39,339 karma · joined July 8, 2008
Chief Security Officer for Evertas Insurance -- the world's first cryptoasset insurance carrier. https://evertas.com/
Previously, CEO and Co-Founder of CryptoSeal (YC S11), which was sold to CloudFlare on 2 June 2014. CISO/Board Member of Tezos Foundation 2018-2020.
Previous startup founder (HavenCo, a couple ecash projects, distributed colo, and DoD/Iraq contracting, new thing), too. Deeply interested in computer security, infrastructure, security, conflict zones, and making the world a better place.
Aside from living on a Caribbean island during crypto export controlled 1990s, I've lived on a tiny artificial platform in the North Sea, plus more reasonable places like London, Amsterdam, Iraq, Afghanistan, Kuwait, and spent 6 months diving in Thailand.
"I, the greengrocer XY, live here and I know what I must do. I behave in the manner expected of me. I can be depended upon and am beyond reproach. I am obedient and therefore I have the right to be left in peace."
Email: ryan@venona.com (etc) Twitter: @octal https://twitter.com/octal LinkedIn: http://www.linkedin.com/in/ryanlackey
Top color: aaaaaa
If you scanned every American Football player before/after a game, it would probably lead to an end of the sport. Similarly with boxing, and soccer heading practice.
Also would be super useful in war zones -- you can't MRI due to metal fragments, and can't CT over and over again due to radiation, and right now most of the guidance is "don't get injured again" and is broadly ignored. Being able to scan people near point of injury (or just after high risk activities) would be great.
(Obviously lots of other uses for this in disease screening, etc.; difficulties with ultrasound due to bone, gas, etc.)
1) Rich people are WAY richer, and time is even more valuable 2) Businesses have some very important employees and "2 day trip" vs "3-4 day trip" is worth $50-100k 3) Larger population of people able to pay $20-30k for a flight than ever before.
The biggest practical impact is there's probably going to be a private jet version instead of just a commercial one, and there will likely be transpacific demand exceeding transatlantic. Also government/military use.
There are actual risks that this trend doesn't continue, but as long as the trend continues, it is pretty good for revenue. "AI shown to hit a wall/doesn't actually deliver/stops growing so fast", "massive improvement in hw efficiency or tech such that all the old stuff becomes obsolete", "bottleneck on power/regulations/etc such that no one wants anything but the most efficient cutting edge stuff" would be the ways it could end and then all these factors reverse. Right now, power is so constrained that old, inefficient power generation is actively being turned back on or set up at new sites (e.g. old aviation turbines which are very inefficient compared to combined cycle).
No one really knows how quickly AI hardware investments will become obsolete and thus how long it should be amortized, but 2-3 years would be extremely conservative, and in fact used H100 (discontinued/2 generations old) prices are higher today than they were when the equipment was new several years ago.
I don't any of these will be dissuaded by cute family photos. Fortunately the frontier model companies and major infrastructure providers are able to pay for top-tier corporate security (although tech people generally have been unwilling to do this at home for lifestyle reasons), but I'd be afraid for people elsewhere in the supply chain.
(And destructive attack is all on top of the normal corporate espionage, infiltration, subversion, etc.)
Some browsers and some end user devices get upgraded quickly, so making it easy to make it optionally-PQ on any site, and then as that rollout extends, some specialty sites can make it mandatory, and then browser/device UX can do soft warnings to users (or other activity like downranking), and then at some point something like STS Strict can be exposed, and then largely become a default (and maybe just remove the non-PQ algorithms entirely from many sites).
I definitely was on team "the risks of a rushed upgrade might outweigh the risks of actual quantum breaks" until pretty recently -- rushing to upgrade has lots of problems always and is a great way to introduce new bugs, but based on the latest information, the balance seems to have shifted to doing an upgrade quickly.
Updating websites is going to be so much easier than dealing with other systems (bitcoin probably the worst; data at rest storage systems; hardware).
1) Internal risks and controls within the datacenter (the company involved and their operating history, fires, flood, etc,) -- for a sufficiently "good" datacenter, you can assume it gets maxed out in quality, or at least to the point where it's no longer efficient to spend more. Most of these risks also cause service disruptions, so if you're building for high availability anyway, the rest of this stuff is usually handled as part of that. Essentially, if you're too cheap to build a good enough datacenter to max this out, you're not getting insurance anyway in most cases, so it's not a variable factor so bunch as binary or maybe a few broad risk bands (ISO tier for datacenters).
2) External risks. This is mostly natural catastrophe ("nat cat" or "cat risk"); usually there's one dominant driver of that ("severe convective storms" in Texas; floods and hurricanes in places like Florida; earthquakes in California). In some places it's multiple risks (Japan has both earthquake/tsunami and typhoon). This drives the majority of insurance premium.
War risk, geopolitical, political risk, terrorism, SRCC ("strikes, riots, and civil commotion") are in a third category -- often essentially not a factor (e.g. for a $200mm facility in rural Texas), but often handled through special programs at a national level or specialty insurance. A lot of normal policies exclude or let the client buy-back that part of the risk.
As my personal interests in war zones, drones, etc. and professional interests in crypto, AI, and datacenters seem to have converged, looking forward to seeing "quality of air defense artillery/integrated air defense system" as well as "comprehensive quick reaction force capable of dealing with national-level threats" as elements of insurance underwriting for $50B AI datacenters/"AI factories" in the future. I assume in most cases this kind of stuff will be handled by national, military, defense, or civil defense parts of the government, but could easily be contracted as well. I don't think Oracle Cloud is likely to stand up their own private army though.
What a long and unpredictable path his life took. Too bad he isn't still with us.
I really loved Dilbert (the Gen X defining comic), and especially his first couple books.
If a tsunami affects me on a mountain something would be seriously wrong, so I’m not going to worry.
Probably long term the solution will be hybrid — mining gets done using any spare power. AI training generally requires protected power even beyond firm power and few miners have this for their mining operations, and also most of the mining facilities aren’t in the ISO 5 or 6 facilities we (I insure miners and AI) want to see for $500mm worth of mining hardware. Usually the mining companies don’t want to make the upfront capital outlay for these, so a lot of the time they do partnerships where part of their PPA is shared.