If pressed there probably won't be a huge amount of details on what extra security / insight that might provide vs their competitors, but there'll be implicit suggestions that it's because what he knows is classified and nation-state level and that it actually filters down to the way they design and implement the services.
Is there real magic technology previously unknown to security that they'll be able to add? And would it be wise to expose it via a small startup if so? Personally doubt both, but probably doubt the former more so.
Meanwhile a basic product will develop, sales will flow, it's probably a safe-ish bet for the early investors/founders, the sun will continue to rise in the east and set in the west, etc.
Or "don't accept ' or 1=1 -- as a password", for that matter. Internet-facing web system with several thousand users, just a year ago or so. Made me feel like I'm back in the '90s.
I mean, of course I meant this was an SQL injection.
Only by using frameworks and DB drivers correctly (RTFM) is one able to accurately avoid SQLi. I would argue that "using software correctly" is by no means trivial and rarely happens in most systems that have less than NASA quality safeguards.
I would agree that most modern frameworks which are adopted by at least a few hundred developers tend to use best practices and a "security by default" mindset, but that's far from saying that "avoiding SQLi is trivial".
> "don't accept ' or 1=1 -- as a password"
(the way that it's stated) implies that one should be checking input for possible SQL injection attacks and dropping the request, rather than sanitizing input so that the attack doesn't work, but the password is valid.
Probably sells them on an image and liability benefit, too: "bank shouldn't be liable because we even went so far as putting former director of NSA in charge of our security. What more could we have done!?" Trying to counter liability in courts or with lobbying is main security model for big business. So, something like this is undoubtedly a benefit.
Not only what he learned while he was there; it seems his original plan was to continue to receive a steady stream of intelligence info even after he'd left:
https://fcw.com/articles/2014/10/22/nsa-cto-moonlight-gig-en...