Live data from Hacker News

16 Things

a16z.com

61–70 of 135 posts

Re: 16 Things

#61
post #28

Their "Security" section is a bit naive. The questions it poses go all the way back to the 1990s. If the Jericho Forum had started a VC fund, this page would be their investment thesis. The 2000s saw a wave of companies try to capitalize on "deperimiterization", some with huge capex requirements (one NAC startup had designed and contract fabbed their own MIPS core). They all flopped. Maybe it's true that firewalls ar…

What's changed is the Benefit side of Cost/Benefit.

Now the leading Benefit is "not having embarrassing company documents on the front page of newspapers every day for a month".

That's quite a "new" Benefit.

Re: 16 Things

#62
post #24

> http://a16z.com/2015/01/22/digital-health/ LOL, I love these stories, especially when featuring games like these: > [...] Tomorrow? To understand your personal diagnostic data, you might soon depend more upon an iPhone app developed in a garage than on your local MD. This garage theme is annoying. The fact that Jobs and Woz had a garage ruined garages... Seriously. They literally changed use in the post-jobs era. I…

Well if I were diabetic, I certainly wouldn't go to my doctor every time I needed to check my glucose. That would get really expensive. I would instead rely upon a home glucose checker, which could easily be integrated with an iPhone using Bluetooth or as an attachment ala Square. Even moreso, if it integrated with HealthKit, I could have my glucose levels over time and have them shared with my doctor using the integration with Epic's MyChart app.

So, not as silly as you might think.

Re: 16 Things

#63

Earlier quoted context omitted.

Couldn't the view simply be one of pragmatism? That one can't ONLY focus on prevention, but look at the full lifecycle of prevention, detection, response / remediation, etc.? Kind of an electronic view of "it won't happen to me"?

Assuming it's not everybody, are consumers/enterprises equipped with the risk management and actuarial tools to assess and influence their chances of being attacked?

"Assuming it's not everybody, are consumers/enterprises equipped with the risk management and actuarial tools to assess and influence their chances of being attacked?"

I think those are separate questions. Consumers largely are not.

Enterprises are getting wiser on the risk management side and are starting to use things like "Factor analysis of information risk" (FAIR) to create a framework around the effect of various incidents. Assessing chances of being attacked quantitatively is probably much more difficult than influencing their chances of being attacked (which includes the various best practices tptacek alludes to such as firewalls, having a SOC, utilizing proper controls, AV, etc. (the implementations of the S&S 8 principles.))

As to chances of being attacked, I think it could be examined similar to something like a health issue. What are my chances of getting cancer? Well, I can read the literature and follow behaviors which should reduce my chances of getting it (in the risk world that would things such as using antivirus, not sharing passwords / SSNs / etc in plaintext, over the phone, etc.); however, I should also be preparing for what do should I contract cancer.

Re: 16 Things

#65
post #24

> http://a16z.com/2015/01/22/digital-health/ LOL, I love these stories, especially when featuring games like these: > [...] Tomorrow? To understand your personal diagnostic data, you might soon depend more upon an iPhone app developed in a garage than on your local MD. This garage theme is annoying. The fact that Jobs and Woz had a garage ruined garages... Seriously. They literally changed use in the post-jobs era. I…

> If he were diabetic, I wonder, would he use an iPhone application to measure his blood glucose levels, or the MD

Actual diabetics I know do occasional in-office tests, but for routine testing use at-home personal testing kits, which one could easily imagine syncing to devices and online services the way personal fitness trackers do. With severe diabetes, you need monitoring more frequently than is practical with in-office-only testing.

Re: 16 Things

#66

Earlier quoted context omitted.

> We don’t invest in themes; we invest in special founders with breakthrough ideas. Which means we don’t make investments based on a pre-existing thesis about a category. That said, here are a few of the things we’ve been observing or thinking about. The list is nothing more than some of the things they find interesting.

> The list is nothing more than some of the things they find interesting. If that is true, I don't see the point of the article or that it warrants much discussion. I don't think that is the intent of the article though. I took it as they expect these 16 themes to yield a lot of the new ideas they will invest in. If that is the case then these 16 are quite arbitrary and I don't see why these were chosen.

That would be PG point on his RFS https://www.ycombinator.com/rfs

The majority of VC companies have investiment thesis. In those thesis they put the kind of market and companies they would like to invest and why. It helps to guide the new associates and partner on where and what to look.

Re: 16 Things

#67
post #52
post #28

Their "Security" section is a bit naive. The questions it poses go all the way back to the 1990s. If the Jericho Forum had started a VC fund, this page would be their investment thesis. The 2000s saw a wave of companies try to capitalize on "deperimiterization", some with huge capex requirements (one NAC startup had designed and contract fabbed their own MIPS core). They all flopped. Maybe it's true that firewalls ar…

What bothers me are things like this which appear to be marketing messages aimed at CYA types or to simply lather up grandpa and the media: "The threat of people getting into our systems today is so great that every company in the world has to embrace the notion that not only are they going to get hacked, there’s a good chance hackers are already inside … and they just don’t know it." ...and this: "This set of compan…

Well, customer data isn't stolen by actual hacking, in my experience it's humans.

So many companies, particularly younger ones, have zero interest in putting up barriers to access as the company grows because in the early days, everybody was trustworthy and "because bureaucracy bad". So all the customer emails, phones, addresses, birth dates (and, I'm guessing, in the US SSNs) routinely fly around in Excel files called something like "Order Metadata Report" and sent to 50 people in 5 departments each of whom has their own use for it (like counting customers). Judging by the Sony hack it's not just SMEs.

If you want to steal data from a company, just pay a student a few hundred bucks to take up an unpaid internship in marketing (particularly anything to do with emails or customer segmentation) and give him a USB key and teach him some VBA and basic SQL (making him useful for reporting). The interns always end up running the reports so have a lot of access, usually complete access - financial information is the only thing that's not shared around. More advanced companies have a shared database access built into the excel files with a single login for everybody which never changes (hello 300 angry users) so with a copy of this file, you have perpetual up to date information long after you're gone.

Then you try to stop them from doing this and the C-level folks will say something like "it's OK just this time" and "please stop slowing us down". Most of them will be gone to the next thing by the time the black swan lawsuit hits - if there even is one. How would customers know? Why would they care?

Cf http://xkcd.com/538/ and http://www.commitstrip.com/en/2014/10/28/security-checklist/

Re: 16 Things

#68
I have feeling that "16 big things that VC will fund" is different that "16 big things companies/people/users will pay for".

Re: 16 Things

#69
post #68

I have feeling that "16 big things that VC will fund" is different that "16 big things companies/people/users will pay for".

VCs dont care about users. They care about exit, and that usually involves bigger sucker buying you out.

Re: 16 Things

#70
post #9

Earlier quoted context omitted.

From later in the post: "The key is nobody has to cool these devices, so it’s almost like free computing at the endpoint." Also, you don't have to buy it! (the user bought their phone/computer and pays for the power) I agree its a bit handwavy. I suppose the remaining cost is the cost of transmitting more data? But regardless, it is a good point - we are absolutely crazy to not be taking advantage of all the free com…

Yes, but it needs to be done very carefully. As soon as your app is draining my battery or running my fans inappropriately , your app is gone. The key word, of course, is inappropriately. This puts caps on how much you can use, but it is still an essentially free resource.

I think that's a major issue. The best way we know how to save battery live on devices now is not all these fancy computing techniques or what have you, it is the finish a computation and shut the device off as quickly as possible. So this strategy seems to run counter to that basic idea of power saving.
Post reply on HN