The whole Trail of Bits story
tl;dr I sat down with Derek Hsue on The Archive for two hours and twenty minutes. It’s the best interview I’ve done.
Also on Spotify, Apple Podcasts, and X.
There’s a lot in here I haven’t talked about anywhere else. The 2013 government shutdown killed every contract we had, and a two-year-old Trail of Bits went eight months without a dollar of revenue; I was down to one paycheck before we clawed our way to private clients. We bought every 32xlarge EC2 instance on Earth for a day to compete in DARPA’s Cyber Grand Challenge, with an Amazon tech in Sydney running through a data center to find us machines. I got robbed in the DAO hack, and that’s how Trail of Bits ended up in blockchain security. Derek also got me talking about the incident response years at the New York Fed, hiring for mastery, and what I’ve had to learn to become a CEO.
There are four exchanges worth pulling out.
On how companies will have to adapt now that frontier models can do real offensive work (watch):
“It means that companies have to respond at machine speed to these intrusions, because that LLM is going to be seeking out all these little opportunities, these chinks in your armor, in order to further burrow itself into your company.”
On why North Korea keeps winning against blockchains (watch):
“What you see from them is they’re performing intrusions, assessing the environment they have access to, and on the fly writing novel tools to take advantage of it. They’re writing smart contract code. They’re writing malware. They’re doing things that are really quite sophisticated.
So yeah, I’m impressed. They did a good job. I was an attacker. I have to appreciate good game when I see it.
With the NSA or somebody else in the US, they’re going to have reams of lawyers. They’re going to pull out some huge book of Title 50, Title 10 stuff. They have so much restraint. North Korea and Iran don’t.”
On how Trail of Bits ended up in blockchain security (watch):
“So we all bought DAO tokens and then we all got robbed. And it was this funny light bulb moment when we were like, oh my God, did another hacker just steal money from us?”
And on who Trail of Bits hires (watch):
“We take all comers. One of our most successful employees was a lot like me. It took me six years to graduate college. I had to go back for my final semester and finish physics one, discrete math, and linear algebra.
I was a smart kid that burned out, and I think a lot of people who are highly motivated and understand what they want to do in the world have a similar experience.
At Trail of Bits, the thing that binds everybody together is that we all want to be the best at what we’re doing. It’s team cohesion through competence.”
Where to jump in:
- 1:14 — What is Trail of Bits and how did it get started
- 6:49 — My upbringing and developing a passion for computer science and hacking
- 16:25 — Working at the NSA
- 22:51 — North Korean hacks on crypto
- 28:22 — The incident response team at the Fed
- 33:05 — The motivation behind Trail of Bits, and DARPA’s role
- 47:23 — Starting Trail of Bits
- 58:22 — Government shutdown, losing all revenue, and surviving with one paycheck
- 1:04:36 — Hiring people for mastery and building a high-agency team
- 1:15:34 — Bitcoin post-quantum cryptography
- 1:20:12 — The culture and expectation at Trail of Bits
- 1:38:42 — Mythos and AI’s role in cybersecurity
- 2:05:48 — The San Bernardino iPhone, and my proudest moments
- 2:12:12 — Learning to become a CEO