Episode 101 ·
John Callahan - CTO at Veridium
Today we are talking to John Callahan, the CTO of Veridium. And we discuss ubiquitous computing and what that means for personal devices, why biometrics are the bridge to making the computer invisible and the efforts to put control of data back in the hands of the individual.
All of this, right here, right now, on the Modern CTO Podcast!
Dr. John Callahan is responsible for the development of the company’s world class enterprise-ready biometric solutions, leading a global team of software developers, computer vision scientists and sales engineers.
He has previously served as the Associate Director for Information Dominance at the U.S. Navy’s Office of Naval Research Global, London UK office, via an Intergovernmental Personnel Act assignment from the Johns Hopkins University Applied Physics Laboratory. John completed his PhD in Computer Science at the University of Maryland, College Park.
SHOW NOTES:
- Works from home, but flies to New York and Boston offices often
- Veridium is a biometric authentication platform
- Biometrics used to be science fiction
- Worked at Xerox in the 80’s Star work station worked 40k dollars
- Ubiquitous computing - computing will meld into the background - Print melded in to the background. Working to realize that dream
- Loves computer tech - it's as fundamental as writing
- Always looking towards the next challenge
- Sept 1991 edition of Scientific American. The computer of the 21st century - Mark Wiser
- Biometrics are the bridge to making the computer invisible
- The concept of the personal device was an anathema to how mark was think. Time is valuable
- Second factor and multi-factor authentication
- Was approached by Veridium several years ago. Had a couple of questions IEEE 2410 biometric standard
- Has about 45 in engineering - biometric team and mobile and server team
- Technology advances exponentially
- How does Alexa identify us? Phone uses face ID - Explicit authentication session
- Behavior biometrics - allows you to conduct longer authenticated sessions without having to fall back to explicit authentication
- Even more value to be brought through your data
- 3rd choice for where you keep your biometric data - Self Sovereign identity - ability for you to control your own data. Context of Data Breach - how do you not keep data on a silo database
- Decentralized identity foundation - putting people back in control of their data
- Efforts to work for self sovereign identity - Buzz Word How trust is established - check another party that can be offline
- Part of an organization called SOVRIN
- Using Digital credentials that you have to supply
- The subject providing the digital credential is best done through biometrics
- Problem with bitcoin and crypto is how do you control the private keys and how do you manage them properly
- What if you lose the keys? Recovery - Grant Dasher got up at a conference - google strong authentication work.
- In the end we have ourselves to present. Biometric recovery and the ability to use it to reestablish key pairs.
- How do you handle identical twins? All biometrics are not created equal. Face is one of the weaker biometrics. FaceID apple has put very fancy hardware - up the scale is fingerprint 90% - Iris is above that - DNA above that. Iris is different across identical twins. Most except fingerprint require special hardware. Veridiums solution is for fingerprint acquisition
- Enables convenience - Reached a breaking point
- We live in a password world but in 10 years or less it will be biometrics
- Greg Egan - Transporting consciousness
- Worked on a sliver of the Cassini project at NASA
- Take the offer of employee 13 at adobe instead of going to graduate school - JOKING
- Advice to previous self? Have Confidence and stay in it. Communicate more - evangelize. Jump in to open source projects
Transcript
(Joel Beasley at 00:00:01) Hello, my friends. This morning, I was on a run listening to Tom Bilyeu talking about how identity and values drive behaviors. And as I've been growing myself and helping others, I've learned how important it is not to base your identity on who you've been, but to base it on who you want to be. So if you want to be a great leader, you have to first see yourself as someone who values leadership skills. When you get to the top, you'll see that leadership is everything.
(Joel Beasley at 00:00:27) You can't have a company, you can't have a team without a leader, and there are a lot of bad leaders out there. So what is a bad leader? It's one that doesn't grow, one that doesn't improve themselves. Great leaders are always growing and looking for an edge. To learn more about how you can raise the bar and develop an edge, to identify your competitive advantage and become a better leader faster for yourself and for your team, visit leaderbits.io.
(Joel Beasley at 00:00:53) Today, we are talking to John Callahan, the CTO of Veridium, and we discuss ubiquitous computing and what that means for personal devices, why biometrics are the bridge to making the computer invisible, and the efforts to put control of data back in the hands of the individual. All of this right here, right now on the Modern CTO podcast. Here we go. This is the Modern CTO podcast. Now, do you typically work from home, or are you just home for the holidays?
(John Callahan at 00:01:33) I do. I am up to our New York and Boston offices quite frequently, though. And luckily, the company's grown. I used to have to go overseas quite a bit, but this past year, we've expanded. So we have New York, Boston, London.
(John Callahan at 00:01:50) I'm in the Washington, DC area, actually. And so the European team has expanded greatly, and I haven't had to go over there in about six months.
(Joel Beasley at 00:02:01) So that's exciting for you, right? Now you have to, you don't have to be trapped, not living in an airplane or out of a suitcase, which is—
(John Callahan at 00:02:10) Yeah, most of the time.
(Joel Beasley at 00:02:12) But the industry itself is booming, and you guys have to do stuff that was like science fiction, you know, two decades ago with the scanning and the biometric security and authentication. Can you tell me a little bit about, you know, the company, its name, and what it does?
(John Callahan at 00:02:30) So Veridium, and I'm the Chief Technology Officer. And so we have a biometric authentication platform, and it is an end-to-end solution that is handling authentication, right? Proving your identity to, typically, what's called technically a relying party. But when you log in to a website, you use your biometrics. And we work cross-devices, so that's the other exciting thing. We can use things like Face ID, Touch ID on those particular phones, but we also have modalities that work across phones. That's really what's successful.
(John Callahan at 00:03:13) And I guess the last thing is the ability of the platform to plug into existing architectures, existing identity access management solutions—Active Directory, the Citrix platform. That was a must. Right? So when we say end-to-end, we really mean it. Mobile to server, authentication and identity verification, and across platforms or across the devices.
(Joel Beasley at 00:03:38) So you have this platform, and you can work with all of these different devices and manage all the security?
(John Callahan at 00:03:47) That's right. So, I mean, it's one of the reasons I joined the company. As you said, biometrics—I'm not a biometric scientist by training.
(Joel Beasley at 00:03:56) You're not? Oh.
(John Callahan at 00:03:57) No, no, no, no. We have experts that are much better than me.
(John Callahan at 00:04:01) Now, I'm a computer scientist by training, more of a software architect. That's actually where I worked in. But, you know, biometrics were kind of science fiction. I don't know what your first experience was, but mine were when you went into some place and they had those little single-digit fingerprint readers hooked up by USB, right?
(John Callahan at 00:04:19) Okay? Those have been around for, oh, maybe 20 years or so. Before that, fingerprint, rolled fingerprint and ink, or something that some of the SLAP scanners are called. But they were highly proprietary. Well, they are highly proprietary, right? Each company, you have to have their software. So there really was no standard. So as these roll out, what was science fiction, was really proprietary, is now becoming standards rolling out for them, right? And have rolled out for them for security purposes, for privacy purposes, and for interoperability. So that's one of the reasons I joined, where they said, "Okay, this stuff is finally breaking out of the onesie-twosie solutions."
(Joel Beasley at 00:05:05) Mm-hmm.
(John Callahan at 00:05:06) And people are going to start talking standards, and the way it's going to be able to interoperate. So that's, you know, essentially how I got involved and very excited about the platform solution.
(Joel Beasley at 00:05:18) And so this was—you know, you've had an amazing career, right? Xerox, NASA. You were even a teacher at West Virginia?
(John Callahan at 00:05:27) Oh, you've been reading my bio.
(Joel Beasley at 00:05:29) I guess that's correct.
(John Callahan at 00:05:31) I—yep. So many of my students, they're out there. I was tenured faculty at West Virginia University. Yes, that was an exciting time.
(Joel Beasley at 00:05:39) So tell me a little bit about, like, what you were doing along this journey. I'm really curious about what you were working on at Xerox. We had a couple people that were working on—who did we—I had a guest on the show, and he was working in, like, Xerox Labs, and he had written the algorithm for the momentum with the mouse. Like, as you move the mouse across the screen, it moves faster.
(John Callahan at 00:06:04) So Doug Engelbart's team. So, on my—confessions on my resume, it says Xerox Corporation, Palo Alto, California. Totally true. However, if you put my age there, a lowly, just graduated with my bachelor's degree. So they don't put those people at Xerox PARC, right?
(John Callahan at 00:06:27) But next door to PARC, they were trying to commercialize the PARC technology and sell workstations. Now, in 1985—so I age here—the Star workstation, you can look this up, the Star workstation, the low-end unit in 1985 dollars cost $40,000.
(Joel Beasley at 00:06:48) Oh, my goodness.
(John Callahan at 00:06:50) And it had gray-screen monitor, drag and drop, email, WYSIWYG document editing. This is all—so I was on the part of the team, you know, as a programmer, essentially, commercializing. The language was Mesa, right?
(John Callahan at 00:07:04) It's a precursor to Ada. Anyway, so I was on the Xerox Office Business Systems unit team there, and then I went back to do graduate school. And Xerox had a program, actually, that they were reaching out to universities. Unfortunately, that $40,000 workstation essentially had a 20-meg disk that would crash once a month. But it had Etherneted services, file server, print server. There was no mainframe in that system. It was really historic, but then we had a saying at Xerox: You can tell we're the pioneers because we're the ones with the arrows in our backs.
(Joel Beasley at 00:07:44) I like that. I mean, I was funny. Yeah.
(John Callahan at 00:07:46) Yeah, yeah. I was never there when Steve Jobs supposedly came through and saw all this stuff and decided to do it for less than $5,000, but that was how the story goes. You know, it was great. It opened up my eyes. I had the pleasure to work with a wonderful man, if I may go on and on here.
(Joel Beasley at 00:08:04) Yes, please.
(John Callahan at 00:08:06) So my advisor at Maryland eventually left, with tenure, the university position. Mark Weiser. So many people will remember a guy named Mark Weiser. Mark was my mentor and advisor until he left to head up Xerox's research lab. And Mark's idea that won him several awards was ubiquitous computing. And in ubiquitous computing—they did a lot of work on this—the computing will meld, and I'm going to segue back to biometrics here. Computing will meld into the background, right? So just like you would pick up a pen or a pencil, I could actually pick up your tablet computer and then authenticate and get my information. Your wall might be active, right? And the most fascinating thing was he said the same phenomena that's happening now with computing technology happened with print 500 years ago. People were enamored with books. They went around and bragged to each other about books, right?
(John Callahan at 00:09:06) But eventually, print melded into the background. Now, one of the key technologies to ubiquitous computing is, how would you authenticate, right, when you went to somebody's wall in their house or picked up their tablet, right? You wouldn't do that now, right? We find these devices to be personal. Well, Mark found that to be an anathema. He said that's not how it should work. You should be able to—the world should be open to you, right?
(John Callahan at 00:09:32) That was the concept of ubiquitous computing, and we're totally not there yet. But to do that, you need to authenticate, you need to authenticate strongly and conveniently, right? So part of my journey has been, you know, trying to really realize Mark's vision. He passed away in 1999, unfortunately, at the age of 54. He really would have loved what's going on today and really been one of the leaders. Eric Schmidt of Google worked under him in Xerox PARC, actually.
(Joel Beasley at 00:10:02) Oh, really?
(John Callahan at 00:10:03) Oh, yeah, seriously. So I remember walking through the lab and seeing Eric Schmidt's door, actually, when he was still at PARC. So anyway, there's the long answer there.
(Joel Beasley at 00:10:14) I'm just, like, fascinated. I'm listening to stories over here. This is amazing. So then, did you tell me about NASA?
(John Callahan at 00:10:24) So, so my problem has been—I like computer technology. We are so lucky to live at this time. Imagine all of human history, and we are now—computing technology, which is as fundamental as writing, is on the scene and evolving rapidly, right?
(John Callahan at 00:10:46) So it's very exciting being alive during this sliver of time. People like Alan Turing, right, were some—but they would have even thrived more during this particular time. So I've been unable to focus on a particular job because I like lots of different things as they crop up. You know, I'm more of a—I'm going to say renaissance person, but I have difficulty focusing on some of the trends, so I tend to look at computing across things. So that's what drew me to biometrics, the next challenge, you know, the next mountain that I think is going to be exciting. Because, I mean, identity authentication are really broken. I mean, how many passwords do we have? Password reset—
(Joel Beasley at 00:11:28) Come on, though. Hold on a second. My challenge here.
(John Callahan at 00:11:30) Nightmare, please.
(Joel Beasley at 00:11:30) I love—I like this little thing right here. My phone opens to me, sees my face. I'm loving it.
(John Callahan at 00:11:36) So—well, that's what I'm talking about. You now have another convenient option other than passwords.
(Joel Beasley at 00:11:43) I wish everything could just look at my face and just, like, I don't ever want to enter—you find in life that the innovation happens where people, like, want to be lazy, right? It's like, it'll save me some time. Like, the amount of time humans spend authenticating is absurd.
(John Callahan at 00:12:00) Yeah, yeah. No.
(Joel Beasley at 00:12:01) It should just—the world should just work for me and only me.
(John Callahan at 00:12:04) Well, and this was Mark's vision with ubiquitous computing, right? So I, the rest of your listeners here, I would urge you, go to Scientific American, September 1991. Okay? And the name of Mark's article was "The Computer of the 21st Century." That was the title of the article by Mark Weiser and his team at Xerox in 1991. And that's exactly what Mark said. Okay? You should—the computer shouldn't be, you know, the focus of your attention.
(John Callahan at 00:12:39) When people first got books, they ran around and bragged to their friends about books. Now it integrates into our life, into the background of our life, right?
(Joel Beasley at 00:12:47) Look at my—look at my new iPhone. I mean, that's what we're doing. It's a new book.
(John Callahan at 00:12:51) Exactly. People are bragging about this now, and that's what happened when books first came out. They were so unique, right? But and—I laugh all the time when we go around and we show these devices, but they are a means to living our lives, right? They should be invisible. And part of what you just said, biometrics are that bridge to making it convenient and making the computer invisible, as Mark said in '91.
(Joel Beasley at 00:13:17) Well, it's happening, too, because, like, for example, let's take a look at my phone here. It's got a cute little monkey on there. She's 16 months old, right?
(John Callahan at 00:13:26) I have two myself. Yep.
(Joel Beasley at 00:13:27) Nice. And then you see the 24-hour time frame. It's all my phone, all my data. While this thing goes clunk, I go to Apple, put in my Apple ID. I don't care about the physical device itself.
(John Callahan at 00:13:36) This is—so you're making Mark's point. You've got to read this article, Joel, because it says you should be able to pick up someone else's device or replacement device as easy as I would lend you my pen.
(Joel Beasley at 00:13:49) Right. You're my best friend now. That's a Zebra. Really? That's my favorite pen.
(John Callahan at 00:13:55) Oh, mine too. So, but the idea, you get it, right? You should not be tied—Mark, and I hate to echo him all the time, but he always echoes in my head through my life. He was very influential. The concept of a personal computer or personal device was an anathema to the way Mark was thinking about the world, right? The computer should get out of your way. You know, it obviously is helping you, but out of your way. As you're saying, the time we spend—time is one of the most valuable things here, right? And password resets, and even—so I think we're experiencing now this with second factor and multi-factor authentication, right? Certainly, super positive for security, right?
(John Callahan at 00:14:41) Particularly, people are now using biometric authentication, not just for primary like you, but also for secondary authentication. That's where we hit the marketplace, right? Coming in for second and multi-factor. But ultimately, moving to replace things like passwords completely, right? And to use your face, fingerprint, to do primary authentication, to get the computer, as Mark said, with ubiquitous computing, out of the way.
(Joel Beasley at 00:15:07) Yeah. How do we—like, why isn't there some sort of—yeah, I'm an engineer by trade, right? So why isn't there some sort of API-style layer? No one's connected the dots where, like, my Mac has a camera on it, and when that multi-factor authentication comes through, like, it should just bounce right off my face just like it can unlock my computer. Why do I have to type in those silly codes all the time?
(John Callahan at 00:15:30) Well, so that's happening. And, again, so that builds into my point before that I remember being approached by Veridium several years ago, and my questions were, "Okay, you're a biometric company. Got it. But what more are you doing?" And my two questions are: you cannot go in with a biometric solution. You've got to have a platform. You've got to plug into existing identity systems. Okay? The second thing was security, right?
(John Callahan at 00:16:00) How is this secured? And when I heard that they had been working with the IEEE on a standard—it's known as IEEE 2410, or the Biometric Open Protocol Standard—that's the API you're talking about. There are register and enroll. This is an open protocol. You can find it on the web.
(John Callahan at 00:16:20) Okay. So it's an API, right? You have a client, the server. There are enrollment APIs. There are authentication APIs. And now, in fairness, and we are working this next year for FIDO certification, the FIDO Alliance has an API as well, okay? And that has its server-client-server side. There are toolkits.
(John Callahan at 00:16:45) There's a server-side API. So this is happening. Standards are advancing. Right?
(John Callahan at 00:16:50) So we're not in that proprietary—
(Joel Beasley at 00:16:52) Well, you know what I'm learning right now?
(John Callahan at 00:16:54) Companies. Yeah.
(Joel Beasley at 00:16:55) I think the thing that's brought me the most by this conversation is that you can say the phrase "I triple E." Like, I'm over 30, and every time I've seen that, I'm like, I-E-E-E-E. I've just—I don't hear people talk about it. I don't go to, like, the IEEE events or anything, but, god, it's so much easier. Every time I've read that in my life, my brain says I-E-E-E-E or whatever it is. You could just say "I triple E."
(John Callahan at 00:17:21) There you go.
(Joel Beasley at 00:17:22) That's so much easier.
(John Callahan at 00:17:23) Oh, well, you can thank them for that. And that's the academic background, because that's where academics publish—one of the venues for publishing. So—
(Joel Beasley at 00:17:32) How many people do you have right now at the company?
(John Callahan at 00:17:35) So we have about 70 people in parts of the world. As I said, New York, Boston, and London, and Bucharest, Romania.
(Joel Beasley at 00:17:43) Oh.
(John Callahan at 00:17:43) We have a team. So—
(Joel Beasley at 00:17:47) How many engineers?
(John Callahan at 00:17:49) Oh, engineering-wise, out of the 70, it's probably—I haven't taken account lately, but probably 45. Yeah.
(Joel Beasley at 00:17:58) Oh, okay. So you're mostly engineering.
(John Callahan at 00:18:00) Yeah. Yeah, quite. So we have a biometric team and then our mobile and server teams. Right? So it's—and the rest is sales force and leadership. And we're very busy at the moment because, as I said, as you demonstrated, biometrics have come of age. We have these—I call them supercomputers in our pockets. They're only going to get better. And in fact, I will say it's going to get better than what you're thinking.
(Joel Beasley at 00:18:26) No, I've got great—
(John Callahan at 00:18:27) I've got—I'm going to test you. I'm going to test you.
(Joel Beasley at 00:18:29) No. No, you're not going to win this one, my friend. I understand that humans think—oh—
(John Callahan at 00:18:33) Go ahead. Go ahead.
(Joel Beasley at 00:18:34) Humans think linearly, in a linear fashion, but technology advances exponentially. Okay? So if I'm going—if you go talk to a human, our default program state is, "Oh, what's going to happen in the next five years?" We look back 10, we kind of divide, we estimate forward. Incorrect, my friend. That's linear thinking. Technology advances exponentially. So I think it's way—like, everyone else around me is like, "No, no, no." I've argued with people about, like, "Oh, voice isn't the future." Like, two years later, you know, it is. And it's just because—whatever you can look in society, like, for example, with the Alexa thing. I saw my hairdresser. She says her new best friend's Alexa. I had not had a voice assistant or anything like that. Like, really? Like, are these things advanced? Like, do they work good enough? Because I tried them a long time ago, and they were, like, subpar at best.
(John Callahan at 00:19:24) Oh, totally. Yeah.
(Joel Beasley at 00:19:25) And she's like, "No, it's great." She's like, it's her best friend. She can tell her jokes. She plays it. So I went home and—or I went to Best Buy, and I got one. And they said, "Yeah. This thing was, like, sold off the shelves. Like, we've never been so unprepared." And that was, like, last Christmas, so that was a year ago. And this whole past year, I've fallen in love with Alexa. Like, I use her for so much stuff. She turns on my lights, my automation. And she can do any order—I order stuff, like, when I would need to reorder things on Amazon. Like, so useful.
(John Callahan at 00:19:55) So there's a case in point of how does that—how does Alexa identify us? Right? So you just—you used your phone, for example, with Face ID on your iPhone to use Face ID, making your life more convenient. But that was still an explicit authentication session. Right? So you paused, you showed your face, and so forth. And that will continue to play a role for strong authentication and sessions where you're doing some—let's say you're transferring a large bank amount of money, not me, but, you know, money in your podcast Google bank account. And we're doing some, you know, password—what I'm saying, some credential reset. Okay? But in the near future, our phones, our devices, like Alexa, are going to get really good—I had to admit this to myself—they're going to get really good at knowing it's you continuously and in the background. So, again, pulling that ubiquitous computing theme up. It's not going to wait for these explicit sessions.
(Joel Beasley at 00:21:05) It doesn't today. You want to hear something creepy?
(John Callahan at 00:21:08) Yeah. Yeah. So yeah.
(Joel Beasley at 00:21:09) We have one out in the center of the office. And the other day, we're just, like, "Play Heidi's favorite music," and it started playing the music that Heidi suggests. Like, we didn't—we never set Heidi up. Like, we never set the people—it learns the people that are speaking in the area around it, and it will learn their names when you're talking to them. It'll learn all this stuff. And then when they start suggesting songs, it'll develop profiles based on their interest. We never set up a profile for anybody. The only thing I've ever done is just plugged it in and hooked it to my Amazon account.
(John Callahan at 00:21:41) Right. So this is where there are several names for this now. So either behavioral biometrics or continuous authentication or adaptive authentication or behavioral authentication. Right? These are all current terms. Our own product in first quarter of next year, so 2019, we have added behavioral biometrics. So that allows you to conduct longer authenticated sessions without having to fall back to explicit biometric authentication because your phone will be able to know that it's still you using it from your last authentication session. Okay? And there's various ways of doing that, including the gait, right, movement of device, geolocation, other things learning that it is actually you. If it is in doubt at all, right, that it's you, it will call for an explicit authentication session, right, and ask you to authenticate in order to bump that up. But that's coming next year. And in fact, it's already in many products—our product, the first quarter. Behavioral biometrics, we call it, or user behavioral authentication.
(Joel Beasley at 00:22:51) You know, you can see that today already. You put ideas into my head, my friend. When I travel, my Visa yells at me. "Bump, fraud." I land in San Francisco. I'm in Florida. "Fraud. You're not in San Francisco."
(John Callahan at 00:23:03) I love it. I have American Express. I do the same thing. I count on it. I use that for—I would love to see the positive confirmation of a purchase. Right? So, you know, I get a feeling of confidence through these sorts of things. Yeah. We're already seeing that. There are privacy implications involved, obviously—that location tracking, use of that to ad tracking. I definitely have concerns, but we have an answer to that.
(Joel Beasley at 00:23:34) Yeah. See. And you know what? I've—I've gone—as I've gotten older, I've—I lean on convenience. Like, I'm like, I don't care. Like, all this—the here's the thing. The amount of value it brings me for it to know all this stuff about me is greater than the amount that, like, I care if the government knows where I am. I don't care. Like, I just don't care.
(John Callahan at 00:23:57) But what if I told you that, actually, that value—there could be even more value involved in that. Right? So this is one of the issues that—I'm not a legal person. I'm a technical person like you—have a technical background. But what if I told you that your data is actually more valuable than that value you're getting now?
(Joel Beasley at 00:24:18) Pay me for it.
(John Callahan at 00:24:19) There you go. Right. So we looked at—how could we transition? You know? So we allow our biometric product—you can configure the authentication sessions to keep your biometric data on your phone or device using the native authenticator, for example. It's locked into the phone. It can't, you know, be extracted. That biometric data can't be extracted from the phone. We also have configuration for those organizations that need to do biometric comparison on a server. Okay? Governments, law enforcement, and so forth—we do have customers in that area that need to do that. That's specialized type of needs. But even in that case, you know, a siloed database of biometric data has to be very carefully protected, and how could you get away from that? How could you—you know, what is the other choice? Okay? Biometric data on the user device or biometric data on the server. There is a third choice now, and that third choice—so we joined up with—
(Joel Beasley at 00:25:35) Wow. I'm going to cry. I'm just kidding.
(John Callahan at 00:25:37) No. Not this—no. Not necessarily. You can still keep it on your own device, but there's this movement that we are promoting that's coming down, like, self-sovereign identity. Have you heard this term?
(Joel Beasley at 00:25:49) No.
(John Callahan at 00:25:49) So I would—this is, hopefully, this is another benefit to your listeners. So the ability for you to control your own data. So let's put this in the context of a data breach in general. Right?
(Joel Beasley at 00:26:06) Yeah.
(John Callahan at 00:26:07) How would you not keep sensitive data of any sort, medical records and so forth, on a siloed database that is probably going to get breached at some point anyway. Okay? Will get breached. And spread it—that's right. And spread it out so that you actually retain ownership. Right? You keep control of that data. Now, it has, for example, been blessed, signed, encrypted properly, whatever. There are several schemes like this. But you actually can keep it. You can keep it on your device. You can keep it in the cloud. There's a concept called cloud wallet. All right. It's being advanced by an organization called the Decentralized Identity Foundation.
(Joel Beasley at 00:26:45) That sounds like I trust it. Decentral—
(John Callahan at 00:26:47) There you go. So the Decentralized—the DIF. Oh—
(Joel Beasley at 00:26:51) There we go.
(John Callahan at 00:26:52) Yeah. The DIF. So we are a DIF member. That is putting you back in control, holding that information. Now we're not alone in this. We didn't pioneer the concept, but we are definitely promoting this as the next step in evolution.
(Joel Beasley at 00:27:10) I could tell you right now—
(John Callahan at 00:27:11) Control. Now the way in which—so the idea would be just like—if I were to give you my driver's license, Joel—
(Joel Beasley at 00:27:19) Yep.
(John Callahan at 00:27:19) And you were to look at it. Okay? You would probably tilt it to see the holographic stuff. You'd examine—you know, we're not experts, obviously, like at the airport where they put the UV light. You may even have one to do that. But that's between two parties. Right? Me and you. You look at that credential, and you trust it to a point. Right? To say, "Okay. This is who he is, and it says he lives here, the picture matches," and so forth. Only two parties. What do we have on the web right now when you do something like log in with Google, log in with Facebook, log in with—you have three parties. Okay? You have you, what's called the relying party, the site you're trying to get into, and then the IDP called the identity provider, right, like Google or Facebook or Twitter. What if I told you that self-sovereign identity will allow you to do that former thing where it's just me and you, and that's it. So that's coming. That's what self-sovereign identity is trying to enable on the web and to do so for even critical credentials that are going to be digitized in the near future. So passports and driver's licenses are still physical documents. Right? We have not gone that last step.
(Joel Beasley at 00:28:34) We haven't. Yeah.
(John Callahan at 00:28:35) But it's coming. So I point your listeners to projects by the Department of Homeland Security here in the US. There are other efforts worldwide that actually are working on this. Some of the work is under self-sovereign identity so that you own and control your own identity credentials. Now, the trick is—and I'm going to say a buzzword here, but don't be afraid—how trust is established between you and me when I hand you a digital credential. You do have to check another party, but that party can be offline. And, basically, when I was issued it by a government, they actually signed it and they essentially put, like, the public key and the signature on a blockchain. That's the way the information gets from the issuer to know that you can trust the credential they gave you. And, again, we did not pioneer this. This work has been going on for more than three years. It's been funded by DHS, organizations like the Decentralized Identity Foundation. And we are part of an organization called Sovrin, S-O-V-R-I-N. So sovrin.org. It actually operates. So it's an operationalization of this. It actually has a blockchain dedicated only to digital identity, and we are the only biometric authentication company, actually, as a founding steward. They're called stewards. Those are the ones operating nodes. That is the next step in evolution. Right? That we can get past these breaches, not only now have biometric authentication, but now get away from the breaches by—it's called spreading out the attack surface. Right? If your credentials are with you and me and so forth, it's not in some silo where you break into the castle and you get access to everything, millions of records. Right? If I were to spread out the attack surface, that's much more resilient, right, to attack than having a single silo. I like to think nowadays we live in a mainframe era of web services. Right? But you—you don't remember mainframe. Oh, I know.
(Joel Beasley at 00:30:46) I do. I want to see where you're going.
(John Callahan at 00:30:48) Well, the idea being when you use any large web service, even though it's a large cluster of computers, you can think of it—it is one big silo of data. And we used to do this 30 years ago with big—and we got away from that through personal computing. Well, another wave is coming where we won't have those silos anymore, but we will be able to establish trust between all of our individual devices that manage this. Now, a lot of it will happen in the cloud, but it will be provisioned differently.
(Joel Beasley at 00:31:20) So, like—
(John Callahan at 00:31:21) Let's just stop there.
(Joel Beasley at 00:31:22) Oh, yeah. Well, let's—no. Let's not stop there at all. Let's keep going. I want to know, like, how it would look because—my background's developing applications. Right? So, like—
(John Callahan at 00:31:30) Okay.
(Joel Beasley at 00:31:30) Let's say that—let's just stick with a really simple concept of, like, a bank. Right?
(John Callahan at 00:31:36) Mm-hmm.
(Joel Beasley at 00:31:36) You get a—a bank has, like, all my information. They have, like, my driver's license, my Social Security. They're a big silo waiting to be attacked. Right?
(John Callahan at 00:31:45) Yep. Yep. Yep.
(Joel Beasley at 00:31:46) Now they need that information in order to—to have—like, to authenticate with—they need that information. Right? Like, I have to give it to them. They have to have it on file somewhere. So, like, how do they have the information, but it not of—and then have the information of millions of people, but it not be in a silo?
(John Callahan at 00:32:06) So without diving so deep on self-sovereign identity, which is its own other topic, I would go to an issuer, maybe that bank initially, and I would provide that type of information, and you can actually provide it digitally through these digital credentials. But you have to think that information should really be ephemeral in the sense that after I provide it, they could get rid of it.
(John Callahan at 00:32:34) And they've issued me credentials such that when I approach them later, or even if it's portable, I approach them with a credential that I control. And that word "control" is important, and it has to do with controlling a private key.
(Joel Beasley at 00:32:50) I'm sold. I already got it. Let's make storing personal data illegal.
(John Callahan at 00:32:54) Well, GDPR in Europe is making a step toward that, right? So if you think about GDPR and let's keep biometric data because that comes under GDPR, if you read that legislation in Europe, it is saying, if you don't absolutely need it, you cannot store it. It must be ephemeral. You must have a compelling reason for storing it. That's part of the GDPR legislation. If a company is breached and that data is lost and it is not found to be—if it's data they should not have kept, the fines are, I mean, it's upwards of 20% of revenues or something for that company. I mean, it's quite punitive.
(John Callahan at 00:33:41) So they want to—I've never met a company yet that doesn't, they do not want to hold this long term. They would like to de-risk by not holding that, including biometric data. They don't want to hold that. So it should be ephemeral at best, and it could be. But I think your question is, how down the line, when I return to them to do operations, do they continue to have that confidence in subsequent authentication? One thing that occurred to me several months ago is banks not only have to do—they call it "know your customer" type of operation, like when you use it for an account. That's what you're talking about. That's not just an upfront activity, and then you have an account and they stop. They are obligated in most jurisdictions around the world to do continual anti-money laundering checks and these sorts of things. They could do this by getting rid of the ephemeral data and using those digital credentials that you have to supply should you need some subsequent verification of your identity.
(John Callahan at 00:34:52) And then, finally, if you're holding that digital credential, and again, your listeners and so forth, look at some of the work on self-sovereign identity on the Sovrin network itself. The tough nut is, how do I associate that digital credential that I'm handing you? So it's been cryptographically signed. You, as the relying party that needs to trust me, can check that. But how do you know that I actually unlocked the private key to prove that I control those credentials? That is best done biometrically. You can do that through passwords and so forth, but the binding—what's called verification of identity—that the subject actually providing the digital credential is the person you're currently operating with on the other end, that is actually the great unsolved problem at the moment, open to most disruption.
(Joel Beasley at 00:35:48) State the key.
(John Callahan at 00:35:49) Did you understand that?
(Joel Beasley at 00:35:51) In the most simple fashion, state the actual problem.
(John Callahan at 00:35:54) So right now, private—public key encryption. You're pretty straightforward with that, right?
(Joel Beasley at 00:35:54) Yep.
(John Callahan at 00:35:54) So, yeah, I have a public key published by you, and I say, Joel, I send you a challenge. I encrypt something with the public key. I send you the challenge. You, what do you do?
(Joel Beasley at 00:36:14) I decrypt it.
(John Callahan at 00:36:15) You decrypt it with the private key. You might then sign something, send it back. I decrypt it with the public key. You encrypt it with the private key. I decrypt it when I get the challenge answer back with your public key that I have access to, and that establishes that level of trust, right? Okay. Now the last link that really hasn't been solved is, how do I know it's you that control the access to that private key? Somebody could've stolen your password, right, if you lock it with a password or unlocked it with your phone. You see the problem? The problem is the subject. How do I know you, literally, as a subject, control that private key?
(John Callahan at 00:36:57) Possession of device is one thing, right? The fact you possess a device that has the private key, but that's only part of the solution. How do I strongly bind your ability to control that private key with you?
(Joel Beasley at 00:37:12) You just have that in that whole thing, right?
(John Callahan at 00:37:13) Right.
(Joel Beasley at 00:37:14) You'd have to make a new system. I mean, you'd have to modify it to include—
(John Callahan at 00:37:21) But that's what our biometric solution does. We rely on public key encryption. We have a private key, but control of that is unlocked by your biometric. FIDO approaches it the same, and so does Face ID and Touch ID on Apple devices and Samsung devices with Samsung fingerprint. They all rely on the biometric unlocking that private key. But the key there is, how do you know that the actual unlocking was done by the subject who initially enrolled that key pair in the first place? It's a subtle nuance, but biometrics are one of the strongest ways of binding that.
(Joel Beasley at 00:38:00) You have to use biometrics when you're building that whole process to begin with. It has to be embedded in its root.
(John Callahan at 00:38:07) That exists. So the whole reason for our solution, FIDO's solution, is to strongly bind that control of the private key on a device to you. Not just possession, right? Not just the fact you have the phone, and therefore, can exercise a private key in the fashion we just talked about.
(Joel Beasley at 00:38:29) Yeah. I'm sure some of the people with all that Bitcoin wouldn't mind that too much.
(John Callahan at 00:38:32) I'm sorry?
(Joel Beasley at 00:38:33) I'm sure all the people with the Bitcoin wouldn't mind it too much.
(John Callahan at 00:38:36) Well, certainly, that's—you know, so Bitcoin is a marvelous type of—I often compare it to using the real, "Oh, Bitcoin is used by bad guys," and I said, well, so are the public roads. So don't blame the technology. It is a technology. How we use it is—
(Joel Beasley at 00:38:53) No, no. The bad guys aren't allowed on the roads. They just walk into the jail, and they just—
(John Callahan at 00:38:59) Last time I checked, police were still chasing people down the road or something.
(Joel Beasley at 00:39:03) Okay. You got me there. I guess they do exist in public.
(John Callahan at 00:39:07) So it's not the fault of the road, right? The road has uses, the same with Bitcoin. And, no, you're right. But the problem with Bitcoin and other cryptocurrencies is how do I control those private keys, and how do I manage them properly? People have panicked at the loss of—
(Joel Beasley at 00:39:26) Write them down.
(John Callahan at 00:39:27) Yeah. So this gets us to a good point. It comes down to public key cryptography enabled to secure the infrastructure. So I talked about end-to-end. It's reliant on good, strong cryptography. But binding the subject who controls the private keys, that is a challenge, and that's typically done through biometrics. Now what happens—
(Joel Beasley at 00:39:57) Your company solves, right?
(John Callahan at 00:39:58) That's what our company solves. And not just for Bitcoin and stuff like that, but I'm saying for just the control of the private keys for authentication and identity verification. But what if you lose those private keys? What if you lose them?
(Joel Beasley at 00:40:13) Yeah. You need some sort of process, restoration process.
(John Callahan at 00:40:17) Recovery, right? So recovery. So I recall a few months ago being at a conference and a guy from Google, his name is Grzegorz Czajkowski, got up. And Grzegorz is one of the people behind the new, you know, the Google strong authentication work.
(Joel Beasley at 00:40:35) And he's got a cool name.
(John Callahan at 00:40:36) Really cool name, and he's really smart. And Grzegorz said in this talk, since instituting strong second-factor authentication, we have not had a problem with phishing at Google. Not one. Zero. They, however, say, we encourage longer sessions, adaptive authentication, making sure it's you based on your usage patterns and so forth, just like I said a couple minutes ago about behavioral biometrics. But where there are still issues are what they call bootstrapping, like onboarding, and account recovery. Those are open to hacking. Those are the cracks in—how does this person who may have lost all their private keys, the slip of paper with the fancy words that you wrote down to recover, right? You just said, what if I lose all of those?
(Joel Beasley at 00:41:35) All I've got was wallet and then—
(John Callahan at 00:41:36) I lost my wallet. So a digital wallet or a real wallet?
(Joel Beasley at 00:41:41) No. I just said, like, when you were talking about writing everything down, I remember my dad's wallet used to be like three, four inches thick. I was like, you're going to get scoliosis sitting down on that wallet.
(John Callahan at 00:41:49) Oh, the Costanza wallet.
(Joel Beasley at 00:41:50) Yeah. Yeah. Yeah. The Costanza wallet. And he had like all his passwords in it and would write it down. And that was like the eighties.
(John Callahan at 00:41:56) God's sake. Yeah. No. This is crazy. So in the end, we have ourselves to present, right?
(Joel Beasley at 00:42:03) Yeah.
(John Callahan at 00:42:04) And even if we're incapacitated, you know, God forbid, we have ourselves—biometric recovery and the ability to use that to recover or reestablish key pairs. Typically, in things like self-sovereign identity, the way it's done is you obviously don't recover those private keys, but that key is revoked. So it's basically on a revocation list, and you're reissued. But the ability to revoke, I mean, that is authoritative in a sense. You've got to go zero out those keys, put them on a blacklist. Several blockchains have a way of doing this. But to do so is a very strong activity and can be bound to the biometric. So you can say, yes, we can prove, using fingerprint, face, voice, whatever biometric modalities to establish you had control of those, and we will revoke those and reestablish new private keys associated with it. That is the self-sovereign identity way of account recovery.
(Joel Beasley at 00:43:19) How do you handle identical twins?
(John Callahan at 00:43:23) So, interesting you should say that because, you know, all biometrics are not created equal. So here's my little biometric spiel.
(Joel Beasley at 00:43:35) Okay.
(John Callahan at 00:43:35) Again, I'm not a biometric scientist. I came to this—
(Joel Beasley at 00:43:38) We will hold you accountable at the level of a scientist, though.
(John Callahan at 00:43:42) Obviously. Yes. So not all biometrics are created equal. Face is actually one of the weaker biometrics.
(Joel Beasley at 00:43:52) Can you tell the difference in DNA between identical twins?
(John Callahan at 00:43:55) So on a scale, roughly, in my head, Joel, face is at about a 25% mark. Now with Face ID, what Apple has done is to put very fancy hardware, the dot sensor and so forth to give them more than just your face image. You get a 3D picture, so those are necessary because face is rather weak. Up the scale from there is fingerprint, which is probably about a 90% level. It really jumped from face up. So fingerprint, iris is slightly above that, and then DNA could be even further above that. The problem is that to do iris, and by the way, fingerprint, iris, and DNA—of those, I'm 100% sure, because I just read the other day, iris is different even across twins, across identical twins.
(Joel Beasley at 00:44:56) Okay.
(John Callahan at 00:44:57) Okay? The issue there is most of those, except fingerprint, require special hardware. And for the most part, you are not going to be able to equip all phones, at least probably in the next ten years, with special iris or, God forbid, DNA type of adapters. I don't even see that right now in the market. But our solution right now works even for two or three generation phones for fingerprint acquisition. We basically take a picture of your hand, and we extract the fingerprint in it. It works across Android and iOS devices, and it can extract up to 150 features per finger, which is highly distinctive across—if it's all eight fingers, it's a trillion people, which is way more than the current population of the planet, obviously. So if you get that level of distinction with eight fingers, you can reestablish with a large degree of confidence even in a population of identical twins.
(Joel Beasley at 00:46:05) That's interesting.
(John Callahan at 00:46:06) Yeah. But that's only in cases. You wouldn't, for example, require eight fingers for authentication purposes. That's inconvenient for things like account bootstrapping and recovery processes to get that degree of confidence to reissue keys or even revoke old keys on behalf of the user. They might not even be aware that keys are involved in the background, right?
(Joel Beasley at 00:46:28) Right.
(John Callahan at 00:46:28) We're talking techie to techie here. People shouldn't have to worry about that type of—and that's public key encryption that's had that problem of making it convenient, but hidden from users. And I think one of the last ways of getting that working is really biometrics because that enables people to use a convenient mode, but to get the confidence of the underlying cryptography foundation.
(Joel Beasley at 00:46:52) I like it.
(John Callahan at 00:46:53) Well, this is coming. This is why I joined the company as CTO because the time is right. I mean, this is happening now and very quickly. And as evidence, you don't even have to look at the biometric evidence, but the complexity of passwords, right? The baroque nature of rules and cycling. If I have to go through another—one of the things that annoys me lately is I put a password in that I think is really strong, even using a password generator, and it gets rejected because it doesn't have enough capitals or special characters. And I'm thinking, this is unbelievable. We've reached a breaking point. We have absolutely reached a breaking point. So what's next? And this is why I joined Veridium as CTO.
(Joel Beasley at 00:47:39) I love me some LastPass, though.
(John Callahan at 00:47:42) You know what? I see them as strong gap solutions for the meantime. We have a password world. We live in that password world. But I'll make a prediction here. I think in ten years or even less, you know, when I tell my children—my children, okay, they think I lived in a world when they see black and white movies. Oh, was the world black and white?
(Joel Beasley at 00:48:06) Oh, stop it. Have you heard me talk about that on the show?
(John Callahan at 00:48:09) No. I didn't.
(Joel Beasley at 00:48:10) Oh, yeah. When I was a kid, when I was a kid, I was like in elementary school, I asked my parents, I was like, when did the world get color? Here's the thing. Here's the argument to that, okay? Because I have some consciousness then. Here's the logic to it. By the way, if your kids are asking that, they're very bright because they're logical.
(John Callahan at 00:48:28) I can't argue with them.
(Joel Beasley at 00:48:30) Because here's why. Well, at least from—well, your kids. How old are your kids?
(John Callahan at 00:48:34) Well, now they're 11 and 14. They're teenagers.
(Joel Beasley at 00:48:37) All right. So I'm like 31, right? And, uh, or I'm coming up on 31. Oh, that's very soon. Uh, but now I'm thinking about age. Anyways, you got me thinking about how I'm getting older. When I was in school, there weren't really computers. Maybe a couple computers in third or fourth grade. We started to have them a lot. Uh, but all the pictures we would see of the past are in black and white.
(John Callahan at 00:49:06) Sure. Okay. Right?
(Joel Beasley at 00:49:07) So all the—well, that would be true. Yeah. Well, all the pictures we would see in the past are black and white. Because I guess, like, you know, color was relatively new in photography and things like that. So we'd go to school, and all day I'd look at pictures of the past as black and white. And I'm just like, we'd watch movies as black and white. We'd see pictures as black and white. And then all of a sudden, some of the newer stuff started to have color. And I'm like, when did we get—when did the world get color?
(John Callahan at 00:49:32) Yeah. So my point, though, is when I tell them now about dialing a phone or playing a record. Yeah. This is going to happen to you, definitely myself, of course, when you talk about typing in a password.
(Joel Beasley at 00:49:47) I know.
(John Callahan at 00:49:48) Okay? We are going to be—that will be anachronistic, um, to the point where they won't remember a world in which that happens. Right? It, um, so we are in a gap. Right? So technology like LastPass and so forth are a gap technology, and we need them, you know, to get from here to there.
(Joel Beasley at 00:50:09) Yeah.
(John Callahan at 00:50:09) Uh, but I think ultimately, long term, uh, convenience and increased security using biometric data where we are, uh, with the strong foundation of cryptography is going to be the—that next, uh, hurdle, and we're on the cusp of it right now. So—
(Joel Beasley at 00:50:26) My thumbs will be stronger than my kids. They'll be so used to—I've typed, like, my whole life, and they'll have, like, Alexa doing stuff.
(John Callahan at 00:50:32) Voice? Go back to your Alexa. You don't have to type. Come on. I have a friend now. He literally, uh, I couldn't believe it. He uses transcription all the time.
(Joel Beasley at 00:50:42) Yeah. Well, you know what's big in China? And when it's becoming big here, I'll share my phone right here. You see this? Uh, this little thing in the bottom corner. There's a microphone next to my text message.
(John Callahan at 00:50:53) Sure. Yep. Mhmm.
(Joel Beasley at 00:50:53) And I can just be like, "Hey, boo. I love you. Bring us office cookies soon."
(John Callahan at 00:50:59) There you go.
(Joel Beasley at 00:50:59) And then boom, that's it.
(John Callahan at 00:51:01) So if you brag about your strong fingers, that's going to be like me and my Xerox stories.
(Joel Beasley at 00:51:05) I know.
(John Callahan at 00:51:05) They're going to seem old.
(Joel Beasley at 00:51:07) I know. I love it. This is a fantastic conversation. I learned so much about security. You're right on the tip of the future, man.
(John Callahan at 00:51:17) Thank you very much. So, hey, I wish—now it's wonderful to be alive now. It's such an exciting future, so stay in there and stay broad.
(Joel Beasley at 00:51:26) Yeah. We're going to make it into the computers, though. I think we'll end up going into the computers. I'll just go here in a second. Look. Think about it. If you look at the—if you stand back like an alien, right, just pretend you just—you just come across Earth and you just, oh, you hit play on the past 25. All we've done, it looks like technology is God. We built it. We worked for it. We grow it. We improve it. It takes over the world, and we constantly are making it smaller and putting it into our bodies closer and closer every day. Well, like, you think that is just going to stop? There's this thing called momentum. That's not going to stop. We're going to completely become ingrained and become one with the computer, and then eventually have the option to, like, go in it or, like, for example, like teleportation. Right? Like, I totally see us being able to just teleport our consciousness. Like, why not? Put it into the computer, put it into a body. Like, why is that not possible?
(John Callahan at 00:52:21) Or have you read Greg Egan? So the science fiction writer Greg Egan. Uh, one of his, uh, best books is, um, I'm trying to remember the title. It's been so long since I read it. Anyway, it'll come to me in a moment, but Greg Egan talks about this.
(Joel Beasley at 00:52:35) We're already teleporting stuff.
(John Callahan at 00:52:38) Yeah. That's, um, and that goes back to my NASA days. Uh, one of the things—you know, NASA's done fantastic things. It was a privilege working on projects there. One of the projects I worked on was Cassini, the Cassini, uh, Saturn mission. Okay? A very sliver of that. Uh, but the amount of science produced for the amount of money in those remote missions is incredible. And, of course, that was done through telepresence. Right? We wouldn't have been able to, uh, do that without, uh, computer technology and robotics at a distance. And, uh, the amount of money we had to spend to get that amount of science, you know, is just a tremendous value in my opinion. So—
(Joel Beasley at 00:53:17) Like tech transfer. Did you hear our, um, episode with Douglas Terrier, the CTO of NASA?
(John Callahan at 00:53:22) No. I'm sorry.
(Joel Beasley at 00:53:23) I don't—
(John Callahan at 00:53:24) I don't know him. Yeah. Okay. I'll have to, uh, get back on that.
(Joel Beasley at 00:53:27) We talk about—we talk about the concept of tech transfer, how technology is innovated by government. Like, for example, we got power tools from the space stations and stuff and yeah. How technology transfers from the private to public or from the, yeah, government to public sector.
(John Callahan at 00:53:46) Sure. I remember witnessing this, uh, with the Internet itself. And I can say I didn't invent it, but I was there when it happened. I did have an ARPANET account.
(Joel Beasley at 00:53:54) So did you?
(John Callahan at 00:53:55) Oh, yeah.
(Joel Beasley at 00:53:56) Who's that famous politician that, like, takes credit for the Internet all the time?
(John Callahan at 00:53:59) Oh, Al Gore.
(Joel Beasley at 00:54:00) Al Gore. You were in the room with Al Gore. You didn't create it yourself. You were in the room.
(John Callahan at 00:54:04) Uh, I—
(John Callahan at 00:54:05) I wasn't even up that high up the ladder. I was just a graduate student, early graduate student at that point.
(Joel Beasley at 00:54:11) So okay, John. As we wrap up, what is some advice you would give yourself if you could teleport back 10 years?
(John Callahan at 00:54:22) Uh, take that offer of employee number 13 at Adobe and instead of going to graduate school. No. Seriously, that happened to me. I say, okay, your girlfriend will wait and you can go back for your graduate degree. No. No regrets there. Um, uh, besides the obvious things, uh, in hindsight, I'm not sure I would say do anything. I would just say have confidence, stay in it, uh, learn lots of things. Um, as a technical person, I think communicate more. I think one of the things I like about the role I'm doing now is I do get to evangelize, uh, talk with people like you. Uh, you know, tech people, we'd—we love to come in, hack for hours and hours, and go home. That's how we recharge. And, um, but I think it would be communicate more, and that's what I would say. So jump into open source projects even more. Right? Contribute, uh, regardless of what level of skill you have. There's always need for QA and documentation type of things or testers on even mainline projects, you know, on GitHub or something. I would say, you know, jump in, uh, more on those type of efforts. So, and that's to a technologist. To people who are nontechnical, um, similar advice. Just jump into these things, right, and engage yourself. Uh, don't be afraid. Yes. There will be trolls that will, "Why did you do that?" And, uh, "You did that pull request wrong," blah, blah, blah. Trust me. There's more good people that are patient that will help you than there are those trolls trying to shoot you down out there on GitHub and other, uh, open source projects. So—
(Joel Beasley at 00:56:03) That's some good advice too. I've actually told some of the new programmers, like, be careful on Stack Overflow. Like, that's not—that's not an accurate representation of everything. Sometimes people are really mean on Stack.
(John Callahan at 00:56:14) Uh, yeah. That's just inappropriate. We need to be welcoming. We need to reach out to, uh, on such projects and really be very, very open to all types of people on those projects.
(Joel Beasley at 00:56:26) Nice. So almost 13th employee at Adobe. Close to Eric, right?
(John Callahan at 00:56:33) No. No. No. No. I don't know. I mean, I've talked to him once—
(Joel Beasley at 00:56:36) Close to his office. You were close—
(John Callahan at 00:56:38) So—
(Joel Beasley at 00:56:38) You walked by his office. Right? All of these—this I think this is your time to shine, man. I think, John, I think this opportunity that you're in right now with the biometrics, I think it's the right time. I think you're going to end up as, like, you know, 20,000 employees right at the company. And I hope you'll still, uh, still come on the show and answer my emails.
(John Callahan at 00:57:00) It'd be a pleasure, Joel. Thank you. No. Um, um, I hope we grow. I think the time is right, uh, and but we'll always work hard to keep those biometrics private and keep authentication and identity strong. So—
(Joel Beasley at 00:57:13) Fantastic. If you need anything from me, anytime, you just reach out. I'm always available.
(John Callahan at 00:57:17) Thanks to you and your team, Joel.
(Joel Beasley at 00:57:19) Thank you. Anytime. Bye.
(John Callahan at 00:57:20) All right. Bye-bye.
(Joel Beasley at 00:57:28) Thank you so much for listening. If you'd like to help, please take a moment right now to open up the iTunes app and leave a review of the podcast. If you take a screenshot of the review and text it or email it to a friend who needs to listen to the podcast and then CC me, [email protected]. If you CC me on the email, I'll send you a copy of the Modern CTO book or give you a shout-out on the podcast, whichever you prefer. We're trying to get listed on the top 100 for iTunes, and I need your help in order to do this.