Jan 2, 2019 · 28m · a16z

a16z Podcast | How Hacks Happen (Let’s Just Say Mistakes Have Been Made)

Kim Zetter · 20m spoken Sonal Chokshi · 3m spoken Michael Copeland · 2m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this episode of the a16z Podcast, cybersecurity journalist Kim Zetter joins hosts Michael Copeland and Sonal Choksi to discuss how major corporate cyber breaches occur, the evolution of nation-state threat actors, and practical defensive strategies for enterprises and consumers.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. The host holds 13.8% of the talking time here. How this is scored →

The host as informed peer 3.0 Guest teaching 5.1 Guest disagreement 1.7 The host pushing back 1.4
05100:0010:0020:001:48–4:28 · The host as informed peer 2/10 Target Breach Analysis and Third-Party Vendor Risks Sonal and Michael ask foundational questions regarding recent high-profile breaches like Target. Kim educates the hosts on third-party HVAC vendor access and how attackers pivot through supply chain connections.4:29–9:35 · The host as informed peer 2/10 Mechanics of Phishing, Spear Phishing, and Human Error Kim reframes Sonal's question about user ignorance by demonstrating personal phishing dynamics. She details spear-phishing mechanics and recounts how RSA employees manually retrieved phishing emails from spam folders.9:35–12:20 · The host as informed peer 2/10 Nation-State Threat Actors and Cyber Espionage Trends The hosts inquire about state-sponsored threat actors. Kim provides an informative breakdown of Chinese economic espionage and Russian hacking underground sophistication and legal immunity.12:21–18:10 · The host as informed peer 3/10 Ransomware Growth and Critical Analysis of the Sony Hack Kim aggressively critiques official government claims linking North Korea to the Sony breach. She delivers a detailed breakdown explaining why IP address evidence is flimsy and why released data aligns with anti-piracy underground motives rather than state action.18:10–20:57 · The host as informed peer 3/10 Corporate Breach Disclosure and Evolving Transparency Standards Sonal and Michael query corporate disclosure norms. Kim outlines evolving disclosure laws and explains how widespread breaches have reduced corporate embarrassment around reporting.20:58–25:17 · The host as informed peer 5/10 Active Defense Dilemmas and Internal Anomaly Monitoring Sonal demonstrates background knowledge from her time at Wired regarding active defense strategies. Kim details the legal risks under the Computer Fraud and Abuse Act and explains Target's alert fatigue failure.25:18–28:58 · The host as informed peer 4/10 Practical Security Recommendations and Podcast Conclusion The conversation moves to practical advice where hosts suggest biometrics and watermarking analogies. Kim provides concrete recommendations on cloud auditing and data seeding.1:48–4:28 · Guest teaching 5/10 Target Breach Analysis and Third-Party Vendor Risks Sonal and Michael ask foundational questions regarding recent high-profile breaches like Target. Kim educates the hosts on third-party HVAC vendor access and how attackers pivot through supply chain connections.4:29–9:35 · Guest teaching 6/10 Mechanics of Phishing, Spear Phishing, and Human Error Kim reframes Sonal's question about user ignorance by demonstrating personal phishing dynamics. She details spear-phishing mechanics and recounts how RSA employees manually retrieved phishing emails from spam folders.9:35–12:20 · Guest teaching 5/10 Nation-State Threat Actors and Cyber Espionage Trends The hosts inquire about state-sponsored threat actors. Kim provides an informative breakdown of Chinese economic espionage and Russian hacking underground sophistication and legal immunity.12:21–18:10 · Guest teaching 7/10 Ransomware Growth and Critical Analysis of the Sony Hack Kim aggressively critiques official government claims linking North Korea to the Sony breach. She delivers a detailed breakdown explaining why IP address evidence is flimsy and why released data aligns with anti-piracy underground motives rather than state action.18:10–20:57 · Guest teaching 4/10 Corporate Breach Disclosure and Evolving Transparency Standards Sonal and Michael query corporate disclosure norms. Kim outlines evolving disclosure laws and explains how widespread breaches have reduced corporate embarrassment around reporting.20:58–25:17 · Guest teaching 5/10 Active Defense Dilemmas and Internal Anomaly Monitoring Sonal demonstrates background knowledge from her time at Wired regarding active defense strategies. Kim details the legal risks under the Computer Fraud and Abuse Act and explains Target's alert fatigue failure.25:18–28:58 · Guest teaching 4/10 Practical Security Recommendations and Podcast Conclusion The conversation moves to practical advice where hosts suggest biometrics and watermarking analogies. Kim provides concrete recommendations on cloud auditing and data seeding.1:48–4:28 · Guest disagreement 1/10 Target Breach Analysis and Third-Party Vendor Risks Sonal and Michael ask foundational questions regarding recent high-profile breaches like Target. Kim educates the hosts on third-party HVAC vendor access and how attackers pivot through supply chain connections.4:29–9:35 · Guest disagreement 2/10 Mechanics of Phishing, Spear Phishing, and Human Error Kim reframes Sonal's question about user ignorance by demonstrating personal phishing dynamics. She details spear-phishing mechanics and recounts how RSA employees manually retrieved phishing emails from spam folders.9:35–12:20 · Guest disagreement 1/10 Nation-State Threat Actors and Cyber Espionage Trends The hosts inquire about state-sponsored threat actors. Kim provides an informative breakdown of Chinese economic espionage and Russian hacking underground sophistication and legal immunity.12:21–18:10 · Guest disagreement 4/10 Ransomware Growth and Critical Analysis of the Sony Hack Kim aggressively critiques official government claims linking North Korea to the Sony breach. She delivers a detailed breakdown explaining why IP address evidence is flimsy and why released data aligns with anti-piracy underground motives rather than state action.18:10–20:57 · Guest disagreement 1/10 Corporate Breach Disclosure and Evolving Transparency Standards Sonal and Michael query corporate disclosure norms. Kim outlines evolving disclosure laws and explains how widespread breaches have reduced corporate embarrassment around reporting.20:58–25:17 · Guest disagreement 2/10 Active Defense Dilemmas and Internal Anomaly Monitoring Sonal demonstrates background knowledge from her time at Wired regarding active defense strategies. Kim details the legal risks under the Computer Fraud and Abuse Act and explains Target's alert fatigue failure.25:18–28:58 · Guest disagreement 1/10 Practical Security Recommendations and Podcast Conclusion The conversation moves to practical advice where hosts suggest biometrics and watermarking analogies. Kim provides concrete recommendations on cloud auditing and data seeding.1:48–4:28 · The host pushing back 1/10 Target Breach Analysis and Third-Party Vendor Risks Sonal and Michael ask foundational questions regarding recent high-profile breaches like Target. Kim educates the hosts on third-party HVAC vendor access and how attackers pivot through supply chain connections.4:29–9:35 · The host pushing back 1/10 Mechanics of Phishing, Spear Phishing, and Human Error Kim reframes Sonal's question about user ignorance by demonstrating personal phishing dynamics. She details spear-phishing mechanics and recounts how RSA employees manually retrieved phishing emails from spam folders.9:35–12:20 · The host pushing back 1/10 Nation-State Threat Actors and Cyber Espionage Trends The hosts inquire about state-sponsored threat actors. Kim provides an informative breakdown of Chinese economic espionage and Russian hacking underground sophistication and legal immunity.12:21–18:10 · The host pushing back 2/10 Ransomware Growth and Critical Analysis of the Sony Hack Kim aggressively critiques official government claims linking North Korea to the Sony breach. She delivers a detailed breakdown explaining why IP address evidence is flimsy and why released data aligns with anti-piracy underground motives rather than state action.18:10–20:57 · The host pushing back 2/10 Corporate Breach Disclosure and Evolving Transparency Standards Sonal and Michael query corporate disclosure norms. Kim outlines evolving disclosure laws and explains how widespread breaches have reduced corporate embarrassment around reporting.20:58–25:17 · The host pushing back 2/10 Active Defense Dilemmas and Internal Anomaly Monitoring Sonal demonstrates background knowledge from her time at Wired regarding active defense strategies. Kim details the legal risks under the Computer Fraud and Abuse Act and explains Target's alert fatigue failure.25:18–28:58 · The host pushing back 1/10 Practical Security Recommendations and Podcast Conclusion The conversation moves to practical advice where hosts suggest biometrics and watermarking analogies. Kim provides concrete recommendations on cloud auditing and data seeding.

speaking balance: gold is the host, purple is the guest (3 minute bins)

0:00 · the host 20.2% · guest 79.8%0:00 · the host 20.2% · guest 79.8%3:00 · the host 25% · guest 75%3:00 · the host 25% · guest 75%6:00 · the host 0.8% · guest 99.2%6:00 · the host 0.8% · guest 99.2%9:00 · the host 11.2% · guest 88.8%9:00 · the host 11.2% · guest 88.8%12:00 · the host 4.7% · guest 95.3%12:00 · the host 4.7% · guest 95.3%15:00 · the host 0.2% · guest 99.8%15:00 · the host 0.2% · guest 99.8%18:00 · the host 30% · guest 70%18:00 · the host 30% · guest 70%21:00 · the host 19.7% · guest 80.3%21:00 · the host 19.7% · guest 80.3%24:00 · the host 14.8% · guest 85.2%24:00 · the host 14.8% · guest 85.2%27:00 · the host 10.7% · guest 89.3%27:00 · the host 10.7% · guest 89.3%
Sharpest disagreement ▶ 14:30 Rejection of Official Sony Hack Attribution

Kim forcefully rejects the official US government claim that North Korea was behind the Sony hack, calling the government's IP address evidence flimsy.

Hardest push from the host ▶ 0:17 Challenging Breach Frequency Perception

Sonal challenges the premise that cyber breaches are actually increasing in frequency rather than just receiving heightened media and governmental coverage.

Biggest teaching moment ▶ 8:45 RSA Spam Folder Failure Example

Kim educates the hosts on human vulnerability in security by detailing how trained personnel at top security firm RSA retrieved a phishing email directly out of their spam folder.

The host holds their own ▶ 20:58 Wired Domain Expertise Citation

Sonal demonstrates technical domain fluency by referencing past industry discussions at Wired regarding the shift from passive defense to active offensive security.

the scores for every segment, with the reasoning behind each
ChapterTopicThe host as informed peerGuest teachingGuest disagreementThe host pushing backWhy
Target Breach Analysis and Third-Party Vendor Risks 2511 Sonal and Michael ask foundational questions regarding recent high-profile breaches like Target. Kim educates the hosts on third-party HVAC vendor access and how attackers pivot through supply chain connections.
Mechanics of Phishing, Spear Phishing, and Human Error 2621 Kim reframes Sonal's question about user ignorance by demonstrating personal phishing dynamics. She details spear-phishing mechanics and recounts how RSA employees manually retrieved phishing emails from spam folders.
Nation-State Threat Actors and Cyber Espionage Trends 2511 The hosts inquire about state-sponsored threat actors. Kim provides an informative breakdown of Chinese economic espionage and Russian hacking underground sophistication and legal immunity.
Ransomware Growth and Critical Analysis of the Sony Hack 3742 Kim aggressively critiques official government claims linking North Korea to the Sony breach. She delivers a detailed breakdown explaining why IP address evidence is flimsy and why released data aligns with anti-piracy underground motives rather than state action.
Corporate Breach Disclosure and Evolving Transparency Standards 3412 Sonal and Michael query corporate disclosure norms. Kim outlines evolving disclosure laws and explains how widespread breaches have reduced corporate embarrassment around reporting.
Active Defense Dilemmas and Internal Anomaly Monitoring 5522 Sonal demonstrates background knowledge from her time at Wired regarding active defense strategies. Kim details the legal risks under the Computer Fraud and Abuse Act and explains Target's alert fatigue failure.
Practical Security Recommendations and Podcast Conclusion 4411 The conversation moves to practical advice where hosts suggest biometrics and watermarking analogies. Kim provides concrete recommendations on cloud auditing and data seeding.

Statements from this episode (13)

Assertion Not checkable as stated
Zetter: Obama administration's cybersecurity focus drove private sector investment
“The government's focus on cybersecurity, and by government I mean the Obama administration specifically has made cybersecurity one of its primary focuses. And that has then trickled down and caused everyone else to focus on this more, because that means money …”
Kim Zetter Jan 2, 2019 ▶ 0:43
Insight
Zetter: Security improvements force hackers to retool rather than stopping them
“What changes is in some of these hacks is that we get a little smarter with security, and so the hackers have to go back and retool their techniques. But they do come back again. They come back with new techniques and new methods and new tools just to achieve …”
Kim Zetter Jan 2, 2019 ▶ 1:30
Prediction Held up
Zetter: Third-party vendors will increasingly become conduits for cyberattacks
“And that's something that I think we will see more of. We sort of see you know, victims get hacked, obviously, and their systems are insecure, but a growing problem are the issues with third-party vendors, contractors, other people that you work with that are …”
Kim Zetter Jan 2, 2019 ▶ 2:59
Assertion Supported
Verizon Report: Phishing Emails Are Opened Within 90 Seconds On Average
“A report came out this week from, ah, Verizon, ah, examining how long it takes, ah, someone to open a phishing email after it's landed in a company's network, and it takes on average about a minute and a half because someone in that company is going to open th…”
Kim Zetter Jan 2, 2019 ▶ 8:30
Assertion Supported
RSA was breached after an employee opened an email in spam
“This was a security company, one of the top security companies, RSA, that's having its conference next week. They got hit in a phishing attack in, ah, Around the same time that Google got hit. And in that case, they sent only a handful of emails to some specif…”
Kim Zetter Jan 2, 2019 ▶ 8:51
Assertion Not checkable as stated
Zetter: Chinese Hackers Do Not Conceal Tactics Due to State Support
“The Chinese don't necessarily try to hide their tactics because they are supported by their government, so they don't really have anything to worry about there.”
Kim Zetter Jan 2, 2019 ▶ 11:02
Assertion Supported
Zetter: US Authorities Must Wait for Russian Hackers to Travel Abroad
“It's hard to go after Russians. Little cooperation with the government, and so U.S. Authorities have to wait for someone to leave Russia and go, you know, on vacation to Thailand or someplace, and not been there.”
Kim Zetter Jan 2, 2019 ▶ 11:49
Prediction Held up
Zetter: Extortion through public data releases will become a major cyberattack trend
“The threat was, if you don't comply with our demands, We'll release the data, and I think that's what we're going to see more more of. I think that's a new trend that we're going to get.”
Kim Zetter Jan 2, 2019 ▶ 13:20
Assertion Not checkable as stated
Zetter: US government evidence attributing the Sony hack to North Korea is flimsy
“So the idea that the government would say definitively this is North Korea already is a little shaky. And what they've provided as evidence is an IP address that they say is, which they haven't even disclosed the IP address. All they've said is that an IP addr…”
Kim Zetter Jan 2, 2019 ▶ 14:37
Assertion Supported
Zetter: Hackers behind 2014 Sony breach never mentioned 'The Interview'
“But it was only after media reports started surfacing, quoting anonymous government officials about the Sony movie, that everyone then jumped on this bandwagon and said this was about the movie. But the hackers themselves never mentioned the movie.”
Kim Zetter Jan 2, 2019 ▶ 16:25
Assertion Not checkable as stated
Zetter: Companies increasingly self-disclose hacks on blog posts before customer notification
“Now we're actually seeing blog posts, things like that, where they are coming out and formally announcing the hack, and sometimes even before they notify the customers. So that's a growing trend, and I think that companies are realizing that they have to get o…”
Kim Zetter Jan 2, 2019 ▶ 19:07
Assertion Supported
Zetter: Microsoft uses civil lawsuits to dismantle botnets and malicious IP infrastructure
“We've seen this a couple of times with Microsoft, where they've gone to, ah, they filed a civil action court in order to get certain IP addresses or hosting companies taken down in order to control botnets and other malicious activities that's sort of, ah, con…”
Kim Zetter Jan 2, 2019 ▶ 22:59
Disclosure
Cybersecurity expert Kim Zetter avoids online banking and digital health records
“I don't do my, I don't do online banking. Okay. So I don't have a lot of trust in in those kinds of systems. I don't have a lot of I do very little. I don't put my health records online, that kind of thing. So I keep it as much to the minimum as I can.”
Kim Zetter Jan 2, 2019 ▶ 27:00
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.