Tanium CEO’s Refreshingly Honest Take on the State of Internet Security

[unable to retrieve full-text content]

On Tuesday, the wood-smoke air of California’s wildfires descended on the Bay Area as cybersecurity professionals gathered at the Palace Hotel for an industry event.

I spent the morning interviewing Orion Hindawi, CEO of Tanium, the world’s highest privately valued cyber startup (worth $ 3.75 billion at last appraisal in May), for a fireside chat at his company’s second annual conference, Converge 2017. Hindawi has a no-nonsense approach to business–a suffer-no-fools attitude that landed him in the sights of a couple of unflattering stories about his management style earlier this year. (He later apologized for being “hard-edged.”)

On stage the chief exec delivered his peculiarly unvarnished view of the state of Internet security. “The idea that we’re going to give you a black box and it auto-magically fixes everything, that’s a lie,” Hindawi told the audience. (One could almost hear a wince from part of the room seating his PR team.) “All I can tell you is we can give you better and better tooling every day. We can make it harder for the attackers to succeed. That’s the best I can offer.”

Hindawi is a realist through-and-through. His outlook is perhaps best summed up by his response to a question about whether he subscribes to a glass-half-full or glass-half-empty view of the cyber threatscape. His reply would become a running joke for the rest of the conference. He said simply, “It’s just a glass, dude.”

Other tidbits of wisdom from Hindawi: not all hackers are Russian spies (the majority are lowly criminals). Unsecured Internet of Things devices pose a risk to everyone. And sometimes cyber insurance is the way to go when old systems are all but impossible to patch; the decision boils down to managing “operational risk, like earthquakes,” he said.

Hacking is not a dark miasma that penetrates all things, although it can sometimes feel that way. Companies, like Tanium, that are building the tools to swing the balance back in defenders’ favor without over-promising provide hope. Enjoy the weekend; I will be heading north of San Francisco, visiting friends who, luckily, were unharmed by the area’s recent conflagrations.

Robert Hackett

@rhhackett

[email protected]

Welcome to the Cyber Saturday edition of Data Sheet, Fortune’s daily tech newsletter. Fortune reporter Robert Hackett here. You may reach me via Twitter, Cryptocat, Jabber (see OTR fingerprint on my about.me), PGP encrypted email (see public key on my Keybase.io), Wickr, Signal, or however you (securely) prefer. Feedback welcome.

THREATS

Always use (advanced) protection. Google debuted an opt-in mode for high-risk users who wish to lock down their accounts on services such as Gmail, Google Drive, and YouTube with extra security. (Paging John Podesta.) The feature requires people to log-in using a special USB key (or Bluetooth dongle for mobile devices), it prevents third-party applications from accessing your Google data, and it adds beefed up malware-scanning of incoming documents. This author plans to sign up.

Gather ’round the good stuff. Pizza Hut warned customers that their personal information and payment card data may be at risk after hackers gained access to the company’s website and app for a 28-hour period starting on Oct. 1. An estimated 60,000 customers are thought to have been impacted. The company is offering victims free credit monitoring for a year.

Unicorn? More like Duo-corn. Duo Security, a Mich.-based cybersecurity startup whose tools help companies manage people’s digital identities, said it raised $ 70 million at a $ 1.17 billion valuation (including the capital raised) this week. Th round catapults the firm into “unicorn” territory, the swelling ranks of private firms occupied by young guns valued at $ 1 billion or more. Alex Stamos, Facebook’s security chief, recently praised Duo as the maker of his favorite cybersecurity product.

KRACKing Wi-Fi. A couple of Belgian researchers published a paper containing proof of concept code that exploits vulnerabilities in the way cryptographic keys are exchanged over Wi-Fi, allowing hackers to steal people’s data. Big tech companies like Microsoft issued a patch for the so-called KRACK bug on Oct. 10, Apple is in the middle of testing patches for iOS and macOS, and Google, whose Android 6.0 devices are the most vulnerable, said it would release a patch in early Nov.

Cyber insurers are going to get Mercked. Cyber insurers might be on the hook to cough up $ 275 million to cover damage to drugmaker Merck as a result of a June cyber attack, dubbed “NotPetya,” according to one firm’s forecast. The companies at issue have not yet disclosed figures themselves.

Surprise! It is depressingly easy for penetration testers to break into places where they are not supposed to be.

Share today’s Data Sheet with a friend:

http://fortune.com/newsletter/datasheet/

Looking for previous Data Sheets? Click here.

ACCESS GRANTED

Boycotts are hardly an option: To opt out of a credit score is to opt out of modern financial life itself. As Equifax’s now former CEO Richard Smith testified in October, if consumers were allowed to abandon the credit system, it would be “devastating to the economy.” The better answer is systemic reform to the credit oligopoly.

–Fortune’s Jeff John Roberts and Jen Wieczner explain what practical recourse consumers and regulators have when it comes to dealing with the major credit bureaus in the wake of a massive data breach at Equifax.

ONE MORE THING

The adventures of John Titor. Namesake of a bygone Internet hoax, “John Titor” claimed to be a man sent from the future to retrieve a portable computer. Titor sent faxes to an eccentric radio program, Coast to Coast AM, that specialized in the paranormal. Here’s an oral history of that running joke; the pseudo-scientific explanations of time travel are delightful.

Tech

Italy state role in Telecom Italia could solve network tiff: PD's Orfini

ROME (Reuters) – Italy should play a role in resolving the gridlock over Telecom Italia’s (TIM) network assets, possibly by involving state lender Cassa Depositi e Prestiti (CDP), president of the ruling PD party said in a position paper.

Italian politicians have been calling on and off since 2006 for TIM’s network to be transferred to a state-controlled entity as Rome considers it a strategic asset that should be a neutral platform open to all phone companies.

The heavily-indebted company has been criticized for putting off costly upgrades to its ageing copper network and is now facing competition from Open Fiber, jointly controlled by utility Enel and CDP.

The network issue returned to the forefront of political debate when French media group Vivendi built a 24 percent stake in TIM, becoming its top investor and increasingly calling the shots at Italy’s biggest phone group.

In the document published by online magazine Key4Biz, Matteo Orfini said the state needed to push for the creation of a single integrated network company and eliminate infrastructure rivalry which he called “unsustainable in the long term”.

“The status quo is not an option,” he said.

Listing a series of scenarios to resolve the network tiff, Orfini said a public or private Italian investor could flank Vivendi as a shareholder in TIM, to help sharpen the Italian phone group’s business focus.

He added that CDP could propose to buy part or all of Vivendi’s stake in TIM.

Orfini said Vivendi should be given the opportunity to give up control of Italy’s biggest phone group and instead focus on its plan to build a European media powerhouse, by involving broadcaster Mediaset, in which it has built a stake of just under 30 percent.

Plans to spin off TIM’s network, which according to some estimates could be worth up to 15 billion euros ($ 17.7 billion), have foundered in the past over its valuation and because TIM insisted on hanging onto the business.

Orfini said that while a spin-off might be difficult in the short term, the network could be separated into a regulated newco, fully controlled by TIM but legally distinct.

That move, along with some state participation in TIM, could facilitate a later integration with network rival Open Fiber.

TIM shares rose more than 3 percent after the position paper came out. The stock was up 2.1 percent at 0.77 euros by 1153 GMT.

TIM, which considers its network a strategic asset, declined to comment. Vivendi could not immediately be reached for comment.

Reporting by Giselda Vagnoni, writing by Agnieszka Flak; Editing by Ken Ferris

Tech