In short
Tech Leaders Podcast - Episode #89: Chris Wysopal, Founder and CTO @ Veracode: Ethical Hacking and Cyber Safety
Episode Overview In this episode, Chris Wysopal, founder and CTO of Veracode, discusses his experiences as an ethical hacker, the evolution of cybersecurity, and the significant role of his team at L0pht in raising awareness about IT vulnerabilities. The conversation covers a range of topics, including leadership, ethical hacking, government responsibility in cybersecurity, and the impact of generative AI on the field.
---
Key Topics Discussed
- What Good Leadership Means to Chris (02:20)
- Empowering team members to be their best.
- Supporting problem-solving and cross-functional collaboration.
- Fostering growth among individuals and the organization.
- Pioneering Cybersecurity (04:20)
- Chris's transition from software engineering to ethical hacking during the early days of the internet.
- The establishment of L0pht, a hacker collective that focused on discovering and addressing security vulnerabilities.
- Major Breakthroughs by L0pht (12:47)
- Raising awareness about critical vulnerabilities in widely used software, particularly from major vendors like Microsoft.
- Emphasis on the importance of ethical hacking as a means of improving security.
- Testimony Before the US Senate (18:00)
- L0pht's impactful assertion that they could "take down the internet in 30 minutes."
- The significance of this statement in demonstrating the vulnerabilities present in cybersecurity at the time.
- Government Actions on Cybersecurity (22:12)
- Discussion on whether governments are doing enough to prevent cyber-attacks.
- The need for regulation and accountability from technology vendors.
- Generative AI's Role in Cybersecurity (32:00)
- Potential benefits and threats of generative AI for cybersecurity.
- The dual-use nature of AI technology for both good and malicious purposes.
- Introduction to Veracode (34:24)
- Overview of Veracode’s mission to provide security in the software development lifecycle.
- The importance of integrating security testing as part of the software development process.
- Advice to His 21-Year-Old Self (43:24)
- The importance of persistence and hard work in entrepreneurship.
- Realistic expectations about the time it takes to build a successful startup.
---
Key Takeaways
- Ethical Hacking: Wysopal’s journey emphasizes the role of ethical hackers in identifying and fixing vulnerabilities, advocating for a proactive approach to cybersecurity.
- Awareness and Education: The testimony before the Senate played a pivotal role in raising awareness of cybersecurity issues and the need for better defense mechanisms.
- Collaboration: Wysopal highlights the necessity of collaboration between hackers and vendors to improve software security.
- Evolving Threat Landscape: The conversation acknowledges the challenges posed by emerging technologies, particularly generative AI, and the ongoing cat-and-mouse game between attackers and defenders.
- Regulation and Responsibility: There is a growing expectation for technology vendors to take responsibility for security, supported by evolving government regulations.
---
Conclusion This episode captures a crucial moment in the history of cybersecurity, revealing the evolution from a nascent field to a vital component of modern technology. Chris Wysopal’s insights underscore the importance of ethical practices, continuous learning, and proactive measures in safeguarding our digital landscape.
For more information, visit [Be Digital UK](https://www.bedigitaluk.com/).
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Transcript
Automatic transcript. May contain errors.0:00And we told them we could take the internet down in 30 minutes if we wanted to. And that was the headline. I mean, if you're saying you can take the internet down 30 minutes out. So that was the big takeaway from the hearing. And then we told people how to fix this.
0:20so we were lucky enough to have the opportunity to interview one of the chief protagonists of the loft group one of the most important ethical hacker groups in the history of software and cybersecurity. Back in 1998, a group of young elite ethical hackers went to Capitol Hill and in front of a puzzled US Senate committee, warned of the impending threat around the evolution of hacking, especially adversarial hacking. One of those protagonists was a chap called Chris Weissopal. Chris is a seasoned veteran in the cyberspace, as well as an entrepreneur in his own right, and general oracle when it comes to anything related to penetration testing and ethical hacking.
1:13We really had some fun doing this interview. We talked about the history of hacking and the cybersecurity space generally. We talk about that moment of infamy when they chillingly professed to the US Senate committee that they could take down the internet in 30 minutes and how profound that was and how impactful it was on Chris and his peers. We talk about the real threat of quantum computing. Chris tells us how robust the Bitcoin network really is to hacking. And also we discuss how impactful generative AI is going to be on the cyberspace and also on the SaaS business model. There was so much value in this episode.
1:54I took so much from it. I'm sure you will too. It is Chris Weissopal.
2:04Chris, I've been really excited to talk to you. I mean, your background is incredible. I've been through some amazing experiences in your career, and I'm looking forward to unpacking those. But before we dip in too much, I just want to ask you the question we always start on. What does good leadership mean to you, Chris? Okay. Well, Gareth, thanks for having me on the podcast. Good leadership for me is letting your people be their best, letting them do the problem solving, letting them work out how to be cross-functional within an organization, and really being there for vision and guiding. And then when there's execution challenges, maybe helping there.
2:47But I think the real thing is you want to see your people grow. You want to see your successor grow into that role. You want to see everyone grow. And that's a source of pride to see people take on more challenges and leave the company you're at and go start their own company. I mean, that's leadership, I think. That's fantastic. Yeah, I think leaving people in a better place, having known you, I suppose, is probably another way to put it, isn't it? Is empowering them to fulfill their potential. So I love that, Chris. That's really, really great answer. So Chris, for the listeners who are not familiar with yourself, could you maybe give us a little bit of an overview of your background?
3:28Sure. So as a teenager, I was really interested in deconstructing things and hacking and learning about how things worked. The personal computer had just come out, so I'm really dating myself and trying to figure out how that worked and all that. And so I got a taste for sort of reverse engineering and hacking and taking things apart, but there was really no career in that. So I went to school for computer engineering. I went to Rensselaer Polytechnic Institute and got a bachelor of science in computer engineering. And I was interested in both hardware and software. I didn't pick one over the other, but eventually all the jobs were in software.
4:11So I became a software engineer, and that's what I kind of did in the 90s for a while. And then I realized my passion really was hacking. Oh, wow. So I kind of segued in the mid-90s to the late 90s to a career in cybersecurity when there really wasn't any careers in cybersecurity. I kind of had to pioneer the way to be, you know, I'm just not a compliance guy. I'm not going to just check boxes. I'm actually going to hack things and break into things and find vulnerabilities and figure out how hackers do things. That was all new in the 90s. So that was really how I started was moving from software engineering to figure out how to make a career in hacking.
4:52Wow. So I got to ask you this, Chris. What was the first computer you had? So my first computer that I actually owned was the original IBM PC. Oh, wow. It didn't even have a hard drive. It was just two floppies. Oh, wow. So it was pretty basic. But before that, I played around a lot with the Radio Shack TRS-80 because that was something that was available at the mall. So I would go there at the mall and be able to play on a computer before anyone even really even had one at home. It was in the very, very early days. And so I was hooked. Oh, wow. I've not heard of that. You were obviously in early then, and you were hooked early then.
5:32I'm amazed. Just to quickly talk about those early days as well. I can't believe you foresaw that there would be a vocation within cybersecurity at that time, in the mid-90s. You must be a bit of an out there thinker to even consider that that was an option for you. Yeah, that was the thing. So I was involved. I ended up finding a group of hackers in Boston that sort of had a like mindset. We weren't like, we're going to figure out how to steal money by credit cards or something. we were trying to figure out like how does cyber security even work like how are these companies protecting themselves from the bad guys how can we figure out how the bad guys work so that's why we called it a hackers think tank we were really kind of pushing the envelope of this and at some point we said you know companies would want to hire guys like us first but at first we realized that they didn't want to hire guys with hacker handles and hacker names.
6:32And they wanted to hire people who look like IBM professionals. So that was the gap between our skill set and our mindset and what companies would hire. And that's the gap we kind of had to bridge in the late 90s and say, no, actually, you should take us seriously. You should listen to us. We actually know how hackers work. We can actually find the same problems and write the same tools they do. you should hire us. And it really took, I think, that US Senate hearing that I got invited to with my colleagues from the loft to sort of wake people up to the fact that people from our background could be trusted and should be listened to.
7:13Yeah, absolutely. So can you tell us about how that group then that you joined, how did that come about? And what was it like in the early days? And can you elaborate a little bit more about, sorry, I don't know how you say it, L0PHT, yeah? We spell it that way because that's hacker elite speak. Like, you know, hackers were the first ones with online culture, right? So we pronounced it loft. Yeah, sure. Online culture really started with hackers because we were using any vehicle we could to communicate to each other over text, even before the internet, right? With bulletin board systems where you would use a modem.
7:49The older folks, remember, that's how you connected to the internet before broadband. There was actually, you would use a modem to dial up to a bulletin board system and share files, share text files, communicate, chat with people. And that's how I met the people at the loft was through these bulletin boards that were focused on technology, focused on, you know, computer cybersecurity, focused on hacker techniques. And so I found people by going to different bulletin boards and finding a little community there that was people interested in like, well, how does the cell phone system work? Like, can we reverse engineer that?
8:25Can we take a phone apart? Can we learn how the firmware on that works? Can we look at the radio and understand how it's communicating? That was like the hacker mindset I was interested in. It's like figuring out how to reverse engineer things. And then you can figure out how you can manipulate them, where the weaknesses are. And so we had seven, eight people at different times come together at the loft, all with slightly different skill sets. I was more on the software side. Other people were more on the hardware side, the radio side. We came together and we started to do projects and learn how Microsoft Windows worked, how Internet Explorer worked, and we figured out how to break it.
9:03And we started to publish what we were doing. And we were like, everyone should know this. Everyone should know if they're using Microsoft's Internet Explorer that your computer can be compromised and taken over unless you patched. Or there was vulnerabilities that Microsoft doesn't even know about. These were all new concepts back then in the 90s. And that's what got the press interested in what we were doing and eventually got us invited to speak at the Senate because the Senate was like, computer security is going to be important to the US federal government. We need to understand this. And I think they had a lot of foresight to say, we want to hear from hackers.
9:42We don't want to hear from people that worked for AT &T's security department or Microsoft's security department, even if there was such a thing back then. There might have been a few people or a bank. We want to hear the people that were trying to break in. And that was how we kind of changed and made jobs for ourselves because we showed that you need to understand the adversary. You need to understand the offense or you clearly can't do cybersecurity. And we were the ones that you should be talking to if you want to understand that. I'm assuming Loft wasn't the only hacker group around at that time.
10:18I don't know if the cypherpunks were around then and a couple of other groups. Yeah, the cypherpunks were a little bit earlier. There were some other groups out there, like Legion of Doom was one. That was a WWF wrestling tag team, wasn't it? Yeah, I know. It's just so funny. The names back then, like people's hacker names were Kingpin. Yeah, yeah. And, you know, there was a guy, Eric Bloodaxe. Like everything was overdramatic, right? But yeah, there were people that were before us. But to be honest, they were a little bit early. Like society wasn't quite ready yet. Like it took a few years of sort of sanitizing hackers to be like, you know, we're not all, you know, evil masterminds trying to steal all your data and take all your money.
11:05That the techniques of hackers were the value. And it could be used for good or bad. I mean, that's one of the big lessons I've learned is everything is dual use. Like people are like, well, isn't Gen. I going to let the bad guys do all this stuff. I'm like, well, what about like the internet and microprocessors? Yeah. Like they're in, they're in missiles. Right. And, and, and communication networks. So like technology has always been used for good or bad. So I'm, I'm all for the good guys using the technology. Yeah. And that's why we need to leverage things like Gen. AI. So I think understanding how things can be used for bad is part of solving for the good.
11:49Yeah, sure. This episode was brought to you by Be Digital. Be Digital support leadership teams to optimize cost and get more out of technology investments. Be Digital and the team have unrivaled expertise with technology license management and data remediation and are therefore perfectly positioned to help prepare organizations for AI technology capability. And on the last point, BDigital have just developed a cutting edge AI readiness assessment, which provides tech leaders with a platform they need to make well-informed decisions about AI adoption strategy in 2024 and beyond. Go to BDigitalUK.com to find out more and get in touch.
12:39So, reflecting on the time with Loft Group then, Chris, okay, what were some of the most challenging or most profound sort of ethical hacking discoveries you made? And how did they shape the cybersecurity landscape from the work that you guys did? And how did that shape how cybersecurity was approached and thought about? Yeah, so I think some of the important stuff was what we were doing with Microsoft Windows, because it wasn't esoteric. It wasn't like only banks use this, and we could only break into banks with this piece of software or technique. It was something that was becoming the foundation of all business.
13:20You were doing penetration testing, basically, on Windows. on the software, right? So that was the big discovery was you didn't say, oh, I have a target, it's this bank. Let me learn what they're doing, how they're doing it and how to break in. It was the big profound discovery was I'm gonna target the software that I know is widely used. So if I set up a lab environment and I set up two Windows machines talking to each other, a web server and a web browser, and I set this up in my environment, I can legally hack on this. Like I legally purchased the software, I'm legally running it, I can hack on this, I can find vulnerabilities and then when I find that vulnerability, I can write a tool that will exploit that vulnerability and now I have something that if anyone is using that software anywhere, I can attack them and everything I've done is ethical and legal and what I'm doing is I'm pointing out problems.
14:20Now, some people will say, well, what if you distributed that tool? Right? Like now people can hack into things. And I would say, well, but now people can see if they're vulnerable. Right? They can test it out and they don't have to believe me. They don't have to believe the vendor. They don't have to believe the government. They can run the tool and see how it works and what it's doing. And they can see if they're vulnerable. So it was sort of that understanding that you could hack on software legally, and then you could demonstrate with full force of working proof of concepts that this stuff is real.
14:53And I think that was very powerful. And that was when a lot of businesses woke up and the government woke up to say, like, you know, there's a new breed of hacker out there and they're reverse engineering software and they're building exploits. And so the other profound thing that really happened was Microsoft actually came to us and said, you know, we want to fix the problems that you're pointing out. We know we have to fix them. We want to fix them. Would you let us know about the problem before you told the world? And that way we could protect our customers from this problem. And they didn't quite say the problem that we created, that we should have found.
15:35And they weren't like, oh, thank you for finding this and thank you for bringing it to our attention, which later companies started to do. But at the beginning, it was like, just please tell us so we can protect our customers. Protect their brand as well. It's the PR thing, isn't it? It's a big PR thing because then you're controlling it, right? You're controlling it. When we start talking about it, they're like, yes, and we fixed that a few weeks ago and the patch is available and our customers can be protected. But that was a phase that we had to evolve through before companies would start to do this themselves and realize that they should be doing it themselves.
16:13So this was the other big evolution was we needed external hackers to point problems out to these big vendors and kind of shame them a little bit and to say, you know, you guys need to do better. And I think that's what we were doing when we went to the Senate. We were saying these companies like Microsoft and IBM and Oracle, they can find the same things we're finding. You might think we're super geniuses, but actually people can be trained to do this and the tools are available. So we said, anyone can do this and the vendors themselves should be doing it. You shouldn't be relying on us to do it because if they don't do it, we're going to do it or someone at an adversary will do it.
16:54A very big moment when we were at the Senate was Senator Fred Thompson, who was the chairman. You might know him from Hunt for Red October and other T and some TV shows. But he said, what's to stop a adversary like Russia or China from getting a group of individuals like you and attack and doing the exact same thing, finding vulnerabilities in software and using that to attack the United States government. And we actually hadn't thought of that. It was actually a new thought because no one was doing it back then, right? No one was doing it. It was the early days. And we said, you know what, that's a really good point.
17:35We think that they could absolutely do that. And it really kind of changed the calculus of protecting the United States government and the military. It changed the calculus to see that this was possible. So what were you thinking about? What threats were you guys discussing? Like attacking national infrastructure, just attacking military systems, satellites, NASA, I suppose, could be something they could attack? Were these the kind of conversations you were having? Absolutely. I mean, the big conversation was like, can you take down the internet? That was really the punchline. We came knowing that we knew vulnerabilities in internet routing and the internet routing protocols.
18:11And we told them we could take the internet down in 30 minutes if we wanted to. And that was the headline. I mean, if you're saying you can take the internet down in 30 minutes, so that was the big takeaway from from the hearing. And then we told people how to fix this in the government. But yeah, we were talking about taking down the internet, we were talking about taking down the GPS system, satellite communications, we were talking about hacking the power grid. And so yeah, critical infrastructure. And I think that was the start of the federal government really taking this seriously. Yeah, sure.
18:43I mean, taking the internet down in 30 minutes, that was very, that was a very impactful thing to say, which I think caught a lot of the imagination of a lot of journalists, didn't they? And I think you did get a bit of notoriety as a result of that. So can you tell us a little bit about that, reflecting on that sort of testimony before the Senate committee? This was 1999. Was it 98? 1998. So a little over 25 years ago. I think we were scared going into it because we didn't know if we were going to be thought of as the bad guy. They were going to say, all our problems are due to people like you, like you shouldn't be publishing any of this.
19:24All you're doing is hurting, pointing out problems is hurting, you know, and that, that is one viewpoint. And, you know, when you, when you think about maybe the federal government, you, you think like you might be, you know, a scapegoat, right? A lot of these hearings, they turn on the people. And, and so we had no idea what was going to happen and why we were invited. Should we really believe why we were invited there they even let us testify with our hacker aliases like i had a placard that said weld pond in front of me my to my left was a guy with a placard that said mudge and to my right was a placard with a with a guy that said space rogue i thought they would have had your real names in the senate committee no and they told us we were the only ones allowed up to that point to use our fake names uh testifying the other people were in the witness protection program yeah That's incredible.
20:17You made history there then, Chris, yeah? We made history. So, I mean, the whole air of the whole thing was very special. It wasn't a run of the mill. We have hackers with their hacker names here. And so it was a lot of these hearings, not all the senators show up. They all showed up for this. It was a packed house and packed audience. So it was very exciting. I thought we were making a difference. I thought the, we were really connecting with some of the senators, like Senator John Glenn was there. I got to meet John Glenn, which was amazing. And, you know, he had a question about the global positioning system.
20:55And he said, he started, he says, hi, hi, gentlemen. I don't know if you know this, but I'm a pilot. And, you know, obviously - John Glenn was an astronaut, wasn't he? He was one of the - John Glenn was an astronaut and a test pilot. So, you know, there was some laughter in the room when he said, I'm a pilot, because obviously everyone in there knew that John Glenn was a famous astronaut. First guy to circle the earth, I think. Yeah, yeah, I think so. First human to circle the earth. You know, he was obviously technically adept at technology. And he asked about the GPS system. He says, you know, he's a pilot.
21:29He flies all the time and he relies on GPS. And we talked about that. So, you know, a lot of it was like very concrete stuff, right? It wasn't like esoteric. It was things that were going to impact people's lives. Yeah. And they wanted to understand how technology is brittle and vulnerable and what we should do about it. Yeah, I suppose if you've got someone like John Glenn pointing out concerns around an adversarial's ability to hack into GPS systems, I think people start to listen and take things seriously then, don't they? Absolutely. And little did they know this was going to become such a huge subject matter and give birth to the cybersecurity space, I suppose, as the internet and everything evolved.
22:11But how do you currently see government involvement in regulation around cybersecurity? Have you got any thoughts on how that has played out today? Are government doing enough? Are we still a little bit behind the curve? I'm talking about the US, I suppose, or globally. What was your thoughts on the current status quo? Obviously, there was no regulation back in 1998 or very, very little. We saw that that was a problem because we saw that there was real risks. And we saw with using software and internet and connecting it up to critical infrastructure was going to cause some real risks. I mean, we saw the colonial pipeline.
22:52We've seen the power grid go down in places like Ukraine and Estonia with cyber attacks. So it's like no laughing matter. It really is life or death. And there was absolutely no regulation back then. And basically, we said that vendors need to do better, right? Like vendors need to do this. This concept of having external researchers find some things and having those few things be fixed just isn't sustainable. But then again, regulation is challenging around technology because you want the innovation, right? Maybe big companies can handle regulation with teams of lawyers and compliance people, but startups, it's very challenging to comply to different things.
23:37So we understood that regulation was going to be a challenge. I think we're still, some things have changed over time, but we're starting to see some motion in regulation in the United States, at least, I think in a good way, which is where the buyer expects things of the seller, right? And so the regulation we're starting to see in the United States came out of the US. Biden had an executive order two years ago, the cybersecurity executive order, and said, the US federal government is going to make vendors of technology attest that they have security processes. And they've tried to make their software and hardware secure.
24:19And they're going to show us with facts about what they did. And then we're going to make a judgment. Did they do a good enough job? And that's going to be part of the buying process. And I think that's a good way to not be heavy handed, yet have expectations for vendors. And I think most vendors out there do build stuff securely now, but there's a lot that don't, a significant amount that don't. And so I'm hoping this level of regulation gets everyone on board with, we can make things significantly more secure. Not perfect. No one's looking for perfection. Yeah. No one's looking for a plane to never have any problem, but we don't want people to die.
24:57We don't want them to fall out of the sky. And so regulation around a dangerous technology seems to make a lot of sense to people. I think we're heading in the right direction. I think it's just taken so long. We talked about holding vendors accountable 25 years ago, and we're starting to see that now, at least with the federal government. And we're starting to see it in the EU with the Cyber Resiliency Act. And I know the UK is also working on something very similar to hold, especially makers of connected technology like smart TVs and all these IoT devices that are peripherating and controlling our doors, our locks, and parts of our lives make those more secure.
25:38Yeah, sure. Can you just maybe in quite simple terms, where is the border between secure and insecure? What do you mean by being secure? Have you got a specific thing that sort of means it's secure? What is the provision you need to take in order to be categorized as secure? Yeah, so I would say put the software through or the hardware through the kind of attacks that an adversary would do. So we know of a whole bunch of different classes of vulnerabilities, right? If you're making a jet engine, you know one of the vulnerabilities is cracks or bubbles in the castings of the metal. If you're making a fan blade, you know that things can go wrong in the casting process.
26:26So what do you do? You test it. You X-ray it and you look for those cracks and you look for those air bubbles and you X-ray it to do that. So once you know of a known weakness or vulnerability, you can design a test to now test for that. So we know of all these different attack methodologies. So you design tests that test if that attack works. I understand. Or if the vulnerability is present, you can actually look for the vulnerability in different ways. Like you don't need to spin the fan blade. You can x-ray it. Both will detect failure. One's a non-destructive test and one's a destructive test in the case of failure.
Read the full transcript
27:04Yeah, sure. So the same thing happens with software and hardware. And so do all those things that an adversary would do or try to find the weaknesses an adversary would try to do and run those tests before you release the software to the public. So that's what we call software security testing today. And everyone who's building software or hardware needs to do this before they release it to the public. And so they get a certain assurance level by saying, how much time and energy and what kind of testing did I do before I put this on the market? I think that's what we're expecting people who build technology to do these days.
27:43How much of an issue is the innovation or the emergence of quantum computing for the cybersecurity space? Is it a bit of a myth that you don't really pay much attention to it? Or do we have something to seriously consider over the next 10, 15 years? Yeah. See, the estimates are just so crazy. It's like, it's going to happen. It could happen in 10 years. It could happen in 40 years. It could happen in five years. It could happen in 50 years. So I think the theory seems correct, but no one knows how long it's going to take to actually build it. It's sort of like fusion in the 80s, right? It's like, it seems possible the sun is using it, but you have to make some inventions along the way that you don't know about yet.
28:24So I think it is a risk, but I think there's a simple solution. And the simple solution is to make, you know, crypto systems where you're using encryption, decryption, make them pluggable. Like if you're building software today, make sure you can quickly swap out and update to a new encryption system quickly. So people are building these quantum resistant crypto systems today. We're not 100 % sure they're going to be quantum resistant. But when someone comes up with ways to break them, we need to be able to quickly swap to new encryption systems and decrypt the old stuff and re-encrypt it with the new systems.
29:02So I think as long as we designed with this crypto agility to quickly swap out and update crypto systems, then I think we're okay. So I think we're sort of planning for the Y2K moment when this actually happens. It's the years before Y2K when you're like, I know we have to do it. Let's just prepare for it. How robust are these distributed technology systems, in your opinion, Chris? Yeah, I think they're incredibly robust. I think the foundational level of blockchain is incredibly robust. There's been a lot of attention paid to them. There's billions of dollars there. If someone could break it, I think they would have by now.
29:42So I think the fundamentals of the blockchain and the fundamentals of Bitcoin and Ethereum are solid. But there's all kinds of technology that rides around those things that aren't so solid. And I'm talking about companies that are exchanges, they're bridges between different blockchains. Anyone can just write that and say, hey, come deposit money or cryptocurrency with me or use me for transactions. All of that software can be written in a way that has lots of vulnerabilities, just has poor protocols with where the humans interface with it. And, you know, we've seen lots of crypto heists, you know, starting with Mt.
30:27Gox, like six or seven years ago. And, you know, it's been a billion dollars or more a year for the last few years or billions. And it's just because there's a lot of software that's built to interact with these blockchains. I'm involved with a company called Enciphered, which does software and hardware wallets and recovers crypto that you may have mistakenly locked away because you forgot your passphrase. Oh, wow. Okay. And so all these wallets, whether they're hardware or software, have weaknesses in them that are just waiting to be exploited. Right? There hasn't been a perfect wallet yet. They keep getting better and better.
31:05But the beauty of this is old software will eventually vulnerabilities will be found in it. And if you lose your key, what you do is just wait until someone figures out how to crack your wallet. And so that's what this company is doing. They're figuring out how to crack wallets. And that's a good example of a technology that has weaknesses in it that you need to use. You need to use to operate on these different blockchains. You need to have a wallet. So you need to be able to store your private keys securely. And so that's an example of the edges of the crypto system that aren't perfect. Yeah, sure.
31:45So we talked a little bit about blockchain. We talked about quantum. Just to get your thoughts on the sort of macro emerging trends, maybe we can use this as a segue to get into Gen AI, I suppose. But is there anything, what emerging trends or challenges do you think are quite noteworthy at the moment within the cybersecurity space? So Gen AI is, I think, the big emerging trend. We've been using AI for a while with cybersecurity used to detect attacks mostly. It mostly was being used around detecting patterns to find flaws, find attacks, and things like that. And that wasn't terribly useful to the bad guy, right?
32:22But now with Gen.ai, we have something that's genuinely useful both to fix issues and solve problems and maybe even prevent them on the cybersecurity side. But Gen.ai is also good at generating attacks, generating exploit code, generating content for phishing and things like that. So I feel like with AI, it was some incremental progress for the good guys and it was valuable. But now with Gen.ai, we have a huge breakthrough for both the good guys and the bad guys. And so there's a new cat and mouse game going on where it's who's going to take advantage of this technology better. And it's something that we're really focused on at Veracode because we don't want to find just problems in your software.
33:13We want to help you fix the problems in your software. And one of the things that's always dogged us was how do we generate that code to fix a problem for someone? We would tell them basically the guidelines, oh, you want to do some infant validation. You don't want to make a SQL query this way. You want to kind of make it this way. And that took some learning by the developer to actually fix problems. It took a lot of time. With Gen AI, we can just generate the fix. We can say, here's the code, cut and paste this in, or accept this pull request, or merge request. And so we can automate the fixing process, not just the finding process.
33:50And that's the thing that's really exciting about Gen I is it can automate the job of a cybersecurity professional to fix things and deal with attacks. And we need it badly because there's not enough cybersecurity professionals to go around. And we definitely need it badly if the attackers are taking advantage of GenII to write and scale their attacks. So it's going to be an interesting next few years as we see how this evolves. Yeah, sure. So I know you obviously set up a company, Veracode. Can you just give us a little bit of an introduction to Veracode? What problem did you set out to solve?
34:29And there's a little bit of an overview on how you've evolved and where you are today. Yeah, so some of the things I was talking about earlier where you needed adversarial thinking at the software vendor. You needed someone who would run those tests, who would attack the software. I did that as a consultant. That was like my first cybersecurity job. It's like, hey, fly me to Microsoft and I'll sit there and I'll type on the keyboard and I'll show them where their problems are. And I did that as a consultant for a few years and actually did it for Microsoft. And at some point, I realized that I can only be in one place at one time.
35:04There's not enough people around here to do this. I need to write software to do my job. I need to replace myself with automation. And so that's where I founded Veracode in 2006 with actually one of my co-founder is a guy from The Loft, Christian Ryu. And he was up there at Microsoft too, showing Microsoft how to do this. And we said, let's make a product that then software vendors can use and make it part of their software development lifecycle. So part of building software is doing things like quality testing, making sure the features work, making sure if someone bangs on the software with a load, the server doesn't crash.
35:45Performance testing. These are all the things you want to do before you release something to the real world. And what we say is add security testing to that mix. So we write security tests. We write software, like there are people who write performance test software and people who write quality assurance software. We write security testing software that software companies can use as part of their software development lifecycle. So they can actually build this in. So every time they check in code, they can run our tests to see if they just created a new weakness, a new vulnerability that could be exploited.
36:22We can point it out to them. And now the exciting thing is with Veracode Fix, we can tell them how to fix it. Someday we'll just fix it because they'll trust us so much to just do it, right? So we're not quite there yet. So right now the developer is still in control, but that's where we're at. And it's very exciting to just give developers instructions and pieces of code that they can just fix their stuff and move on building the functionality that they want because they don't want to learn how to do this, right? They just want to build their cool software. And we're there as their security expert automating the process for them.
37:00So let's talk a little bit about what excites you at this point in your career, Chris. What technology innovation are you really excited about? And maybe let me add a bit onto that. What technology innovation are you most concerned about too? So I think I have to go back to Gen AI in this question. I think that whenever we see a big new technology come out, I think the last one that I would say is a big new technology that impacted the world was cloud computing. I feel like there's so much more software available and Internet of Things and devices doing things that would not be enabled unless we had that cloud computing infrastructure that startups could use and build upon.
37:45If everyone had to build a huge data center, I think we'd have much less innovation and much less software. So I saw that as the thing that happened sort of over the last 10 years. It had a huge impact on cybersecurity because there's all these new vulnerabilities, all these new ways of doing things. People could take advantage of the cloud to do attacks and scale attacks, but they could also take advantage of the cloud to secure things. So it was a new technology, and it was interesting to see how both the adversary and the people in cybersecurity were using that. I think Gen AI is the same thing.
38:22I think we're going to see this over the next 10 years and maybe beyond, maybe beyond. I mean, people are arguing, like, is this a bigger impact on society than the Internet? And I think the jury is out on that. We don't really know. It needed the Internet to actually get here, but what impact will it have? And from a cybersecurity perspective, I'm very excited that we can automate fixing issues. We can automate people's actually jobs. People say, you know, it's going to take white collar jobs away first because it's automating white collar jobs. And but it's it's it's automating a lot of the grunt work.
39:00It's automating a lot of the grunt work that people just don't want to do. Like I know developers don't want to fix code. They don't want to take my advice and change their code to fix a vulnerability. that's just taking their time away from building the cool new thing that they really want to do. I want to automate that grunt work. So I think that's an example of automating grunt work to allow us to innovate. So yes, it is getting rid of a white collar task, but it's allowing that engineer then to innovate and be creative. And so that's how I see Gen.I. really impacting the tech space. And I think it will make us improve cybersecurity, but it's going to have to, because there is the doom scenario where it allows the evil genius to have all these agents around the world that are doing all these bad things.
39:52And it's force multiplying evil ideas. And we definitely have that. And so we need to be prepared for that and automate against that. So I'm an optimist. When I see new technology, we've constantly had new technology, nuclear technology, genetic engineering technology. And it's super powerful. And we've always seen the doom and gloom, but we're still here. And we see the doom and gloom over nanotechnology and over AI. But I think if we're optimistic and a lot of things that I read are like how this is going to be, you know, this is going to be good for society. So I see good and bad in everything.
40:41And but I think the good will prevail. Yeah, I think in terms of the field of medicine, okay, and the evolution of medicine and other biotech industries, I think generative AI is going to have a really profound positive effect on those industries. You know what I mean? Absolutely. I was listening to a podcast the other day and they were talking about how generative AI is going to have an enormous knock-on effect to SaaS businesses, okay? Because people will potentially be able to generate their own software on demand for things, which will remove the need for you to purchase SaaS products and things like that.
41:22Is the SaaS business model sort of a phenomena between the internet and AI? Do you see it like that? Or do you think that generative AI is not really going to be creating software products for people on demand? Yeah, I do think that generative AI is going to change the notion of the kind of software that people can create on their own. I mean, today would be someone learning Python and scripting up home automation or scripting up some of the tasks in their job to do things that you might pay a provider for. So I do think that it is going to allow people to do more with software, customize things with software and not rely on maybe service providers as much.
42:11But I don't think it's going to go away because you do need someone who is centralizing that data and is working across a lot of data and learning from data. And the SaaS model has that today. And for certain industries like security, learning about attacks across a lot of organizations is very beneficial. In our case, learning how people are writing software and fixing software helps us have our customers do that better. So I think that centralization is important. And it's not like you couldn't have a group of people get together and do that. I just think that business can push that really well.
42:57So I don't think SaaS is going to go away. I think it might change a bit, but I think it changes for a better. we start serving APIs more than web UIs that someone is talking to an agent that is then calling our API and we become more of a building block to the things that people need to get done. Yeah, sure. Good answer. So let's finish on this one, Chris. Looking back now on your career, and I know you probably got a long way to go, okay, but what advice would you give to your 21-year-old self? What would you tell that guy? Yeah. So I think the biggest lesson I learned was when I founded my first startup was, well, I think the first lesson is how much of a grind it is.
43:42And there's so much work you just have to do. Because you're sort of doing everything at that point before you can sort of hire people. But yeah, there's a lot of grunt work and a lot of grind work and it's not sexy and you have to keep pushing through it. And that's somewhat related to my other big lesson, which I think is the biggest one is everything is going to take a lot of time. I think when I first started Veracode, I was like, in two or three years, we'll have a company that we can sell. And maybe you would, but that would probably be a failure at that point. If you're building anything of promise and value, it's going to take longer.
44:22And then at some point I thought, well, we'll have something to sell at five years. And then I really learned over the long haul that most startups take 10 years to get to the point where you've really built that value and you're really going to get either an IPO or a strategic acquisition where you're really going to get the value from your work. And so I'd say if you're starting something, shoot for a 10-year run. Shoot for something that's going to take 10 years to fully reach its potential for your liquidity event and don't sort of shortchange yourself at five. Now, things might change and you might have to sell at five because for some reason there's a market downturn.
45:03You couldn't scale your sales force. You couldn't figure out how to sell it through the channel. There's all kinds of reasons why you might not reach your full potential. But I think shoot for that 10-year run. And most successful exits are at that point in time. You can exit earlier, but I think give it that full 10 years and definitely no less than five. So you're in this for the long haul as a founder. You've got to commit a lot to that. Like if you have just had a new baby, that baby is going to be in fourth or fifth grade. Yeah, sure. When you sell your company. So you got to think about it that way.
45:42Yeah, fantastic advice. Hard work and patience. That's brilliant insight, Chris. Yeah, look, thank you so much for coming on the Tech Leaders Podcast. Excellent. Thank you so much for having me here.
45:58It was really challenging to cram everything in. Chris is a fountain of knowledge, and there's so many amazing points that he made that I could draw attention to. But obviously, being in front of the U.S. Senate committee professing to bring down the internet in 30 minutes was a particular highlight and something that had a lot of attention at the time. But I have to say, the insight into how organizations like IBM and Microsoft used Loft Group to help develop their products and also to set security standards, which were the basis of how they still operate today. That was absolutely fascinating.
46:34I mean, this was an era when it was a very formal era. It was a shirt and tie era. And you were the two chief players in the software and tech space, Microsoft and IBM, asking guys in baggy T-shirts and flip-flops for their opinion on how to build robust software. It was probably representative of the beginning of a new culture, a Silicon Valley culture, which gave rise to the likes of Google and Facebook not too long after. So I thought that was absolutely fascinating and it felt like a real piece of history that we were learning about there. So, yeah, I hope you enjoyed it. Thank you so much for downloading and supporting the show.
47:14Don't forget to give us a like or subscribe. Any piece of engagement really helps us. Thank you so much.
47:25This episode was brought to you by Be Digital. B-Digital support leadership teams to optimize cost and get more out of technology investments. B-Digital and the team have unrivaled expertise with technology license management and data remediation and are therefore perfectly positioned to help prepare organizations for AI technology capability. And on the last point, B-Digital have just developed a cutting edge AI readiness assessment, which provides tech leaders with a platform they need to make well-informed decisions about AI adoption strategy in 2024 and beyond. Go to Be Digital UK to find out more and get in tech.
From the publisher
Once claiming to the US Senate that he could ‘take down the internet in 30 minutes’, this week’s guest gives us insight into the underbelly of the cyberworld. Chris Wysopal, founder and CTO of Veracode, tells us all about his experience as an ethical hacker and how he and his team at L0pht pioneered the way for cybersecurity.
From taking an interest in the potential of cyber hacking at the start of the online era, to being a trailblazer in the discovery of IT vulnerability as a whole; Chris and his team were at the forefront of raising cyber risk awareness. Determined to battle the ‘bad guy image’ in cybersecurity, the L0pht team were on a mission to showcase the fallibility of big vendors, such as Microsoft, and evidence they need for effective security measures.
Now, Chris’ colourful past shapes the security-led solutions of Veracode, a platform that detects flaws and vulnerabilities at every stage of the modern software development lifecycle. This interview is a deep dive into the depths of cyber security and is not to be missed!
Timestamps
- What does Good Leadership means to Chris? (02:20)
- Pioneering the start of cybersecurity (04:20)
- Starting a hacker collective (07:18)
- L0pht’s biggest cybersecurity breakthroughs (12:47)
- Challenging the US Senate with cyber risks (18:00)
- Are governments doing enough to prevent cyber-attacks? (22:12)
- GenAI’s role in cybersecurity (32:00)
- An introduction to Veracode (34:24)
- Chris’ advice to his 21-year-old self (43:24)
