Jan 2, 2019 · 33m · a16z

a16z Podcast | The Hard Things about Security

Stina Ehrensvärd · 19m spoken Martin Casado · 5m spoken Sonal Chokshi · 5m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, Yubico CEO Stina Ehrensvärd and a16z General Partner Martin Casado discuss the evolution of hardware authentication, open security standards like FIDO, and the strategic journey of building a global cybersecurity company. They explore the fundamental limitations of software security, the friction between usability and safety, and how bridging Swedish engineering culture with Silicon Valley ambition shaped Yubico's success.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 17.6% of the talking time here. How this is scored →

The host as informed peer 2.9 Guest teaching 3.3 Guest disagreement 1.2 The host pushing back 0.6
05100:0010:0020:0030:000:48–4:35 · The host as informed peer 2/10 Origins in Pharmaceutical Packaging & Regional Entrepreneurship Differences Host asks basic conversational origin questions while guest explains the transition from pharmaceutical packaging to driverless security keys. Guest educates on why early smart cards failed due to driver requirements.4:35–9:30 · The host as informed peer 3/10 Threat Landscape and Limits of Software and Biometric Security Host probes why physical hardware tokens are safer than biometrics or remembered passwords. Guest and co-host school on SIM swapping, OPM fingerprint breaches, and public key cryptography.9:30–12:53 · The host as informed peer 4/10 Security vs. Privacy and the Reality of Cyber Warfare Host cites Kim Zetter's book on Stuxnet to demonstrate knowledge of digital attacks on physical infrastructure. Guest clarifies the distinction between privacy and security.12:53–17:03 · The host as informed peer 3/10 Open Standards, the FIDO Alliance, and Distributed Trust Models Host notes the fundamental tension between usability and strong security. Guest explains distributed trust models and how redundant keys prevent user lockout.17:03–20:14 · The host as informed peer 3/10 The Future of Security: Passwordless, IoT, and Dedicated Server Chips Host summarizes co-host's points on chip specialization. Co-host and guest detail passwordless authentication and dedicated security chips like Google's Titan.20:14–24:49 · The host as informed peer 2/10 Earning User Trust, Open Source, and Corporate Resistance Co-host sharply criticizes tech giants like Apple for prioritizing brand image over customer security. Guest recounts an accidental open-source announcement on a podcast that became her strategy.24:49–27:37 · The host as informed peer 3/10 Pitching President Obama and Advice on Startup Fundraising Host reinforces guest's fundraising advice by referencing Ben Horowitz's philosophy on controlling startup destiny. Guest shares anecdotes pitching Obama and meeting advisors at Starbucks.27:37–29:52 · The host as informed peer 4/10 Swedish Work Culture vs. Silicon Valley Ambition Host connects flat Swedish workplace hierarchies with historical high-performing R&D labs like Bell Labs. Guest explains why flat structure yields candid technical critique.29:52–31:23 · The host as informed peer 2/10 Clear Startup Communication and Functional Product Design Guest reframes host's query on aesthetic design by emphasizing that YubiKey design prioritizes envelope shipping, robotic assembly, and crush resistance over visual flair.0:48–4:35 · Guest teaching 3/10 Origins in Pharmaceutical Packaging & Regional Entrepreneurship Differences Host asks basic conversational origin questions while guest explains the transition from pharmaceutical packaging to driverless security keys. Guest educates on why early smart cards failed due to driver requirements.4:35–9:30 · Guest teaching 5/10 Threat Landscape and Limits of Software and Biometric Security Host probes why physical hardware tokens are safer than biometrics or remembered passwords. Guest and co-host school on SIM swapping, OPM fingerprint breaches, and public key cryptography.9:30–12:53 · Guest teaching 4/10 Security vs. Privacy and the Reality of Cyber Warfare Host cites Kim Zetter's book on Stuxnet to demonstrate knowledge of digital attacks on physical infrastructure. Guest clarifies the distinction between privacy and security.12:53–17:03 · Guest teaching 3/10 Open Standards, the FIDO Alliance, and Distributed Trust Models Host notes the fundamental tension between usability and strong security. Guest explains distributed trust models and how redundant keys prevent user lockout.17:03–20:14 · Guest teaching 4/10 The Future of Security: Passwordless, IoT, and Dedicated Server Chips Host summarizes co-host's points on chip specialization. Co-host and guest detail passwordless authentication and dedicated security chips like Google's Titan.20:14–24:49 · Guest teaching 2/10 Earning User Trust, Open Source, and Corporate Resistance Co-host sharply criticizes tech giants like Apple for prioritizing brand image over customer security. Guest recounts an accidental open-source announcement on a podcast that became her strategy.24:49–27:37 · Guest teaching 2/10 Pitching President Obama and Advice on Startup Fundraising Host reinforces guest's fundraising advice by referencing Ben Horowitz's philosophy on controlling startup destiny. Guest shares anecdotes pitching Obama and meeting advisors at Starbucks.27:37–29:52 · Guest teaching 3/10 Swedish Work Culture vs. Silicon Valley Ambition Host connects flat Swedish workplace hierarchies with historical high-performing R&D labs like Bell Labs. Guest explains why flat structure yields candid technical critique.29:52–31:23 · Guest teaching 4/10 Clear Startup Communication and Functional Product Design Guest reframes host's query on aesthetic design by emphasizing that YubiKey design prioritizes envelope shipping, robotic assembly, and crush resistance over visual flair.0:48–4:35 · Guest disagreement 1/10 Origins in Pharmaceutical Packaging & Regional Entrepreneurship Differences Host asks basic conversational origin questions while guest explains the transition from pharmaceutical packaging to driverless security keys. Guest educates on why early smart cards failed due to driver requirements.4:35–9:30 · Guest disagreement 1/10 Threat Landscape and Limits of Software and Biometric Security Host probes why physical hardware tokens are safer than biometrics or remembered passwords. Guest and co-host school on SIM swapping, OPM fingerprint breaches, and public key cryptography.9:30–12:53 · Guest disagreement 0/10 Security vs. Privacy and the Reality of Cyber Warfare Host cites Kim Zetter's book on Stuxnet to demonstrate knowledge of digital attacks on physical infrastructure. Guest clarifies the distinction between privacy and security.12:53–17:03 · Guest disagreement 1/10 Open Standards, the FIDO Alliance, and Distributed Trust Models Host notes the fundamental tension between usability and strong security. Guest explains distributed trust models and how redundant keys prevent user lockout.17:03–20:14 · Guest disagreement 1/10 The Future of Security: Passwordless, IoT, and Dedicated Server Chips Host summarizes co-host's points on chip specialization. Co-host and guest detail passwordless authentication and dedicated security chips like Google's Titan.20:14–24:49 · Guest disagreement 3/10 Earning User Trust, Open Source, and Corporate Resistance Co-host sharply criticizes tech giants like Apple for prioritizing brand image over customer security. Guest recounts an accidental open-source announcement on a podcast that became her strategy.24:49–27:37 · Guest disagreement 1/10 Pitching President Obama and Advice on Startup Fundraising Host reinforces guest's fundraising advice by referencing Ben Horowitz's philosophy on controlling startup destiny. Guest shares anecdotes pitching Obama and meeting advisors at Starbucks.27:37–29:52 · Guest disagreement 1/10 Swedish Work Culture vs. Silicon Valley Ambition Host connects flat Swedish workplace hierarchies with historical high-performing R&D labs like Bell Labs. Guest explains why flat structure yields candid technical critique.29:52–31:23 · Guest disagreement 2/10 Clear Startup Communication and Functional Product Design Guest reframes host's query on aesthetic design by emphasizing that YubiKey design prioritizes envelope shipping, robotic assembly, and crush resistance over visual flair.0:48–4:35 · The host pushing back 0/10 Origins in Pharmaceutical Packaging & Regional Entrepreneurship Differences Host asks basic conversational origin questions while guest explains the transition from pharmaceutical packaging to driverless security keys. Guest educates on why early smart cards failed due to driver requirements.4:35–9:30 · The host pushing back 2/10 Threat Landscape and Limits of Software and Biometric Security Host probes why physical hardware tokens are safer than biometrics or remembered passwords. Guest and co-host school on SIM swapping, OPM fingerprint breaches, and public key cryptography.9:30–12:53 · The host pushing back 1/10 Security vs. Privacy and the Reality of Cyber Warfare Host cites Kim Zetter's book on Stuxnet to demonstrate knowledge of digital attacks on physical infrastructure. Guest clarifies the distinction between privacy and security.12:53–17:03 · The host pushing back 1/10 Open Standards, the FIDO Alliance, and Distributed Trust Models Host notes the fundamental tension between usability and strong security. Guest explains distributed trust models and how redundant keys prevent user lockout.17:03–20:14 · The host pushing back 0/10 The Future of Security: Passwordless, IoT, and Dedicated Server Chips Host summarizes co-host's points on chip specialization. Co-host and guest detail passwordless authentication and dedicated security chips like Google's Titan.20:14–24:49 · The host pushing back 0/10 Earning User Trust, Open Source, and Corporate Resistance Co-host sharply criticizes tech giants like Apple for prioritizing brand image over customer security. Guest recounts an accidental open-source announcement on a podcast that became her strategy.24:49–27:37 · The host pushing back 0/10 Pitching President Obama and Advice on Startup Fundraising Host reinforces guest's fundraising advice by referencing Ben Horowitz's philosophy on controlling startup destiny. Guest shares anecdotes pitching Obama and meeting advisors at Starbucks.27:37–29:52 · The host pushing back 1/10 Swedish Work Culture vs. Silicon Valley Ambition Host connects flat Swedish workplace hierarchies with historical high-performing R&D labs like Bell Labs. Guest explains why flat structure yields candid technical critique.29:52–31:23 · The host pushing back 0/10 Clear Startup Communication and Functional Product Design Guest reframes host's query on aesthetic design by emphasizing that YubiKey design prioritizes envelope shipping, robotic assembly, and crush resistance over visual flair.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 29.5% · guest 70.5%0:00 · the host 29.5% · guest 70.5%3:00 · the host 26% · guest 74%3:00 · the host 26% · guest 74%6:00 · the host 29% · guest 71%6:00 · the host 29% · guest 71%9:00 · the host 11.4% · guest 88.6%9:00 · the host 11.4% · guest 88.6%12:00 · the host 7.2% · guest 92.8%12:00 · the host 7.2% · guest 92.8%15:00 · the host 17.8% · guest 82.2%15:00 · the host 17.8% · guest 82.2%18:00 · the host 12.4% · guest 87.6%18:00 · the host 12.4% · guest 87.6%21:00 · the host 6.9% · guest 93.1%21:00 · the host 6.9% · guest 93.1%24:00 · the host 7% · guest 93%24:00 · the host 7% · guest 93%27:00 · the host 26.1% · guest 73.9%27:00 · the host 26.1% · guest 73.9%30:00 · the host 23.9% · guest 76.1%30:00 · the host 23.9% · guest 76.1%33:00 · the host 4.9% · guest 95.1%33:00 · the host 4.9% · guest 95.1%
Sharpest disagreement ▶ 20:55 Calling out corporate image over security

Martin Casado directly attacks major corporations like Apple, claiming they prioritize brand pride over customer safety by refusing third-party security integration.

Hardest push from the host ▶ 7:00 Host challenges physical token safety

The host openly questions the core premise of physical security keys, asking why an easily lost token is safer than biometric data or passwords stored in a mind.

Biggest teaching moment ▶ 30:50 Redefining hardware design priorities

Stina corrects the host's assumption about visual design, revealing that the true engineering challenge was designing a key flat enough to ship in a standard letter envelope.

The host holds their own ▶ 10:50 Host cites Stuxnet and physical software impacts

The host demonstrates domain expertise by bringing up Kim Zetter's book on Stuxnet to illustrate how digital software vulnerabilities directly impact physical industrial infrastructure.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Origins in Pharmaceutical Packaging & Regional Entrepreneurship Differences 2310 Host asks basic conversational origin questions while guest explains the transition from pharmaceutical packaging to driverless security keys. Guest educates on why early smart cards failed due to driver requirements.
Threat Landscape and Limits of Software and Biometric Security 3512 Host probes why physical hardware tokens are safer than biometrics or remembered passwords. Guest and co-host school on SIM swapping, OPM fingerprint breaches, and public key cryptography.
Security vs. Privacy and the Reality of Cyber Warfare 4401 Host cites Kim Zetter's book on Stuxnet to demonstrate knowledge of digital attacks on physical infrastructure. Guest clarifies the distinction between privacy and security.
Open Standards, the FIDO Alliance, and Distributed Trust Models 3311 Host notes the fundamental tension between usability and strong security. Guest explains distributed trust models and how redundant keys prevent user lockout.
The Future of Security: Passwordless, IoT, and Dedicated Server Chips 3410 Host summarizes co-host's points on chip specialization. Co-host and guest detail passwordless authentication and dedicated security chips like Google's Titan.
Earning User Trust, Open Source, and Corporate Resistance 2230 Co-host sharply criticizes tech giants like Apple for prioritizing brand image over customer security. Guest recounts an accidental open-source announcement on a podcast that became her strategy.
Pitching President Obama and Advice on Startup Fundraising 3210 Host reinforces guest's fundraising advice by referencing Ben Horowitz's philosophy on controlling startup destiny. Guest shares anecdotes pitching Obama and meeting advisors at Starbucks.
Swedish Work Culture vs. Silicon Valley Ambition 4311 Host connects flat Swedish workplace hierarchies with historical high-performing R&D labs like Bell Labs. Guest explains why flat structure yields candid technical critique.
Clear Startup Communication and Functional Product Design 2420 Guest reframes host's query on aesthetic design by emphasizing that YubiKey design prioritizes envelope shipping, robotic assembly, and crush resistance over visual flair.

Statements from this episode (26)

Opinion
Ehrensvärd: Swedish entrepreneurs are more frugal and cautious than Silicon Valley founders
“Swedes are in general more frugal and more cautious. There is this saying that a Swede think that a million dollar is a lot of money.”
Stina Ehrensvärd Jan 2, 2019 ▶ 1:32
Insight
Ehrensvärd: All downloadable software on phones or computers is eventually hackable
“Any software that's downloaded on a computer or on a phone can sooner or later be hacked, and that's the reality we're seeing.”
Stina Ehrensvärd Jan 2, 2019 ▶ 3:29
Opinion
Casado: Hardware roots of trust are the only proven solution for account takeovers
“The first one is we're trying to develop solutions for these, and there's only one that's kind of been really proven to work, and these are hardware tokens and hardware roots of trust.”
Martin Casado Jan 2, 2019 ▶ 5:50
Opinion
Ehrensvärd: Biometrics offer no higher security than passwords or PINs
“I believe that the PIN or a password or biometrics is about the same level of security.”
Stina Ehrensvärd Jan 2, 2019 ▶ 6:35
Insight
Casado: Mobile 2FA is fundamentally insecure due to retail SIM-swapping vulnerability
“But even those aren't something that you can really protect because somebody could walk into a T-Mobile store in Idaho, and they could show a fake ID from our team. They could port my phone number to their phone, and then they could use that to reset all of my…”
Martin Casado Jan 2, 2019 ▶ 8:22
Disclosure
Casado: Stolen fingerprints from OPM data breach permanently ruined his Global Entry access
“So that had a database of fingerprints, and for those of us, like myself, I used to work for the government, that had our credentials stolen, we can't even do global entry anymore because of biometrics.”
Martin Casado Jan 2, 2019 ▶ 9:00
Opinion
Casado: Authentication must be physical and independent of the human body
“Now a hardware token that's independent of that, you can protect it, and so I feel very strongly that the solution must be physical, it must be independent of the physical body, and something that you can put in a safe if you want to.”
Martin Casado Jan 2, 2019 ▶ 9:20
Assertion Not checkable as stated
Ehrensvärd: Strong security historically came at the expense of privacy
“Historically, security and privacy has not been a good fit. You know, good security has always come with not so great privacy.”
Stina Ehrensvärd Jan 2, 2019 ▶ 9:31
Assertion Not checkable as stated
Ehrensvärd: Cyberattacks can cause greater damage than traditional physical warfare
“Now we only have to hack into each other's systems on the government level, on a personal level, to do damage that can be far bigger than what we've done.”
Stina Ehrensvärd Jan 2, 2019 ▶ 10:43
Insight
Casado: Software attackers control system rules once inside
“Well, the thing with software is if someone gets in the software at all, any piece of it, then basically they control the laws of physics.”
Martin Casado Jan 2, 2019 ▶ 11:11
Assertion Supported
Ehrensvärd: Google experienced zero successful phishing attempts after deploying FIDO U2F
“And since Google deployed this for all staff and contractors, they had zero phishing attempts.”
Stina Ehrensvärd Jan 2, 2019 ▶ 12:48
Assertion Not checkable as stated
Martin Casado: FIDO Has Become the Primary Standard for Web Authentication
“So I think it's fair to say over the last few years, Fido has become the standard for authentication, which is really significant.”
Martin Casado Jan 2, 2019 ▶ 12:54
Prediction Not checkable as stated
Ehrensvärd: FIDO authentication will have as large an impact as SSL
“I'm absolutely convinced that this will have as big impact on internet security as SSL have had in the past.”
Stina Ehrensvärd Jan 2, 2019 ▶ 13:32
Prediction Partly held up
Ehrensvärd: Banks and US government services will support FIDO by 2018
“By end of this year I will be able to log in to several banks, to US government services, and none of these services share any information about how my keys used.”
Stina Ehrensvärd Jan 2, 2019 ▶ 14:14
Assertion Supported
Ehrensvärd: Google cut support costs by 92% using hardware security keys
“Google published a report not long ago where they said that they were able to cut down support to 92% compared to a phone app.”
Stina Ehrensvärd Jan 2, 2019 ▶ 15:19
Assertion Supported
Ehrensvärd: Mozilla and Microsoft are adding native hardware security key support
“Google was the first. Mozilla is coming on board. Microsoft is coming on board.”
Stina Ehrensvärd Jan 2, 2019 ▶ 16:15
Prediction Not checkable as stated
Casado: Dedicated Security Chips Will Disrupt Server-Side Hardware Security
“Google has announced that they're doing this with a special purpose chip, and so to have something that's a few hundred bucks that, you know, is part of the same model, I think is probably a disruption on the server side.”
Martin Casado Jan 2, 2019 ▶ 19:13
Prediction Not checkable as stated
Ehrensvärd: The internet, software, and computing devices will never be secure
“We have to accept that we're not gonna have a secure internet. We will not be able to trust our software, will not be able to trust your networks, our Wi-Fi's, our devices, either computers or phones.”
Stina Ehrensvärd Jan 2, 2019 ▶ 19:25
Opinion
Casado: Apple resists third-party security to protect its public image
“And I think, like, for me, like, the crowning example of this has been Apple. Any number of security vendors will tell you, like, when we try and, you know, provide a solution on top of Apple, they don't want to admit that they're insecure.”
Martin Casado Jan 2, 2019 ▶ 21:13
Assertion Not checkable as stated
Casado: Open source contributions drove Yubico's bottom-up adoption
“Having a real security ecosystem around it makes a solution better. One of the reasons that Ubico's won the hearts and minds and has been this kind of organic, you know, bottoms up phenomenon is contributions of open source, and so.”
Martin Casado Jan 2, 2019 ▶ 21:30
Disclosure
Ehrensvärd: Yubico acquired Google as a customer through open-source community member
“One of them worked for Google. And that's how we got to Google.”
Stina Ehrensvärd Jan 2, 2019 ▶ 24:30
Disclosure
Ehrensvärd: Ram Shriram backed Yubico after initial Silicon Valley rejections
“Everyone said no to me when I landed here, because we weren't proven, but I continued, and eventually I got introduced to Ram Sharam, who sits in the board of Google, and he had this Silicon Valley mindset. After 40 minutes, he said, how can I help?”
Stina Ehrensvärd Jan 2, 2019 ▶ 27:25
Opinion
Chokshi: Pretending tech workplaces lack hierarchy is disingenuous
“Yeah, I think people often pretend like there is no hierarchy, and I think that's actually very disingenuous. There's clearly, there's a hierarchy.”
Sonal Chokshi Jan 2, 2019 ▶ 28:07
Opinion
Ehrensvärd: Swedes are among the world's best software developers
“Yes, and that's also why Swedes are some of the best Software developers on the planet because they have the ability to work together, but also question each other.”
Stina Ehrensvärd Jan 2, 2019 ▶ 28:44
Assertion Supported
Ehrensvärd: YubiKey was designed to ship via standard envelope postage
“You can fit in into an envelope so you don't have to ship it with anything more than a standard letter.”
Stina Ehrensvärd Jan 2, 2019 ▶ 31:00
Prediction Open · timeframe Jun 2023
Ehrensvärd: Yubico will integrate YubiKey hardware security into credit cards
“So we will put YubiKey functionality into credit cards, and it's basically because it's a small chip. It's basically like a chip, and the software on the chip, it's not big. You know, that can be integrated into a lot of different things. We will see it in the…”
Stina Ehrensvärd Jan 2, 2019 ▶ 32:57
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.