You Get Hacked When You Don't Do These Simple Things! (Don't let your life be ruined...)

0:00

this week i'm talking with matthew holland the founder and ceo of field effect security for the past decade matt's been the guy that every three-letter agency in the western world has called when they have a problem that they can't solve before matt started field effect he enabled allied governments to pursue their lawful mandate

0:17

this episode is all about cyber security exploits hacking and defending and while this is a world we all hear a lot about rarely are the people talking as knowledgeable and informed as matt in fact i'd say he's one of the top three in the world at what he does let's dive into the mind of an attacker what's possible and what questions you

0:36

should ask your cyber security vendor along the way we'll talk about snowden what it's like to work at an intelligence agency and of course huawei and national security it's time to listen and learn what are we drinking this is a highland park 30. is there a story behind this it's delicious uh aside from i find it a very nice

0:57

combination of smoky and uh sherry there's not much of a star it's just it is really really good you're the guy who got me into scotch after like three years of trying everybody's favorite scotch you just gave me one i was like oh this is good and then all of a sudden i like scotch but the key is non-pd yeah yeah i mean so so

1:23

you know people in scotland would probably hate me because you know the flavor profiles there that tend to i guess stand out more are smoky and peaty but i just don't like that stuff so everything you would try it up until then was probably just those that's gonna be repeating yeah but man a good cherry whiskey is just amazing

1:39

absolutely amazing it is it's totally it's changed my view of all scotch and whiskey that's great i think it makes you a better person well i try so uh i've known you since what 1999 we met two thousand around that yeah that's crazy yeah world we used to work together at the intelligence agency yep and then that was the most insane period of time

2:06

ever right we're in this small team september 11th happens the world forever changes our team works non-stop for effectively seven years like i don't remember any of us having vacation from 2001 to 2008 other than like a random monday or something yeah i mean firstly i think vacation is probably largely overrated just because

2:31

i'm a workaholic um but yeah no it was a really neat way to start uh i i mean our career was you know just a year or two apart but it is it was definitely a very interesting experience being thrust into a an environment where everything you do contributes much more than you would ever think because coming out of university

2:50

you know you're you want to get a job with a good salary all of a sudden you're you know in our case we're doing things that actually matter to the country that have a very significant outcome and uh it it's like going from zero to mature very very quickly overnight yeah yeah i remember one of the first meetings i had with you

3:13

uh we were trying to figure out how something worked and i stood up you know in my university sort of bravado and i was like oh i'll tell you how this works and then i spent like 30 seconds explaining this thing and then you looked at me and just deadpanned like you're absolutely wrong here's how it works you stood up and for

3:31

45 minutes you worked through like every instruction that happened in the operating system and i was just blown away by your level of knowledge i mean that's kind of you to say um yeah there's probably a factor of uh blown away at how much of a jerk i was in the process of that which i'd like to say has changed but probably

3:50

not so much um but uh yeah it was it was a really uh it was cool i i think the environment that we we got to work in was learning from people the you know for me that that time in my life really defined what a good team was characteristics like you know you care about you know when you learn something you share it with other people

4:12

in the office i remember you know there was five or six of us in particular at one point where you know it was a very large research uh focused group and anytime you learned something or i learned something or one of our colleagues learned something it was a really neat discovery but we took the time to educate each other

4:28

and i think what that fostered was a team that you know a level of trust that i had never experienced in my life i remember you know entering that team being massively humbled uh and you know once once the ego got dealt with uh and you know you could really jump into that environment it just it catapults one's growth and and i

4:50

still look back to those times and and consider myself extremely lucky and um i guess always acknowledge that at that time in my life largely defined who i am today i want to come back to that in a second i remember it it's weird to hear you say sort of like you were humbled you were literally the best in the world at what you do and

5:10

we're going to come back to that throughout this interview is it drinking whiskey you're pretty good at that um i remember showing up like you used to drive me all the time in your mazda what was that the it was mx6 buddy that was that was the smelled like toffee nut latte yeah no that was the that was the dream cyber mobile

5:31

we spent a lot of time together um what made you leave like why so i i i reflect on that quite a bit um just because i get that question often and i i don't think i've ever really had a good answer that that wasn't necessarily uh immature um the ultimate reason i left was because i saw a limit to what i could grow into and what

6:00

the vision of the group i was in uh achieving one like there was a ceiling arbitrarily put on top of that and i'm the type of person that i don't work well when somebody says this is as far as you can go or this is what we're going to do regardless of what the evidence or ideas or good ideas bad ideas whatever

6:21

that that stopped and it was not an environment that i said i can grow here anymore um one of the big indicators of that which um you probably laugh at this but there's a there's a management competition i screwed up the entire the entire uh interview but it was the same problem where somebody would ask you know the

6:39

interviewer would ask me a question and rather than give them the answer of you know i would i would build a team to do this i would request funding to do this i would uh you know reach out to universities to you know bring them into the into the fold so you know that's the answers they wanted to hear what i gave them were the technical responses to the

7:00

questions they were asking so how would you solve this problem my answer was well i would do xyz yeah and then i would do this you didn't play the game no it was just i answered the question and i think that was the first time it really dawned on me that i probably don't fit into the mold that they were looking for so i think that's when i started to the

7:22

i guess the the the ball started rolling on my departure i remember it changed probably about eight months before you left like it started to get more i don't know i don't even know how to word this like when we started it was very fast moving we had a lot of authority a lot of control a lot of decision making power and then

7:42

slowly as we became more successful the irony is like that sort of became less and less over time yeah i remember um having a conversation with one of our mutual colleagues at the time and i remember being very irritated about the um you know the arbitrary handcuffs that were being put on our ability to innovate

8:01

research um you know i remember a contentious time that you and i actually you know stood up at a town hall and got a giant argument with a director right yeah stu if you're listening we're sorry and it was it was very frustrating and i remember that colleague saying this is just part of business man like once you once you're part of a group

8:21

that does something really good and and people take notice and they you know they want to turn that into a larger part of the organization and with that comes what you're seeing now you know formalized you can't work more than this you have different reporting responsibilities and you know at that time i just i just

8:38

wanted to innovate i just wanted to come up with new solutions to the problems that operations were running into you know not being able to do that in its raw form was extremely frustrating see left and we we can't talk about what we did there but we can talk about what you did right after you left and so you started a linchpin

8:57

and you you had an unconventional sort of way of starting that company which is releasing a privilege elevation to get some attention on microsoft you want to talk about that yeah so that that was a that was a funny period so um you know at the time my business partner and i we we thought you know how can we make a splash because when we left

9:18

you know our intention was to um you know augment the uh the world that we left with i guess uh a privatized twist on things so we thought about okay how can we how can we really stir things up a bit and at the time microsoft was releasing uh mandatory driver signing um as part of windows vista which is showing our age right there

9:42

and and you know there's so much hype around it and the way it was being advertised was it was going to be the silver bullet to stop all malware to stop you know anything bad that could be happening and anybody who has spent any time i guess on the offensive side of the house you know was looking at that and saying

10:00

no yeah it'll it'll be it'll make things better but it's not going to be the silver bullet that everybody thinks so we said all right well why don't we just do something kind of funny and um you know show them so what we did was we wrote a tool called uh denwep ativ the name of the company was denwipatsev which is vista poond in reverse

10:21

um you know got a signing certificate under this fake company uh legitimately registered fake in reality uh and released a tool that would load it was an assigned component that would load an unsigned driver and it was not to do anything other than show how easy it is with the most simplest goofiest approach to get around

10:42

this problem and so at the time i was in australia with my business partner starting things up we were working out of a closet really kind of a ragtag uh set up to start and at the time there were people being arrested for violations of the dmca digital millennium's copyright act which you know back at that time was a really contentious thing because it was

11:06

changing what people could or could not do with computers and it was it was a really big deal so when we released that some people are like oh that's kind of neat and other people are you know one person in particular was like this is a violation of the dmca you should be arrested ps it's not really that cool i'm going to go and release a tool that

11:26

um actually exploits ati drivers and nvidia drivers and then basically does the same thing but i've done it a lot cooler uh so so take that linchpin haha right and in reality that that was i remember that guy yeah that was so much worse because i and i don't know if it actually resulted in the revoking of ati and nvidia's

11:48

uh signing certificate but it was something that you know to us it was it was overlooked it was well it was stupid to say that we were violating the dmca and two the response was just so much unbelievably worse and it was a very weird first few months of the company do you ever miss sort of working at the intelligence agency

12:09

i miss people i miss a lot of really good people amazing people it's a very underrated people think that uh all sort of like government employees are lumped in the same same group they're not as we can both attest to you yeah so so i miss the people uh i miss having firsthand exposure to the mission um you know i think back

12:31

to some of the things i got to see and be a part of uh that you know no one will ever know about and and that is really cool it was really neat being a part of that um it it it creates memories that i'm pretty sure if i were to run into somebody 30 years from now on the other side of the world in a bar you know

12:50

immediately there's that connection of like hey we did that that was really cool um so yeah i mean i miss aspects but i don't miss the the handcuffs that uh were were ultimately a part of my departure from there and then when you left do you ever feel like there was they didn't want you to succeed because they wanted you to come back

13:10

was there a part of you that felt like they didn't want to give you contracts they didn't want to i don't know if there's any any interest in me coming back i think there was definitely skepticism as to whether i could succeed which um it's i'm fine with that i mean you know clearly at the time my business partner and i

13:30

were the first ones to kind of make that jump and do that together and there's a lot of skepticism as to whether we should be allowed to do that whether we um are able to do that i remember having a departure interview with a hyatt manager who sat me down and said you're gonna go sell to china you're going to enable china and i looked at them in the

13:51

eye and i said what on earth would make you think i would ever do that that is the most ridiculous thing ever so so i think there was a bit of fear that we would enable you know adversaries of of allied countries um and which yeah i mean in retrospect i can understand i just think it at the time it was a uh it was an

14:09

immature view i remember going to a meeting a couple weeks after you left and they were like oh we're not going to buy anything from him and i was like we're gonna end up giving this guy like 50 million bucks a year i want to say i was closer to reality than they were but i mean so so the idea of going private was taking the handcuffs off and create an

14:29

environment where we put really really smart people together i'm you know part of our recruiting strategy was immediately going after the best people in the community and taking all barriers out of their way and making letting them do amazing things i want to dive into that a little more because you were able to replicate

14:46

i mean an entire wing of an agency if you want you want to say that with 1 10th 1 20th the number of people and have higher output how are you able to do that you just same people you just took them out of the environment and what enabled that largely removing barriers i mean i think that was a big component of it

15:11

you know giving them an environment uh that they could excel in which you know breaks down into what tools do you need do you need to put in a purchase requisition to get what you need or can i just get that for you like that was one of the comments uh from one person i remember early on when they joined they're like

15:28

okay these are the things i'm gonna need to do my job and i was like okay i'll be back in 30 minutes and here's your stuff and the reaction was really like we can just do this it's like yeah go be a genius go produce amazing things so i think that was a big component um i think making it clear that everything that we were doing was as a team

15:50

and i i think as an aside this is one thing i think people who are entrepreneurs sometimes get caught up in that it's about them it's about their journey and the the way i approach it is no we're all in this together i'm really lucky to have you in the company and creating that environment where they knew that they were lucky that i appreciated them

16:08

and that whatever we do we're doing together i think it it's it's a it's an empowering message to build a team around i remember one of the things i took away that i've learned from you is when you started doing that with people and you were like what equipment do you need to do your job and you just go out and get it for them

16:28

and they were astonished by how simple that was and that's something we do with everybody here too we just sort of like what is it you need to do your job to the best of your ability there's a downside to that too which is really interesting because then you lose the excuse of the equipment's the problem if only i

16:44

had the right tools i could like deliver right like so you there's a subtle sort of undercurrent to it which is uh i expect you to be amazing at what you do and keep getting better yeah and i mean i think for some people um sometimes just that belief helps them get there and so you did lpl from what 2007 7 to 18 to 2018 what are some of the

17:07

lessons you learned about growing that when you ended how many people were there so so globally i'm going to lump in the the partner company that we we were sold with but i think we're at the time close to 90 to 100 we sold in 2018 but i i didn't leave until december of 2019. i want to i want to come back to that

17:27

but what are some of the lessons you learned from growing scaling running that company recruiting i think one of the biggest things was i you know starting a company from scratch you know at that time i i had a computer science background i clearly had a lot of experience in cyber security you know i took some accounting courses and marketing courses

17:48

in university so i think there was a bit of a foundation as to okay if you know i remember doing a business plan because that was one thing you did you made a business plan um but one thing through the linchpin experience that i that i got to have was i got to do every job so i got to literally be the janitor i

18:05

got to be the marketing person i got to be the primary sales person i remember doing um you know really challenging sales pitches in front of audiences that didn't even want me in the room because i was you know stamping on their their creative territory i got to write code i got to manage projects um i got to be the the evangelist in the company

18:24

and you know going from there to to field effect with that with that base i think allows me to really you know make decisions that are more informed um it allows me to i guess understand and appreciate all the different parts of field effect and that which is a much more uh we're going to come to feel fast yeah in

18:45

a second um so i think so i think there was that i think um the ability to make decisions uh and be confident in those decisions not get caught in uh you know paralysis of decision making that that um that is something that i think at first i i struggled with but over time uh the ability to filter out the noise and focus on the things that actually

19:07

truly matter um have uh i've really helped so why'd you leave i mean uh right before you left you're the you're the guy every three letter agency and basically the allied world would call when they had a problem they couldn't solve and you would solve it why would you why leave i was going to make a joke about they

19:30

ran out of problems but they didn't no problem's done i'll problem solve actually the same reason i think and this is actually where i think i realized why you know the root factor of why i left cse is it was a similar scenario where uh yeah yeah but it was a it was a change in uh in what i could do was you know i i started to see a ceiling

19:57

on what i could achieve and it became clear to me that um you know i was the square peg trying to fit into the round hole um because of um you know ambitious ambitions and and you know um more creative things that i that i thought we could do and that was that was actually pretty an interesting experience coming to terms that i

20:16

you know i was there the square peg in the round hole because it definitely took time to you know the goal is not going to change yeah yeah and you go through this evolution of like what's wrong with everybody why is nobody on board with this and then uh the realization that oh it's it's me i'm the problem here and then the the appreciation of okay okay

20:38

understanding why that is and i think that that ultimately uh made the transition very easy actually um and and uh it's not something that i look back with at this point with any animosity or anything it was just part of life you exited with more than enough to sort of walk away for the rest of your life and just sort

20:56

of like sit on a boat in costa rica and never have to worry again and then with the sharks there are sharks yeah but then you you start a field effect and how many employees are you now almost 100 you're almost 100 you're entirely self-funded to this point so you basically took all this money you made and you were like oh i want to

21:22

do this again and i'm going to put it all on the line like what went into that thinking um several factors i i think um i i really enjoy solving hard problems and the the the current state of the cyber security industry to say it's a hard problem is an understatement um it is a an unethical show i would say and it it really bothers me uh where

21:48

it's at so i think there's a there's a large part of me that wants to fix that um there's also the aspect of i'm like ultimately a serial entrepreneur and and i remember chatting with my wife like when that transition was happening she asked me like why are you doing this and i was like what else am i gonna do i'm

22:09

just gonna start something else and it's either you know a cyber security company that i'm once again running that i believe can change the world and fix a lot of problems or i can open a coffee shop probably going to take the same amount of time so how about the cyber security firm and how important has she been through this

22:31

she's amazing um i i i don't think i i could ever thank her enough i think the the the formula for for my success um she is a she is a huge part of that um she has a you're a workaholic yes if you if you could if you could sample what makes her run you know who she is and somehow create like a vaccine and inoculate the world like you would

22:53

have world peace uh hands down and that obviously is is a strong statement but she is a phenomenal anybody who knows her um would uh would definitely agree with that i would agree she's amazing she's pretty cool you mentioned sort of the state of the cyber security industry talk to me a little bit about that where

23:10

are we what's it look like i mean there's nobody in the world from my point of view that would have a better aperture into not only how things are how they're sold but also the attacker's mindset in terms of what you're buying worth versus what you're consuming and how it's impacting your business this is the part in the discussion where

23:30

i get angry that's okay we get a lot of scotch so i i think to answer that question the first thing you know we need to do is look at what the cyber security industry actually is because i think that it gets muddled um the the way the public looks at it the way it's reported on it's just everything it's like a grab bag for

23:50

yeah so i think there's there's three groups or or pillars of cyber security there's the one there's the offensive side which we've talked about the the ransomware the intelligence agencies i say offensive but the whole it's that traditional hacking which um you know has largely been glorified thanks to hollywood um mr robot gets it right though i don't

24:10

know i remember in swordfish he said sound like 30 seconds later everything yeah that's largely horseshit isn't that how it works with vr goggles yeah um but if you've ever seen mr robot that that is actually an accurate representation um if you ever uh are curious but it is a you know it is this glamorized uh thing

24:29

that is entirely misrepresented but it is an economy in itself there's an economy behind ransomware and they get paid for it they are successful there's an economy behind intelligence agencies that that is ultimately what drives that dollars and cents on the defensive side the second bit and by the way the first bit only exists

24:48

because uh humans are generally generally horrible at writing software so that wouldn't exist if people are actually good at security models and implementing software the second bit only exists because the first bit exists so that's the defensive side and that is um so let me i guess the best way to describe it is

25:11

as a consumer it is probably the worst experience you could go go through so if you if you're going to go buy some cyber security um are you buying an antivirus that's exactly what i want to do i want to buy it yeah buy some cyber yeah because that that's largely because it's it's it's a we're joking about yeah it's a black box industry right

25:29

a lot of a lot of businesses a lot of people don't know what they're actually buying and that has been exploited by the industry and this is the part where i get angry because none of the solutions out there there are a few that are that are decent but like look at what your options are do i buy an antivirus do i buy any spyware do i buy

25:47

a firewall chain maybe an ids intrusion detection system maybe endpoint uh detect and respond maybe user behavior analysis maybe a network monitor and the way that vendors will you know try to push it forward is they say you actually need all of that which is total crap you do not need all of those things they do not work

26:11

well together so that that whole thing angers me to no end the third bit is a category that isn't actually cyber security i read an interesting article uh recently and it kind of clued me in i was like actually yeah no this third thing or pillar exists that is entirely wrong and it's that bit that happens in you know on the internet

26:34

uh social media that type of thing that isn't actually security related but people like to kind of put a buck or a box around that so an example would be um you know election interference so how do what are the organized um influence in influential campaigns on on social media to to get people to vote in particular

26:55

directions i i do not think that's cyber security but that also gets lumped in so that that is the third bit which is kind of like faux cyber security it's a little bit confusing because then you lose track of what's actually happening but i mean intelligence agencies have been spying on other countries forever one of the things that have changed now

27:13

is not only the amount of consumer data and the value of that data but also that people are spying on companies now as it means to fast track their r d um why invest hundreds of millions of dollars when you can sort of like just hack into somebody else's computer and download all their work and then claim it as your own you know i

27:34

mean it highlights why you know people companies need to take this this problem seriously and and i don't think it necessarily extends just to large companies at this point um you know legal firms uh accountants huge targets huge targets i mean you think about what they're dealing with in regards to

27:52

confidential agreements financials of individuals and companies and and that's one thing i think we've seen over the last couple of years is the the attention that states sponsored groups are going after it's no longer you know the sony's of the world it is now your your your law firms because there's a lot of intelligence value there

28:11

um patent firms i mean there's a lot of intelligence value there so uh the you know how how seriously smaller companies need to take this threat i think has really gone up i i find it super interesting i mean i was talking to kpmg just last week and they were like oh send me this and i was like how do i send it to you and they're like

28:31

just put in an email it's like what what are you talking about like i'm not putting that in an email yeah i sort of compromised with like i used quickforget.com and like uploaded something and was like this is good for like six hours so you better download it but um it's amazing to me that the lack of thought that goes into the information

28:52

you share and how that manifests itself or what's exposed right because if somebody breaks into that computer that whole email change there now the file's there already but the a lot of the emails stored in the cloud it's a lot easier to access than people realize um and what makes you want to tackle this problem like this is like

29:12

the greatest intractable problem ever with tons of competition like the government's doing host-based you have private sector doing all of these things cobbling together solutions like what makes you think that you you can have a better outcome for customers probably arrogance um a joke but that's i mean nobody knows

29:35

the industry better than you do but like seriously there's billions of dollars going on here yeah so i mean if we if we look 20 years ago it's the same problem one of the things i tell people when they join who you know when i hire from intelligence agencies is that be prepared to be disappointed because the problems that you are going to see

29:57

will shock you that you know that they're still out there so the techniques that are you know are 10 years old or the problems that should be 10 years old are still happening today and you know i think that is that's a large referendum on how not good the cyber security industry is at actually trying to solve the problem and

30:18

if i look at you know the vendors out there i'm not going to name any specific competition but what i see is a sales strategy that is like a warped used car salesman strategy and that's probably an insult to use car salesmen out there because it's it's much worse um that it's it's all about the transaction it's all about you know getting getting

30:39

that done taking the customer's money and saying good luck and that isn't results we're not responsible for anything yeah and that's not making anything better how should that work like how do people buy cyber isn't it the i wasn't on sort of like the acquisition of cyber side but like this gardner quadrant does that

31:00

sound familiar yeah yeah so that that is i guess a measuring system a measuring stick to help the vendors or customers or prospective customers um companies i guess is a better term uh to to you know guide them in buying what they they may or may not need there are a few problems with that the gardener quadrant system is

31:22

often outdated we we were for example field effect was marketing a managed detect and response service well before it was defined in gartner and ironically at the time we had a hard time you know gaining traction because that's always looking at like existing sort of technology and threats and looking backwards saying like oh these

31:40

people accomplish this but not looking forward in terms of where the industry's going yeah so so that that you know that that is a it is a useful classification system it is just behind the curve continuously the second thing is i don't think uh businesses actually necessarily know what they're looking for um yeah like how would you

31:59

be educated if you're like a law firm an accounting firm you get 100 employees you don't have like a cyber guy or girl and like how do you how do you go about doing that so so i mean that's that's ultimately the the realm that you know field effect sits in the the the small to medium business space because you know it is infeasible for every

32:22

company to have an i.t team and in in our experience i mean an i.t team is good um they have expertise but they may not necessarily be you know security experts is is that kind of like shopify for cyber security because shopify is really arming you you don't have to worry about building a store you don't have to worry about

32:44

managing inventory you don't have to worry about they're arming the rebels if you will against amazon like are you giving world-class technology to small and medium-sized businesses as a means to like you don't really have to know all the ins and outs of cyber security but then it becomes trust based like why would i trust you over another

33:02

vendor uh that's a great question i mean i i think trust takes time you don't just uh magically get trust right out of the gate and i think that is a that is something we put a lot of time into building we take time to create a customer relationship uh ask customers what their needs are what are their problems and then

33:22

um you know tell us about your network how can we help you um and you know early on in that process i think it becomes clear that we're not just out trying to sell software in a commoditized way the first thing we do is do an external view of the network and identify okay here's a problem right here we want to help you fix problems it's not just here is a

33:43

solution that you have to run with it is all about us helping you be better fixing problems and sustaining that moving forward and that is largely a component that i don't think most vendors in the cyber security industry get they are more interested in showing you check out this really cool interface which you know no one in your company is

34:05

probably going to know how to use and then if you don't see something it's like oh it's on our fault it was in the interface somewhere and you didn't yeah you didn't see the logs so why why didn't you action that and then that i mean i i think the assumption that the average business is going to care about cyber security

34:23

is is a false uh a false starting point because businesses you know you buy your computer hardware you get your i.t set up if i if i'm a business and i you know out there i'm not starting my day off thinking oh i can't wait to buy some cybers or understand some you know cyber security and um that is the baseline right that that i

34:45

think for uh you know an effective solution that's what you're dealing with you're you're dealing with a company or a customer that doesn't care about cyber security but you need to help them the baseline of the the interface could be an office manager not somebody who has a computer science degree or somebody who has

35:03

any background or interest in cyber security so having a system that you know is set up and built and implemented to work with people who don't necessarily care or will care or or should even care because that's not their job that's what we do well that's a good point right like you're not trying to make them carry you're just trying to

35:25

say this isn't a worry for you anymore yeah yeah and when something comes up here's a very concise way of dealing with it not a you know a series of links go google this learn how to implement a vpn learn how to use a firewall or how to patch your system um it's a it's a guided approach to this is specifically what you need to do

35:44

let's flip that around and uh what people don't often see which you can add uniquely is sort of what's the mind of the attacker like if you're looking at acquiring um valuable information from a company walk me through that whole process like how do you think about that how do you go about doing that what does that look like

36:08

so initially an attacker is going to profile the target and that can look like different things so if you know the the target has online services they'll probe those services to see what's there uh are there any email addresses on your website that are really easy to uh you know identify what type of social media presence is there

36:28

um you know and that ultimately will lead into typically a social engineering campaign uh either in the form of you know an email that is received that looks really normal that you want to trust and hopefully will get you to click on something or double-click in an attachment or it'll go to your phone you click on that and

36:48

that exploitation occurs the other approach that we see quite a bit is uh people don't use multi-factor authentication with um just a basic email setup so brute force brute forcing passwords works somebody gets in will scope out your inbox and and see what's there who are your customers uh what what's your routine and then they will

37:12

uh perform perhaps a financial redirection so in that case they would get an idea of what your entire portfolio is and email all of your customers and say um hey here's your new payment instructions and they will have all the outstanding invoices already uh you know listed and ready to go so they can immediately

37:29

um you know say you know you owe us x amount this is where i want you to send this money now and that is remarkably and surprisingly effective yeah and hard to track down even though there's like a total with bank accounts we'll come to cryptocurrencies and sort of run somewhere later but with bank accounts it's it's easy to see

37:48

where the money goes it's really hard to get the money back once it's gone yeah and that's conventional sort of attacks right versus um sort of somebody like boeing or general electric or sort of cisco who would have a lot more valuable ip and probably worth a zero day or sort of like developing a custom exploit can you walk me through like how

38:10

that would work yeah specifically of course so like you're interested in more of the pointy end of the stick yeah yeah so the uh you know the way the way exploitation works is um at least in specific platform you'd like to walk through uh let's walk through windows windows okay um so if you're going after a windows box uh

38:33

it's either a server or workstation and typically servers if they're internet facing gives you the ability to hit it direct so if you have a zero day and um you know a web server for example that is something you can directly access and and exploit that that is a very um direct way i guess of of attacking the other approach is

38:54

uh you you have a windows client you're sitting at your desk you have a laptop and you're just you know typing away and you get an email uh that is probably the most common way and what what that looks like is again back to the the scenario where you're trying to convince somebody uh to trust an email so they click on a

39:12

link what happens like walk me through i click on this link yeah yeah so so the first thing that happens is uh you know the browser would be exploited so whatever browser renders that link the uh a web browser exploit would basically gain code execution and and modern browsers are definitely getting better at per you know protecting against that type of

39:32

thing so you know chrome is every browser has a sandbox now most browser flavors are uh you know some measure of chrome so even microsoft edge is now based on uh chromium so and so is brave and so is like firefox isn't there is it no no firefox is not okay i think they're still rocking their own their own setup for

39:52

now they just fired their threat team oh jeez i didn't even hear that um so so yeah it gains execution inside the browser and then the goal is then to uh gain privilege in the uh in the in the operating system so that could constitute a sandbox escape to get out of that browser sandbox uh a privilege escalation to ideally

40:15

execute at a higher privilege level to to basically nullify any security on the host and ideally get execution in the operating systems kernel and once you're there um it's largely game over so what but you get kernel on an individual host walk me through how you like how does that become network access to at a super admin level or

40:37

so so once you have that you you there really is no barriers to do to doing anything on that host so if you want to open up comms back to mothership you can do that if you want to access a whole bunch of data you can do that but how do you open up comms like isn't everybody monitoring these links now in terms of like how you expel

40:57

information uh no no i'd say so so we're kind of diving into why this is actually a really hard problem and why any specific pillar doesn't work so if if you only buy a network monitoring solution you won't see really anything that i've described thus far if you buy an endpoint only solution there may be hints of things that have

41:19

happened depending on the um sophistication of the endpoint solution but as soon as it gets so uh particularly deep in the kernel you're not going to see that so it's a very challenging position that that's why having a holistic approach is so important you need network you need endpoint so if you get by either one of those things

41:42

the other will pick it up and how does that work like on a particular client i can understand how those things communicate but then how do you how do you take an attack on one company and then translate that into a defense on another company with something you haven't seen before so i guess largely that depends on how well

42:02

the cybersecurity solution is implemented if it is part of a network where you can dynamically signature an attack quickly and create an artifact we'll say that can be applied across the network of other customers that is a way to combat against that i mean the zero day problem is is something that's always going to be there

42:24

i think this is something a lot of vendors don't actually realize that no matter how much you lock down your operating system there's always going to be a creative group out there that does things better that can get around it i mean if you look at apple apple iphone for the past i don't say decade they've been adding an increasing number of security

42:47

mechanisms into the operating system that largely limit an operator to only being able to do specific things but that is largely crippling from a security standpoint because all you need to do is get around these set of mitigations and you now can own any apple device in the world and a really scary thing is recently a company called vupin

43:10

uh that isn't you know they buy zero-day exploits um not sure where they go after that but what they do is i can speculate but uh they buy zero day exploits and where um they they posted something recently where they said we're we're full up on ios privilege escalations um we get enough yeah and if that isn't a wake-up call

43:33

uh to to apple i don't really know what would be that's that's basically the industry is saying yeah your operating system is not as secure as you think it is that it's kind of like the great wall theory right like you have this big wall around but once you're on the inside of that wall it's like there's no defenses after that

43:51

yeah and that perfectly describes apple that actually describes every mobile operating system out there well android talk to me about the specific challenges with android because they have their they have like a host of other problems that aren't common occurrences that have to be dealt with like everybody has a different version

44:10

of android that they're running it's always out of date it's yeah so android's an interesting beast because um a lot of it's the most common platform yeah yeah and it gets a lot of positive um how do i say reviews but um attention out there because it is an open platform you know you can download nightmare yeah you can download the

44:29

source code and you can see what's running and that is a component of a secure operating system i guess that you know the average person could go out and audit what's there the average person could if they want take that download it pilot put it on their phone and maybe add some additional bells and whistles the concept is very noble the reality of

44:47

it is not so great because what we have today is there is the main android branch that you know evolves that google releases android 11 just got recently released and vendors will take that and they will adopt it as is or they will customize it or they will um you know take particular parts of the uh what's um called a change

45:13

history it's basically the the changes that have been made to the code base and when that when that is taken in context with um vulnerabilities the fixes may or may not make it in so you could have you know the latest samsung phone running android 11 that doesn't actually have all of the security fixes that the main

45:34

android branch has right because somebody's accepting or rejecting yeah yeah and i can tell you that 100 certainty um i have not looked at android 11 but what i have experienced over the past two decades there are problems in the samsung version that have been missed because humans again are part of the equation uh and you know on the list it'll say

45:55

you know cv efix cb fixed but those fixes aren't there bad guys or attackers will know that and they will exploit that and there is literally nothing you can do to defend against that if you are a target and that is a pretty frightening proposition so you would rather go up against an android phone than an iphone if you were

46:16

attacker uh that's an interesting question i think the odds of getting uh exploited are higher on android although the um the nature of android also creates a scenario where there's so many different flavors of android it makes it much more difficult to create a mass attack whereas on ios because it's the same

46:39

version of the of the operating system across the board on every device if you can find a problem in that you get all those devices on android um you get the nuances i put nuances in quotes of some of the decisions that individual vendors will make that that makes it very difficult to take an attack on samsung and apply it to i

46:58

don't know google phone or a zte phone so it's i would say generally it's the security position on android is is is worse um but um you know the the odds of being hit in a mass attack are potentially lower but if somebody is targeting you i would say that the odds of you know you them being successful against you are higher on android for

47:20

sure as phones or you know if you want to call them personal computers it's like those are our personal computers right more so than we think become more prevalent they'll become the surface of which gets commonly attacked walk me through like how does phone exploitation even work like how do you is it the same sort of system

47:42

that you would use for windows or apple is it different like how do you attack the phone you have this thing on you all the time it's got a mic it's got a camera so the unfortunate answer is the exact same way you'd go after every other type of computer uh ios is just an operating system android is just an operating system there's there's no

48:02

there's no special features that make it impervious to attack there there are different security mechanisms in place that an attacker needs to get around but it's the same deal so if i'm going after your windows laptop and the scenario that i described where i send you an email um on on mobiles uh it's the same thing

48:21

and it's actually worse in some cases um about a year ago a company out of israel called um nso nso group they got busted for having a whatsapp uh zero zero click mechanism so there's some quick lingo dive here uh one click versus zero click one click is you have to social engineer somebody to the point

48:44

where they can click on a link and exploit the phone zero click is where there's nothing you can do you are just owned and you have no idea by you don't even see a message like you're just yeah no decision on your part you're sleeping in the middle of the night in this case uh nso group um you know sends you a malicious bit of content via

49:04

whatsapp assuming they've been able to you know figure out your whatsapp id uh and then exploit your phone and congratulations uh that that whole step of getting around sandboxes privilege escalation that it's all the same concepts but in this case it is a direct way to attack a device that you own so previously like tools like that were

49:25

only in the hands of governments and they weren't generally targeting individuals or small corporations has that changed i think the accessibility is different there's like an asymmetry to this right like some some person some teenager guy or girl sitting in there garage can literally have a massive disproportionate impact yeah i mean

49:51

there's there's uh i'm sorry i'm thinking of the the attack on twitter recently and how how you know that was a social engineering yeah yeah and and you know in the context of going after mobiles i mean that that's that's it all comes down to the accessibility of the attack factor and the the creativity of the person

50:12

running the the attack vector so i was thinking you know with that with nso group you know there's there's a lot of articles on them about who they sell to you and don't sell to um they have a whole group now our whole internal group within the company that i've read uh dedicated to making sure they make ethical decisions

50:31

i don't personally trust that they're making it i think why do you need a group to make ethical decisions i mean that's an indication that you know ethics weren't a component in the founding of the company uh but that's a probably a whole other discussion um but yeah i i think you know the the the point that the attacker and what

50:52

that looks like is is you know it it's much more plausible that it is not an intelligence agency um you know you look at the the the groups that are running out of uh you know other countries i'll pick on india a little bit just because i've seen some you know some ip reports on you know some some problems coming out of there but

51:13

firms of social engineering efforts um you know it doesn't take a lot to go after android that's two years old and how many i haven't looked at the statistics of how you know what the market coverage is of of android versions um pretty confident that if you're rocking a version of android that's a year old you're probably pretty big target

51:37

and that you know again i don't mean to pick on android but that is just a reality of how that ecosystem has evolved people don't really realize the scale at which this affects the economy right like you see these ransomware attacks which i want to come to next in terms of like 20 million dollars paid in bitcoin but what you don't see

51:56

is the trillions of dollars in ip that have been transferred to foreign governments over the last decade recently we've seen a lot of intellectual property leaks um i kind of feel that you know it's if you were going to steal intellectual property and then create a competing product with traces which you know wow i got

52:17

busted for that yeah well i want to come back to wow internal rage meter just went up um you know it's a much more you know deniable scenario where you know things hit the internet and people say okay i just it was out there now so it's public domain knowledge so the you know having separation from the attacker uh and the beneficiary of

52:39

of you know the results of the attack um you know it makes a lot of sense if if one's goal was to get a hold of somebody's intellectual property i mean once it's out there everybody's going to consume it um you know you look at the leaks of the whole eternal blue leaks it's a series of tools from an sa that got leaked uh yeah windows

53:00

vulnerabilities yeah um you know went to wikipedia nsa or was that the cia ones that got released vault seven no that was that was nsa was there cia ones or am i making that up no there was one that was rude in uh vault 7 was was that group it was that leak i guess um the one i'm referring to um was uh from nsa and it was a whole treasure

53:25

trove of tools and this one was particularly interesting because it really there are events that occur that destabilize i guess the defensive posture ransomware in general i don't get how it even exists because it is the most benign is the easiest malware to detect and stop how there's even an industry around that

53:44

blows my mind but the attack vector uh that people use to wrap ransomware the payload weaponized that chain that i talked about earlier basically allowed you know a point and exploit capability on patched windows machines so walk me through ran somewhere like what what happens uh depends on the flavor but the the the overall

54:05

goal is to extort money out of the the victim so there's different ways to do that if you attack uh an individual you would uh you know potentially encrypt their personal photos um credit card information maybe other personal compromising information and then say give me x amount of money or i'm going to i'm going to you know

54:30

expose all your photos or i'm going to delete it all when it comes to businesses it's more of going after intellectual property where if a particular workstation gets compromised ransomware runs on that workstation encrypts everything potentially deletes deletes everything at the time uh typically making a copy of it because there's value in that

54:49

and then we'll go through all the network shares and do the same thing so uh there's one one particular there's different groups i guess of ransomware actors out there some that are uh you know won't call the bluff and others where if you say i'm not going to pay you they will 100 follow through on what they're going to do and

55:06

this weird i guess sub industry has emerged from ransomware actually being a thing and being accepted where companies will actually act as negotiators so if you think back to those really cool movies where you know there's a really cool ransom sorry hostage negotiator uh trying to talk somebody out of the scenario that exists for ransomware

55:30

and it it it it drives me too perfectly yeah yeah why is that a problem like do do you like do your customers have ransomware problems like well no because they they they use covalence uh we we protect against that that vector um but the how do you stop that like if it's that easy to stop why doesn't everybody stop it

55:52

i i wish i had an answer to that i don't think um you know a network monitoring solution will not stop ransomware there's nothing you can do about you need to be on host yeah you have to be on host and you have to have a measure of sophistication uh and uh tradecraft to identify and block it it's we've we've seen we have some coexistence

56:13

scenarios where i won't identify the companies but they are very very large successful companies cyber security companies and you know the ransomware gets by them but we stop it and it blows my mind that you know based on the because for you that's easy like that's not that's not a big thing that you're worried about

56:34

it it is a very very basic profile to stop identify um i don't know i might be jaded because i've been doing this for 20 years and in the grand scheme of uh things that i've been a part of uh ransomware is definitely low on the sophistication bar do you think it would exist without cryptocurrency and anonymous payment forms because it always seems to

56:56

be at least in the news it's always like you need to pay in bitcoin so i can like run away with this money and yeah i would say definitely be harder because that is definitely a very convenient payment structure to pay to pay with bitcoin the i'm just thinking in the cases where we we've seen financial redirections and those are anonymous accounts that

57:16

are used and then torn down um so there's there's definitely how hard is that to track like if you're sort of like the fbi or the another three-letter agency like to follow that path all right i i don't i don't know about that uh it's not my not my background um but i would say the the challenge would not necessarily be

57:39

the difficulty it would be the average person or business getting any agency to care to track it down because that you know intel agencies law enforcement agencies aren't sitting around waiting for things to do you know there's really big problems they're going after and trying to fix and solve and um you know a small company you know a

58:01

law firm getting ransomware is is just low on their well it's not even a matter of payment for them in some cases it's life or death for the business because you can effectively turn the business off overnight and just eliminate it especially if you're small and you you don't have these sort of like big bank

58:19

accounts to pay yeah yeah i'm aware of um you know businesses that have been shut down because of ransomware the the the payment is just too high and uh it's much easier just to say okay thrown in the towel uh we're gonna fold up shop and maybe start again and this is ultimately why i don't like i get very frustrated that companies will pay ransom

58:43

or not take the time to um you know hire a company ahead of time like it's much much easier and cheaper to be preventative and to to harden your your system and be ready for attacks i mean that that is the reality of today and anybody who thinks otherwise is you know they've got their head in their sand you're going to get ransomware

59:04

bad things will happen and hopefully it doesn't kill your company or compromise customer data that's that's a whole other aspect of this equation that i don't think people take into consideration of their legal obligations to report compromises in customer data now there are fines i i remember before kovit 19 dropped

59:25

there was discussions about you know six-figure fines going to canadian companies uh if they are ransomware customer data gets compromised and it has shown that they weren't taking the problem seriously ahead of time so they didn't have the adequate security protections in place what's adequate like that sounds so subjective yeah yeah

59:44

i mean is that back to that gartner i checked the box you can't sort of like fire me so so if i was a uh you know virtual uh cso i i would probably you know reference the gardner quantra to make sure that you know the executive board is covered in regards to liability um there's almost like two layers to this right there's the apparent layer

1:00:07

which is like i want to solve cyber security but the real layers like i want to keep my job and the easiest way to do that is not take any risks and go with the industry standard and ultimately that when it comes down to accountability that is a safe way to go it is unfortunately even if you're owned yeah yeah it's it's

1:00:26

it's the safe way to go but it is not the best thing for the company it is not uh it is not forward-facing uh it is i think it's being naive in regards to the the type of attacks that are coming so if you're a customer and you don't know a lot about this what are the questions you should ask to sort of reveal the type of solution you're

1:00:49

getting for real instead of sort of like checking the box you know right off the bat i would say how are you protecting my company just tell me how you're protecting my company like full stop what happens when something goes wrong and and you'll probably get a whole bunch of you know sales jargon what's the

1:01:10

difference between a good answer and a bad answer to that question oh god if somebody uses the word next generation seamless um yeah we'll stop everything yeah ai we've got machine learning any of that if any of that comes up big red flags so if somebody can give you a good answer to what happens when your system

1:01:32

fails that gives you comfort then i think that is a that is a good position to move beyond um when i when i said earlier that you know the cyber security industry is like a a bunch of unethical uh used car salesmen uh it's it's because there's so much jargon and salesmanship that goes into this for example the the process of buying a car

1:01:58

um what do you expect when you go to a dealership to buy a car what what what do you want to walk away assuming you really like a car or a brand what do you expect to walk away after a transaction occurs the car yeah unfortunately with the current cyber security industry there are sales persons all over the place that will will say

1:02:18

you know what you need is you need some wheels and then another sales person will say i can sell you the engine and another salesperson will say i'll sell you the steering wheel you probably only need the steering wheel uh but i can sell that it's gonna it's gonna be some rooms over here and it is up to you as a as a as a

1:02:33

company to put those things together and make use of that so you're cobbling together the solution yourself and each vendor like no vendor is responsible then because it's like oh this person there's a lot of finger pointing yeah and ultimately the the only working cyber solution and i i don't care what the the sales point is the only

1:02:53

true working cybersecurity solution is one that looks at it from where's your data how are you going to be attacked across the board so it needs to include an endpoint component a network monitoring component a cloud component potentially an iot component uh and xyz for things that we don't even need know it exists yet this is where this

1:03:14

whole concept of next generation drives me nuts because people say we have this next generation thing and what i'm seeing right now is the exact same thing i've been seeing 20 years ago regardless of whether it has a machine learning component or not like what does that mean next generation like if you knew the next generation of

1:03:31

exploits you'd be well ultimately it doesn't mean anything a good solution should be iterative a good solution should be engineered to handle the future without needing to put a sales tag around a uh you know this is what we have now we call it the next generation thing that the world has never seen ps it's got machine learning ai

1:03:52

blah blah blah blah which ultimately doesn't mean anything if you're a buyer all it does is confuse you it drives me there's so much jargon in this industry in particular right and a lot of it is salesy like it's created by the yeah sales teams the sales force the yeah the the number of times i have had to worry about

1:04:15

this you know these features that are sold uh to businesses around the world uh being on the other side of the coin just years ago uh never i've never had to worry about machine learning and by the way existing machine learning implementations and a lot of solutions out there is the exact same thing that you know i've seen in anti-viruses back in 2005.

1:04:37

they just didn't call it machine learning it was just training analytics to to look for anomalies and so when you were an attacker what did you worry about oh that's an intimate question getting caught i mean ultimately uh yeah i mean so as an attacker it is a um it is a continuous balance between risk uh and losing a capability

1:05:05

and this is what does that mean and i'm speaking from um you know back when i uh you know was at cse uh it means that you know when i said earlier that on the you know that first pillar of cyber security you want to call it a pillar there's an economy behind it so there's a cost to building uh capabilities to to go after

1:05:27

a particular target if you lose that capability that immediately is an expectation of okay find a new one and it's difficult there's there's cost of that there's labor uh and and that that is a very big component that goes into the the i guess the risk equation as to how you're going to approach an operation how aggressive you're going to be and

1:05:53

different different you know agencies around the world will do different things i mean you look at china and russia they're remarkably aggressive with a lot of i don't say disregard to their own intellectual property and what they're using but they're certainly not quiet about what they're doing it's like spray and pray

1:06:09

right yeah i find i find it really intriguing uh it makes it makes me wonder a little bit like do they have a an army of thousands of people in warehouses cranking the stuff out which they probably do which is really scary yeah one of the things that i always found really fascinating about intelligence problems was there's always

1:06:28

a country with more people who are just as smart if not smarter than you and just as good if not better technology than you and yet you're tasked with sort of defending or in some cases acquiring information against these people and the hubris that sort of like goes into oh we know best and yeah yeah that was always an intriguing

1:06:52

calculation um back uh back at cse um and it's it's it's it's a good debate to have i guess if you've got um you know something that took a lot of time to build do you throw it down a hill and hope for the best or do you protect it you put shoulder pads and knee pads on it and you know try to make it last as long as possible and

1:07:17

so talk me through that though like how do you see that because um allied governments friendly governments whatever you want to call them have exploits that are zero days that they don't release that have huge national security implications like we we've seen some of those become public and have massive implications within the

1:07:38

nhs nhs hack in great britain the result of a stolen zero day from an allied government that one's tough um like should they disclose them what's your like how do you think about that so so from what i so full disclosure i don't have as much much exposure to what the internal debate is on that i'm aware that it happens um

1:08:05

it's i think a lot of it comes down to what the perceived value is gained versus lost if you just if you if you don't disclose something and you use it operationally uh is there more good for the the mission the country its people by not disclosing adverses disclosing it and losing a capability um yeah it's a tough one because you know

1:08:29

the the the adversaries of uh allied governments aren't going to disclose they're not going to care if they have something they can weaponize they will use it and i think unfortunately that is probably the the tone that is set globally that underpins a lot of these the decision making like if if you're being attacked constantly and having

1:08:50

your intellectual your nation's intellectual property stolen i mean you could disclose all the vulnerabilities you have and you know about as a nation it's not going to stop them it's just not going to they're they're you know going back to the the vupin example of um there are more out there um so there's a backlog apparently

1:09:10

yeah yeah speaking of i'm going to probably push some of your buttons here so you might want to take a drink talk to me a little bit about wow way i'm just gonna leave it there expand on wow uh so we've had many conversations what a chestnut that situation is um so huawei's had a bit of a an interesting uh less than smooth ride uh i i would say

1:09:43

they came out of nowhere with all this tech yeah which which miraculously happened right after a cisco leak a giant cisco source code it's a coincidence yeah so i you know there's there's documented ties to uh the chinese federal government with that company existing there is i don't know if they were ever convicted

1:10:06

it was back in 2003 2004 but there was a there was a very clear-cut case that huawei was using conveniently leaked intellectual property this is back to you know if i was going to steal your intellectual property it is much more deniable if i leak it into the internet and then use it and come out six months later and say oh look i just found this

1:10:26

out there and i used it really convenient um yeah and you know where we are today huawei basically you know price undercuts um other other vendors and you know i ask how do they get to that point that that sounds like they have a lower r d budget and how do you have a lower r d budget you you get intellectual property via

1:10:50

creative means um you know today with uh them being banned from the u.s uh i don't disagree with that uh i have different thoughts about the whole tick tock situation um but wait dive into the huawei thing why don't you disagree with that why don't i disagree with them being banned yeah i mean i agree with them

1:11:10

being banned yeah so i don't think there is a framework to build trust i don't think they have earned that trust and given you know if a nation is going to re-kit their entire country with a new type of wireless gear especially with the complexities of 5g you need to trust that vendor you need to be sure that the interests

1:11:33

of that vendor are at the very least not opposed to the interests of the country that you're in and i don't know how anybody could possibly say that about huawei i remember when the brits did this whole thing like we're going to set up this accredited lab we're going to test it so we're going to allow british telecom to use it

1:11:52

but we'll test everything that's deployed i remember just like that would fall apart in a second because the minute there's a zero day you're going to deploy it right away especially if it's leaked on the internet and then you've deployed code that you haven't code reviewed and then the whole thing just falls apart and i'm like okay

1:12:08

well well it doesn't scale to the realistic pace of software development so let's let's imagine that a government does have a program in place where every iteration of source code and these aren't small systems we're talking about millions of lines of source millions let's assume you have a crack team of amazing source reviewers

1:12:28

that can say with confidence yep this looks great uh or better yet they have a set of automated tools to be able to derive that answer which is challenging probably possible extremely challenging the realistic outcome is the time for say huawei releases a new iteration the time from that release because if they are a vendor that

1:12:52

actually believes in securing their product and that new release of the firmware has uh you know fixes time matters you're against the clock before um you know vulnerabilities could be discovered and put out because all it takes is for them to release that firmware once have somebody rip that firmware apart

1:13:08

and identify differences between the old and new so you're immediately up against the clock and if this ideal analysis process is being slowed down in any way you're immediately compromising the vendor and giving them the the argument that this system doesn't work because what they and i don't necessarily disagree with that if i was the vendor

1:13:31

and my releases were being slowed down by a month i would get pretty cheesed because it's not my fault yeah you're slowing down fixes and and oh i'm sorry your routers just got hacked that's on you that's that's not on the vendor at that point so i don't think that program is is or that that concept is one that actually works

1:13:50

and the way to avoid that is sort of like just not allow that in your critical infrastructure or do you think it should be not allowed in any infrastructure your personal take oh my personal take i i i'm again i'm i'm completely fine with the ban i mean they're still allowed to uh sell into canada uh i i'm not aware of what the uh

1:14:12

i think it's not a lot in the the i mean my knowledge is out of date so we'll have to like fact-check this but i think it's not allowed in the critical components of canadian telcos but it's allowed in the periphery but that's like silly when you think about it right because you don't want to ever be held hostage to somebody who can

1:14:28

who can turn that off and somebody who's more patient than you right because you could just go 25 years with no incident and then all of a sudden there's an incident but you've built up 25 years of trust and credibility so the story you tell yourself is we haven't had an incident it's cheaper because it's likely subsidized and not only r d but

1:14:48

subsidized by the government yeah so i mean ultimately this is i don't have any problem with the huawei being banned in the u.s i would not i would not argue about that by the way the the name of the vendor is a rhodium started sorry for boop and started zero oh okay they're the ones that bought the zero days yeah i always lump

1:15:07

them together just you know well same parent company i would imagine yeah yeah what do you think of snowden oh i feel like you're asking questions that has slowly taken years off my life uh so i've been doing that since i met you uh no you're great bud i do not agree with what snowden did in any way and that is that is putting

1:15:30

it very very kindly um regardless of you know at this point there's been things that he brought to light that has been declared illegal the the unfortunate assumption is that agencies security agencies intel agencies are you know these devious groups that are like let's do whatever we can and i don't think the average person

1:15:54

actually realizes how difficult that job is how normal the people are who do that job they have families they come in they want to you know solve a mission or solve a problem make things better and the way he went out uh with this giant trove of information which i'm going to come back to completely ignores the the the way that technical

1:16:19

implementations get approved it's not like developers are sitting at their desk and say i have this great idea let's go do it and all of a sudden it's running in operations without any um you know accountability or review there is a team of lawyers depending on the size of the country that will look at that and say this

1:16:38

is okay this is bad i remember being a cse and arguing for something for i don't know how many years but there was there was a problem legally and it didn't get through and that that vetting process people take extremely serious and if something goes through that process uh there is a measure of legality to it there are a group of lawyers

1:17:02

who honestly like to say no to ideas that have said yep this is okay so the idea that anything that has been deemed illegal you know i'm not in a position to say that's right or wrong but what i can say is the process that those things would have gone through people underestimate the sheer size of the bureaucracy

1:17:23

to get anything implemented absolutely crazy so so that whole side of things um uh i find unfortunate um because the the byproduct of that is distrust for agencies that are working extremely hard to keep countries safe and is it is extremely disheartening for those people to you know get dragged through the mud publicly when the public doesn't

1:17:46

actually have an awareness as to how much they sacrifice on a day-to-day basis like i couldn't count the number of long nights that i've seen people work um you know it it can break families it can break relationships and um it has yeah definitely so the other side of it is you know trusting his intentions so he he had gripes about

1:18:09

you know those types of illegal you know mass monitoring or mass surveillance programs in the u.s why did he go public with such a large archive that had nothing to do with that why did he you know expose um completely legitimate legal intelligence gathering programs uh that have a ton of people's names associated with that

1:18:36

why did he go out the door with that and that i think is what i have a much larger problem with and that you know there was no thought process i you know it sounded it to me it seemed like more he was just giving the intelligence community the middle finger yeah i mean i sort of took away the same thing from that whole thing which was

1:18:55

even if he felt just in what he was doing it would have had a different sort of feel to it when it came out and and you don't need to reveal the techniques you can just reveal the details of the programs but the actual techniques that he revealed the software techniques the exploitation techniques that i mean that that definitely cost

1:19:13

people lives that had a huge impact on people working there yeah and how far back did he set programs how much did you know entire agencies need to go into damage control because some yahoo decided that this thing over here was illegal and then oh ps here's a whole bunch of other interesting stuff unredacted

1:19:34

being released yeah i think people think oh there's no names associated with it but like on the original documents there's definitely names and i think we both assume that every intelligence agency worth their salt in the world has unredacted copies of all of those documents yeah yeah to the best of my knowledge wikileaks doesn't receive

1:19:51

redacted versions of things uh so i mean that's that's largely my opinion on him if he's so you don't think he should be pardoned a little part of me will die if he's pardoned why do you think he's in russia is there is there something to that story i mean the where's the safe place to go when you've uh burned uh you know a particular group

1:20:15

like right into the pretty yeah i mean yeah i'd be really curious to actually know what his living conditions are like right now and uh you know hopefully they're not comfortable um but i mean he brought it upon himself there there's other ways he could have done that uh and and come forward with how could you

1:20:34

have done that differently what do you think well like internally there's lots of outlets for that stuff he said he followed that there was no documentation released that i can remember that he did follow those yeah i mean you look at the the whistleblower protection and that's in place now um was that person in there or yeah you

1:20:55

know i was just thinking that i don't know whether it was post snowden i mean maybe his decision to do that would have actually improved the protections for whistleblowers and uh you know that's probably important to acknowledge but it's um i thought he was the best thing to happen to linchpin though i remember like and i don't mean that in

1:21:12

a negative way i just remember like what happened in the immediate aftermath of that was they locked down the process by which people get hired so like i don't think you or i would make it through today from start to finish because of our backgrounds and sort of different quirks of our personality and so what happens is like post node and

1:21:34

you end up hiring i call it the stormtrooper problem which is like you end up basically hiring the same type of person right there they're sort of like never had a problem in their life they get straight a's they do all the right things they tie their shoelaces the right way and they come into the organization and

1:21:52

they get promoted and the process for promotion now is sort of like here are the 10 things you need to do to get promoted because it's so sort of like laid out and so bureaucratic that you end up you're 30 and all of a sudden you're you're in charge of solving a problem that nobody's ever solved before but you're in a group of people who all

1:22:12

see the problem the exact same way so you all share the same blind spot so i remember when that started happening i was like oh man this is like great news for matt because you're hiring in a way the misfits of the the industry right the people who don't want to go to meetings the people who don't want to fill out the forms to go

1:22:29

travel the people who just want to be able to do their job yeah i'm trying to think back of uh you know what was there was there an effect um i i don't actually know if i could speak to that without violating an nda honestly but um yeah we don't want to get you in trouble yeah this year yeah i think how you characterize the

1:22:50

the mindset of these organizations are um it's pretty accurate i mean the well we both sat in meetings where they're like oh we can't hire this person because there's like a flaw in their background and and there's some legitimacy to that too right like you're trying to manage top secret information you're trying to

1:23:10

manage risk and manage an organization but the flip side of that is like you're hiring effectively the same person yeah you're not wrong i definitely don't i don't disagree um i think from one one benefit to linchpin from that was definitely it pushed people out the door uh absolutely uh i i think that's a trend that uh that continues uh to this day i mean

1:23:35

i'm i'm still you know full disclosure actively recruiting from intelligence agencies the people that are excited to leave and do something more and uh you know for the lack of better better terms be unleashed to solve technical problems like there's that there's that hunger there uh and it's uh i love that perspective

1:23:56

of unleashing people that have sort of like had handcuffs before and it's like now your ceiling is not bureaucracy your ceiling is your own ability yeah i've been doing this for 15 years almost as an entrepreneur in you know two companies and i've gotten to witness people going go through that unleashing process and it is really cool to see um

1:24:22

how you know one month after they're they're just blown away with what they are now afforded to do and what what what what you know i'm not saying don't do this it is just here's the goal here's the problem solve it let me know what you need we'll catch up every once in a while in canada people typically join join the

1:24:42

company with you know one year leave of absence or a five-year sabbatical component and i always i always laugh about that because yeah i mean nobody's ever going back well yeah so yeah so from a risk standpoint uh that makes sense so i never i never argue with that uh but from a practical standpoint uh nobody's ever gone back

1:25:03

and it's become something that i've seen weaponized against the employee um you know oh you're you're going to this company we're not going to give you your one year uh leave of absence and it's like okay that is extremely bad decision and you're showing some really unfortunate true colors um you know in that does that ever make somebody stay

1:25:23

or does it like push them at the door faster pushes them in the door and motivates them yeah chips on shoulders man there's something to the motivation that comes from that that just drives people i mean google's project zero is largely built from people who have exited the intelligence in the industry with a chip

1:25:40

on their shoulder i don't know if that's worked worked out so well but i want to just sort of like end on some of the lessons that you've learned growing field effect now to 100 people that's the critical phase for a lot of companies like a lot of companies break in this sort of like 40 to 100 people range because you start reaching

1:26:03

the ceiling of the processes that you put in place but also the ceiling of the people who've got you here how do you think about that how do you scale and how do you go beyond that and crack through that sort of ceiling uh i i think the the first component is is making sure that everybody is going in in the same direction um the you know

1:26:26

you you have to be very straightforward frank honest uh when you know looking internally but also what the company goals are and everybody needs to know what the company goals are i don't think that you know execution is not necessarily something that comes naturally to a lot of people and and for me right now like one of my one of my

1:26:49

biggest concerns as we approach 100 as we go through kovid 19 i mean when this kobit 19 started there was you know a decision to be made to go aggressive or yeah or or cower i guess from the scenario and you know in my opinion it was very clear we go aggressive because you know our competitors are probably going to be

1:27:07

category b and damage control so yeah um so you can get ahead yeah so so execution is is a big part of that and you know it takes a bit of time to understand what execution looks like in each particular problem or a given company so that discovery of you know how do we execute as a group has been something that i i think is is

1:27:28

extremely important and largely the the company is absolutely doing amazing at it uh and and that that i think is is one thing that um you know always resonates in my head that you know everybody has great ideas but how you push through is execution you need to you need to material materialize those great ideas into things that uh

1:27:49

a reality is there anything else you want to say about the state of cyber before we wrap this up how about you am i out of square jar content say whatever you want yes i think we're already explicit at this point so so so i would say uh you know if you are a company uh looking for help uh it is it can be a challenging thing i i think it's uh

1:28:12

it's that going to the doctor scenario when you have a pain you don't want to necessarily find out what it is because you know people are naturally averse to bad news you can't be like that with cyber security if you don't have a cyber security vendor if you don't have a company helping you out with that problem um get on it

1:28:33

uh everybody is a target at this point your company is not small enough uh to be off uh an attacker's radar i have seen five person companies uh actually i've seen two person companies uh attacked and hit so um you know my advice is don't be don't be afraid to to ask for help hello field effect dot com yeah the second thing i would say is uh

1:28:59

you know anybody out there looking for uh you know a really cool opportunity for a really cool company um you know the experts of the world regardless of what company you're working for right now we're always looking for more people that's amazing like my kids call you uncle matt but they also uh whenever elon musk comes out they say

1:29:18

we know somebody is going to do more than elon sort of like and they're pointing to you so we're looking forward to seeing how this progresses over the next couple years i don't know how to respond to that but that's very uh that's very kind to them thanks for chatting man yeah thanks for having me it's good time you