Episode 632 ·
TECH TITANS: How to Grow as a Security Professional with Taher Elgamal, Father of SSL
For the next 3 episodes, we are doing something very special. We are taking the best leadership episodes from the most popular past guest and distilling them down to 10-minute segments to turbocharge your leadership. If you want even more 10-minute condensed leadership episodes you can subscribe to Joel Beasley | Tech Titans in your podcast app. Taher Elgamal, Father of SSL, joins us in this episode to share his greatest leadership advice on growing as a security professional.
All of this right here, right now, on the Modern CTO Podcast!
Check out more of Taher at https://www.linkedin.com/in/taherelgamal/!
Check out more about Tech Titans on Spotify, Apple, and iHeart!
Produced by ProSeries Media.

About Taher Elgamal:
Dr. Taher Elgamal is an internationally respected information security leader and cryptographer. He was the recipient of the lifetime achievement award from the RSA conference in 2009. He has successfully served as CISO, Chief Scientist, CTO, as well as founder and CEO of numerous key organizations. Dr. Elgamal invented several industry and government standards in data security and digital signatures for areas including the DSS government standard for digital signatures. He is recognized in the industry as the "father" of SSL.
About Evolution Equity Partners:
Evolution Equity Partners is an international venture capital investor leveraging deep sector expertise to help exceptional entrepreneurs develop market leading companies.
Evolution has invested in the US, Europe and in emerging markets and assists portfolio companies to expand in new markets.
Segments where Evolution invests include: Information Security, Enterprise Software & Solutions, Consumer
Current and previous portfolio companies include AVG Technologies (AVG : NYSE), Cognitive Security (CSCO : NASDAQ), OpenDNS, SecurityScorecard, 60K, NEJ-TV among others
Transcript
(Intro Narrator at 00:00:00) For the next three episodes, we're doing something very special. We're taking the best leadership episodes from the most popular past guests and distilling them down to ten-minute segments to turbocharge your leadership. If you want even more ten-minute condensed leadership episodes, you can subscribe to Joel Beasley Tech Titans in your podcast app. Taher from Salesforce joins us in this episode to share his best advice on growing as a security professional. You're listening to Joel Beasley Tech Titans.
(Joel Beasley at 00:00:34) Our audience is comprised of people who want to grow in their technical career. Maybe they just got pushed into first-time management, and that's one section. The other section is VP of engineering types who want to become into the C-suite, and then the last one is the C-suite wanting to listen to their peers. There's security professionals all the way up and down that stack.
(Joel Beasley at 00:00:55) So in general, if a security professional, executive, technologist-type person is looking to improve and grow at their career path in security, who should they be reading? What type of activity should they be performing?
(Taher at 00:01:13) The security profession, honestly, the best thing is to participate in the security groups. There is a number of circles of security for CISOs and security professionals that meet in different places under different umbrellas all over the world. It is really important to get the knowledge firsthand from someone who's actually doing these things. It's hard to read a book today about what should a CISO do, and the reason is six months from now we will in fact change that. The threats are changing. The world is actually changing. We get to face things that we did not anticipate two years ago. So belonging to these groups, in my opinion, is probably the most important thing to do. Be up to date on things.
(Taher at 00:02:00) It's a very, very fast-moving part of the technology world, actually.
(Joel Beasley at 00:02:05) From a leadership perspective and, you know, the sense of growing your career, when you founded those companies, what were some of the lessons that you learned from a leadership perspective that's helped you be a better leader today?
(Taher at 00:02:19) People are the most important assets any organization has. That's what you learn very quickly. There's a word in technology that we always refer to, which is "disagree but commit." So that's actually really—you cannot get ten people in one room and expect they're going to agree because people just don't have the same opinion about anything. But you have to commit. So after we've disagreed, a decision was made. Everybody in an organization needs to go after the same goal. If there are people trying to serve their own personal businesses or their own personal things, that actually destroys organizations, and I have seen that firsthand. So it's the team that is the most important thing.
(Taher at 00:03:06) Leaders of small, medium, and large organizations all learn this. Be transparent with people. You know, this is the twenty-first century. It's not 1950 anymore. So the old-style management doesn't even exist anymore. Be transparent, be open, but make a firm decision and demand that people actually follow the decision. You can have your opinion, you can state things, but people do have to follow the decision when the decision is in fact made.
(Joel Beasley at 00:03:40) What is the security thing, for lack of a better term, that all businesses should be thinking about? Because there's so many different areas to focus. There's so many different security companies selling different nightmares. What's the one thing that people should at least make sure they have as a basic base covered?
(Taher at 00:03:58) This is an involved question. Different way, if you don't mind. Perfect. Yeah. So there are certain things that you have to do yourself as a business, and number one is understanding what the business actually is, who the customers are, and what the relationships look like, and what do you actually care about. Because whoever is going to attack is going to attack something that you care about that has something of value, right? Because that's why businesses exist. Every business needs to understand what they have that people would like to steal or destroy or whatever. We are in fact all connected today. If you look at attacks and how attacks have been successful, 90-some-plus percent of the successful breaches were because somebody used a bad password. It's so silly.
(Taher at 00:04:51) You know, we're in 2022 now. We're twenty-five-plus years in this journey, and people still use passwords that I can get sitting here in about two minutes. So that is actually the number one attack vector. It's kind of simple. So, you know, Salesforce went out a couple of years back and said, "Hey, all Salesforce customers, use multifactor auth." And, you know, there's multifactor auth in a lot of different places. Some of them are probably harder than others to open up and stuff. But at least not use a single password to log into the Salesforce ecosystem because that is the number one attack vector. Walk by a lot. So, yeah, if I were to advise somebody, force all your users to update your authentication. Just don't allow a password to be the only authenticator.
(Joel Beasley at 00:05:43) There's been a lot of talk about passwordless, like no-password authentication.
(Taher at 00:05:49) Mm-hmm.
(Joel Beasley at 00:05:50) It seems a little bit ambiguous. Is there a couple different implementations of this? What is it? How do you describe it from a high level?
(Taher at 00:05:58) So, you know, a password is not a natural thing in the—should not have been a natural thing in the internet to begin with. And people think it is my fault, actually, that passwords exist in the way they existed. So I accept the blame. The reason is inside of SSL, which is any connection you connect to anything these days has an SSL connection. Inside of SSL, there is an option that allows the client, the user, to cryptographically prove themselves to the back end. But that was an option. It was not actually made as a mandatory thing. The connection from the server back is mandatory to have the cryptographic support so that when you go to your bank, you actually do know that it's your bank and there's nobody imitating the bank, sort of thing.
(Taher at 00:06:47) But because, you know, we had no idea how to get billions of people to use cryptographic keys and manage that, so we said we'll just make it an option, let people use it. And that's how passwords started, actually, believe it or not. The password idea started in IBM Research in the sixties. The idea of a password, and it was not for connecting to outside resources. It was actually done so that researchers inside of IBM, when they come in the morning, they see the stuff they do. They're not trying to prevent others from seeing it. It just was a productivity tool rather than a security tool.
(Taher at 00:07:27) So we decided to use it as a security tool. There is no requirement that you have to have a password to log into your bank or to an e-commerce thing. It's not a part of the ecosystem. It just needed because, you know, the back end needs to know who their customers are. So say you have to provision something. So there is a number of different ways that the world now is providing that removes passwords completely. Some of them use biometrics, for example. Some of them use technology, actual cryptographic technology. Some of—there's a number of different ways. The password is not a necessary part of this digital economy ecosystem. It actually is not. It is here just because.
(Joel Beasley at 00:08:13) If you could go back in time to when you first started working, your first day of work at your first real big job, and you could give yourself one piece of advice, what would it be?
(Taher at 00:08:23) So I started at Hewlett Packard Labs in '84 when I finished my PhD at Stanford. I was still mostly academic because I'm just a PhD graduate. I did not work in the industry before. Right now I'm a true industry person. Focusing on connections with people would be my advice to myself.
(Taher at 00:08:43) The thing I actually enjoy the most is talking to people, because that's where you learn, that's where you accomplish things, that's where things really progress. The nature of me as an academic was, "Hey, I'm going to invent the next few things. I'm going to hide myself from my room and, you know, go work some stuff out." That would have been the advice I would give myself, because I've built a lot of good partnerships and relationships in the industry over the years that I cherish quite a lot.
(Joel Beasley at 00:09:10) What's the best advice for people who don't have a lot of relationships currently and they want to go out there and work on what you just said? They want to go out there and get more relationships. How do they do that?
(Taher at 00:09:21) People want to know them just as much as they want to know people. It's the thing that is sometimes hard to see. You know, a lot of people in the technical world are introverted just naturally. You don't have to do anything about it. But that does not mean that these introverted people do not want to know others. They just do not know how to go about it. You know, you start with—just like accomplishing any big thing in the world—you do baby steps, and you see the successes and you see the failures, and you learn from both, as it turns out. And just be very explicit about wanting to do that rather than feel comfortable.
(Joel Beasley at 00:10:00) I like that. It's one of the main drivers when I started this show was to just know more people. I never expected it to become my full-time job. I thought it would, you know, I'd get a VP of engineering at Salesforce or something, right? Some cool big company. You're welcome to plug. And through this, it ended up becoming my full-time job. But one of the things that was driving me was to know people, to be able to speak better, to be able to speak publicly, and just to get better at that. And one of the things that actually scared me, to your point of baby steps, was I would fear being on a stage in front of hundreds of people or thousands. Well, it turns out when you want to start, no one's going to let you on a stage in front of hundreds of people. You start with a table. You start with a small group, and then you work your way up, and then it's a long process. And then, you know, you'll get an opportunity, and then all of a sudden your group size will grow, and you'll go from speaking to the table or the people that'll listen to you to maybe a small room, and then that'll happen for a year or so. And then you'll go, and then eventually you find yourself one day getting off the stage after talking to 5,000 people, and you're like, "Oh, this is kind of how it happens." You know, it's very slow and—
(Taher at 00:11:09) I was actually trained professionally while at Netscape to do public speaking.
(Joel Beasley at 00:11:14) Really?
(Taher at 00:11:15) Yes. So, and I committed to it. So did the company, because in those days, talking about internet security was an unknown topic. I mean, who would actually understand what the heck that was twenty-five years ago? But somehow, because Netscape was selling things to companies, the company needed someone to actually speak about security, and sometimes in a smaller group, sometimes with a single customer, sometimes in a big audience.
(Taher at 00:11:42) And the first time they threw me in RSA to talk to a 5,000-people audience—honestly, it was a scary event because it's not something that I've done before, and I'm naturally introverted just like a lot of technology people. But it was an awesome experience, and I enjoyed it. I think the audience didn't kick me off, so I think it was okay. But it is actually a tough experience. It's not a simple thing that just happens by nature. When you talk to a big audience, it's actually very different, and that's what I was taught back then.
(Taher at 00:12:13) It's completely different from talking to a small audience. You know, how do you focus? How do you look people in the eye? Who do you focus on? When you have 5,000 people, you're not going to see the people in the audience. It's like you're an entertainer at that point in time. Now, there's content that people want to get, so it's not like it's a random entertainment, but it's almost like being an entertainer. When you're presenting to ten people in a room, you're actually talking about a subject that we had agreed on, and there is an agenda and that kind of thing, which I still do quite a bit.
(Joel Beasley at 00:12:44) What are some tips for speaking to a large audience?
(Taher at 00:12:47) You know, what I was taught—if your thought process got interrupted, because we're all humans and, you know, our brain kind of does whatever it wants to do every once in a while—always have a backup thing you want to say at any point in time. So when you get in the middle, have a story, and people love stories. So have a couple of stories in the back of your mind. Whenever you get a lull in your presentation, just say one of these stories. It actually works really well.
(Taher at 00:13:15) Actually, comics do this. Well, I mean, comics are entertainers. It's not very different from speaking in front of 5,000 people. It's a different thing, but yes.