Sep 29, 2020 · 1h 25m · knowledge-project

#93 Matt Holland: Zero Day

Matthew Holland · 56m spoken Shane Parrish · 21m spoken
0:00 / 0:00

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this in-depth interview on The Knowledge Project, cybersecurity pioneer and Field Effect Security CEO Matthew Holland joins Shane Parrish to demystify modern cyber threats, critique predatory commercial security practices, and share lessons from their careers in elite intelligence agencies.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. Shane holds 27.1% of the talking time here. How this is scored →

Shane as informed peer 5.0 Guest teaching 4.3 Guest disagreement 1.9 Shane pushing back 0.9
05100:0020:0040:001:00:001:20:001:21–5:43 · Shane as informed peer 6/10 Introducing Matthew Holland and Episode Overview Shane sets the stage with deep domain familiarity given his shared intelligence background with Matt. The exchange is warm and collegiate, establishing mutual respect from their early operational days.5:43–8:47 · Shane as informed peer 5/10 Bureaucratic Ceilings and Leaving Government Service Matt explains his frustration with arbitrary institutional ceilings and failing a management interview by answering technically rather than bureaucratically. Shane validates this from shared organizational memory.8:47–11:53 · Shane as informed peer 5/10 Founding Linchpin Labs and the Vista Driver Signing Stunt Matt recounts the founding stunt of Linchpin Labs, creating a spoof company to expose Microsoft Vista's driver signing flaws and dodging DMCA threats. Shane tracks the technical context seamlessly.11:53–14:03 · Shane as informed peer 6/10 Institutional Skepticism, Missing the Mission, and Going Private Shane reveals he accurately predicted Linchpin's massive commercial success while agency managers were dismissively predicting failure or betrayal. The tone is reflective and validating.14:03–17:02 · Shane as informed peer 5/10 Building Linchpin Labs and Removing Barriers for Talent Matt outlines his leadership philosophy of removing administrative barriers for elite technical talent, which Shane notes he also adopted in his own business.17:02–20:13 · Shane as informed peer 4/10 Exiting Linchpin Labs and Recognizing the Ceiling Matt describes recognizing when he became the square peg in a round hole post-acquisition. Shane guides the narrative smoothly around entrepreneurial transition.20:13–25:54 · Shane as informed peer 4/10 Founding Field Effect Security and Entrepreneurial Drive Matt launches into an energetic critique of the cybersecurity industry, breaking it down into three pillars and deriding marketing hype and fragmented point solutions.25:54–29:31 · Shane as informed peer 4/10 Corporate Espionage, Small Business Vulnerabilities, and Industry Failures Matt details how state-sponsored actors and cybercriminals increasingly target mid-sized professional firms like legal and accounting practices rather than just major enterprises.29:31–34:10 · Shane as informed peer 5/10 Fixing Small Business Security and the Field Effect Approach Matt critiques backward-looking industry benchmarks like the Gartner Magic Quadrant and explains how security vendors abandon SMBs to complex, unmanageable dashboards. Shane connects the model to Shopify's enablement strategy.34:10–36:31 · Shane as informed peer 4/10 The Attacker's Playbook: Profiling and Financial Redirection Matt walks through how basic credential stuffing and inbox surveillance lead to lucrative corporate invoice redirection schemes. Shane prompts with informed questions about cyber economics.36:31–41:49 · Shane as informed peer 6/10 Technical Exploit Chains, Kernel Access, and Mobile Vulnerabilities Matt breaks down technical exploit chains across Windows and iOS, illustrating sandbox escapes and kernel-level compromise. Shane demonstrates clear understanding of exploit architectures.41:49–45:01 · Shane as informed peer 5/10 The Security Realities and Fragmentation of Android Matt explains the paradox of Android's open architecture, where downstream OEM fragmentation creates persistent unpatched vulnerabilities despite upstream Google fixes.45:01–49:02 · Shane as informed peer 5/10 Mobile Surveillance, Zero-Click Exploits, and Ethical Dilemmas Matt explains zero-click versus one-click mobile exploits, highlighting NSO Group's WhatsApp vectors and questioning the genuine ethics of private offensive surveillance firms.49:02–53:51 · Shane as informed peer 4/10 Intellectual Property Leaks, NSA Tool Dumps, and Ransomware Realities Matt expresses frustration that ransomware continues to thrive despite being fundamentally straightforward to detect and block if endpoint tradecraft is applied properly.53:51–57:30 · Shane as informed peer 5/10 Ransomware Economics, Legal Liabilities, and Corporate Risk Aversion Shane and Matt discuss the moral hazard of ransomware extortion, cyber hostage negotiators, and CISOs using compliance frameworks merely to avoid liability.57:30–1:01:26 · Shane as informed peer 5/10 Demystifying Cybersecurity Sales Jargon and Evaluating Vendors Matt mocks cybersecurity sales buzzwords like 'next generation,' 'seamless,' and 'AI,' comparing the industry to deceptive used car salesmen selling dismembered auto parts.1:01:26–1:05:33 · Shane as informed peer 5/10 The Offensive Economy and the Zero-Day Disclosure Dilemma Matt reflects on the operational economics of zero-days in offensive intelligence, weighing the risk of burning capabilities against operational payoff.1:05:33–1:11:18 · Shane as informed peer 6/10 Huawei, 5G Supply Chains, and National Security Risks Shane and Matt dissect the Huawei 5G controversy, explaining why national security source-code auditing labs cannot scale to the velocity of modern firmware releases.1:11:18–1:16:55 · Shane as informed peer 6/10 Edward Snowden, Intelligence Realities, and Whistleblower Dynamics Matt delivers an impassioned critique of Edward Snowden, explaining internal legal vetting and operational harm while rejecting the public narrative of unchecked intelligence agencies.1:16:55–1:21:21 · Shane as informed peer 6/10 Institutional Bureaucracy and Unleashing Elite Technical Talent Shane highlights the 'stormtrooper problem' of post-Snowden bureaucratic hiring, while Matt agrees that escaping institutional red tape is what allows boutique offensive/defensive firms to thrive.1:21:21–1:23:22 · Shane as informed peer 4/10 Scaling Field Effect to 100 Employees and Driving Execution Matt concludes by discussing the necessity of aggressive execution when scaling past 100 employees and urges businesses not to delay securing expert cybersecurity support.1:21–5:43 · Guest teaching 3/10 Introducing Matthew Holland and Episode Overview Shane sets the stage with deep domain familiarity given his shared intelligence background with Matt. The exchange is warm and collegiate, establishing mutual respect from their early operational days.5:43–8:47 · Guest teaching 2/10 Bureaucratic Ceilings and Leaving Government Service Matt explains his frustration with arbitrary institutional ceilings and failing a management interview by answering technically rather than bureaucratically. Shane validates this from shared organizational memory.8:47–11:53 · Guest teaching 3/10 Founding Linchpin Labs and the Vista Driver Signing Stunt Matt recounts the founding stunt of Linchpin Labs, creating a spoof company to expose Microsoft Vista's driver signing flaws and dodging DMCA threats. Shane tracks the technical context seamlessly.11:53–14:03 · Guest teaching 2/10 Institutional Skepticism, Missing the Mission, and Going Private Shane reveals he accurately predicted Linchpin's massive commercial success while agency managers were dismissively predicting failure or betrayal. The tone is reflective and validating.14:03–17:02 · Guest teaching 3/10 Building Linchpin Labs and Removing Barriers for Talent Matt outlines his leadership philosophy of removing administrative barriers for elite technical talent, which Shane notes he also adopted in his own business.17:02–20:13 · Guest teaching 2/10 Exiting Linchpin Labs and Recognizing the Ceiling Matt describes recognizing when he became the square peg in a round hole post-acquisition. Shane guides the narrative smoothly around entrepreneurial transition.20:13–25:54 · Guest teaching 6/10 Founding Field Effect Security and Entrepreneurial Drive Matt launches into an energetic critique of the cybersecurity industry, breaking it down into three pillars and deriding marketing hype and fragmented point solutions.25:54–29:31 · Guest teaching 5/10 Corporate Espionage, Small Business Vulnerabilities, and Industry Failures Matt details how state-sponsored actors and cybercriminals increasingly target mid-sized professional firms like legal and accounting practices rather than just major enterprises.29:31–34:10 · Guest teaching 5/10 Fixing Small Business Security and the Field Effect Approach Matt critiques backward-looking industry benchmarks like the Gartner Magic Quadrant and explains how security vendors abandon SMBs to complex, unmanageable dashboards. Shane connects the model to Shopify's enablement strategy.34:10–36:31 · Guest teaching 6/10 The Attacker's Playbook: Profiling and Financial Redirection Matt walks through how basic credential stuffing and inbox surveillance lead to lucrative corporate invoice redirection schemes. Shane prompts with informed questions about cyber economics.36:31–41:49 · Guest teaching 6/10 Technical Exploit Chains, Kernel Access, and Mobile Vulnerabilities Matt breaks down technical exploit chains across Windows and iOS, illustrating sandbox escapes and kernel-level compromise. Shane demonstrates clear understanding of exploit architectures.41:49–45:01 · Guest teaching 6/10 The Security Realities and Fragmentation of Android Matt explains the paradox of Android's open architecture, where downstream OEM fragmentation creates persistent unpatched vulnerabilities despite upstream Google fixes.45:01–49:02 · Guest teaching 5/10 Mobile Surveillance, Zero-Click Exploits, and Ethical Dilemmas Matt explains zero-click versus one-click mobile exploits, highlighting NSO Group's WhatsApp vectors and questioning the genuine ethics of private offensive surveillance firms.49:02–53:51 · Guest teaching 6/10 Intellectual Property Leaks, NSA Tool Dumps, and Ransomware Realities Matt expresses frustration that ransomware continues to thrive despite being fundamentally straightforward to detect and block if endpoint tradecraft is applied properly.53:51–57:30 · Guest teaching 4/10 Ransomware Economics, Legal Liabilities, and Corporate Risk Aversion Shane and Matt discuss the moral hazard of ransomware extortion, cyber hostage negotiators, and CISOs using compliance frameworks merely to avoid liability.57:30–1:01:26 · Guest teaching 5/10 Demystifying Cybersecurity Sales Jargon and Evaluating Vendors Matt mocks cybersecurity sales buzzwords like 'next generation,' 'seamless,' and 'AI,' comparing the industry to deceptive used car salesmen selling dismembered auto parts.1:01:26–1:05:33 · Guest teaching 5/10 The Offensive Economy and the Zero-Day Disclosure Dilemma Matt reflects on the operational economics of zero-days in offensive intelligence, weighing the risk of burning capabilities against operational payoff.1:05:33–1:11:18 · Guest teaching 5/10 Huawei, 5G Supply Chains, and National Security Risks Shane and Matt dissect the Huawei 5G controversy, explaining why national security source-code auditing labs cannot scale to the velocity of modern firmware releases.1:11:18–1:16:55 · Guest teaching 4/10 Edward Snowden, Intelligence Realities, and Whistleblower Dynamics Matt delivers an impassioned critique of Edward Snowden, explaining internal legal vetting and operational harm while rejecting the public narrative of unchecked intelligence agencies.1:16:55–1:21:21 · Guest teaching 3/10 Institutional Bureaucracy and Unleashing Elite Technical Talent Shane highlights the 'stormtrooper problem' of post-Snowden bureaucratic hiring, while Matt agrees that escaping institutional red tape is what allows boutique offensive/defensive firms to thrive.1:21:21–1:23:22 · Guest teaching 4/10 Scaling Field Effect to 100 Employees and Driving Execution Matt concludes by discussing the necessity of aggressive execution when scaling past 100 employees and urges businesses not to delay securing expert cybersecurity support.1:21–5:43 · Guest disagreement 1/10 Introducing Matthew Holland and Episode Overview Shane sets the stage with deep domain familiarity given his shared intelligence background with Matt. The exchange is warm and collegiate, establishing mutual respect from their early operational days.5:43–8:47 · Guest disagreement 2/10 Bureaucratic Ceilings and Leaving Government Service Matt explains his frustration with arbitrary institutional ceilings and failing a management interview by answering technically rather than bureaucratically. Shane validates this from shared organizational memory.8:47–11:53 · Guest disagreement 2/10 Founding Linchpin Labs and the Vista Driver Signing Stunt Matt recounts the founding stunt of Linchpin Labs, creating a spoof company to expose Microsoft Vista's driver signing flaws and dodging DMCA threats. Shane tracks the technical context seamlessly.11:53–14:03 · Guest disagreement 2/10 Institutional Skepticism, Missing the Mission, and Going Private Shane reveals he accurately predicted Linchpin's massive commercial success while agency managers were dismissively predicting failure or betrayal. The tone is reflective and validating.14:03–17:02 · Guest disagreement 1/10 Building Linchpin Labs and Removing Barriers for Talent Matt outlines his leadership philosophy of removing administrative barriers for elite technical talent, which Shane notes he also adopted in his own business.17:02–20:13 · Guest disagreement 1/10 Exiting Linchpin Labs and Recognizing the Ceiling Matt describes recognizing when he became the square peg in a round hole post-acquisition. Shane guides the narrative smoothly around entrepreneurial transition.20:13–25:54 · Guest disagreement 3/10 Founding Field Effect Security and Entrepreneurial Drive Matt launches into an energetic critique of the cybersecurity industry, breaking it down into three pillars and deriding marketing hype and fragmented point solutions.25:54–29:31 · Guest disagreement 3/10 Corporate Espionage, Small Business Vulnerabilities, and Industry Failures Matt details how state-sponsored actors and cybercriminals increasingly target mid-sized professional firms like legal and accounting practices rather than just major enterprises.29:31–34:10 · Guest disagreement 2/10 Fixing Small Business Security and the Field Effect Approach Matt critiques backward-looking industry benchmarks like the Gartner Magic Quadrant and explains how security vendors abandon SMBs to complex, unmanageable dashboards. Shane connects the model to Shopify's enablement strategy.34:10–36:31 · Guest disagreement 1/10 The Attacker's Playbook: Profiling and Financial Redirection Matt walks through how basic credential stuffing and inbox surveillance lead to lucrative corporate invoice redirection schemes. Shane prompts with informed questions about cyber economics.36:31–41:49 · Guest disagreement 2/10 Technical Exploit Chains, Kernel Access, and Mobile Vulnerabilities Matt breaks down technical exploit chains across Windows and iOS, illustrating sandbox escapes and kernel-level compromise. Shane demonstrates clear understanding of exploit architectures.41:49–45:01 · Guest disagreement 2/10 The Security Realities and Fragmentation of Android Matt explains the paradox of Android's open architecture, where downstream OEM fragmentation creates persistent unpatched vulnerabilities despite upstream Google fixes.45:01–49:02 · Guest disagreement 3/10 Mobile Surveillance, Zero-Click Exploits, and Ethical Dilemmas Matt explains zero-click versus one-click mobile exploits, highlighting NSO Group's WhatsApp vectors and questioning the genuine ethics of private offensive surveillance firms.49:02–53:51 · Guest disagreement 2/10 Intellectual Property Leaks, NSA Tool Dumps, and Ransomware Realities Matt expresses frustration that ransomware continues to thrive despite being fundamentally straightforward to detect and block if endpoint tradecraft is applied properly.53:51–57:30 · Guest disagreement 2/10 Ransomware Economics, Legal Liabilities, and Corporate Risk Aversion Shane and Matt discuss the moral hazard of ransomware extortion, cyber hostage negotiators, and CISOs using compliance frameworks merely to avoid liability.57:30–1:01:26 · Guest disagreement 3/10 Demystifying Cybersecurity Sales Jargon and Evaluating Vendors Matt mocks cybersecurity sales buzzwords like 'next generation,' 'seamless,' and 'AI,' comparing the industry to deceptive used car salesmen selling dismembered auto parts.1:01:26–1:05:33 · Guest disagreement 1/10 The Offensive Economy and the Zero-Day Disclosure Dilemma Matt reflects on the operational economics of zero-days in offensive intelligence, weighing the risk of burning capabilities against operational payoff.1:05:33–1:11:18 · Guest disagreement 2/10 Huawei, 5G Supply Chains, and National Security Risks Shane and Matt dissect the Huawei 5G controversy, explaining why national security source-code auditing labs cannot scale to the velocity of modern firmware releases.1:11:18–1:16:55 · Guest disagreement 4/10 Edward Snowden, Intelligence Realities, and Whistleblower Dynamics Matt delivers an impassioned critique of Edward Snowden, explaining internal legal vetting and operational harm while rejecting the public narrative of unchecked intelligence agencies.1:16:55–1:21:21 · Guest disagreement 1/10 Institutional Bureaucracy and Unleashing Elite Technical Talent Shane highlights the 'stormtrooper problem' of post-Snowden bureaucratic hiring, while Matt agrees that escaping institutional red tape is what allows boutique offensive/defensive firms to thrive.1:21:21–1:23:22 · Guest disagreement 1/10 Scaling Field Effect to 100 Employees and Driving Execution Matt concludes by discussing the necessity of aggressive execution when scaling past 100 employees and urges businesses not to delay securing expert cybersecurity support.1:21–5:43 · Shane pushing back 1/10 Introducing Matthew Holland and Episode Overview Shane sets the stage with deep domain familiarity given his shared intelligence background with Matt. The exchange is warm and collegiate, establishing mutual respect from their early operational days.5:43–8:47 · Shane pushing back 1/10 Bureaucratic Ceilings and Leaving Government Service Matt explains his frustration with arbitrary institutional ceilings and failing a management interview by answering technically rather than bureaucratically. Shane validates this from shared organizational memory.8:47–11:53 · Shane pushing back 1/10 Founding Linchpin Labs and the Vista Driver Signing Stunt Matt recounts the founding stunt of Linchpin Labs, creating a spoof company to expose Microsoft Vista's driver signing flaws and dodging DMCA threats. Shane tracks the technical context seamlessly.11:53–14:03 · Shane pushing back 1/10 Institutional Skepticism, Missing the Mission, and Going Private Shane reveals he accurately predicted Linchpin's massive commercial success while agency managers were dismissively predicting failure or betrayal. The tone is reflective and validating.14:03–17:02 · Shane pushing back 1/10 Building Linchpin Labs and Removing Barriers for Talent Matt outlines his leadership philosophy of removing administrative barriers for elite technical talent, which Shane notes he also adopted in his own business.17:02–20:13 · Shane pushing back 1/10 Exiting Linchpin Labs and Recognizing the Ceiling Matt describes recognizing when he became the square peg in a round hole post-acquisition. Shane guides the narrative smoothly around entrepreneurial transition.20:13–25:54 · Shane pushing back 1/10 Founding Field Effect Security and Entrepreneurial Drive Matt launches into an energetic critique of the cybersecurity industry, breaking it down into three pillars and deriding marketing hype and fragmented point solutions.25:54–29:31 · Shane pushing back 1/10 Corporate Espionage, Small Business Vulnerabilities, and Industry Failures Matt details how state-sponsored actors and cybercriminals increasingly target mid-sized professional firms like legal and accounting practices rather than just major enterprises.29:31–34:10 · Shane pushing back 1/10 Fixing Small Business Security and the Field Effect Approach Matt critiques backward-looking industry benchmarks like the Gartner Magic Quadrant and explains how security vendors abandon SMBs to complex, unmanageable dashboards. Shane connects the model to Shopify's enablement strategy.34:10–36:31 · Shane pushing back 1/10 The Attacker's Playbook: Profiling and Financial Redirection Matt walks through how basic credential stuffing and inbox surveillance lead to lucrative corporate invoice redirection schemes. Shane prompts with informed questions about cyber economics.36:31–41:49 · Shane pushing back 1/10 Technical Exploit Chains, Kernel Access, and Mobile Vulnerabilities Matt breaks down technical exploit chains across Windows and iOS, illustrating sandbox escapes and kernel-level compromise. Shane demonstrates clear understanding of exploit architectures.41:49–45:01 · Shane pushing back 1/10 The Security Realities and Fragmentation of Android Matt explains the paradox of Android's open architecture, where downstream OEM fragmentation creates persistent unpatched vulnerabilities despite upstream Google fixes.45:01–49:02 · Shane pushing back 1/10 Mobile Surveillance, Zero-Click Exploits, and Ethical Dilemmas Matt explains zero-click versus one-click mobile exploits, highlighting NSO Group's WhatsApp vectors and questioning the genuine ethics of private offensive surveillance firms.49:02–53:51 · Shane pushing back 1/10 Intellectual Property Leaks, NSA Tool Dumps, and Ransomware Realities Matt expresses frustration that ransomware continues to thrive despite being fundamentally straightforward to detect and block if endpoint tradecraft is applied properly.53:51–57:30 · Shane pushing back 1/10 Ransomware Economics, Legal Liabilities, and Corporate Risk Aversion Shane and Matt discuss the moral hazard of ransomware extortion, cyber hostage negotiators, and CISOs using compliance frameworks merely to avoid liability.57:30–1:01:26 · Shane pushing back 1/10 Demystifying Cybersecurity Sales Jargon and Evaluating Vendors Matt mocks cybersecurity sales buzzwords like 'next generation,' 'seamless,' and 'AI,' comparing the industry to deceptive used car salesmen selling dismembered auto parts.1:01:26–1:05:33 · Shane pushing back 1/10 The Offensive Economy and the Zero-Day Disclosure Dilemma Matt reflects on the operational economics of zero-days in offensive intelligence, weighing the risk of burning capabilities against operational payoff.1:05:33–1:11:18 · Shane pushing back 1/10 Huawei, 5G Supply Chains, and National Security Risks Shane and Matt dissect the Huawei 5G controversy, explaining why national security source-code auditing labs cannot scale to the velocity of modern firmware releases.1:11:18–1:16:55 · Shane pushing back 1/10 Edward Snowden, Intelligence Realities, and Whistleblower Dynamics Matt delivers an impassioned critique of Edward Snowden, explaining internal legal vetting and operational harm while rejecting the public narrative of unchecked intelligence agencies.1:16:55–1:21:21 · Shane pushing back 1/10 Institutional Bureaucracy and Unleashing Elite Technical Talent Shane highlights the 'stormtrooper problem' of post-Snowden bureaucratic hiring, while Matt agrees that escaping institutional red tape is what allows boutique offensive/defensive firms to thrive.1:21:21–1:23:22 · Shane pushing back 0/10 Scaling Field Effect to 100 Employees and Driving Execution Matt concludes by discussing the necessity of aggressive execution when scaling past 100 employees and urges businesses not to delay securing expert cybersecurity support.

speaking balance: gold is Shane, purple is the guest (3 minute bins)

0:00 · Shane 72.6% · guest 27.4%0:00 · Shane 72.6% · guest 27.4%3:00 · Shane 29.2% · guest 70.8%3:00 · Shane 29.2% · guest 70.8%6:00 · Shane 22.1% · guest 77.9%6:00 · Shane 22.1% · guest 77.9%9:00 · Shane 6.6% · guest 93.4%9:00 · Shane 6.6% · guest 93.4%12:00 · Shane 30.3% · guest 69.7%12:00 · Shane 30.3% · guest 69.7%15:00 · Shane 28.9% · guest 71.1%15:00 · Shane 28.9% · guest 71.1%18:00 · Shane 28.7% · guest 71.3%18:00 · Shane 28.7% · guest 71.3%21:00 · Shane 19.4% · guest 80.6%21:00 · Shane 19.4% · guest 80.6%24:00 · Shane 16.3% · guest 83.7%24:00 · Shane 16.3% · guest 83.7%27:00 · Shane 45.1% · guest 54.9%27:00 · Shane 45.1% · guest 54.9%30:00 · Shane 31.7% · guest 68.3%30:00 · Shane 31.7% · guest 68.3%33:00 · Shane 17.4% · guest 82.6%33:00 · Shane 17.4% · guest 82.6%36:00 · Shane 29.8% · guest 70.2%36:00 · Shane 29.8% · guest 70.2%39:00 · Shane 17.4% · guest 82.6%39:00 · Shane 17.4% · guest 82.6%42:00 · Shane 9.4% · guest 90.6%42:00 · Shane 9.4% · guest 90.6%45:00 · Shane 30.1% · guest 69.9%45:00 · Shane 30.1% · guest 69.9%48:00 · Shane 16.2% · guest 83.8%48:00 · Shane 16.2% · guest 83.8%51:00 · Shane 14.8% · guest 85.2%51:00 · Shane 14.8% · guest 85.2%54:00 · Shane 20% · guest 80%54:00 · Shane 20% · guest 80%57:00 · Shane 20.6% · guest 79.4%57:00 · Shane 20.6% · guest 79.4%1:00:00 · Shane 11.4% · guest 88.6%1:00:00 · Shane 11.4% · guest 88.6%1:03:00 · Shane 41.6% · guest 58.4%1:03:00 · Shane 41.6% · guest 58.4%1:06:00 · Shane 17.6% · guest 82.4%1:06:00 · Shane 17.6% · guest 82.4%1:09:00 · Shane 33.5% · guest 66.5%1:09:00 · Shane 33.5% · guest 66.5%1:12:00 · Shane 11.5% · guest 88.5%1:12:00 · Shane 11.5% · guest 88.5%1:15:00 · Shane 64.4% · guest 35.6%1:15:00 · Shane 64.4% · guest 35.6%1:18:00 · Shane 31.7% · guest 68.3%1:18:00 · Shane 31.7% · guest 68.3%1:21:00 · Shane 28.2% · guest 71.8%1:21:00 · Shane 28.2% · guest 71.8%1:24:00 · Shane 64% · guest 36%1:24:00 · Shane 64% · guest 36%
Sharpest disagreement ▶ 1:14:00 Impassioned condemnation of Edward Snowden's leak

Matt forcefully rejects the whistleblower narrative, condemning Snowden for leaking unredacted legitimate intelligence programs and setting defensive missions back years.

Hardest push from Shane ▶ 56:36 Shane probes the superficiality of corporate cyber compliance

Shane challenges the distinction between genuine organizational defense and cynical box-checking meant only to protect executives from legal liability.

Biggest teaching moment ▶ 1:08:15 Why government code review labs fail against firmware updates

Matt methodically breaks down why government source code review programs fail in practice due to the sheer volume and velocity of modern OEM software releases.

Shane holds their own ▶ 1:17:20 Shane's breakdown of institutional hiring blind spots

Shane articulates the 'stormtrooper problem,' detailing how rigid post-Snowden vetting filtered out unconventional talent and created bureaucratic homogeneity.

the scores for every segment, with the reasoning behind each
ChapterTopicShane as informed peerGuest teachingGuest disagreementShane pushing backWhy
Introducing Matthew Holland and Episode Overview 6311 Shane sets the stage with deep domain familiarity given his shared intelligence background with Matt. The exchange is warm and collegiate, establishing mutual respect from their early operational days.
Bureaucratic Ceilings and Leaving Government Service 5221 Matt explains his frustration with arbitrary institutional ceilings and failing a management interview by answering technically rather than bureaucratically. Shane validates this from shared organizational memory.
Founding Linchpin Labs and the Vista Driver Signing Stunt 5321 Matt recounts the founding stunt of Linchpin Labs, creating a spoof company to expose Microsoft Vista's driver signing flaws and dodging DMCA threats. Shane tracks the technical context seamlessly.
Institutional Skepticism, Missing the Mission, and Going Private 6221 Shane reveals he accurately predicted Linchpin's massive commercial success while agency managers were dismissively predicting failure or betrayal. The tone is reflective and validating.
Building Linchpin Labs and Removing Barriers for Talent 5311 Matt outlines his leadership philosophy of removing administrative barriers for elite technical talent, which Shane notes he also adopted in his own business.
Exiting Linchpin Labs and Recognizing the Ceiling 4211 Matt describes recognizing when he became the square peg in a round hole post-acquisition. Shane guides the narrative smoothly around entrepreneurial transition.
Founding Field Effect Security and Entrepreneurial Drive 4631 Matt launches into an energetic critique of the cybersecurity industry, breaking it down into three pillars and deriding marketing hype and fragmented point solutions.
Corporate Espionage, Small Business Vulnerabilities, and Industry Failures 4531 Matt details how state-sponsored actors and cybercriminals increasingly target mid-sized professional firms like legal and accounting practices rather than just major enterprises.
Fixing Small Business Security and the Field Effect Approach 5521 Matt critiques backward-looking industry benchmarks like the Gartner Magic Quadrant and explains how security vendors abandon SMBs to complex, unmanageable dashboards. Shane connects the model to Shopify's enablement strategy.
The Attacker's Playbook: Profiling and Financial Redirection 4611 Matt walks through how basic credential stuffing and inbox surveillance lead to lucrative corporate invoice redirection schemes. Shane prompts with informed questions about cyber economics.
Technical Exploit Chains, Kernel Access, and Mobile Vulnerabilities 6621 Matt breaks down technical exploit chains across Windows and iOS, illustrating sandbox escapes and kernel-level compromise. Shane demonstrates clear understanding of exploit architectures.
The Security Realities and Fragmentation of Android 5621 Matt explains the paradox of Android's open architecture, where downstream OEM fragmentation creates persistent unpatched vulnerabilities despite upstream Google fixes.
Mobile Surveillance, Zero-Click Exploits, and Ethical Dilemmas 5531 Matt explains zero-click versus one-click mobile exploits, highlighting NSO Group's WhatsApp vectors and questioning the genuine ethics of private offensive surveillance firms.
Intellectual Property Leaks, NSA Tool Dumps, and Ransomware Realities 4621 Matt expresses frustration that ransomware continues to thrive despite being fundamentally straightforward to detect and block if endpoint tradecraft is applied properly.
Ransomware Economics, Legal Liabilities, and Corporate Risk Aversion 5421 Shane and Matt discuss the moral hazard of ransomware extortion, cyber hostage negotiators, and CISOs using compliance frameworks merely to avoid liability.
Demystifying Cybersecurity Sales Jargon and Evaluating Vendors 5531 Matt mocks cybersecurity sales buzzwords like 'next generation,' 'seamless,' and 'AI,' comparing the industry to deceptive used car salesmen selling dismembered auto parts.
The Offensive Economy and the Zero-Day Disclosure Dilemma 5511 Matt reflects on the operational economics of zero-days in offensive intelligence, weighing the risk of burning capabilities against operational payoff.
Huawei, 5G Supply Chains, and National Security Risks 6521 Shane and Matt dissect the Huawei 5G controversy, explaining why national security source-code auditing labs cannot scale to the velocity of modern firmware releases.
Edward Snowden, Intelligence Realities, and Whistleblower Dynamics 6441 Matt delivers an impassioned critique of Edward Snowden, explaining internal legal vetting and operational harm while rejecting the public narrative of unchecked intelligence agencies.
Institutional Bureaucracy and Unleashing Elite Technical Talent 6311 Shane highlights the 'stormtrooper problem' of post-Snowden bureaucratic hiring, while Matt agrees that escaping institutional red tape is what allows boutique offensive/defensive firms to thrive.
Scaling Field Effect to 100 Employees and Driving Execution 4410 Matt concludes by discussing the necessity of aggressive execution when scaling past 100 employees and urges businesses not to delay securing expert cybersecurity support.

Statements from this episode (33)

Disclosure
Holland: Founders bypassed Vista using fake company DenWipAtsiv, 'Vista Pwned' backwards
“So what we did was we wrote a tool called DenWipAtsiv. The name of the company was DenWipAtsiv, which is Vista pooned in reverse. You know, got a signing certificate under this fake company, legitimately registered fake in reality, and released a tool that wou…”
Matthew Holland Sep 29, 2020 ▶ 10:06
Assertion Not checkable as stated
Parrish: Intelligence agency awarded Holland tens of millions after vowing not to
“I remember going to a meeting a couple of weeks after he left and they were like, oh, we're not going to buy anything from him. And I was like, we're going to end up giving this guy like fifty million bucks a year. I want to say I was closer to reality than th…”
Shane Parrish Sep 29, 2020 ▶ 13:50
Insight
Parrish: Giving employees requested tools removes excuses for poor delivery
“There's a downside to that too, which is really interesting because then you lose the excuse of the equipment's the problem. If only I had the right tools I could like deliver, right? Like, so you, there's a subtle sort of undercurrent to it, which is I expect…”
Shane Parrish Sep 29, 2020 ▶ 16:08
Opinion
Holland: The cybersecurity industry is an unethical shit show
“The current state of the cybersecurity industry, to say it's a hard problem is an understatement. It is a, an unethical shit show, I would say, and it really bothers me where it's at.”
Matthew Holland Sep 29, 2020 ▶ 20:36
Insight
Holland: Offensive hacking only exists because humans write bad software
“The first bit only exists because humans Are generally horrible at writing software. So that wouldn't exist if people were actually good at security models and implementing software.”
Matthew Holland Sep 29, 2020 ▶ 23:45
Opinion
Holland: Commercial security vendors falsely claim businesses need every tool
“And the way that vendors will try to push it forward is they say, you actually need all of that, which is total crap. You do not need all of those things. They do not work well together.”
Matthew Holland Sep 29, 2020 ▶ 24:55
Opinion
Holland: Social media influence campaigns are not actual cybersecurity
“What are the organized influence, influential campaigns on, on social media to get people to vote in particular directions? I do not think that's cybersecurity, but that also gets lumped in.”
Matthew Holland Sep 29, 2020 ▶ 25:38
Assertion Supported
Holland: State-sponsored hackers target law and patent firms over corporate giants
“And I don't think it necessarily extends just to large companies at this point, legal firms accountants, huge targets. I mean, you think about what they're dealing with in regards to confidential agreements, financials of individuals and companies. And that's …”
Matthew Holland Sep 29, 2020 ▶ 26:29
Opinion
Holland: Gartner's Magic Quadrant is continually outdated and behind the curve
“The Gardner Quadrant system is often outdated. We were For example, Field Effect was marketing a managed detect and response service well before it was defined in Gartner. And ironically, at the time, we had a hard time, you know, gaining traction.”
Matthew Holland Sep 29, 2020 ▶ 29:57
Opinion
Holland: Most cybersecurity vendors prioritize flashy interfaces over solving problems
“And that is largely a component that I don't think most vendors in the cybersecurity industry get. They are more interested in showing you, check out this really cool interface, which, you know, no one in your company is probably going to know how to use.”
Matthew Holland Sep 29, 2020 ▶ 32:24
Insight
Holland: Assuming average businesses care about cybersecurity is a false premise
“And then that, I mean, I think the assumption that the average business is going to care about cybersecurity is, is a false starting point. Because businesses, you know, you buy your computer hardware, you get your IT set up. If I'm a business and I, you know,…”
Matthew Holland Sep 29, 2020 ▶ 32:46
Insight
Holland: Invoice redirection fraud via compromised email is surprisingly effective
“The other approach that we see quite a bit is people don't use multi-factor authentication with just a basic email setup. So brute force, brute forcing passwords works. Somebody gets in, We'll scope out your inbox and see what's there. Who are your customers? …”
Matthew Holland Sep 29, 2020 ▶ 35:12
Insight
Holland: Operating system zero-day vulnerabilities are an unavoidable permanent problem
“The zero-day problem is something that's always going to be there. I think this is something that a lot of vendors don't actually realize, that no matter how much you lock down your operating system, there's always going to be a creative group out there that d…”
Matthew Holland Sep 29, 2020 ▶ 40:21
Opinion
Holland: Bypassing Apple's core mitigations allows attackers to compromise any device globally
“All you need to do is get around these set of mitigations, and you now can own any Apple device in the world.”
Matthew Holland Sep 29, 2020 ▶ 40:55
Assertion Supported
Holland: Samsung Android 11 builds may lack upstream security fixes
“You could have, you know, the latest Samsung phone running Android 11 that doesn't actually have all of the security fixes that the main Android branch has.”
Matthew Holland Sep 29, 2020 ▶ 43:13
Insight
Holland: Android fragmentation prevents mass attacks better than Apple iOS
“The nature of Android also creates a scenario where there's so many different flavors of Android, it makes it much more difficult to create a mass attack. Whereas on iOS, because it's the same version of the operating system across the board on every device, i…”
Matthew Holland Sep 29, 2020 ▶ 44:12
Opinion
Holland: Targeted attacks are more likely to succeed on Android than iOS
“The odds of being hit in a mass attack are potentially lower, but if somebody is targeting you, I would say that the odds of, you know, you, them being successful against you are higher on Android for sure.”
Matthew Holland Sep 29, 2020 ▶ 44:50
Opinion
Holland: NSO Group cannot be trusted to make ethical decisions
“They have a whole group now or whole internal group within the company that I've read dedicated to making sure they make ethical decisions. I don't, Personally trust that they're making ethical decisions.”
Matthew Holland Sep 29, 2020 ▶ 47:48
Opinion
Holland: Running a one-year-old Android OS makes users significant targets
“Pretty confident that if you're rocking a version of Android that's a year old, you're probably a pretty big target, and that, You know, again, I don't mean to pick on Android, but that is just a reality of how that ecosystem has evolved.”
Matthew Holland Sep 29, 2020 ▶ 48:49
Opinion
Holland: Ransomware is the easiest malware to detect and stop
“Ransomware in general, I don't get how it even exists. It is the easiest malware to detect and stop. How there's even an industry around that blows my mind.”
Matthew Holland Sep 29, 2020 ▶ 50:50
Insight
Holland: Network monitoring solutions cannot stop ransomware
“A network monitoring solution will not stop ransomware. There's nothing you can do about that. Yeah, you have to be on host, and you have to have a measure of sophistication and tradecraft to identify and block it.”
Matthew Holland Sep 29, 2020 ▶ 53:01
Insight
Holland: Law enforcement lacks bandwidth to investigate small business ransomware attacks
“The challenge would not necessarily be the difficulty. It would be the average Any person or business getting any agency to care, to track it down. Because that, intel agencies, law enforcement agencies aren't sitting around waiting for things to do. You know,…”
Matthew Holland Sep 29, 2020 ▶ 54:30
Insight
Holland: Ransomware attacks are inevitable, making prevention far cheaper than response
“Much easier and cheaper to be preventative and to harden your system and be ready for attacks. I mean, that is the reality of today, and anybody who thinks otherwise is, you know, they've got their head in their sand. You're going to get ransomwared. Bad thing…”
Matthew Holland Sep 29, 2020 ▶ 55:44
Opinion
Holland: Relying on legacy security vendors for liability safety is naive
“It's the safe way to go, but it is not the best thing for the company. It is not it is not forward facing. It is, I think it's being naive in regards to the type of attacks that are coming.”
Matthew Holland Sep 29, 2020 ▶ 57:18
Assertion Not checkable as stated
Holland: Modern security machine learning is just 2005 antivirus analytics
“The existing machine learning implementations and a lot of solutions out there is the exact same thing that, you know, I've seen in antiviruses back in 2005. They just didn't call it machine learning. It was just training analytics to look for anomalies and.”
Matthew Holland Sep 29, 2020 ▶ 1:01:12
Assertion Supported
Holland: Huawei clearly used leaked Cisco intellectual property in 2003–2004
“It was back in 2003, 2004, but there was a very clear cut case that Huawei was using conveniently leaked intellectual property.”
Matthew Holland Sep 29, 2020 ▶ 1:06:21
Opinion
Holland: Countries cannot trust Huawei for 5G wireless infrastructure
“If a nation is going to re-kit their entire country with a new type of wireless gear, especially with the complexities of five G, you need to trust that vendor. You need to be sure that the interests of that vendor are at the very least not opposed to the inte…”
Matthew Holland Sep 29, 2020 ▶ 1:07:33
Opinion
Holland: Snowden leaked legitimate programs just to insult the intelligence community
“Why did he, you know, expose completely legitimate legal intelligence gathering programs that have a ton of people's names associated with that? Why did he go out the door with that? And that, I think, is what I have a much larger problem with in that, you kno…”
Matthew Holland Sep 29, 2020 ▶ 1:14:22
Assertion Not checkable as stated
Parrish: Snowden's leak of exploitation techniques cost people lives
“You can just reveal the details of the programs, but the actual techniques that he revealed, the software techniques, the exploitation techniques that, I mean, that, that definitely cost people lives that had a huge impact on people working there.”
Shane Parrish Sep 29, 2020 ▶ 1:15:00
Opinion
Holland vehemently opposes any pardon for Edward Snowden
“A little part of me will die if he is pardoned.”
Matthew Holland Sep 29, 2020 ▶ 1:15:53
Insight
Parrish: Bureaucratic hiring creates homogeneous teams with shared blind spots
“What happens is like post Snowden you end up hiring, I call it the storm trooper problem, which is like you end up basically hiring the same type of person, right? They're sort of like never had a problem in their life. They get straight A's. They do all the r…”
Shane Parrish Sep 29, 2020 ▶ 1:17:21
Assertion Contradicted
Holland: Google's Project Zero was largely built with ex-intelligence talent
“I mean, Google's Project Zero is largely built from people who have exited the intelligence industry with a chip on their shoulder.”
Matthew Holland Sep 29, 2020 ▶ 1:21:13
Insight
Holland: No company is too small to be targeted by cyber attackers
“Everybody is a target at this point. Your company is not small enough to be off An attacker's radar. I have seen five person companies. Actually, I've seen two person companies attacked and hit.”
Matthew Holland Sep 29, 2020 ▶ 1:23:59
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 200 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.