What's in the SOSS? An OpenSSF Podcast

Funding the Future: Community Collaboration and the Spirit of Open Source with Mila Zhou

OpenSSF Season 3 Episode 19

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 38:48

Join host Yesenia as she sits down with Mila Zhou, Open Source Program Manager at AWS, to explore the fascinating intersection of finance, strategy, and security in the open source ecosystem. Mila shares her unique journey from forensic auditing to spearheading AWS funding initiatives, breaking down how strategic financial backing transforms vulnerable "long tail" projects and empowers dedicated security champions. Discover how full-time security engineers at foundations are securing critical repositories like PyPI, why community-driven forks like Valkey represent the true spirit of collaboration, and how the OpenSSF Ambassador Program is helping close the gap between developers and security experts. 


Chapters:

  • 00:25 - Welcome & Introductions
  • 01:03 - From Accounting to AWS OSPO
  • 06:26 - A Day in the Life of an OSPO Program Manager
  • 09:53 - Navigating Critical Funding & The Long Tail
  • 13:25 - Valkey and Community-Driven Innovation
  • 15:29 - The Invisible Power of Dedicated Security Engineers
  • 28:46 - Marketing, Non-Code Contributions, and the Ambassador Program
  • 36:25 - Rapid Fire Fun
  • 37:05 - Final Thoughts & Closing


Episode links:

Intro Music & Promotional Soundbyte (00:00)

Free open source software, they are not free as beer, but free as puppy, right? So like, how can you make sure that they are sustained, they are secured, they have the resource to continue to build? That's critical. Those crises like Log4j, like those are also like a wake up call to everyone that like to see how much you rely on open source. So, but in how much you are underfund it. So take action.


Yesenia (00:25)

Hello and welcome to What's in the SOSS, OpenSSF's podcast where we talk to interesting people throughout the open source ecosystem, sharing their journey, experiences and wisdom. So Yesenia, one of your hosts, and today I have the utmost pleasure of having Mila here. I first met Mila when we had worked on the Alpha-Omega project together and truly very excited about today's call, knowing her background, which I won't spoil much.


It's really nice to see the intersection of strategy, security, and sustainability. Welcome, Mila. Please introduce yourself to the audience.


Mila Zhou (01:03)

Hello, Yesenia. Thank you for having me. And it's a great joy. It's a great joy to talk to the audiences here. And my journey is kind of not typical, kind of everywhere. I actually was trained as an accountant. So that's budget planning, that's forensic floor auditing. But then, like, there's always a voice in my mind that's like, you're not going to do what you started. 


So when I started to work, my first job actually is a pricing analyst. I look at the ticket price. I sold ticket for Packers, for MADS, for Bus Cable 2. And it's from there that I got used to look at data to forecast the market trend.


And from there, I moved to AWS, become open source program manager. That was very unexpected. Probably like the focus is very different as a program manager comparing to pricing analyst or accountant, because I would say as program manager, the key there is communication. Like you talk to..the community, talk to service teams to understand the importance of open source, to understand how it's connected with your business. And then what would allow me to leverage my background in business in accounting is that I mostly manage the funding program, the credit program and security program, and both of them have the budget management mindset inside. So that's where like I can really use what I studied before.


Yesenia (03:04)

And I love that going from accounting to now helping us in the open source space. And from what I know is you wear a lot of hats at AWS and within OpenSSF. Can you share your origin story of how you moved into the world of OSPO and open source security?


Mila Zhou (03:30)

Uh, I feel like it kind of, I kind of spoiled a lot in my introduction. Hah! Uh, well, I think really is the mindset is the mindset really is like, I want to look for things I'm interested in. So like I was keep on switching positions, looking for areas that I found like I can keep on learning and open source is the field like ever since I took this job as open source program manager, I never got, I never got bored, but always I feel like, okay, I'm learning something new. That's incredible. And get into this field, I think open source is like an OSPO is solving a lot of, good challenges because open source projects, a lot of time we'll talk to them as like they're probably goods.


So most people rely on them, use them, even without notice that. like free open source software, they are not free as beer, but free as puppy, right? So like, how can you make sure that they are sustained, they are secured, they have the resource to continue to build? That's critical.


And that's also a problem a lot of time people and companies don't think about. But like I think a lot of I would say challenges, crisis, but there's also opportunities for open source to get noticed. It's like those crises like Log4j, 


Yesenia (05:07)

Mm-hmm.


Mila Zhou (05:08)

like those are also like a wake up call to everyone that like to see how much you rely on open source. So, but in how much you are underfund it. So take action to make sure that all those things are in the right place before the next crisis come. I think all those interesting problems that we're trying to solve is fascinating to me, what inspired me to continuously work on that and persuade me that this work is very meaningful.


Yesenia (05:42)

I love that. the open source ecosystem I know when I first got in here, it was just, like you said, it's ever changing. 


Mila Zhou (05:49)

Yes.


Yesenia (05:50)

It's ever changing, like per week with the latest breaches, with the latest technology and everything. And you really never get bored and there's always a challenge and there's, you know, lot of it's a technical challenge, but there's also the people challenge and then there's the financial challenges…


Mila Zhou (06:06)

Yes.


Yesenia (06:07)

Regulatory challenges. It just continues and...I love that we have you here in this space and I get a first eye view at some of the work that you do. For those that don't know, you know, the role of OSPO and what's involved, could you guide us through what a typical day looks like?


Mila Zhou (06:26)

I think it depends on which part of OSPO you are looking at. Mine is less about license, but more about collaboration. So a huge focus on me is to connect with the open source communities through events, through our programs. Like, I think my job, the core part is to make sure that we connect with open source communities and at the same time, make sure that we work with service teams to participate in open source in the right way, in the best way, in a way that fits into the community. Because we notice that open source communities, like they are very different.


Like you talk to Kubernetes and you talk to Python, you talk to PostgreSQL in very different ways. So a typical day of me is like we talk with service teams, understand, OK, what open source activities, upstream activities they are participating in, and we will suggest them like what else we can do. And at the same time, like we do talk with open source communities, ensure that


Um, like how we can help you to ensure that they have the resource they need to continuously to build, to innovate. And then another part of me is like, uh, talking about all those open source stories, uh, like through giving talks at events, through podcasts, through blogs and others, because especially security, I do find that like open source security oftentimes it's less a tool issue, but more an adoption issue. And that takes you to just keep on talking about it, like nudging people. But that's amazing, because that's actually a low hanging fruit. And of course, a very big part is how to streamline our process, our operation, to make sure that we'd the resources we have, can maximize the impact of that and have a strategic plan that we can tie back all the impacts we have in open source to business so that we can really bridge the gap of sustainability.


Yesenia (09:01)

I love that. It’s a lot to do in a day, which I know doesn't take a day.


Mila Zhou (09:06)

Well, like, I will probably be doing a lot more every day.


Yesenia (09:11)

Yeah, but it just goes through the multi-tier thought process that you have to flow through in your day. And I'm sure the context switching from, you know, project X to program Y to foundation W, right? 


Mila Zhou (09:26)

Yeah.


Yesenia (09:27)

And really seeing it from the different layers and levels that is open source, which people don't think about. Let's shift gears into AWS's OSPO. I, from my understanding, you spearhead funding programs at AWS that provide resources to open source projects. When you're thinking about this, what are like key criteria as you're looking for when you're deciding which communities to support?


Mila Zhou (9:53)

Yeah. Well, I think actually Alpha-Omega kind of best describes how we look at that. Like Alpha is that we look at all those obvious ones, critical ones, like Python, Rust, No-Brainer, that you definitely need to support them. Definitely need to make sure that they have the resources to build, to fix, to sustain and secure, right?


And then the other side is you look at all those long tails because you only add secure and sustain as your shortest piece. then, so look at all those who are like, I think there are a lot of critical open source projects that rely on single maintainers or a very small group of people. Then we need to...


Also love to support those projects to ensure that like they do have the resources so we can relieve some weight or burdens on the maintainers. With the credit program, we actually take credits publicly as well as internally. We definitely prioritize those projects. They are not CV backed.


They are critically important to the ecosystem. And they do have a community. If you are a single maintainer project, that's critical, that's widely used, of course we are going to support. But if you are a single developer who are trying to build your brand new open source projects, then probably it'll be hard for us to prioritize you just because there is a long tail of open source projects that we want to make sure that they can get the help.


Yesenia (11:50)

Yeah, and I know from our conversations within the Alpha-Omega group, like, there's like a thousand that's considered critical and there's definitely more.


Mila Zhou (12:01)

I think the number they mentioned is like 10k or 100k something like that. So I was like, wow, that's a lot.


Yesenia (12:10)

Yeah, every year that's a lot. And I know there was a lot of debate in even creating that list. So it's interesting because there's projects that even though it's like 10,000 projects, there's projects that we're not even considering or thinking about or know about really. And it's not because we're not thinking about it. It's just we are thinking about the 10,000 that we already have.


Mila Zhou (12:29)

Yeah, I mean, almost with Alpha-Omega, I think a lot of conversation you also heard is like the Omega part, we actually have kind of have real challenge to connect with them, identify them and meaningfully improve their position. And I felt like we are trying to use AI or like trying to leverage all those security tools and help maintainers to use those tools. And then that comes to the adoption challenge we talked about.


Yesenia (13:10)

Yeah. So it's interesting because you're both in AWS and the Alpha-Omega, but I'm just curious, how do you balance AWS's strategic goals with the need to foster neutral, community-driven innovations within open source?


Mila Zhou (13:25)

I think sitting in my role, I do have the privilege that our goal actually align pretty well. Fostering community-driven innovation wherever we can is my team's strategic goal. So we partner with service teams to persuade them to invest on Upstream and drive the community building. That definitely put me in a kind of position where I can just focus on that, like foster the community-driven innovation. And if we take a look at all the work we have done, I would say Valkey is a very good example. Valkey is a public fork of Redis, but Valkey has been like keeping open source and community building as its core value. And I really looking forward…


I'm super excited about Valkey and I have been helping them to organize events, especially connect the community in China. I found my work is super rewarding in that part.


Yesenia (14:40)

I love that. And especially one of my favorite things about open source is, you know, it's not just within whatever country or city or state you're in and you know, it's impacting different areas in the world. Like you just mentioned China…


Mila Zhou (14:55)

Yeah.


Yesenia (14:57)

So it's pretty, I love that about it. So let's, let’s shift gears a little bit because I think between you and me as Alpha-Omega leaders, this is probably something we can talk about all day. But AO, Alpha-Omega, invested over $7 million last year to secure open source projects. And a lot of it was beyond just patching vulnerabilities. What is the most significant, not obvious outcome that you've seen from your perspective from these investments in your AWS work?


Mila Zhou (15:29)

I love talking most about our investment on staffing. Like we staff Python software security for Seth, for Mike. One is the Python language security engineer in residence, and Mike is the PyPI security and safety engineer. We also sponsored before Samuel in Ruby Central.


And we sponsor a few other staff in Rust, Linux kernel, things like that. I found those work actually super meaningful. A lot of time, there is a lot of invisible work they did. This year, I have a talk that I'm giving. I talked at FOSS Backstage and OCX about the power of dedicated security engineer that's mostly taking Seth and Mike's work as a use case talking about the return of like staff security engineer at foundations. 


I talk with Mike a lot and Seth, but Mike is easier because he's in New York. We can just meet anytime. So Mike told me that like, example, for PyPI, they have about 300 malware every month. That's 300. 


Yesenia (16:58)

Wow.


Mila Zhou (16:59)

Yeah. And then ever since he started, added a feature to PyPI that's quarantine packages. PyPI is one of the only major repositories that has this feature. So that allows him to drop the handle time, respond to malware reports time from days to less than a minute. And then, 


Yesenia (17:31)

Oh wow.


Mila Zhou (17:32)

Yeah, and all the, because he can just quarantine them. Like it does no damage, but like people will not be able to download it. And then he investigates it and the report completely resolved before it was days, but now it just takes like within hours they will resolve the report. So, I think with the staff, you have a full-time eye on your environment. That's unbelievable. And another very funny story he shared with me, I really love that. always, PyBI doesn't allow you to upload package that contains obfuscated code.


But they didn't enforce it because they didn't have the tool for that. And Mike built a tool to detect that, to investigate. And then he found a package that's been like that. And that's actually someone's side business. They were just taking PyPI's resource to store their stuff and then they will direct their customers to come to PyPI to download the package. 


Yesenia (18:51)

Oh, wow!


Mila Zhou (18:53)

Yeah. And Mike just gave them a few months to migrate. And they did that a few months later, the business was gone because they were kind of like using PyPI to compensate themselves for the cost. 


Yesenia (19:10)

Of storage and transfer. Wow!


Mila Zhou (19:)

Yeah. But if you don't have someone working full time on that, you will never see that. I feel like we actually definitely should talk more about how much the power of a dedicated security engineer on that. And adoption problem is also something they can really help a lot. Like with PyPI, like they have the, like the 2FA mediation part. was really like 2FA was there since 2019.


But in the past few years, really like no one cared about adopting it. And then Mike started. They had like email campaign. They went to podcast, write blogs, and then roll out all those programs that make sure that people are aware of that, encouraged to do that and make it as easy as possible for people to just change their habits, adopting to that.


That's also invisible work, but very critical.


Yesenia (20:13)

Yeah, it's a lot of the work that the Alpha-Omega does is very, I would say invisible, you from the audits, from the staffing, I think is one of the biggest. So I agree with that because the efforts and the work that the staff that has been funded through Alpha-Omega, just the impacts, like you said, it's just a dedicated focus on security, whatever they see, whatever they find - has made one of the biggest changes, especially Seth's work in the Python Foundation. And a lot of the information that they do, a lot of the things that they find and they fix within their own ecosystem, my favorite part is that they share it with the community. It's not just like they do the work in silence and it's like magic…


but they're like - It's like, we go: this is how I did it. These are the steps. This is the improvement. This was the impact. Go forth and conquer. And I think I agree with you on that. The staffing is one of the...


Mila Zhou (21:09)

Yeah. I think that's really a beautiful part. Like with Python built trust publishing, and then we see Ruby started to also have the trust publishing process. And then like all those sharing, they're actually really... That's the spirit of open source. Like you stop to reinvent the wheel. But just learn from each other that allows us to innovate fast, that allows us to help each other, especially with security.  There are too many news of attack. 


Yesenia (21:43)

Yeah.


Mila Zhou (21:45)

And everyone feel that we need help. Especially like when you are the one who is attacked. It's not that you don't have the ability to respond, but like there is a lot on you, like emotionally, mentally and physically, and like you have to respond to all those. And it's amazing if you can have a support. I think with Alpha Omega, we also see that we provide a space for like security experts in different ecosystems to collaborate together to solve the problem. So that's actually amazing.


Yesenia (22:22)

Yeah, community collaboration, know, not many, not many people, maybe by the time this podcast is released, we'll, we'll be sharing about the corp of security engineers. It's something I'm working on right now to share insights of that, but just that's one of my favorites really is that corp of security engineers of folks from these different foundations and these different ecosystems coming together and trying to solve one of the bigger open source issues of like, how do we patch these vulnerabilities? How do we help a single maintainer or a volunteer maintainer with a critical project that has, you know, a massive log4j for example, or, you know, the onyx access that happened, the NPM attacks. it's, know, it's job security as a security professional. We'll never, we'll never get bored because every week there's at least three that show up.


Mila Zhou (23:20)

Yeah, that problem sounds super exciting. Very, very interesting. is it a program that you are leading or a conference or a paper you are working on?


Yesenia (23:32)

It's an article that we're going to be releasing, but the group has cadence conversations about once a month, once a month every two weeks. We're meeting to try to really solve and put together that process. And this is folks from industry, I'm not going to call out companies, from the industry and then from the foundations that are coming together. 


And we're looking at how do we manage these vulnerabilities? How do we manage these security fires that happened and how do we put things together so open source can be a little bit more proactive rather reactive.


Mila Zhou (24:09)

Well, let us know. Let us know when it's published.


Yesenia (24:13)

Well, we'll probably have a podcast episode. We'll see. So moving forward, I know we talked about the power of a dedicated open source security engineer. In context of Alpha Omega, like how do we ensure security found funding, you know, goes to those that are going to help maintainers and manage the human infrastructure and not just like code fixers. Like the difference between our dedicated open source security engineers versus our volunteers.


Mila Zhou (24:45)

Yeah. I actually, I like to go back to the Python model, because in the Python model, you actually see, a set that might as the community champion, like, they are the one build a playbook. They are the one like provide suggestions and help to enable volunteers. Seth drove PAPE, I think that's A10 - That actually make the process to become a Python security response team member process become transparent. In Seth words: before the member on the team actually are like the, like it's more trusted group on a mail list, a private mail list.


So the same group of people doing everything like triage, fix bad patch, and then disclaim. But like that model is not sustainable because you put all the burden on a few people and you don't have the process for people to raise hand to join you to help you. And that PEP actually built a standard process and made it transparent. So ever since that, it was approved August last year. And ever since then, they have more than four people join the team. yeah, so I think open source on one hand, we always say that, okay, we don't have people to help. On the other hand, actually, there is a lot of people who are willing to help, but like there is not a very clear way. I think like that actually like with security staffing, you actually enable the volunteers to join you as long as like they are providing the clear process and they are doing the…cheerleader work, to encourage people to join us.


Yesenia (26:42)

I love that because it shows it more as a role model. I know when I started, there was several folks in open source that for me were role models. I was like, I want to be just like them, or I love the work that they do, or how they present themselves. So I agree with the security champion becomes that like that advocate, that visual, that role model, the inspiration for people to like, I really like the work that you do. I like how you do the work. Teach me how you work or how you do.


Mila Zhou (27:15)

Mm-hmm. Mm-hmm. Yeah, yeah, yeah. And I think they represent the spirit of like, yeah, just do it. Because a lot of time in community, people will also ask, can I, could I, do I have the permission? But they are the ones who just do it and then tell you, you can, and I can help you. I think last year when I went to…like last year when I attended the Spring Days at PyCon and then that was the first time I attended the spring today. I don't know if you know Eric in Read the Doc. Yeah, it was super nice. It was super nice encouraging me to like it. you can commit. You can help to like improve read the doc. I was like, wow, I want to try. 


So like that kind of encouraging environment and like especially security expert like Seth and Mike, they can really help you to solve your problem, understand how security works and improve your position. With them being there, that's incredible.


Yesenia (28:13)

Yeah, it's such a great space and the same, and it's not just Seth and Mike, but a lot of the community members are like, you want to join? Let me show you, come. Let's be best friends. So moving over into marketing security, I think that's a good topic that we've kind of clicked on in different areas in today.


Mila Zhou (28:23)

Yes.


Yesenia (28:28)

All right, so moving over into the marketing security section of today's talk, I know we kind of touched on it in different areas today. But why does clear conversation and clear communication matter as much as the technical work that's within the open source space?


Mila Zhou (28:46)

Yeah, I think that's super interesting and like a super interesting topic because in open source a lot of time our focus actually is on the code. Last year, my coworker and I, Lahari and I, we did a talk about how to attract or get more non-code contribution to a project. Because if you really think about how a open source project can grow, can become a successful community, there is a lot more work beyond code. There is documentation. There is marketing. There is community building and all those things. So if we really want to have a sustainable and secure open source project, we should focus on all the other elements. That's not just code. 


And marketing, clear messaging, communication, it's critical for you to send your message out to let the world know who you are, what you are doing, and why they should care about it, and how can they be a part of it. Because really, open source, a core value of it is the community. If you cannot grow a successful community and enable the community to grow and to sustain itself, then probably the project will not last that long.


Yesenia (30:31)

Mmm hmm


Mila Zhou (30:32)

So then it comes back to marketing. In marketing, what's a powerful message? It's usually simple, short, brief, and cut to the core. When you think about Nike, you think about its slogan right away. So that's why I definitely believe that as we are promoting the open source security work, we should pay attention on what's the message we're delivering and how we're delivering it, how it can resonate with our audiences so that we can drive adoption, we can encourage funding, we can make sure that whatever we're doing will continue to get the support.


Yesenia (31:19)

Yeah, like that. You know, it's just, it's interesting when I got into the open source space, it was a lot of like the technical piece. And I'm like, my technical brain's tired from work. Like what else can I do? which is why one of the reasons I co-lead one of the BEAR working group, which is, you know, that, how do we get the word out? How do we get people in? How do we get them to stay? And a lot of it has been just marketing from public speaking engagements, getting people to post on social, that's not just OpenSSF, you know, and really advocate for the community. It's one of the bigger things that I drive folks towards. I'm like, you can just start with that. Just start, get on LinkedIn and talk about the projects. And hey, this week I learned about Rust and Rust is doing XYZ and I think it's pretty cool. And you can join us on this call. It's free, it's public.


Mila Zhou (32:01)

Yes!


Yesenia (32:15)

So I really, I dived in to that side, even though my background's all engineering and cybersecurity. I was like, I can go out in public stage and talk about the great work that other people are doing. Sure. You know, I'll advocate. And then, you know, as you get in and you just get comfortable, then you find your project and dive into it further. But I think it's great to know that the marketing piece within the open source has been growing because of folks like yourselves and others really bringing that advocacy and voice to the maintainers that are already tired. And the last thing I'm sure they want to do is like talk about their work in a marketing standpoint. Like we'll leave you to the technical pieces.


Mila Zhou (32:54)

Yeah, definitely. That's why we come together, to work together. You're not alone.


Yesenia (33:01)

Yes, you’re not alone. Let me be the face and help kind of just drive people towards the great work that you're doing.


And with that, OpenSSF recently launched an ambassador program. So for you, I would like for you to share your general thoughts about how individuals, contributors can shift a security culture with something like the ambassador program, which is somebody that's really putting time into these projects and whatever kind of contributions that they're doing.


Mila Zhou (33:31)

This ambassador program, I think that actually echoes what we just talked about. We need people to get on the stage to share the work. if you look at the criteria for you to apply for the ambassador program, we are looking for people who have been contributing, or participating in the work group or who have the experience to public speaking, share the word, or organizing events like meetup, community management. And all those actually are critical criteria for an open source project to be adopted. We talked that in open source security, a huge part really is adoption.


A lot of challenges, attacks we got, it's not too fancy. It's just like, because you have a weakest link and the weakest link actually is kind of easy to break because you didn't do your security hygiene because like all those basic tools available there, you're not using them. So I think the ambassador program, like from personal perspective, like they will provide you the cohort that where you can have a more systematic understanding of best practices, security positions. 


And at the same time, like you can be the one who share the word to amplify the impact of the tools of the knowledge and help one more developers, maintainers to improve their packages, their software.  I remember last time, GitHub has a open source security, cohort. And then like they did a video record with the log4j contributors. And he talked about like when log4j come, actually they didn't, they were not, they were not security experts. So they, they did patches after patches to fix things because they were not expert. They don't know the best way to solve the problem. They were just trying their best. But, they also found the security cohort was super helpful. So that tells us there is a gap between developers and the security experts. And that ambassador program can hopefully help us to really close the gap or at least make the gap smaller.


Yesenia (36:09)

All right, well, thank you for that. Let's move over to the rapid fire part of the interview. I'm gonna ask you serious questions. First thing that kind of pops into your mind and we'll take it from there. What's your favorite off of the computer activity?


Mila Zhou (36:25)

Reading.


Yesenia (36:26)

What books? 


Mila Zhou (36:27)

I'm reading The Dungeon Crawler Carl. It's a sci-fi,


Yesenia (36:32)

Nice, nice. I'll put that one on my to read list. Sweet or sour?


Mila Zhou (36:38)

Sour.


Yesenia (36:39)

Vim or Mac or Emacs.


Mila Zhou (36:41)

Emacs.


Yesenia (36:42)

Favorite open source mascot?


Mila Zhou (36:44)

PG (PostgreSQL) elephant, "Slonik"


Yesenia (36:47)

Favorite nighttime treat.


Mila Zhou (36:49)

Fruit!


Yesenia (36:50)

And then best way to grow a project, social media conferences or contributors.


Mila Zhou (36:55)

conferences.


Yesenia (36:57)

There you have it folks. That is our rapid fire section. Mila, any last minute advice or thoughts for our audience?


Mila Zhou (37:05)

I definitely encourage everyone to be a part of open source community. Like find something that's…find a project that's like interesting or find a group of people that you like just be together with them because like Open source is so - like we use it everywhere, but we really don't know that we're using that. But like it takes, it takes people to care about the thing that we're using and make sure that it can continuously to exist. And then participating in it, to invest in it is the best way for us to to be a part of it and to ensure that what we like will continue to exist.


Yesenia (37:44)

Yeah, it's definitely needed. It's across so many things I've used. 


Mila Zhou (37:48)

Yeah.


Yesenia (37:48)

Mila, thank you so much for joining us today, for all the knowledge that you shared and all the contributions that you do to the open source community. It's greatly appreciated, seen, and admired. So thank you so much to our listeners, and we'll catch you on the next episode.


Mila Zhou (38:01)

Yeah, talk to you soon. Thank you for having me. Bye bye.


Yesenia (37:48)

Thank you so much to our listeners, and we'll catch you on the next episode.