Live data from Hacker News

16 Things

a16z.com

91–100 of 135 posts

Re: 16 Things

#91
post #88

Earlier quoted context omitted.

FireEye is the firm I alluded to in my comment. Varonis, Lifelock, Trusteer, and Cloudflare aren't reactions to deperimeterization and the declining effectiveness of firewalls. (Ironically, Cloudflare is if anything a cause of the declining effectiveness of firewalls, not a solution). Also: my argument isn't that it's impossible to build a billion dollar security company! It's that the dynamics of doing so aren't iso…

What do you think of software like Bromium, Qubes, etc. which creates enclaves within endpoints?

Very cool and very difficult to operationalize. If I was a VC, I would (cruelly) sum them up as "features of Citrix". Also, if you want to sell an enterprise security team a security product, saying that it reduces the need for stuff like Citrix would be a pretty good pitch.

Re: 16 Things

#92

Earlier quoted context omitted.

Thanks for the links! At least I am not going crazy ;) > Have you considered pay-what-you-want pricing, with a suggested anchor? As of late 2014, I am working on this full-time. Scary, but I think I can pull it off. I am shooting for a $12 monthly subscription fee (auto-renewing), that will give you blanket access to everything for 30 days. My thinking is that, I am targeting sysadmins, devops folks, and developers w…

You can have more than one distribution channel, e.g. your own monthly subscription site, plus a bundle of transcripts (reformatted as an ebook) + a package of screencasts, sold via https://www.softcover.io/ which takes 10%. Use 80/20 rule to figure out which topics are in high purchase demand and could benefit from a deeper dive. Lower-cost channels can feed demand for deeper/premium products/channels. Background: h…

Thanks for all the links. I will definitely be checking this out! I had watched Nathan Barry's screencasts with Michael Hartl, but I didn't know he was active on HN, these links look pretty good, so I'll want to read these over! Thanks again.

Re: 16 Things

#93
post #88
post #84

Earlier quoted context omitted.

CISO budgets are exploding at large companies; in '98 most of these companies didn't even have a CISO. Firewalls have proven to be ineffective and companies are willing to pay for solutions that are more effective. Attackers have also gotten a lot more professional and sophisticated. There's certainly been plenty of billion dollar security companies been built outside of the firewall space in recent years (FireEye, V…

FireEye is the firm I alluded to in my comment. Varonis, Lifelock, Trusteer, and Cloudflare aren't reactions to deperimeterization and the declining effectiveness of firewalls. (Ironically, Cloudflare is if anything a cause of the declining effectiveness of firewalls, not a solution). Also: my argument isn't that it's impossible to build a billion dollar security company! It's that the dynamics of doing so aren't iso…

Varonis and Trusteer essentially deal with the issue of "the bad guys are already inside" and Lifelock the damage control element of post-compromise.

I'd say in mobile security space Good Techonologies, OpenPeak, Ionic, Telesign and Okta all probably have valuations in the mid-hundreds of million of dollars.

The big winners in mobile have been gaming and advertising, but I'd suspect that in terms of enterprise software security companies are probably out-performing the average.

Re: 16 Things

#94
post #88

Earlier quoted context omitted.

FireEye is the firm I alluded to in my comment. Varonis, Lifelock, Trusteer, and Cloudflare aren't reactions to deperimeterization and the declining effectiveness of firewalls. (Ironically, Cloudflare is if anything a cause of the declining effectiveness of firewalls, not a solution). Also: my argument isn't that it's impossible to build a billion dollar security company! It's that the dynamics of doing so aren't iso…

What do you think of software like Bromium, Qubes, etc. which creates enclaves within endpoints?

I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one).

Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it being overkill for an entire enterprise.

I think securing endpoints is basically a lost cause though (I'm happy to consider that a minority opinion however). My company spent many years trying to get TPM's to be the solution to this problem, and I'm pretty sure that ship has now sailed; with the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile).

I think we'll eventually realize that much like networks, devices have to assumed to be untrustworthy, and we have to route accordingly.

Re: 16 Things

#96
post #28

Their "Security" section is a bit naive. The questions it poses go all the way back to the 1990s. If the Jericho Forum had started a VC fund, this page would be their investment thesis. The 2000s saw a wave of companies try to capitalize on "deperimiterization", some with huge capex requirements (one NAC startup had designed and contract fabbed their own MIPS core). They all flopped. Maybe it's true that firewalls ar…

> Why is 2015 different?

NSA/North Korea/China/Eastern Europe/Anonymous and Sony/Target/Home Depot.

I think far less has changed about what we're trying to secure. Far more has changed about who we're trying to secure it from and, as others have pointed out, the consequences of not securing it. In 1998, hackers didn't represent an existential threat to the company. I'm not sure you can say the same today.

Re: 16 Things

#97

Earlier quoted context omitted.

What do you think of software like Bromium, Qubes, etc. which creates enclaves within endpoints?

I've worked implementing both, and Bromium is basically as good of a solution to this problem as you're going to get, in the sense that it requires the least modification of user behavior (the user's Windows machine mostly behaves like a normal one). Even Bromium was pretty upfront about the use case for their product though (high-value targets like executives who travel to China). They were very honest about it bein…

> the only 2 sectors of the industry that are continuing to grow being completely unsuited to TPMs (virtualization and mobile)

A counterpoint is that mobile platforms often have some form of secure enclave, but sadly not standardized. Even AMD's low cost x86 CPUs are adding an ARM coprocessor, which could in theory be used for functionality similar to TPM, DRM, or AMT. Some of those are more useful than others. On the Intel side, SGX will add more enclave options, and complexity, but hopefully will be open and well documented.

Re: 16 Things

#98
post #51

Earlier quoted context omitted.

Yep. Information security is a nonalgorithmic problem. Much as people might like to disagree or pretend otherwise, it is fundamentally at odds with a service that can scale to meet the needs of clientele in an automated manner. The most successful companies in that space are consultancies that can deliver personalized results to every client on every engagement, and while they are very successful, they will never be…

Something I used to think about during my tenure as a graduate student in computer security: has anyone written the definitive book/study/dissertation on why security incidents happen? As mentioned elsewhere in this thread, it's a very complex problem involving operational, economic, and technical factors, suggesting (as others have mentioned) it's not something that really can be "sold". Watching bugtraq for a while…

>Maybe a good commercial opportunity would be policy compliance checking tools. Imagine a simple policy like "the corporate network should not be accessible from the outside world". Would it be possible to check all firewalls/routers/NATs/etc. for compliance with this policy?

This is already a very big part of the security industry. Countless companies and products (claim to) do this.

Re: 16 Things

#99
post #84
post #28

Their "Security" section is a bit naive. The questions it poses go all the way back to the 1990s. If the Jericho Forum had started a VC fund, this page would be their investment thesis. The 2000s saw a wave of companies try to capitalize on "deperimiterization", some with huge capex requirements (one NAC startup had designed and contract fabbed their own MIPS core). They all flopped. Maybe it's true that firewalls ar…

CISO budgets are exploding at large companies; in '98 most of these companies didn't even have a CISO. Firewalls have proven to be ineffective and companies are willing to pay for solutions that are more effective. Attackers have also gotten a lot more professional and sophisticated. There's certainly been plenty of billion dollar security companies been built outside of the firewall space in recent years (FireEye, V…

In '96 or so, I went to my first Internet security conference. The attendees were a motley crew - junior programmers like myself, schoolteachers, old-school sysops, etc. Lots of us worked for companies that wanted unfettered access to this new Internet thing, but it had to be absolutely secure - and of course, it can't cost anything! There was hardly such thing as a network security professional then.

Things have changed a lot.

Re: 16 Things

#100
post #93
post #88

Earlier quoted context omitted.

FireEye is the firm I alluded to in my comment. Varonis, Lifelock, Trusteer, and Cloudflare aren't reactions to deperimeterization and the declining effectiveness of firewalls. (Ironically, Cloudflare is if anything a cause of the declining effectiveness of firewalls, not a solution). Also: my argument isn't that it's impossible to build a billion dollar security company! It's that the dynamics of doing so aren't iso…

Varonis and Trusteer essentially deal with the issue of "the bad guys are already inside" and Lifelock the damage control element of post-compromise. I'd say in mobile security space Good Techonologies, OpenPeak, Ionic, Telesign and Okta all probably have valuations in the mid-hundreds of million of dollars. The big winners in mobile have been gaming and advertising, but I'd suspect that in terms of enterprise softwa…

Which of Trusteer's product lines tapped a market opportunity that wasn't already addressed by RSA or Symantec in 2003? If the answer is "most of their revenue came from products that refined value propositions that RSA and Symantec already had products for", then what does Trusteer have to do with Weiss' investment thesis?
Post reply on HN