Ex-NSA Chief’s Cybersecurity Startup Draws Funding
wsj.com
wsj.com
NSA isn't exactly the world's top defensive security organization. As a red-team, I could see some value in ex-NSA, but for commercial information assurance (IA), aside from "we've seen how things are done badly, by contractors", I would consider NSA experience not just irrelevant but negative.
In addition to being ineffective at the IA mission, NSA has entirely unreasonable resources and imposes constraints on their users. These would be unavailable for commercial companies, so NSA IA experience is even less helpful.
I could sort of see putting $XX mm into a company for "halo effect" on your other investments, but in this case there are more than enough negative external optics which come with the decision. I personally would not want to be associated via common investor with this.
(maybe should post as a throwaway, but w/e; I stand by this)
"Developed and implemented X meaningful control at Google" is close to auto-investable, IMO.
There are some pharma (drug discovery) and prop-trading firms I'd respect highly, too. Not high street banks but smaller or more focused entities. Knowing which is hard.
For big companies which are "obviously" good: Apple's not bad internally. FB, Amazon, Microsoft aren't bad. The hard part is identifying who is good internally out of large teams. (Yahoo! has also traditionally had good infosec relative to everything else, although perhaps sacrificed business to it.)
LV casinos as a sector seem to be ok.
For harder bets: There are few tougher environments today than the bitcoin ecosystem. A lot of those companies are shitshows staffed by people with zero infosec background, but there are exceptions.
Also of course some of the most elite consultancies (iSEC, IOActive, Cylance, etc.) have great people. There are individual good people in large big-N consultancies too, but as a blanket statement, not as good to recruit from.
(For offense: Israel/8200/etc. are probably the best recruiting pool, due to cost relative to skill. There are good people in the NSA ecosystem as well, for offense, although largely contractors, and expensive. I don't buy that extreme competence at actually implementing widely-known-but-we-didnt-think-people-would-actually-go-that-far vulnerabilities makes you a stronger defensive player, though; developing fundamentally new attacks, or finding vulnerabilities, sure, but spending $5b to do the attack everyone had identified as a possibility is just an engineering and economic exercise.)
(In SV today, startups in security are probably the best pool of talent, hence acquihire. I probably know a pool of ~200 good to great people in the general security ecosystem at any given time from a bunch of companies who are recruitable or buyable.)
http://www.thewire.com/technology/2013/06/facebooks-former-s...
Old -- but there are other articles about it as well...
It would be hard to imagine more prominently anti-NSA security executive than Alex Stamos, their current CSO.
And the ones listed by @rdl.
They're a pretty good case study for how the right senior hires at the right time can set the tone for a security organization for many years after those people leave.
NSA name sounds important, cool, and carries powerful connotations. I bet even if he said he is making flux capacitors, he'll find some investors to throw a few millions his way.
He downloaded what was effectively the brochure stand you see in the lobby of a cheap hotel. Look, we have this for use, here is a high level overview. Come talk to us, we will read you into the program, and provide you with the details.
Sure it was an intelligence loss - but it was all stuff that any cleared staff could access anyway.
The NSA and other government security organizations say that the information he leaked was very damaging. The NSA also changed their security procedures in response.
All of that could be for show, but I haven't seen evidence that it is.
https://www.schneier.com/blog/archives/2014/10/nsa_classific...
Anyone wanting to know about how thoroughly SAP's are protected can start with the NIPSOM Industrial Security Manual(s):
http://fas.org/sgp/library/nispom.htm
They start with that stuff as a framework and use specialists for categories demanding it. Much better than CISSP as it covers papers, personnel, INFOSEC, COMSEC, OPSEC, EMSEC... the works. My own framework built on it plus what I learned in privacy guides (eg Eden Press), spy/military nonfiction, and writings of crooks. All kinds of useful techniques to draw on when filling in the blanks of the framework for a given organization. INFOSEC turned into the most fun of the rabbit holes. Mostly solved and just not reaching mainstream, but still stuff to figure out for pro level and high assurance sector. Many, many surprises await.
http://lukemuehlhauser.com/wp-content/uploads/Bell-Looking-B...
Many systems, under A1 label, were created back then which defeated NSA pentesters. NSA was mainly evaluator rather than developer, but developed some interesting tech of their own. EKMS for key management and especially the inline-media encryptor come to mind. My own IME designs were based on theirs.
https://www.nsa.gov/ia/programs/inline_media_encryptor/
However, most of the developments came from computer science, U.S. military organizations, and defence contractors. They produced a lot of secure technology. People in NSA's IAD helped where possible. Those same methods are used on select systems today although NSA is fast-tracking everything now for some reason at low-assurance. Probably part of BULLRUN.
Anyway, NSA could easily offer good INFOSEC by just applying what's proven to work to various use cases as Bell said. Anyone could. Some did to varying degrees: Sentinel's HYDRA firewall, GEMSOS's thin clients, Mikro-SINA VPN, Secure64's SourceT OS for DNS, and so on. Each of these either had clear security improvements or did vastly better on penetration tests with GEMSOS and HYDRA surviving NSA pentests with much praise from evaluators.
So, people wanting security should just apply what works to every part of the stack. Won't be easy. Will take time. Will probably be incremental. Nonetheless, insecure protocols, monolithic kernels, C libraries... these things have never worked and never will. Just doing the opposite of mainstream in key areas will get one far. Imitating the best of the past will get you really far. And the hardware is the most important battle from there as I said in counterpoint to Dan Geer.
https://www.schneier.com/blog/archives/2014/04/dan_geer_on_h...
So, screw Alexander's outfit. Nobody needs it: just lessons NSA and others taught us long ago plus what we've learned in mean time. So, use them instead and save yourself the consulting fee. You'll need it for the premium that real security costs you. ;)
I have a feeling this is going to be just like all the other ones, with some proprietary IDS.
One interesting thing to note, being originally from NoVa/DC. No mention of a clearance requirement in the company's job reqs. I've never seen a job req that required a clearance without one.
It probably will be some new detection technology, since that's the direction the industry is going (if you can't prevent all breaches, you need detection anyway) and I don't think we've exhausted the space of possible approaches to detection yet.
This is relevant to whether NSA experience is a pro or con in the commercial space - he doesn't have the type of NSA experience you're probably thinking of.
In any case, even if he isn't technical, his staff is. Especially his right-hand, James Heath, that led the creation of many technical capabilities. If he went with Alexander, then the two could accomplish plenty in INFOSEC (mainly detection/response) at corporate levels and with easy government contracts.
Or "don't accept ' or 1=1 -- as a password", for that matter. Internet-facing web system with several thousand users, just a year ago or so. Made me feel like I'm back in the '90s.
I mean, of course I meant this was an SQL injection.
Only by using frameworks and DB drivers correctly (RTFM) is one able to accurately avoid SQLi. I would argue that "using software correctly" is by no means trivial and rarely happens in most systems that have less than NASA quality safeguards.
I would agree that most modern frameworks which are adopted by at least a few hundred developers tend to use best practices and a "security by default" mindset, but that's far from saying that "avoiding SQLi is trivial".
> "don't accept ' or 1=1 -- as a password"
(the way that it's stated) implies that one should be checking input for possible SQL injection attacks and dropping the request, rather than sanitizing input so that the attack doesn't work, but the password is valid.
Probably sells them on an image and liability benefit, too: "bank shouldn't be liable because we even went so far as putting former director of NSA in charge of our security. What more could we have done!?" Trying to counter liability in courts or with lobbying is main security model for big business. So, something like this is undoubtedly a benefit.
If pressed there probably won't be a huge amount of details on what extra security / insight that might provide vs their competitors, but there'll be implicit suggestions that it's because what he knows is classified and nation-state level and that it actually filters down to the way they design and implement the services.
Is there real magic technology previously unknown to security that they'll be able to add? And would it be wise to expose it via a small startup if so? Personally doubt both, but probably doubt the former more so.
Meanwhile a basic product will develop, sales will flow, it's probably a safe-ish bet for the early investors/founders, the sun will continue to rise in the east and set in the west, etc.
Not only what he learned while he was there; it seems his original plan was to continue to receive a steady stream of intelligence info even after he'd left:
https://fcw.com/articles/2014/10/22/nsa-cto-moonlight-gig-en...