Episode 227 ·

Mike Wilkes - CISO at SecurityScorecard

Today we are talking to Mike the CISO at SecurityScorecard. And we discuss the future of security, why all hands on deck can be a liability if you don’t have discipline, and how the key to getting started with security is to put in place a great foundation that can scale.

All of this, right here, right now, on the Modern CTO Podcast!

About Mike:

Mike Wilkes is the Chief Information Security Officer (CISO) at SecurityScorecard. Wilkes is responsible for developing enterprise-wide security programs to protect corporate systems as well as growing and extending the SecurityScorecard platform to customers, executives, and boards of directors.

Wilkes is a technology evangelist with experience reaching back to the earliest days of the internet and the birth of ecommerce (he and his team built, launched, and supported starbucks.com in 1998), Mike has been leading the digital transformation of globally renowned brands such as Sony Playstation, Macy’s, nVidia, KLM, and many others. Before joining SecurityScorecard, he was the VP, Information Security at ASCAP and the Director of Information Security, Enterprise Architecture, and DevOps teams for Marvel Entertainment.

Mike has held leadership roles in financial services with hedge fund AQR Capital as Vice President in the Information Technology Group and prior to that as Manager of the Enterprise Server Platform for the CME Group. Earlier roles performed while living abroad in Europe saw him designing and hardening critical energy sector infrastructure for Nuon and RWE, authoring Rabobank’s first global trading technology vision document, creating the world’s first bank MVNO (Mobile Virtual Network Operator) as well as delivering a security audit of the euro printing facilities for Royal Johan Enschedé (founded in Haarlem, Netherlands in 1703) to renew their accreditation with the European Central Bank.

Mike received his Bachelor’s degree from the University of Wisconsin Madison and a Master’s degree from Stanford University. He is the author of Cisco Internet Applications and Solutions (Cisco Press, 2002) and joined NYU as an Adjunct Professor Teaching infosec to graduate students for the Computer Science and Engineering department.

About SecurityScorecard:

SecurityScorecard is the global leader in cybersecurity ratings and the only service with over a million companies continuously rated. SecurityScorecard’s patented rating technology is used by over 1,000 organizations for self-monitoring, third-party risk management, board reporting, and cyber insurance underwriting; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their externally facing digital footprint. SecurityScorecard is the only provider of instant risk ratings that automatically map to vendor cybersecurity questionnaire responses - providing a true 360 degree view of risk.

Transcript

(Joel Beasley at 00:00:00) Hello, my friends. Today we are talking to Mike, the CISO at SecurityScorecard. And we discussed the future of security, why all hands on deck can be a liability if you don't have enough discipline, and how the key to getting started with security is putting a solid foundation in place that can scale. All of this right here, right now on the Modern CTO Podcast. This is the Modern CTO Podcast.

(Joel Beasley at 00:00:36) Hello, Mike.

(Mike at 00:00:38) Hello. Good afternoon.

(Joel Beasley at 00:00:40) It's Mike. This is exciting. We're gonna have a good time. Are you excited?

(Mike at 00:00:44) Yeah, I'm looking forward to talking with you.

(Joel Beasley at 00:00:46) You know, when we were doing our podcast prep meeting, it came up that you used to work at Marvel, and then the entire team just went incredibly geek. And I said, guys, we've gotta cover—we can't just go 100 miles deep on Marvel. We've gotta cover everything with Mike.

(Mike at 00:01:02) Sure. Yeah. No, that's definitely something that people like to hear stories about.

(Joel Beasley at 00:01:07) Oh, man. So how did you—I guess we could start there too. Or how did you get involved with SecurityScorecard?

(Mike at 00:01:14) Well, I've been following SecurityScorecard since around 2015 when I first heard about the company and its product. And I've purchased the solution a couple of times because I think it's got a really great value add in terms of vendor security and third party risk. And how did I first hear about it? I think the offices were on 15th Street. They hadn't moved back then.

(Mike at 00:01:40) And, you know, I try to stay abreast of new technology. And anything that lets me walk up to a portal, type in a domain name, and then suddenly get 12 months of security history and posture and patching cadence is fascinating. Finding out about breaches, looking at compromised credentials—it just, you know, it's doing the work for me and finding out whether or not I wanna work with vendor A or vendor B based on these ratings.

(Joel Beasley at 00:02:10) Come on now. So wait, if I put in our podcast domain name, like moderncto.io, will stuff come up?

(Mike at 00:02:17) Yep.

(Joel Beasley at 00:02:18) Wow. That's gonna be fun. We should have done that before the episode.

(Mike at 00:02:23) Yeah, I'd be happy to show you your findings. This is using only publicly available open source intelligence. So for example—

(Joel Beasley at 00:02:30) How long does it take?

(Mike at 00:02:31) Well, if the domain's been tracked or requested by someone else, then it's already there. Otherwise, it takes maybe three business days to start to build information and intel. And it'll look through the headers on your website and figure out if you're running a vulnerable version of WordPress or other types of tools and services that are exposed. And we have partnerships that help us find information from the dark web to see if your users were a part of any breaches, because it's not their fault. But the fact that their credential might have been compromised is useful information for you to have in terms of business email compromise, credential stuffing, things like that.

(Joel Beasley at 00:03:09) Yeah, I noticed about two years ago I started getting—just in my life, whether it was Google—they were doing it where I would get this thing that says, you know, your password that you're using to enter right now was actually detected in a previous data breach. You should change your password.

(Mike at 00:03:27) Mhmm.

(Joel Beasley at 00:03:28) And then I got it from that, I got it from LastPass. And then I was like, there's gotta be some companies out there that are serving up all of this information because it seems to be pretty easy to integrate into your software. So do you guys do that at all? Is that a reason why companies use you?

(Mike at 00:03:45) No. I think a lot of the reasons people use us are the primary 10 factors that we're able to measure about you. We've only recently added the feature of looking at credential risk through a partnership because, you know, spending the days and nights downloading those dark web breach datasets is a specialization that we don't necessarily need to duplicate. Right? I actually think it was some alumni from SecurityScorecard that started Hack Notice, and so they're in the business of making that information available.

(Mike at 00:04:17) But it's not your fault, right, that your gym was lax with their security. But it is your fault if you use the same password for your business as well as for that gym login.

(Joel Beasley at 00:04:29) So companies will actually use Security—because I had in my head that it was more of a—I could go to SecurityScorecard, get something on me, and then have an evaluation that way. So it sounds like you can do that, but also you can use it to put in other people's information and see what their security scorecard is.

(Mike at 00:04:48) Correct. Because, you know, the weakest link in a chain is the one that will break. And, you know, you're familiar maybe with the point of sale compromise that Target had where someone bought a $2,000 piece of malware on the dark web, attacked the heating, ventilation, and air conditioning—the HVAC vendor. And it was a bad architecture designed to have that on the same network as your ecommerce platform.

(Mike at 00:05:12) But they were able to inject this malware onto the point of sale, collect—what, something on the order of 30 million credit cards and debit card numbers—the PIN codes to which 10% are all 1, 2, 3, 4, unfortunately. So you immediately had, you know, 3 million credit cards and PIN and debit cards that you could use for a $2,000 investment. And you wanna look at the security posture of your vendor portfolio because oftentimes they have integrations or they send emails that, you know, have been deemed to be, based on behavioral analytics, trusted. And so these are the attack surface that you have to worry about. When I was at Marvel, my biggest attack surface was Disney because, you know, Disney bought Marvel in 2009.

(Mike at 00:05:56) We had a really great security program that I had built, and everyone was really well trained to not click on spear phishing and phishing emails. But, you know, who isn't gonna click on an email from Bob Iger saying click here? Right? And so a 180,000 employees in Disney—maybe after the furlough, you know, maybe 80,000 employees. But the attack surface there was way larger because Marvel was only about, you know, 500, 600 people.

(Joel Beasley at 00:06:23) Click here to get your paycheck or your raise. Right?

(Mike at 00:06:25) Or even just to look at the quarterly earnings call. Right?

(Joel Beasley at 00:06:30) Oh, yeah. That's interesting. Being sneaky with something that you would expect to receive probably has way better conversion rates.

(Mike at 00:06:38) Yeah. Yeah. And so we did phishing awareness training to train people not to click on Bob Iger's emails.

(Joel Beasley at 00:06:45) Oh, so how did you even get into security? Obviously, the CISO—and was that—am I saying it right, by the way? Do they call it CISO, or is it CISO?

(Mike at 00:06:55) I particularly use CISO, but other people say CISO or CISO. So, you know, it's kind of like GIF and GIF. Right? There's a religious war on the topic.

(Joel Beasley at 00:07:07) We don't cover that here on the podcast. It's like religion, politics, and violence.

(Mike at 00:07:13) Pronunciation of three letter extensions. Yeah.

(Joel Beasley at 00:07:17) I love it. So at what point were you like, I wanna get into security, or have you always been in security since day one?

(Mike at 00:07:24) That's an interesting way of, you know, trying to tell the story. I started out actually in California working in the Department of Education on the internet, working for a think tank, the Southwestern Lab for the U.S. Department of Ed. And I was responsible in my first real job out of college for California, Arizona, Nevada, and Utah K through 12 public education—distance learning, model technology programs, educational technology grants. And after about a year of working at the federal level and state level, I realized there's nothing I could do to make education better. I studied philosophy in college, and I have a master's in philosophy of education from Stanford.

(Mike at 00:08:04) But this indentured servitude wasn't gonna last. Right? There were more computers in the dumpsters of California than in classrooms. Right? It's the heart of Silicon Valley, but the education system has been really slow to pick it up. It's like a dinosaur. And so I left that and started working. You know, my hobby became my career. I've been a computer abuser, as I say, for many years. If you don't know three ways of abusing a tool, you don't know how to use it.

(Mike at 00:08:29) And so, think of Matthew Broderick, Hackers, you know, that was the kind of—bulletin board systems, dial-up modems back in my day. And so from there, really, it just followed that I started analyzing websites for a company called Internet Profiles. I audited Yahoo's traffic back when it was only getting 20 million hits a day, and I ran the data management platform for that company. And then I moved to the content side and started building websites at a web design house called Organic in San Francisco. And this was during the dotcom rise. Right? The roaring twenties for my generation. And we, you know, I built what—Starbucks' first website in 1998, launched the playstation.com for the PS2. Macy's, their first ecommerce website.

(Joel Beasley at 00:09:13) And these are all projects that you've done?

(Mike at 00:09:16) Correct. That was the head of the—what we got called DevOps last time. Yeah.

(Joel Beasley at 00:09:20) That's awesome. Wait, let's go through them again real quick. List them off again?

(Mike at 00:09:23) Alright. So Starbucks 1998.

(Joel Beasley at 00:09:25) Boom.

(Mike at 00:09:26) PlayStation PS2 launch for the PS2 2000.

(Joel Beasley at 00:09:31) Was that online yet? Was PS2 online yet? Did that—yeah.

(Mike at 00:09:35) Yeah. They had the PlayStation Store. Yeah. And they had group gaming with the PS2. There's a little known or at least now defunct entity called blockbuster.com, which we built and launched at Organic. And many other, you know, large properties, brands that you would know of, you know, Washington Mutual Mortgage, other things like that.

(Joel Beasley at 00:09:55) So you got to build and launch the website for Blockbuster?

(Mike at 00:09:58) Yep. And it was funny, though. I tell the story from a security—to answer your original question, how do I get into security—they weren't really security officers and CISOs back in the day, right, during that whole heady days of dotcom and South of Market. And so I had to pay attention to security only because, you know, I was on the other end of a pager if the thing went down or if it got attacked. And so I actually put a—you know, Microsoft donated the hardware to Starbucks saying, you know, you can run your website on Windows. And, of course, that would be their bragging rights.

(Mike at 00:10:29) But I didn't want to go to sleep at night knowing it was running on Windows IIS version 3 or something. Right? It was just not very stable back then. So I actually put a reverse proxy on a Solaris box with an Apache web server in front of it, recompiled the headers to identify as IIS, and then did a bunch of proxying and caching on the front end so that the actual Windows servers didn't fall over and didn't have a lot of work to do.

(Mike at 00:10:54) And it was funny. This would be called deception now and, you know, because you're putting a different piece of hardware in front and you're kind of telling people that it's a different operating system and different web application server. And this has special guidance now for you to have a whole deception program to your platform of proactive security. But anyway, so I was doing it out of, you know, sort of pragmatism at the time. And so I've always had to pay attention to security and to understand how to harden a website and protect it and, you know, expose only the essential services and log and monitor them for suspicious activity.

(Mike at 00:11:30) But I haven't really been doing InfoSec unless, you know, putting the title in my name, I guess, for the last five or six years. So I have a good 25 years before that of building platforms, building banks for Rabobank when I lived in Amsterdam, putting com.com behind Akamai. What else? What are some of the other fun things? And, of course, Marvel. That was a great two years where I like to joke it was my job to keep Iron Man safe.

(Joel Beasley at 00:11:59) Oh, that's right. I was thinking that there's a nerd joke in there somewhere for like, why do you need security at Marvel? Because they have all the superheroes.

(Mike at 00:12:07) Yeah. And, of course, if you know what happened in Endgame, you know what happened to Iron Man after I left. So—

(Joel Beasley at 00:12:15) Robert Downey Jr. just cried after you left.

(Mike at 00:12:18) Yeah. But, and, of course, Stan Lee passed away under my watch, and so we had to be prepared for that moment and the amount of traffic and condolences. And it was called Project Excelsior, of course. And, you know, it was very cool to be the head of InfoSec, DevOps, and architecture. I had all three titles there. I was actually three fourths of all signatures you needed to get a change released into production at the time. So—

(Joel Beasley at 00:12:44) That's awesome. That is so—I'm fascinated. I like when I meet people like you that have gotten to do some really interesting projects and then I'm always interested in the company. And I actually—this interview was originally scheduled with Sam.

(Mike at 00:13:00) Mhmm.

(Joel Beasley at 00:13:00) And so we did all of our research and process on Sam. And then yesterday, we switched it to you. So we did, you know, emergency prep meeting yesterday afternoon and this morning to understand you and your background. But, you know, Sam was a fascinating person. Right? And then you're a fascinating person. Are you sure?

(Mike at 00:13:18) Yeah. Get him on the show. Yeah.

(Joel Beasley at 00:13:21) But I always—I give a good example like Zoom. So Harry and then Eric. And when I get to meet or talk and learn about the different executives that are all in the team and they have similar mindsets and they're driven people and they're really interesting and they think about all sorts of things from human performance to their technical abilities and skill sets. When I see those types of groups, I do two things. First of all, I make notes about what they do and I invite them on the show as much as possible. And the second thing is I try to mimic some of their behaviors that I see. Right? And, of course, buy their stocks when they're publicly traded. Are you publicly traded?

(Mike at 00:14:00) No. We haven't gone public yet.

(Joel Beasley at 00:14:03) Okay. Yeah. So when you do that, I'll make sure to buy some of the stock. Because I think that these companies that are founder-led and have really great executive teams—I think that they do the best overall long term as long as that energy is still there.

(Mike at 00:14:19) Yeah. I think that there's always that talk about people, process, and tools, and a lot of pre-breach CISOs focus on tools. But post-breach CISOs, of which I am one because there have been breaches in companies that I've worked in—the Chicago Mercantile Exchange as an example of one of them. I wasn't the CISO there at the time, but I was enterprise server platform manager. And in the post-breach perspective, you focus more on people and process because all hands on deck is a real liability if you don't have some discipline.

(Mike at 00:14:52) Right? Because people can be going in and trying to fix the problem, and they could actually be, you know, destroying forensic evidence. Right? Trying to delete files that have showed up from bad guys, or, you know, helping the bad guys move laterally within the platform just by being on the server and logging into it, you know, if it's been compromised. So, yeah, there's definitely a different perspective, I think, like I said, between pre-breach and post-breach.

(Mike at 00:15:17) And good leadership, you know, good teams, good corporate culture, good security DNA, you know, these are the core values of SecurityScorecard. So I'm really excited to have joined the organization and to bring my perspective and help it evolve to its next level of maturity.

(Joel Beasley at 00:15:33) Yeah. I haven't been a part of a company yet that, like, the post-breach world. I mean, I've been a part of, you know, post your application goes down world.

(Mike at 00:15:43) Post crash and burn?

(Joel Beasley at 00:15:44) Post crash. Yeah. And doing the post-mortems. But, like, it's such a stressful time when you when you go through that. And I was actually listening to this, like, neuroscientist this morning and he was talking about the connection between stress and neuroplasticity.

(Joel Beasley at 00:16:01) And as you were just describing, you know, they could be deleting things or helping, you know, hackers move laterally within the organization. That sounds like, if I were an attacker creating chaos within the host I'm trying to attack and their personnel just going crazy trying to figure out what's going on, that sounds like it opens up a thousand doors for you to be able to move around because people are going to be reacting quicker and, like, not thinking long term. It's just going to be a frantic. And that would be an opportunity for the attacker to, like you said, move laterally.

(Joel Beasley at 00:16:35) I never thought about that before.

(Mike at 00:16:37) Sure. Take the Twitter ransom or Bitcoin scam that happened recently. That was a distraction from the actual attack, right? The actual attack was to actual trade data.

(Mike at 00:16:47) But they, you know, got $270,000 worth of Bitcoin out of it, you know, as a side distraction. Right? Just like Ocean's 11 movies or whatever. Right? There's always this second narrative, this second heist that's going on.

(Mike at 00:17:00) So you have to be very careful about that. The bad guys are playing multiple pieces on the chessboard at the same time. And, you know, if you don't reserve your judgment and — I think it's the amygdala, right? The lizard brain.

(Mike at 00:17:14) Your higher order thinking skills go away when you're in a fight or flight situation. So the amygdala hijacks your ability to think rationally. If you've been staying up for 24 hours, 48 hours, you know, on an incident doing an investigation, you start to lose your ability to make good judgment. And so that's why incident response plans have to include swapping people out and giving people time down to sleep, eat, you know, rest, and recover and get back into it.

(Joel Beasley at 00:17:40) So for you as a person, like, how do you rest and recover? Like, in general, not just from a breach.

(Mike at 00:17:46) Sure. One of the things that I like to do is to play music. I'm a musician. At ASCAP, I was a member of the organization as well as the CISO. And if you're not familiar with ASCAP, you know, the American Society of Composers, Authors, and Publishers, it was really great for me to put together a house band when I was there, actually, and to play drums.

(Mike at 00:18:05) I played jazz. And so for me, it's, you know, improvisation. It's communication. It's not, you know, although there are other forms of music that are equally, you know, rewarding for cleaning out your brain and detoxing, you know, kind of chemicals. Just, you know, the act of singing has resonant frequencies that help purge your brain of toxins as well.

(Mike at 00:18:26) But I just think that the idea of, you know, playing music, being creative, and, composing and, you know, being artistic and creative is a great release for some of the stresses of computers and the damn people that abuse them. Yeah.

(Joel Beasley at 00:18:41) I fully agree. I'm a musician as well. And, yeah. That, what I've noticed is that when I get into that state of — I guess most people call it flow — when you're just, like, in the groove. Yeah. Like, those moments are, it's a beautiful thing because it's like a place I can go.

(Joel Beasley at 00:19:01) And I remind myself, you know, like, when I'm stressed out or, like, don't feel like doing something or when I'm just having a bad day, having that skill and then being able to go over there, it can completely just adjust my mood. It's like, all right, let's go do something that I love for 15 minutes. I can go play a couple songs and just completely turn around my day. So, I mean, I love it. I've been playing guitar for about seven years.

(Joel Beasley at 00:19:29) I've been playing piano for about a year, and I really liked switching to piano because it just gave me a better understanding of music as a whole. But then I also did two years of drums, and that really helped with my understanding of rhythm.

(Mike at 00:19:45) Rhythm. Yeah.

(Joel Beasley at 00:19:46) Yep.

(Mike at 00:19:47) For me, it was difficult to move away from, you know, polyphonic, you know, percussion because I didn't have to worry about how long I sustained a note for, really. I just had to hit the note. I mean, okay, maybe I have to grab the cymbal to stop it, you know, ringing at the end of, you know, a lick or a turnaround or something.

(Mike at 00:20:03) But the first time I actually tried to sing and play drums was mind-blowing. It was just, like, so difficult. I have so much respect for people that, you know, like Phil Collins or others, you know, that can play drums and sing at the same time because, you know, it's just such a coordination of talent and, you know, independence of, you know, limbs and arms and fingers.

(Joel Beasley at 00:20:24) Yeah. It's like they get it so down that they're not even thinking about it. And so they can do the second act, which is singing. Every time I see the microphone, like, the first time I saw a microphone over the drums, I was like, I guess they just do that so he doesn't feel left out.

(Joel Beasley at 00:20:43) But then I've seen some people that, like, legitimately sing and they're drummers and I'm just like, whoa, that's a lot of things happening. They just must have those, you know, eight, ten songs that they're doing for the set down so hard in their muscle memory that they can do these two things at once. It's unbelievable.

(Mike at 00:21:01) Yeah. And the, you know, drum kit becomes an extension of your voice. And in this case, not necessarily your vocal cords, but you as a composing player and an improviser. You know, you just think a thing and you do it. It's not like you're reading sheet music necessarily.

(Mike at 00:21:16) You know, because the old joke is, how do you stop a drummer from playing? You put sheet music in front of him, right?

(Joel Beasley at 00:21:23) So this act of music throughout your life and this artistic component with everything from, you know, even being a part of deciding to spend your time at Marvel to ASCAP, to just, you know, being a musician. How has there been, like, any benefits professionally? Like, what is your takeaways? Would you recommend people with a passion in music to pursue it?

(Mike at 00:21:49) Yeah. I mean, I've met a lot of people in InfoSec that have a music background, you know, that play and play regularly. And I think it was the New York City meetup, InfoSec meetup, that I was interviewed on, and that was a theme that had come up from David Raviv's discussions with CISOs and different people, you know, in the industry, that a lot of them have had a musical background. And I think that it ties in a little bit maybe to mathematics and computers and logic, in that, you know, Gödel, Escher, Bach talked about, you know, the connections between, you know, art and math and how we have this part of our brain, essentially, that develops when you learn music, and especially at a younger age. And it just helps you.

(Mike at 00:22:41) I mean, there was, you know, Music of the Spheres, I think, is one of those connections that talks about how, you know, there's a lot of intervals and math involved in, you know, the scales and chords and, obviously, musical signatures. Music of the Spheres, I think that's a book. Yeah. I'd have to remember the author that talks about the overlap between math and music.

(Joel Beasley at 00:23:04) That'd be a good — it'd be even better if it was, like, a documentary or a video. That Music of the Spheres. I think that's interesting, connecting music back to math and intervals. I would actually be pretty interested in consuming that information.

(Mike at 00:23:19) Yeah. Well, if you want, I can send you a link and we can maybe add it to the notes.

(Joel Beasley at 00:23:24) Yeah. And then we'll talk about it next time, right?

(Mike at 00:23:26) Sure.

(Joel Beasley at 00:23:27) Okay. Yeah. So, all right. Let's bring some value to some of the CTOs, right?

(Joel Beasley at 00:23:32) So, like, cybersecurity for CTOs. What should — let's say, let's give some more context. Let's say CTO at a company, 50 to 200 people, right? Around there. I think that's often called, like, the SMB space or the early part of the SMB space.

(Joel Beasley at 00:23:50) Maybe they don't have a CSO yet. What should that CTO be thinking about as far as, like, threats or strategy?

(Mike at 00:23:59) Sure. Well, I think that even if you have a small company, you want to lay a good foundation for the time when you're larger, right, and you have, potentially, more people, you know, doing security as their full-time task. And so it's important to understand that, you know, there's basically three things that InfoSec is concerned with, right? Availability, integrity, and confidentiality of data.

(Mike at 00:24:25) And so if you set up a good, you know, foundation for that, meaning, you know, you don't give permissions to people. You give permissions to a role and you add people to that role. It's called role-based access controls, RBAC. So even in a small company, it still makes sense. It feels like a little bit of overhead, you know, to create, like, a DevOps role and then add your DevOps user even if there's just one.

(Mike at 00:24:48) But eventually, there will be more. And you don't want to have these snowflake permission sets that, oh, you know, the first Promethean DevOps user had all of this permission. They had root. They had the admin on everything. And then you hire a junior, and you don't want to give them all that power.

(Mike at 00:25:03) And so you want to give them, you know, what's called least privilege. You want to give them just enough to do their job and no more. And so that's how you grow a very secure base within your company and within your permissions. Because otherwise, you try to retrofit it in later when you get bigger and maybe you have to pass a compliance audit or you have a pen test that reveals that there's, you know, some overly provisioned users on your network, right?

(Mike at 00:25:26) Everyone's either a sysadmin or they have no access at all. That's the typical pathology that I find, is that people are all in on letting everyone do everything in the name of DevOps and saying, you know, empower the users, you know, to make and do things. But if they don't have the sense of responsibility of thinking about security, they may only be thinking about the feature that they're trying to deploy. And they may not, you know, store session states, you know, in a safe way. And, you know, your startup can be disrupted by a security incident quite easily if you don't have that embedded in the, you know, like I said, the DNA and the foundation of your company.

(Mike at 00:26:03) You certainly need to do some security awareness training, teach people, you know, how to do, you know, best practices for coding, OWASP Top 10. There's basic CIS controls that are considered best practices that all companies should be adhering to. And if you embed security in the development and software development life cycle, then you don't have to worry about it becoming this, you know, roadblock on the way to release in the future, when you are more mature and you do have, you know, potential investors and auditors looking at your due diligence on whether you just cowboy the code right into production or if you have a bit of a process wrapped around it.

(Joel Beasley at 00:26:42) Yeah. I just went through, like, a Fortune — we got, like, a top 50 company as a client. And I went through the unbelievably long security review process. I had heard people talk about it before. We had only had, like, SMB-type customers and we filled out a small questionnaire and it was a relatively easy process.

(Joel Beasley at 00:27:06) And then going through it with one of the biggest companies on the planet, it was just unbelievable. I mean, it took, like, from the time we started to the time we finished was probably like three or four months, but the sales cycle was nine months long.

(Mike at 00:27:21) Yeah. No. I don't doubt that. And it's a burden that a lot more companies are facing these days. And as you move your workloads to the cloud or as you start running on multiple cloud platforms, because you want to take advantage of certain strengths that Azure might have or Google or Amazon, you have this burden of filling out these vendor security assessment questionnaires.

(Mike at 00:27:41) And you don't want to have to fill them out, you know, and spend three months every time you get one. So we have a product that we've launched called Atlas, which helps companies do this. And so it categorizes your responses, and it uses, you know, machine learning to help you answer all the variance of these survey questions that you might get and help you, you know, speed that process up.

(Joel Beasley at 00:28:04) That sounds very useful. I wish I would have heard that before because what I think the longest process or the thing that made it take the longest was debating the relevance of even certain questions.

(Mike at 00:28:18) Mm-hmm.

(Joel Beasley at 00:28:18) Because I was like, this doesn't make sense in the context of the type of product and service we're delivering to you.

(Mike at 00:28:27) I guess one of those questions was, do you encrypt your offsite tape backups?

(Joel Beasley at 00:28:31) Yeah. That's exactly it.

(Mike at 00:28:33) It's like we don't have offsite tape backups. I'm sorry.

(Joel Beasley at 00:28:36) I know. It's hard to go through those too, because it's just, it's a difficult thing. So Atlas is something that — is it, like, a tool that I go in and tell Atlas everything and it helps me answer future ones? Or does it know the questionnaires of, like, companies that have it, like, stored?

(Mike at 00:28:54) Correct. It's starting to standardize these things. Like, SIG has these t-shirt sizes of, you know, how many questions you answer. And so we're helping people with that burden and ingest it into any system of record they may have. Because you might have a governance risk and compliance tool if you're a large enough organization. You may even have, you know, governance officers, right, and compliance officers, that aren't even related necessarily to the InfoSec team.

(Mike at 00:29:17) So this helps the whole spectrum of whether it's a mature organization, like NYU, for example. I started teaching cybersecurity this spring to the next generation. I want to share my stories and my experience and my philosophy with them to help make, you know, grow the next generation of InfoSec professionals. And NYU has, you know, a really large, you know, student body, and it's tons and tons of IP address space and lots of risk because you have, you know, academics that are doing research in AI, but they don't know necessarily how to lock down, you know, all of that intellectual property. And so I was using, you know, the course to talk about very pragmatic things, not, like, the Acme Widget Company, you know, and a kind of textbook approach to security.

(Mike at 00:30:01) And so I was teaching a class and I had 102 students this summer in my summer course, all of whom were InfoSec professionals, CTOs and CSOs for banks and for startups all over the world because it was a virtual class, right? And it was just fascinating to, you know, see that, you know, there's a real need, you know, to be disciplined, but not to overload your work with too much process and too much overhead. And so even just answering those vendor security assessment questionnaires, if you can automate that and you can make it repeatable and, you know, trusted, then, you know, that's a real burden that pragmatically saves time. And it technically reduces risk, right, because you're answering the questions, you know, more completely.

(Mike at 00:30:45) A lot of people hand those questionnaires to like a summer intern and ask them to fill it out, and they don't know half the answers. And a lot of the questions are outdated, you know, and not modern, you know, CISO 2.0 kind of questions about, you know, ephemeral infrastructure on an elastic cluster, you know, auto-scaling in the cloud. You know, how do you scan and retain the data from these little Junebug VMs that come and live for a day and then disappear the next day, right, when you don't need them? So anyway, there's definitely challenges to addressing those vetting questions like you mentioned.

(Joel Beasley at 00:31:19) What was something that you learned from teaching the class?

(Mike at 00:31:24) Well, I think that even though you're teaching, or I was teaching a webinar, which was two and a half hour lectures once a week, you need to build the relationship with all of the students, or at least the students that are engaging. Some of them don't have the time of day and don't necessarily need to be able to ask you a question in a Slack channel or, you know, try to understand something a little more deeply. But I work on establishing those relationships. And the spring course that I taught was 16 students, and it was very easy to have a relationship and a discourse and a dialogue with them. But when it ballooned to 102 for the Cyber Fellows cohort, I needed a teaching assistant.

(Mike at 00:32:05) And so I had to, you know, help them echo the same philosophy of grading assignments and doing office hours and asking questions. But even though we're socially distant, that doesn't mean we can't stay connected, right? And to value and cherish, you know, the importance of listening to the students, understanding their problems. One of them had lost his job. Another one was moving because of family health issues. And so I was very flexible at letting them submit an assignment late and to be human and to give people the benefit of the doubt and not be a hardliner, I guess, about when they submit their assignments and when they can be graded.

(Mike at 00:32:47) So I think that was one of the lessons that I took away from teaching this summer, definitely.

(Joel Beasley at 00:32:52) Are you going to do it again next year?

(Mike at 00:32:54) I am. And I'll probably have 150 students next summer.

(Joel Beasley at 00:32:56) Well, yeah. We'll put a link in the show notes. Can people just register, or do they have to be enrolled at NYU?

(Mike at 00:33:05) I've put the first two lectures of my spring offering of the course up on YouTube because those are kind of like selling the course and talking about what's going to come in the 14 or 12 weeks, depending on which semester it's taught. But it is part of the master's program. But the NYU Tandon School of Engineering's master's program is one of the top five cybersecurity masters in the country, if not the world. And it's reasonably priced compared to some of the other ones. So, you know, I can definitely wave the flag of purple NYU because it's a great way to get yourself that next level as you're working towards the C-suite or towards management positions, because you can't just be an individual contributor that knows how to hack or that knows how to do firewall rules.

(Mike at 00:33:56) You have to understand some of the social aspects of infosec and risk and to understand it as a craft almost that you practice and not just an exchange of time and attention to create code and harden it and test it.

(Joel Beasley at 00:34:15) Are you following any authors that you believe have unique thoughts and are good at explaining things through their books that write in the security space?

(Mike at 00:34:26) Well, if you haven't heard of him, I'm always evangelizing people to read Neal Stephenson. So if you haven't read Cryptonomicon or Snow Crash or The Diamond Age, I would recommend them. Snow Crash first, then Diamond Age, and then Cryptonomicon. But he's a phenomenal author. I first heard about him when I was working in Palo Alto at a bookstore, and I read this book, or saw this book come in, and it was first edition paperback called Snow Crash. I turned it over, and William Gibson was praising this author.

(Mike at 00:34:58) I was like, well, anyone who knows William Gibson as one of the principles of the cyberpunk and, you know, Johnny Mnemonic and Mona Lisa Overdrive and all sorts of great classics. And his praise of Neal Stephenson made me read the book, and the book was amazing. It was so good. It's a great story about the Babylonian epic of Mesopotamia and the Tower of Babel. And it has to do with software and code, and it has this great character in it called Hiro, H-I-R-O, Protagonist.

(Mike at 00:35:31) And Hiro Protagonist is a pizza delivery boy because in the not-too-distant future, the U.S. is only good at two things: delivering a pizza in less than 25 minutes and writing software. And it's this sort of near future, and it's just, it's got some of the greatest passages. You know, everyone who loves good writing will enjoy that book.

(Joel Beasley at 00:35:50) What based book is that?

(Mike at 00:35:51) That's Snow Crash. And it'll be made into a movie, just like all the Philip K. Dick books, you know, turned into movies like Total Recall and Blade Runner. Neal Stephenson's books will eventually be turned into mega blockbuster hits as well.

(Joel Beasley at 00:36:02) Email Netflix and say get on this.

(Mike at 00:36:05) Oh, they've been buying and selling the rights to Snow Crash for years. I don't know who owns it right now. It might be Sony. It might be Universal. But eventually, there'll be a half-assed movie version of this really awesome book.

(Mike at 00:36:18) Because oftentimes, you know, books are never matched in terms of quality. When the movie comes out, the book is always better.

(Joel Beasley at 00:36:26) The book is, it's more detailed. It's always more detailed.

(Mike at 00:36:29) Yeah. The mind's eye is a nicer canvas than the actual, you know, digital film.

(Joel Beasley at 00:36:35) Always. It's beautiful. Like, it's a weird thing to describe, but when you understand, like, I've actually got interested in imagination and how to see if you could actually increase the resolution of the mind's eye and unique objects. I haven't been necessarily successful at it, but I definitely, the one takeaway from all of that research I did a year or two ago was to just be very intentional. Like, if I go into a creative session about, you know, what I want the outcome to be, and then be very flexible for how I get to that outcome, but just to make sure I move myself forward in the creative session.

(Joel Beasley at 00:37:17) Because the worst thing to do is like go into a creative session, spend all your dopamine, right, and then come out and not have anything.

(Mike at 00:37:24) Yeah. Or to develop a pattern where you could potentially be blocked, right? And so I think improvisational theater is a good way to train your creativity and to teach people to not be blocking when you're improvising. These are some of the core skills that you need to be a good comic as well.

(Mike at 00:37:39) But the other author that I want to mention is Bertrand Russell. He's a philosopher from the thirties or forties, but he had a really good book on idleness and the benefits of being idle. Because a lot of times, I think we're so overloaded these days with inputs and sensory, you know, multitasking, that there's a trend. It was one of the staff choices at the Harvard Book Store last year when I was passing through on a trip up to Boston. And it's a topic that I think is really useful because it's not necessarily meditation and like sort of Eastern philosophy.

(Mike at 00:38:17) It's just about idleness and allowing yourself some time in your schedule to be idle because your brain is working on things all the time in the background. And sometimes if you have all this frontal lobe activity going on, your other brain that kind of mulls things over on the back burner, as it's called, isn't getting any cycles and it isn't doing its job. And so, you know, just the game of catch, right? Think about that, right? There's no winner. There's no loser. You know? You're just doing it for the enjoyment of playing it.

(Mike at 00:38:45) It's called an infinite game. And in life, there's finite and infinite games. And you can hear my philosophy coming through, right?

(Joel Beasley at 00:38:53) Yeah. Oh, yeah. It sounds like Simon Sinek, and I love that guy.

(Mike at 00:38:55) The idea is that if you allow yourself to have some idleness, your creativity can be much more productive because you don't want to try to tap the muse 24 hours a day, even if you have mood enhancing substances that can help you sustain a creative exertion for a while. You actually need that downtime to return to it fresh and to have a sustainable level of creative output.

(Joel Beasley at 00:39:21) You are 100% correct. I have spent, so I started a business right when my wife was pregnant. And now I have two kids and we're three years into it. And we just in like the past two months had our first profitable months, right. So I did like a very difficult thing at one of the most difficult stages in life, right. So I was, you know, I've been obsessed with performance and gaining edges and understanding, and I'm willing to try everything. Like I spend time enhancing my sleep, my routines, just studying and I've gotten to the point where I could push myself to burnout and understand my limit and then see if I can push it 10% farther. And so I know like how I could kill myself working. Like that's actually a very sad problem that happens quite a bit in Japan, so much so that they have their own word for it, where people die at their desk.

(Joel Beasley at 00:40:07) But I found my limits, and I found how far I can stretch my limits. And then I found what I enjoy and I kind of bounced and slid around the spectrum of myself to really, to really kind of, you know, I'm 32 to give some context today. But to really understand myself as I was maturing in my late twenties and as I'm entering my mid-thirties. So really trying to figure all of that out and what I learned, just out of half reading, half experience is that the best way for me to function, right? Because I don't know about other people, but the best way for me to function is like with training and some intensity and then rest.

(Joel Beasley at 00:40:49) And then in those rest moments is when everything rebuilds. If it's that way physically for your body when you work out, you know, you build the muscle not when you're at the gym. You build the muscle when you're sleeping later when your body is repairing. You're ripping the muscle. You tear the muscle when you're at the gym.

(Mike at 00:41:03) Yeah.

(Joel Beasley at 00:41:05) Yeah. And so that's kind of like what we're doing. We're tearing the muscle while we work, right? If it's a non-gym task, think about our brain, and then we've got to let it, we've got to let it heal. We've got to let it do its thing. And I actually, I love that you call it idleness because I actually will put into my schedule times where I call it boredom, right? Induce boredom. I don't let myself, like, I won't play the piano. I won't go write an article. Like, I want to go, go, go all the time.

(Joel Beasley at 00:41:30) And so I'll intentionally create pockets of boredom for an hour here or 30 minutes there. And it just forces me to just like lay down, relax or sit down, relax, clear my mind. I'm not meditating or listening to any meditation apps or anything like that.

(Mike at 00:41:52) So you're trying to achieve the similar kind of clarity when you do return to, you know, engaged functions.

(Joel Beasley at 00:41:57) Yeah. You have to get bored. And I was thinking too, like, you know, historically, it was much easier to get bored. In fact, we have all these inputs and stimuli because of all the boredom. It's kind of funny, right? We created all those great things.

(Mike at 00:42:09) And we've become a bit addicted to them. I have a funny example to tell about books though, if you don't mind. A lot of people talk about antisocial social media, right, because you're head down into the phone. But you have to remember, and this is one of the things that I put into, I think, lecture two or something, when I talk about intellectual property and the origin of risk and things like that, is that when books first came out, everyone was illiterate, right? The population of the world, and Gutenberg was to distribute and create literacy. And so imagine they went through the same kind of backlash actually. You're engrossed in this thing, and you're imagining this world that doesn't exist, and you're believing that you're in a relationship with the author and they're speaking to you, right?

(Mike at 00:42:57) Which is exactly what's happening with social media apps, right? You have this imaginary connection to this thing, and you're ignoring the people around you physically. And so books were antisocial when they came out, right? And people that were bookworms were considered outcasts, you know, because they spend all their time reading. And so I think of these as almost successive waves of the exact same thing. The Gutenberg distributed the authorship, you know, the ability to write. And it was not just the people making copies of the Bible, you know, in a monastery and monks and scribes that were writing, or people with papyrus in Egypt. Instead, you also had this democratization of voice, right? Anyone could publish a pamphlet, and anyone could be an author. And then along came the Internet, and anyone could become a podcaster, or anyone could become, you know, a tastemaker and, you know, somebody who unwraps packages on YouTube and earns $5 million for doing so, right?

(Mike at 00:43:53) I think it was democratizing the power of voice and authorship. And I think the next phase will be augmented and virtual reality. When you're able to use VR tools to create a VR experience, you'll be able to author your own reality. Now, yes, I can't actually make sure that I am living in San Simeon in a palatial house on the coast of California. But I can experience that, you know, with good VR. And so, eventually, I think that's the next wave of that same wave that Gutenberg represented, that MP3s represented and that iTunes store. Right? Everyone could publish. The music companies, you know, were the gatekeepers. They all fell down.

(Mike at 00:44:26) And the same kind of thing will happen for reality. We'll democratize the authorship of reality.

(Joel Beasley at 00:44:37) Well, we'll need Neuralink to do that, to really get in there.

(Mike at 00:44:39) That'll be a scary day. Certainly.

(Joel Beasley at 00:44:44) Are you following the updates with them? Are you following their corporate updates?

(Mike at 00:44:48) The Tesla Neuralink?

(Joel Beasley at 00:44:50) Yeah. Like, he just did one, I think, like three weeks ago where they showed the pigs. Did you see that?

(Mike at 00:44:55) No, I haven't. I haven't seen that.

(Joel Beasley at 00:44:57) Oh man. We'll get you a link afterwards. There's like a seven minute highlight of a three hour event. I can tell you, you only need the seven minute highlight, but they put the Neuralinks in the pigs and they're reading real-time brain scans and understanding. And obviously right now it's for medical purposes. Like they're helping people with, you know, like spinal cord injuries and that's going to be the...

(Mike at 00:45:20) Yeah.

(Joel Beasley at 00:45:21) Yeah. That's going to be the business model that allows it to then become recreational in a decade, right, to where we're doing some other...

(Mike at 00:45:27) Well, that and of course, pornography. The great gatekeeper of all these choices, right? Beta versus Betamax versus VHS. But whoever authors the best VR porn experience will win out, I'm sure.

(Joel Beasley at 00:45:39) I'm sure they will. Yep.

(Mike at 00:45:41) Yeah. But I think that it's true. I mean, the boundary and this is where I think that my training and philosophy is actually not just fun for cocktail parties, but it's also relevant to the future of business and thinking and knowledge and education and information. Because this is, you know, the information age. And if you're ignorant, it's kind of a choice.

(Mike at 00:46:02) Right? Ignorance is a choice at this point. You don't want to know the truth about things if you live in your echo chamber and you don't actually consume the Internet the way it was intended. And I know that the way it was intended was way pie in the sky Pollyanna. You know, everyone is gonna be knowledgeably free and everyone can get a master's from MIT for free.

(Joel Beasley at 00:46:21) Alright. So you just said like 18 things I wanna talk about. So I'm curious. So philosophy. What is like the thing that's looping in your mind? Because I feel like if I were alive two hundred years ago, I would probably be either like a comic or a philosopher.

(Joel Beasley at 00:46:41) Right? Just because my default, it's more awareness of my default programming. Like I'm just constantly, you know, just asking why. Like, my brain just goes there.

(Joel Beasley at 00:46:53) It just goes there all the time.

(Mike at 00:46:54) Yeah. You get meta on it. And I wanted to get meta on it. And so it was fun to go to a class called Philosophy of Education, which was a class teaching you about thinking about thinking about teaching about thinking. And so when we break that barrier and we start to figure out, who am I if I replace my arm with a prosthetic? Who am I if I become, you know, a brain in a vat? These are, you know, fundamental Gedanken in German, right, thought experiments like Einstein used to do. But we're very much gonna be living, you know, that experience very soon. People have put, you know, magnets in their fingers, and they can sense magnetic fields. Right?

(Mike at 00:47:36) Hacking, biohacking, that's really, you know, the next frontier. And, you know, maybe nanotechnology is three d tours and no. I haven't seen that.

(Joel Beasley at 00:47:48) Cyborgs Among Us? No. Is that where you got your magnet thing?

(Mike at 00:47:51) No. I was just aware of biohackers for various reasons.

(Joel Beasley at 00:47:55) Alright. So there's this documentary. It's called Cyborgs Among Us. And these people, it follows the medical field, the legitimate side of it, but then it follows the underground field. And these people are like cutting their bodies open and putting electronics into their bodies.

(Joel Beasley at 00:48:09) And they're having like tattoo parlors do it because they

(Mike at 00:48:13) Because it's not regulated or even acknowledged as a thing. It's very bleeding edge, and it's very much covered in the diamond age. And so that was that Neal Stephenson book that talks about the near future where nanotechnology is pretty much harnessed. So imagine you walk up to a matter compiler, AKA a three d printer, but really, really good one. Right? They can extrude atoms and molecules in whatever order you want. So you could ask it, make me a Patek Philippe watch. And boom. You know? It three d prints a Patek Philippe watch or assembles it with nanites and nanobots.

(Mike at 00:48:46) So imagine living in that world. It's very much a Star Trek world where you maybe have universal income. You can just study and do whatever you want, travel the world. There's no like work life balance because it's all just one thing. And so he talks about that a little bit and how The US in the future devolves into these city states where you have like people living in a neo Victorian fashion because they just loved Victorian era, you know, life and style. And you have people living in Maoist enclaves and people living in, you know, tree hugger, hippie, California, Pacific Northwest, and Birkenstocks, and, you know, tie dyes. And everyone got to live however they want. Again, democratizing reality. And his book is just so amazing because he has this ability to do research and understand things. So he's talking about these things called toner days, where all of these nanites, like the Russians and the Chinese and the Americans are all battling each other and trying to get nanites into your body or into your company or into the world.

(Mike at 00:49:41) And they kill each other, and so they're dead, and they're just floating in the air like toner, you know, like smog. And it's a real thing. I'm sure we'll experience it before I die probably, toner days, where the world is full of swarms of dead nanites, you know, that have been battling for, you know, political and economic control.

(Joel Beasley at 00:50:00) It sounds like nothing you're saying right now

(Mike at 00:50:05) is It's not sci fi. No. Yeah.

(Joel Beasley at 00:50:06) It's not sci fi. It's next

(Mike at 00:50:08) to and future. Yeah.

(Joel Beasley at 00:50:09) All I'm thinking about as you're describing these different scenarios is just distance from where we are now until there. So I'm not in my head, like, I'm not like debating whether it's gonna happen. I'm just like, oh, we're probably this many years from that situation and so on and so forth. Yeah.

(Mike at 00:50:23) We're on the cusp of a lot of these things. Definitely. And having like, you know, gecko robots that can climb walls. Right? They have this now. Right? They print nanotubes on these little and they've studied the gecko and how it actually sticks to walls. And now they build them, you know, micro sized so they can crawl inside of you and give you a colonoscopy. Right?

(Joel Beasley at 00:50:44) Yeah. I think that's one of the reasons why we're also seeing a rise of entrepreneurs because as technology explodes, there has to be that component to take it to market.

(Mike at 00:50:56) Yeah. Somebody's got a way to make it commercial, a way to add value to people's lives. Hopefully, it's not just a bunch of pet rocks, right, where people are buying it because it's a fad. You know?

(Joel Beasley at 00:51:09) I remember pet rocks. That was that was a tough yeah. I remember seeing the

(Mike at 00:51:13) I'm pretty sure there's been waves of them. Right? There was like the original pet rock back in the prehistoric era. Someone like convinced someone to give them, you know, the dead rabbit they killed because this rock was really cool looking. But

(Joel Beasley at 00:51:24) Yeah. You should have seen when I found out how money and value works and that they're essentially the same thing, just conversions of them. Man, that was an interesting time in my like professional career moving from like just being an engineer doing projects to like running and operationalizing a business. Yeah.

(Joel Beasley at 00:51:43) And I find a lot of interesting content serves me from like the philosophy world. Whenever I need to think about life going over there, just it's like it's another thing like music. It's like another avenue where I can go to to get some answers or unique perspectives. But I really, I really like things that are long form like this conversation that we could speak for more than an hour. It's not like a thirty second news clip on like some one of the major networks or anything.

(Joel Beasley at 00:52:13) Cause we

(Mike at 00:52:14) can actually Yeah. You hit the sizzle bullets.

(Joel Beasley at 00:52:16) Yeah. It's like right now I have been so disconnect. So I would say ten to twelve years ago, I went from like cable to like Hulu, Netflix, you know, whatever. Just because I don't like ads and that really drove me to those paid services. But I noticed like it helped increase my attention span and I really like the feel of not having ads.

(Joel Beasley at 00:52:42) And now every time ads, like I see them like maybe at driving in someone else's car or something, they just bother me like a 100% crazy. But I went down this whole rabbit hole about like philosophy and advertising when I was trying to to better understand business. Right? But that's kind of kind of off topic.

(Mike at 00:53:01) That's a tough one, though. I can tie that one in, actually. My father was in advertising, and he said, son, you can do anything you want in this life except go into advertising.

(Joel Beasley at 00:53:12) You know,

(Mike at 00:53:12) it was like the preacher. Right? And the preacher's son is saying, you can do anything you want, just don't become a preacher or whatever. But I think that advertising has got a bum rap in some regards because if it was relevant, it wouldn't be irksome. It wouldn't be annoying. It wouldn't be a distraction. And if we could do one to one marketing and we could not invasively sell you as the product and know what is interesting for you, then we would enjoy these things. It would almost be, I like to use the example of walking through the book stacks in the library. Right? And you serendipitously come across this book that's standing out because of its color or its shape or where you just happen to be gazing.

(Mike at 00:53:51) We need more serendipity engines in life. We don't need homogenizing, turning people into sheeple, you know, engines of, you know, oh, other people like you also bought this. Right? That's a homogenizing in a bad way, a homogenizing force in the universe, in my mind. And so if we have these algorithms that were serendipitous, someone like you, although you don't know it, might really like to read Neal Stephenson, or you might really like to read, you know, this Japanese, you know, Haruki Murakami or something. And how can you discover stuff outside of your ken, outside of your locus of of, you know, exposure, that really does melt your butter and really is interesting for you, that you would never have gotten, you know, without a good wide range of friends, you know, trying to keep you discovering new music, discovering new authors. And so I really think that the folks doing AI and machine learning need to really focus on this idea of what makes something serendipitous and what makes it a benefit to introduce something that you wouldn't necessarily have thought of on your own?

(Joel Beasley at 00:54:55) Yeah. I like the I've noticed that the act of discovery is really powerful. Like when I feel like I discovered something that's unique for like myself, I noticed that that's always like, I think I give more weight to me discovering something or finding something by accident than I do something being served directly at me because I did this other action.

(Mike at 00:55:16) Yeah. The correlation engines. Yeah. But did we want to touch on a couple of items related to, you know, work from home, you know, CISO?

(Mike at 00:55:25) Yeah.

(Joel Beasley at 00:55:26) Yeah. Well, I've got to, well, first of all, let's make sure that we push people to security scorecard. So let's talk about what the customers look like for security scorecard, like who uses you, and then yeah. Let's talk about that.

(Joel Beasley at 00:55:42) What does your customer look like?

(Mike at 00:55:44) So we have a range of customers from, you know, huge brand names with thousands and thousands of vendors that they need to assess the risk of and keep tabs on the risk over time. And we also have, you know, like you mentioned, people that just wanna know what their own score is and how they can improve their Internet facing posture. So there's basically self scoring, and then there's your vendor pool on your partners. One of the analogies I've used in the I think it's relevant. In the energy sector, they used to read your meter, you know, once a year or maybe twice a year.

(Mike at 00:56:21) And that's just two data points per, you know, household. Now, you know, audits and security and ratings of your vendors can't be a point in time once a year kind of thing. And who has the resources to fill out those questionnaires more than once a year? If you've got 2,000 vendors or even 200, you want to know and have your finger on the pulse of their security posture. You wanna get a push message that says, oh, they just really, really didn't hit this last month's patching round, and their score has dropped.

(Mike at 00:56:54) And anyone with a, you know, a c, d, or an f has like five or six times the chance of being breached in the near future. Because you can correlate your hygiene and your patching cadence and how you handle your security exposures as an analog to what you're doing on the back end. So I don't need to know the inside of your network necessarily just to know that you may be at risk. I can just kind of observe it by looking at, you know, whether you patch, you know, your servers and and whether or not you have, you know, certain exposures that have been identified with our with our scanning. And so the customers are quite varied.

(Mike at 00:57:30) Some of them are very mature and use our API, and they integrate it with their entire, you know, vendor procurement system and risk management. And other ones, you know, use the portal, log in, download a report, you know, and compare two vendors and say, well, I'm gonna go with, you know, box.com instead of, you know, Dropbox because of these factors, you know, that are important to me. And so we help people, you know, make informed decisions about risk. And, you know, having, you know, I think 1,500,000 rated companies makes us, you know, the largest dataset out there. And so if you wanna do a comparison report, I like to point out rivalries. Right? NYU's rival is is Columbia. So I ran the report, you know, the security scorecard report for Columbia and NYU, And then I showed it to the CISO at NYU, the global CISO. And she was really caught up in this, you know, oh, well, we have to be better than Columbia. It doesn't matter what our score is as long as we're better

(Joel Beasley at 00:58:27) than Columbia.

(Mike at 00:58:27) Right? And, of course, you know, they're stronger in security in some ways and weaker in others. But anyway, it's kind of a gamification aspect to it as well because we don't want it to be boring, and hopefully I'm not in in my description of it. But the idea is to help people manage risk well, whether it's their own, you know, backyard or the people that, you know, deliver the milk to your front door. You need to understand their risk because they are an attack vector.

(Mike at 00:58:52) You know, you can you can be breached through your third parties. Right?

(Joel Beasley at 00:58:56) And so when when you get to meet with people and and talk with them, what is like the next step? Like, let's say they're interested in SecurityScorecard. What's the next step?

(Mike at 00:59:08) Sure. Well, oftentimes, we can set up a free account where where you can look at your own score and get familiar with how we represent, you know, the findings and the and the risks and and issues that are discoverable, because this is what a hacker sees. And so you wanna know that. And then from there, you grow your appetite for saying, well, I kind of need to know, you know, something about, you know, this vendor that we rely on that maybe is our hosting provider for the website or Amazon itself. And you don't necessarily care about all of Amazon because it's a behemoth or all of SAP.

(Mike at 00:59:43) You only care about one particular business unit. And so we're working on ways to sort of tailor and customize these cards when you're dealing with an entity like Google that just has such a sprawl of of network services. You know, giving one letter grade score to Google isn't really a pragmatic or meaningful act. You wanna talk about, you know, their cloud services. You wanna talk about their email. You wanna talk about their, you know, different business units that aren't necessarily sharing infrastructure either. And so the ability to customize, you know, and make whitelist and blacklist type mappings really helps clarify whether or not that vendor's service, you know, is is a potential risk, an attack vector for you. And when when I was making the analogy with the meter reader for the energy companies, they've experienced the same kind of disruption because now you have a smart meter, which is sending, you know, five minute time series data back to the energy company. And you have people with a Tesla power wall in their basement and solar panels on the roof. And they're, you know, collecting the energy during the day, and then they're selling it back to the grid at night when there's peak demand because everyone's watching, you know, Stranger Things or Game of Thrones.

(Joel Beasley at 01:00:56) The Modern CTO Podcast on YouTube. Come on now.

(Mike at 01:00:59) Come on, for the Modern CTO Podcast on YouTube. As soon as you guys light up an episode, you know, the energy grid needs to handle all those computers being turned off. But it's such a radical job and architecture change for the energy company to go from two data points per household to five-minute time series data. And the same kind of thing applies to risks and security of your third parties.

(Mike at 01:01:24) So we have this infrastructure that is scanning millions and millions of IP addresses every night and providing a new risk update and profile on them. The analogy I use here is an ancient philosopher, and hopefully you'll appreciate again the philosophy angle. Heraclitus was a historian and philosopher, a Greek philosopher, who wrote something that can be roughly translated as, you can never step into the same river twice. And this for me is better than the goalposts are moving or someone took the cheese, because the river is, like, obviously, the world of threats and exposures and vulnerabilities. And you yourself are the different person from day to day.

(Mike at 01:02:05) Right? Like, all of us are living in one big tabletop exercise right now, right, where you did this "what if you couldn't go to work." There was a chemical spill or there was, you know, a virus. And so the whole world is living in one big tabletop exercise right now.

(Mike at 01:02:20) And this idea that our attack surface has changed radically. Everyone's working from home. You can easily hack—not my home router, but you can hack people's home routers much more easily than you can, you know, the corporate firewall. And so your attack surface is now a thousand endpoints if you have a thousand employees, rather than just that one firewall for the office. And so you need to have things like, you know, roaming DNS firewall policies that stop people from clicking on phishing emails that they see now.

(Mike at 01:02:47) You have to have a DLP program to make sure that—because CEOs and lots of people are emailing documents around now that they would have normally dropped onto a file share when they're in the office. And so the whole pattern and behavior has changed radically. And you have to worry about people not knowing the difference between closing an app and closing a window because they walk away from that shared computer and then the kid logs in and goes somewhere and maybe they're trying to get some V Bucks for free and it's a scammer site that installs some malware and, you know, suddenly, you know, mom or dad's corporate credentials have been compromised because they closed the window, they didn't close the app. And so they were still logged in. There's still a valid token.

(Mike at 01:03:27) Right? There's all these things that we have to pay attention to because of this. Right? BYOD policies. You know, maybe you can't buy a laptop right now.

(Mike at 01:03:35) The Department of Education is, you know, trying to buy laptops, and they can't get them to start school this week because the demand is so high. So you have to kind of relax your bring your own device policy. And how do you maintain security on all these non-corporate-owned devices? Those are some of the shifts that I've observed since COVID started. But definitely the roaming DNS firewall policy is really helpful. Get a tool like OpenDNS or Cisco Umbrella that publishes that out so that they don't have to be on the VPN to be protected.

(Joel Beasley at 01:04:05) And then is this line of, like, remote—the changes from the remote work environment and protecting—is this something that your company does, like, consulting on if people want to know more about that? Or—

(Mike at 01:04:18) No. Not necessarily. Our core two products are Atlas, which is to fill out those questionnaires and make it easier, and the ratings platform and to grow that. At some point, we want to try to invert, you know, the relationship between credit scores and cybersecurity scores. Because right now, if you talk about, you know, scores and ratings, you think of applying for a credit card, applying for a loan, you know, buying a car.

(Mike at 01:04:47) But really, that will become legacy. It won't be as important. Your credit score is just a tiny piece of information. Your cyber score is multifaceted. Right? Your exposure, your risk, your identity management. And so eventually, we want to change the language so that when people talk about credit scores, they'll be talking about, you know, legacy ratings. And when someone just says the word ratings, they will think, you know, cybersecurity ratings like us. And, yeah, we're the first mover. You know, we have the best technique, you know, the smart engineers.

(Joel Beasley at 01:05:19) Breaches? Do you track breaches?

(Mike at 01:05:20) We do. Yeah. They show up as events on the history timeline.

(Joel Beasley at 01:05:24) Just like the credit report.

(Mike at 01:05:26) Yeah. And if you're going to evaluate two vendors and one has a breach and the other doesn't, you know, that's certainly an indicator.

(Joel Beasley at 01:05:33) Does it drop off after seven years?

(Mike at 01:05:36) No. No. Because the Internet doesn't forget. Right? Those breach articles are always available. If not on the site itself, you can always go to archive.org and look at the Wayback Machine. Right?

(Joel Beasley at 01:05:46) I love the Wayback Machine. Yeah. Well, real quick. I want to touch on election security. And the reason I'm, you know, not going to drill hard on it, but I was just thinking about election security because it's coming up. And I've thought in the past different systems or ways we could maybe make it more efficient and heard a lot. There's other people thinking of—sometimes I get these ideas and I go out there and I'm like, okay, there are really smart people executing these. I can go back and do my own, do something else. It's not my responsibility because I can go focus on my thing because there's brilliant people working on it. But I was just curious, what are your thoughts on election security coming up?

(Mike at 01:06:32) I'm pretty worried about the ability for the integrity of the data. I'm not as worried about the confidentiality of the data. Remember, you know, infosec, availability, integrity, and confidentiality. Those are the three pillars. In this case, yes, people want to know that who they voted for is private. So that'd be the confidentiality part. But the integrity part is more important at the moment, and we don't have good systems of control. Even in the most well-funded, you know, tech giants, they still have problems with the integrity of data. Someone on the inside changing it, things changing accidentally, whether it's malicious or not. And so I thought one of the best ways to approach this—I went to a, you know those camp, hacking camps that they do in Europe where they, you know, get a bunch of tents together and build a local area network and a local, you know, temporary cellular network?

(Mike at 01:07:26) I went to one in 2000—I think it was 2005, Hacking at Random. And there were some folks giving a lecture there on quantum voting machines. Of course, that's the perfect solution to integrity and confidentiality. Because if you looked at my vote, you would change the spin on the quantum. Right? You would affect it. The act of observance is detectable. And so I think it was the Swiss that were actually working on building it. But quantum technology is kind of ephemeral. Right? Quantum storage doesn't last for more than a few, you know, nanoseconds. And so how do you store those votes, you know, for a long time? But this would be the best way to improve the integrity and trust of voting systems would be to put some money in research, you know, primary scientific research, like we do for, you know, solar physics and, you know, fossil fuels and solar, you know, renewable energy. Put some money and research and oomph into quantum voting because then we could have absolute privacy and absolute integrity.

(Joel Beasley at 01:08:27) Yeah. No. I fully agree. I think there is also something in there with, like, blockchain technology that could be useful.

(Mike at 01:08:35) Correct. Yeah. The public ledger, the distributed ledger is also an immutable record that can be used as well.

(Joel Beasley at 01:08:42) Right. And then, you know, we have—and then the popular vote doesn't even elect. So you have the, like, electoral college, at least here in the United States.

(Mike at 01:08:51) Representative democracy. Yeah.

(Joel Beasley at 01:08:54) Yeah. So I'm curious. Yeah. Which made sense back when you would have to make a three-week trek to go vote.

(Mike at 01:09:00) In colonial times. Yeah.

(Joel Beasley at 01:09:02) Yeah. But not when I can press a button.

(Mike at 01:09:04) No. But we are actually working on something. I'm not sure if I'm supposed to talk about it. But there will be news that will be coming regarding, you know, the sort of health of all of the states' election commissions and infrastructure. And providing a very, you know, politically neutral, but technically, it's going to have some teeth in it. Right? Where we sit with risk on this most interesting fall election coming up.

(Joel Beasley at 01:09:37) I love when smart people can come together and have, like, nuanced conversation and discuss, like, actually approach it from the perspective of the craft and not necessarily what's happening in society with different teams. So like the act—like how you're describing it, the way you speak about it, like it's completely not partisan. It's just like we're going to analyze security from a security perspective. And I love that. I love when people can disassociate from, like, their personalities and personal beliefs and just think about the greater good and the actual intent of, like, having a fair marketplace.

(Mike at 01:10:20) You know, people believe in, you know, the power of price, and transparency of price will normalize markets. Right? Except it doesn't always. Right? There are certainly—I mean, I lived in Amsterdam for eleven years, and I've experienced enlightened socialism. And I know that, you know, it wouldn't work in the U.S. in that same way because Holland is only, like, 17 million people. They only have one traffic report in one time zone. But, you know, the U.S. is far too big to operate on the same model. But I do know that, like, health care, for example, could be done much better than the way we do it.

(Mike at 01:10:57) We sort of have this Olympic scale where you have the best in the world, and then you have things that are not even found in developing countries occurring in this country. And so it's that whole spectrum that we have in the U.S. And if we could just raise up the lower a little bit, not necessarily by, you know, bringing down the upper end—we still want to have the best medicine, you know, on the planet and the best, you know, surgeons and the best, you know, scientists—but raising up that bottom bar is really, you know, keeping the total cost of the system down. When I could go to the pharmacy and, you know, get a prescription with no co-pay and there was no reason not to go into a doctor and, you know, do preventative, you know, checkups and treatment. There's no disincentive, you know, because of fear of cost or someone getting you that you have high blood pressure and your premiums go up. You know? The idea is to keep people healthy, you know, and do it preventatively is a lot less expensive than than these extreme end-of-life measures that we're so used to here and trying to hang on like that. And so, really, the total cost of the system goes down. I think the same kind of thing applies to security.

(Mike at 01:12:00) If we get more proactive, we don't have to spend as much money on reactive measures and, you know, recovering from a breach. We can reduce the frequency at which, you know, security is compromised.

(Joel Beasley at 01:12:13) Yeah. It's like we need more well-trained security people.

(Mike at 01:12:17) Yeah. We need people that understand risk better. And so tools like ours help people and boards of directors, you know, understand their risk better and their risk profile.

(Joel Beasley at 01:12:26) Any content to recommend to me that's philosophy related around risk?

(Mike at 01:12:34) Well, there's a book that I almost quoted earlier by James P. Carse called Finite and Infinite Games. And it's written from a fairly religious perspective, but C.S. Lewis was terribly religious as well. Right? But he wrote some really good stuff that was not necessarily religious, but informed by his belief system, that's also very interesting in the area of philosophy and, you know, risk. Another one would be—well, James Dewey. I mean, I have to make a call-out to my master's thesis. James Dewey is an American pragmatist from the American school of philosophy, and he and Bertrand Russell were great fans and friends. John Dewey, I wrote my master's thesis on him. He was a very prolific writer, lived to the age of 92, wrote hundreds and hundreds of books, and his books would have titles like School and Society, Nature and Growth.

(Mike at 01:13:31) And it was interesting to realize that his writings were kind of perverted and turned into the melting pot where they turned everyone into an American and they lost some of their cultural uniqueness and diversity. But he was a fascinating character because one of the things I did when I was finishing up this biography of him, because everyone knows about his writing, but people didn't know too much about him as a person. He actually traveled to Mexico in 1937 to help give Trotsky a fair trial. He was such a believer in democracy and justice and right. And this was when he was quite old and his doctor advised against it. But he actually met Frida Kahlo and Diego Rivera and Trotsky in Mexico in 1937, because he had been exiled and condemned to death. And so if you want to talk about, you know, giving people a fair trial and being impartial and nonpartisan, you know, giving Trotsky a chance to tell his side of the story versus Stalin was certainly an American ideal, and Dewey was an American idealist. And so some of his books are quite accessible. Like I said, you know, Nature and Growth, School and Society, and of course, some of his papers. He was a Columbia professor as well and, just a fascinating philosopher.

(Joel Beasley at 01:14:45) That James Carse, it's how you say it?

(Mike at 01:14:48) Did I say it correctly?

(Joel Beasley at 01:14:48) So Finite and Infinite Games, I'm assuming that's an older book.

(Mike at 01:14:52) Yeah. And it's really short, easy to read. You can probably find a paperback for it for, like, $5 to $10.

(Joel Beasley at 01:14:58) Because for me, I had only heard it—I'd heard it first from, like, Simon Sinek. That sounds like he was inspired by probably that book. And then he wrote like a more modern-day version of it. I'm going to—

(Mike at 01:15:11) I'd have to Google it and check it out. Yeah.

(Joel Beasley at 01:15:13) Have you ever come across Simon and his thoughts?

(Mike at 01:15:15) I'm not sure if it's ringing a bell. What's the name again?

(Joel Beasley at 01:15:18) Oh, yeah. So Simon, I think I'm saying it right. Simon Sinek, S-I-N-E-K. But he wrote recently a book called The Infinite Game. But he's also written Leaders Eat Last and Start With Why.

(Mike at 01:15:33) Oh, okay.

(Joel Beasley at 01:15:33) Yeah. So—

(Mike at 01:15:35) Yeah. That's definitely those Hudson, you know, book shops on your way to the train station.

(Joel Beasley at 01:15:41) Yes. You've seen it. Yeah. You've definitely seen it.

(Mike at 01:15:43) Yeah. Those contain true nuggets of wisdom, and I love the fact that they're popular and not just, you know, being read by people that think about, you know, Lao Tzu and, you know, the nature of power and things like that.

(Joel Beasley at 01:15:58) Yeah. So the Simon guy used to be like a marketing executive. I think he felt like his soul was being drained from that. And he had done this TED Talk that became like one of the most popular TED Talks.

(Mike at 01:16:09) He had his Mad Men epiphany. Yeah.

(Joel Beasley at 01:16:11) Right. And so he then he became obsessed with just like ideas that matter or ideas that are worth spreading, changing the world. And so he writes and he judges his success not based on the book sales, but based off of the reviews and how the idea spreads throughout society. So I think he's like a modern day philosopher type person.

(Mike at 01:16:34) That's great. Oh, and there's one book that I should definitely plug, because it has to do with these analogies, right? Where you take something that someone's very familiar with, and you don't have to teach them something. You just say, well, this is actually kind of like that.

(Mike at 01:16:45) And they go, oh, and then they have this light bulb. Right? So there's this book called Everything I Need to Know I Learned on TV. And it's a philosophy book. And it talks about, you know, The Simpsons and how Homer is a perfect example of hedonism.

(Mike at 01:16:59) Right? Dope. Another donut. Dope. And then you got Jack Bauer at 24, you know, and you got utilitarianism.

(Mike at 01:17:05) Well, I'm going to shoot these two people to save those 500, you know. And it talks about The Sopranos and Buffy the Vampire Slayer, and it uses all these popular TV to explain classical philosophy and different belief systems. So Everything I Need to Know I Learned from TV is certainly worth reading.

(Joel Beasley at 01:17:23) Yeah. It's like, as humans, we have this capacity to understand. It's just the medium that we experience it through.

(Mike at 01:17:30) Sometimes there's a lot of friction. And other times, it just floats, you know, and melts like butter and you just take it in.

(Joel Beasley at 01:17:37) So we talked about election security. We talked about security in general. Talked about what SecurityScorecard does. You guys are going to become like the credit agency for security, which I think is pretty cool.

(Mike at 01:17:50) Trust and transparency too. Yeah. Because we put our algorithms out there. No one else does. We tell you exactly how we calculate that score.

(Mike at 01:17:58) So there's no gaming of it going on. You know, there's no nepotism. It's all, you know, straight up truth. As best we can assimilate it, of course. Because remember, that river that you can't step into twice is constantly changing.

(Mike at 01:18:11) And IP address attribution is a known challenge at the world at large. And, of course, it's a hard nut for us to crack as well. But we have a lot of smart people. Our data scientists are working on different ways of improving our attribution. Because an IP address could be an AWS endpoint for me today.

(Mike at 01:18:29) And a week from now or a month from now, it could be someone else's. And so how do you track the risk of that IP address and what domain name or services were behind it, what company was using it at the time? You know, that's a fast moving bit of water and river.

(Joel Beasley at 01:18:43) Who allocates IP addresses?

(Mike at 01:18:45) Well, there are different—you know, ICANN has to do with the top level domains. You have RIPE and APNIC that allocate slash 24s or larger to different companies. And so those are like net block owners. And if you're big enough, you can have an ASN, an atomic or an autonomous system number, which means you own a bunch of networks and people advertise routes between them. But maybe that's a little too much in the weeds for this audience.

(Mike at 01:19:14) But basically, there's some real risks out there called BGP hijacking. BGP is Border Gateway Protocol, and it's happened some fairly recently. Although, it was like a 2008 Black Hat conference where someone hijacked all of the Black Hat traffic through a server in New York by advertising a shorter route because BGP has this whole trust technology behind it and no verification. So if you advertise a shorter route to this network, they'll start sending you the traffic. And they were hijacking all the traffic and sort of man-in-the-middle decrypting it in real time during their hack at that hackathon at this Black Hat conference.

(Mike at 01:19:51) And it was—or Defcon maybe it was. I don't remember which. And this has happened in the wild for real in China and Russia recently, where—and people say, oh, it's a typo. But some company in China advertised a shorter route to Google, Microsoft, Wells Fargo, Bank of America. All the traffic started going, you know, very scenically to Asia and then to the bank.

(Mike at 01:20:13) And so people thought it was just a slow day on the Internet, but no. It's because the traffic was going halfway around the world first and then being routed back. But there were BGP hijacks that happened. Wired magazine wrote a magazine article about it two or three years ago where traffic was going through Iceland and Belarus for several hours and, obviously, capturing all that traffic and decrypting it because of vulnerabilities that people do or don't know about is a real rich source of data. But, yeah, certainly something to Google if you've never heard of BGP hijacking.

(Joel Beasley at 01:20:45) Yeah. So we'll just touch on this briefly because I want to respect your time. So we'll wrap up in like five minutes, if that's okay.

(Mike at 01:20:53) Sure.

(Joel Beasley at 01:20:53) But can you—I have never heard of this thing, what you're describing. They're advertising a shorter route to a network. Can you explain it to me like I'm a two-year-old?

(Mike at 01:21:07) Sure. IP addresses are the fundamental sort of map and address book for the Internet. My laptop has an IP address. When I browse the Internet, my laptop, or at least that of my Internet service provider, you know, the people that give me my network connection, shows up in the log files of all of the places that I view. It's a bit of a digital footprint.

(Mike at 01:21:33) We have a website, securityscorecard.com. That's a human name, right? But that resolves to an IP address, which is a dotted quad, a series of four numbers. And the sum of these ranges and IP addresses in DNS are reserved for private networks that aren't publicly routed.

(Mike at 01:21:51) You may know them as 192.168.something.something or 10.dot and then the rest of the numbers. There's a huge range of addresses that have been reserved for private networks. But all of the publicly routed networks, you know, the Internet is a packet-switched network. It's not centralized. So there's no central control.

(Mike at 01:22:09) It was designed by the RAND Corporation in California as a part of DARPA, the military project back in the day when they thought that maybe, you know, Washington might be nuked. So how do you build a network technology that is decentralized? And packets just sort of find their way to where they need to go. And anything that participates in routing traffic respects, you know, these routing tables and rules. And so if you advertise a shorter route to get to the 3.252 network .x.x...

(Mike at 01:22:41) People will start sending you traffic to that route and say, oh, well, you're only four hops away. Cool. Then it'll get there faster. Even though geographically it might be, like I said, very circuitous routing, it may go through Belarus or, you know, China on its way to the bank. And so if you specifically advertise routes for Google or for Amazon or for, like I said, banks and major tech companies, you can actually hijack that traffic, send it to your equipment, your routers, capture a copy of it, decrypt some of it that's maybe not so cryptographically strong, see what's in it, you know, but then still route the traffic on.

(Mike at 01:23:16) And so the idea is that, you know, the shortest distance between two points in the physical world is as a crow flies, right? Straight line. But on the Internet, it could be, you know, four hops through San Francisco in order to get to Minneapolis. On a given day, it could go through Japan and go around the other direction around the world, based on network disturbances and congestion and things like that.

(Joel Beasley at 01:23:40) So we're talking—this is specifically for like DNS lookups because of the domain?

(Mike at 01:23:46) Also routing of just packets.

(Joel Beasley at 01:23:49) Really? So that's where—that's where I—there's just this gap of knowledge for me. So there's some sort of process. I'm going to actually research this. I'm fascinated by it.

(Joel Beasley at 01:24:01) So when I try to connect to you, let's say I'm going to just connect directly to you, right? Point to point, let's say—

(Mike at 01:24:10) We're sharing an MP3 on Napster back in the day. Yeah. A copy of a song from my hard drive. Yeah.

(Joel Beasley at 01:24:18) Yeah. When does my computer interface and request the length of available paths? Like, what process is that?

(Mike at 01:24:26) It doesn't. But if you've ever used the traceroute command, it'll actually expose to you all of the machines along the way. Because if I traceroute from you to me right now, we may come up with, you know, 15 hops, 30 hops. It depends if you're in New York or if you're in California. There's different paths it could take.

(Mike at 01:24:44) And then an hour later, you'd run that same traceroute. It could potentially go a different route because all of these routers are keeping tables and saying, oh, this has got 15 milliseconds of latency. You want to go that way because it's optimizing for latency, and it wants you to get those packets where they need to be as quickly as possible. And so sometimes, you know, if you do this command, traceroute, and you say traceroute, you know, google.com or something, it'll show you the number of machines between you and Google servers that participated in the handling and passing of your traffic. And so your Internet service provider is going to be your first hop from home or from the office.

(Mike at 01:25:19) And then from there, it's going to be network aggregators, you know, major telcos that have fiber optic connections that connect the backbone and fiber of the actual Internet. So yeah. It's an area that people don't get into that much. But Bruce Sterling wrote a really great article back in, I think it was maybe '92, '93, for an original bulletin board system called The WELL, and it's called A Brief History of the Internet. And he talks about how the Internet grew up from just five nodes—UCLA, Palo Alto Research Center, you know, SRI, what's it called?

(Mike at 01:25:55) The people at the RAND Corporation, SRI, that invented, you know, this whole network and how it evolved since then. And he puts it in barely, you know, common terms, just sort of explaining how this whole thing grew up. And it became a bit of a chaos for the government because they can't control it as well as they'd like to, or Russia or China with the great Chinese firewall, because it's fundamentally built on letting packets find their way any way they can, like water flowing downhill. It'll go this way, that way. It'll go under a rock, around the rock.

(Mike at 01:26:27) And so that's a fundamental design choice of the Internet and packet-switched networks and TCP/IP. And so you really can't go against the grain on that. And so that's one of the security limitations of this design is that, yes, you can actually advertise a false route to a network, and packets will go that route.

(Joel Beasley at 01:26:45) So the packet is sort of engineered to find its source. It's like a heat-seeking missile.

(Mike at 01:26:52) And be reassembled on the other side in the right sequence. Yep.

(Joel Beasley at 01:26:55) Wow. That's pretty interesting. And then the companies that are passing all this information, those are like our ISPs?

(Mike at 01:27:02) Correct. And the major network aggregators and, you know, people that operate the major fiber channels, you know, like your Sprints, your AT&Ts. MAE-West is the name of the access point that is for most of the West Coast. All of the traffic that goes onto the European continent goes through Amsterdam and through the Amsterdam Exchange. And so there's these bunkers underground full of lots of network connections and fiber, and that's where all the traffic headed to Europe—it actually passes through Dublin on its way into Amsterdam.

(Mike at 01:27:31) But, you know, the undersea cables and all of that, that's all wrapped up with the physical infrastructure of the Internet.

(Joel Beasley at 01:27:36) Yeah. I had Siena on the show, and he was telling me about the underwater cables that they do and how they connect the world and how things go from, like, fiber optic—like, digital to analog signals and all of this all of this really, really interesting stuff. But so this packet is engineered to find a way. So in order for you to do one of these hacks, you would have to be one of the larger providers. You would have to be like a larger entity. Like, I couldn't do one of those hacks.

(Mike at 01:28:00) You'd have to at least have an ASN assigned to you because then you're playing at that BGP level. But, yeah, look for the Wired article on the Belarus BGP hijack or attack.

(Joel Beasley at 01:28:13) So then if you're that large and it happened in China, then that's like extra scary because that means it was like a major provider in China that did that and then basically just filtered all of our data.

(Mike at 01:28:25) Correct. And captured it and tried to later decrypt it if it was using weak cryptography. So that's one of the blessings and curses, of course, of crypto is that the government wants backdoors. But if we let them have it, they'll be abused, you know, by nation states as well as three-letter agencies. So it's a tough walk, you know, to compromise between absolute security, future perfect secrecy, forward secrecy, and making this kind of stuff observable and understandable of what's happening on our networks.

(Joel Beasley at 01:28:58) Have you ever gotten to go down to Augusta, Georgia and see the cybersecurity command center?

(Mike at 01:29:03) No. I haven't. No.

(Joel Beasley at 01:29:04) It's like a new thing. They were just finishing it. I was there like two years ago, and they were just finishing it. But it's where—it's like the big capital for our—like, of the nation for our cybersecurity operations. They just built a brand new campus.

(Mike at 01:29:20) Cool. Well, I have to get ready for my 2:30.

(Joel Beasley at 01:29:22) Let's keep going.

(Mike at 01:29:23) But let's talk again sometime. If you want to come back at me and say, okay. Now that we've done the whole holy cow, you know a lot about a lot of different things. Let's pick some more topics to discuss. It was enjoyable.

(Mike at 01:29:34) I enjoyed talking with you.

(Joel Beasley at 01:29:36) Me too. Thank you so much, Mike. You have a wonderful day.

(Mike at 01:29:38) You too.

(Joel Beasley at 01:29:41) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you would like to hear discussed on the podcast, either add me on LinkedIn or send me an email [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.