A big part of public interest in the blockchain can be attributed to a desire to reclaim our digital identities and reintroduce privacy to our online lives. But cryptocurrency remains vulnerable to hackers and cyberattacks. What can we do at the consumer level to protect ourselves from scams and keep our digital assets safe?
Full Transcript
Alexsandra Guerra: You’re listening to the Reversing Climate Change Podcast by Nori, the world’s first carbon removal marketplace. Here are your hosts, Ross Kenyon and Christophe Jospe.
Christophe Jospe: Hello and welcome to the Reversing Climate Change Podcast. I’m Christophe Jospe sitting with my colleague and co-collaborator Ross Kenyon and producer Paul Gamble. We’re here in Kirkland, not coincidentally drinking Kirkland beverages. From Costco. Yeah. Yeah. We learned that it’s named after. Yeah. I guess so, right? Well, Ross, how about you start us off and introduce our guest? Man, was that like trying to write with your left hand, I guess, or your opposite hand? You’re left-handed, right?
Unknown speaker: He is left-handed.
Christophe Jospe: Okay, so it’s like writing with your right hand.
Ross Kenyon: Normally, I start the show and then Kristoff introduces them.
Christophe Jospe: So how was that? Was that a little weird for you?
Ross Kenyon: It did feel like writing with my left hand, but I’m left-handed, so I’m still used to it. Very confusing. Well, today we are here with Roderick Jones. He is the founder and president of Rubica. They work on cybersecurity. We saw a great presentation by him at Pioneer Square Labs in downtown Seattle. We were learning about the applications for cybersecurity, the future of that, how it will look for blockchain and how vulnerable actually are these systems? What are the vectors? And we thought it’d be interesting to have him on the show to tell us a little bit about that.
Yeah, I guess that’s a good summation there. Would you agree with that?
Roderick Jones: Yeah, I think that’s it.
Ross Kenyon: I don’t need to retract any statement.
Christophe Jospe: That’s good. And probably connect the dots along the way to why does this matter with what Nori is doing and climate change and maybe there’s some overlap even.
Ross Kenyon: I guess we’ll find out. Yeah, I mean, security is very important, obviously, for blockchain. People tout it. But there are ways in which it is secure and there are ways in which it is not. And there are various mitigation strategies for that. You should never say something is secure. You say it’s security-minded or more secure or something like that. Why don’t you tell us how you got into this field? You told a story at the event that we loved and we wanted to just repeat it.
Roderick Jones: Right. So many years ago, more than 20 years ago now, I started life as a detective at Scotland Yard in London. And If you know anything about being a police detective, it’s a lot of boring time hanging around, waiting for things to happen, and then moments of extreme activity. And in the times where you’re hanging around being bored, you kind of think about lots of different things. And I used to spend a lot of time thinking about how you would break into banks. And I was always fascinated by robberies and heists and this kind of stuff.
In the run-up to the Millennium, there was a Millennium Dome built in the UK, and in it they put the Millennium Diamond, which I think is a 43-carat diamond, and one of the greatest heists I was ever involved in. And I wasn’t, you know, sort of involved in actually trying to steal the diamond, I will say. Was basically this attempt by South London organized crime gangs to kind of break into the Millennium Dome, jack their way in with industrial machinery through the protections around the diamond and steal it and then make off in the river on a boat.
Ross Kenyon: It’s like a Ritchie film, right?
Roderick Jones: Yeah, well, it’s sort of... The real life is always a little more mundane than the reality. But I mean, I happen to be on a boat on the River Thames to intercept the boat as it went off. But unfortunately, because I wanted to race down the river and the boat never happened because they were captured in the act of stealing the diamond.
Ross Kenyon: Let them go a little bit longer.
Roderick Jones: Yeah. And I always thought it was a great robbery. And the reason why I brought it up at the crypto event was because I actually think it was the high watermark of kind of physical theft. I think the valuation around the diamond might have been $350. So serious, serious value. But I don’t think there’s been a significant robbery attempt that looks anything like that since the millennium. If you look at where the big heists are now, it’s that sort of almost billion dollar attempt to cyber break into the Bangladeshi bank.
You know, it’s like this cyber attack is like billion dollar industry. Nobody’s breaking into anything. Nobody’s doing heists anymore.
Ross Kenyon: Makes it the perfect time for us to get together.
Roderick Jones: So that’s, that’s kind of where it started. You know, yeah. I mean, I mean, it’s just almost, I was thinking, it’s like no one has yet written a screenplay for the great, you know, kind of blockchain Bitcoin heist. That’s waiting out there for Guy Ritchie to do.
Ross Kenyon: I think the Coen brothers are working on something about, I think it’s Silk Road though, right? I think, I think it’s something like that.
Roderick Jones: Yeah, maybe.
Ross Kenyon: Yeah, it’s coming. With cybercrime, when I think about it in movies, it’s like the hacker just, I’m in the mainframe. Yeah, boring. Yeah, it’s like, Except for Mr. Robot, I guess, which is the most accurate, they say.
Christophe Jospe: You finally came around, Ross. You didn’t like it before, but I’m glad you dropped it.
Unknown speaker: He hasn’t finished it yet. Don’t give him credit.
Ross Kenyon: Yeah. So you started working in this space, you started caring about cybersecurity, and apparently you went private sector at some point.
Roderick Jones: Yeah. So in 2004, I moved to America from London, moved to San Francisco, started my first company, which is called Concentric Advisors. And then in that space, we started looking at cybersecurity about 10 years ago, actually, in a meaningful way. But I think the thing that drew me more recently into the blockchain and cryptocurrency piece was just this brilliant dissonance between what people assumed security and actual reality. And I think that’s absolutely accelerating at the moment. I think it’s almost linguistic. It’s encrypted. It’s cryptocurrency. There’s just this assumption from the humans using it that it’s all secure.
But like anything, really, the fundamental technology is new and therefore very open to exploitation. And it has some built-in insecurities and some added insecurities. So that kind of dissonance between the perception and the reality has really drawn me to it. And then statistically, I think I mentioned when we met that this year... There’s estimates that say there’s been $2 billion of cryptocurrency stolen from when Bitcoin started, so 2009, 2010. But this year alone, there’s been a billion dollars. So it’s an accelerating trend. There’s some stats put out by Bloomberg. That’s what makes it a very relevant topic for July 2018.
Christophe Jospe: So what are some of the vulnerabilities of cryptocurrencies? Yeah.
Unknown speaker: Just ruin this for us.
Roderick Jones: I would break them into systemic, which are slightly different to talk about. And then the main action right now seems to be around usage. So it’s obviously the exchanges have suffered. But the lion’s share of attacks, the exchanges in Japan and Korea that have specifically lost large amounts of currency. Mount Gox is the most famous. Mount Gox, but then the NEM heist at the beginning of the year, I mean, it’s $300 million walks out the exchange there. No one has got back. You know, I mean, there’s some fascinating side effects of that.
So the exchanges, it seemed to be incredibly vulnerable. But then, you know, the mental pie chart is, you know, exchanges, consumers and businesses. That’s where the victims have been of these attacks. And I think Of those, really, consumers are the rising target. And before we started this, we were talking about the Ola VPN breach affecting people with Ether wallets. That’s the new reality. Consumers are very wide open to having their cryptocurrency taken off them.
Ross Kenyon: And that’s just user error. What’s the acronym that you love, Paul?
Paul Gambill: Oh, PEPCAC?
Ross Kenyon: Yeah. Do you know about PEPCAC?
Roderick Jones: No.
Paul Gambill: Problem exists between chair and keyboard.
Roderick Jones: Yeah. Yeah. Yeah. I mean, and I think it’s always a little too easy to kind of poke fun at people. But I mean, I think people are really over their knowledge base in terms of how to manage private keys, these new systems. It’s not friendly to new people. It’s not at all. It’s not friendly to veterans either. Yeah, let’s face it. It’s just not friendly. So, you know, there’s a lot of catch up between the core infrastructure around the security of these assets needs to be easier to use. The whole systems need to be easier to use and more secure.
And we’re just not there yet. It’s still very early in the systems.
Ross Kenyon: We’ve had many discussions internally about the tradeoffs between being custodial and really helping people and not having... Having to have them manage their public and private keys versus obviously we take on less liability if they have it, but it’s not as good of a user experience, but it’s more secure. It shields us a little bit. There’s a balance to strike and there are ways to do it, but that’s been one of the harder design questions I think we face internally. Would you agree with that?
Paul Gambill: Yeah, it’s probably the biggest ongoing question.
Christophe Jospe: Okay, so my turn to ask a dumb question. What is a public and private key?
Unknown speaker: So good. Good host.
Christophe Jospe: Why do I need to care about my public and private key? What are they?
Roderick Jones: I mean, the public and private key aspects of it, I mean, this comes back to the fundamental design of the system. It is, I mean, Right. And, you know, you’ll be past my limit of knowledge soon. But I mean, essentially, how you make transfers is that everyone knows your public key. And then, you know, essentially, that’s what they use to transfer these assets to you. Only you have your property.
Christophe Jospe: And we were talking about exchanges before and the exchanges, when they’re centralized, manage your private key, which is an issue around how much you’re willing to give you. And then potentially as a consumer, you don’t know this, which makes you more vulnerable to attack.
Roderick Jones: And if you think about The vulnerability with cryptocurrency right now is the key one is when you have a live connection to the internet, that is when things can be transferred in and out of that wallet if you have a hacker in your environment. So that is why I think the exchanges are suffering the lion’s share of big losses. It’s all around when they have this trading wallet open. If hackers are in their machines, and I’ll come back to that point, then they can get into that and then just transfer these digital assets out, which is untraceable.
So that makes it almost the perfect crime.
Paul Gambill: It’s sort of like if you imagine like a big physical bank vault, normally if you’re holding on Right.
Roderick Jones: That’s a good analogy. And I think what the challenge is, and I think what people are beginning to understand more is that all of this cryptocurrency and blockchain infrastructure runs over machines. Whether that’s your smartphone, your laptop, or a server. And if those machines are compromised by hackers in any way, you inherit that vulnerability into the system. And I think there’s obviously protections around that. People are just now beginning to wake up to the fact that having protection around those machines is actually critical to then run these secure systems over the top.
You need security around the whole piece. It’s not enough just to have a secure blockchain. You need security underneath it. Maturity is developing to understand that.
Ross Kenyon: So those are from the user experience, either as a consumer or an exchange, and businesses probably are fairly close to individuals too in how they manage their keys.
Unknown speaker: That sounds about right.
Christophe Jospe: Okay, so my next dumb question. You hear about individuals who get a message on their computer at some kind of ransomware. Someone took control of their computer and they say, you know, send me X amount of Bitcoin to unlock your computer. Right. When I think about ransoms, of course, you pay the ransomer, but then you’re enabling up this whole new industry. And this problem exists between chair and keyboard. And we don’t want that to happen, but that’s kind of inevitable with the cryptocurrency space. So on the one hand, cryptocurrencies enable a whole new form of money and ways to create value and create innovation and industry that we both care deeply about.
On the other hand, the argument could be made, well, why do we use this if it just creates new vulnerabilities?
Roderick Jones: Yeah, I’ll break that down a little bit. I think one of the arguments that people use against cryptocurrency adoption is that it’s fully anonymous and it’s used to buy drugs and facilitate organized crime. Well, so is the US dollar. I mean, If you’ve seen an episode of Narcos or have any awareness of drug running, it’s big chunks and blocks of cash. That’s how it used to be done. Anonymous digital money is just the same as anonymous regular fiat currency. I’ve always found that argument to be spurious. And actually, there are ways to trace some of the currencies and Bitcoin is a public ledger.
There’s some traceability in that actually doesn’t exist within fiat currency to some degree. So I think the anonymity argument and the fact that cryptocurrency are used to enable crime is something of a spurious argument and not a very thought out one because crime existed before cryptocurrencies came and crime was quite successful before cryptocurrencies came. On the specific point of what crypto and digital crime enables is like everything in technology and now allows for enormous scale. So instead of just doing a ransom letter, which those still exist, you can now send email ransom letters.
Ransomware. It’s pointless because you just restart your computer and just delete the ransomware. So there are easy solutions to that. And actually, you have a clear indicator usually on how sophisticated the attack is against you, depending on how much money somebody is demanding to unlock your computer. If it’s $8,000, it’s probably not a very sophisticated attack. If it’s $800,000, you probably got a problem.
Paul Gambill: Or I kind of wonder if from a more like socially engineering perspective, it’s more effective if you get a large volume of victims and just ask them for $10. Yeah. Like that’s something that a lot of people might just be willing to pay and make money go away.
Christophe Jospe: Kickstart releasing your... Yeah. Right, right. There’s some hacker listening right now who’s like, challenge accepted.
Roderick Jones: I mean, I’m sure it’s happened already. Yeah, no, I think that’s frankly the history of digital crime. It’s like allowed for scale, email scams, phishing, all of that. It allows for scale because you only need, it’s the same as sort of Facebook advertising, really. You only need 0. 3% of people to click through. Right. If you’ve got a 2 billion community, it’s like you’ve still got a big audience. This is the office space left. Yeah. So yeah, to answer that, I think, you know, the anonymity piece is- Totally.
Christophe Jospe: The softball pitch that I wanted to throw to you is convince me why cryptocurrencies are a superior way of storing value than cash.
Roderick Jones: It depends where you’re from, I think. It would depend on your view of that. Since 1971 or 72, I forget the exact date. The International Monetary Fund. So there’s been 141 banking crises that have wiped out people’s savings. So if you’re Argentinian, for example, which is some of the early entrepreneurs in Bitcoin, you’ve seen your parents’ savings wiped out and your college funds depleted and you don’t have a lot of faith in the fiat currency that was supposed to be supporting your country. So I think there is room for digital assets in all kinds of areas and people seem to be making the argument about Bitcoin as a store of value as long as you understand its volatility.
So I think there’s a good argument for it. I don’t think there’s a problem with having more room for another kind of currency.
Ross Kenyon: So you’ve covered the on the individual level, things that can go wrong and businesses seem pretty similar there to exchanges a centralized hub. They’re a big, juicy target. But on the level of blockchains, you had an amazing slide at this presentation about how much it would cost to rent hashing power to 51% attack any blockchain.
Roderick Jones: Yeah, I think that was, you know, something we started looking at because I started looking at the 51% problem in the context of, okay, well, where is all the mining resources currently sit for Bitcoin right now? And then when you dig into that, you quickly discover them. You know, which is interesting when you think about if you do believe the thesis that Bitcoin is going to become a reserve currency and a store of value, well, then most of the mining operations in China with an authoritarian government that has the power to turn all that off if it wants.
In the event of a 51% attack, which is where you essentially destroy the thing that blockchain is there for to create an immutable digital asset, you essentially reintroduce replication. If you think about it just mentally, you have all of a sudden instead of one Bitcoin, you have two. They’re exactly the same thing. So you can spend it twice. You reintroduce this double spend problem. Which crashes the value of the network. So the 51% attack is something that essentially where the mining resources on the network destroy the value of the network by just creating double resources.
Now, for that to happen with Bitcoin would cost a lot of money and a lot of computing power. But the slide I showed when we met was more when you go down that scale of these proof of work coins, you can rent the computing power at a kind of a low number to create these 51% attacks against some of these smaller coins and you get down to the I think it’s been a long time. $16 million loss and change because of that. And I think that was a couple of months ago.
So it’s a kind of a recent phenomena that the kind of people in the space that want to disrupt these systems and make money of them have just understood their capability to do that. But again, it’s an evolutionary system right now.
Ross Kenyon: And it seems like the only way to really predict against that, I think there’s some work done on the consensus model for making sure that it’s harder than you might think to do it, but also just the size of the network, right? Like Bitcoin is the biggest. So it’s very expensive to change the past or double spend in the present.
Roderick Jones: Right, right, right. The confusing power to do it at Bitcoin. I mean, I think it’s very expensive to do it. If you were to even try it, it would be prohibitive. I remember seeing the number once and was it?
Paul Gambill: It’s not an impossible number, but it’s large enough that there are very few groups in the world.
Ross Kenyon: It’s if you wanted to destroy trust rather than steal money, then it might be worth it.
Roderick Jones: Yeah. And it’s also you get into the question of actually where, you know, the example I gave you where you can rent those hashing computing power. They have power up to a certain level, but even theoretically say it was $700,000 an hour to kind of attack the Bitcoin blockchain. We still actually probably wouldn’t be able to rent that power anywhere. You know, that computing power, that becomes a bigger number that just isn’t sitting around in AWS or anything, you know.
Ross Kenyon: Maybe the number I saw was buying all the gear and setting up enough farms to do it with everything that exists now without cycling off. Okay.
Paul Gambill: Yeah. So one way that this is sort of relevant to us at Nori is that we’re building our application on top of Ethereum. Ethereum currently is a proof of work blockchain that’s open to the same sort of attack right now. It’ll be transitioning to a proof of stake consensus mechanism in the future, which I think one of the kind of big reasons behind it is that it’s less susceptible to this sort of attack.
Unknown speaker: That’s right.
Christophe Jospe: Paul, can you define proof of stake? And also, like, why is that going to have a dramatically lower energy consumption than proof of work?
Paul Gambill: So proof of work works by you have different people at minors competing to solve a math problem. And the first one to solve the math problem finds the next block of transactions. So all the transactions that people have been doing in the previous 10 minutes or so get batched up into this block and then they’re published and then everyone agrees that this is what happens. This produces an arms race of creating better and faster computing equipment to do so, but that uses up a ton of energy. And is fairly wasteful, lots of waste heat and so on.
Proof of Stake works by getting people to submit into bonds a stake of amount of Ether in the Ethereum case. That’s basically simulating that. So it’s saying... So there are four of us sitting around the table here, all four of us put in some ether into the pool. And that pool is the now like size of what is being used to confirm each transaction, you’re sort of simulating it in software. It’s way better as far as security goes for this consensus mechanism because in order to try to break the block or get the next transaction, you have to have more money than the entire pool is using.
And if you’re caught, which you will be, you lose all of your money. So there’s an enormous disincentive against people trying to hack the network.
Roderick Jones: I think the proof of stake networks and started researching that this year are going to be the future because I think there’s actually still some governance issues to figure out in those spaces. For example, how big do you allow the staking pools to be and things like that? They’re obviously solvable. There’s enough people interested in it. But I think just in terms of just environmental issues, You know, protection alone, it hasn’t been a proof of stake because the mining of the proof of work blockchains has proven to be environmentally prohibitive and is starting to get that kind of a reputation.
And actually the proof of stake systems as well are less susceptible. They have different securities. Security problems, but they certainly don’t suffer from the same kind of 51% attack, which is just brute force. It would have to be a lot cleverer. And I think some of the math I’ve seen around understanding how to defend from that is based around this, you know, kind of computing theory that came out in the 80s, the Byzantine general problem. And I don’t ask me to explain it too much because I’m still kind of gathering it, but it, you Problem was used to solve the issue in critical systems like airplanes.
If you have a sensor in a system that’s telling you two things at the same time, how do you know how to trust it? Some of the math, it’s pretty solid math that’s been used in critical systems over the past 30 years has been transferred into these proof-of-stake systems to solve some of the security issues. I think there’s interesting work being done on that. I think Ethereum has the Casper Protocol, and then Archane, the guys downtown in Seattle are building one as well, and they seem to be moving forward in that system.
And kind of working together, collaborating on improving.
Unknown speaker: That’s right.
Ross Kenyon: Yeah, Tezos is now just launching at long last. Also proof of stake system.
Roderick Jones: Yeah, I think there’s a good article about them in Wired this month.
Unknown speaker: There was, yeah. Dramatic cover story, yeah.
Ross Kenyon: So what could someone do at the consumer level to make sure that they are as safe as possible? Someone who’s maybe doing regenerative agriculture on our platform, who’s working with Nori tokens, what’s the best way that they could do this safely?
Roderick Jones: There’s some very simple answers to this. I mean, I think, first off, good password management. And that is, you know, kind of basic, but I’ll explain why that becomes important. So using things like a password manager, not using the same passwords at the same time in different things.
Unknown speaker: One password.
Roderick Jones: Yeah, one password. LastPass, those kinds of things. Actually, those basics are very important. Moving away from using a text message as a secondary piece of authentication to using authenticator apps like the Microsoft or Google one. And I will tell you why those things are just the starter points for getting into this is because what we’ve seen from the community is it would appear that crypto users seem to be disproportionately affected by the phone porting scams where your phone number is ported out to an attacker device. And then they can see these secondary authentication pieces.
But it relies on the hackers having got your credentials in the first place.
Paul Gambill: You know, since those attacks started happening, I used T-Mobile for my service and they added a feature where you can sign up to add a password.
Unknown speaker: That’s right.
Paul Gambill: To prevent that thing from happening.
Roderick Jones: We should probably explain what this attack is. So this is a social attack. This isn’t really like hacking any software.
Paul Gambill: If you have two-factor authentication, What people do is they call up your telco provider and pretend to be you and get So that’s why Roderick is saying use Google Authenticator or Authy or something like that to generate real-time codes.
Roderick Jones: Yeah, it feels like there should be a basic user kit for when you’re starting to use cryptocurrency. And it doesn’t have to be that complicated, but I would certainly say password manager for sure, authentication application, and then I would advocate some kind of VPN application. I think when you’re moving into a space where the attacks are becoming more advanced against crypto users, you’re going to need more advanced security. And that’s what we do fundamentally. But I think it all starts with just do some good basic digital hygiene first, and you’ll be a long way forward.
And then you can add some advanced stuff in.
Ross Kenyon: Yeah, that’s right.
Christophe Jospe: Yeah, and it used to be this VPNs. It’s an old technology. The protocols are pretty old.
Roderick Jones: I think part of the interest in cryptocurrency is the anonymity aspect is the kind Retaking and reclaiming your privacy potentially and your digital identity back from some of these larger technology companies that have sort of taken that over without anyone really noticing. And I think VPN technology, because it does reintroduce privacy for you as an individual as gaining in popularity. And I think that’s a good thing, especially in the light of where the whole technology environment is going.
Ross Kenyon: How do you feel about hardware wallets? You gave us those three rules of software, security hygiene. Do you think a hardware wallet for cryptocurrency is good? And what exactly is that?
Roderick Jones: Yeah. So that’s somewhere where, you know, you’re essentially a crypto coin. There’s just a series of numbers and you need to store them. And some people actually advocate quote unquote paper wallets where that number is just written down and that’s the storage, you know, that Paper isn’t as durable as some things and it’s not as easy to use digitally. But yeah, I mean, a hardware wallet is just a place where those numbers are stored and it has extra security on. So typically they’re USB devices that plug into your computer and they have some extra security to unlock then those assets inside.
Paul Gambill: So the way they work is you have your public key and your private key is stored on that device and you actually never have access to your private key. So the private key never leaves that hardware wallet, never goes onto your computer where it could be potentially compromised in some way. It’s just sending a token saying like, yes, I know what the private key is and you can trust me because you’re connected to me.
Christophe Jospe: But if you lose that hardware wallet, what happens?
Paul Gambill: Well, then the hardware wallets come with what are called seed words. So like if you’re using a Ledger wallet is a pretty popular one or a Tracer or however you say that they’ll have like say 24 different. I mean, it actually brings up a fundamental thing that hasn’t been I mean, clearly, there’s a lot of work to be done there.
Roderick Jones: Consider how much biometric data is available, even just opening your iPhone, you know, it’s facial recognition. So tying a lot of innovation together and creating more clear ownership structures around the digital assets, I think is going to have to emerge over the next five years to make these just more tradable, easier to use, going back to some of the stuff we started talking about. We’re still in a position of writing things down on a piece of paper to prove that our assets were not in a very smooth world yet, you know.
Ross Kenyon: We’re in a period now where the identity crisis that has always been, or maybe the philosophical tension that’s at the base of this entire sector is between, do people want these projects to be adopted by the mainstream? Do we want banks and hedge funds and the government to use blockchain applications? Or is this a totally revolutionary, crypto-libertarian, anarchistic kind of project? And there are projects that span that whole gamut too. There’s some that hedge somewhere in the middle. There are some that are very far one way or the other. That’s part of the fun in this space is there’s a lot of these philosophical projects going on.
But I think what you’re saying, though, is that you would like it where the existing financial infrastructure is quite bad, like ACH taking days, as opposed to now you can just do things that clear immediately. And you could do things without having a password necessarily, maybe biometric information is much more secure. But then also, do you want to pass it to corporations and the government relative to having a private key that’s on a paper in your basement? It’s not my basement. Don’t go looking for it.
Christophe Jospe: Part of me thinks like, is this to some extent the modern day keeping money under your bed, under the mattress? And are those sorts of people going to say, hey, okay, well, I didn’t trust the bank in the first place, but now with crypto, I can be my own bank and I can access my own bank.
Roderick Jones: Yeah, I think there’s certainly that phrase of being your own bank is, I think, what has driven a lot of people into it. But then, you know, what happened was the price of Bitcoin went up to $10,000, $20,000 and you became a millionaire and realized that you might need security like a bank. And where do you get that from, you know? How do you keep your laptop secure to secure a million dollars on it? That is not something you could buy. Again, part of the reason why we invented Rubica and built the company to provide that level of security to individuals.
But I think the broader question about where this goes with regard I think there’ll be a lot of hybridization of some systems being adopted by government, with government, with regulation. The space is crying out for regulation in some areas because the entrepreneurs are looking for definitions from government. So they don’t get on the wrong side of the SEC and get on the wrong side of our life. Right. I mean, and actually where you look at the jurisdictions of Switzerland, where they’ve actually taken a step forward in that and said, we’re actually going to define what the regulation is involving that space.
They’re starting to attract lots. I think government will be interested in it. And I think also the great joy of the space really is bringing people into the financial sector that have been removed from the financial sector. You’ve lived in a Western economy for the last 50 years. You’ve done very well with the economic system. But if you’ve been in Africa or countries in South America where they’ve had economic and currency collapse, it hasn’t been roses. So you’re bringing the unbanked, as it were, into the system and providing a level of transparency where there’s only been corruption previously is the great dream of these blockchain projects.
And I think that is what makes it so interesting.
Ross Kenyon: There’s a great book I’ve been reading called Blockchain and the Law. This comes out of Harvard University Press, but it talks about this tension quite a lot. But also with this increased transparency, there’s increased ability for control because James C. Scott, the anthropologist from Yale, has this idea of The view from the center and centralized institutions, they like things that are neat and orderly. Like he gives an example of Paris, Parisian streets used to be all crisscross and crazy. The state didn’t like that because whenever they had to put down a rebellion, they would go into one of these weird twisty streets and it would get barricaded and they get sniped down at.
I think it was during the Haussmann era in the 19th century, they built the large boulevards because it was very easy to run cavalry through it and run troops and not get pinned down. In the blockchain, sure, there’s like some pseudonymous characteristics of it. You can identify someone or if you know how to do it, you can be anonymous, but you have to work at it. It’s just not built into it. There’s a concern that what if all of your financial transactions were all of a sudden easily decipherable by either the government or by corporations or by criminals?
And that’s something that blockchain could happen with transparency.
Roderick Jones: I agree with that danger. That danger sits out there. And I think we’re at an interesting point in society right now where society is just waking up to the dangers of total information surveillance that wasn’t imposed by government. But we all volunteered for it. We all decided to use Google, Facebook, and all these services.
Ross Kenyon: My Kindle advertises to me like Druid love stories. And I want big data to come save me from it. Give me something better than this. I want a better ad.
Paul Gambill: We’ve gone more Brave New World than 1984.
Roderick Jones: We’ve gone into that space. Bank of England have been quite explicit about this in that they’ve outlawed, and the European Union has outlawed large denomination notes because they didn’t want them to be used as a store of value or for crime. That was the story. But the more that you I actually think from the innovation that’s occurring the blockchain community, Community is writ large. Some of that, like I said, it will be a hybrid. Some of it will be adopted by government. There is a high probability that digital money will exist.
The United States Fed will have some play in that space, but there’ll still be these other tokens as well. Because it’s essentially, I can decide that this is worth something and I can trade it with you. New things are attracting value all the time. I mean, if you look at the computer gaming space, that whole explosion of digital assets becoming worth money happens. Absolutely. It happened there first and that isn’t slowing down, you know, these special things that people are putting labor into in terms of playing these games that are worth value and they’re tradable.
So I don’t think you ever get to roll back the idea of digital assets being tradable and having a value, you know, just that’s the nature of the space, you know.
Ross Kenyon: Where do you fit in professionally with this space? It sounds like an active intellectual interest of you, but where does Rubica fit in?
Roderick Jones: Yeah. So Rubica, in terms of cryptocurrency, we began this project a couple of years ago, two, three years ago, because we simply wanted to provide individuals with advanced cybersecurity. And that was our task. That’s how we set out. And how that came about really was I was thinking about the space and just thinking that we’ve been given lots of digital rights and opportunities, but no company or no government has given you as an individual the ability to defend yourself. I thought that was a really interesting idea. You do get very, very good cybersecurity because good cybersecurity exists.
It’s just very expensive and it sits in corporations. So we decided to kind of take some of that innovation and miniaturize it essentially and package it for use of individuals. And so we built a system that does involve a VPN. So essentially a software that sits on all your devices. And we made a key innovation there. Cybersecurity in the past has always been about protecting the machines. But we said we want to protect the individual. And the machines are attached to the individual. But we want to protect the iPhone, the laptop.
Tell us all the technology you have and we’ll put our software on all of it. And then we can form a baseline of your digital version of yourself. And then we’ll protect that. So we did that. And as we were building that and we launched it into market last year at a very high price point just to kind of, because it’s expensive to start with, just to see what the market looked like. Then, as I said, this thing that we couldn’t have predicted, Bitcoin price goes to And you have a whole new generation of people who are suddenly very interested in advanced security because they have digital assets and no protection for them.
So we were working almost in parallel with a community that we weren’t really talking to at the time. And then we started to merge. And when we just completed our last round of funding, we took some strategic investment from Reflective Ventures who are attached to the R-Chain project, mainly because I saw that as a pathway for us in the future. The problem with cybersecurity for consumers in Western society is people do not understand how vulnerable they are and they need a lot of education in terms of how much security and how vulnerable they are online.
You don’t have to do that education with the crypto community. They’re already there. They already understand that if I have a $10,000 coin sitting on my computer, I probably should buy some protection for that computer, you know, and the rest of it folds in. So that was how we became, you know, more merged with that kind of crypto space.
Ross Kenyon: You were talking earlier about some tokenizing performance on this network or something.
Roderick Jones: Yeah. So as any good entrepreneur should, one of the best pieces of advice I ever got from another good entrepreneur in San Francisco, we were talking about fundraising and the venture community. I started looking at ICOs at the time and I was thinking, oh, that’s interesting. The fascinating thing about blockchain systems is that it is a new way to organize it. You can create micro incentives for people to act in a virtuous way in networks, which is really important.
Ross Kenyon: That’s what we talk about every single podcast.
Roderick Jones: So guess what my number one problem is? I’m trying to get people to do virtuous things. I’m trying to get them to give themselves safety. Protect yourself and your family. But people don’t want to do it. It’s like, oh, I’ll take care of that password manager thing on Sunday. I don’t really want to do it. So my idea was, and I think it’s something we’ll probably still explore this year, is if you could create a token that when people had our cybersecurity service on, they were rewarded, they earned tokens for doing that, and we could create that kind of virtuous circle in that network of the more cybersecurity.
Now, the value to us is when you have Rubica running on your service, we might see an attack against you, and then that data we can use to create even more value in the network.
Paul Gambill: It felt like a very blockchain type project, you know? You’re paying people to be more secure and in the process of doing so, you’re making the network more secure.
Roderick Jones: Right, right. Which is a perfect- That’s awesome. But it’s a perfect use of the idea, right? As an entrepreneur, you’re always kind of scanning for ideas. And I was sitting next to a very smart guy. He was a lawyer. He was a lawyer at a big VC firm and then found the light. And he was saying to me, like, we’ve been organizing companies in the same way since the 17th century. The Dutch kind of like stock corporate. Sell through fear. Sell through fear. Sell through fear. I think that is, you know, an old model and I don’t really want to pursue that.
So I think the idea of motivating people to contribute to a network and rewarding in that and us essentially, you know, managing that seems like a way smarter 21st century way of organizing a cybersecurity company. Yeah, that’s the idea.
Ross Kenyon: I’ve kind of taken it back a little bit. Yeah, that’s brilliant.
Roderick Jones: Thank you. I saw it haven’t come out name for the token, but it rubies maybe, but it seemed a little trite. Yeah.
Ross Kenyon: Like it’s cutesy. Are you sure it’s not already taken? Maybe they get taken pretty quick.
Roderick Jones: But the other thing that’s beautiful about it is you can incentivize so much more of the network. That works as well. People looking for bugs get legitimately rewarded. People hosting some of the key VPN and nodes, guess what? They earn more rubies potentially for hosting that. And everyone’s incentives are aligned to make sure the whole thing’s secure because that makes the tokens worth more money and all the rest of it. So it remains an interesting idea.
Ross Kenyon: You might need a lower price point. I know you started a bit high, but maybe this is a way to...
Roderick Jones: Yeah, I think...
Ross Kenyon: You want a robust network with lots of participants.
Roderick Jones: Yeah, I mean, I think that’s a thing that I think... I mean, we have some really great people work for us and I’m asking them about... So I’ve always felt that the more users we have, obviously we see more data, but we see more threats. We’ve already seen that at a small number of users. We see threats first. We saw some of the big attacks last year before anyone else just because we had a different data set we were looking at. So I think there’s a very interesting opportunity there to push that out.
And I think we’re going to launch a new price point in autumn, in the fall, which will allow more users to adopt the service. I’m not going to say the number yet, but it’ll be significantly lower than where we started because we want to attract more users in and see where it goes. But I still think there’s something quite exciting about using tokenization as well.
Ross Kenyon: That’s great. I think this is a good point to close it out then. Thanks so much for being here with us, Roderick.
Roderick Jones: Thank you.
Ross Kenyon: Are you going to tell me to do the thing?
Unknown speaker: Yes.
Ross Kenyon: Dear listener, if you like what we do, please review us. Give us a good review. Give us a good rating. Share it with your friends. Help get the Reversing Climate Change podcast out there. If you like the show, that’s the most important thing you could do to help us. And thanks for listening. Thank you.












