The Exchanges

Every argument clarity score on this site is built from rows on this page. Each question and answer was assessed with names hidden, the host's own answers included, on four things from 1 to 5: directness (does it answer the question asked), coherence (do the ideas follow), precision (concrete details and clear references), compression (says a lot per word). The weighted mix (30/30/25/15) is the exchange score. A person's published score averages their exchange scores on raw tape only, at least 8 of them, shrunk toward the cohort mean. Full method →

Matthew Holland no published score: no usable exchanges on raw tape, and a fair score needs 8+ · coarse estimate ≈4.0/5 from 14 produced feed exchanges record → ← everyone

Every exchange below was scored with names hidden, four dimensions each from 1 to 5. An exchange's score is 0.30·directness + 0.30·coherence + 0.25·precision + 0.15·compression. The published score averages the raw tape exchange scores and shrinks small samples toward the cohort mean, so five great answers can't beat twenty good ones. Produced feed rows count only toward coarse estimates, never toward a full score.

clear all ✕
14exchanges match
0on raw tape
0redirected or not addressed
Answered produced feed D 5 · C 5 · P 5 · Cm 5 5.00

Q Let's flip that around and, uh, what people don't often see, which you can add uniquely is sort of what's the mind of the attacker. Like if you're looking at acquiring, um, valuable information from a company, walk me through that whole process. Like how do you think about that? How do you go about doing that? What does that look like?

A So initially an attacker is going to profile the target, and that can look like different things. So if, you know, the target has online services, they'll probe those services to see what's there. Are there any email addresses on your website that are really easy to identify? What type of social media presence is there? And that ultimately will lead into typically a social engineering campaign, either in the form of You know, an email that is received that looks really normal, that you want to trust, and hopefully will get you to click on something, or double click on an attachment, or it'll go to your phone, you click on that, and that exploitation occurs. The other approach that we see quite a bit is people don't use multi-factor authentication with just a basic email setup. So brute force, brute forcing passwords works. Somebody gets in, We'll scope out your inbox and see what's there. Who are your customers? What's your routine? And then they will perform perhaps a financial redirection. So in that case, they would get an idea of what your entire portfolio is and email all of your customers and say, hey, here's your new payment instructions. And they will have all the outstanding invoices already, uh, you know, listed and ready to go. So they can immediately say, you know, you owe us X amount. This is where I want you to send this money now. And That is remarkably and surpr…

AI assessment note: “initially an attacker is going to profile the target, and that can look like different things.”

Answered produced feed D 5 · C 5 · P 5 · Cm 4 4.85

Q more so than we think. Become more prevalent. They'll become the surface of which gets commonly attacked. Walk me through, like, how does phone exploitation even work? Like, is it the same sort of system that you would use for Windows or Apple? Is it different? Like, how do you attack the phone? You have this thing on you all the time. It's got a mic. It's got a camera.

A So the, the unfortunate answer is the exact same way you'd go after every other type of computer. Uh, iOS is just an operating system. Android is just an operating system. There's, there's no, there's no special features that make it impervious to attack. There, there are different security mechanisms in place that an attacker needs to get around, but it's the same deal. So if I'm going after your Windows laptop in the scenario that I described where I send you an email on Mobiles, uh, it's the same thing, and it's actually worse in some cases. Uh, about a year ago, a company out of Israel called NSL Group, they got busted for having a WhatsApp zero, uh, zero click mechanism. So there, there's some quick lingo dive here. Uh, one click versus zero click. One click is you have to social engineer somebody to the point where they can click on a link and exploit the phone. Zero click is where there's nothing you can do. You are just Owned, and you have no idea.

AI assessment note: “the unfortunate answer is the exact same way you'd go after every other type”

Answered produced feed D 5 · C 5 · P 4 · Cm 4 4.60

Q And then, that was the most insane period of time ever, right? We're in this small team. September 11th happens. The world forever changes. Our team works nonstop for effectively seven years. Like, I don't remember Any of us having vacation from 2001 to 2008 other than like a random Monday or something?

A Yeah, I mean, firstly, I think vacation is probably largely overrated just because I'm a workaholic. But yeah, no, it was a really neat way to start. I mean, our career is, you know, just a year or two apart, but it was definitely a very interesting experience being thrust into a, an environment where everything you do contributes much more than you would ever think. Because coming out of university, you know, you're You want to get a job with a good salary. All of a sudden you're, in our case, we're doing things that actually matter to the country, that have a very significant outcome. And, uh, it, it, it's like going from zero to mature very, very quickly.

AI assessment note: “firstly, I think vacation is probably largely overrated just because I'm a workaholic.”

Answered produced feed D 5 · C 5 · P 4 · Cm 4 4.60

Q And then when you left, do you, do you ever feel like there was, they didn't want you to succeed because they wanted you to come back? Was there a part of you that felt like they didn't want to give you contracts? They didn't want to.

A I, I don't know if there's any, any interest in me coming back. I think there was definitely skepticism as to whether I could succeed, which, um, it's, I'm, I'm fine with that. I mean, You know, clearly, at the time, my business partner and I were the first ones to kind of make that jump and do that together, and there was a lot of skepticism as to whether we should be allowed to do that, whether we are able to do that. I remember having a departure interview with a Hyatt manager who sat me down and said, you're gonna go sell to China. You're gonna enable China. And I looked at him in the eye, and I said, what on earth would make you think I would ever do that? That is the most ridiculous thing ever. So, so I think there was a bit of fear that we would enable, you know, adversaries of, of allied countries, which, yeah, I mean, in retrospect, I can understand. I just think at the time it was a, uh, it was an immature view.

AI assessment note: “I don't know if there's any, any interest in me coming back.”

Answered produced feed D 5 · C 5 · P 4 · Cm 4 4.60

Q worry about building a, You don't have to worry about managing inventory. You don't have to worry about their arming the rebels, if you will, against Amazon. Like, are you giving world-class technology to small and medium-sized businesses as a means to, like, you don't really have to know all the ins and outs of cybersecurity, but then it becomes trust-based. Like, why would I trust you over another vendor?

A Uh, that's a great question. I mean, I think trust takes time. You don't just, uh, magically get trust, right? Out of the gate. And I, and I think that is a, uh, that is something we put a lot of time into building. We take time to create a customer relationship. Uh, ask customers what their needs are. What are their problems? And then, you know, tell us about your network. How can we help you? Um, and, you know, early on in that process, I, I think it becomes clear that we're not just out trying to sell software in a commoditized way. The first thing we do is do an external view of the network and, and identify, okay, here's a problem right here. We want to help you fix problems. It's not just Here is a solution that you have to run with. It is all about us helping you be better, fixing problems, and sustaining that moving forward. And that is largely a component that I don't think most vendors in the cybersecurity industry get. They are more interested in showing you, check out this really cool interface, which, you know, no one in your company is probably going to know how to use.

AI assessment note: “we're not just out trying to sell software in a commoditized way.”

Answered produced feed D 5 · C 5 · P 4 · Cm 4 4.60

Q So you would rather go up against an Android phone than an iPhone if you were an attacker?

A Uh, that's an interesting question. I think the odds of getting, uh, exploited are higher on Android. Although the, the nature of Android also creates a scenario where there's so many different flavors of Android, it makes it much more difficult to create a mass attack. Whereas on iOS, because it's the same version of the, of the operating system across the board on every device, if you can find a problem in that, you get all those devices. On Android, you get the nuances. I put nuances in quotes of some of the decisions that Individual vendors will make that, that makes it very difficult to take an attack on Samsung and apply it to, I don't know, a Google phone or a ZTE phone. So it's, I would say generally it's the security position on Android is, is, is worse. You know, the, the odds of being hit in a mass attack are potentially lower, but if somebody is targeting you, I would say that the odds of, you know, you, them being successful against you are higher on Android for sure.

AI assessment note: “the odds of getting, uh, exploited are higher on Android”

Answered produced feed D 5 · C 5 · P 4 · Cm 4 4.60

Q You're almost a hundred. You're entirely self-funded to this point. So you basically took All this money you made, and you were like, oh, I want to do this again, and I'm going to put it all on the line. Like, what went into that thinking?

A Several factors. I, I think, I, I really enjoy solving hard problems, and the, the, the current state of the cybersecurity industry, to say it's a hard problem is an understatement. Um, it is a, is a, an unethical shit show, I would say, and it, it really bothers me, uh, where it's at. So I think there's a, there's a large part of me that wants to fix that. There's also the aspect of, I'm, like, ultimately a serial entrepreneur, and, and, I remember chatting with my wife, like, when that transition was happening, she asked me, like, why are you doing this? And I was like, what else am I going to do? I'm just going to start something else, and it's either, you know, a cybersecurity company that I'm once again running that I believe can change the world and fix a lot of problems, or I can open a coffee shop. Probably going to take the same amount of time, so how about the The cybersecurity firm.

AI assessment note: “Several factors. I, I think, I, I really enjoy solving hard problems”

Answered produced feed D 5 · C 4 · P 4 · Cm 4 4.30

Q We spent a lot of time together. What made you leave?

A So I, I, I, I reflect on that quite a bit, um, just because I get that question often, and I don't think I've ever really had a good answer that that wasn't necessarily immature. The ultimate reason I left was because I saw a limit to what I could grow into and what the vision of the group I was in achieving was. Like, there was a ceiling arbitrarily put on top of that. And I'm the type of person that I, I don't work well when somebody says, this is as far as you can go, or this is what we're going to do, regardless of what the evidence, uh, or ideas or good ideas, bad ideas, whatever. That, that stopped, and it was not an environment that I said, I can grow here anymore. Um, one of the big indicators of that, which, um, you'll probably laugh at this, but there's a, there's a management competition. I screwed up the entire, the entire, uh, interview, but it was the same problem where Somebody would ask, you know, the interviewer would ask me a question, and rather than give them the answer of, you know, I would, I would build a team to do this. I would request funding to do this. I would, uh, you know, reach out to universities to bring them into the, into the fold. So, you know, that's the answers they wanted to hear. What I gave them were the technical responses to the questions they were asking. So how would you solve this problem? My answer was, well, I would do X, Y, Z. An…

AI assessment note: “The ultimate reason I left was because I saw a limit to what I could grow”

Answered produced feed D 5 · C 4 · P 4 · Cm 4 4.30

Q Uh, I wanna, I wanna come back to that, but what are some of the lessons you learned from growing, scaling, running that company, recruiting?

A I think, I think one of the biggest things was I, you know, starting a company from scratch, Um, you know, at that time, I, I, I had a computer science background. I clearly had a lot of experience in, in cyber security. You know, I took some accounting courses and marketing courses in university, so I think there was a bit of a foundation as to, okay, if, you know, I remember doing a business plan because that was one thing you did. You made a business plan. But one thing through the Lynchman experience that I, that I got to have was I got to do every job. So I got to Literally be the janitor. I got to be the marketing person. I got to be the primary salesperson. I remember doing really challenging sales pitches in front of audiences that didn't even want me in the room because I was, you know, stamping on their, their creative territory. I got to write code. I got to manage projects. I got to be the, the evangelist in the company. And going from there to field effects with that base, I think allows me to really, you know, make decisions that are more informed. It allows me to, to, I guess, understand and appreciate all the different parts of field effect and that, which is a much more, uh, diverse.

AI assessment note: “one thing through the Lynchman experience that I, that I got to have was I got to do every job.”

Answered produced feed D 5 · C 3 · P 4 · Cm 3 3.85

Q Was there CIA ones, or am I making that up?

A No, there was one that was rooted, vault seven was, was that group, was that leak, I guess. Um, the one I'm referring to, um, was, uh, from NSA, and it was a, it was a whole treasure trove of tools, and this one was particularly interesting because it really, there are events that occur that destabilize, I guess, the defensive posture, Ransomware in general, I don't get how it even exists. It is the easiest malware to detect and stop. How there's even an industry around that blows my mind. But the attack vector that people use to wrap ransomware, the payload, weaponize that chain that I talked about earlier, basically allowed a, you know, a point and exploit capability on patched Windows machines.

AI assessment note: “No, there was one that was rooted, vault seven was, was that leak”

Answered produced feed D 3 · C 4 · P 4 · Cm 3 3.55

Q And how does that work? Like on a particular client, I can understand how those things communicate, but then how do you, how do you take an attack on one company and then translate that into a defense on another company with something you haven't seen before?

A So I guess largely that depends on how well the cybersecurity solution is implemented. If it is part of a network where you can dynamically signature an attack quickly, And create an artifact, we'll say, that can be applied across the network of other customers. That is a way to combat against that. I mean, the zero-day problem is something that's always going to be there. I think this is something that a lot of vendors don't actually realize, that no matter how much you lock down your operating system, there's always going to be a creative group out there that does things better, that can get around it. I mean, if you look at Apple, Apple iPhone, for the past I don't know, I'll say decade. They've been adding an increasing number of security mechanisms into the operating system that largely limit an operator to only being able to do specific things. But that is largely crippling from a security standpoint, because all you need to do is get around these set of mitigations, and you now can own any Apple device in the world. And a really scary thing is recently a company called Vupen, uh, that isn't, you know, they buy zero-day exploits. Um, not sure where they go after that, but what they do is, well, I can speculate, but, uh, they buy zero-day exploits, and they, they, they posted something recently where they said, we're, we're full up On iOS privilege escalations.

AI assessment note: “dynamically signature an attack quickly, And create an artifact, we'll say, that can be applied”

Answered produced feed D 4 · C 3 · P 4 · Cm 3 3.55

Q There's like an asymmetry to this, right? Like some, some person, some teenager, guy or girl sitting in their garage can literally have a massive disproportionate impact.

A I'm thinking of the, the attack on Twitter recently and how, how, you know, that was a social engineering attack. Yeah. Yeah. And, and, you know, in the context of going after mobiles, I mean, that, that's, that's, it all comes down to the accessibility of the attack factor and the, the creativity of the person running the, the attack factor. So I was thinking, you know, with, with NSO group, you know, there's, there's a lot of articles on them about who they sell to and don't sell to. Um, they have a whole group now or whole internal group within the company that I've read, uh, dedicated to making sure they make ethical decisions. I don't, Personally trust that they're making ethical decisions.

AI assessment note: “I'm thinking of the, the attack on Twitter recently and how, how, you know”

Answered produced feed D 4 · C 3 · P 4 · Cm 3 3.55

Q What's the difference between a good answer and a bad answer to that question?

A If somebody uses the word next generation, seamless, um, we'll stop everything. Yeah, AI, we've got machine learning. Any of that, if any of that comes up, big red flags. So if, if somebody can give you a good answer to what happens when your system fails, that gives you comfort, then I think that is a, that is a good You know, you know, you know, you know, the cybersecurity industry is like a, a bunch of unethical, uh, used car salesmen, uh, it's, it's because there's so much jargon and salesmanship that goes into this. For example, the, the process of buying a car, um, what do you expect when you go to a dealership to buy a car? What, what, what do you want to walk away? Assuming you really like a car or a brand, what do you expect to walk away after a transaction occurs?

AI assessment note: “If somebody uses the word next generation, seamless... big red flags.”

Partly produced feed D 2 · C 3 · P 2 · Cm 2 2.30

Q a lot of companies. Like a lot of companies break in this sort of like 40 to a hundred people range because you start reaching the ceiling of The processes that you put in place, but also the ceiling of the people who've got you here. How do you think about that? How do you scale and how do you go beyond that and crack through that sort of ceiling?

A Uh, I, I think the, the, the first component is, is making sure that everybody is going in, in the same direction. You, you have to be very straightforward, frank, honest when, you know, looking internally, but also what the company goals are. And Everybody needs to know what the company goals are. I, I don't think that, you know, execution is not necessarily something that comes naturally, uh, to a lot of people. And, and for me right now, like one of my, one of my biggest concerns as we approach 100, uh, as we go through COVID-nineteen, I mean, when this COVID-nineteen started, there was, you know, a decision to be made to go aggressive or, or, or cower, I guess, from the scenario. And, you know, in my opinion, it was very clear we go aggressive because You know, our competitors are probably going to be category B in damage control, so.

AI assessment note: “making sure that everybody is going in, in the same direction.”

page 1
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 200 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.