Jan 2, 2019 · 29m · a16z

a16z Podcast | Security’s Wakeup Call

Ash Carter · 12m spoken Alex Stamos · 9m spoken John Jack · 4m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

Hosted by Andreessen Horowitz, this panel featuring former Deputy Secretary of Defense Dr. Ash Carter and Yahoo CISO Alex Stamos analyzes evolving corporate cybersecurity threats, state-sponsored cyber espionage, and strategic risk management practices for enterprise leaders.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The host as informed peer 3.8 Guest teaching 5.8 Guest disagreement 1.6 The host pushing back 0.8
05100:0010:0020:003:14–5:53 · The host as informed peer 2/10 Payment Infrastructure Weaknesses and Mid-Market Vulnerabilities Host John Jack sets up Alex Stamos with a brief prompt on credit card breaches. Stamos provides a detailed technical breakdown of point-of-sale vulnerabilities on legacy Windows XP systems and explains how nation-state actors target mid-market industrial firms.5:53–10:25 · The host as informed peer 4/10 Strategies for Minimizing Attack Surface and Proactive Communication John Jack cites Andreessen Horowitz's core thesis that software is eating the world to frame a question around attack surface management for corporate executives. Stamos and Carter educate the host and audience on cloud migration, CISO role dynamics, and fragmented vendor architectures.10:25–14:27 · The host as informed peer 5/10 Normalizing Incident Response and State-Sponsored Cyber Threats John Jack shares insights from his 12 years selling security software and adds an insightful follow-up on how Chinese state actors leverage small suppliers to penetrate corporate supply chains. Carter and Stamos explain the reality of nation-state espionage and day-to-day incident response.14:27–22:12 · The host as informed peer 4/10 Executive Wargaming and Intelligence Sharing Barriers John Jack asks why threat intelligence isn't universally shared between government and private industry, pushing Carter on whether the agency logjam can be broken. Carter and Stamos school the host on over-classification issues and federal inter-agency turf wars between law enforcement, defense, and homeland security.22:12–29:21 · The host as informed peer 4/10 Personal Cybersecurity Practices and Geopolitics of East Asia Stamos dismantles common assumptions regarding personal cyber hygiene, explaining that targeted individuals cannot protect themselves with existing tech. Ash Carter politely rejects the host's prompt to talk about the Middle East, reframing the true national security focus toward East Asia and domestic digital skills.3:14–5:53 · Guest teaching 6/10 Payment Infrastructure Weaknesses and Mid-Market Vulnerabilities Host John Jack sets up Alex Stamos with a brief prompt on credit card breaches. Stamos provides a detailed technical breakdown of point-of-sale vulnerabilities on legacy Windows XP systems and explains how nation-state actors target mid-market industrial firms.5:53–10:25 · Guest teaching 5/10 Strategies for Minimizing Attack Surface and Proactive Communication John Jack cites Andreessen Horowitz's core thesis that software is eating the world to frame a question around attack surface management for corporate executives. Stamos and Carter educate the host and audience on cloud migration, CISO role dynamics, and fragmented vendor architectures.10:25–14:27 · Guest teaching 5/10 Normalizing Incident Response and State-Sponsored Cyber Threats John Jack shares insights from his 12 years selling security software and adds an insightful follow-up on how Chinese state actors leverage small suppliers to penetrate corporate supply chains. Carter and Stamos explain the reality of nation-state espionage and day-to-day incident response.14:27–22:12 · Guest teaching 6/10 Executive Wargaming and Intelligence Sharing Barriers John Jack asks why threat intelligence isn't universally shared between government and private industry, pushing Carter on whether the agency logjam can be broken. Carter and Stamos school the host on over-classification issues and federal inter-agency turf wars between law enforcement, defense, and homeland security.22:12–29:21 · Guest teaching 7/10 Personal Cybersecurity Practices and Geopolitics of East Asia Stamos dismantles common assumptions regarding personal cyber hygiene, explaining that targeted individuals cannot protect themselves with existing tech. Ash Carter politely rejects the host's prompt to talk about the Middle East, reframing the true national security focus toward East Asia and domestic digital skills.3:14–5:53 · Guest disagreement 1/10 Payment Infrastructure Weaknesses and Mid-Market Vulnerabilities Host John Jack sets up Alex Stamos with a brief prompt on credit card breaches. Stamos provides a detailed technical breakdown of point-of-sale vulnerabilities on legacy Windows XP systems and explains how nation-state actors target mid-market industrial firms.5:53–10:25 · Guest disagreement 1/10 Strategies for Minimizing Attack Surface and Proactive Communication John Jack cites Andreessen Horowitz's core thesis that software is eating the world to frame a question around attack surface management for corporate executives. Stamos and Carter educate the host and audience on cloud migration, CISO role dynamics, and fragmented vendor architectures.10:25–14:27 · Guest disagreement 1/10 Normalizing Incident Response and State-Sponsored Cyber Threats John Jack shares insights from his 12 years selling security software and adds an insightful follow-up on how Chinese state actors leverage small suppliers to penetrate corporate supply chains. Carter and Stamos explain the reality of nation-state espionage and day-to-day incident response.14:27–22:12 · Guest disagreement 2/10 Executive Wargaming and Intelligence Sharing Barriers John Jack asks why threat intelligence isn't universally shared between government and private industry, pushing Carter on whether the agency logjam can be broken. Carter and Stamos school the host on over-classification issues and federal inter-agency turf wars between law enforcement, defense, and homeland security.22:12–29:21 · Guest disagreement 3/10 Personal Cybersecurity Practices and Geopolitics of East Asia Stamos dismantles common assumptions regarding personal cyber hygiene, explaining that targeted individuals cannot protect themselves with existing tech. Ash Carter politely rejects the host's prompt to talk about the Middle East, reframing the true national security focus toward East Asia and domestic digital skills.3:14–5:53 · The host pushing back 0/10 Payment Infrastructure Weaknesses and Mid-Market Vulnerabilities Host John Jack sets up Alex Stamos with a brief prompt on credit card breaches. Stamos provides a detailed technical breakdown of point-of-sale vulnerabilities on legacy Windows XP systems and explains how nation-state actors target mid-market industrial firms.5:53–10:25 · The host pushing back 1/10 Strategies for Minimizing Attack Surface and Proactive Communication John Jack cites Andreessen Horowitz's core thesis that software is eating the world to frame a question around attack surface management for corporate executives. Stamos and Carter educate the host and audience on cloud migration, CISO role dynamics, and fragmented vendor architectures.10:25–14:27 · The host pushing back 1/10 Normalizing Incident Response and State-Sponsored Cyber Threats John Jack shares insights from his 12 years selling security software and adds an insightful follow-up on how Chinese state actors leverage small suppliers to penetrate corporate supply chains. Carter and Stamos explain the reality of nation-state espionage and day-to-day incident response.14:27–22:12 · The host pushing back 2/10 Executive Wargaming and Intelligence Sharing Barriers John Jack asks why threat intelligence isn't universally shared between government and private industry, pushing Carter on whether the agency logjam can be broken. Carter and Stamos school the host on over-classification issues and federal inter-agency turf wars between law enforcement, defense, and homeland security.22:12–29:21 · The host pushing back 0/10 Personal Cybersecurity Practices and Geopolitics of East Asia Stamos dismantles common assumptions regarding personal cyber hygiene, explaining that targeted individuals cannot protect themselves with existing tech. Ash Carter politely rejects the host's prompt to talk about the Middle East, reframing the true national security focus toward East Asia and domestic digital skills.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 0% · guest 100%0:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%3:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%6:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%9:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%12:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%15:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%18:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%21:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%24:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%27:00 · the host 0% · guest 100%
Sharpest disagreement ▶ 24:40 Reframing geopolitical priorities away from host prompt

Ash Carter politely but directly rejects John Jack's request to discuss the Middle East, redirecting the discussion to explain why East Asia and China represent the true strategic focus.

Hardest push from the host ▶ 19:14 Host pressing on breaking institutional logjams

John Jack directly interrupts Ash Carter's list of governmental barriers to ask if the bureaucratic logjam around threat sharing can actually be broken.

Biggest teaching moment ▶ 22:24 Uncomfortable truth regarding personal cybersecurity

Alex Stamos corrects popular assumptions about personal security by explaining that if a user is individually targeted by an adversary, current consumer technology offers no real defense.

The host holds their own ▶ 14:15 Host expanding on supply chain attack vectors

John Jack actively demonstrates domain knowledge by extending Ash Carter's point about component theft to explain how hackers use small vendors to pivot into primary targets.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Payment Infrastructure Weaknesses and Mid-Market Vulnerabilities 2610 Host John Jack sets up Alex Stamos with a brief prompt on credit card breaches. Stamos provides a detailed technical breakdown of point-of-sale vulnerabilities on legacy Windows XP systems and explains how nation-state actors target mid-market industrial firms.
Strategies for Minimizing Attack Surface and Proactive Communication 4511 John Jack cites Andreessen Horowitz's core thesis that software is eating the world to frame a question around attack surface management for corporate executives. Stamos and Carter educate the host and audience on cloud migration, CISO role dynamics, and fragmented vendor architectures.
Normalizing Incident Response and State-Sponsored Cyber Threats 5511 John Jack shares insights from his 12 years selling security software and adds an insightful follow-up on how Chinese state actors leverage small suppliers to penetrate corporate supply chains. Carter and Stamos explain the reality of nation-state espionage and day-to-day incident response.
Executive Wargaming and Intelligence Sharing Barriers 4622 John Jack asks why threat intelligence isn't universally shared between government and private industry, pushing Carter on whether the agency logjam can be broken. Carter and Stamos school the host on over-classification issues and federal inter-agency turf wars between law enforcement, defense, and homeland security.
Personal Cybersecurity Practices and Geopolitics of East Asia 4730 Stamos dismantles common assumptions regarding personal cyber hygiene, explaining that targeted individuals cannot protect themselves with existing tech. Ash Carter politely rejects the host's prompt to talk about the Middle East, reframing the true national security focus toward East Asia and domestic digital skills.

Statements from this episode (14)

Assertion Supported
John Jack: Target data breach direct costs reached $236M
“There's the target breach, which the cost to target is now two hundred and thirty six million dollars direct costs and rising, and we know what happened to a few people's jobs there.”
John Jack Jan 2, 2019 ▶ 0:53
Insight
Carter: Executives overlook foreign IP theft as a core cyber threat
“They don't quite know Why it could be detrimental to their business to be insecure. They understand the reputational part of it, but not necessarily the instrumental part. And these are real, real, one of the threats to them is real world competitors elsewhere…”
Ash Carter Jan 2, 2019 ▶ 2:40
Prediction Not checkable as stated
Carter: Skeptical major breaches will trigger systemic cybersecurity changes
“The short answer to your question is, I've been waiting for Godot here for many years, I certainly hope that this is the beginning of a wake-up call, but I, I'm skeptical.”
Ash Carter Jan 2, 2019 ▶ 3:02
Opinion
Stamos: 470 of the Fortune 500 cannot defend against modern cyber adversaries
“If you look at the Fortune 500, I would say 470 of those companies are kind of screwed because they're playing at What's happened is, is that the level of adversary has caught up to a level that's well beyond their ability to play”
Alex Stamos Jan 2, 2019 ▶ 4:13
Insight
Stamos: Attack surface minimization is the most effective security strategy
“Attack surface minimization is by far The cheapest and most effective way to reduce your security risk.”
Alex Stamos Jan 2, 2019 ▶ 7:15
Opinion
Stamos: Backward compatibility neutralized Microsoft's $1 billion security investment
“It's the reason why Microsoft has spent probably a billion dollars on security in the last decade, and they still haven't gone anywhere. It's because they're not willing to do a tax service minimization due to the way they do backwards compatibility.”
Alex Stamos Jan 2, 2019 ▶ 7:20
Prediction Not checkable as stated
Carter: Turnkey security architecture for non-tech firms will be huge market
“And so somebody's gonna make an, a hell of a lot of money Who figures out how to brand That architecture, and can credibly say, I'll put together an architecture for you, non-tech company, as good as the one Alex is going to put together for a tech company and…”
Ash Carter Jan 2, 2019 ▶ 9:50
Assertion Not checkable as stated
Stamos: Preventing initial network intrusion in companies over 24 employees is impossible
“No enterprise with more than a couple dozen people is gonna keep the bad guys from first getting a foothold in their network. That's impossible.”
Alex Stamos Jan 2, 2019 ▶ 12:13
Assertion Not checkable as stated
Carter: Chinese state-sponsored cyber aggressors are smart and largely unopposed in US
“Jim Comey is basically telling the truth. The Chinese government-sponsored and at kind of one arm's length proxy I.T. Aggressor, ah, services are large, they're smart and they're largely unopposed in this country”
Ash Carter Jan 2, 2019 ▶ 12:41
Assertion Not checkable as stated
Ash Carter: U.S. government collects little threat intelligence relevant to commercial cyberattacks
“A lot of the threat information that the government collects in the counterintelligence area, counterterrorism, protect our own networks area, some of it's germane, but a lot of it is not really germane to these commercial attacks. Said differently, the govern…”
Ash Carter Jan 2, 2019 ▶ 17:47
Assertion Not checkable as stated
Carter: Homeland Security sought bureaucratic control of cyber defense without capability
“I could never get Homeland Security, quite honestly, because I thought they had the attitude that they wanted this bureaucratically. I mean, all bureaucracies want things, and they wanted this, but they didn't have the capability.”
Ash Carter Jan 2, 2019 ▶ 19:41
Assertion Not checkable as stated
Stamos: Individual targets cannot protect themselves online against determined attackers
“The kind of inconvenient truth of the tech industry right now is that there's pretty much nothing a individual person can do to be safe online if they're targeted by a bad guy.”
Alex Stamos Jan 2, 2019 ▶ 22:24
Prediction Not checkable as stated
Stamos: Tech industry must redesign consumer technology safety within five years
“But beyond that, it's incumbent on us to the next five years, we need to redesign how technology works so it actually people are safe if they're targeted, not just that they're lucky.”
Alex Stamos Jan 2, 2019 ▶ 24:01
Opinion
Carter: Chinese strategic hubris poses a greater existential threat than Putin
“When it shades into hubris and risk taking, it's a problem. And I just say that because that could ruin everything. Putin can't ruin everything. And, you know, ISIS can't ruin everything. That could ruin everything.”
Ash Carter Jan 2, 2019 ▶ 26:38
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.