Assertion certainty 4/5 debate potential 2/5

Provos: Google experienced zero successful employee phishing attacks after mandating hardware keys

Niels Provos · a16z Podcast | The State of Security · Jan 2, 2019 · at 5:34

Niels Provos, VP of Security Engineering at Google, discusses Google's deployment of hardware security keys during an a16z security panel.

0:00 / 0:12exact quote · 12.5s
▶ Watch the full episode on YouTube → 720p mp4 · rendered on demand · StarZero watermark
“We have mandated a hardware second factor for everybody at Google since 2009. You know, everybody is using a security key nowadays. We have not had a single successful phishing attack against a Google employee since then.”

quote is from the automated transcript, cleaned for reading: filler sounds and stutters are removed, nothing is rephrased. names can be misheard (the analysis reads context, assessments check outside sources). how →

More from Niels Provos

Insight
Niels Provos: Computer security is an incentive problem, not a tech problem
“It's probably not really a technology problem, it's an incentive problem.”
Niels Provos Jan 2, 2019 ▶ 3:33 a16z Podcast | The State of Security
Prediction Not checkable as stated
Provos: Everyone will rely on managed cloud providers for security by 2028
“In 10 years, everybody is going to be on a professionally run cloud that takes care of all of your security needs.”
Niels Provos Jan 2, 2019 ▶ 16:04 a16z Podcast | The State of Security
Assertion Not checkable as stated
Provos: Google cannot offer mandatory hardware security key protection to billions
“Google rolled out this advanced protection program where you are forced to associate a security key with your account. That's the only way that you can get into your account. But that is not something that we can offer to billions of users.”
Niels Provos Jan 2, 2019 ▶ 11:08 a16z Podcast | The State of Security
Assertion Contradicted
Niels Provos: Chromebooks with security keys create uncompromisable endpoints
“I continue to be a big proponent of something like a Chromebook with a security key, right? Essentially, you have an endpoint that cannot be compromised, even if you try. Because the weak point in all of this continues to be the human.”
Niels Provos Jan 2, 2019 ▶ 11:57 a16z Podcast | The State of Security
Insight
Provos: Security doesn't need to be perfect, just better than peers
“Well, another thing that remains true is, adversaries often go to the place where the bar is lower. Right? So you oftentimes don't need to achieve perfect security, as long as security is mostly higher than somebody else.”
Niels Provos Jan 2, 2019 ▶ 15:15 a16z Podcast | The State of Security
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 1,000 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.