Jan 2, 2019 · 17m · a16z

a16z Podcast | The State of Security

Joel de la Garza · 4m spoken Niels Provos · 4m spoken Martin Casado · 3m spoken Stina Ehrensvärd · 2m spoken Sonal Chokshi · 30s spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

Recorded at the Andreessen Horowitz summit, this panel discussion brings together security executives to explore the convergence of physical and cybersecurity, hardware-based authentication standards, regulatory incentives, and the transition to cloud infrastructure.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 4.3 Guest teaching 4.8 Guest disagreement 2.7 The host pushing back 2.5
05100:0010:000:33–2:43 · The host as informed peer 6/10 Is Cybersecurity a Distinct Discipline or Part of General Security? Martin introduces the topic by drawing on his personal background in the intelligence community and government think tanks to discuss critical infrastructure security. Joel responds by recounting Citigroup's experience with nation-state attacks, reframing security as a business process feature rather than a standalone product.2:43–4:45 · The host as informed peer 1/10 The Incentive Problem and the Automobile Safety Analogy Niels explicitly challenges the previous guest's premise, arguing that security is primarily an incentive problem rather than a pure technology issue. Stina adds an analogy to automobile safety regulations, while the host remains mostly quiet.4:45–8:28 · The host as informed peer 4/10 Authentication Challenges and Hardware Root of Trust Solutions Stina explains user credential vulnerabilities, prompting Niels to interject with Google's zero-phishing statistics using hardware keys. Martin probes further into the effectiveness of government regulation and NIST standards.8:28–11:43 · The host as informed peer 5/10 Industry Adoption and Challenges of Hardware Roots of Trust Martin frames the discussion around hardware roots of trust like Google's Titan chip, but Stina sharply rebuts the idea that the industry is open to it. Joel further notes serious CVSS vulnerabilities in commercial hardware implementations.11:43–15:29 · The host as informed peer 4/10 Best Security Practices for End Users and Addressing the Human Element Martin shares his personal security practices such as using Signal, while the panel highlights human risk factors and Chromebook deployment. Joel and Niels emphasize that user education and basic hygiene deliver the highest security ROI.15:29–17:12 · The host as informed peer 6/10 Future Predictions: Security Standards, Insurance, and Cloud Migration Martin challenges Niels on cloud security, raising the common objection that cloud migration increases attack surface area. Niels defends cloud adoption by arguing that economies of scale yield far superior security resources.0:33–2:43 · Guest teaching 4/10 Is Cybersecurity a Distinct Discipline or Part of General Security? Martin introduces the topic by drawing on his personal background in the intelligence community and government think tanks to discuss critical infrastructure security. Joel responds by recounting Citigroup's experience with nation-state attacks, reframing security as a business process feature rather than a standalone product.2:43–4:45 · Guest teaching 5/10 The Incentive Problem and the Automobile Safety Analogy Niels explicitly challenges the previous guest's premise, arguing that security is primarily an incentive problem rather than a pure technology issue. Stina adds an analogy to automobile safety regulations, while the host remains mostly quiet.4:45–8:28 · Guest teaching 5/10 Authentication Challenges and Hardware Root of Trust Solutions Stina explains user credential vulnerabilities, prompting Niels to interject with Google's zero-phishing statistics using hardware keys. Martin probes further into the effectiveness of government regulation and NIST standards.8:28–11:43 · Guest teaching 6/10 Industry Adoption and Challenges of Hardware Roots of Trust Martin frames the discussion around hardware roots of trust like Google's Titan chip, but Stina sharply rebuts the idea that the industry is open to it. Joel further notes serious CVSS vulnerabilities in commercial hardware implementations.11:43–15:29 · Guest teaching 5/10 Best Security Practices for End Users and Addressing the Human Element Martin shares his personal security practices such as using Signal, while the panel highlights human risk factors and Chromebook deployment. Joel and Niels emphasize that user education and basic hygiene deliver the highest security ROI.15:29–17:12 · Guest teaching 4/10 Future Predictions: Security Standards, Insurance, and Cloud Migration Martin challenges Niels on cloud security, raising the common objection that cloud migration increases attack surface area. Niels defends cloud adoption by arguing that economies of scale yield far superior security resources.0:33–2:43 · Guest disagreement 1/10 Is Cybersecurity a Distinct Discipline or Part of General Security? Martin introduces the topic by drawing on his personal background in the intelligence community and government think tanks to discuss critical infrastructure security. Joel responds by recounting Citigroup's experience with nation-state attacks, reframing security as a business process feature rather than a standalone product.2:43–4:45 · Guest disagreement 5/10 The Incentive Problem and the Automobile Safety Analogy Niels explicitly challenges the previous guest's premise, arguing that security is primarily an incentive problem rather than a pure technology issue. Stina adds an analogy to automobile safety regulations, while the host remains mostly quiet.4:45–8:28 · Guest disagreement 2/10 Authentication Challenges and Hardware Root of Trust Solutions Stina explains user credential vulnerabilities, prompting Niels to interject with Google's zero-phishing statistics using hardware keys. Martin probes further into the effectiveness of government regulation and NIST standards.8:28–11:43 · Guest disagreement 4/10 Industry Adoption and Challenges of Hardware Roots of Trust Martin frames the discussion around hardware roots of trust like Google's Titan chip, but Stina sharply rebuts the idea that the industry is open to it. Joel further notes serious CVSS vulnerabilities in commercial hardware implementations.11:43–15:29 · Guest disagreement 2/10 Best Security Practices for End Users and Addressing the Human Element Martin shares his personal security practices such as using Signal, while the panel highlights human risk factors and Chromebook deployment. Joel and Niels emphasize that user education and basic hygiene deliver the highest security ROI.15:29–17:12 · Guest disagreement 2/10 Future Predictions: Security Standards, Insurance, and Cloud Migration Martin challenges Niels on cloud security, raising the common objection that cloud migration increases attack surface area. Niels defends cloud adoption by arguing that economies of scale yield far superior security resources.0:33–2:43 · The host pushing back 1/10 Is Cybersecurity a Distinct Discipline or Part of General Security? Martin introduces the topic by drawing on his personal background in the intelligence community and government think tanks to discuss critical infrastructure security. Joel responds by recounting Citigroup's experience with nation-state attacks, reframing security as a business process feature rather than a standalone product.2:43–4:45 · The host pushing back 0/10 The Incentive Problem and the Automobile Safety Analogy Niels explicitly challenges the previous guest's premise, arguing that security is primarily an incentive problem rather than a pure technology issue. Stina adds an analogy to automobile safety regulations, while the host remains mostly quiet.4:45–8:28 · The host pushing back 3/10 Authentication Challenges and Hardware Root of Trust Solutions Stina explains user credential vulnerabilities, prompting Niels to interject with Google's zero-phishing statistics using hardware keys. Martin probes further into the effectiveness of government regulation and NIST standards.8:28–11:43 · The host pushing back 3/10 Industry Adoption and Challenges of Hardware Roots of Trust Martin frames the discussion around hardware roots of trust like Google's Titan chip, but Stina sharply rebuts the idea that the industry is open to it. Joel further notes serious CVSS vulnerabilities in commercial hardware implementations.11:43–15:29 · The host pushing back 2/10 Best Security Practices for End Users and Addressing the Human Element Martin shares his personal security practices such as using Signal, while the panel highlights human risk factors and Chromebook deployment. Joel and Niels emphasize that user education and basic hygiene deliver the highest security ROI.15:29–17:12 · The host pushing back 6/10 Future Predictions: Security Standards, Insurance, and Cloud Migration Martin challenges Niels on cloud security, raising the common objection that cloud migration increases attack surface area. Niels defends cloud adoption by arguing that economies of scale yield far superior security resources.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 2:43 Challenging the core security premise

Niels explicitly interrupts and reframes the discussion by asking why anyone should care about security if lack of security carries no direct cost.

Hardest push from the host ▶ 16:30 Pushing back on cloud security safety

Martin directly challenges the guest's optimistic view on cloud migration by citing the popular counterargument regarding increased attack surface.

Biggest teaching moment ▶ 10:24 Debunking industry openness to hardware security

Stina immediately and bluntly rejects the host's implicit assumption that the market welcomes hardware roots of trust, stating the industry was 'absolutely not open at all.'

The host holds their own ▶ 0:33 Establishing domain expertise via intel background

Martin demonstrates deep expertise by sharing his prior work with think tanks analyzing critical infrastructure and national sovereignty threats.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Is Cybersecurity a Distinct Discipline or Part of General Security? 6411 Martin introduces the topic by drawing on his personal background in the intelligence community and government think tanks to discuss critical infrastructure security. Joel responds by recounting Citigroup's experience with nation-state attacks, reframing security as a business process feature rather than a standalone product.
The Incentive Problem and the Automobile Safety Analogy 1550 Niels explicitly challenges the previous guest's premise, arguing that security is primarily an incentive problem rather than a pure technology issue. Stina adds an analogy to automobile safety regulations, while the host remains mostly quiet.
Authentication Challenges and Hardware Root of Trust Solutions 4523 Stina explains user credential vulnerabilities, prompting Niels to interject with Google's zero-phishing statistics using hardware keys. Martin probes further into the effectiveness of government regulation and NIST standards.
Industry Adoption and Challenges of Hardware Roots of Trust 5643 Martin frames the discussion around hardware roots of trust like Google's Titan chip, but Stina sharply rebuts the idea that the industry is open to it. Joel further notes serious CVSS vulnerabilities in commercial hardware implementations.
Best Security Practices for End Users and Addressing the Human Element 4522 Martin shares his personal security practices such as using Signal, while the panel highlights human risk factors and Chromebook deployment. Joel and Niels emphasize that user education and basic hygiene deliver the highest security ROI.
Future Predictions: Security Standards, Insurance, and Cloud Migration 6426 Martin challenges Niels on cloud security, raising the common objection that cloud migration increases attack surface area. Niels defends cloud adoption by arguing that economies of scale yield far superior security resources.

Statements from this episode (18)

Insight
De La Garza: Cybersecurity shouldn't exist as a standalone industry
“There's a really weird thing about information security in that it's an industry that, for the most part, shouldn't exist. If you bought a car and your car dealer made you pay an extra 200 bucks to not have your car go up in flames, you'd be able to sue them. …”
Joel De La Garza Jan 2, 2019 ▶ 2:05
Prediction Not checkable as stated
De La Garza: Security will become a feature rather than a standalone product
“And so I think as business models evolve, as we make this transition to the cloud, as blockchain becomes more widely deployed, security starts to become more of a feature and less of a product. And I think we start thinking less about kind of the specific tech…”
Joel De La Garza Jan 2, 2019 ▶ 2:26
Insight
Niels Provos: Computer security is an incentive problem, not a tech problem
“It's probably not really a technology problem, it's an incentive problem.”
Niels Provos Jan 2, 2019 ▶ 3:33
Prediction Not checkable as stated
Stina Ehrensvärd: All software across all devices will eventually be hacked
“Any software, on a computer, or a phone, or a server, eventually will be hacked.”
Stina Ehrensvärd Jan 2, 2019 ▶ 3:53
Assertion Not checkable as stated
Ehrensvärd: 90% of data breaches stem from compromised credentials
“Probably 90% of every breach you read about is a user credential that has been compromised, and it's either a static password or a weak One, you know, two-factor authentication, like SMS or an app that is being taken.”
Stina Ehrensvärd Jan 2, 2019 ▶ 4:58
Assertion Not checkable as stated
Provos: Google experienced zero successful employee phishing attacks after mandating hardware keys
“We have mandated a hardware second factor for everybody at Google since 2009. You know, everybody is using a security key nowadays. We have not had a single successful phishing attack against a Google employee since then.”
Niels Provos Jan 2, 2019 ▶ 5:34
Opinion
De La Garza: US computer intrusion laws are profoundly broken
“The criminal justice laws, the laws around computer intrusions in this country are really profoundly broken. There's not a lot of sophistication or nuance in them. It's essentially treating every kind of computer intrusion like it was armed robbery.”
Joel De La Garza Jan 2, 2019 ▶ 6:27
Insight
De La Garza: Compliance and security are typically enemies
“I'm typically of the opinion that compliance and security are the enemies of each other, but this is one instance where I think it's actually really starting to raise the bar.”
Joel De La Garza Jan 2, 2019 ▶ 7:02
Prediction Not checkable as stated
De La Garza: Consumer electronics will eventually feature standard security stamps
“I think we're going to get to a point where our consumer electronics will have that kind of security stamp on the back. That'll be based on some kind of measurable, meaningful standards.”
Joel De La Garza Jan 2, 2019 ▶ 7:10
Assertion Not checkable as stated
De La Garza: Commercial hardware trust roots have serious security vulnerabilities
“Historically, we've had issues, so we've been working with a lot of the commercially available hardware routes of trust, not represented by anyone on the stage, but I won't disclose the vendors, and have generally found that a lot of those hardware solutions h…”
Joel De La Garza Jan 2, 2019 ▶ 9:14
Assertion Not checkable as stated
Provos: Google cannot offer mandatory hardware security key protection to billions
“Google rolled out this advanced protection program where you are forced to associate a security key with your account. That's the only way that you can get into your account. But that is not something that we can offer to billions of users.”
Niels Provos Jan 2, 2019 ▶ 11:08
Assertion Contradicted
Niels Provos: Chromebooks with security keys create uncompromisable endpoints
“I continue to be a big proponent of something like a Chromebook with a security key, right? Essentially, you have an endpoint that cannot be compromised, even if you try. Because the weak point in all of this continues to be the human.”
Niels Provos Jan 2, 2019 ▶ 11:57
Assertion Not checkable as stated
Joel De La Garza: Security training yields highest ROI on security spend
“Where we get our single largest return on investment in terms of security spend is around training and engagement and just helping get people like yourselves to know that you're targeted, how you're going to be targeted.”
Joel De La Garza Jan 2, 2019 ▶ 12:57
Opinion
Ehrensvärd: US prioritizes speed over security, unlike Europe
“Here in America, it's been more about convenience and speed, while Europe has sort of, the convenience and speed is not as important as security.”
Stina Ehrensvärd Jan 2, 2019 ▶ 14:49
Insight
Provos: Security doesn't need to be perfect, just better than peers
“Well, another thing that remains true is, adversaries often go to the place where the bar is lower. Right? So you oftentimes don't need to achieve perfect security, as long as security is mostly higher than somebody else.”
Niels Provos Jan 2, 2019 ▶ 15:15
Prediction Not checkable as stated
Ehrensvärd: Native security standards will make cybersecurity safer by 2028
“I believe that the world is going to be much better in 10 years. And going back to the car and the seatbelts, today we have 10 times more cars on the street compared to 60 years ago, and we have actually fewer fatal accidents. And it's because there is built-i…”
Stina Ehrensvärd Jan 2, 2019 ▶ 15:41
Prediction Not checkable as stated
Provos: Everyone will rely on managed cloud providers for security by 2028
“In 10 years, everybody is going to be on a professionally run cloud that takes care of all of your security needs.”
Niels Provos Jan 2, 2019 ▶ 16:04
Prediction Not checkable as stated
De La Garza: Enterprise cybersecurity will shift to risk transfer and insurance
“In 10 years it's all about standards, and then it ultimately becomes about risk transfer, right? Some form of insurance. And it's about leveraging standards to mitigate as much of the risk as possible and then transferring the risk that you can't control throu…”
Joel De La Garza Jan 2, 2019 ▶ 16:13
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.