YouSaid · the spoken record

Matt Blaze

lines on the record
21
first
2017-06-16
most recent
2017-06-16
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. When I got asked questions, I couldn't answer by the president. That would be a pretty scary moment. But I think I really was there for a lot of the turmoil around sort of things that happened in the moment. So crisis in the moment, Benghazi, the Boston Marathon bombing. And I wasn't afraid, but those were what I think makes maybe pivot a bit and say what makes me afraid today is another attack on our country, a terrorism attack or a major cyber attack, and whether we're prepared to have the right response and have a calibrated response. And then going back to your initial comments, Martin, particularly in the terrorism realm, I'm a little concerned about that.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  2. Maybe a renewed and proper sort of trajectory for the trust between Silicon Valley and technology companies and the government. Something that I've been very concerned about in the post-Snowden era, as Matt mentioned, I was the general counsel at NSA back in 2010 and 2011. So I sort of worked on the programs and I saw what happened when they were revealed and I saw what happened in terms of that working relationship, which is ultimately sort of fundamental to innovation and ingenuity and really the ability for government and our technology community to work together to solve these problems. I'm much more hopeful today than I was three years ago. And so I think that's on the right path.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  3. I think cybersecurity is a really young discipline, and we forget that, right? These other physical security disciplines, we've been building them for decades and centuries and millennia, and we've learned a lot. And we know comparatively very, very little about cybersecurity, and so we feel at a loss. But I think there is a lot we can learn and build from. And we're very, very early in the stages of figuring out how to protect this. And if you look historically at technologies that have upended conflict and made it much easier to be an attacker than a defender, There are any number of these throughout history from armor in World War II to gunpowder in sort of the 16th century in Europe. And in each one, you have a radical period of instability, and then you have a group of defenders that get together and figure out how to fix the balance and move things back. And each time when they do that, it's because they think about understanding and controlling the environment, and they deploy these same tactics. And so I'm incredibly confident we'll get there.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  4. I think this is a trend that I'm tracking. I mean, like right now, I think it's going to be a long time before we get rid of any single factor, but I do think that we're seeing multi-factor authentication. That means I try multiple things. Like I will do the password and I will determine where you're coming from. And so I actually think that the trend is going to be more usability because we have these physical access.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  5. To a place where you can, for example, know pretty well that it's you, that it's logging into your bank account, even though you don't have to kind of regurgitate those 30 numbers or whatever that was.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  6. Away these days. And so we see a huge growth in companies that are trying to exploit this, so you don't have to do things like passwords. I'll give you an example. There are companies that can detect very, very accurately who you are by how you walk just using the accelerometer in your pocket. There are companies that will take, if you have your phone out, what they'll do is they will use the speaker to send out a hypersonic sound that you can't hear. Then, sorry, they use the speaker to do that and they use the microphone to collect it and they can actually map out a physical room. So they can, like within the microphone, map out using basically sonar, just using an iPhone, a physical room and determine if you're in your office or not. There are companies that will determine how fast you type and all of these things will uniquely identify you in the physical world and make that available to you in the cyber world. So I do think that we're getting very good now that we have a proliferation of physical devices with a lot of sensors.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  7. Yeah, so if you guys can't tell, I'm super obsessed with the interface between the cyber world and the physical world and the way that I described it in my talk. I'm like, we've got all these really sophisticated cyber contexts concepts that were actually applying to physical security. But it actually turns out that the reverse is true, which you can take physical concepts and physical roots of trust and bring them into the cyber world. And in the past, that's been very difficult because anytime that you take electrons and you tie them with atoms, it's actually very difficult because of the distribution problem of the atoms. But the iPhone has solved that. So if you think about it, everybody has a smartphone these days or to some first order approximation, everybody has a smartphone. And that smartphone connects that person to the physical world. It's got all of these sensors. It got accelerometers. It's got speakers. It's got cameras. And so you can take that physical set of atoms, all of those sensors, and you can tie that to the cyber world in pretty meaningful.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  8. That's where really the rubber hits the road for me for cybersecurity and where we need as a government to work with the private sector to figure out how to protect the nation from that level of attacks. But increasingly, I think, as Martinez rightly said, those level of capabilities are falling into the hands of criminal organizations and much less sophisticated groups. So that's the concern, I think, as you look ahead.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  9. Yeah, I have lots of people living in my basement. I agree with the analogies are really hard and I think thankfully we've moved beyond the 9-11 Pearl Harbor analogy, which was inapp, I think. Coming at it from a sort of Washington DC and national security perspective, I think much of what we talk about as cyber attacks and cyber threats are really not the kinds of attacks or threats that rise to the level of our national attention. For me, they're annoying, they're somewhat disruptive. For me, the sort of cyber security hit home several years ago. I was at NSA as the general counsel there and starting to think about cyber. And I think now about what we see going on from Russia, for example. That deserves a national response. You know, they have seen cyber as a vector to carry out their very aggressive foreign policy.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  10. You care. Do you care because they're a lot closer to your bedroom than they were got into your basement? We think about it as a binary event. They get in and we lose. And that's not really the way it works. And if you think about these models, the way the secret service works, the way law enforcement works, the way a lot of physical security works, they have these strategic approaches that focus on understanding the environment and controlling the environment. And that understanding and control is what gives defenders their advantage.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  11. Unless they get to the president and cause harm and cause damage. Someone breaking into your environment, if you stop them before they cause damage, isn't that much of a problem? A similar example is if an intruder, if a criminal breaks into your basement and never gets out of your basement and spends six months inside your basement, how much do you care?

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  12. Which makes some sense in this room. Sometimes people get very confused when I'm saying it in a different city. But what's interesting about it is it's really easy to break into the White House or at least jump the fence at the White House. People do it all the time. The Secret Service has learned this very fundamental lesson that threads through actually most of physical security, which is a very high impermeable perimeter doesn't work. And in fact, at the perimeter, the defender has the greatest disadvantage. The intruder can keep trying to get over. Once the intruder gets over the fence and into your environment, they're in an environment that in theory you as the defender control, which is where you have the greatest advantage. So if you think about what the Secret Service does, right, you can jump the fence and people do it all the time. There's been a bunch of coverage of that. And usually what happens is 30 seconds later or 15 minutes later, you get tackled on the lawn. And that's actually okay. It gets back to this notion of what is failure and what is success. Someone jumping the fence doesn't matter.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  13. So there are a lot of different analogies that people use, and the problem is that a lot of them break down very quickly because we like nuclear deterrence is an analogy that everyone jumps to, which is interesting because getting back to this earlier conversation, nuclear deterrence is built around the model of A sovereignty ending massive event as opposed to constant low grade threat. It really doesn't map very well. An analogy that I actually really like to use is thinking about the way the Secret Service protects the president.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  14. I went to a similar type of panel, but it was kind of more an industry focused panel. The conversation would go like this. You'd say, oh, okay, well, listen. I guess the nuclear power grid can go down, and everybody's like, yeah, that's right. Okay, here's some incremental changes we can do to the supply chain or the technology. Okay, yeah. So nuclear power plants, you can do this thing to them and like, oh yeah, okay, we can beef up physical security, whatever. Cybersecurity, well, you can probably take down the internet due to a BGP attack. And then all of a sudden we're like, oh my God, cybersecurity is totally broken. We don't know what we're doing. And so we kind of evaluated it very, very differently than other pieces of infrastructure. And so I think, I mean, I know you were looking for what did the government gets wrong.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  15. Yeah, actually, I think Washington is kind of what gets it right, actually. Believe it or not, maybe not the response you're getting. And the reason is because they take a holistic view to cybersecurity. And I think that's what we should all do. So let me just explain. So I used to sit on these councils, which were like, this is back in 2000 or 2003, and they were sovereignty-ending event councils, right? And so you'd have, I was like, the cyber guy, and then we'd have the civil engineer, and then we'd have maybe the new guy and whatever, and we'd all do these think tanky type things about how can you protect the critical infrastructure, what are the possible things that could actually create sovereignty ending, which I think at the time the definition was seven days without basic services and so forth. And in those types of think tanks, like cyber was just another piece of infrastructure, and you take these very holistic views. And I thought that the government did a very good job of that because it's got such kind of a deep understanding of these. And so every time...

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  16. There is a very serious threat from cyber intrusions, but it's not often the threat we talk about. We tend to imagine that getting inside is the big problem and that once they get inside there's this risk of this big, massive institution ending event. And that is certainly possible. But much more frequent is the steady, low grade degradation of trust in the systems that we use. And once intruders get in, they need to sort of move laterally through these environments to find the target that will let them cause damage. And there's still this large focus, and there always has been at sort of the perimeter and the edge and keeping people out and stopping those institution-ending threats. But if we focus more on the low-grade constant degradation and the constant exposure, that's where the real challenge lies. And that's where innovation is really required.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  17. And in case you're wondering, the statistics is totally wrong. There's no basis for it whatsoever. But it's exactly the kind of statistic you'd expect to hear about cybersecurity because it's about sort of this big, massive destruction no companies could survive, huge consequences. And I was talking to a colleague of mine and he was pointing out that if that were true, virtually every business that went out of business would happen because of a cyber attack

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  18. There's some things that are different, right? He actually tracks this guy by having rooms of printers set up between about 9 p.m. and 8 a.m. because this is when the intruder was breaking in, tracking and printing out records of what part of the environment he's in and where he's moving. So some things are different, but actually a lot of it's pretty similar. And many of the techniques he uses look a lot like the techniques we still use today. So I would actually sort of say there aren't as many changes as we think they think there are. And one of the big problems and part of, I think, what you identifying, Martin, is there's a big difference between sort of what cybersecurity threats actually are and how we talk about them. There's a statistic that's been going around, it was used in a couple of cybersecurity bills recently. It was used on the hill. And the statistic is 60% of small businesses that get targeted with a cyber attack go out of business within six months.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  19. You know, it's funny, there's a book called The Cuckoo's Egg, which details this very sophisticated attempt to break into Berkeley's security systems and the efforts of this security researcher to track and catch and stop the guy who's breaking in. And it's interesting because he walks through how he does it, and it's a very detailed description of a threat and counter response. The funny thing is it took place in the early 1980s.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  20. Threat, or at least a little bit of lack of care in talking about the threat. I do think, and where I may just sort of take a different, maybe glass half empty versus glass half full perspective, you know, as much as we celebrate all of the ways in which the advances in computing and in big data and analytics give us greater ability to counteract the threat, those same capabilities are also going into the hands of our adversaries. And so the same things that help protect us are also the same things that are causing us to feel vulnerable and to feel exposed. And where just like in terrorism where there are asymmetric threats from individual terrorists and ISIS can outsource and crowdsource terrorism to anyone who can communicate with ISIS over an encrypted channel, we see individual small groups of people, as you said, gaining the capabilities of what were nation state capabilities in terms of the ability to carry out attacks from just a few years ago.

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source

  21. We need to be really rigorous and precise when we talk about the threats we face. You were there, Matt, with us in the Situation Room. We were briefing the president. I was the person who started off the briefings with the president to talk about the threats we faced from terrorism. And there's always this impulse to inflate the threat because you don't want to be wrong, right? And so there's this sense like you should kind of go to the scariest, darkest corner of the room. But I think it's critical that individuals in that position and companies in that position actually don't fall prey to that impulse. And to really understand, okay, what is the nature of the threat? How do we put it into perspective so that policymakers, companies can make sound resource decisions, sound business decisions, sound policy decisions about how we're going to counteract the threat? So I think that's a fundamental point, and I do think we face a bit of inflation about the nature of

    2017-06-16 · a16z Podcast · a16z Podcast: Changing the Conversation about Cybersecurity · IDENTIFIED FROM THE TRANSCRIPT · source