YouSaid · the spoken record
Matt Holland
- lines on the record
- 116
- first
- 2020-09-29
- most recent
- 2020-09-29
- sittings or episodes
- 1
- sources
- podcast
Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections
“Internal rage meter just went up. You know, it's a much more deniable scenario where, you know, things hit the internet and people say, okay, I just, it was out there now. So it's public domain knowledge. So having separation from the attacker and the beneficiary of the results of the attack makes a lot of sense if one's goal was to get a hold of somebody's intellectual property. I mean, once it's out there, everybody's going to consume it. You know, you look at the leaks of the whole eternal blue leaks. It's a series of tools from an essay that got leaked Windows vulnerabilities. It went to WikiLeaks.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“The last decade. Recently, we've seen a lot of intellectual property leaks. I kind of feel that, you know, if you were going to steal intellectual property and then create a competing product with traces, which wow I got busted for that.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I haven't looked at the statistics of what the market coverage is of Android versions. Pretty confident that if you rock in a version of Android, that's a year old. You're probably a pretty big target. And again, I don't mean to pick on Android, but that is just a reality of how that ecosystem has evolved.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I mean, that's an indication that ethics weren't a component in the founding of the company. That's probably a whole other discussion. But yeah, I think the point that the attacker and what that looks like is much more plausible that it is not an intelligence agency. You look at the groups that are running out of other countries. I'll pick on India a little bit just because I've seen some IP reports on some problems coming out of there, but firms of social engineering efforts, you know, it doesn't take a lot to go after Android that's two years old. And how many.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I'm thinking of the attack on Twitter recently and how that was a social engineering attack. Yeah, and, you know, in the context of going after mobiles, I mean, it all comes down to the accessibility of the attack factor and the creativity of the person running the attack vector. So I was thinking with NSO group, there's a lot of articles on them about who they sell to and don't sell to. They have a whole group now, a whole internal group within the company that I've read dedicated to making sure they make ethical decisions. I don't personally trust that they're making ethical decisions.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Like you're just, yeah, no decision on your part. You're sleeping in the middle of the night. In this case, NSO group sends you a malicious bit of content via WhatsApp, assuming they've been able to figure out your WhatsApp ID and then exploit your phone and congratulations. That whole step of getting around sandboxes, privilege escalation, it's all the same concepts. But in this case, it is a direct way to attack a device that you own.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, the unfortunate answer is the exact same way you'd go after every other type of computer. iOS is just an operating system. Android is just an operating system. There's no special features that make it impervious to attack. There are different security mechanisms in place that an attacker needs to get around, but it's the same deal. So if I'm going after your Windows laptop in the scenario that I described where I send you an email on mobiles, it's the same thing and it's actually worse in some cases about a year ago company out of Israel called NSO Group. They got busted for having a WhatsApp zero click mechanism. So there's some quick lingo dive here. One click versus zero click, one click is you have to social engineer somebody to the point where they can click on a link and exploit the phone. Zero click is where there's nothing you can do. You are just owned and you have no idea.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That's an interesting question. I think the odds of getting exploited are higher on Android, although the nature of Android also creates a scenario where there's so many different flavors of Android. It makes it much more difficult to create a mass attack. Whereas an iOS, because it's the same version of the operating system across the board on every device, if you can find a problem in that, you get all those devices. On Android, you get the nuances. I put nuances in quotes of some of the decisions that individual vendors will make that makes it very difficult to take an attack on Samsung and apply it to, I don't know, Google phone or a ZTE phone. So it's, I would say generally, the security position on Android is worse. The odds of being hit in a mass attack are potentially lower. But if somebody is targeting you, I would say that the odds of you them being successful.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, and I can tell you that 100% certainty I've not looked at Android 11, but what I've experienced over the past two decades, there are problems in the Samsung version that have been missed because humans, again, are part of the equation. And on the list, it'll say, you know, CVE fix, CV fixed, but those fixes aren't there. Bad guys or attackers will know that and they will exploit that. And there is literally nothing you can do to defend against that if you are a target. And that is a pretty frightening proposition.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Concept is very noble. The reality of it is not so great because what we have today is there is the main Android branch that evolves, that Google releases, Android 11 just got recently released. And vendors will take that and they will adopt it as is or they will customize it or they will take particular parts of what's called a change history. It's basically the changes that have been made to the code base. When that is taken in context with vulnerabilities, the fixes may or may not make it in. So you could have the latest Samsung phone running Android 11 that doesn't actually have all of the security fixes that the main Android branch has.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, you can download the source code and you can see what's running. And that is a component of a secure operating system, I guess, that the average person can go out and audit what's there. The average person could, if they want, take that, download it, compil it, put it on their phone, and maybe add some additional bells and whistles.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, and if that isn't a wake-up call to Apple, I don't really know what would be. That's basically the industry saying, yeah, your operating system is not as secure as you think it is.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That is largely crippling from a security standpoint because all you need to do is get around these set of mitigations and you now can own any Apple device in the world. And a really scary thing is recently a company called Vupin that they buy zero day exploits. Not sure why they go after that, but what they do is, well, I can speculate, but they buy zero day exploits. They posted something recently where they said we're full up on iOS privilege escalations.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, I guess largely that depends on how well the cybersecurity solution is implemented. If it is part of a network where you can dynamically signature an attack quickly and create an artifact, we'll say, that can be applied across the network of other customers. That is a way to combat against that. I mean, the zero-day problem is something that's always going to be there. I think this is something a lot of vendors don't actually realize that no matter how much you lock down your operating system, there's always going to be a creative group out there that does things better, that can get around it. I mean, if you look at Apple iPhone for the past, I don't know, say decade, they've been adding an increasing number of security mechanisms into the operating system that largely limit an app writer to only being able to do specific things.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“No, no. So we're kind of diving into why this is actually a really hard problem and why any specific pillar doesn't work. So if you only buy a network monitoring solution, you won't see really anything that I've described thus far. You buy an endpoint only solution, there may be hints of things that have happened depending on the sophistication of the endpoint solution. But as soon as it gets particularly deep in the kernel, you're not going to see that. It's a very challenging position. That's why having a holistic approach is so important. You need network, you need endpoint. So if you get by either one of those things, the other will pick it up.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, once you have that, there really is no barriers to doing anything on that host. So if you want to open up comms back to mothership, you can do that. If you want to access a whole bunch of data, you can do that.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Jeez, I didn't even hear that. So, yeah, gains execution inside the browser. And then the goal is then to gain privilege in the operating system. So that could constitute a sandbox escape to get out of that browser sandbox, a privilege escalation to ideally execute at a higher privilege level to basically nullify any security on the host and ideally get execution in the operating systems kernel. And once you're there, it's largely game over.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so the first thing that happens is the browser would be exploited. So whatever browser renders that link, web browser exploit would basically gain code execution. And modern browsers are definitely getting better, protecting against that type of thing. So, you know, Chrome is, every browser has a sandbox now. Most browser flavors are some measure of Chrome, so even Microsoft Edge is now based on Chromium.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Okay. So if you're going after a Windows box, it's either a server or workstation. And typically servers, if they're internet facing, gives you the ability to hit it direct. So if you have a zero day and a web server, for example, that is something you can directly access and exploit. That is a very direct way, I guess, of attacking the other approach is you have a Windows client. You're sitting at your desk. You have a laptop and you're just typing away and you get an email that is probably the most common way. And what that looks like is, again, back to the scenario where you're trying to convince somebody to trust an email. So they click on a link.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So you're interested in more of the pointy end of the stick? Yeah. So the way exploitation works is what specific platform you'd like to walk through.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“What's your routine? And then they will perform perhaps a financial redirection. So in that case, they would get an idea of what your entire portfolio is, an email, all of your customers and say, hey, here's your new payment instructions. And they will have all the outstanding invoices already listed and ready to go. So they can immediately say you owe us X amount. This is where I want you to send this money now. That is remarkably and surprisingly effective.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So initially, an attacker is going to profile the target, and that can look like different things. So if the target has online services, they'll probe those services to see what's there. Are there any email addresses on your website that are really easy to identify? What type of social media presence is there? And that ultimately will lead into typically a social engineering campaign, either in the form of an email that is received that looks really normal, that you want to trust, and hopefully will get you to click on something or double click on attachment, or it'll go to your phone and click on that, and that exploitation occurs. The other approach that we see quite a bit is people don't use multi-factor authentication with just a basic email setup. So brute forcing passwords works. Somebody gets in, we'll scope out your inbox and see what's there, who are your customers.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah. Yeah. And when something comes up, here's a very concise way of dealing with it not a series of links, google this, learn how to implement a VPN, learn how to use a firewall, learn how to patch your system. It's a guided approach to this is specifically what you need to do.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That I think for an effective solution. That's what you're dealing with. You're dealing with a company or a customer that doesn't care about cybersecurity, but you need to help them. The baseline of the interface could be an office manager, not somebody who has a computer science degree or somebody who has any background or interest in cybersecurity. So having a system that is set up and built and implemented to work with people who don't necessarily care or will care or should even care because that's not their job, that's what we do.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, you didn't see the logs, so why didn't you action that? And that, I mean, I think the assumption that the average business is going to care about cybersecurity is a false starting point because businesses, you know, you buy your computer hardware, you get your IT set up. If I'm a business out there, I'm not starting my day off thinking, oh, I can't wait to buy some cybers or understand some cybersecurity. that is the baseline”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That's a great question. I mean, I think trust takes time. You don't just magically get trust right out of the gate. And I think that is something we put a lot of time into building. We take time to create a customer relationship, ask customers what their needs are, what are their problems, and then tell us about your network. How can we help you? And early on in that process, I think it becomes clear that we're not just out trying to sell software in a commoditized way. The first thing we do is do an external view of the network and identify, okay, here's a problem right here. We want to help you fix problems. It's not just here is a solution that you have to run with. It is all about us helping you be better, fixing problems, and sustaining that moving forward. And that is largely a component that I don't think most vendors in the cybersecurity industry get. They are more interested in showing you.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So, I mean, that's ultimately the realm that field effect sits in, the small to medium business space. Know it is infeasible for every company to have an IT team. And in our experience, I mean, an IT team is good. They have expertise, but they may not necessarily be security experts.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so that is a useful classification system. It is just behind the curve continuously. The second thing is I don't think.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, yeah. So that is, I guess, a measuring system, a measuring stick to help vendors or customers or prospective customers, companies, I guess is a better term, to guide them in buying what they may or may not need. There are a few problems with that. The Gardner Quadrant system is often outdated. We were, for example, Field Effect was marketing a managed detect and response service well before it was defined in Gartner. And ironically at the time, we had a hard time gaining traction.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, so I mean, if we look 20 years ago, it's the same problem. One of the things I tell people when they join who, you know, when I hire from intelligence agencies is that be prepared to be disappointed because the problems that you are going to see will shock you that they're still out there. So the techniques that are 10 years old are the problems that should be 10 years old are still happening today. I think that's a large referendum on how not good the cybersecurity industry is at actually trying to solve the problem. And if I look at the vendors out there, I'm not going to name any specific competition, but what I see is a sales strategy that is like a warped used car salesman strategy. And that's probably an insult to use car salesman out there because it's much worse. It's all about the transaction. It's all about getting that done.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I mean, it highlights why companies need to take this problem seriously. And I don't think it necessarily extends just to large companies at this point, legal firms, accountants, huge targets, huge targets. I mean, you think about what they're dealing with in regards to confidential agreements, financials of individuals and companies. And that's one thing I think we've seen over the last couple of years is the attention that state-sponsored groups are going after. It's no longer the Sonies of the world. It is now your law firms because there's a lot of intelligence value there. Patent firms. I mean, there's a lot of intelligence value there. So the How seriously smaller companies need to take this threat, I think has really gone up.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, no, this third thing or pillar exists that is entirely wrong. And it's that bit that happens in the internet, social media, that type of thing, that isn't actually security related, but people like to kind of put a box around that. So an example would be election interference. So how do the organized influence influential campaigns on social media to get people to vote in particular directions? I do not think that cybersecurity, but that also gets lumped in. So that is the third bit, which is kind of like faux cybersecurity.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“It's a black box industry, right? A lot of businesses, a lot of people don't know what they're actually buying. And that has been exploited by the industry. And this is the part where I get angry because none of the solutions out there, there are a few that are decent. But look at what your options are. Do I buy an antivirus? Do I buy any spyware? Do I buy a firewall chain? Maybe an IDS, intrusion detection system, maybe endpoint detect and respond. Maybe user behavior analysis. Maybe a network monitor. And the way that vendors will try to push it forward is they say, you actually need all of that, which is total crap. You do not need all of those things. They do not work well together. So that whole thing angers me to no end. The third bit is a category that isn't actually cybersecurity. I read an interesting article recently and it kind of clued me in. I was like, act.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“With VR goggles, yeah. But if you've ever seen Mr. Robot, that is actually an accurate representation, if you ever are curious. But it is this glamorized thing that is entirely misrepresented, but it is an economy in itself. There's an economy behind ransomware and they get paid for it. They are successful. There's an economy behind intelligence agencies. That is ultimately what drives that. Dollars and cents. On the defensive side, The second bit, and by the way, the first bit only exists because humans are generally horrible at writing software. So that wouldn't exist if people were actually good at security models and implementing software. The second bit only exists because the first bit exists. So that's the defensive side. So let me, I guess the best way to describe it is as a consumer, it is probably the worst experience you could go through. So if you're going to go buy some cybersecurity,”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah. So I think there's three groups or pillars of cybersecurity. There's the one, there's the The ransomware, the intelligence agencies. I say offensive, but it's that traditional hacking, which has largely been glorified thanks to Hollywood. Mr. Robot gets it right, though. I don't know if you've remember.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So I think to answer that question, the first thing we need to do is look at what the cybersecurity industry actually is, because I think it gets muddled, the way the public looks at it, the way it's reported on.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yes. If you could sample what makes her run, who she is, and somehow create like a vaccine and inoculate the world, like you would have world peace hands down, and that obviously is a strong statement, but she is a phenomenal. Anybody who knows her would definitely agree with that.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“She's amazing. I don't think I could ever thank her enough. I think the formula for my success, she is a huge part of that. She is a funder.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Several factors. I think I really enjoy solving hard problems and the current state of the cybersecurity industry, to say it's a hard problem is an understatement. It is an unethical shit show, I would say. It really bothers me where it's at. So I think there's a large part of me that wants to fix that. There's also the aspect of I'm like ultimately a serial entrepreneur. I remember chatting with my wife when that transition was happening. She asked me, like, why are you doing this? And I was like, What else am I going to do? I'm just going to start something else. And it's either a cybersecurity company that I'm once again running that I believe can change the world and fix a lot of problems or I can open a coffee shop. Probably going to take the same amount of time. So, how about the cybersecurity firm?”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, and you go through this evolution of what's wrong with everybody? Why is nobody on board with this? And then the realization that, oh, shit, it's me. I'm the problem here. And then the appreciation of. Okay, understanding why that is, and I think that ultimately made the transition very easy, actually. And it's not something that I look back with at this point with any animosity or anything. It was just part of life.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Yeah, yeah, but it was a change in what I could do. I started to see a ceiling on what I could achieve. And it became clear to me that I was the square peg trying to fit into the round hole because of ambitions and more creative things that I thought we could do. And that was actually a pretty interesting experience coming to terms that I was the square peg in the round hole because it definitely took time to, you know,”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“They didn't know's done. I'll problem solve. Actually, the same reason I think, and this is actually where I think I realized why, you know, the root factor of why I left CSE is it was a similar scenario where”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So I think there was that, I think the ability to make decisions and be confident in those decisions, not get caught in paralysis of decision making. That is something that I think at first I struggled with, but over time the ability to filter out the noise and focus on the things that actually truly matter have really helped.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“That are more informed. It allows me to, I guess, understand and appreciate all the different parts of field effect, which is a much more diverse.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I think one of the biggest things was starting a company from scratch at that time. I had a computer science background. I clearly had a lot of experience in cybersecurity. I took some accounting courses and marketing courses in university. So I think there was a bit of a foundation as to, okay, if I remember doing a business plan because that was one thing you did, you made a business plan. But one thing through the Lynchmann experience that I got to have was I got to do every job. So I got to literally be the janitor. I got to be the marketing person. I got to be the primary salesperson. I remember doing really challenging sales pitches in front of audiences that didn't even want me in the room because I was, you know, stamping on their creative territory. I got to write code. I got to manage projects. I got to be the evangelist in the company. And going from there to field effect with that base, I think allows me to really make decisions.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“So globally, I'm going to lump in the partner company that we were sold with, but I think we're at the time close to 90 to 100. We sold in 2018, but I didn't leave until December of 2019.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“In the company and creating that environment where they knew that they were lucky that I appreciated them and that whatever we do we're doing together, I think it's an empowering message to build a team around.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Largely removing barriers. I mean, I think that was a big component of it, you know, giving them an environment that they could excel in, which breaks down into what tools do you need? Do you need to put in a purchase requisition to get what you need, or can I just get that for you? Like that was one of the comments from one person I remember early on when they joined, they're like, okay, these are the things I'm going to need to do my job. And I was like, okay. I'll be back in 30 minutes. And here's your stuff. And the reaction was Really? Like we can just do this? It's like, yeah. Go be a genius. Go produce amazing things. So I think that was a big component. I think making it clear that everything that we were doing was as a team. And I think as an aside, this is one thing I think people who are entrepreneurs sometimes get caught up in that it's about them. It's about their journey and the way I approach it is no, we're all in this together. I'm really lucky to have you.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“Reality So the idea of going private was taking the handcuffs off and creating an environment where we put really, really smart people together. Part of our recruiting strategy was immediately going after the best people in the community. And taking all barriers out of their way and letting them do amazing things.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT
“I don't know if there's any interest in me coming back. I think there was definitely skepticism as to whether I could succeed, which I'm fine with that. I mean, clearly at the time, my business partner and I were the first ones to kind of make that jump and do that together. And there was a lot of skepticism as to whether we should be allowed to do that, whether we are able to do that. I remember having a departure interview with a Hyatt manager who sat me down and said, you're going to go sell to China. You're going to enable China. And I looked at him in the eye and I said, what on earth would make you think I would ever do that? That is the most ridiculous thing ever. So I think there was a bit of fear that we would enable adversaries of allied countries, which, yeah, I mean, in retrospect, I can understand. I just think at the time it was an immature view.”
2020-09-29 · The Knowledge Project with Shane Parrish · #93 Matt Holland: Zero Day · IDENTIFIED FROM THE TRANSCRIPT