Episode 568 ·
Salesforce And Their Biggest Asset with Taher Elgamal, CTO of Security at Salesforce
Today we’re talking to Taher Elgamal, CTO of Security at Salesforce; and we discuss the genesis of SSL; why we should strive towards a passwordless internet; and how we might be able to get the entire world on the internet.
All of this right here, right now, on the Modern CTO Podcast!
Check out more of Taher and Salesforce at https://www.salesforce.com/!

About Taher Elgamal:
Dr. Taher Elgamal is an internationally respected information security leader and cryptographer. He was the recipient of the lifetime achievement award from the RSA conference in 2009. He has successfully served as CISO, Chief Scientist, CTO, as well as founder and CEO of numerous key organizations. Dr. Elgamal invented several industry and government standards in data security and digital signatures for areas including the DSS government standard for digital signatures. He is recognized in the industry as the "father" of SSL.
About Salesforce:
Salesforce is a company that makes cloud-based software designed to help businesses find more prospects, close more deals, and wow customers with amazing service.
Customer 360, our complete suite of products, unites your sales, service, marketing, commerce, and IT teams with a single, shared view of customer information, helping you grow relationships with customers and employees alike.
Transcript
(Intro Narrator at 00:00:01) Today, we're talking to Taher, CTO of Security at Salesforce, about doing away with passwords in place of multi-factor authentication and more. You're listening to Joel Beasley, Modern CTO.
(Taher Elgamal at 00:00:17) Yeah, I was born in Egypt.
(Joel Beasley at 00:00:19) Oh, very cool. And how long have you been a citizen?
(Taher Elgamal at 00:00:23) A citizen, thirty-some years. I just got my fourth passport, so it must be thirty-plus years. I lived in the Bay Area since '79, so forty-three years and counting.
(Joel Beasley at 00:00:36) So you've gotten to watch all the emergence of the technology in Silicon Valley then?
(Taher Elgamal at 00:00:41) Yeah, yeah. We had fruit orchards when I actually first came to California. It was not high-tech. We had National Semiconductor and Hewlett-Packard, and that was it.
(Joel Beasley at 00:00:49) Can you give me the background of what it was like from 1979 to today watching Silicon Valley grow?
(Taher Elgamal at 00:00:57) Yeah. I mean, I came to Stanford to get a PhD. I got accepted at Stanford, so I said, heck, I'm definitely going to Stanford. So I did that.
(Taher Elgamal at 00:01:07) And honestly, the plan was to get a degree and maybe work a little bit and then go back. I've been here for forty-three years. I don't think I'm going back. But I still got friends and family. When I first joined, I mean, Stanford was a big thing back then, still is a big thing.
(Taher Elgamal at 00:01:26) But you would actually drive on El Camino Real, which is the big street down here, and you see fruit orchards literally. You stop and pick up a peach or something and you move on. We did have Hewlett-Packard, which actually was my first job after the PhD, and National Semiconductor. I mean, the industry was very, very young. Apple had started by the time I graduated, but was a tiny company.
(Taher Elgamal at 00:01:54) And there's this kind of history. Downtown Palo Alto now is a humming place. It's an awesome place.
(Joel Beasley at 00:02:00) Yeah, I've gotten to visit down there. It's definitely got that feel and that vibe.
(Taher Elgamal at 00:02:04) Yeah.
(Joel Beasley at 00:02:05) How did you get involved with the SSL project? Are you the founder? Did you participate with a group of people? I saw that you are on Wikipedia listed as the father of SSL. I want to explain that.
(Taher Elgamal at 00:02:16) Good question. So I went to an IDC conference in 1994 where Jim Clark was supposed to speak. I knew Jim because he was actually a professor at Stanford when I was a grad student. So I said, oh, I want to hear this guy.
(Taher Elgamal at 00:02:35) So I went to hear him out and he talked about cryptography, which is actually the topic of my PhD. So I'm a professional cryptographer. And I said, why is this guy talking about cryptography? He's a computer graphics guy, actually, by trade. So I went to him after his presentation and chatted, and he said, yeah, we're starting this company called Mosaic. We're going to do e-commerce over the Internet. So that was actually the original vision. I ended up becoming the chief scientist at Netscape really early on. And the vision was to enable e-commerce. And we knew that the Internet was so open that if we didn't secure the channel between the buyer and the seller, things would go crazy.
(Taher Elgamal at 00:03:17) Things still went crazy, but we were good at making sure that the connection between the buyers and the sellers is in fact secured. So the idea of SSL started at Netscape a little before I joined, actually, so it was not my idea. I ended up writing the patents. There are two patents that Netscape had for the original SSL method.
(Taher Elgamal at 00:03:42) And then we put a team together. So I hired the team that actually worked on the SSL 3.0 spec, which is kind of the beginning of this world. So I did not write the spec. I just was sort of the godfather of that thing. And the patents got accepted.
(Taher Elgamal at 00:04:00) You know, after that we said, we're not going to own the entire e-commerce world. It's way too big for one small company to own. And we knew that Microsoft was actually working on a competing protocol to SSL. So if we did not come together and do one, I think life would have been a lot harder today. So at Netscape, we agreed that the right thing to do was to take SSL and make it a standard in the IETF.
(Taher Elgamal at 00:04:29) And we actually brought Microsoft with us. So we had one big, huge meeting in the IETF, and we proposed that we make this a standard, and Microsoft stood up and said, yes, we're going to sign up if this becomes an IETF standard that's not owned by anybody else. And so TLS 1.0 became an actual standard. So I was the co-head of the IETF working group that actually made TLS 1.0 a standard.
(Taher Elgamal at 00:04:57) So the father of SSL—I mean, I did not write the Wikipedia page, so I don't know who did. As you know, nobody ever knows who's actually writing on Wikipedia. But it's kind of an implication that I both wrote the patents, built a team, and made it a standard and promoted it in the world, kind of thing. Yeah, it was a good route.
(Joel Beasley at 00:05:17) That is very cool. What comes after SSL? Will we always need SSL? Will there be some new technology, some new way of browsing, some new standards that usurp it from its current dominance?
(Taher Elgamal at 00:05:30) So, you know, TLS 1.3, which is kind of the latest standard, which is not really being used all over the place quite yet, is based on a modification of the protocol. It's actually closer to the Google QUIC protocol than anything. It carries the TLS name because TLS was designed to be backwards compatible. So if one side has a more recent version than the other side, then we'll agree on which version to use, kind of thing. So is it going to be completely replaced?
(Taher Elgamal at 00:06:07) I don't believe so, because there are billions of copies of that thing. It's in every fridge and in every doorbell and laptop and mobile and everything. It's kind of part of the Internet as far as that goes. That does not mean that it does not continue to get fixed and, you know, get more security and perhaps more efficiency and so on. So it will continue to get better.
(Joel Beasley at 00:06:30) Who manages the project now? How is it managed? I don't have a lot of knowledge in this area. Who can contribute to it? How do contributions get approved and released? How does that process work?
(Taher Elgamal at 00:06:39) The IETF does, the Internet Engineering Task Force, which does most of the Internet protocol standards. It's open. Anybody can go to these meetings. Anybody can provide feedback into the RFCs and propose things. And a community of people will show up every once in a while in some random city in the world and work on the new proposals and see if we need to update something or not.
(Taher Elgamal at 00:07:06) It's open to everyone. You can go and propose changes as far as that goes.
(Joel Beasley at 00:07:10) Does it have a legal entity associated with it?
(Taher Elgamal at 00:07:13) I don't actually know the answer to this. But there is an agreement that the IETF sets the standard. So you are supposed to use an implementation that satisfies the RFC exactly. There are very, very few entities that actually implement SSL because implementing cryptographic protocols is really not for the hobbyist.
(Taher Elgamal at 00:07:36) So most people will just get it from whatever. There's lots and lots of open source. OpenSSL is very well known. So that's how people implement things. So if you get open source, then you're bound by the open source license, which is attached to the project.
(Taher Elgamal at 00:07:53) If you buy it from a vendor, then you have a contract with the vendor, what you can and cannot do. But the protocol itself is kind of fixed by the IETF.
(Joel Beasley at 00:08:03) Is there a president of the IETF?
(Taher Elgamal at 00:08:06) They're not called president. There are actually people responsible for general areas of the IETF. So the security area has actually a named individual who, quote unquote, runs that.
(Joel Beasley at 00:08:20) Got it.
(Taher Elgamal at 00:08:21) Although the contributions to the standards come from the world, basically.
(Joel Beasley at 00:08:26) Yeah, but there's some handoff of relationships and positioning from one generation to the next. It's who's involved, who's around, who knows it deeply, who's there all the time. And it just sort of naturally flows. It's not like a board of directors for a charity where there's formal voting and things of that nature.
(Taher Elgamal at 00:08:45) The voting for the standards comes from the working group.
(Joel Beasley at 00:08:49) Right.
(Taher Elgamal at 00:08:49) 100%. The individuals who run these things don't actually contribute to the content itself. They sometimes help in resolving conflict, like the group is split between two different opinions completely and nobody's budging, or somebody standardizing a patented idea, which we did with SSL.
(Taher Elgamal at 00:09:09) But part of what we did is that we said the patents are for the world to use. So we actually opened up the patents to everyone. We needed the patents for defensive reasons.
(Joel Beasley at 00:09:19) Very cool. You're educating me a lot about SSL.
(Taher Elgamal at 00:09:22) It's underneath every single e-commerce transaction that happened since 1996.
(Joel Beasley at 00:09:27) Yeah, it's ubiquitous. I wasn't programming before 1996. I probably started writing code in '98. So for me, it was ubiquitous. It was just always there.
(Joel Beasley at 00:09:36) It was, okay, you need this. This is what you do. And I never really looked under the hood. You know, whatever that says about me, I don't know. I was always focused on how do I achieve an outcome with the code, and then how do I do that while minimizing the risk that I'm assuming.
(Joel Beasley at 00:09:51) And so SSL was just, okay. And then it's subsequently gotten a lot easier. There's been all sorts of projects. I think it was OpenSSL. Different hosts and vendors—we won't name specific ones—but they've implemented various ways of, you can get a basic free SSL by clicking one button, or you can go get a paid one and stuff like that. Do you know, is there a difference between the free SSL that you can get and then paying for an SSL?
(Taher Elgamal at 00:10:19) Not in terms of the protocol definitions.
(Joel Beasley at 00:10:21) Okay.
(Taher Elgamal at 00:10:22) The IETF was the right party to bring into this because people have to abide by what the protocol says, because we wanted interoperability across. That's actually the most important thing. So the difference when you get a paid SSL is that you get support from the vendor, which a lot of people want and need, and there's nothing wrong with that. And if an entity knows how to handle open source, they just bring the open source. It's completely free for people to do whatever they wish.
(Joel Beasley at 00:10:53) I want to talk a little bit about you and your career. You clearly are crushing it, right? When you get to a position where you are, you happen to be very technically competent, but also good as a leader. And so I'm curious, how do you manage it, or how do you look at it? Do you spend a bucket of your time improving as a leader and then dedicated time understanding the technology? How do you stay in the details when you're so high?
(Taher Elgamal at 00:11:19) You know, I wish there was a silver bullet there. I just do fun things is the answer to you. So when I left Netscape, I said, what should I do now? And I was still in my forties. You know, I need to do something. I'm not going to be able to retire.
(Taher Elgamal at 00:11:37) So I started a company. So I actually threw myself into what does it mean to be a CEO of a young startup. You know, that company got sold. So I just do the things that I believe are the right use of time. There's no really magic formula there.
(Taher Elgamal at 00:11:54) I want and need to stay technical because that's my background. I don't write code anymore. I haven't written code in a while. That actually needs a lot of focus. But I need to know if somebody's kind of saying the truth or BSing a little bit.
(Joel Beasley at 00:12:10) Yeah. And you're surrounded by experts too in the act of your everyday. So you're picking up stuff by being around all of these people having these conversations.
(Taher Elgamal at 00:12:20) All the time. And you know, as they say, if you don't learn every day, there's something wrong. So we all have to learn something new every single day. Otherwise, life gets very boring.
(Joel Beasley at 00:12:30) How did you meet Parker Harris and Marc Benioff and all of them?
(Taher Elgamal at 00:12:35) Interesting. So I started Securify in '98 when I was leaving Netscape. Marc Benioff was an angel investor in that company. So I met him before Salesforce ever started, actually. He was still at Oracle, and we met in that cafeteria in Oracle, which is a fifteen-minute drive from my home.
(Taher Elgamal at 00:12:57) And he agreed to invest in the company. So I actually know him personally. When the opportunity for the Security CTO came up some ten years ago, I actually pinged him and said, hey, is this real or is this a fictitious thing that I just heard about? So, you know, it turns out that it was real, and I got contacted by the company and I interviewed, and I'm still here.
(Taher Elgamal at 00:13:20) It's a very enjoyable place because the growth the company has experienced is awesome. And, you know, building an enterprise application suite in the cloud is just a magnificent thing. It is where the future is going for sure.
(Joel Beasley at 00:13:34) Well, and I'm a fan of the Salesforce culture, even though I don't participate in it. I've had the following exposure to it. I got to meet Parker a few years ago when he came on the show, and that was my first sort of flag to pay attention to the culture there because of the types of conferences you guys put on and the events and all of that. And then secondly, I met, through one of the funds that invested in me, I met a company that does a lot of marketing work with you. It's one of your partners or something of that nature. And their culture was really good, and then I found out that you're one of their bigger clients. And then they were telling me about the work that they did with you guys, and it just kind of made sense. Salesforce has built this ecosystem of vendors and partners and clients that all have a very similar style and personality, and it aligns with who I am and how I run my company.
(Joel Beasley at 00:14:24) So while I don't do anything directly with Salesforce other than these interviews every once in a while, I really enjoy what they have built. Is that one of the things that attracted you to want to work there?
(Taher Elgamal at 00:14:34) So the culture at Salesforce is very well known. It's transparent. It's just a great group of people. You go and talk to anyone about any topic, and everybody's open to discussions. And the company does do what it preaches.
(Taher Elgamal at 00:14:49) The amount of give back that this company does in the world is amazing. And you refer to it as an ecosystem. It's actually more of an economy than just an ecosystem. There are millions of people who benefit from the Salesforce economy and built careers.
(Taher Elgamal at 00:15:06) Not being inside of Salesforce, but being in the ecosystem. That is just amazing. And that was part of the vision from the beginning.
(Joel Beasley at 00:15:14) How do you—you could do anything you want in the world, right? You've got the credentials, you've got everything needed. How do you view how you spend your time at Salesforce?
(Taher Elgamal at 00:15:24) I mean, look, I'm a software guy at the end of the day, right? So since my very first job after I graduated from Stanford, I'm a software guy. So the idea of running software in the cloud makes a lot of sense for anybody who's in the method of building new things for the world. So thinking about who is going to try to attack, what the nature of attacks look like. And this is not a Salesforce-specific thing.
(Taher Elgamal at 00:15:55) This is for all connected entities, which is everybody these days. So any connected company has people thinking about who the attackers might be, what are they likely to do, what are the assets that we have that we want to protect. You know, how do we collaborate with each other to make sure that we all know who's doing what and so on and so forth. You know, Salesforce included, basically. The security program covers all aspects of cybersecurity and things around cybersecurity. So there are certain threats that basically get on top of mind depending on the time.
(Taher Elgamal at 00:16:35) But in general, it's the complete security program that we think about.
(Joel Beasley at 00:16:41) What is the security thing, for lack of a better term, that all businesses should be thinking about? Because there's so many different areas to focus. There's so many different security companies selling different nightmares. What's the one thing that people should at least make sure they have as a basic base covered?
(Taher Elgamal at 00:17:00) This is an involved question. You're looking for a single answer, so I'm going to answer it in a different way, if you don't mind.
(Joel Beasley at 00:17:07) Perfect, yeah.
(Taher Elgamal at 00:17:08) So there are certain things that you have to do yourself as a business. And number one is understanding what the business actually is. Who the customers are and what the relationships look like and what do you actually care about. Because whoever is going to attack is going to attack something that you care about that has something of value, right? Because that's why businesses exist. So every business needs to understand what they have that people would like to steal or destroy or whatever. We are, in fact, all connected today. If you look at attacks and how attacks have been successful, 90 some plus percent of the successful breaches were because somebody used a bad password. It's so silly.
(Taher Elgamal at 00:17:54) You know, we're in 2022 now. We're 25 plus years in this journey. And people still use passwords that I can get sitting here in about two minutes. So that is actually the number one attack vector. It's kind of simple.
(Taher Elgamal at 00:18:08) So, you know, Salesforce went out a couple of years back and said, hey, all Salesforce customers use multi-factor auth. And there is multi-factor auth in a lot of different places. Some of them are probably harder than others to open up and stuff. But at least not use a single password to log into the Salesforce ecosystem because that is the number one attack vector by a lot. So yeah, if I were to advise somebody, force all your users to update your authentication. Just don't allow a password to be the only authenticator.
(Joel Beasley at 00:18:45) There's been a lot of talk about passwordless, like no password authentication.
(Taher Elgamal at 00:18:51) Mhmm.
(Intro Narrator at 00:18:52) It
(Joel Beasley at 00:18:52) seems a little bit ambiguous. Is there a couple different implementations of this? What is it? How do you describe it from a high level?
(Taher Elgamal at 00:19:00) So, you know, a password is not a natural thing in the, should not have been a natural thing in the Internet to begin with. And people think it is my fault, actually, that passwords exist in the way they existed. So I accept the blame. The reason is inside of SSL, which is any connection you connect to anything these days has an SSL connection. Inside of SSL, there is an option that allows the client, the user to cryptographically prove themselves to the back end. But that was an option, was not actually made as a mandatory thing. The connection from the server back is mandatory to have the cryptographic support. So that when you go to your bank, you actually do know that it's your bank and it's nobody imitating the bank sort of thing. But because we had no idea how to get billions of people to use cryptographic keys and manage that, we said, you know, we'll just make it an option. Password idea started in IBM research in the sixties. The idea of a password. And was not for connecting to outside resources. It was actually done so that researchers inside of IBM, when they come in the morning, they see the stuff they do. They're not trying to prevent others from seeing it. It was a productivity tool rather than a security tool.
(Taher Elgamal at 00:20:32) So we decided to use it as a security tool. There is no requirement that you have to have a password to log into your bank or to your e-commerce thing. It's not a part of the ecosystem. It's just needed because the back end needs to know who their customers are. So say you have to provision something. So there is a number of different ways that the world now is providing that removes passwords completely. Some of them use biometrics, for example. Some of them use technology, actual cryptographic technology. Some of there's a number of different ways. But the password is not a necessary part of this digital economy ecosystem. It actually is not. It is here just because, but
(Joel Beasley at 00:21:18) So biometric, that's one way of doing it. Cryptographic, another way of doing it. Can you explain to me the cryptographic way of doing it? I understand scanning my face or some sort of biometric thumbprint or something like that. I don't understand the cryptographic thing. Do I get some sort of key that I hold or?
(Taher Elgamal at 00:21:37) Yeah. So you get a key on the device, and you kind of provision some flavor of the key to the back end that you want to log into, so they know that this is that person. So in the back end, they bind the individual with the device and the key and that kind of thing. And then when you log in, you just say, hey, I use my face recognition to log in to my phone. And the bank knows the phone and knows me and knows that I logged in using my face. And that key will prove to the back end that this is the same thing, basically. It's rather actually straightforward.
(Joel Beasley at 00:22:16) So it's similar, it's just like when I push code up to GitHub, it's looking at my key, and
(Taher Elgamal at 00:22:21) That's
(Joel Beasley at 00:22:21) how I don't have to enter a password when I push the code because it might
(Taher Elgamal at 00:22:25) Well, I mean, you have a GitHub account.
(Joel Beasley at 00:22:27) But when I push code, though, I have the key inside of my, stored.
(Taher Elgamal at 00:22:31) Absolutely.
(Joel Beasley at 00:22:32) Yeah. And so just using that. Yeah.
(Taher Elgamal at 00:22:34) And that's how they know who that person is. So you just need to prove that this is this person.
(Joel Beasley at 00:22:40) Okay.
(Taher Elgamal at 00:22:41) And depending on the severity of what actually the communications look like, you can have higher and higher levels of authentication. You know, for a GitHub connection, they just want to know it's you. You would probably be annoyed if somebody intercepted that push and adds a few lines of code before it goes to GitHub. That would be annoying, right? That would be very,
(Joel Beasley at 00:23:04) that would be unacceptable.
(Taher Elgamal at 00:23:05) Yeah. There you go. So SSL covers these kinds of things. It actually has an integrity check that whatever you sent is the same thing that got received, and it will actually not accept the connection if something changes.
(Joel Beasley at 00:23:19) That way, if you're attacked by, let's say a government that actually has a lower level in the OSI, right, and they could grab data and manipulate it on its path. So this I
(Taher Elgamal at 00:23:29) don't know what your code looks like, my friend, but the government doesn't care about your code at all unless you're writing something that I do not know.
(Joel Beasley at 00:23:37) No comment.
(Taher Elgamal at 00:23:37) So different entities will care about different communication channels. Yeah. Thieves want to steal money. That's what they do for a living. It's their job description. So they want connections to financial institutions. That's what they do. And then if there is a way for them to get some of the money their way, they will do it. Governments want to know what their enemies are doing and what whoever they believe their enemies are. But, you know, they're not going to intercept the thing because you're buying shoes from Nike. I mean, it's like, who cares?
(Joel Beasley at 00:24:08) Let's talk about the next big exciting thing that is coming with Salesforce that you're allowed to talk about publicly.
(Taher Elgamal at 00:24:15) You know, Dreamforce was not too long ago. As you mentioned, Salesforce does an amazing job with these events. We finally had an in-person event, you know, a couple of months back. And we had some tens of thousands of people running around San Francisco talking about the new world. And so, you know, the biggest piece of what was announced was what we're calling Genie now, which is kind of how Salesforce manages data. So if you're a Salesforce customer, you'll get data about your customers in the Salesforce ecosystem. And you would understand what they have done in the past. Did you market to them? All kinds of data from different aspects of a customer. And you'll be able to basically enable your business, grow your business, whatever it is that you need to do. Getting to know the customer more is a big, huge push at Salesforce today and has been for several years. But Genie is about data. I'm not a marketing guy, so why it was called Genie is not my issue.
(Joel Beasley at 00:25:18) If a security professional, executive, technologist type person is looking to improve and grow at their career path in security, who should they be reading? What type of activity should they be performing?
(Taher Elgamal at 00:25:31) The security profession, honestly, the best thing is to participate in the security groups. There is a number of circles of security, CISOs and security professionals that meet in different places under different umbrellas, all over the world. It is really important to get the knowledge firsthand from someone who's actually doing these things. It's hard to read a book today about what should a CISO do. And the reason is, six months from now, we will in fact change. The threats are changing. The world is actually changing. We get to face things that we did not anticipate two years ago. So belonging to these groups, in my opinion, is probably the most important thing to do. Be up to date on things. It's a very, very fast-moving part of the technology world, actually.
(Joel Beasley at 00:26:28) From a leadership perspective and, you know, the sense of growing your career, when you founded those companies, what was some of the lessons that you learned from a leadership perspective that's helped you be a better leader today?
(Taher Elgamal at 00:26:44) You know, people are the most important assets your organization has. That's what you learn very quickly. There's a word in technology that we always refer to, which is disagree but commit. So that's actually really important. You cannot get 10 people in one room and expect they're going to agree. Because people just don't have the same opinion about anything. But you have to commit. So after we've disagreed, a decision was made, everybody in an organization needs to go after the same goal. If there are people trying to serve their own personal businesses or their own personal things, that actually destroys organizations. And I have seen that firsthand. So it's the team that is the most important thing. And leaders of small, medium and large organizations all learn this. Be transparent with people. You know, this is the 21st century. It's not 1950 anymore. So the old style management doesn't even exist anymore. Be transparent, be open, but make a firm decision and demand that people actually follow the decision. There is no, you can have your opinion. You can state things. But people do have to follow the decision when the decision is in fact made.
(Joel Beasley at 00:28:03) How do you, when you're hiring, how do you find people that you believe will be, you know, A players and do well within your team?
(Taher Elgamal at 00:28:13) People are history. So there is multiple things. If you're hiring experienced people, whether they're in the security space or just in general in technology, they're actually known. Their backgrounds are known. Somebody has known them before. They've done A, B, and C. They've done good work. They have contributed. So it's a matter of fit in what you need to achieve versus what they have done in the past. When you're hiring the younger people graduating from college, you're just sensing what the basic skills are. Because college grads can learn about everything and very quickly. So you can actually sense when you're talking to an individual what their appetite looks like. Are they going to really pivot into a new direction if that is what is needed and so on and so forth. So intelligence is interesting, but it's really the aptitude about belonging to a business that is the most important thing.
(Joel Beasley at 00:29:13) What questions am I not asking?
(Taher Elgamal at 00:29:15) Well, you asked me what I do every day and I never answered you. If you noticed. Yeah. Because every day is different. There is no typical day. I talk to customers a lot because Salesforce is extremely customer centric. It's all about what the customer needs and wants. So I talk to customers a lot. You know, obviously I talk to a lot of the internal technical teams and so on. I talk to security peers across the world. And I talk to good people like yourself. I actually just did a webinar half an hour before you and I started here. So I do this kind of thing fairly regularly.
(Joel Beasley at 00:29:56) What was the topic?
(Taher Elgamal at 00:29:58) So, in my usual way of answering questions, if I rewind a couple of years, I was chosen as a Marconi Fellow in 2019. The Marconi Society existed for a while. And they choose, every year they choose one individual worldwide who contributed to communications. Because Marconi is Marconi, right? He's the inventor of the radio. So every year, one person, or sometimes two, gets chosen as a Marconi fellow. So I was chosen with Paul Kocher as Marconi Fellow in 2019. So that was actually a webinar that the Marconi Society was sponsoring to talk about the digital inclusion over the next 10 years, which is a rather intriguing topic.
(Joel Beasley at 00:30:50) Well, what's the context? What is digital inclusion?
(Taher Elgamal at 00:30:54) You know, people talk about the digital divide all the time. People in poorer countries don't get the connectivity that we get here. We're lucky. Right? We're fortunate to be here. We know that. But part of the promise of this global Internet is to bring people together. It is in fact really a new society that we're putting together. It's not perfect. It never will be perfect. But it has a lot of promise. And, you know, we're all here for a reason. So we can exchange views while using this wonderful system here that you guys put together. I don't know which thing is this. And we can learn from each other a lot quicker. We get access to data. We get access to information. It's sort of unfortunate that some of the information is actually not completely trustworthy because we don't actually know the real source for some of that stuff. So it's, honestly, it's like we're building a new society but it's a lot more global than anything that humanity has ever done before. And, you know, so the individuals on, in that webinar were really amazing. Irwin Jacobs, Maury Cooper, I mean, people who invented mobile, the founder of Qualcomm. It was just an unbelievable collection of people participating. So everybody has their own sort of view on what this world should look like. And how do we include everyone? There is 7 billion people on the planet. We believe that maybe 60% of that 7 billion are actually connected.
(Joel Beasley at 00:32:24) Really?
(Taher Elgamal at 00:32:24) So there is a number of people who are not. And, you know, 60% of 7 billion is a very large number of people. And they are in all parts of the world. Obviously the poorer places struggle to get connectivity, so you're not going to see these people. But, you know, honestly some of these people may have as big a promise or bigger promise than anybody else. So how do we bring humanity into this ecosystem and allow people to excel at what they want to excel at? And that was the premise of the webinar.
(Joel Beasley at 00:32:57) Very cool. I happened to, before the pandemic, I lived in Florida and cookie cutter neighborhood type deal. And then we sold everything, bought an RV, traveled around the US for 10 months with the kids, and we found this little farm out in just outside of Nashville, Tennessee. And the interesting thing about this was it had gigabit fiber and it's in the middle of nowhere.
(Joel Beasley at 00:33:19) And then I found out that there was a government program that paid the service providers to run lines specifically to rural areas. Partly Musk tapped into it a little bit with the Starlink funding as well. And so I was really grateful for that. I tell everyone it's my favorite government program. So yeah, we're doing that.
(Joel Beasley at 00:33:39) Like, as a people, we are incentivizing and we're working towards this.
(Taher Elgamal at 00:33:43) Mhmm.
(Joel Beasley at 00:33:44) I'm not surprised when you say 60%. The engineering side of me wants to dig deeper into that number. Like, did they age adjust for kids who can't technically use the Internet?
(Taher Elgamal at 00:33:55) Hey, hey, hey, hey, hey.
(Taher Elgamal at 00:33:57) The Gen Zs are much better at using the Internet than I will ever be. Yeah. So the younger people are born into this world. This is just part of their world.
(Joel Beasley at 00:34:07) Yeah. But when they say—I guess to clarify—when they say that there's 7 billion people and 60% are connected, are they doing that based off of household and access to Internet, or are they saying a one-month-old isn't connected because they're one month old?
(Taher Elgamal at 00:34:22) I don't think they're talking about the one-month-old individuals. They are talking about the poor environments
(Joel Beasley at 00:34:29) Got it.
(Taher Elgamal at 00:34:30) who were not funded by their government to get a fiber link into their neighborhoods.
(Joel Beasley at 00:34:37) How are we solving this currently? I mean, I'd seen Zuckerberg did something where he flew a drone that could operate for a long term, and I don't know if that was just a test or a project or if it actually became something. How are we helping as the world, in this group that you're a part of? What are the big ideas to get these people online?
(Taher Elgamal at 00:34:54) Governments have to play in this game. They need to support their people. Some governments want to support their people. Some governments honestly want to prevent their people from gaining access to things. So you can add your own a little bit there.
(Taher Elgamal at 00:35:08) The Marconi Society itself is a nonprofit. It just tries to get people to talk about interesting things and promote certain ideas and so on. So it's a matter of bringing the cost of connectivity down and enabling more endpoints to participate. Obviously the WiFi—the mobile WiFi—increased the connectivity by a lot, because the vast majority of people in the world do not own a laptop and never will. You know, the IoT thing that we talk about in this industry is kind of intriguing because we're connecting devices that are not meant to communicate, but they are actually part of the network.
(Taher Elgamal at 00:35:51) So bringing the cost down becomes really important because these are really poor countries and poor areas that honestly cannot afford to bring a fiber link.
(Joel Beasley at 00:36:02) Is the competition in the economy doing that? Is it bringing the cost down?
(Taher Elgamal at 00:36:07) Yeah. There's a lot of efforts to actually bring the cost down, absolutely, from the chip all the way up to the end product.
(Joel Beasley at 00:36:14) Other than security, what would you say is one of your greatest technology interest topics?
(Taher Elgamal at 00:36:20) Interesting question. You know, security to me, when I started out, was an exercise of mathematics. I was not actually a security person. I was a cryptographer when I started. And cryptography is basically built on mathematics.
(Taher Elgamal at 00:36:39) So math was actually what I enjoyed. When I grew up into the security world, as that economy grew, trust is actually the most important thing. How do you trust the source of information? So that kind of thing I spent time just thinking through. It's really very interesting.
(Taher Elgamal at 00:36:57) I have not spent technically enough time on machine learning or any of that stuff, although I have interest clearly, because it affects the society today and it will probably have a bigger effect tomorrow. So understanding how that works is very intriguing. But basically I live in the internet. When I started with Netscape, I spent a bunch of years in the payment ecosystem.
(Taher Elgamal at 00:37:21) So payment companies were the number one target, because we wanted transactions. And to do a transaction, you just talk to payment people also. So the payment companies were actually a very, really early target for us to talk to.
(Joel Beasley at 00:37:36) If you could go back in time to when you first started working, your first day of work at your first real big job, and you could give yourself one piece of advice, what would it be?
(Taher Elgamal at 00:37:48) So I started at Hewlett Packard Labs in '84 when I finished my PhD at Stanford. I was still mostly academic because I'm just a PhD graduate, and I did not work in the industry before. Right now I'm a true industry person. Focusing on connections with people would be my advice to myself. The thing I actually enjoy the most is talking to people.
(Taher Elgamal at 00:38:15) Because that's where you learn. That's where you accomplish things. That's where things really progress. The nature of me as an academic was, hey, I'm going to invent the next few things. I'm going to hide myself in my room and go work some stuff out.
(Taher Elgamal at 00:38:29) That would have been the advice I would give myself because I've built a lot of good partnerships and relationships in the industry over the years that I cherish quite a lot.
(Joel Beasley at 00:38:41) What's the best advice for people who don't have a lot of relationships currently and they want to go out there and work on what you just said? They want to go out there and get more relationships. How do they do that?
(Taher Elgamal at 00:38:54) People want to know them just as much as they want to know people. It's the thing that is sometimes hard to see. You know, a lot of people in the technical world are introverted just naturally. You don't have to do anything about it. But that does not mean that these introverted people do not want to know others.
(Taher Elgamal at 00:39:11) They just do not know how to go about it. You know, you start with—just like accomplishing any big thing in the world—you do baby steps, and you see the successes and you see the failures and you learn from both, as it turns out. Just be very explicit about wanting to do that rather than feel comfortable.
(Joel Beasley at 00:39:32) I like that. It's one of the main drivers when I started this show, was to just know more people. I never expected it to become my full-time job. I thought it would—you know, I'd get a VP of Engineering at Salesforce or something, right?
(Joel Beasley at 00:39:45) Some cool big company.
(Taher Elgamal at 00:39:46) You're welcome to apply.
(Joel Beasley at 00:39:47) Yeah. And through this, it ended up becoming my full-time job. But one of the things that was driving me was to know people, to be able to speak better, to be able to speak publicly, and just to get better at that. And one of the things that actually scared me, to your point of baby steps, was I would fear being on a stage in front of hundreds of people or thousands. Well, it turns out, when you want to start, no one's going to let you on a stage in front of hundreds of people.
(Joel Beasley at 00:40:14) You start with a table, you start with a small group, and then you work your way up, and then it's a long process. And then, you know, your group size will grow, and you'll go from speaking to the table or the people that'll listen to you to maybe a small room, and then that'll happen for a year or so, and then you'll go—and then eventually, you find yourself one day getting off the stage after talking to 5,000 people, and you're like, oh, this is kind of how it happens.
(Taher Elgamal at 00:40:38) I was actually trained professionally while at Netscape to do public speaking.
(Joel Beasley at 00:40:43) Really?
(Taher Elgamal at 00:40:44) Yes. So I committed to it. So did the company. Because, in those days, talking about internet security was an unknown topic. I mean, who would actually understand what the heck that was 25 years ago?
(Taher Elgamal at 00:40:58) But somehow, because Netscape was selling things to companies, the company needed someone to actually speak about security. And sometimes in a smaller group, sometimes with a single customer, sometimes in a big audience. And the first time they threw me in RSA to talk to a 5,000-person audience, honestly, it was a scary event. Because it's not something that I've done before and I'm naturally introverted, just like a lot of technology people. But it was an awesome experience.
(Taher Elgamal at 00:41:28) And, you know, I enjoyed it. I think the audience didn't kick me off, so I think it was okay. Yeah. But it is actually a tough experience. It's not a simple thing that just happens by nature.
(Joel Beasley at 00:41:38) Right.
(Taher Elgamal at 00:41:40) When you talk to a big audience, it's actually very different. And that's what I was taught back then. It's completely different from talking to a small audience. You know, how do you focus? How do you look people in the eye?
(Taher Elgamal at 00:41:52) Who do you focus on? When you have 5,000 people, you're not going to see the people in the audience. It's like you're an entertainer at that point in time. Now there's content that people want to get. So it's not like it's a random entertainment.
(Taher Elgamal at 00:42:04) But it's almost like being an entertainer. When you're presenting to 10 people in a room, you're actually talking about a subject that we had agreed on and there is an agenda and that kind of thing, which I still do quite a bit.
(Joel Beasley at 00:42:18) What are some tips for speaking to a large audience?
(Taher Elgamal at 00:42:22) You know, what I was taught is look at the back of the room kind of thing. Don't look at your feet and do not hesitate. If your thought process got interrupted—because we're all humans and, you know, our brain kind of does whatever it wants to do every once in a while—always have a backup thing you want to say at any point in time. So when you get in the middle, have a story. And people love stories, so have a couple of stories in the back of your mind. Whenever you get a lull in your presentation, just say one of these stories.
(Taher Elgamal at 00:42:56) It actually works really well.
(Joel Beasley at 00:42:58) I see comics do this. Like, sometimes they'll forget.
(Taher Elgamal at 00:43:01) Well, I mean, comics are entertainers. It's not very different from speaking in front of 5,000 people. It's a different thing, but yes.
(Joel Beasley at 00:43:07) Yeah. This is great. I want to be respectful of your time. Is there anything else, any maybe calls to action? Go join salesforce.com, go apply, go get a job at Salesforce? Any calls to action that we want to get out there to the world?
(Taher Elgamal at 00:43:22) No. I think you should use Salesforce as a customer more than anything else, actually.
(Joel Beasley at 00:43:26) Use Salesforce. Yes. Boom. You nailed it. We made a podcast.
(Joel Beasley at 00:43:30) How do you feel?
(Taher Elgamal at 00:43:32) It's great.
(Joel Beasley at 00:43:34) Thank you so much for listening. And if you found this episode useful, please share it with a friend or colleague who you think would get value from it. And if you have topics that you'd like to hear discussed on the podcast, either add me on LinkedIn or send me an email, [email protected]. Every time I get an email or LinkedIn message, it absolutely makes my day and inspires me to keep going.