hours while, you know, you argue about the details of this stuff.

And this is like I understand why the big companies are historically driving this because no one else can afford to be a part of this process just because you have the membership fees, you have the travel fees, you have the time commitments of spending, you you it’s usually a week every quarter or something like that that we’re talking about. Like it is an enormous resource, just just vacuum for anyone involved in this process. So, like this is very, very cool because I know a lot of open source developers that have historically said.

I’m not involved in any of this. Like these people are screwing this stuff up. But I I have no way to even contact them and tell them this stuff, you know? And so this is amazing. I love it.

Erik Möller (24:03) Yeah, thank you. I largely agree with your characterization there. I want to recognize that there are efforts and some standards bodies like W3C to make their processes more accessible, to fund things like scholarships for travel. It’s not all the same. There are efforts to make these more open, but often the costs are just implicit in the way they work.

rotate its meeting location around the world. It’s a lot of international travel that’s just very expensive, very time consuming, very good and important work is being done there. And it’s not a critique in principle

Josh Bressers (24:41) Yeah. Yeah.

Erik Möller (24:42) of the idea that you have to get together in person, but it does just present a real barrier and sort of leads to a bit of a self-selection into who can participate. that’s what we’re looking to address there. And again, like,

To me, that is in a pretty fundamental way, the way that public money can engage meaningfully in the development of the commons, in the development of open infrastructure is by looking at the landscape and saying, okay, this is an area where what we have is in principle not wrong, but it creates these structural imbalances that actually have very unintended side effects on ultimately.

and therefore through targeted intervention we can make a pretty big difference here. That’s the goal.

Josh Bressers (25:34) Yeah, yeah. I I love that. And and yes, I mean I I I will clarify one other thing, you know, you mentioned

These are not they’re not bad people, right? No, we love to crap on standards organizations all the time because they annoy us for some reason or another. But like they’re doing their best. And so I do think having open source people show up to their meetings is going to improve a lot of this a ton because they want to know, right? They want to know what’s happening on the ground. They want to understand how people are using these standards. So this is the I again, this is like a super nerdy and like down in the weeds thing, but I am really, really excited to see where this one goes. Cause I I I feel like and and I guess this is a comment on the Sovereign Tech Agency.

This is not the sort of effort that’s going to make the front page of the newspaper, right? The number of people who probably even understand what this means is a very small number. Just because it’s so it’s such a weird thing. But I feel like it is hugely important. And I think this also kind of it it comes back to what you mentioned about, you know, like roads and bridges type stuff. Like no one wins an award for repaving a road, but if the work doesn’t get done, you know, you’re gonna hear about it. And so this is like road paving

No one’s probably gonna get famous for doing it, but holy cow is it important.

Erik Möller (26:45) It really is and I think it directly ties into the sovereignty stuff in a very real way, right, because ultimately it’s standards and interoperability and portability that help us avoid vendor lock-in and help us avoid situations where, this document format is just the one everyone uses.

because this is the software that everyone uses and therefore this will always be the software that everyone uses and you can probably guess what software I’m talking about.

Josh Bressers (27:12) Indeed.

Erik Möller (27:14) So that’s the sort of thing where standards make a huge difference.

Josh Bressers (27:18) Yeah, yeah. And and and what Erik’s talking about, I have a show I did several months ago where I talked to the Nextcloud folks about some of this because Nextcloud I know is heavily involved in the European Union digital sovereignty, whatever. I can’t remember the name of your like Google Docs slash office three sixty five sovereign instance you’re building, but it’s it’s very cool work and it’s it’s very exciting as well.

Erik Möller (27:41) Yeah, that’s not directly us. Just to be clear again, like we are not the ones who do the open source and the public administration work, but there is a. Yeah, for sure.

Josh Bressers (27:48) Right, not the STA, but it’s a EU, right? Right.

Erik Möller (27:52) And.

We have a sister organization that’s also funded by the same ministry we are, which is called the Center for Digital Sovereignty

Josh Bressers (28:02) Nice.

Erik Möller (28:03) How could you not get confused between Sovereign Tech Agency and the Center for Digital Sovereignty Basically, their purpose is to help in the context of a German public administration to ensure that

we have a real sovereign tech stack and the solution that they’re building, which is called OpenDesk, sort of pulls in various different components. In their case, they’re pulling in things like Nextcloud for the file storage component and then stuff like OpenExchange, as I recall, for the groupware component.

And so like I saying earlier, that’s not directly our work, but it does relate to it because at the end of the day, again, there are key based technologies that are sort of driving a lot of this stuff. And that’s where we come in again.

Josh Bressers (28:59) Yeah,

yeah. Okay. Okay. So we’re kind of winding this one down, Erik, a little bit. So tell me tell me what’s next. Like what are you excited about? What are the things that that are maybe in the works or or coming up that that’ll be I guess interesting to us weird open source nerd types, right?

Erik Möller (29:16) Yeah, I mean, super relevant to this podcast, we do have a program called Sovereign Tech Resilience. And that program is about security and it is about just generally making software more maintainable by addressing long standing and well known issues or issues that can be discovered through audits.

So historically the program has covered bug bounties and security audits. We are currently still operating the bug bounty a little bit in life support mode, but we are hoping to put it fully back online soon. But we also earlier this year ran a pretty large tender for support in a bunch of new areas, including

post quantum encryption mitigation, supply chain security audits, and other areas where we will have expert vendors that we can work with relevant to the EU context. Also, cyber resilience act compliance is another area where we will have experts that we can work with. And the idea here is a little different than with the Sovereign Tech Fund. Here, instead of a project applying for funding with us, they come to us and say, we would like to do a security audit and then we pair

with an auditor from our network and they do the audit, we pay for it. And similar with the other areas that I mentioned. And so we’re expanding that program. We’re hoping to relaunch it later this year. And that will give more open source projects, more access to more resources. And more broadly speaking, of course, AI is always a big topic. It’s a big topic for us in a number of different ways. You’ve seen all the stories about

agents going rogue and breaking out of sandboxes and supposedly controlled security experiments that have made the news recently. I think, broadly speaking, these stories help make one very important argument for us, which is that no matter how good AI gets, you still need human oversight, you still need governance, and you still need stewardship.

There is no world in which humans play a role, in which humans don’t continue to play some of those roles when it comes to open source critical infrastructure. And in many ways, what those kinds of incidents show is that the role of the human maintainer is more important than ever. Like if you saw the recent case where I…

UK based security research institute that’s part of the government. AISA did like an experiment with an agent that then also attempted to do social engineering and attempted to basically submit malicious code. Like that was caught by a human maintainer, you know, like who

Josh Bressers (32:26) Yeah, yeah.

Erik Möller (32:27) noticed the weird activity. I was like, that doesn’t look right. And so

that just underscores the need for investing in human maintainers even as we think about ways that AI may play a positive role in accelerating security work and supporting defensive work. And I think in the AI context, the other question that I ask myself a lot is how can we make this stuff more normal?

this stuff more like open source because right now

Josh Bressers (33:01) Yeah, yeah.

Erik Möller (33:01) it’s not very much like open source at all. Even in the best case you’re working with open weights as they are called but those tend to be basically just blobs that you work with that you maybe manipulate and fine-tune in ways that are specific to your application but you cannot easily reproduce the whole toolchain that was used to create the thing as we can do with any other build artifact in

source. You’re often tied to very specific vendors like NVIDIA to run the thing, as is generally not really acceptable in any other way. We do open source like imagine, like, libcurl said, well, it’s been a blast, everyone. But from now on, you can only run libcurl on the AMD architecture.

Josh Bressers (33:47) Yeah.

Erik Möller (33:48) It’s just not something that we accept in other contexts. So it’s been sort of weird that we have all come to accept it in the AI context.

And so I think a core question from a sovereignty perspective is, to make this stuff more normal, how can we promote reproducibility, verifiability, and in general ensure that the core technologies that are used in AI are built in a way that is vendor neutral, that is cross-platform.

I will say again the word reproducible because I don’t think it can be overstated to me until you have

Josh Bressers (34:25) Yeah, yeah.

Erik Möller (34:27) reproducibility. do not have so many.

Josh Bressers (34:32) Yes, a hundred percent. A hundred percent. That’s man, I know. I We could talk about that for about three hours, I think. So we will leave that one go for the moment. So let’s let’s close it down, Erik. So what do you want people to know? Where do you want them to go? Like what’s what’s the takeaway for ever everyone listening?

Erik Möller (34:53) Yeah, so go to sovereign.tech, that’s our website.

Josh Bressers (34:57) Link in the show notes.

Erik Möller (34:59) that website in the photo also has a link to our newsletter, which I really do recommend people subscribe to. It’s for us the best way to of just notice that a new job is going up or a new program has been launched. the new fellowship cohort is ready for applications. we’re accepting new programs to the fund.

anything like that will go into the newsletters. So if you are a maintainer and you want to keep up, that’s the way to go unless you’re really, really a huge fan of social media, in which case we also tend to post most of the stuff on Mastodon LinkedIn, and Blue Sky.

Josh Bressers (35:39) Indeed. Yes. And your blog is amazing. I love your blog. I’ve got your that’s in my RSS

Erik Möller (35:43) Thank you.

Josh Bressers (35:44) feeds, so it’s always fun to see what’s going on. It’s it’s there are it is so I’m I’m a s as a security person, I would say there aren’t very many news feeds I read that will say it’s like happy news. It’s usually ter something terrible is going on. And and

Erik Möller (35:58) I can see that, yeah.

Josh Bressers (35:59) the Sovereign Tech Agency blog is one of those like, good, I know I can read something positive now when that one pops up. So I love it. Yeah.

Erik Möller (36:07) glad to be a bread spot in your day.

Josh Bressers (36:09) Indeed. All right, Erik. This has been a treat, man. I really appreciate the time. This is I’ve learned a ton. I I imagine everyone else has. And and you’ll have to come back when you’re when you’re up to some new exciting shenanigans. So thank you so much.

Erik Möller (36:22) Likewise,

thank you. Pleasure to be here and yeah, I look forward to being in touch.