The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Product/The Inverted Podcast
The Inverted Podcast artwork

Inverted Podcast #26: Hacklore Debunking Common Security Myths with Bob Lord

The Inverted Podcast · 2026-07-29 · 46 min

0:00--:--

Key moments - from our scoring

Substance score

55 / 100

Five dimensions, 20 points each

Insight Density11 / 20
Originality10 / 20
Guest Caliber15 / 20
Specificity & Evidence10 / 20
Conversational Craft9 / 20

Bob Lord brings his extensive security background - including roles at Twitter, Yahoo, the Democratic National Committee, and CISA - to debunk pervasive myths in cybersecurity advice that have calcified into industry dogma. Through Hacklore.org, a site co-signed by roughly 100 CISOs and security experts worldwide, Lord challenges advice like avoiding public WiFi (HTTPS and browser security have largely solved the Firesheep problem), using VPNs for privacy (IP masking doesn't stop dozens of tracking techniques including GPU fingerprinting), juice jacking at airports (zero recorded crimes despite sheriff warnings), and mandatory password rotation (which drives predictable patterns like "NYKnicks2025"). The site distinguishes between genuinely possible attacks and probable ones, emphasizing that security professionals should separate possibility from likelihood. Lord advocates for password managers generating unique, randomly-generated passwords and passkeys as the real future, noting that forced complexity requirements actually enable spray attacks by creating predictable user patterns. The episode resonates with operators managing security policies, particularly those struggling to justify outdated compliance mandates or seeking evidence-based alternatives to legacy password policies.

Key takeaways

  • →HTTPS encryption and browser security improvements have made the "avoid public WiFi" advice largely obsolete - the original Firesheep threat that drove this myth has been addressed by the industry.
  • →VPNs don't preserve privacy effectively because IP address is just one tracking method among dozens, including browser fingerprinting and GPU jitter analysis.
  • →Juice jacking has never been prosecuted or even detected in the wild despite widespread warnings, making it a pure security myth rather than a real threat vector.
  • →Mandatory password rotation policies backfire by training users into predictable patterns (capital letter + special character + number) that attackers exploit via password spray attacks.
  • →Password managers generating unique, randomly-generated passwords and passkeys are the evidence-based solutions for authentication security, not forced complexity or rotation rules.

Guests

Bob Lord

Topics in this episode

PasskeysPassword managersHTTPS encryptionPassword spray attacksHacklore.orgFiresheep Firefox pluginVPN privacy mythsGPU fingerprintingJuice jackingDEFCON security conference

Questions this episode answers

What is juice jacking and is it actually a real security threat?

Juice jacking is the theoretical attack where a public USB charger would steal data from your phone; while demonstrated at DEFCON 2011, there have been zero recorded prosecutions or detections of this crime despite widespread warnings, making it folklore rather than a real threat.

Why shouldn't I avoid public WiFi networks anymore?

HTTPS encryption and browser security improvements have largely solved the original Firesheep vulnerability that made public WiFi dangerous; the threat of intercepted unencrypted traffic that motivated this advice in 2010 has been mostly mitigated by industry-wide adoption of encrypted connections.

Does using a VPN actually protect my privacy online?

VPNs only mask your IP address, but attackers have dozens of other tracking methods including browser fingerprinting, JavaScript analysis, and even GPU jitter timing; therefore a VPN alone does not preserve privacy against determined tracking.

Why is forcing employees to change passwords every 90 days bad security?

Mandatory password rotation drives users into predictable patterns (uppercase first letter, special character at end, number substitution) that attackers exploit through password spray attacks, making shorter-lived passwords actually less secure than long, randomly-generated ones managed by a password manager.

What is the best current approach to password security?

Using a password manager to generate unique, long, randomly-generated passwords for every account is the current best practice, with passkeys (physical or biometric) representing the more secure future as adoption across websites improves.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

11 / 20

The episode contains genuine non-obvious points - juice jacking has zero recorded real-world instances, bad security advice is actively harmful not neutral, and the upstream/proximate-cause framing is substantive - but large stretches are social filler, repetition, and meandering AI speculation that dilutes the insight rate.

giving people information that doesn't help them stay more secure in a meaningful and measurable way is actively harmful. It is not neutral. Uh, it is actively harmful
people are willing to spend minutes per year to keep their digital lives safe

Originality

10 / 20

The 'hacklore' framing - folklore that was once true but has aged past its prime - is a genuinely useful organising concept, and the upstream/proximate-cause distinction is sharp, but the individual myths debunked (public WiFi, 90-day passwords, juice jacking) have already been widely covered in security circles, limiting the originality score.

we need to separate what is, what is possible from what is likely
do we want to try to change the behavior of a billion people, or can we ask a handful of companies to change their, their software and their hardware

Guest Caliber

15 / 20

Bob Lord is a genuine, senior practitioner - first security hire at Twitter, CISO at Yahoo, rebuilt the DNC's tech stack post-2016 hack, and co-founded the CISA Secure by Design initiative - giving him real standing on every claim he makes, though the conversation doesn't fully extract the depth his résumé warrants.

I was the first security hire at Twitter, I was CISO at Yahoo, uh, had so much fun with the Russians, I decided to go to the Democratic national committee after the 2016 hack
I first deployed physical security keys, as Dario knows, at the DNC, in 2019

Specificity & Evidence

10 / 20

There are useful concrete anchors - Firesheep plugin, DEFCON 2011 demo, the San Diego sheriff PSA with zero prosecutions, Apple CVE bounty, ~100 co-signing CISOs, sub-0.5% unencrypted traffic figure - but most claims about enterprise impact, MFA growth data, and AI risk remain anecdotal and vague.

there was a presentation at the DEFCON security conference in 2011, I believe, and some researchers were able to take advantage of the fact that USB is used for both data transfer as well as for charging
when a reporter called to say, hey, very interesting, can I understand more about the prosecutions that you have? They said, well, no, we've never prosecuted, we've never detected any of these

Conversational Craft

9 / 20

The host provides competent topic steering and helpful listener-facing summaries, and the co-hosts add relevant practitioner colour from their Microsoft MFA work, but there is no real pushback, no probing follow-up on contestable claims, and the AI segment drifts with no sharp questioning.

So I just want to summarize a little bit for people. Um, basically you're saying that some of security advice where we've been given is wrong because it can super easily be circumvented
Are there any other big ones you want to highlight for people listening?

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker C65%
  • Speaker B13%
  • Speaker A12%
  • Speaker D10%

Most-used words

security26advice22data19password18different16stories16change15back12secure12hacklore11everybody10users10attacks10certain10world10safe10

Episode notes

What security advice is actually helping people stay safe, and what has become outdated “hack lore”? In this episode of the Inverted Podcast , Jeroen Kemperman, Dana Kaufman, and Dario Salice are joined by Bob Lord (former Yahoo CISO, former Twitter security leader, and founder of Hacklore) to debunk some of the most persistent myths in cybersecurity. The conversation explores why common advice such as avoiding public Wi‑Fi, using a VPN for everyday browsing, constantly changing passwords, clearing cookies, avoiding QR codes, or worrying about "juice jacking" may no longer reflect how modern attacks actually work. Bob explains how security guidance can outlive the threats it was created to address, creating confusion, wasted effort, and a false sense of security. The group also discusses Secure by Design principles, why security teams need better data to drive decisions, how passkeys are changing authentication, and what new myths may be emerging in the age of AI. If you build, market, sell, or use security products, this episode is a practical guide to separating real risk from security folklore and focusing on what truly makes people safer.

Full transcript

46 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Foreign.

Speaker B: Welcome everybody to another episode of the Inverted podcast. And it's been a, ah, little while since we did a recording, so it's good to see you, Dana and Dario. I hope that the summer is starting well, wherever you are. And welcome, uh, today, special guest, uh, Bob, we're going to come to you in a moment. Uh, but before that, just wanted to remind everybody that you can find us all on LinkedIn. We have a group there that you can join and you can find us on all the different social, uh, media platforms where we podcast on YouTube, Spotify, you can engage with us there. And uh, yeah, our podcast is about those products that are just different, that are inverted, where success is when nothing happens. We drive things down, we make things disappear, and we try to drop users out of our products rather than keep them in. And that just means that you need a different approach, you need to sell these products in a different way, you need to build them in a different way, you need to explain them in a different way. And that's what we try to help you, the listener, learn about in this podcast. And today we want to talk about something really special because sometimes the industry's been telling you stuff that's actually no longer correct and there's a bunch of myths around security. And for that we have special guest Bob Lord, um, former CISO of Yahoo. Very, very big security career. And now he has started a new initiative called hacklore. Bob, why don't you introduce yourself to the audience and tell us a bit about what hacklore is.

Speaker C: Yeah, so first of all, thank you for having me. It's a great honor. Uh, and I'm here with some luminaries, so, you know, I'll know when to step back and not answer the questions and defer to you all. But, uh, yeah, so, uh, I've had a career working, uh, both as a builder of software for enterprises and consumers, um, as well as being a defender of networks. So I was the first security hire at Twitter, I was CISO at Yahoo, uh, had so much fun with the Russians, I decided to go to the Democratic national committee after the 2016 hack. So I joined in 2018 to help refactor a lot of the technology stack. That's where I really became familiar with the idea that the software that we have come to depend on for our, uh, organizations and our national security and our economy is really not fit for purpose and it's not really built to withstand the kinds of attacks that we see. Um, and so it's really not secure by design and has the Great fortune of turning some of my scar tissue into action, and I was able to join cisa, uh, to kickstart the Secure by Design initiative there. So, uh, that's been one of the things that has been a, uh, constant thread is trying to figure out how do we move responsibility upstream where it can be handled most effectively, uh, and most economically. So, uh, regard to the hacklore thing. So for many, many years, and this goes back to the Twitter days, uh, I've been fascinated by the ide that people repeat certain mantras in the world of cybersecurity. And for many of these pieces of advice, there was a germ of truth at one point. So back at Twitter, one of the things that we ran into was this plugin called Firesheep. I don't know if any of you remember this. Firesheep was this Firefox plugin. And what it would do is, uh, you'd run this thing, put your device into promiscuous mode, and it would listen to all of the packets on your network. And the Firesheet plugin would then look for social media and other kinds of traffic that was unencrypted, and then it would display that for you in a web browser. So you really could.

Speaker B: So for our readers, it basically means you could sit in an airport and read other people's Twitter posts, social media, Facebook messages, and all that stuff.

Speaker C: That's exactly right. And so this is a great stunt. I don't know if anybody ever did any of this to commit real crimes, as opposed to just test it out and get a few, uh, articles posted. But you really could sit there and watch people's Twitter feeds, including their direct messages. Um, but it had this other feature where you could push a button, and because it captured all of the session cookies that were moving back and forth in the clear, you could become that person and not just read their direct messages that they happen to be reading in that moment. You could go send direct messages as them and some things like this. So we had already had plans to move the entire site to HTTPs so that everything would be encrypted all of the time. The Firesheet plugin dramatically accelerated those plans. And that was true for Facebook, and that was true for a lot of companies. Uh, that really took this as the end of the era where you could just get away encrypting the login session, the name and password, and then it fall back to regular unencrypted traffic. So those days were a number, and so there really was a germ of truth. When you said don't use public WI fi or don't do social media on public wi fi, there was a germ of Truth in 2010. That changed over the years. We made so much improvement. We had browsers improve security, we had websites improve security. Operating systems, let's encrypt came to make certificates free so you didn't have to, you didn't have an additional burden every year of paying for those. There were so many advances, but we never stopped to refactor and say, is the problem that we used to have is that mostly solved? Kind of solved. And it turns out it was mostly solved. And so that was just one of the things that was constantly bothering me year after year that I was fighting people to do the things that really would stop the hacks, really take them out of the pool of people who are going to be victims. Uh, and so their minds were really just filled with, I don't want to call it disinformation, let's just call it misinformation or out of date information. And so I decided to, uh, come up with a whole bunch of these things that have been bothering me. Create a website so you can go to hacklore.org so it's a combination of hacking and folklore, just, you know, the stories we tell ourselves. So hacklore.org will give you the complete list, uh, as well as the things that we think are going to be the things you should do to stay safe online. And I asked a few friends to co sign and a few more friends and a few more friends. So I think there are About a hundred CISOs and security experts around the world. So if you don't want to listen to me, that's totally fine, I completely understand. But you should go look at the list of people who co signed on this and maybe listen to them. So anyway, I just really wanted to create a place where people could go to not just see advice, because there's a million pieces of advice floating around. But where do you get to go see the places? What place can you go to to really see the out of date, uh, items, the ones that have passed their prime and uh, have aged like milk. So that was really the who genesis

Speaker D: of that, I think. I really like the example with the Firefox plugin because yes, there's something that worked at some point but now doesn't apply anymore. Um, there's like whole industries, like I think the podcast industry wouldn't work, uh, if it wouldn't be sponsored by all of those VPN providers. Where do you see the pushback against things like statements like, well, today everything is encrypted. So the fear of just having people intercept, uh, your traffic at Starbucks or, um, at an airport is just not valid anymore. But now whole industries try to build up their value proposition. Have people pushed back against that, or are people in general in agreement that that specific attack vector is just not valid anymore?

Speaker C: Well, I think maybe we, uh. So we did this, I think in November of last year, so just before the travel season, just before in the United States, were going on vacation for Thanksgiving. And I think we hit, uh, a sweet spot of time. I think maybe if we'd done this a year or two before, I think there would have been a lot of pushback. I think if I had done it a year from now, people would have said, why are you bothering? This is a complete waste of time. Uh, so I think the timing was right. I think, uh, there was enough, uh, real, uh, sensibilities, uh, around how the attacks really work that we didn't get a ton of pushback. Strangely, just this morning I received an email from a VPN provider saying, hey, we think you're doing really great work with hacklore. Would you, uh, would you be willing to link to our site that, uh, that talks about how to secure yourself and I. The answer is no, uh, because that's, that's just not something that most people need most of the time. So, uh, the pushback that we've gotten has really been around people's, uh, misunderstanding of how the Internet works and how bad guys work. And so they'll talk about things like it preserves your privacy. And it is true that one of the tactics that people use to track you is your IP address. And if you move your IP address to a pool of, uh, addresses that have thousands or millions of people. Yes, that is one element. However, I'm sad to report tracking by IP address is not the only tactic that people have to track you. And there are literally dozens of them. And you can go read academic papers about how people can use a variety of techniques, including, uh, certain kinds of fingerprinting that looks at, uh, your JavaScript. They can even do things like look at the subtle timing differences between your GPUs. So even GPUs from the same manufacturer coming off the assembly line at the same time will have slightly different jitter, uh, in the way that, uh, they render and, uh, so they can track you that way. So if somebody is going to want to track you, and believe you me, they want to track you, uh, they're going to do it. So I think people misunderstand a little bit about how privacy works on the Internet. And so part of the pushback is that they, they equate the vpn, uh, the personal vpn, as the thing that's going to give you the privacy. So, uh, I think that's, that's sort of another layer of mythology that we have to debunk. So I'm open to ideas on how to do that.

Speaker A: Bob M. I checked out his browser map for website, which is really good. And then I read the article, the blog that you posted about the juice jacking in the airport. And even that's a little different because. And I was unaware of the complete background.

Speaker B: But can you explain to people listening what juice jacking is?

Speaker A: Juice jacking is like when you go again at the airport or a public place and plug in your device into a USB port instead of a power cord. A power port like in the wall,

Speaker B: one that's in the wall

Speaker A: to charge your device. And in the article you were saying that that lore stemmed from an article that there's no indication that anything had ever happened. In the first example you were talking about, something actually happened to, um, a plugin was working. In this case, it's almost pure lore, right?

Speaker C: Yeah, that's exactly right. So there, uh, uh, I'll send you the link if you don't have it handy and you put that in the show notes. But yeah. So, uh, there was a presentation at the DEFCON security conference in 2011, I believe, and some researchers were able to take advantage of the fact that USB is used for both data transfer as well as for charging. And so the idea was to create a charging station that would in fact charge your phone, but it would also try to steal data off your phone. And so that was a very interesting, uh, demonstration. And you would imagine that the companies who make phones would go do something about that. And it turns out they did. So they went and they made that much harder. Uh, and so now there are a series of, uh, questions that you get and there's certain modes that you can put your phone into where that's not even possible. And so I think more importantly is the fact that there are no recorded instances of this crime ever actually taking place. There was one report from. Go back and look at the article, but I think it was, uh, the sheriff's department in, I think was San Diego or something like that. And so they had issued a public service announcement and they did a little video warning people about the dangers of juice Jacking, don't go to the airport and plug in your phone to get charged because criminals are going to plant malware and steal your data. And when a reporter called to say, hey, very interesting, can I understand more about the prosecutions that you have? They said, well, no, we've never prosecuted, we've never detected any of these. This.

Speaker B: But.

Speaker C: But we just want people to be, to be safe. Um, so this is a thing that's literally never happened, but we, we have people breathlessly telling you to be scared of this and to, to not, uh, to not do this. We've had CISOs, uh, in January, I think it was. There was. Or December, there was a CISO who did a Little video on LinkedIn explaining things that you should and should not do at the airport. And he was warning of juice jacking, too. So, you know, no one is immune from these stories. And you should step back and say, why is this. If this has never happened, why would we be warning people? And I think part of it is because we don't have enough people who push back. And so you ask, where are all the CISOs who are not saying, yeah, our users get compromised? Just literally never this way or that way. This is how they get compromised. Well, I doubt most CISOs are going to have communications teams that will allow them to go out into the public to say, here's how our users get compromised. That's just not a thing they're. They're going to be able to do. So the vacuum gets filled with commercial interests, people selling you a solution, uh, people who are repeating things that may at one point have been true or that they just heard somewhere and has some element of truthiness. It's plausible. It's plausible it could happen. But we need to figure out, as professionals, as security professionals, we should be separating what is, what is possible from what is likely. And we just, we just need to do a better job of that. So part of the goal of the website is to have a place where people can point to. And I've had several people email me saying, hallelujah, I've been telling people this for years. You didn't say anything novel.

Speaker D: But.

Speaker C: But now I have a place where I can point to whenever people in my company start to engage in, uh, these conversations about, um, you know, turning off your, your Bluetooth or clearing your cookies or change Your password every 90 days or criminals are going to hack you. So, um, we really just wanted to have that place was. And so, again, some of these things actually were problems. Some of them were Never problems, but they're all stories and we need to find ways to tell better stories.

Speaker B: So I just want to summarize a little bit for people. Um, basically you're saying that some of security advice where we've been given is wrong because it can super easily be circumvented. Like, why worry about your P. There's so many other ways to track it. And then there's just some attacks that are theoretically possible but super unlikely, so we shouldn't worry about them. So I guess this all leads to this collection of wrong security advice. You call them security myths or hacklore. So we've already talked about you have to use a vpn. You can't use public WI fi, you can't use public USB chargers. Are there any other big ones you want to highlight for people listening? Uh, maybe start for people personally, like, what should they no longer stop doing?

Speaker C: Yeah, I mean, I think the other one we haven't really talked about is never, uh, scan a QR code at a restaurant. And so, you know, this one, this one did, uh, we did get some feedback on this because QR codes are used in the commission of various kinds of scams. And that's true, but the idea that you should never use a QR code is just untethered from the way the attacks actually work.

Speaker B: Yeah, I saw this happening. I was recently traveling, uh, through Germany and I wanted to charge my car at a time at a hotel. And there was a QR code of the company that actually allowed you to start the charging. Because every charge station in Europe seems to have its own app and its own this. Like, I have like 20 charge apps now. And right next to it there was actually another QR code that looked a bit the same. And I scanned it and then I saw that's a different app and it was actually a commercial. It wasn't malicious. It was more like annoying. So, uh, I mean, I guess if you scan a QR code that's in a restaurant on the menu or on the table, and there's a waiter there that's actually managing the table, I think that's definitely. But maybe there's other places where it's more useless, huh?

Speaker C: Yeah, I think it's sort of a sad state of affairs. So the reality is that as new technologies become part of the mainstream, there is often abuse, but also exaggerated stories about the abuse. And so the, this is just the normal cycle. We used to see this about URLs. People would say, never type in a URL that you see in a You know, uh, a flyer that you get in the mail. I mean, we used to hear all of these things. This is the natural progression. And so we have to ask ourselves, what is it that we can do as citizens to stay safe? And the answer is not to avoid all QR codes at all costs. The answer is to understand that there are scams. Everywhere we go. There are scams. Uh, on the phone, there are text scams, there are email scams, there are scams on LinkedIn, there are direct messages on Facebook. Like, no matter how people communicate, either actively by reaching out to you or by setting up a, uh, watering hole, a place where you might just happen, ah, to stumble into, there are scams going on. And so I think the trick is to understand that that is the sad reality of the world today and to be very cautious and not to believe that simply because somebody handed you something or because something showed up in the mail or because you saw something at a charging station, that this necessarily represents, uh, the company that you think it is. And so be a little skeptical as you engage in the world. That's unfortunately the correct lesson. Um, it's a very sad lesson, but that's what's going to keep people more safe than just avoiding the latest technology.

Speaker B: And you have some other hacklore myths, right? Like something about password changes and can you give us one or two more before we move on to other things as well?

Speaker C: Yeah. So another one that we heard was around, uh, clearing cookies. So make sure that every few days you just clear all your cookies, which will of course will log you out of everything. And people again think that this is a privacy preserving tactic. And uh, I'm sad to report that your privacy is a very hard thing to protect and you probably can't, uh, is probably the truth of it. So clearing your cookies isn't going to do what you think it's going to do. There are, uh, of course plugins for your browsers which will limit certain kinds of tracking and prevent certain kinds of ads from popping up. Those have some efficacy, but they're, you know, the world is kind of filled with data brokers who are going to find ways to get your data. And it's outside the scope of the hacklore.org site to figure out how to keep you more safe. The other thing I'll mention is there really are high risk individuals who are not contemplated by this website. So there are people who are reporters working on national security matters. There are, uh, victims of domestic violence. There are so many different places where people need tailored advice that is going to be responsive to the way that the attackers are going to come after them. But this is really the, the advice for everyday people that is, um, is contemplated here. Not, not the high risk individual. So people come to me and they say, oh, yes, but what about this, this one case? What about human rights activists working in certain parts of the world? Yeah, they, they need special advice. This is not the website for them.

Speaker B: So the one, the final one I wanted to ask you is the, the changing of the passwords. Right. Like, I, uh, run into this all the time where people are forced to change their password every six months. So they'll just, I don't know, say, uh, the New York knits 2025, New York knits 2026, New York knicks 2027. And when their password was in a breach like five years later, the attackers could easily guess it. Uh, so can you talk a bit about that and what do you see the future of passwords going?

Speaker C: Yeah, so passwords, uh, have been the bane of everybody's existence on this call for many, many years, and there are really no good solutions. The best workaround that we have today is to use a password manager. And so the idea is to have a. Since you have to have passwords for some websites, you want to have passwords that are strong. And I define that as meaning that they're very long and that they are randomly generated by a computer, um, and that they're unique, so you never reuse them, ever. In fact, they should never have existed at any time in the history of the universe. That's really what you want to do. Remembering that for the 500 websites that you may have accounts on is impossible. So a password manager allows you to make sure that you have unique passwords that are very long and that are randomly generated so you don't remember them. That's the current best workaround. But now we have the advent of passkeys. And so I first deployed physical security keys, as Dario knows, at the DNC, in 2019. And since then, the technology and the usability and the, uh, number of sites that have deployed this technology has dramatically improved. Now with passkeys, you have a far easier user experience. And that is, I hope, the future. I defer to all of you just to tell me if that's actually the case, but I use a whole bunch of passkeys myself and, um, that's my hope.

Speaker A: So the, the thing about passwords, I worked a lot on it, so it's near and dear to my heart. We were attacking these password issues in the past. And the myth was you had to change your password all the time. And um, you'd have patterns like always use upper lowercase and a special character which drove users into specific patterns. They would always do first, um, capital letter first, and then a special character at the end. And they would substitute numbers for everything. And bad actors use that when they brought in password spray attacks. So what password spray attacks did is they like we call it a low and slow attack. They would just try different passwords, you know, once every five seconds to go under the detection and they'd span it from around the world using different IPs, so it looked like different users, but they used company policies against them because they knew that you required an uppercase, lowercase number, special character and you'd force a password change every 90 days. Which then the users got into these bad habits and the bad actors knew that they could program these attacks to use like common words, common phrases, and just said upper lowercase, number, special character. And that was kind of the myth was that you needed to enforce that. Right. And so, um, it was, you know, it took a long time for CISOs and everybody to get past the uh, you know, the concept of having to change a password every 90 days instead of using a really long password with a password manager that never changed. Um, so that's part of the lore that even still exists today because companies are still using these password policies.

Speaker C: Yeah. And it also got codified into regulation and so there are places where they can't change it. So once these stories become pervasive, regulators who are looking to find some way to, uh, instruct organizations to do certain things to be more secure, they'll grab onto the ones that seem measurable and that's one of them. And so you'll, you'll find that there are going to be certain institutions like the financial services industry where you talk to them behind the scenes and they'll say like, this is making me insane. We know this makes our customers less safe. And so, uh, and it's not only that, then when they're less safe, if there's a breach or if there's an account compromise, and it's, we think it's because of this, like we have to sometimes make them whole. So it's kind of our mistake at the beginning, but we're forced into these things. So you'll hear different kinds of stories like that. Um, and so these are the reasons why we need to think deeply about the stories. Because sometimes a well meaning person is going to say oh, since everybody tells me this thing, I'm just going to make this a matter of regulation.

Speaker A: Right.

Speaker D: I think one of the things that I find so appealing about this hack lore concept, it's really. It highlights that the distraction of these hack lores is a damaging element in itself. Like, we tell people, or people are being told, you have to change your password every 90 days and then you're secure, or you have to use a VPN and then you're secure. And it gives people a sense that they have accomplished something, they have done something. And it competes with taking actual. Taking real action. And, um, like, I wonder where you see that happening as well. Like, where are. Where are people putting themselves into a false sense of security because they think they have followed that. That statement. I mean, I remember the FBI field office in San Diego you mentioned that came up with the juice jacking statement. And then, yeah, tons of CISOs told their employees, don't, uh, charge your phone on, um, when you're at Starbucks or at an airport. But not having a charged phone can also then bring other security issues. So it's really this distraction. And, um, like, do you see that us getting rid of these hack lores is a step towards a less noisy security story?

Speaker C: Yeah. So I hope we could do a few things. One is, there's the very specific example of advice for everyday people. And so if we can bust some of those myths and help take back some of the communications channels from the folks who are selling products, I think that's going to be a big help. But you're hinting at something else, which is how do we expand the scope of our analysis of stories? And it's not just the specific thing that was bugging me that one Sunday afternoon, uh, when I just said, I just can't stand it anymore. I'm going to create a website. Uh, so I think there's. There's a lot more to it we need to start thinking about. As a sector, we're supposed to be very good at risk management, but we often engage in activities that seem to be diversionary. Uh, they seem to be things that cost a lot of time and effort and attention and money, but they don't actually make things better. And so this is an industry that is sadly free of the burden of real data and analysis. And so, uh, we suffer the consequences of that. But we should constantly ask if we're asking people to do something. And that could be enterprises, it could be governments, when we're asking somebody to do something because it's going to reduce Their risk. We need to ask, well, is that actually how the attacks work? What evidence do we have to support that? We should be pressure testing these things far more than we do. And what we'll find in many cases is that we lack the data to answer those questions. But we stop there. So we just go with whatever feels right or whatever our intuition was at the last job seemed to work there. So I'm just going to carry it forward here. But we need to start figuring out how to get a lot more information. That's sort of the tie into the whole secure by design thing, which is let's start asking questions about who's really responsible for something. Is it really the human who clicked the link that caused the downfall of the company? Because a system that is designed such that a user clicking a link, uh, accidentally causes a massive ransomware account that takes down the company, that's a system that's brittle by design. And so we have to ask ourselves, was it really the user or can we ask a few more whys and can we separate the proximate cause of the incident from the root cause? And so like maybe it's the IT team. Why did the IT team allow me to run admin? Uh, uh, run as admin. Like maybe we should ask that question, but we should maybe ask a few more questions beyond that, which is why do operating systems ship such that you can just go in and uh, anybody uh, can run anything, uh, by default and any application can access all my photos by default and we should be asking a few more wise to figure out where are the upstream fixes. Um, same thing with the hackler advice. There are places where I will be wrong on this. There will be some article at some point where somebody eavesdrops in on a conversation between a person in a cafe and their bank. That's going to happen. But that's not evidence that the website advice is wrong. That's evidence that some technology needs to go get fixed. So the question is if somebody gets juice jacked in the wild, the question is there's two companies you can call and say why did this happen? Why did this happen and what are you doing to fix this so that this never happens again? We can either choose to give advice to a billion people or we can go tell two companies to go change something. That's really where we are. And the stories that we tell and the outcomes we seek, we just need to be much better at tying those all together.

Speaker D: And I think when we often one of the feedbacks or pushback I get to this, when I talk about hack lords is that people sometimes also in the industry say well, but there's no harm in it. Oh yeah, there's no, nobody ever. There's no harm in changing your password on a regular basis or there's no harm in not using the Starbucks WI fi, but it's, it's still limiting us. And like uh, recently you had a post where you, I think you analyzed your own traffic Bob, about to see how much non encrypted traffic is actually still going out in and out of your computer. Like do these numbers help people understand that? Like that certain problems are really not there anymore? I think you had less than a half a percent of your traffic that was actually not encrypted. So the responsibility is not you to figure out which network you use, but it's the application providers to make sure that they just use basic common sense protections.

Speaker C: Yeah, I think that's exactly right. So I was surprised that nobody else was measuring their network. So for bizarre reasons I just, I tap my network and so I look at, I look to see like what's, what's not encrypted, um, some stuff like the thermostats and a few other things like that are sometimes non encrypted. Uh, some of the video transmissions uh, are sometimes uh, from various IoT devices are not encrypted. But uh, really everything is basically encrypted. And so uh, and off my laptop and my phone everything is encrypted, uh, unless I specifically go to a site that hasn't been updated since 2005, which um, occasionally happens but not very often. Um, and so I was just really surprised that nobody else had done that analysis that I could find and so I just published it. So I didn't do anything all that interesting. Although having said that, I did find a vulnerability in Apple and so I did have a CVE assigned to that and I got a bounty for finding something. So I think I paid off some of the gear that I had purchased to do all my network tapping. But you're asking something even more important, which is, uh, why does it matter? And the answer is it really matters that giving people information that doesn't help them stay more secure in a meaningful and measurable way is actively harmful. It is not neutral. Uh, it is actively harmful and is harmful because I have found that no matter what people tell me, no matter how much they convince me that they really want to stay secure, people are not willing to spend hours per month keeping their digital lives safe. They're not willing to spend minutes per month at best, no matter what they tell me in practice when I sit down with them. People are willing to spend minutes per year to keep their digital lives safe. And that's something that calculus changes after they get compromised, but before a compromise, minutes per year. So the advice that we as professionals give to everyday people, but also to enterprises, it needs to truly be the focused, stack ranked advice that is most responsive to how the attacks really work. So I'm glad you asked that question because it's, uh, it's, it's the reason we, we shouldn't tell people to avoid using umbrellas because they might be struck by lightning. Because people do get struck by lightning by holding umbrellas or standing near trees. Like that's that's happened. People stand near trees in a storm, tree gets struck by lightning, they die. You can tell everybody to avoid trees. Nonsense. That's the same sort of thing that we need to think about when we think about advice just in general. Not just everyday people for the things that I'm, uh, that I'm passionate about, but just advice in general. We need to think much more deeply about the audience, their appetite for change, and the way the attacks really work.

Speaker A: Bob, um, you mentioned in the attack you really need to go back and talk to two companies about really fixing the issue. Which brings to mind the problem or the question, like if you're building these security products or these security features in these companies, how do you get your management and uh, um, the CEO and the CISO to buy into these changes that you want to make? Uh, because you might be going against your features might stop growth or impact features that everybody likes, or because you're basically, you know, trying to make something more secure. And there's really no revenue at times, you know, revenue, um, acceleration or gain coming from it. So how do you think about that?

Speaker C: I do think about that. That's what you guys are for. That's what this podcast is to tell me about that. Um, so the only piece of advice that I think I have that's useful is one that I apply to just about everything, which is people learn and change their minds very rarely, but they change their minds based on either stories or stats. And so you have to figure out which kind of person you're dealing with on what day they are, what personality on that day there. But I think figuring out how they respond to those kinds of things is really key. Again, stories are kind of simultaneously easier but harder. Uh, getting real stats that move people to change their minds and to devote resources in seemingly non obvious ways, that's much harder. So I defer to the experts that you all are to figure out exactly how to do that. It's a hard question. I mean I fought the growth team uh, at all my companies. Every time they have a very specific thing that they need to get done. And ah, let's face it, the incentive structures, uh, in the world, both externally in terms of stock price and perception as well, that all trickles down into an organization. And so people get promoted because they are able to get 5% more eyeballs this month. That's how they get promoted. Um, and so it is hard to create a culture where you get to be promoted because you prevented a certain number of things. That's just hard, that's just a hard calculus to make, especially because you can't prove what didn't happen. So you've got multiple things that are holding you back from making a persuasive argument. But uh, in the end I've found that stories were probably more compelling than the stats. Uh, just because talking about a grandma who lost her Twitter account or whatever because of something and it was the way that she like those stories do matter, I think, uh, a great deal more than people think.

Speaker A: I think the data piece is key too. It's something that we talk a lot about on the podcast and a lot of people building the products. You mentioned it like oh, that data is not easy to get or you can't figure out how to actually do it. And one of the things that we recommend to people that we talk about this is like, hey, keep iterating, trying to get the data that you need, trying to get a handle on it, get a proxy, um, don't give up because that's one of the reasons, one of the ways that you're going to convince people to um, adopt or invest in these security efforts. And one of the things we talked about in, and one of the reasons uh, Jeroen and I met was um, we were working on at Microsoft, um, we wanted to enable MFA for all consumer customers. And that went anti growth because everybody was afraid that if we started asking for secondary information, users would just walk away. So we spent a lot of time on the data and what we found is because the users had second factors, they were able to better recover their accounts if they got compromised. They felt more comfortable using our accounts and our services and it actually led to growth because uh, we'd have revenue growth because the users were more engaged and then we would have less people walk away which basically negated any detrimental effect to new users. And so after we figured that out and started applying it, that's one of the things that we went to our industry peers and said, hey, you need to uh, start, you know, give a fresh look at the data and how things go. And um, I remember talking to Jeroen about it and he was like, yeah, like growth is what everybody looks at and like this would be a non starter without uh, proper argument. Right, like having all your ducks in a line. And it took us a long time to get the data but we kept at it. So I think it's, it's an important thing for people building security products to remember is to keep the data pursuit going.

Speaker C: Well said.

Speaker B: Speaking about security myths, uh, we have a lot of uh, different security myths that we talked about today, but there's an entirely new class of software being built which is AI. Uh, and Bob, are you already seeing security myths around AI that we should debunk right now before they become common sense?

Speaker C: Yeah, somebody said that we should start a uh, an AI hacklore, uh, portal or maybe a sub, subsection. Um, the stories that we're hearing, uh, it's hard to know. For each of the bits of advice that we have in the hackler.org, we say this is the thing that people have been telling you, this is why it's not true. And then here's what you should do instead. That's. We, I personally don't have that complete story for all the things that we see in AI. The, the everything is moving so quickly and people are bought into either the doomerism or the accelerationist. Like there, there are all of these different stories that we're telling. It is very hard to know which of those is untrue in part because it may be true next week. The, the thing is things that people were saying, oh, but AI can't do this just a few months ago. The AI is now doing that flawlessly. So I'm open to advice from you or your listeners. I do think that there are probably a number of uh, bits of AI lore that we do need to articulate and debunk. But for me the fire hose of change has really caused me not to, to dive in. But if anybody has ideas, I'm completely open.

Speaker B: Well, what you see a lot is that companies or I see a lot, I don't see it a lot. But what I imagine is companies that are like, oh, I don't understand, so let me just turn it off. And that's kind of uh, such a waste because the world is, as you said, is moving so fast. If you don't at least experiment with it, you're going to find yourself on the other end and all the companies that did experiment with it will be leagues ahead of you. And yeah, there are lots of security controls and products out there that help you to do AI secretly, uh, securely. Sorry. But yeah, you're right, the uh, myths are being written right now I guess.

Speaker C: Right.

Speaker A: I think one of the myths that are going to propagate is the whole open cloud and the agents accessing your data and there's whole industry efforts working on addressing that issue. But because it was such a big deal, it's going to linger on in people's minds that AI accessing your data is a huge problem. Um, even though it's going to be fixed, hopefully by all these identity standards that are being worked on.

Speaker C: We spent 30 years trying to reduce the likelihood of arbitrary code execution and data extraction. We spent our careers for 30 years that was what we were doing. And now we're saying, oh well, yeah, yolo, just give uh, these uh, alien technologies access to literally all of our data and I'm sure it'll come out great. So we'll see.

Speaker D: And that's maybe the phase we're in right now with a lot of these AI technology. I mean like OpenClaw is such a good example where I don't know how many uh, Mac minis that Apple sold because people want to run OpenClaw on a specific device but still logged in with their Google account and all of their other accounts to give it access to data. So I think a lot of the things that we're now going through, like those growing pains of, yeah, maybe you shouldn't have uh, an AI agent that has access to all of your indefinite sessions without any scope limitations. All of the things we're learning, those growing pains, those will be the heck lores of next year and in five years and in 10 years. So maybe there are things that are, yeah, uh, there's a lot of things that we are learning now that we'll do better in the future. And I think a lot of the standards that have been mentioned to make E commerce, financial transactions, health analysis, all of those things more secure with AI. But maybe we should learn from the last 30 years of hacklores. How do we avoid building new ones as we're making this new technology also more secure? So maybe you should make an MCP server that with hack lore that every language model can be trained with um, to avoid creation of hacklores.

Speaker C: I think you're joking, but that might actually work.

Speaker D: I wanted to make a joke, but then while I was talking, I realized, well, who do people ask now about security advice? It's LLMs. So if LLMs don't spread hack lore, um, then we win.

Speaker B: Bob, thanks so much for joining us today. Any final thought you want to get across to our listeners? Any final content?

Speaker C: Yeah, check out hacklore.org send, uh, me, uh, your thoughts. But I think the main thing is just to keep moving upstream. So when we give advice, ask if we're giving the right advice to the right people. And this is just an example for the everyday people on the, the website that I created. But again, do we want to try to change the behavior of a billion people, or can we ask a handful of companies to change their, their software and their hardware? That's the same kind of question we should be asking throughout everything that we do. Are we moving upstream, uh, or are we really just treating the proximate causes of problems? And I see this everywhere I go on every project since I started thinking this way. Every project I see has some, uh, bias towards proximate causes, not ultimate causes. So move upstream.

Speaker B: Yeah, that's what we said. Also one of our podcasts, like, try to take the user out of the loop and just solve it for it so it's not a problem anymore. And yeah, thanks so much, Bob, for joining, uh, our podcast today. Thanks, Dana and Dario, as always for being such great co host. And, um, yeah, thank you for listening wherever you are, uh, wherever you're in the world, for listening, for watching. And remember that we're all out there to keep everybody safe and save you. One is worth it. And we'll see you all in the next one.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Secure AI Starts with EducationBuilding Unbreakable Brands · on Password managers86 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Passkeys82 / 100
  • AI for Security vs Security for AI: From IBM Master Inventor to Microsoft AI ArchitectShipTalk · on Password spray attacks78 / 100
  • What happens to commerce and payments in a programmable world?Voice of MPE · on Passkeys71 / 100
  • When Identity Becomes The Front Line Of CybersecurityThe Business of Cybersecurity · on Passkeys71 / 100
  • How Crypto Onboarding Finally Gets Easier - Aditi Sriram | ATC #618Around The Coin · on Passkeys67 / 100

More from The Inverted Podcast

All episodes →
  • Inverted Podcast #24: What’s Happening in Identity?80 / 100
  • Inverted Podcast #23: Recovery- The Most Dangerous Feature You're Ignoring74 / 100
  • Inverted Podcast #22: Become Incorruptible with Eric Ries74 / 100
  • Inverted Podcast #21: AI Regulations & Humans in the Loop55 / 100
  • Inverted Podcast #25: Product Design for Trust & Safety
Explore the best B2B Product podcasts →
All The Inverted Podcast episodes →