The Exchanges

Every argument clarity score on this site is built from rows on this page. Each question and answer was assessed with names hidden, the host's own answers included, on four things from 1 to 5: directness (does it answer the question asked), coherence (do the ideas follow), precision (concrete details and clear references), compression (says a lot per word). The weighted mix (30/30/25/15) is the exchange score. A person's published score averages their exchange scores on raw tape only, at least 8 of them, shrunk toward the cohort mean. Full method →

Ryan Noon no published score: only 6 usable exchanges on raw tape, and a fair score needs 8+ · coarse estimate ≈4.0/5 from 6 raw tape exchanges record → ← everyone

Every exchange below was scored with names hidden, four dimensions each from 1 to 5. An exchange's score is 0.30·directness + 0.30·coherence + 0.25·precision + 0.15·compression. The published score averages the raw tape exchange scores and shrinks small samples toward the cohort mean, so five great answers can't beat twenty good ones. Produced feed rows count only toward coarse estimates, never toward a full score.

clear all ✕
6exchanges match
6on raw tape
0redirected or not addressed
Answered raw tape D 5 · C 4 · P 4 · Cm 4 4.30

Q Yeah, that makes a lot of sense. You were one of the fastest adopters, I feel, in terms of hands-on use of LLMs for security applications. How did you start thinking about the use cases where generative AI would be useful?

A The, the second you give a coder a REPL, uh, you know, we will, we will start iterating basically, right? And chat GPT, if nothing was not the world's greatest REPL. So, I mean, we just started playing with it and then we're like, there's a lot of security domain knowledge, like baked into this thing. It turns out if you feed, you know, precisely one internet to precisely a million GPUs, it picks up a thing or two about cybersecurity. And so, you know, it's, it's the kind of thing that Obviously like the bad guys are, are, are starting to figure out in earnest. Uh, and you know, it's not like you can prevent this stuff from getting democratized, but we just, we just, you know, you could do simple things like you could feed it, you know, like a bunch of, you know, raw email headers. Anyone who's coded with these things, it's, it's like this weird wetware grafted into the middle of a computer. You know, it's like, it's, uh, it's, it's squishy and stochastic and parody, you know, but you have to integration test and model around it. I think the analogy I used at the time is like Shang Tsung from Mortal Kombat. Like it has, it has eaten the souls, you know, of, of thousands of security engineers. And so like, you might as well use it because honestly, like there's a lot of just raw operational work that happens in security of just like, we need to, you know, rarefy this signal, fil…

AI assessment note: “we just started playing with it and then we're like, there's a lot of security domain knowledge”

Answered raw tape D 5 · C 4 · P 4 · Cm 3 4.15

Q How does that differ from totalitarian states from a cybersecurity perspective?

A Like, you could literally, you know, if you're like North Korea, you're going to say, you're all going to use this Linux distribution, but it doesn't support, you know, whatever I want. I'm sorry. We're an authoritarian state. Like, oh, oh, well, what, you know, like, what if I get fished? Sorry. Like, that's not how bank accounts work in our country. You know, like, it's just like you can control information. You know, you can't, this usually gets like you through the lens of like social media disinformation. If you can, you know, regulate and lock down, you know, the entire social media discourse, then like, you know, What election is going to get hacked and where would it get hacked, you know? Uh, but the same thing I think holds true for all of, all of cybersecurity. The other interesting, you know, like way of looking at this, that's always kind of baffled me is that, you know, if, if cyberspace is a space, right? Like in, in like U S military terminology, it is a command just like, you know, North Africa is a command, like cyberspace is a command like William Gibson, you know, would be proud. Right. But like in this space, like, You are kind of on your own as an American. Like, you know, it's like, if I, if I was in, you know, like, like the military protects Americans and guards our borders, what does that even mean, you know, with like, cyberspace? Like, I hope you're h…

AI assessment note: “if you're like North Korea, you're going to say, you're all going to use this Linux”

Answered raw tape D 5 · C 4 · P 4 · Cm 3 4.15

Q But, uh, if you, if you want a, a, a grouchy yet somehow still optimistic guy, uh, on your cap table, just, you know, give me a call, but I, I'm looking to do less stuff in security. Is there any other advice that you tend to give, um, people starting companies for the first time?

A Oh man. Uh, Yeah. I, I mean, there's just the basics, like figure out your team, you know, like being a solo founder is actually totally okay. It's way better than being like, we had three coffees together and we just got married, you know? So like, like just start with the team. Like everything is built on the team. Like it's the saddest thing in the world when you see like a beautiful company and then like, it's just the foundation has a, has a crack in it and you have to tear the whole thing down, you know, make sure you have the same like risk appetites and stuff like that. It's just those basic, basic, basic stuff. Like. You know, especially when, you know, we are irrationally exuberant again in Silicon Valley. We had a solid six months of being depressed because the end of free money.

AI assessment note: “there's just the basics, like figure out your team”

Answered raw tape D 4 · C 4 · P 4 · Cm 3 3.85

Q Do you, do you see any CISOs actively using, um, LLM tools today? Or is it still kind of early and it's like there's an adoption curve and, or is it going to just be in the hands of the vendors?

A Well, I, I think the best thing about the security industry, uh, is that there's also the security cottage industry of, like, it's not the fancy security vendor who's, you know, buying the CISO steak and having them drive Ferraris around Vegas every August. It's, like, just a strong, like, security engineer who's just hacking something together, and so some of the best companies that I've seen, you know, are just that, uh, and, and so you're seeing all these, like, there are cool projects out there. Um, you know, I, You know, I, I don't want to name drop too many of my friends on this podcast, but like, you know, just like the, the stuff that Socket's doing, just like analyzing NPM dependencies, like, you know, even just like stack analysis, like looking for like, you know, Hey, you, you drop sensitive information in the middle of your code base. Like that's like such a messy, hard problem as any like computer science can, you know, person can tell you. And like, these things are pretty good at reading code, you know? So like all sorts of just basic stuff like that is, is starting to, to pull through. So.

AI assessment note: “all sorts of just basic stuff like that is, is starting to, to pull through”

Answered raw tape D 4 · C 4 · P 4 · Cm 3 3.85

Q things and bundling and cross-selling and sort of the traditional enterprise playbook, which parts of tech have sort of forgotten for a while and maybe are coming back to now that we don't have ZERP anymore. Um, how do you, uh, how do you think about the things that incumbents will do versus startups? Like, is there any room for startups right now on the, on the AI security side?

A I mean, there's, there's always room for startups. The cynical take here, or like the, the, the take I can give that is perhaps most informed and most cynical, uh, whether this is whatever uninformed, informed pessimism versus inform whatever is, uh, is that basically, you know, in the cybersecurity industry, there's some basic economics, right? There's, if you care about this, like there's a great paper that is actually required reading for everyone who's ever joined material, which I've never enforced. Uh, but it's called the market for silver bullets, right? Like Ian Grigg wrote it. I think I've sent it to you once and it's like fundamentally, you know, there's, there's like markets for lemons and whatever, but there's markets for silver bullets, which is that like fundamentally there's, there's the buyer, there's the seller and there's the attacker, you know? And so like the buyer cannot really be sure of the effectiveness of what they're buying and whatever, whatever. And so you can't really like look at a solution and be sure that it will Save you, right? Like, you know, you, you could buy an insurance policy, you know, and, and there's a, you know, like a truism that all cybersecurity products are just, you know, complex insurance policies or whatever, right? But the, the, the point is like that, that mushiness exists. And so what has resulted in, in, in the free market …

AI assessment note: “I mean, there's, there's always room for startups.”

Answered raw tape D 5 · C 3 · P 3 · Cm 3 3.60

Q Yeah. I guess, um, more generally, you know, it's been about seven years since you co-founded Material. What do you think are the biggest, uh, changes or evolutions in security since then?

A That's a good question. Um, Honestly, like, I don't know how much has changed. Like, it's like, you know, people still send emails, people still reply to text messages. I think, uh, You know, the, there's always like the, but Slack is going to have all those problems too, or whatever, whatever. And I think at the end of the day, like if something's a walled garden, uh, like it will be involved in attacks, you know, someone will go in and like own you because they compromised Slack after they compromised this and, and escalated that whatever, but like entirely new attack surfaces of like, you know, ways to get to users from across the internet, broadly speaking, uh, Like I think have, have a somewhat, somewhat stable. What's the sad thing? I spend a lot of time thinking about like mobile stuff and it's, it's sort of this like tragic thing where like locked these things down, like hardcore now, right? It's actually like super limited what like vendors can do. And, and the average employee, I think understands that their company probably owns their work email account or whatever, uh, and has, has carte blanche to protect that and protect the company. But, you know, like, do you have your phone? Is it my phone? I brought it. I signed it in. Do I have MDM on it? All this stuff. And so that ends up being the situation where, uh, you know, even Apple, who's like so good at locking it …

AI assessment note: “Honestly, like, I don't know how much has changed.”

page 1
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 100 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.