SPEAKER_00: a week before the super bowl happened in tampa the tampa water district got hacked and somebody SPEAKER_01: tried to poison the water what i was totally unaware of that wow they stopped it because SPEAKER_04: somebody was literally sitting at the computer and saw someone else moving the mouse whoa SPEAKER_10: that's an unplug the computer moment yeah holy cow this week in startups is brought to you by scalable path want to speed up your product development without breaking the bank since 2010 scalable path has helped over 300 companies hire deeply vetted engineers in their time zone visit scalablepath.com twist to get 20 off your first month northwest registered agent when starting your business it's important to use a service that will actually help you northwest registered agent is that service they'll form your company fast give you the documents you need to open a business bank account and even provide you with mail scanning and a business address to keep your personal privacy intact visit northwest registeredagent.com twist to get a 60 discount on your next llc and vanta compliance and security shouldn't be a deal breaker for startups to win new business vanta makes it easy for companies to get a sock to report fast twist listeners can get one thousand dollars off for a limited time at vanta.com twist all right everybody we are obsessed in 2023 and now in SPEAKER_14: 2024 with how artificial intelligence is impacting essentially everything we do in business in life and government education now ai gives you if you're a knowledge worker so many amazing tools i'm seeing people on my team get 10 percent 20 faster every month just by using these tools it is bonkers we've never seen anything like this but the truth is if the good guys can get better at their jobs SPEAKER_17: well the black hats the hackers can get better at their jobs as well just think about how powerful it is to use a language model to try to convince people of something in one of your blog posts or your email newsletters in fact grammarly lets you set that well the same technology can be used by hackers you know spoofing emails and the targets are always businesses hospitals critical infrastructure you know all that and the damage from ransomware last year alone 30 billion dollars the department of SPEAKER_18: homeland security said ransomware was the second most comfortable cyber crime and so today we have an expert in the field john miller is the ceo and co-founder of halcyon and they are building products that use ai to stop ransomware attacks before they happen and limit the damage they do SPEAKER_17: john welcome to the program thanks for having me let's talk a little bit about the threats and ransomware in general how does practically ransomware go down and who's doing this and what's their SPEAKER_18: motivation i mean it's pretty obvious but i think it's good to hear it from an expert yeah i mean it's SPEAKER_23: attacker group is growing day after day it used to be something that was heavily russian in origin and then into eastern europe and then you see some chinese actors at it but now we're seeing a renaissance right where people all over the world have figured out that you can just join one of these affiliate programs and you're a ransomware actor so we're in this interesting spot where you know not only do you have ai coming in and adding to automation and and scale and efficiency but more and more attackers are coming online now and they've been kind of bolstered by this economy where you know you have these large ransomware groups where you know a lot of them have ties to fsb or gru and they're actually building the tooling and operating it in a profit sharing capacity with SPEAKER_26: anyone that that wants to partake this is new news to me explain this how affiliate came to ransomware SPEAKER_14: because if you did have the super weapons to exploit people and do ransomware you would probably want to keep them for themselves but that something seems to have changed you this is the first i'm hearing SPEAKER_32: about these affiliate programs explain what absolutely so a great example of it is the mgm attack that SPEAKER_23: happened in las vegas and so there were two distinct groups that were involved in it one of them was called black cat those guys have ties to russian intelligence and they're a ransomware group on their own however they make their toolkit available to an affiliate network and so the group that actually carried it out has been called scattered spider which nobody is exactly sure where they are there was some assumptions that they were based in the united states because their english was so good in their written communications but that's been attributed by some people to the use of llms and help building their ransom notes but it was a completely new attacker group where they didn't have their own tooling and they they split the profits with the the black wow so this is interesting the the russians or you know SPEAKER_14: these other groups are now making the tools they make the weapons they say hey you go do your activity SPEAKER_39: chop it up 50 50. yeah yeah they do it too right and it's it's all different percentages um but it's not SPEAKER_23: like they stop the really sophisticated attackers will focus on the more sophisticated targets and then you have tiers of these attackers where you know you'll have people that specialize in going out and attacking and attacking hospitals right or you know 100 million dollar size manufacturers it's interesting where you're seeing essentially the internet kind of carved up into territories wow you have these different attacker groups that just keep kind of uh rinse and reusing the same techniques and tools over and over SPEAKER_46: how do they get away with it i guess is one of the questions that i think a lot of people have because SPEAKER_17: you know the internet you can be anonymous but there are ways to trace people and then when payments become involved there's ways to trace people so how do they remain anonymous during the attacks and the SPEAKER_48: communications and then how do they remain anonymous in the payment area so the payments are normally SPEAKER_23: done via cryptocurrency right and you know bitcoin is involved but they're washing services there are more secure currencies like monero that are used but for the most part there's no consequence like there's no police that are going to come arrest you right so 99.99 of of ransomware cases out there SPEAKER_14: there's there's no police that are that are chasing you down no fbi coming and saying hey we need to go stop this at the source would this be happening if crypto had not become so ubiquitous and available or is SPEAKER_23: crypto the the kerosene on this fire i mean crypto is definitely the kerosene on the fire it's really difficult to have someone deliver millions and millions of dollars in cash like logistically it's SPEAKER_27: it's it's complicated you know cryptocurrency has has definitely streamlined the business it did happen before there was cryptocurrency i think the biggest thing that's really exploded it is the fact that SPEAKER_23: attackers or people that weren't attackers are realizing that they can really do this consequence free and you know as long as you're not in the us or you know a first world european nation or something like that there's no response the government is for years has tried to keep computer hacking um kind of on the level of espionage right where it's not kinetic it doesn't merit a kinetic response and it's it's bled over into this now where we're not really set up to respond to you know an exponentially growing threat group like this that are you know it's completely willing to target our critical infrastructure our manufacturing at some point this is going to be so acute that SPEAKER_14: we're going to have to strike back in the in the real world and that's pretty obvious yeah i mean it's SPEAKER_60: obvious i don't know if it's going to happen it's not it's not where policy makers are going where SPEAKER_23: where they think they can solve it is by making it illegal for people so if nobody make it illegal to SPEAKER_27: pay the ransom yeah so imagine your business gets ransom or imagine your hospital that gets ransom and SPEAKER_23: you can't provide quality service to your patients which you know results in in death right um telling SPEAKER_32: them that they can't pay a ransom is a a very precarious spot to be in but now crypto people always SPEAKER_14: say to me oh have fun staying poor not going to make it and then when i make these points and then they also add to it well crypto is a hundred percent traced and the blockchain is immutable blah blah blah SPEAKER_29: blah therefore crypto makes it easier to catch criminals is that just them talking their own book SPEAKER_27: and and trying to protect themselves yeah you can wash cryptocurrency right you can put it through laundries online casinos there are services specifically for it you can chain hop right like transfer from bitcoin to monero or you know monero to woo or whatever you want dogecoin it SPEAKER_23: doesn't matter there's enough spots where you can mix it around where you can't track it anymore SPEAKER_69: they don't really need to go to that level of extreme because no one's really going after it SPEAKER_14: it's hard to balance hiring top tier developers and keeping your burn rate under control but these days i see a ton of founders successfully doing this by hiring remote talent so let me tell you about scalable path it's a software staffing company that can help you build an awesome remote developer team and the right developer isn't just a list of technical skills we all know that it's about their personality it's about their work ethic their motivation and their fit within your team and scalable path knows this so here's what they do their team will get to know your vision they're going to get to know your needs and then they're going to develop technical challenges tailored to the roles you're hiring for and these challenges are conducted live and on video so there's no gaming of the system you're going to get great people they also evaluate each candidate's soft skills like communication attitude and work style scalable path has completed more than 300 projects for their clients and they have a network of 30 000 developers they've been doing this for over a decade they know what they're doing so you're going to be in great hands here's the best part twist listeners get 20 off their first month if you're ready to scale your dev team and your business check out scalablepath.com twist once again that domain name scalablepath.com twist 20 off SPEAKER_39: the interesting thing with ransom ransomware is you negotiate with these guys right like you have live SPEAKER_23: communication with them both in the process after you've been ransomed and you're trying to get unransomed and negotiate how much to pay them as well as they'll support you after you've paid them to help SPEAKER_39: recover data so it's not like they're hiding deeply in the shadows and there's just no need for them to SPEAKER_14: so when they did this with caesars and mgm caesars i think just said okay or and one of them caesars just SPEAKER_74: paid 15 million bucks yeah and they were back online quickly so what they do is they take down your SPEAKER_75: systems they somehow lock them up and they have the data of the individuals that's the playbook SPEAKER_23: yeah so normally the first thing they'll do is actual trade your data and they do it like a smash and grab as fast as they can they'll overwhelm the connection pipes but take as much data out as possible and then what they'll do is they'll run encryption software where they'll just scour the whole hard disk and create encrypted versions of all the files and then delete the originals and then you pay them for that key to restore those files and then they call it double extortion you pay them to not publicly release the data that they stole got it so they got you two different ways yeah i mean an interesting one is um i think it was the black cat group i i don't want to uh offend any ransomware group for uh attributing something to to another one but about a month ago they actually reported their own breach to the sec where they ransomware the company the company was trying to keep it under wraps and they uh as the attacker did the disclosure that they were compromised yeah SPEAKER_14: because you do as a public company have to disclose these things now that's part of yeah SPEAKER_23: absolutely yeah and we've had laws you know for a bunch of years and you know at the state level and now we're getting more into like sec mandating uh reporting but you know the majority of these SPEAKER_27: attacks still go unreported if you're running a business and if you don't pay your business is SPEAKER_23: going to go under you're going to figure out what you need to do to pay and just keep it quiet how do SPEAKER_17: people stop this from happening because this is a system level you need to get keys to the kingdom in order to do one of these things which means you have to compromise a pretty serious it person's credentials or can you do this with just the ceo's credentials the cfo's credentials how do they get into the system what what level of keys do they need and then how do you stop it i know your company SPEAKER_83: obviously has has tools and services here but how do people practically stop this from happening our SPEAKER_23: company specializes in we've built an endpoint agent that complements kind of antivirus and edr and provides a another layer to stop it and then if if we miss it um actually recover the system we capture those keys so instead of having to pay for them we we have a copy and we can just use them the normal ingress for these is like phishing attacks right compromised credentials there have been so many password breaches over the years that you can take someone's email address and essentially figure out what the algorithm is they use in their head for creating passwords unless they use really SPEAKER_32: random passwords everywhere and they'll bake that into the the mountain and say you know here's here's SPEAKER_23: what we think five passwords probably are when you run you know try to connect to them the other interesting thing is there's another essentially marketplace where you have what are called initial access brokers right so there is an entire business of all i do is go out and try to get a small landing point inside of a big corporation and then i turn around and sell that so if you wanted to be a ransomware actor today you don't have to hack anything you go and join a ransomware group you go to initial access broker you buy the access you take the tool that you got from the ransomware group you run it there SPEAKER_92: you're done there so there are people who complexity is low so there's a marketplace now of people who SPEAKER_66: have hacked yeah numerous ones they will hack you know somebody in customer support somebody who's a SPEAKER_96: receptionist somebody who's a salesperson whatever it is that gets you into the building essentially SPEAKER_29: now you run this malware that you bought and we try to lateralize you capture cash passwords off of SPEAKER_23: the host right the interesting thing is these these ransomware guys have a lot of money now this is really successful so they can go out and do things like buy zero day vulnerabilities right explain what that is to people um a zero day vulnerability is a flaw in a piece of software that nobody knows is there so an individual researcher goes out and says i've figured out how to hack chrome browser in a way that nobody knows instead of telling anyone or disclosing it you know there are ransomware groups like lockbit that run open bug bounty programs you just reach out to them you tell SPEAKER_32: them what you found and they'll pay you for it and then they'll build that into their malware so this SPEAKER_29: hacker the black hats are offering bounties 100 against microsoft offering bounties or whoever and guess who SPEAKER_104: pays more i'm gonna guess the people who do ransomware pay more well they make money with it right SPEAKER_23: and so i think it was like two or three years ago we hit a point where those types of vulnerabilities were almost exclusively used by governments right intelligence agencies stuff like that then we hit a point where these these cyber criminals are actually using more of these zero day SPEAKER_108: vulnerabilities than than anyone else fascinating so explain how language models and ai has changed SPEAKER_109: the game because we knew it would um is it just people are writing clever emails now i mean you would SPEAKER_23: be amazed at how much ransomware starts with phishing and i'm sure you've gotten more phishing emails than you can count with your life yeah and normally they're pretty easy to pull off when it's like this is broken english like this isn't legit i mean you can use an llm to generate a phishing site for you i don't think that it's really widely being used by the ransomware groups they don't really need it but it is another um kind of fueling factor that's just allowing them to grow even more you get 10 20 performance uptick SPEAKER_00: if you use it right cut out some of the the busy work and give uh a finished product that's going SPEAKER_14: to be more successful the thing i i've recently uh been made aware of because i'm in the venture capital space there are large wires that sometimes you know somebody gets a distribution so a wire goes out SPEAKER_96: you're in a venture fund you're an lp and we're shipping you know oh we're distributing the stock from SPEAKER_17: coinbase or airbnb or from uber it's got to be wired to an account custodian account a bank account whatever it is if it's stock or cash and so there was a report going around silicon valley that somebody had taken a famous a notable person's voice and then did a dialer and then attempted to change the distribution path of shares coming out of a venture firm to a partner or an lp which i don't know was a gp a general partner working at the firm or an lp who was an investor in the firm so have people started using voice now to to kind of uh and then these ai voice generators SPEAKER_23: i i haven't seen it yet but absolutely right it's the the other beautiful thing there's caller id is incredibly fragile and easy easy to spook so the second you call someone and it says that it's you know jason calling me and it's your voice how do you not go buy those amazon gift cards SPEAKER_120: starting a business used to be a pain you needed a lawyer there were hidden fees it was a mess now SPEAKER_14: with northwest registered agent it only takes 10 clicks and 10 minutes northwest provides everything you need to start and maintain your business every llc corporation or non-profit at northwest forms comes equipped with registered agent service a business address a website and hosting email a phone number and this is all covered by northwest's privacy by default again your full business identity will be live in 10 minutes and in 10 clicks so here's your call to action for 39 plus state fees they'll form your llc corporation or non-profit and launch your business in just minutes visit northwest registered agent.com twist today that's northwest registered agent dot com twist today social media seems to be SPEAKER_96: another vector i get dms all the time from people trying to get me to send bitcoin or receive bitcoin whatever but then people create fake versions of you online and mirror your entire account and then try to get people and i get dms on my main account the verified account all the time saying hey um David Friedberg: did you want me to send you those bitcoins and i'm like yeah i sent you three bitcoins and you're SPEAKER_14: gonna send me 300 back right this seems to be something that's now becoming de rigueur but people SPEAKER_55: are getting smarter to it right never send money so it also um makes kyc really difficult where you have SPEAKER_23: online banking and people don't want to go into a branch and show their driver's license and have someone be like so you end up with like we're going to do a video check right like hold your driver's SPEAKER_134: license up and all of that is all fakeable now so never do that yeah it's not that you should never SPEAKER_23: do it it's it's just there's more vulnerability the the more connected so two-factor strong passwords if SPEAKER_17: people just did that how much of this problem would be solved if multi-factor and multi-factor helps a lot SPEAKER_23: the problem that you're seeing is the companies that are going down the caesars and mgm stand SPEAKER_17: multi-factor they can't get around multi how do they come back oh wow octa people who don't know is like an authentication management platform it's got passwords in it it's got its own two-factor but they had if they got wow does it octa now have liability then possibly right like who knows that's SPEAKER_23: that's a a much wow i don't think anyone's really been held liable for uh security vulnerability in their product that resulted in somebody else getting that right like microsoft and apple would SPEAKER_148: be the two largest offenders in the world talk to me about these uh infrastructures i know that we had a the was it the colonial pipeline if i'm remembering correctly so explain what because that's SPEAKER_17: a different goal that's not just money now this is like serious espionage level trying to damage another country so how real is that and how prepared are we for that's the interesting thing it was SPEAKER_00: financial it wasn't espionage and it was over the line of s right like nobody's been willing to carry SPEAKER_23: out an espionage style attack of that magnitude on u.s soil right you end up with a proportional response SPEAKER_00: take out our pipeline we'll take out to new york's because it was a cybercrime group they got away with it there wasn't a proportional response that wasn't what happened if you know what happened in that SPEAKER_23: situation and how did it go down there were attackers that were in the the network for some time they ended up installing uh some new security software where they noticed that there were some irregularities it tipped off the attackers that they were on to them and they they encrypted all the machines they didn't go into the actual pipeline computers but they took all of the the back-end office computers you know essentially offline and then demanded a ransom to to allow uh colonial to SPEAKER_00: regain control of their computers and turn everything back and this was another one of these like payoffs SPEAKER_96: with bitcoin i know the doj in this case somehow recovered some of those they exfilled stuff to amazon SPEAKER_23: and so they were able they were bouncing through like an aws host and so they were able to you know the fbi the secret service us marshals have relationships with those cloud providers but the second that you get out of something like that or you know frankly they left stuff around if they had just moved it all the way off they wouldn't have been able to recover anything totally get SPEAKER_96: when people steal the data the releasing of the data or the selling of the data that's a super attack SPEAKER_14: vector but when they encrypt you a machine why don't people have backups why are these things not SPEAKER_155: duplicated or redundant in some way while they encrypt the machine they go and they encrypt the backups SPEAKER_23: or they believe them right like if you have the ability to write to a backup yeah they they profile it the interesting thing is you know lots of people have offline backups you know vlt tape drives iron mountain all that the logistics of importing that backup data takes weeks there's not enough bandwidth on your network to be like let's restore every system at the same time so they're so sophisticated SPEAKER_17: that they uh know where the backups are they encrypt them as well at least the online ones that are redundant they get the topography of the network boom they just take all the way all the way down SPEAKER_23: to they corrupt the like host-based snapshots like windows has a service called the volume shadow service where you know if an update goes bad or something like that you can snap back they'll actually corrupt that out in every major piece of branchable it's one of the the indicators that we SPEAKER_121: actually use for for stopping ransomware is tampering with that backup source ah so if somebody SPEAKER_17: starts effing with your backup service that's when you know somebody's in there doing something it's one of the signs yeah absolutely tell me more about your software and solution how do you implement it and and um how can uh how does it stop people is this like a constant game of cat and mouse where you constantly have to update it like the wire software people do i i mean the the nice thing about it is SPEAKER_23: that's where you know ai really comes in and gives some superpowers instead of you know thousands of people sitting writing you know reject signatures um you know we we are using um multiple different types of machine learning to to build models that that help uh identify both from a pre-execution before it runs as well as the behavior when something's actually uh running to say we think this is bad let's stop it but where we're the the best way to think about us is we're the first complementary layer to antivirus so for years everyone said you you don't want to run two antiviruses on the same machine because they'll step on each other and conflict yeah so we were the first product where we said let's build ourselves to be a layer behind not try to replace the defenders the the crowd strikes that are out there right and then just focus on the threat of ransomware so instead of trying to stop everything that's out there we focus on these you know 200 300 ransom workers what are the tools that they're using what are the techniques and then we use that to build um you know kind of like a multi-layered protection strategy but where we really differentiate is we're the first endpoint product ever to be focused on recovery too where because these guys are so sophisticated they have so much resources they're going to figure out how to beat everything at some point but because they do encryption on the host we actually capture the the key material the symmetric keys the entropy and we can um reconstitute that data for the users without them having to interact with a ransomware SPEAKER_168: group if if everything fails this is a key thing they have to encrypt it in order to give you the keys SPEAKER_14: to unencrypt it so that step in the process was such a brilliant stroke for them however doesn't take all that much technology to know a machine is doing something with encryption in real time on that server SPEAKER_55: right or on that desktop i'm not sure there's a lot of encryption that's going on on hosts nowadays too SPEAKER_23: right so there's a delicate balance between you know profiling something that's backup software we i mean we also focus on the data protection side right when they come and they steal that data before they encrypt um we have a network driver so we'll actually detect that that data actually going and block it their tactics you said cat mouse i mean it's it's completely appropriate their tactics change constantly they're always looking for a way to deliver more impact quicker this is now becoming SPEAKER_17: in terms of corporate governance a board level issue like when these things happen i remember uber had a big hack and then somebody didn't report it or they try because you know sometimes somebody is embarrassed by and they try to you know maybe resolve it before it escalates this is getting very dangerous for companies and boards because they ultimately are responsible for knowing about these things so what's this what's the state of the it's getting dangerous for the cseps right so in that SPEAKER_23: uber case the person that got prosecuted was the chief information security officer it's the same thing SPEAKER_179: with the solar winds hack if you remember that the sec just filed charges against the chief SPEAKER_66: information security officer so if a cso which is chief information security officer people don't know if a cso doesn't do their duty to report hacks that's criminal behavior now or it's apparently right SPEAKER_23: there isn't a lot of clear guidance on what's good and bad the industry has taken up with this concept of bug man it's where you as an individual can go out and find a vulnerability in uber and then reach out to them and say hey uber i found this vulnerability here's my proof write me a check what's the difference SPEAKER_186: between that and somebody hacking you and asking for a ransom right like attitude um i guess it would be SPEAKER_96: the threat of taking the system down and giving it to other people as opposed to politely asking can i get SPEAKER_31: 10 grand for this yeah that's what i found and also i guess being anonymous versus not being anonymous SPEAKER_80: would be another i mean absolutely you can always ask politely first and if they don't agree escalate SPEAKER_23: right but it's it gets confusing from a legal perspective yeah right where if you look at that uber case and what they prosecuted that cso for it seemed like something that was very common that's done in corporations across the country every day all right listen selling software is hard it's SPEAKER_196: hard right now right 2022 2023 it's been a grind 2024 it's going to be hard too everybody's making very thoughtful decisions and the last thing you need is to slow your sales team down because you don't have your sock two dialed in so if you're a sas or services company that stores customer data in the cloud SPEAKER_199: you need to check out vanta vanta will get your startup sock 2 compliant easier and faster vanta makes it really easy to get and renew your sock 2. on average vanta customers are sock 2 compliant in just two to four weeks compare that to three to five months without vanta vanta can save you hundreds of hours of work and up to 85 on compliance costs and vanta does more than just sock 2. they also automate up to 90 compliance for gdpr hipaa and more you can't afford to lose out on major customers because of silly stuff like lacking compliance just work with vanta get your compliance automated and tight tight is right and close those big deals the lighthouse deals that send all the other customers to you here's the call to action it's very simple vanta is going to give you a thousand dollars off at vanta.com twist that's vanta.com twist to collect a thousand dollars off your sock 2. talk to me about SPEAKER_108: encryption long term because there have been rumblings uh especially during this open ai SPEAKER_31: brouhaha with sam altman being fired and rehired and all that kind of stuff that you know they might SPEAKER_96: have uh this is one of the theories but they might have with you know llms and just the brute force they have been able to figure out how to unencrypt stuff or break some encryption so is that disaster scenario that people put in the quantum you know computing oh it's only going to happen but when quantum computers come out they're going to break encryption and whatever we'll we'll see that coming but then llms we didn't see coming at least not at this velocity so is that real or scare tactics or encryption's been SPEAKER_23: broken a bunch of times before and what happens is it gets broken there's no instant uh scale of attackers so the attackers exploit it everyone responds they replace it and then we go on to the next one right like it's the reason why we don't have web on our wi-fi anymore and we're not using ssl one encryption's always going to get compromised right it's just you have to be dynamic and use it in a way where you can adapt and move to new standards and algorithms but you're already seeing quantum SPEAKER_206: resistant crypto explain what this is for the audience yeah cryptography that theoretically and SPEAKER_23: it's just theoretical right now because no one's been able to actually prove it is resistant to um you know a scale general purpose quantum computer being able to break the encryption right so the majority of you know like cryptocurrency and stuff like that theoretically with a strong enough quantum computer you can unravel the the blockchain right but people have identified it we've known that this is going to be a problem for a long time and and there are numerous companies working on being the next SPEAKER_14: you know quantum resisted cryptography company what do you recommend for startups people who are you know running fast-growing companies uh in terms of the because you can't afford a cso you know you're a 20 30 40 person company what's the best practices just use a great cloud computing provider have great two SPEAKER_23: factor i mean there are some fabulous managed services companies that are out there right that specialize in security that you know are affordable have access to you know a suite of the the best in class technologies that are out there this is going to sound crazy but you know big companies like doubt right like these are serious problems to them and they have real solutions to them so you can actually go out and engage with the the manufacturers right i'm less with apples than everyone else but you know microsoft has a huge SPEAKER_14: security suite product offering should people be using physical keys i mean there's been a lot made of like um people being able to spoof sim cards in order to get two-factor it seems like the majors the SPEAKER_17: you know the the verizons of the world google files are starting to lock this down so they they kind of SPEAKER_14: get it but there have been very interesting edge cases of people being able to figure out how to get e-sims so should people be using what's that key that everybody uses qb or something that you see yubi keys should people start moving to those kind of things is that going to and does that actually SPEAKER_23: really solve the problem maybe for now right like the majority of people i i use my phone for my multi-factor and you run into an issue of what happens when your phone gets compromised which i don't know if you've seen the news but there was you know this uh um highly sophisticated ios tool chain that that just came out where they were hacking iphones and and there was no way of knowing that you were compromised you know it's it's layers of due diligence right i i wish that there was some if you use this you're protected but in this world there's always a way to engineer hack around kind of any security technology that gets deployed which is why it really comes down to to having layers and being able to detect when something's been penetrated and have mitigating controls and and response plans and the right partners how much of this is moved to SPEAKER_96: china now and north korea are those sophisticated players in all this is there it's still in east SPEAKER_39: eastern europe oh no they're they're highly sophisticated i mean the interesting thing with SPEAKER_23: north korea is when you look at the the top four you know non-five-eyes nation states you've got china SPEAKER_220: russia iran and north korea right the old access of evil as i think bush called them yeah north korea SPEAKER_23: operates and and became one of the top four with zero dollars of state funding all of their yeah all of their funding for computer hacking basically like they they were really they're bootstrapped uh they're absolutely bootstrapped they were a big fan of um you know the the banking protocol swift they would go in and hatch with transactions and just steal money that way what about iran it's very SPEAKER_228: interesting so iran have or iran have a big capacity um not a large capacity but they're getting really SPEAKER_23: sophisticated so they were essentially kind of late to the game but you saw probably 10 years ago they started taking on serious targets they they were able to compromise the the navy marine corps intranet you know they got a bunch of like nuclear research stuff from a bunch of universities but yeah i mean they're continuing to gain sophistication with essentially the rest of the world right like as this information is becoming more accessible to everyone they definitely have the motivation and SPEAKER_32: the access to everything that they need to play out some major attacks the governments SPEAKER_96: turn a blind eye to this but they or do they support it are they training people you know are they getting a vig and a piece of the action you would think in a place like north korea maybe a supreme SPEAKER_14: leader would want a piece of the action and would see this as a revenue stream potentially um yeah how do the governments in each of these places participate in this or not it's normally state-sponsored SPEAKER_23: right like if you look at even you know russia china like all of these um attacker groups have direct ties to uh military intelligence so they exist outside of the military and outside of the government SPEAKER_39: they're moonlighting yeah it's your it's your nights and weekends job you don't make a lot working for SPEAKER_23: the government but they've always been supportive of people kind of taking those tools and using them to attack their enemies right like there's no if if you go and hack you know a giant american company as a chinese north korean iranian citizen and it it gets publicly released that you're the one that did it there's no consequence china used to hold competitions at universities where they go and who could hack some american company the best okay lightning round here there's been rumors bitcoin tor the tor SPEAKER_96: network people don't know is a a relay system to anonymously surf the internet it's where all the David Friedberg: dark web transactions there's been rumors those things could have been cia or government-sponsored SPEAKER_23: honeypots etc what do you think it's definitely not conspiracy right like i don't think that it's SPEAKER_76: something that they're the whole system but yeah i mean if you're operating on tour and you think that SPEAKER_23: you're completely anonymous and the u.s government and intel agencies aren't operating tour exit nodes you're collusional yeah right like it's absolutely in those decentralized environments they're going to SPEAKER_00: invest and collect it just comes down with what's their motivation to do something about it how good SPEAKER_17: is america when compared to you know our hacking ability because you're in the community people in the community sometimes get called up to duty or get pulled into operations etc and there's a big SPEAKER_46: tradition of that here uh it's very quiet obviously how good are we compared to the other places yeah SPEAKER_23: so prior to starting halcyon i i started a company where we exclusively worked with the us intelligence community doing sophisticated cyber operations we are the best right we have the best SPEAKER_32: capabilities we have capabilities that most people can't fully comprehend what do we use them for that's SPEAKER_23: the problem right like are they being used for the right things do the the groups that have these capabilities get the right mission handed down to them that allows them to get the maximum value i think politically we don't really understand computer hacking yet i don't think a lot of politicians understand how computers work and the threats we're vulnerable to but from a capability SPEAKER_27: perspective it's fantastic right like better than you could imagine it's just we we don't hear about SPEAKER_96: which i think is a really good thing like our techniques this is why when a lot of you know i mean not to be political or anything but like you know trump having certain papers that have in them in mar-a-lago or maybe other presence happen to that have those techniques in them right i think they SPEAKER_29: call them methods and whatever and sources it's really important that we don't use these tools that we have or let people know we even have them like we got some sophisticated stuff that we just don't want people to know we have them yeah yeah it's different classes right there's stuff that you have to SPEAKER_23: sit on the shelf just for an emergency right life or death the world's gonna end like that's when we pull that one on but they're they're different calibers right where it's you know you have your everyday tools that you run like there's there is no shortage of of capabilities for cyber in the u.s intelligence community we spend a lot of money on on making sure that the the us has omniscient like SPEAKER_148: cyber capabilities omniscient like cyber employees i like the sound of that it's in the right hands i SPEAKER_17: mean obviously these can be used for nefarious purposes too we got to be vigilant about them there's abuse on the margins but generally it seems like we do the right thing as a country SPEAKER_157: yeah very much i mean i think that there's a lot more that we could be doing but people are scared SPEAKER_23: you know it's something where privacy becomes very fluid and you know once you erode it that you can SPEAKER_17: never really pull it back yeah i mean if the amount of access we probably have to an average person's phone as a government is pretty amazing people think that their signal or some of these encryption SPEAKER_23: things are bulletproof you would say no absolutely not right so the the interesting thing with with SPEAKER_00: those messaging applications is in so many cases even when something is deleted it's still left on the phone right because you end up with a database of messages and you don't go back and delete lines SPEAKER_23: out of a database on a cell phone it's a battery device you just flag it as deleted there's so much information on your devices that once it gets kind of captured by one of these you know government tools or programs um it's it's a little unimaginable your privacy is an illusion 100 if we then SPEAKER_29: extrapolate that to tick tock and the chinese government having access to it describe for the audience what they would be capable of doing with 50 100 100 million americans and the access they have on the average phone what what could they be doing with that data it's interesting right because there are SPEAKER_23: legitimate ways to gather data on phones and then the illegitimate ways to gather data on phones yeah give me an example so you remember when iphone came out with uh uh allow this application to get SPEAKER_27: access to your clipboard yes that was in response to applications we're just always reading what was on your clipboard right and then sending it to your password people cut and paste their password all the SPEAKER_269: time from their password manager yeah absolutely so you've basically given the chinese all your SPEAKER_96: passwords and they've got five or six different passwords in there and if you're a typical american SPEAKER_61: you're probably not using a random generator so they just got your gmail just gave them bank of SPEAKER_23: america gave them everything else yeah i mean there's a lot of metadata that you can take off of phones i will say this tick tock probably isn't going to be their only source of this information there are a lot of core services that mobile applications are built upon that data can be mined SPEAKER_80: from i guess would be the best way to put it you know as long as as you're comfortable with the fact that SPEAKER_23: privacy is an illusion and you should do everything like somebody's looking over your shoulder you'll SPEAKER_46: be fine yeah i mean that is what people should be should be doing right yeah especially with digital SPEAKER_23: devices right if you want some privacy get a friend go out into the forest leave your phones behind SPEAKER_17: when we look at apple as an actor here they've been at least publicly it seems like they're in the corner of protecting individuals rights to privacy more than anybody they're not an ad-based business encryption uh and the fact that they wouldn't unlock the san bernardino shooter's phone if you remember that instance that is an israeli tool to do it so is apple and being on the apple ecosystem the best choice for consumers because apple has that default of you know lock it down and only the user has it SPEAKER_280: and we don't have your information on some server at or in a lot of cases they say they don't have it SPEAKER_23: i trust apple the most i guess would be the best way to put it you know you end up with a homogenization kind of problem where if i want to hack you and you're an apple guy i can go out and buy a zero day that doesn't just allow me to hack your apple phone it allows me to hack every apple phone in the world because they're all the same yeah right everything's universal and so you end up with this because you're in the majority everyone's going to always have access to that right like being able to get on an apple phone is bread and butter for an intelligence agency federal law enforcement like you said that they couldn't get in the san bernardino shooter's phone so they went to an israeli company right the capability is always there yeah um where if you want to be really really secure find the most obscure phone that you can think of and use that because nobody's going to go through the effort of you know buying or building a tool to get into something that unique what's the SPEAKER_96: biggest threat we'll end on this the biggest threat that keeps you up at night just in terms of hacking globally uh beyond your company and what you do what i mean you're a venture capitalist i was SPEAKER_23: going to say interest rates but if you're going to take me back to hacking right back to hacking i mean it's it's our infrastructure right if you look at did you make it to the super bowl in tampa you seem SPEAKER_289: like the type of guy to go no i didn't i didn't get yeah i've been to a super bowl i went to the 49ers one SPEAKER_00: one time yeah so a week before the super bowl happened in tampa the tampa water district got SPEAKER_01: hacked and somebody tried to poison the law what i was totally unaware of that wow they stopped it SPEAKER_04: because somebody was literally sitting at the computer and saw someone else moving the maps SPEAKER_07: whoa that's an unplug the computer moment yeah holy cow attacks like that are so much easier than SPEAKER_76: anyone realizes right now for the level of sophistication of these and how do they get SPEAKER_292: the poison into the water where they just like up the amount of fluoride yeah just 100x the fluoride SPEAKER_39: boom yeah whenever wow transportation infrastructure right like um hospitals right manufacturing what SPEAKER_23: happens if the oil companies get shut down for a week right you end up where we've built this this entire supply chain that's as close to just in time as we can get and you start dropping computer outages there and and stuff unravels right yeah people die people i mean americans are dying all of the time SPEAKER_69: now from cyber attacks and we're doing nothing that's incredible yeah because of hospitals because SPEAKER_298: the supply chain and these kind of things going down yeah but i mean the hospital specifically and that SPEAKER_96: is a target huh they want to target hospitals because they know it's mission critical and they're just going to call a ransom you got no choice you got to pay yeah yeah this is why things that are redundant are good uh this is one thing we learned during covid like if all of the medicine we have in this country comes from one other country that's a communist country that maybe is an arrival maybe we should make some of those drugs here um yeah it's just not cheap right like that's the problem like SPEAKER_23: all of this is just more capital that that is expensive right now and people don't want to spend SPEAKER_29: if the problems solved it's a challenge with capitalism capitalism finds the cheapest path and the cheapest path is a dependency you then have to say we want redundancy is more important than SPEAKER_96: the lower price and i think i think americans are starting to see that you see that with people putting solar and generators and having starlink and their landline people are starting i mean SPEAKER_14: putting preppers aside just being off-grid having a well having a generator it's it's not like you're a kook anymore for having those i get the sense that you have all those things i have all of those things thank you for calling me not a kook i i literally am putting generators in both my houses uh my cyber truck when it comes is the equivalent of 11 power walls or something so i'm gonna have a SPEAKER_96: cyber truck that's 11 power walls i have sat star links so yeah i'm i'm big into their cyber truck SPEAKER_312: yeah i thought you're elon's friend you don't get it right away i i literally just traded emails with SPEAKER_313: them about it yeah push me up he's gonna get me one of the foundation series i think i you know SPEAKER_314: what here's the thing i always if you wanna if you wanna throw in a word for me too i pre-ordered SPEAKER_294: i think he's gonna sell every one of these he can make i i think this the sneaky part of that SPEAKER_17: product is the inverter and that you can plug it into your home and it's 11 power walls you just think about if you live in texas and you're gonna buy a truck and you see like three power walls right SPEAKER_53: now and it's pretty good but i really could have gone with like six but three power walls will get SPEAKER_27: you through like two days or a day i i mean it gets me all the way off great if i'm not running my SPEAKER_17: air conditioning yeah so you're in pretty good shape if you have a cyber truck and it's got 11 of these or nine whatever you see you can run your ac you could be doing loads of dishes and it just will change how we look at the power grid itself and that's the ultimate redundancy like how do you hack SPEAKER_59: that it's going to be pretty hard to hack i think it's huge right having that kind of power independence SPEAKER_23: especially where our grid is so fragile if you take down i think it's like nine or 11 substations and i'm talking about like a bomb on a quadcopter and you just fly it in and kaboom yeah the entire SPEAKER_109: nation's power grid and you think about how insane that is you could just literally do nine oklahoma city bombings god forbid not not even that big not even that big you're doing a toyota SPEAKER_23: corolla quadcopter right and your own homemade explosive and have 10 buddies do it all at the same time and you just blacked out the entire united states it's madness and this is where i the SPEAKER_31: next thing i want to go forward it hasn't happened black swan events do happen though and we can SPEAKER_96: predict them now which means we should be doing the thing i want to get is there are these um panels that are like solar panels you put them on your roof or you put them in your backyard and they take moisture out of the air they're like dehumidifier kind of things or and you can basically get enough water to survive and drink off with a couple panels for your family of whatever three four or five SPEAKER_258: i don't know i saw that on star trek and when i was watching in the 90s captain there's a startup making them and so it's i mean it's fantastic i have it well right so i've already got plenty of water SPEAKER_23: but um that's the next piece water electricity and internet what else in the second the second you can do all that stuff off grid with starling giving you 350 megs a second wherever you want like SPEAKER_96: i just put starlink in my ski house and i got over 200 250 megabit and i was like what when i first tried this you're getting three 350 on mine right now that's nuts and then yeah are you SPEAKER_17: on it right now is this uh no i have it as a backup yeah so that's what i do is i have the router uses mine as the backup but i think it's getting to the point with the latency going down that you could actually load balance and you wouldn't be giving anything up versus your cable modem my head of SPEAKER_23: services lives in like a rural town in colorado and there's no broadband there he's been on starlink SPEAKER_27: since it first dropped and you know he does zooms demos everything works right like when you see SPEAKER_31: it on an airplane i was on an air i was on an airplane with it and it was oh my goodness i mean i SPEAKER_76: you know the just the internet coming to planes was so transformative for me like having actual real bandwidth there is going to be it's bonkers it's really going to change how people look at you know SPEAKER_96: taking long haul flights like the fact that you could just literally turn on netflix and then have SPEAKER_14: two other people turn on netflix and stream something and you're like wait a second i mean SPEAKER_23: every time every every night before i travel you got to get it out make sure everything's downloaded and synced and your drm is renewed and yeah no having a real connection would be great where can people SPEAKER_349: find out more about your your company and i know you're hiring you've done great in terms of raising SPEAKER_283: money and uh so who are you hiring for working halcyon halcyon dot ai and that's just because you know we can't afford the dot com yet maybe one day we'll get there i think actually the ai is SPEAKER_39: probably better right now yeah it is the right time of year for ai companies right absolutely but yeah and then you know major kind of security channels and partners if somebody has a security partner that SPEAKER_23: they're they're working with odds are we're kind of partnered with them but and hiring we're definitely SPEAKER_76: hiring the engineers and sales guys come on over you got it all right and we'll see everybody next time SPEAKER_351: on this week's startups bye bye