YouSaid · the spoken record

Stina Ehrensvard

lines on the record
52
first
2018-06-06
most recent
2018-06-06
sittings or episodes
1
sources
podcast

Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections

  1. So we will put UBK functionality into credit cards. And it's basically because it's a small chip. It's basically a chip and the software on the chip. It's not big. That can be integrated into a lot of different things. We will see it in the future. It was more than 10 years ago since we launched this first product. And also the conference not long ago when a guy came up to me and said, oh, I'm reading about Yubico. I just learned about your company and now I'm reading about it again. What an overnight success. And I smile and thanked him and said, yes, after 10 years. We are an overnight success.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  2. I'll tell you what I want. I want a hardware root of trust on any computing device that I have. Heck, man, I actually rely on my own, like, you know, I rely on my driver's license. I rely on my credit cards and et cetera.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  3. I do want to make a point about how unusual this is. Security is typically been something that you sell to the enterprise, right? And maybe antivirus and PCs are something like that, but certainly security, hardware, and they didn't really think about usability. The way that they proliferated was through direct sales. You'd have a sales team, they sell it. And now design is really important because you're attracting the users to these kind of great products. There's actually very different security has always been this kind of nerdy back office thing, and they really turned this into this very consumer design exercise.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  4. I mean, the reality is, if you look at it, it's not a fantastic design, but it's a lot of thinking. How do you make it flat, waterproof, crust safe? You can fit into an envelope so you don't have to ship it with anything more than a standard letter. How can you produce this at the lowest cost possible with only robots if you want something that is really at mass scale and small and affordable, you have to, it's a lot of, it wasn't easy to come up with a design. It looks super easy, but there is a lot of thinking behind it.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  5. I've noticed that when it doesn't work, when there's a lack of communication in some way. So all the mistakes I've done, I think I can point them to me or someone else not communicating. There's a saying that the biggest mistake in communication is the assumption that it has happened. It's so easy to believe that because you have figured it all out and you know it in your head that other people will understand it too. What's obvious to you may not at all be obvious to others. As an entrepreneur to learn to communicate clearly, especially when there is an issue. Your team, to your family, to your investors, to your partners, to your customers. If you learn those skills and refine them, it's going to be so much easier.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  6. It is a healthy disagreement. What Silicon Valley brings is sort of this bold Everything is possible. Let's go and do it. And also being brave and strong about how to position yourself sweet and sometimes little too cautious about sort of positioning. So I think with having part of the team in Sweden and part of the team in Silicon Valley, I have the best of two worlds

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  7. Yes, and that's also why Swedes are some of the best software developers on the planet because they have the ability to work together but also question each other. And they would not take a crappy direction from a boss and just go and do it. They will actually say, you know, I don't think this is a good idea. I think we should do this instead. And so there is a interesting mix of daring to speak out and also collaboration. It's a sort of social democrat country where we're all sort of trained to work together. By the way,

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  8. Because you have to build authority from the bottoms up, you have to earn it. It's not bestowed. You have to work for every scrap of your credibility with your team and the people you're working with.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  9. So, I don't think there is any country in the world that has the higher sort of, if you go out and measure where you're allowed to question your boss as Sweden. So you have to sort of build authority and trust from sort of going from the bottom. You can't just go and say, you do this.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  10. And when you actually don't need investors, that's when they will come to you. Everyone said no to me when I landed here because we weren't proven. But I continue and eventually I got introduced to Ramsharam, who sits in the board of Google. And he had this Silicon Valley mindset. After 40 minutes, he said, how can I help?

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  11. So I had to focus on getting customers and I had to focus on being profitable. And I think this is a really good advice for any entrepreneur. Once you have really great customers and you have a profitable business, the right investor will find you.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  12. But bring the president was one of my many options. There was a little girl I caught up in the highest tree possible and my parents were never afraid I would fall. They said, how is the view up there, Stina? That gave me the self-confidence to take risks. When I started the company, it was not easy for me to raise money because this was not...

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  13. Yes, I do think I have a slightly warped self-confidence. It came through my father. I was born here in US by Swedish parents and then the family moved back to Sweden and my father often presented me in front of friends of the family as here is my daughter Stina. She's the only one in the family who can be the president of United States.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  14. Process to get into the White House, so two hours before the meeting. I got a message saying, you can't come in. But by the way, we can meet you outside at the local Starbucks. When I was picturing myself in this Starbucks, this is almost like a feel-good movie. You know, all these crazy, fantastic, unexpected things happen to be an entrepreneur, you sort of need to have a extra battery of confidence because you're always challenged.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  15. I am so passionate about this. I really, really love my work. And then the other thing that is quite amazing, I get help. There is a saying that if you're bold and kind, mighty forces will come to your help. You know, once I got the opportunity to meet President Obama, I was invited to be here at a security conference at Stanford. I was in a panel in the afternoon talking about the standards. I got a message on my phone. It says the president wants to meet you. I got three minutes to pitch and I think what does he care? So I went in and said, we're working on new open identity standards that will help to protect 300 million Americans from being hacked. And he smiled. His beautiful big smile. And he responded, I know, that's why you're here. And then a few weeks later, I was invited to the White House to meet with his security advisors. And I completely bumbed that you need to go through an ID verification.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  16. One of them worked for Google, and that's how we got to Google. All startups will sooner or later face challenges. Well, some of your challenges will turn out to be your biggest blessings if you're there to seize the opportunity.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  17. A decision we need to make. We can make it open source, or we'll have to go back and correct this podcast that has gone out to 100,000 people. And I thought about this for some time. I said, you know what? I actually think this is a really good business plan. We started with a lot of internet security, open source geeks around the world. They were our first...

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  18. And he had a hundred thousand listeners. And then he added something that got me really confused. He said, and by the way, it's all open source. And Hyend made it open source. I had told him that we're working to figure it out. To be very honest, this was in the early days. I didn't have any marketing department. It was probably flaky and not so well written. So he made his own interpretation. And I had to make a decision really quickly because on my email, I now had 100 people who was listening to his podcast sort of, oh, where can I download the open source software? Where can I build things? And I talk to Jacob and the little group around that was Ubiquiti at the time and said, we have...

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  19. And two weeks later, this podcast went out where it said it was a really bizarre thing. I was at this conference and the last day of the show, I met this woman on the escalator, and she gave me a key. And it was the coolest new product on the show. And then...

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  20. Well, that was a business plan that was set from a podcaster This was a year after we had started Ubico. Basically no investor had a Swedish angel investor. I had no customers. I had very little money on the bank account. It was another security company who invited me to a conference here in US at the RSA conference. They wanted to license our technology. They wanted to show our technology at this conference, but they changed their mind just the day before we arrived. And there I was, you know, I had a handful of Yubikis with me. I had a business card, but I basically had no press release or no story to tell. And it came to me. But here I am at this big conference, and there's probably 100 journalists. They're probably in the press room. So where is the press?

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  21. I can answer part of that, which is Some companies are much more interested in their image than their customers' security. And as a result, for them to adopt a solution that they didn't create is an acknowledgement that they can't provide the security solution themselves. And I think for me the crowning example of this is been Apple. Any number of security vendors will tell you when we try and provide a solution on top of Apple, they don't want to admit that they're insecure. Which is a shame because, I mean, there was a big announcement of zero day vulnerabilities in iOS. So every company has insecurity. Having a real security ecosystem around it makes a solution better. One of the reasons that you, because one the hearts and minds and has been this kind of organic, bottoms-up phenomenon is contributions of open source.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  22. The open standards, I think, is critical because then you're not hiding anything. The future of security can't have this big black box hidden security. Do you know what just trust us? We are strong. We know it. We actually here, this is how it works. Take it or leave

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  23. So on this whole discussion, we have to accept that we're not going to have a secure internet. We will not be able to trust our software. We will not be able to trust their networks, our Wi-Fi's, our devices, either computers or phones. So instead of trying to fix it, we can just say, okay, let's take out the sensitive part. And move it from the internet, move it from the computers. It's an unfortunate realization. The perfect world, we wouldn't have to, but the way the internet was designed, going back to this beautiful invention, it was designed for sharing. It was not designed for security. Instead of saying, oh, this is disaster, we're going to see companies and systems that will very much challenge the large centralized trust models we have today.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  24. Not only that, I'm saying Google has announced that they're doing this for the special purpose chip. And so to have something that's a few hundred bucks that, you know, is part of the same model, I think is probably a disruption on the server side.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  25. Google has made it public that they have a special purpose piece of hardware on all of the service called the Titan chip, a trend to using hardware on every server to protect them as well. Another thing that people talk about is like putting it in a chip like an Intel chip, which is great. One thing about security that I've learned over the years is you have to secure at every layer. Like you need software security. And in software security, you need app security and OS security. You need hypervised security. You need chip security, right? But again, even if you're putting security controls within, for example, an Intel processor, it's still on the same die as all of the other functionality. And then we see bugs like we had recently, like Meltdown. So the idea is to have a separate chip on a separate die who's 100% functionality as for security. And now you have something that you know what it is. You can trust it much smaller attack surface that you can use for whatever.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  26. Same authentication encryption protocol, but not between a user and a server, but between devices, between servers and servers, between a phone and a service. And there are, what is it, 75 million, 100 million servers out there? So it's not only users who need to be protected. There are other systems. And today it's quite costly and cumbersome to protect them. If we just move out the really sensitive parts, the logging credentials and some of the things we really want encrypt, not everything. We have minimized attack vector and we have significantly upped the security.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  27. The next evolution of the FIDE protocol is to make it passwordless, where you can combine the UBK with a fingerprint or biometrics or geolocation or something else, because you always want to have an extra factor, just like your ATM card. You have that pin. So that's a good evolution happening in parallel the same protocol is getting into payments, payment in the browsers, into IoT, into encryption, user-owned identity.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  28. In order to make it really secure and really easy to use. Another way someone needs to download a software which adds complexity and a security risk. So I think that's the sauce. And the reason why Google was able to cut down support was because they gave everyone two or three keys. I mean, if you have a login technology through your phone or through a token or through a card, you will sooner or later lose it just like a car key. The reason why we have an extra car key or an extra house case is good to have an extra. This technology allows you to set up multiple keys

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  29. So we started with that sort of just one touch user experience that didn't have the ultimate protocol because we needed native support in the browser. And then in order for this to work just everywhere, we need all browsers. So Google was the first, Mozilla is coming on board, Microsoft is coming on board.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  30. These big banks don't have to have special hardware and special things they have to do. You don't have to worry about that layer. So now the challenge to overcome is simply time of adoption, cultural barriers, behavior, as you said. But you've mentioned now a few times this sort of tension, I would argue, even though they're complementary between usability and security, because you make certain trade-offs. They tell you you're not supposed to use the same password everywhere, but people are lazy, not even just lazy, they're human. So tell me about how you went through that balance between great security and great usability.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  31. Things take time. Standards work take time. And changing people's behavior also take time. I mean, we're so used to use name passwords. We're starting to get used to the SMS two Google published a report not long ago where they said that they were able to cut down support to 92% compared to a phone app. After that, the other Internet companies came on board. So I feel like the world is getting educated.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  32. What's happening now that is all leading browsers and platforms are engaged in this open standards work. So today I can use my key to log into Google. The same key I can log into Facebook and Dropbox and GitHub. By the end of this year, I will be able to log in to several banks, to US government services, and none of these services share any information about how my key is used. There isn't a centralized service provider who sits on the keys. It's not owned and controlled by the government, not by Google, not by Ubico, not by Microsoft. And that's really what's the game changer is because now we can set up distributed trust models between individuals, some companies, and do things. It's sort of in the same vision of blockchain. How do you secure things that are distributed and not centralized?

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  33. Before SSL, you didn't have secure identity, so you didn't know who you were talking to and you didn't have encryption. And so everything was in plain text. And with SSL, you got both of those. So, for example, if you go to Wells Fargo, you know, you're talking to Wells Fargo because someone has, they have a signed certificate that says Wells Fargo that came from a trusted authority like VeraSign or whoever it is. And so it provides both security and privacy.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  34. So it started just named Q2F, which stands for universal second factor. And then we contributed the code to FIDU Alliance. FIDO Alliance is an open standards consortium, including Microsoft and PayPal and Bank of America and Visa. I mean, 200 companies are there. They are now working, developing this sort of idea, concept, and innovation that we contributed with, not only for authentication, but for payments. I'm absolutely convinced that this will have as big impact on internet security as SSL have had in the past.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  35. And if you put it into the browser, it's much easier for the user. You don't have to do anything. And the risk of having to download something that may be a compromise is mitigated. And that became Fado U2F. And since Google deployed this for all staff and contract there, they had zero phishing attempts.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  36. Quite a lot of problem with this. It was growing. And they realized there was no technologies out there that could solve this at scale. And we approached Google with this idea of one single key to any number of services. At the time, smart cars were the only technology that would solve the problem. But smart cars are complicated. They were designed 30 years ago. They were not designed for the web. They need readers, client software, drivers, and up for the phone. It doesn't work for the phone. So we said, what if we would combine the simplicity of the UBK? This was initially just a one-time password device with public crypto and NFC, so it would work over mobile and then build in the client software and driver directly into the browser.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  37. It can also be physical. My friend Kim Zetter wrote a book on Stuxnet. The idea that something digital can actually affect something physical, like a nuclear factory is insane to me that just goes to show there's a larger attack surface with software.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  38. Security is, I'm safe, privacy is I'm disclosing information about myself, private information about where I live, my phone number, my age, and it could include healthcare records, things that really should not be public, while security is basically a lock and it doesn't necessarily need to have anything about you. It's just a good lock on a door. The world is seeing an interesting war right now over the internet. Historically, we had cannons and tanks and machines to kill each other. Now we only have to hack into each other's systems on the government level, on a personal level, to do damage that can be far bigger than what we've done.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  39. Historically, security and privacy has not been a good fit. Good security has always come with not so great privacy. We started giving away some of our keys to dissidents and journalists around the globe. The most touching of all was a journalist from a non-democratic country who sent us an email with the email heading. Thank you for saving my life. They needed a solution that was not tied to the real identity. Something that was them. They were the same person coming in again. They were the owner of the account that they had set up, but they didn't disclose any personal information.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  40. So that had a database of fingerprints. And for those of us like myself, I used to work for the government that had our credentials stolen, we can't even do global entry anymore because those biometrics, of course, because we can't use our fingerprints anymore. And so the problem with biometrics is if that's what you're using for your credentials and someone steals it, that's it. You're done. Now a harbor token that's independent of that, you can protect it. And so I feel very strongly that the solution must be physical. It must be independent of the physical body and something that you can put into safe if you want to

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  41. And that's why we've moved from software to hardware. Now, a very common thing to do for two-factor authentication is go to cell phones. But even those aren't something that you can really protect because somebody could walk into a T-Mobile store in Idaho, and they could show a fake ID from our team. They could port my phone number to their phone, and then they could use that to reset all of my passwords. So a phone number is not something I can put in my pocket or put an essay from Protect. But if someone steals my physical key, what do I do? I get another key. What if someone steals a biometric? You only have one body.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  42. Kind of the way that I think about this, which is there's many ways to try and do security, right? One of them is pure software. But the problem with pure software is it's kind of turtles all the way down. What do you mean by turtles all the way? And by turtles all the way down is like you've got software protecting software. There's nothing that I can physically do to protect that. So remember, when you connect to the internet, every sociopath on the planet has access to your computer. And if they have access to your software and you have no physical recourse whatsoever, then that's what I mean but turtles all the way down. They can do anything they want because they own the software.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  43. And has a very small attack vector. And why is that? Because I would imagine that it's easier bluntly to steal the hardware authenticator like a little object than it is to steal a password out of someone's head or their fingerprint. What's the rationale for that? Well, a fingerprint is something you can copy. The best hardware authenticator, they generate new passcodes every time they're used. Like old school VPN keys. And the best one actually use public key crypto that is the ultimate encryption method that is really, really difficult to hack. So every time it's used, it's new compared to your fingerprint, which can be copied. There's also privacy concerns with sending information about your fingerprint over the net. But just sending strong digital numbers over the net is the more secure way to do it.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  44. Think of authentication, people talk about two-factor, three-factor, and two-factor authentication. Is it something you have and something you know? And oftentimes that's something you have is like your cell phone. And something you know is like your password or something. And also you can have like a fingerprint sensor you and you can authenticate that way. And that's like bio metric or you can use your eyeballs or retinal scan. And then I've also heard of things like three-factor and four factor. How does this fit in that big picture? So the more factors you have the more likely it is to be secure. But it also add complexity to the user. I believe that the pain or a password or biometrics is about the same level of security. In addition to that, something that you have, or actually you know with something that you are, like a fingerprint or your eyes, should ideally be combined with a hardware authenticator that's in your pocket, that's not connected to the internet.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  45. So, security is top of mind, and it's been top of mind. You know, certainly since I've started computing, but especially now, I mean, you hear it all the time with all the account takeovers. It used to be like, okay, there's some hacker that's going to kind of break into your computer remotely. And more and more, the type of threat really is something where I will become Son and take over your Twitter for the purposes of I'm going to post silly things to taking over a bank account. I mean, like if I can impersonate you and be you, I can have access to those dollars. And we're seeing this more and more. I think this is the primary threat. And so if you're in the security industry, two things come to mind. The first one is we're trying to develop solutions for these. And there's only one that's kind of been really proven to work. And these are Harvard tokens and Harbor Roots of Trust.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  46. My keys behind in my bag, so I actually often wear it on my hands as a bracelet in order to log in. And where before we still log in through Okta, which is like our unified browser login for the firm, now instead of using a text password or like a little app on my phone, I now insert my YubiKey into my USB port, just stick a little button and it just instantly logs me in. It takes like less than not even a second.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  47. My first question was these smart cards that need drivers, why do I need a driver? I can just plug in my keyboard and I don't need a driver and then Jacob, that simple question actually resulted in our first invention. Which was a security key that generates one-time passcode through the keyboard interface. It actually acts as it was a keyboard. So when you touch it, it generates along encrypted code through the keyboard. I don't have to retype. In fact, that's not unlike how YubiKey works right now. So just a quickly explain for people what YubiKey, the hardware token, hardware authenticator, I'm just going to give you my lay person's experience of it. I have like a little USB stick looking thin black little device which has gold prongs and by the way because of that I've turned it into a bracelet charm because

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  48. I needed to figure out something that he couldn't attack. He knew that any software that's downloaded on a computer or on a phone can sooner or later be hacked. And that's the reality we're seeing. So secretly your plan was to see if you could beat him. The only thing that was really secure and still fairly secure with smart cards, but they're just so difficult to deploy. That doesn't work. I mean, Google realized that. And we knew it. Jacob, my husband, was an electronic computer engineer who built his first computer when he was 15. We started dating when I went to college and started product design. And he built the working prototype for one of my designs. And when we knew we wanted to develop a security solution that could scale and was not hackable,

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  49. And then the first time I logged in, I was registering to an online bank. And the bank told me that I would be safe with the username and a password and the software that I downloaded on my computer. But I happened to know a former White Hat hacker who told me it would take him a day to write the code who would empty my bank account. So I called up the customer service at the bank and asked them what they wouldn't do about this. And they said, can you please tell your friend to not do that? What I didn't tell the bank was that the former White Hat hacker, who, by the way, never did anything criminal, is also my husband. And the father threw my three children.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source

  50. Oh, that sounds cool. How can I help? So I don't think there is an idea or a vision that is too big for Silicon Valley. The first time I connected with the internet, I fell in love. I just thought this is the most powerful thing mankind has ever invented. I actually felt it was almost like a spiritual experience. Here's this place where we're all connected, where we all have this endless information that we can tap into. And then when I learned that it was vulnerable, that the security wasn't great. I don't know, but there was this calling where I just felt, I cannot let this fantastic invention fail. It's just one of those things that someone need to be there to protect, like the bare mother is protecting her kids. That's what I felt.

    2018-06-06 · a16z Podcast · a16z Podcast: The Hard Things about Security · IDENTIFIED FROM THE TRANSCRIPT · source