YouSaid · the spoken record
Matt Holland
- lines on the record
- 116
- first
- 2020-09-29
- most recent
- 2020-09-29
- sittings or episodes
- 1
- sources
- podcast
Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections
“You know, the experts of the world, regardless of what company you're working for right now, we're always looking for more people.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So I would say, you know, if you are a company looking for help, it can be a challenging thing. I think it's that going to the doctor scenario when you have a pain. You don't want to necessarily find out what it is because people are naturally averse to bad news. You can't be like that with cybersecurity if you don't have a cybersecurity vendor, if you don't have a company helping you out with that problem, get on it. Everybody is a target at this point. Your company is not small enough to be off an attacker's radar. I have seen five person companies, actually I've seen two person companies attacked and hit. So my advice is don't be afraid to ask for help. Hello at FieldEffect.com. Yeah, the second thing I would say is anybody out there looking for a really cool opportunity for really cool company.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so execution is a big part of that. And it takes a bit of time to understand what execution looks like in each particular problem or given company. So that discovery of, you know, how do we execute as a group has been something that I think is extremely important and largely the company. And that, I think, is one thing that always resonates in my head that everybody has great ideas, but how you push through is execution. You need to materialize those great ideas into things that are reality”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I think the first component is making sure that everybody is going in the same direction. You have to be very straightforward, frank, honest when looking internally, but also what the company goals are. And everybody needs to know what the company goals are. I don't think that execution is necessarily something that comes naturally to a lot of people. And for me right now, one of my biggest concerns as we approach 100, as we go through COVID-19, I mean, when this COVID-19 started, there was a decision to be made to go aggressive or... Or cower, I guess, from the scenario. And in my opinion, it was just very clear we go aggressive because our competitors are probably going to be category B and. Damage control.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I mean, Google's Project Zero is largely built from people who have exited the intelligence industry with a chip on their shoulder. I don't know if that's worked out so well.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah. So, yeah. So, from a risk standpoint, that makes sense. So I never argue with that. But from a practical standpoint, nobody's ever gone back. And it's become something that I've seen weaponized against the employee. You know, oh, you're going to this company. Not going to give you your one year leave of absence. And it's like okay, that is extremely bad decision, and you're showing some really unfortunate true colors. Is that ever made?”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I've been doing this for 15 years almost as an entrepreneur in two companies, and I've gotten to witness people go through that unleashing process. And it is really cool to see how one month after they're just blown away with what they are now afforded to do and what I'm not saying don't do this. It is just here's the goal, here's the problem solve it. Let me know what you need. We'll catch up every once in a while. In Canada, people typically join the company with one year leave of absence or a five-year sabbatical component. And I always laugh about that because, yeah, I mean.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“You're not wrong. I definitely don't disagree. I think from one benefit to linchpin from that was definitely it pushed people out the door. Absolutely. And I think that's a trend that continues to this day. I mean, I'm still full disclosure, actively recruiting from intelligence agencies. The people that are excited to leave and do something more. For the lack of better terms, be unleashed to solve technical problems. Like there's that hunger there.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, you know, I was just thinking that I don't know whether it was post Snowden. I mean, maybe his decision to do that would have actually improved the protections for whistleblowers. And that's probably important to acknowledge, but it's.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, I mean. Yeah, I'd be really curious to actually know what his living conditions are like right now. And hopefully they're not comfortable. But I mean, he brought it upon himself. There's other ways he could have done that and come forward with.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, yeah, to the best of my knowledge, Wikileaks doesn't receive redacted versions of things. I mean, that's largely my opinion on him.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, and how far back did he set programs? How much did entire agencies need to go into damage control because some Yahoo decided that this thing over here was illegal? And then, oh, PS, here's a whole bunch of other interesting stuff unredacted.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So the other side of it is trusting his intentions. So he had gripes about those types of illegal mass monitoring or mass surveillance programs in the US. Why did he go public with such a large archive that had nothing to do with that? Why did he expose completely legitimate legal intelligence gathering programs that have a ton of people's names associated with that? Why did he go out the door with that? And that, I think, is what I have a much larger problem with in that there was no thought process. It sounded to me, it seemed like more, he was just giving the intelligence community the middle finger.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“The bureaucracy Crazy. So that whole side of things I find unfortunate because the byproduct of that is distrust for agencies that are working extremely hard to keep countries safe. And it is extremely disheartening for those people to, you know, get dragged through the mud publicly when the public doesn't actually have an awareness as to how much they sacrifice on a day-to-day basis. I couldn't count the number of long nights that I've seen people work. It can break families. It can break relationships.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Say this is okay, this is bad. I remember being at CSE and arguing for something for I don't know how many years, but there was a problem legally and it didn't get through. And that vetting process, people take extremely serious. And if something goes through that process, there is a measure of legality to it. There are a group of lawyers who honestly like to say no to ideas that have said, yep, this is okay. So the idea that anything that has been deemed legal, you know, I'm not in a position to say that's right or wrong, but what I can say is the process that those things would have gone through.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“The unfortunate assumption is that agencies, security agencies, intelligencies are these devious groups that are like, let's do whatever we can. And I don't think the average person actually realizes how difficult that job is, how normal the people are who do that job. They have families. They come in. They want to solve a mission or solve a problem, make things better. The way he went out with this giant trove of information, which I'm going to come back to, completely ignores the way that technical implementations get approved. It's not like developers are sitting at their desk and say, I have this great idea. Let's go do it. And all of a sudden it's running an operations without any accountability or review. There's a team of lawyers depending on the size of the country that will look at that.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“No, you're great, bud. I do not agree with what Snowden did in any way. And that is putting it very, very kindly. Regardless of at this point, there's been things that he brought to light that has been declared illegal.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so I mean, ultimately I don't have any problem with Huawei being banned in the US. I would not argue about that. By the way, the name of the vendor is Erodium. Bupin started Zerodium.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Oh, my personal take, again, I'm completely fine with the band. I mean, they're still allowed to sell into Canada. I'm not aware of what the”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, you're slowing down fixes. And, oh, I'm sorry, your routers just got hacked. That's on you. That's not on the vendor at that point. So I don't think that concept is one that actually works.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Disagree with that. If I was the vendor and my releases were being slowed down by a month, I would get pretty cheesed because”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yep, this looks great. Or better yet, they have a set of automated tools to be able to derive that answer, which is challenging, probably possible, extremely challenging. The realistic outcome is the time for Huawei releases a new iteration. The time from that release, because if they are a vendor that actually believes in securing their product and that new release of the firmware has fixes, time matters, you're against the clock before vulnerabilities could be discovered and put out because all it takes is for them to release that firmware once have somebody ripped that firmware apart and identify differences between the old and new. So you're immediately up against the clock. And if this ideal analysis process is being slowed down in any way, you're immediately compromising the vendor and giving them the argument that this system doesn't work because what they, and I don't necessarily.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“It doesn't scale to the realistic pace of software development. Right. So let's imagine that a government does have a program in place where every iteration of source code, and these aren't small systems. We're talking millions of lines of source code. Let's assume you have a crack team of amazing source reviewers that can say with confidence,”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so I don't think there is a framework to build trust. I don't think they have. That trust and given if a nation is going to rekit their entire country with a new type of wireless gear, especially with the complexities of 5G, you need to trust that vendor. You need to be sure that the interests of that vendor are at the very least not opposed to the interests of the country that you're in. I don't know how anybody could possibly say that about Huawei.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“And where we are today, Huawei basically price undercuts, other vendors. And, you know, I ask, how do they get to that point? That sounds like they have a lower R&D budget. And how do you have a lower R&D budget? You get intellectual property via creative means. Today with them being banned from the US, I don't disagree with that. I have different thoughts about the whole TikTok situation.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so there's documented ties to the Chinese federal government with that company existing. There is, I don't know if they were ever convicted. It was back in 2003, 2004, but there was a very clear-cut case that Waui was using conveniently leaked intellectual property. This is back to, you know, if I was going to steal your intellectual property, it is much more deniable if I leak it into the internet and then use it and come out six months later and say, oh, look, I just found this out there and I used it. Really convenient”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Vulnerabilities you have and you know about as a nation, it's not going to stop them. It's just not going to. They're going back to the Vupin example of there are more out there.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, from what I, so full disclosure, I don't have as much exposure to what the internal debate is on that. I'm aware that it happens. I think a lot of it comes down to what the perceived value is gained versus lost. If you don't disclose something and you use it operationally, is there more good for the mission, the country, its people by not disclosing adverses, disclosing it, and losing a capability? Yeah, it's a tough one because the adversaries of allied governments aren't going to disclose. They're not going to care if they have something they can weaponize. They will use it. And I think, unfortunately, that is probably the tone that is set globally that underpins a lot of the decision making. Like if you're being attacked constantly and having your intellectual, your nation's intellectual property stolen, I mean, you could disclose all the vulnerable.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, that was always an intriguing calculation back at CSE. A good debate to have, I guess, if you've got something that took a lot of time to build, do you throw it down a hill and hope for the best, or do you protect it? Do you put shoulder pads and knee pads on it and try to make it last as long as possible?”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, I find it really intriguing. It makes me wonder a little bit do they have an army of thousands of people in warehouses cranking the stuff out, which they probably do, which is really scary.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“And I'm speaking from back when I was at CSE, it means that when I said earlier that on that first pillar of cybersecurity, if you want to call it a pillar, there's an economy behind it. So there's a cost to building capabilities to go after a particular target. If you lose that capability, that immediately is an expectation of, okay, find a new one. And it's difficult. There's cost to that. There's labor, and that is a very big component that goes into the, I guess, the risk equation as to how you're going to approach an operation, how aggressive you're going to be in different agencies around the world will do different things. I mean, you look at China and Russia, they're remarkably aggressive with a lot of, I don't want to say disregard to their own intellectual property.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Oh, that's an intimate question. Getting caught. I mean, ultimately, yeah. I mean, so as an attacker, it is a continuous balance between risk and losing a capability.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“The number of times I have had to worry about this, you know, these features that are sold to businesses around the world, being on the other side of the coin just years ago, never. I've never had to worry about machine learning. By the way, existing machine learning implementations and a lot of solutions out there is the exact same thing that I've seen in antiviruses back in 2005. They just didn't call it machine learning. It was just training analytics to look for anomalies.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Well, ultimately, it doesn't mean anything. A good solution should be iterative. A good solution should be engineered to handle the future without needing to put a sales tag around. This is what we have now. We call it the next generation thing that the world's never seen. PS, it's got machine learning, AI, blah, blah, blah, blah, blah, which ultimately doesn't mean anything if you're a buyer. All it does is confuse you. Drives me nuts.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, and ultimately the only working cyber solution, and I don't care what the sales point is, the only true working cybersecurity solution is one that looks at it from where's your data, how are you going to be attacked across the board. So it needs to include an endpoint component, a network monitoring component, a cloud component, potentially an IoT component, an XYZ for things that we don't even need know it exists yet. This is where this whole concept of next generation drives me nuts because people say we have this next generation thing and what I'm seeing right now is the exact same thing I've been seeing 20 years ago, regardless of whether it has a machine learning component or not.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Unfortunately, with the current cybersecurity industry, there are sales persons all over the place that will say, you know what you need is you need some wheels. And then another salesperson will say, I can sell you the engine and another salesperson will say, I'll sell you the steering wheel. You probably only need the steering wheel, but I can sell you that.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“God, if somebody uses the word next generation seamless. We'll stop everything. Yeah, AI, we've got machine learning. Any of that, if any of that comes up, big red flags. So if somebody can give you a good answer to what happens when your system fails that gives you comfort, then I think that is a good position to move beyond. When I said earlier that, you know, the cybersecurity industry is like a bunch of unethical used car salesmen. It's because there's so much jargon in salesmanship that goes into this. For example, the process of buying a car, what do you expect when you go to a dealership to buy a car? What do you want to walk away assuming you really like a car or a brand? What do you expect to walk away after a transaction occurs?”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Know right off the bat, I would say, how are you protecting my company? Tell me how you're protecting my company. Like, full stop. What happens when something goes wrong? And you'll probably get a whole bunch of sales jargon.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, it's the safe way to go, but it is not the best thing for the company. It is not forward-facing. I think it's being naive in regards to the type of attack side are coming.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, if I was a virtual CISO, I would probably reference the Gardner Quantant to make sure that the executive board is covered in regards to liability.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Compromises and customer data now. There are fines. I remember before COVID-19 dropped, there was discussions about six-figure fines going to Canadian companies if they are ransomwared, customer data gets compromised, and it has shown that they weren't taking the problem seriously ahead of time. So they didn't have the adequate security protections in place.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, yeah, I'm aware of businesses that have been shut down because of ransomware, the payment is just too high and it's much easier just to say, okay, throwing in the towel, we're going to fold up shop and maybe start again. This is ultimately why I don't like, I get very frustrated that companies will pay ransom or not take the time to hire a company ahead of time. Like it's much, much easier and cheaper to be preventative and to harden your system and be ready for attacks. I mean, that is the reality of today. And anybody who thinks otherwise is, you know, they've got their head in their sand, you're going to get ransomware. Bad things will happen. And hopefully it doesn't kill your company or compromise customer data. That's a whole other aspect of this equation that I don't think people take into consideration if there are legal obligations to report.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I don't know about that. It's not my background, but I would say the challenge would not necessarily be the difficulty. It would be the average person or business getting any agency to care to track it down because that Intel agencies, law enforcement agencies aren't sitting around waiting for things to do. There's really big problems that are going after and trying to fix and solve. A small company, a law firm getting ransomwared is just low on their.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I would say it definitely be harder because that is definitely a very convenient payment structure to pay with Bitcoin. I'm just thinking in the case is where we've seen financial redirections and those are anonymous accounts that are used and then torn down. So there's definitely.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That's not a big thing that you're worried about. It is a very, very basic profile to stop, identify. I might be jaded because I've been doing this for 20 years in the grand scheme of things that I've been a part of. Ransomware is definitely low on the sophistication bar.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, you have to be on host and you have to have a measure of sophistication and tradecraft to identify and block it. We've seen, we have some coexistence scenarios where I won't identify the companies, but they are very, very large, successful companies, cybersecurity companies. And the ransomware gets by them, but we stop it. And it blows my mind that based on the”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I wish I had an answer to that. I don't think a network monitoring solution will not stop ransomware. There's nothing you can do about that”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“If you say, I'm not going to pay you, they will 100% follow through on what they're going to do. And this weird, I guess, sub-industry has emerged from ransomware actually being a thing and being accepted where companies will actually act as negotiators. So if you think back to those really cool movies where there's a really cool ransom, or sorry, a hostage negotiator trying to talk somebody out of the scenario that exists for ransomware. And it drives me off very well. Yeah, yeah.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Depends on the flavor, but the overall goal is to extort money out of the victim. So there's different ways to do that. If you attack an individual, you would potentially encrypt their personal photos, credit card information, maybe other personal compromising information, and then say give me X amount of money or I'm going to expose all your photos or I'm going to delete it all. When it comes to businesses, it's more of going after intellectual property where if a particular workstation gets compromised, ransomware runs on that workstation, encrypts everything, potentially deletes everything at the time, typically making a copy of it because there's value in that, and then we'll go through all the network shares and do the same thing. So there's one particular, there's different groups, I guess, of ransomware actors out there, some that won't call the bluff and others where”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“No, there was one that was rooted in Voltspen was that group, was that leak, I guess. The one I'm referring to was from NSA. And it was a whole treasure trove of tools. And this one was particularly interesting because it really, there are events that occur that destabilize, I guess, the defensive posture. Ransomware in general, I don't get how it even exists. It is the easiest malware to detect and stop how there's even an industry around that blows my mind. But the attack vector that people use to wrap ransomware, the payload, weaponize that chain that I talked about earlier, basically allowed a point and exploit capability on patched Windows machines.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT