Joe: How's going, Andrew? It's great to get you on the podcast. I'm actually really excited for our conversation today. I know I know we've moved this around. I'll take I'll take full blame, you know, my my two little two little kids in daycare. It's just like they they get sick insanely often.
Andrew Bud: I know what it's like, Joe. I I have four children. They're they're not in daycare a anymore. The eldest is thirty three. But I know what you're being saying. It's not it's a pleasure to be on your podcast today.
Joe: Yeah, yeah, that must be like such a great feeling being on the other side of this. It's like
Andrew Bud: The journey is great all the way.
Joe: Yeah. Yeah, that's you know, that that's what I tell people. and I I was told it by someone and I can't remember who even told me it when my first was like still, you know, cooking, right? that that's what I call it. My wife kinda hates me for it. But you know, when we were when we were expecting our first, someone told me you have to really enjoy every single moment because it changes From week to week, right? You go from having a baby that can't sit up to being able to sit up. And then you get like literally overnight, she goes from not crawling to crawling, right? And like it just happens that quick. So you really have to like be present in the moment. You really gotta absorb it all and like, you know, really enjoy it.
Andrew Bud: We we always my wife and I always said as our children were growing up, isn't this just the best age when they were one? Isn't this just the best age when they were three? Isn't this just the best age when they were five? Isn't this just the best age? But I found it incredibly important to be present. When my when my oldest daughter was, I think about nine months old, I went away on a business trip for a week and a half something like that. And when I came back, she didn't recognize me anymore.
Joe: Mm.
Andrew Bud: And I was so shocked by this that I vowed never to be away for more than four days at a time. And I've I've kind of stuck by that rule. luckily if she doesn't see me for four days, she she now does suc continue to successfully recognise me, but as I say, she's she's thirty three.
Joe: Yeah. That is man, I I've I've had opportunities to travel, you know, all over the place since my kids were were now here. And I've only done one tr I've only done two trips o away from them. One trip because my uncle passed away and you know, I had to go and do that whole thing. But the other day was like literally thirty six hours, right? Like from from the time Like I left the door to the time I came back through the door. It was thirty six hours. I was dead tired. But like I didn't I didn't miss you know.
Andrew Bud: In in in two thousand and three we were doing a a big Silicon Valley fun financing round for my last company, not not for Iproof. And we had v we had meetings with VCs on the Sand Hill Road on like Wednesday, Thursday and Friday, and then we had some more meetings on on Monday and Tuesday. I went from London, from from San Francisco, I went home to London for the weekend, and then I came I came back again for the next week's meetings.
Joe: Yeah. No, I would do the same thing. I I don't I don't I don't I don't I don't find that odd at all. I I would do the exact same thing. Like we're we're not even doing big trips
Andrew Bud: Family in the end, family is the most important family is the most important thing i i in in certainly for me i i in my life. you y you can you y you do business you do business for lots of reasons. A lot of it is about purpose. A lot
Joe: Mm-hmm.
Andrew Bud: of it for me is about purpose. But the highest purpose of all has been to to to to to look after and fend for and bring up our family to the best of to the best of their ability and it's it's frankly the most important achievement that I'll ever have.
Joe: Yeah. Yeah, absolutely. Totally, totally agree with you. Well, you know, Andrew, why don't we take a step back and hear your background, right? I I I'm really interested to hear how you got started in this space. you know, whenever whenever that was, however that looks, because i if someone's listening and maybe they're just getting started out, right? Maybe they're doing a career change or something like that. I always found that it's helpful to hear someone else that came from something similar achieved what you're trying to achieve. And then you can say to yourself, well, if they did it, maybe I can do it too. Right. And that little brain switch is really all that someone needs to really keep going and and achieve it.
Andrew Bud: So I the first thing to say is I'm a I'm a trained engineer. I'm an engineer by training, I'm an engineer by expertise, and I'm an engineer by temperament. And I had the great fortune to be at the cutting edge of three great technological revolutions. In the 1980s, I was in I was very much involved in the transformation of product and manufacturing industry from electromechanical to electronic and microprocessor controls. In the 1990s, I was fortunate to be one of a band of pioneers creating mobile communications. digital mobile communications. and that became then also mobile internet. And now I've been part of the identity revolution. As an engineer, your your your role is to solve problems. And so one of the things that I found most most important most important in life was to understand big problems that needed that needed solving. And to see how good solutions could change people's lives. The f the extraordinary thing about being in the mobile c in the mobile communic mobile phone business, for example, I remember sitting in a in a a sauna in nineteen eighty-nine, absolutely start-naked, together with a very senior executive of a large global telco. We were hypothesizing what the world could look like if everybody had a mobile had a telephone in their pocket that could make and receive telephone calls and give them instant access to to communications. wherever and whenever they liked. It was i i it would change the world. It was a fantastic vision. And then and we worked on it and then you know what it happened. How amazing is that? in the early noughties I understood that text messaging could be an enormously powerful solution to the problem of how enterprises could engage constructively and respectfully with their customers, with consumers. And I s and nobody was doing it, so I set up a business that made text messaging available to enterprises as a means of communication to their customers and consumers and that grew to become the the the world's largest i in its sector. Along the way, we also were asked by the mobile network operators to become processors of mobile payments because the APIs turned out to be the same. And it was not something I knew a great deal about, but if you're going to do it, you do it well. So By 2008, we were the world's largest processor of mobile payments. We were clearing settling about half a billion dollars a year of mobile payments, mostly Joe 4 for ringtones. It's a little known fact that at its height, the global market for ringtones was larger than the entire recorded music industry.
Joe: What?
Andrew Bud: the but the problem was that we didn't have much exposure to the adult or gambling industries, which were huge revenue sources, but also huge fraud furnaces. And because we didn't have experience of that, our systems had a num had quite a number of unresolved exploits and vulnerabilities in them because they'd never been tested. And when the crooks found that out in 2008, within six months millions of people had money stolen from them through our net through through my network. And this was awful. I I I I ended up on television. With a British TV microphone thrust in my face. Mr. Budd, the role of you and your company in this scandal, were you complicit or just recklessly incompetent? Well, the answer was neither. The regulator investigated us very deeply and said that in fact our behavior had been exemplary. but th that was I was very ashamed of that. That was very horrible. And I vowed it wouldn't happen again. and the problem was how to ensure that a customer was physically present in front of their mobile device, any mobile device, no branding, no, no brand segmentation could be permitted, at the time at which they made a transaction, with zero effort, because one of the key characteristics of mobile payment was that it was a zero effort experience, but with such security that people who could steal several million dollars a week would not be able to break through it. We we asked some consultants to tell us how it could be done and they said it can't be done. That was a problem. Because I didn't want to go back on television again. That was a problem because I didn't want to I didn't want to be ashamed of what I was doing anymore. So I spent a year as so you know, you see an unresolved problem, I spent a year figuring out how to solve it, and I ended up inventing the technology that underlies iProve. And when I invented it, I suddenly realized that this wasn't about ringtones. This was about that I what I'd solved was the problem of establishing trust remotely over the internet. And as I said to my first to our first employee, when you're an entrepreneur, one of the biggest problems you've got is to find a problem that is big enough, valuable enough, important enough, and also interesting enough to assemble a team and get them leaping out of bed with enthusiasm every day for ten years. Ten years, he said. And that was fourteen years ago. And we're still we're still motivated by by the by that enthusiasm. when you see a problem when you see an above all in as in my case, you've lived a problem that needs to be solved, you feel and it's worthwhile solving it, you feel compelled to do so. If you can share that vision with others, then you can build a team to to do to do it. I when I mentor young people and I do, I tend to discourage young people from being entrepreneurs too early because there are so many mistakes you can make. that it's best to make those mistakes at other people's expense. Because otherwise you have to make them at your own expense. And that can be really quite painful and uncomfortable as as I discovered. I had to be a an entrepreneur from early on because I I I wasn't I wasn't very good at corporate politics and therefore I had no great career ac prop career prospects in large corporations. So if I wanted to be an important person, I was gonna have to sit on top of a pyramid I built myself.
Joe: Hmm. Yeah, I I feel like that's a pretty common theme now, you know, especially like with the current generations and everything where everyone kind of has a side gig and they're doing that side gig almost in hopes of it turning into the main the main source of income, you know. And I early on I reached out to someone that was actually on the podcast a couple of years ago. I should probably have her back on. I was Al Alyssa Knight, where I mean, she has like 20 plus companies, started out as being like a very infamous, you know, hacker, caught by the FBI, worked, you know, then for the FBI and the NSA, helping them find other hackers and stuff. and she turned that into, you know, this empire that that you just wouldn't have expected. You never would have expected. And when I was getting started, I I had that same mentality where I didn't really want to work the nine to five. I didn't really want to take directions from people that didn't know as much as me and I I felt like I was making better decisions and whatnot, right? and it was like very conflicting for me, right? So I I I knew I wanted to go down the path of being an entrepreneur to some extent. and even to this day, you know, I haven't taken the full, full blown leap. But I do have things in place that I think if I just re-geared myself after this dissertation that I could make that leap. But you know, she she emphasized when your side income is bringing in as much money as your primary income, then and only then should you consider ditching your your nine to five and going all in. Because one, it's too much of a financial strain. for you to just try and go into something with nothing and make it work. It's just too too stressful. Not very many people make it. And, you know, on the other side of it, if you end up not wanting to do it, you still have your nine to five. Right. And if your nine to five really pisses you off, you can just go do do your side stuff, you know? and that that was something that like honestly led me pretty well because there were several times that I was tempted to to jump ship and it was like, nope, I gotta follow this rule. This rule makes too much sense.
Andrew Bud: You know, I I do believe that hunger, I mean real necessity to succeed, is one of the most powerful drivers for success in entrepreneur. Even more than, shall we say, the desire to be wealthy, but the necessity to make to to be a success is an incredibly important wealth it's an incredibly important driver in this. Look in in in two thousand and three when I did this when I did this this fundraising I was talking about earlier. One of the VCs took me aside and said, Andrew, what why are you doing this? Is this because you you want to be s you want it's for your vanity. You want to be seen as the person, you want to be famous for having raised money and done this. Or is it because you want to secure your pension? Or is it because you just want it's a lifestyle thing, you just want to sit at your desk and write code or whatever it is that you do and just be left in peace. I said at the time, Shirley, Shirley Cerudo, If you're listening, Shirley, I still remember this conversation with great affection. I said, Shirley, I've got four children to put through private school in London, and I need to I need to make the money to do that. This is a financial process for me. She said, That's great. Our interests are aligned. That hunger was absolutely essential. When I found it eye proof, I had no pension. I was I was 52 years old and no means of supporting myself in in in retirement whatsoever. I could not afford this thing not to succeed. And That means that that and so this this this necessity, this hunger, that this isn't just a side gig to see whether you can actually make this make this success, but you've got if you're dead serious about it, then I think you're more likely to succeed because you go the extra mile, you make some of the compromises, you you're driven by by creativity. You've got to be careful that it doesn't tip over, because the flip side of that hunger is terror. And I remember waking up at three o'clock in the morning on a number of occasions, literally soaked with sweat and shaking, because I suddenly realized how this thing what this thing could be like if it went wrong. But I think one of the most fundamental one of the most fundamental attributes of a successful entrepreneur is is denial. You know, you the ability to not look down. Because if you look down, if you look down, you'll y there's a real risk you'll freeze with terror.
Joe: Yeah.
Andrew Bud: So you've got to bel you've got to I think the combination of real hunger and an uns an unshaken s conviction in your potential for success are two fundamental of two fundamental drivers. Now having said that, you've just described to me a classic example of the exception that makes the rule of somebody who actually was able to do it as a side gig. But I think you're more likely to succeed if you commit with deadly seriousness to making it to making a go of it. It helps to be a bit older, it helps to have made the mistakes, it helps to have done, to have had experience of the different disciplines that you have to get right in order to run a business, and it helps to have screwed up, as I have done many times, and learned the bitter lesson so that you don't you don't do it when you're running your own business. But obviously that's not an option for. people who get into it earlier on. Resilience, therefore, it matters.
Joe: Yeah, I I I definitely agree. I I think that there's there are probably like two trains of thought, right? Like I I I feel like what I describe probably fits, you know, ninety-nine percent of people. And that's probably also why ninety-nine, ninety-eight percent of people won't won't achieve it, right? not to say that my mentality is poor or or or bad. It's a safer it's a safer outcome, right? Like that it it kind of builds in that cushion no matter what. But you're absolutely right. When people kind of, you know, burn the boats, so to speak. And it's like we have to make this work no matter what. Usually it it starts working, you know? because like that's such a it's such a struggle just to get to that point where you're burning the boats and you have to move forward that it's like, okay, well, there's no turning back. I didn't just go through all of that to turn back. You know, and like that's honestly that's kind of where I'm at with my dissertation right now where You know, I'm getting to the end of my coursework and my my my chair went and hit me with this email yesterday saying, Hey, we gotta start getting you ready to to defend like this fall. And I'm like, defend? What does defend even mean? I don't feel smart enough to defend. I feel stupid right now. Like, what are we talking about defending for? Like, what am I even def I don't know what I'm defending? Like, what am I defending? You know? like that's where I'm at. Like and I mean they're burning the boats
Andrew Bud: Yeah, yeah.
Joe: for me, whether I want it or not. You know, the the boats are burned.
Andrew Bud: You're but y look, you're defending your conviction. Y everybody who everybody who undertakes who creates a brain baby, di a dissert an a a dissertation is a brain baby. A company is a brain baby. Anyone who creates a brain baby does so with with a conv with a conviction. And when you are put in front of that v I don't know what it's called in the United States, in in in Britain when it's called a viva, when you have to defend your your your P your PhD. When you put in or when you put in front of of a venture capitalist and you're trying to raise money, or when you put it in front of a customer who says, What is this rubbish? You have to defend it with absolute conviction. And if you have that absolute conviction, then you can then that will show through. That will show through in your driver, because they'll know not only that you know your stuff, but that there's a hinterland of thought and understanding and work that went behind it. People can feel that. Similarly, when you when you pitch to to venture capitalists. It's the same. I used to lecture at the University of Cambridge's Judge Business School. And one of the on on entrepreneurialism and one of the things that I used to say to them is practice. And when you practice, listen very carefully to that strange squeaking sound that walking on thin ice makes. Sometimes only you can hear that noise. Because when you practice and you pres and you'll hear the bits that don't that aren't con that aren't convincing. And if they're not convincing, then they're not convincing because they're stupid, because you're not stupid. They're not convincing because there's something wrong with the way you're communicating it.
Joe: Yeah, that's a really good point. You know, like I I feel like I spent a couple years like trying to talk myself out of it, almost saying, like, this isn't gonna work. And, you know, to to my own credit, right, it wasn't going to work the other 50 ways that I had thought that it was going to work. It it just wasn't, right? I I guess that shows what one of the deans told me, like, well, that shows that like you put a lot of thought and effort into this thing. And I didn't even discover that it was gonna like fully work until probably last November, where I had someone and I was talking to them, interviewing them for my dissertation, and everyone up to that point had told me this isn't gonna work. Right. Like they were finding holes in it, they were saying, like, this is too hard, you don't understand space is too difficult, like it's different when you have when you're talking about securing satellites in space and whatnot. And Then, you know, it came up where someone was talking to me about low level authentications and how they work and how they can operate and whatnot. And that was the very first time, literally last November, where anyone told me, I think this might work. Right. And this whole time I was just beating my head up against the wall. And then the next two or three people that I that I interviewed for the dissertation came on and they they said, Yeah, I think that this is actually the only way that it would work. Like Literally the only way that it would work. There is no other option. And I like it took me like a week just to recover from that because I was like, my God, I just I literally did all of this work and I thought at the end of it I was gonna have to say it doesn't work. You know, like 'cause that that's what my chair was even saying is like, Hey, you're doing all this work and it's just gonna be that it doesn't work. That's okay, this is acceptable. And I'm like, this isn't acceptable to me. You know, I just did all this for nothing.
Andrew Bud: It so so it's really challenging when you're do it when you're being an innovator because on the one hand you have to invest with conviction, but on the other hand, you can't i and and and not look down. But on the other hand, you actually have to be rational. You have to be realistic about it. look, when we were put when when I invented iProof, the iProof as as you may know, is is based upon the use of the s of the screen of the device to illuminate. The subject's face with an unpredictable sequence of colors. And then we stream the video back to our servers, where we then analyze the reflections of the screen light from the user's face. We look at it spatially, we look at it spectrally, we look at it temporally. We make sure that the sequence of colors that we're seeing on the face is actually the sequence that the phone created. And that's a great way of defending against replay attacks and against pre prepared synthetic video and whole sorts of other things. When I had this idea, It struck me as being of exquisite brilliance. The only problem was it wasn't at all clear to me that this could be made to work. Because from a signal to noise I did some from a signal to noise re ratio point of view, this is really hairy. This is running at sort of six to eight dB signal-to-noise ratio. So it's a great idea, and we could solve world trust and we could we could protect people's identities. And you could do all sorts of great things if this thing could be made to work. And it's very easy as an entrepreneur to fall so in love with your idea that you you end you end up victim of confirmation bias. You start building castles on the basis of a foundation without taking a hard look at whether the whether actually you're kidding yourself and this is a fallacy. And in fact, I spent about two years working with a colleague just building enough enough print prototypes that we could actually assess whether there was enough signal in the reflection from an average from the Samsung S Galaxy S3. So we're not we're talking about a 200 knit screen device, not modern phones, whether there was enough signal on the phone on the face in average conditions actually to get it to make that work. And it was only when we had proven it to our satisfaction that this could be word that that we actually began to say, yes, we can build a business on this. And
Joe: Hmm.
Andrew Bud: and I think that's really important. Conviction is one thing, madness is a s delusion is a slightly different thing. and you just need to be realistic about it. Luckily, in a in a dissertation, if you turn if it turns out that an idea can't can't is impossible, that is in its in itself a success. An acad an academic piece of work does not fail because the fundamental act because the fundamental tenet, the fundamental notion was false. In business, unfortunately, it does.
Joe: Hmm.
Andrew Bud: So you have to it's really important early on to identify the fundamental risk elements, the fundamental n unproven notions upon which you are basing your concept of business success, and then proving them as quickly as possible to make sure that you haven't you have that that all that's n that that you're in a pro that you've got conviction and not del not delusion.
Joe: Hmm. So when you were creating this, what was the idea behind this technology? Was it was it truly to identify there's a real person on the other side of you know the screen? Or what what does that thought process look like? Like how did you get, you know, to actually creating it and identifying, okay, this is the problem. This is how we're gonna solve it.
Andrew Bud: So as I say, the problem was we we we were we were we had fallen victim to this attack, which was basically a bogus transaction attack. The attackers had found a way to initi to make it look as though a transaction had been initiated by the user, when in fact the user was fast asleep, the phone was in their pocket, various other things were happening. So and then the user would be billed and they would they would protest and there'd be a scandal. And when this happened on a large scale, we found that millions of people had been defrauded, and we couldn't actually d even distinguish between those who had been defrauded and those who who were gaming the system and had claimed to be defrauded and were actually repudiating genuine transactions. So it was all a big mess. So the problem we have was how can we be sure that a person is in front of a device at the time which the transaction is registered. So that we could also have non repudiation. You know, a person says, I didn't I didn't do this transactional ha How can we how can demonstrate that? And face matching, face verification, felt like a very good way of doing that. Make sure that the person who supposed the person who was entitled to make this transaction is recognizably in front of the camera. Great thing is, no you didn't have to have any special special sensors because even in those days, quite a lot of most mobile devices had front-facing cameras. But it was obvious to me. that the way the attackers who had put me in front of the camera in front of the T V cameras in two thousand eight, the way they would attack this would be that they would record their malicious software would record the user once and then play them back. At which point you would have something that was that was a real nightmare because it would look as though the user was there, but they weren't. So in the case of a repudiation attack in a case of a repudiation you wouldn't know who was right. So I thought how do we defend against a against a a replay attack? Well, okay, let's sta do what you normally do, which is to stick a one-time code on. How do what what transducers do we have? In a mobile phone, even in those days, you had a screen, you had a loud speaker, and you had a buzzer, and that was it. Those were the only transducers. The most powerful of which was the screen. Okay, can we use the screen to stamp a one time code onto the image in order to distinguish between a a replay and attack another? The answer was yes, we could. And if that was the case, then if the if if Then at least we would have a a genuine we would be able to to prevent replay attacks, because they wouldn't have the right the right cut the right color code or the right flash mark on them. And if someone tried repudiating a a a claim, we could go, excuse me, here's a video of you doing the transaction with a with a cut with a flash mark timestamp on it. What do you not understand about you being caught red-handed trying to commit a fraud? So the the this very much this thought process was very much focused not upon face verification which all the rest of the biometrics industry was focused on. We said we'll just buy biometric we'll buy face verification. That's not the point. It was about how do we determine liveness. And we were one of the very first companies in the world to think about to think about liveness as a problem in itself rather than as a a a rather secondary feature of the The biometrics industry. And that was a completely different mindset. In fact, when I went into the into the security industry and the identity industry, I felt like a Martian because I was thinking about this in a completely different way. Now, what was interesting was that at first I thought of this as being a way of authentication. Great, this will replace passwords. In fact, I was terrified we were going to get there too late. In 2012, there was an article in Wired magazine by the associate editor Matt Honan. It's worth looking up on the internet because it was a brilliant article. In which he described how his life had been destroyed by the takeover of his Apple account. And he said, passwords are clearly dead, we've got to get rid of them now. And my goodness, we our technology may not be ready for when passwords get replaced. Ha light idea shame about the decade. what it turned out, and this is another, I think, lesson for entrepreneurs, we thought we were solving the problem of authentic of authentic of login authentication, of password replacement. And we bumped around the industry, kissing frogs, trying out use cases, until we discovered the the problem that we were really solving, which was the r our remote identity proofing. We were going to customers who said, I don't care authentication's not our problem. Now if you could solve the identity the remote identity proofing problem, now that would be really exciting and important. And we kind of bumped into that as an I mean, we'd we'd thought of it right at the beginning, our original patents cover ident remote identity proofing, but we haven't taken it seriously. And then we just so you think you're setting out to solve one problem, but then it turns out that in fact what you're needed for is to solve some completely different problem. And you only discover that by ex by by s by addressing the market and seeing what seeing what sticks. And so we built our entire we built our almost our entire business for about five years on identity proofing, a business that we'd never even thought of. Now authentication is becoming a a very significant part of our business and it's going to become an even more significant part of our business as we launch a suite of iProved powered products into the enterprise market to help CISOs and enterprises secure themselves against a a range of device or knowledge based attacks by introducing reusable biometrics as a as a credential which cannot be which cannot be stolen, sh forged, cannot be stolen, forged or shared.
Joe: Hm. That's interesting because it sounds like it would be pretty useful technology, you know, nowadays, especially with like deepfakes and, you know, all all all this AI stuff going around, right? I mean
Andrew Bud: It it it Joey, it's a godsend. We've been we had been worrying about synthetic imagery since about two thousand and fifteen. In those days, because we'd been thinking about people putting together banks of PS five PS five g PlayStations and networking them together and using them to produce a pixel realistic CGI. Deepfakes, we we were one of the leaders in in deep convert con in in in deep learning networks. We were the first company ever to launch. An online deep learning powered face matching service. Little company of 15 people as we then were at the beginning of 2016. We we were we became global market leaders in face matching technology. So we've been we've been experts at AI and machine learning for many, many years. if you look if I turn my my t my my thick my camera around, you can see an a framed article that dates from 2019 in which I'm talking about the threats from deepfakes to to To to authentication technology. So we've been waiting, we've been waiting and preparing, and we've built our technology and our systems and our processes and our people, specifically na in the last eight, ten years to defend against this this this threat, and no one got it. And suddenly the world understands it, and we're kind of going, thank goodness people aren't blind to this anymore. We we are thank goodness people now understand what we're up against. And we don't have to teach them about it anymore because the threat is real and present. And I mean it's it's extraordinary how the technology has progressed in the last two or three years. About two years ago, in order to produce a deep fake face swap, which is one of the most primitive of all attacks, it's where you use deepfakery to put the face of Tom Cruise over your face or the victim over your face. two years ago it was it was rather obvious, you know, your ears would be upside down or Or you're you're no or you know, you're y there'd be a break in your fake lip or something. and you would require a PhD in computer science and loads of technology to do it, and it was there was real hero stuff. Now you can produce in the now you can produce absolutely flawless, pixel perfect forged imagery using complete kits, big beginner level kits available on the internet from anything between three and a hundred pounds. Our local f we've identified hundreds of these of these kits. And the result is That these attacks have absolutely exploded. We issue an annual threat intelligence report in which we talk about what we see, because we see everything. And the volume of these attacks has just exploded worldwide. Why? Because the technology has moved on so quickly that now these AI attacks are perfect, dead eas dead easy to mount, and ubiquitous and oftentimes very, very poorly defended against. and you know, we're kind of going, it was worth it was worth invest it was worth investing twelve years of effort in order to defend in order to defend society against the point at which finally we've now reached.
Joe: Yeah. Yeah, I mean it it's so easy to to pull off those attacks and it it's funny because when when you were, you know, creating the defense for it, right, like it was such a difficult thing to pull off. You know, I I remember some like news story that you you were probably referencing with Tom Cruise where they like deep faked Tom Cruise's face or something, you know, and made it like fairly fairly like him and you know it it could fool some people but now I I mean like with my computer right here like it could easily deep fake you know me or anyone else with no problem whatsoever you know and like that's the scary part right because I'm on YouTube and like anyone anyone can deep fake my voice, my my likeness, anything like that. And make it seem like I'm saying or doing something that I'm not, which is a huge a huge problem that that we really do have to solve.
Andrew Bud: Jerem.
Joe: you created this technology well ahead of time before it became so readily available, you know, nowadays, right? Where, you know, now anyone with like a cell phone can hook up like a hugging face solution, you know, and start deep faking people and whatnot. Like it's a crazy situation because like I'm on YouTube, you know, and I I run this podcast. Like if anyone wants my voice, like they can just take it. There's nothing I could do about it. Anyone wants my video, like they can just take it, you know? which opens up the world to a whole new level of risk.
Andrew Bud: So there are a number of interesting ideas there actually just to to to to show and unpack. So on the one hand, people say, you know, you can't use a face as a as a you can't use a face as a security credential because if it gets stolen, then you know you can reset a password, but you can't reset a face. and I'm kind of going, guys, you can't steal a face, at least not without extreme violence. You
Joe: Yeah.
Andrew Bud: know, you can't steal a face. You can copy a face, but then The issue is that a f that at least in in in authentication identity proofing, the security of a face doesn't really is not like a password. It's not a shared secret that if it gets somehow revealed, then person that someone has stolen it. It's just not right. The the face is a valuable but is a valuable security credential because the genuine article is unique. So if you can be sure that you're looking at the genuine article, then you've got a very secure item. And it doesn't matter, you know, our faces. Are completely public, exactly as you say. They're completely public. So there's no question of secrecy. They're not passwords. So th but the the the the the integrity of your face comes down therefore as a something that sh people should trust. Comes down to whether you can determine that it's a genuine face or not, and that's our task. Now we don't claim to be able to detect generic deepfakes. We could but a partly because personally I believe it's actually impossible. I don't believe that that's impossible. Some people claim to do it, and it's undoubtedly possible for people for people to detect some deepfakes that have been made in a certain way. But I happen to believe that the general task of detecting whether an image is a deepfake or not will become impossible. So when we determine the genuine presence of the genuine human presence of a face, we have to We have to change the physics of the capture itself. By introducing this flash mark into the very physics of the scene, we are completely changing the problem that AI has to combat. And the thing is, we're a billion data points ahead of any AI hacker, and we'll remain a billion data points ahead of them. So by by changing the physics, we create a non standard problem, which can be easily faked badly, but is extremely difficult. to fake well. And by doing that, and only by doing that, only by creating a not an unpredictable, ever-changing perturbation into the physics of the image capture itself, do we stand the chance of determining whether we're looking at a at a at a deepfake. Generic general purpose deepfakes, I think, will be undetectable. And in fact, the way we think about defending against against deepfake content is actually to s is actually to say, look, What we're going to trust is not the evidence of our own eyes by looking at the content, but the who is the author, who is the originator, who takes responsibility for this imagery? Because then if you know unequivocally the identity of the real human being who takes responsibility for this, perhaps because they were a photographer, perhaps because they were the publisher, but someone says, I am accountable for this imagery, and I say this is real. Or I admit that this is this has been deep faked, but that's okay. Then you have some chance of of maintaining social order in a context in which, I mean, today already, let's be clear, you can't always trust the image the evidence of your own eyes. The front page of Vogue is not a literal photograph of the model in that. It's been someone has someone very skilled has spent a lot of hours with Photoshop turning it into an idealized image. Avatar was an entire movie made entirely with CGI. And today, large chunks of movies are made with CGI without you even knowing it. So we can't actually believe the evidence of our eyes today already. So but and I think what'll happen is that trust will come down to not, you know, why do I like Avatar? I Avat James Cameron never never suggested that Avatar was real was real life action. He said it's you know, it's a fantasy. I tell I'm telling you, I I'm James Abbott. camera and I'm telling you this is a fantasy. Vogue Vogue know because they've because they know that consumers don't really believe what they see on the front cover of Vogue. So what's gonna the way to defend against deepfakes I think in the in the long term is going to be assuring the ch the identity of the author, of who it is that takes that takes accountability for this. this is going to be a an issue that we see running right the way through. the the the digital economy in future. It's gonna be same with AI agents. You're gonna have A AI agents all over the economy. People are gonna say, to who who is accountable for this AI agent? Who is accountable for what this AI agent does and asks and transacts, which means that the AI agent, just like a piece of content, is going to have to have an unequivocal set of credentials that relate back to somebody who is an who is a an assured, genuine human being. Whose idea human beings are going to end up as the root of as the root certificates for more and more things in in the digital economy, which means the task of assuring that it's a real human being, that that that certificate of genuine humanity will become a root certificate for the for the whole digital economy. It's quite a big vision, isn't it, Joe? But I I I I have no doubt we have this problem of attribution is beginning to appear more and more. We've seen it also in the open source community. People are getting quite worried now about. open source code being being injected into the repos by personal persons unknown, some of whom are not nice, some of whom are lying. So now you so in content, in open source code, with agents, in all cases, a greater understand a social media, you know, there's a I've felt for years that that an anonymity was one of the reasons why why why social media is so toxic, but I think that boat has sailed long ago. In all cases, the ability to attribute to somebody who is a genuine human being, potentially but not necessarily identifiable, I think will make a will make will be will become fundamental.
Joe: Huh. It's interesting the way that you put it, that human beings will have to essentially generate a root certificate of their identity, and then from there everything else is signed with that root cert. which you're you're absolutely right. You know, like trying to and then you'd have to probably store it all on a ledger and everyone can have access to that ledger or something like that.
Andrew Bud: No, you don't it's interesting enough, th this concept was born on ledgers, the ledgers have got nothing to do with anything. You can
Joe: Hmm.
Andrew Bud: carry these certificates around. What's important is your public key. That so you actually distribute this data. So I expect agents, for example, will have personal personal data personal data, personal wallets, which they carry around. And they just hand it out to any they hand out these certificates to anybody who who wants them. What matters is that the public key for those certificates is publicly available. But you don't need a ledger. You just, you know. Sandex five nine i architecture is fine for doing that. I don't think the ledger has a has a particular I don't believe the ledger brings any particular value to this kind of world. And let's be clear, this kind of dis decentralized identity model, which I'm saying is going to have to apply to content, code, and agents, this is already being rolled out, at least in Europe, for citizens. The EU digital identity wallet works exactly that way. And by the end of by by probably the end of twenty twenty seven. four hundred million people will have d EU digital identity wallets filled with credentials that are that that are signed by a by that that are signed and whose public key is on a on on a public on a public keychain.
Joe: Hmm. So how would like the distribution of that work? I mean, are you basically, you know, here in America, right? Like you go to the DMV, you get your ID. I'm imagining it as like they add a little chip into your driver's license that is a PKI, you know, key that like just basically matches up to you and then go from there.
Andrew Bud: I so wish that they had put a key into the into the into the driving license in America. In Europe, all the identity cards now have chips in them and it makes life s a hundred times more secure and and and and easier because you've got trusted imit you've got trusted data. Look, we're starting to see this happen in America. What's gonna happen and and we we we what's happening is that the DMVs are now starting to issue electronic driving licenses. We do this for California. We issue the the calif the digital California driving license into the California wallet. Similarly there are Apple and there are Google and there are Samsung and other wallets around which the DMVs issue these these credentials into. What's important is that people are matched and are genuinely and are genuinely human beings when they are matched, when that driving license is issued to make sure that it's issued into the right person's phone. So now you've got a digital driving license in your Apple wallet, and you can issue you can potentially then issue certificates based upon that into third par into pieces of content or third party applications. So this is coming, just very, very few people have have digital drive digital driving license, mobile driving license, MDLs yet. but I think that's gonna change quite quickly.
Joe: Hmm. Yeah, I know I know in my state they have the digital driver's license and I can't remember there was like some objection to it or some concerns with it and I can't even remember the concerns and so I just like didn't go down that path of of you know putting it into my like iPhone wallet or whatever might be. mostly because like as soon as I Like as soon as I get the an objection like that, like I don't have the brain waves to to focus on it, right? Like I have so much other stuff going on. but
Andrew Bud: I mean, but also the ups also, why would you bother? Because at the moment the the the use the utility of such a mobile driving license is in America is very, very low. Basically, what can you do with it? You can show it at the TSA checkpoint. But you know what? You can show your ordinary driving license at the TSA checkpoint. The real value comes when it starts being when you can start to use it to assert or sign your identity online remotely. That will change everything. And then suddenly you say, Okay, what's the balance of what's the balance of of of of of privacy and security? We're moving into an ex into an increasingly hostile cyber world. You know, today already enterprises enterprises don't get hacked. People hackers don't hack it. Attackers don't hack into enterprises, they log in. Identity is the way that all attacks on enterprises and increasing other organisations take place. So identity becomes the key defensive mechanism. for organizations and ultimately for critical national infrastructure. Well, if you can't defend identity securely, then you become vulnerable to cyber attacks. And I don't know about the United States, but I can tell you that in Europe the it the the the intensity of cyber attacks from hostile state actors has gone through the roof. We are there are people there was a there are people who are saying we are already in the gray area of cyber war now. And the and identity is the key point is the key defense is the key doorway. So, and it will come a point at which people will understand that they can they that there will be a question of whether defending their privacy is more important than defending their identity, their infrastructure, and their life. It's worthwhile going and having a look at that at that Art Wired article from 2012 because there's a full-page photograph of Matt Honan looking absolutely terrified and bewildered by what had happened to him. And so if people need to upload their mobile driving licenses in order to defend themselves against that kind of thing, if they need to do a biometric face matching with flashmark liveness to defend themselves against that against that kind of thing, I think they will, because there are, it gives them agency and it gives them safety against the threats that are. I think only really beginning to emerge now.
Joe: Hmm. Yeah, th that's a good point that you bring up. You know, like we're so c sequestered in America, right? Where like we're so far away from any of our adversaries for the most part. no one else in our hemisphere is even really that much of a threat. I I mean, like, you know, you look at like South America or something, I mean, I I don't I don't consider any other country on our hemisphere to be a threat, right? of any sort. not like an imminent threat. but like in Europe it's a very different mentality. And I've been telling people for a while it's the I I think that the cyber war is already ongoing, right? Like, you know, we're we're really smart people. Like hackers are extremely smart people. You you give us a weekend and we'll test out everything. You know, like we don't have to test out things over a decade. I I think that they're already already going on, right? And one of the things that you never really hear about is any of the cyber any of the cyber capabilities of Europe. You only hear about NSA, you hear about the CIA's group, you hear about you know, Russia and China and Iran's group and Israel's group and North Korea. I've literally never heard anything about any cyber capability within Europe.
Andrew Bud: So GCHQ, which is the British NSA, was the place where Enigma was broken.
Joe: Mm-hmm.
Andrew Bud: And it has, since the Second World War, had an exceptionally close relationship with the NSA, and I think is regarded as being possible one of the world's foremost centers for both cyber cy for cyber warfare and for cyber defense. I learned from GCHQ early in the history of iProof certain key measures that we should take in order to ensure that iProof was s was resiliently secure. You know, they said this is the way you will be attacked. So you need to be ready for a certain for s for for a certain kind of attack. And I took their advice, and that's why we're trusted by nation states, by the by the British, the Americans, the Australians, Singapore and and other other countries other countries as well by by ID me that you'll be familiar with. It's because we had that s kind of advice and support from GCHQ. GCHQ continues to be a globally respected center for cyber what for for cyber defense and cyber security. and in fact only a few days ago the boss of GCHQ said we are being we are subject to attack to to to attack on our critical national infrastructure four times a week from Russia at the moment. Now what they're doing in response I don't know, but they similar to the United States where you have CISA, we have something called the National Cybersecurity Center, which is the public facing commercial facing arm of GCHQ intended to help keep the to intend to intended to help keep British industry and British society say safe by encouraging up adoption of of of good practice measures. So they are urgently saying now you've got to get rid of passwords, you've got to use passkeys in instead. we were fortunate because in twenty seventeen, when NCSC was launched, they also ran a the a comp they also started a competition for emerging cybersecurity companies, and we were the first winner of that, which was Which w which was w which was very nice. But I w s G C HQ is an outstanding organization and is very widely respected, both within the American National Sci national national security agency and other bodies and also within the defense intelligence community in in this country. And I think it is head and shoulders above almost any other friendly nations cyber capabilities, with the exception And this I'm not an expert on, possibly of Israel, which obviously has a different level of resource available.
Joe: Hm. Yeah, it's interesting. I I've never even talked to anyone from UK intelligence, any of the Intel services. It would be really interesting to to have a conversation with someone someday. But
Andrew Bud: I I I'm fortunate to have a conversation every week with one because w since for nine years on my board, I've had a non executive director who we were able to hire immediately that he left the defence and intelligence community as the chairman and CEO of of an organization called Her Majesty's Government Communications Centre, which is it's in the public domain. It's a it's a large centre for research, development and manufacturing of the technology used by the intelligence community. In other words, It's Q's Cave. And which of course and and he he ran that for five years and before that he had a career in in in defence and intelligence. And it's really interesting because I learned an enormous amount from him not just about defence and intelligence but also about how to manage risk and and how to manage people in a highly decentralised, highly capable, highly delegated operating environment. I I I urge I'm urging him to write a book because in reality running a start up and a scale up turns out to to be much more like an intelligence organization than a than an army, which is the other model that people so often use when thinking about management skills. but that's that's the topic for another podcast, I think, Joe.
Joe: Yeah. Yeah. No, we're we're definitely at the time, we're past our time actually, but you know, I've really enjoyed our conversation. I I definitely want to have you back on. I think that we have quite a few other topics that we could be discussing that'd be really fascinating.
Andrew Bud: It would be it would it's been a pleasure chatting to you today, Joe, and it would be a great pleasure to continue the conversation. I hope it's been of interest to your listeners. i each person has their own fund of stories and i all those stories I think always illuminate other people's lives in one way or another. So I hope mine have been of some use.
Joe: Yeah. Yeah. No, I I definitely think so. Well, you know, Andrew, before I let you go, how about you tell my audience where they could find you if they wanted to reach out and connect with you and where they could find your company if they wanted to learn more.
Andrew Bud: So our doorway is www obviously dot iprove and that's spelt ipr. iper douv.com. iproof is an unconventional spelling. And when I set iProve up, as I said, we had no money and I couldn't afford iProve spelt the conventional way, and I'm very glad I couldn't, because it's given us a an individuality. I don't so frankly Welcome direct mails. You can mail me on Andrew dot bud. That's with one D, B U D, Andrew.bud at iprove dot com. we have teams, we have commercial teams in Europe, in North America, in South America, in a a Southeast Asia, in all over Southeast Asia, based out of Singapore. you can reach us in whatever continent you are. We will talk to you in your language, to understanding your problems, understanding your issues, and frankly also if you just want to chat about the issues of biometrics in cybersecurity, the the the centrality of liveness and how that applies to agentic AI. we're trying to solve a set of problems to which, some problems to which nobody yet knows the answer, and we're happy to engage in doing so.
Joe: Awesome. Well, thanks, Andrew. I really appreciate you coming on and everyone listening. You know, I'll put all the links that he mentioned in the description of this episode. Please so, you know, if you want, you know, please go check them out. And yeah, that's all that we have for this episode. Thanks everyone. Hope you enjoyed the recording.