Note Wisdom
Notes from a Stanford CS153 guest talk in which a former Uber and Facebook security leader walks through the 2016 breach that became his own federal criminal case, then uses it to argue that transparency and personal resilience matter more than any control.
Institution: Stanford
Original Course: Stanford CS153 Frontier Systems: The Road Ahead — Resilience Required
Instructor Bio: This session is co-taught by **Anjney Midha** and **Michael Abbott**, co-founders of AMP PBC and co-instructors of Stanford CS 153: Frontier Systems. Anjney Midha is a Stanford alumnus who previously served as a partner at Andreessen Horowitz (a16z) and held early leadership roles at Discord. He specializes in frontier AI ecosystem development and AI-native company building. Michael Abbott brings decades of engineering leadership experience from General Motors, Apple, Twitter, and Microsoft, where he oversaw global-scale cloud infrastructure and consumer platforms serving hundreds of millions of users. His expertise spans scalable system design, operational discipline, and infrastructure engineering.
Course Description: This session addresses the critical challenge of resilience as AI systems grow in scale, complexity, and strategic importance. It covers technical and operational resilience across every layer of the AI stack — from energy infrastructure and data center reliability to model robustness, supply chain security, and systemic risk mitigation. It discusses why resilience engineering will be one of the most important and undervalued disciplines for the next decade of AI development, and outlines principles for building systems that remain stable and secure under stress.
These are my notes from a guest talk in Stanford's CS153 series, reconstructed from a recording rather than copied from anything official — so if a phrasing sounds odd, that's me, not the lecturer. The session is billed around frontier systems, but the actual spine of the hour is a much more personal argument: in 2026 the scarce resource in technology leadership isn't a new control or a cleverer model, it's resilience — the capacity to take a public hit and keep functioning. What makes the talk land is that he isn't offering this as theory. He walks the room through his own federal criminal case, including the parts that went badly for him, and then uses it as the load-bearing example for a set of claims about disclosure, crisis communication, and why security leaders should spend most of their time with executives rather than engineers.
The opening stretch is autobiography, and it's worth sitting with because the whole argument later rests on his credibility rather than on data.
He joined the Department of Justice straight out of school and landed in San Francisco in 1995. The detail that opens the talk is almost comic now: he asked for a direct internet connection at his desk and was told absolutely not, the network was never going to touch the internet. He kept asking, eventually got a standalone machine, and became the only person in the office with a live connection — the de facto gatekeeper to the outside world. If you want a one-line illustration of how fast the ground moved under institutions, that's it.
As a federal prosecutor in Northern California he used to visit technology companies and ask to hear about their cybercrime so he could prosecute it. Every one of them said they had none. His explanation is blunt: there was no upside to telling anyone. Disclosure is bad for the brand and bad for the business. The trust had to be built first — companies only started sharing once they believed he would quietly pursue cases rather than generate negative press.
The story he tells to make this concrete isn't a cyber case at all. A Stanford JD/MBA who ran business development at Cisco apparently felt under-recognized, so he set up a shell entity styled as a Bahamas subsidiary and, as acquisitions were sliced up, routed roughly half of each stock allocation to himself. He prosecuted him. His own aside is that it wasn't really cybercrime — but it was the kind of case you only get access to when a company trusts you enough to tell you what's actually wrong.
Then the pivot to industry. At eBay, the core problem was trust in the plainest sense: before digital payments took hold, the model was win the auction, put cash in an envelope, mail it, and hope the seller ships. He visited 46 of the 50 states to work with regulators and trained law enforcement in about a dozen countries on how to prosecute fraud on the platform. He was, in his framing, dragging government attention toward the internet in its early days.
Facebook in 2008 was smaller than MySpace, scattered through old law-firm offices in downtown Palo Alto. He inherited three engineers and scaled the security organization; later he was the person who managed the company's NSA relationship, which is how he ended up in the middle of the Snowden fallout. His commentary there is a hedge — that the public version of that story wasn't the full story. He doesn't expand on the gap, which is a recurring pattern in this talk.
By 2015 he was Uber's first security chief, and the running joke is that the pattern repeated: three engineers at Facebook, three at Uber, three at Cloudflare in 2018, each scaled into something much larger. Roughly forty people followed him from Facebook to Uber, substantial enough that Meta's general counsel sent him the customary warning letter.
The framing he puts on all of it is a two-phase history. Phase one was the web and e-commerce. Phase two was mobile, and the line he uses is that Uber couldn't have existed before the iPhone (7:17). Once technology became the most important thing in the economy, government started showing up — he names Obama visiting Facebook, and Bush and Gore as well.
This is the centre of the talk and where he spends the most time.
He goes straight at the responsible-disclosure backstory. At PayPal in 2007 the company published what he describes as the first formal policy of its kind: tell us about a vulnerability, we won't sue, we won't call law enforcement. He carried that to Facebook and published a version there shortly after arriving. A couple of years later the researcher community pushed back — nice that you won't prosecute us, but why not pay? His honest admission is that his first reaction was hostile. As a former prosecutor, being told to pay someone who had broken into your system triggered exactly the wrong instincts, and he had to be argued around by his own team. Facebook then launched one of the earliest bug bounty programs. He notes how normalized this has become, pointing out that Google now pays out millions and recently advertised a single-vulnerability award of $250,000.
Uber published a disclosure policy in 2015 and ran a bounty program privately for about a year before opening it publicly in spring 2016. In the fall of that year came the email: someone claiming a major vulnerability and a database dump. It went to the product security team that ran the program. The actual flaw was an AWS misconfiguration sitting in front of legacy databases that his team didn't know existed, because those stores had been deprecated before anyone currently employed had arrived.
He's emphatic that they handled it as a formal incident. Centralized tracker, documented notes, everything. The CEO signed off on paying the researchers $100,000. Three lawyers were in the loop, along with communications. Legal's position was that there was no obligation to report. Comms had drafted disclosure material and set it aside.
The part he clearly regards as good work is what happened next: he wanted to know who these people were and whether the data was actually gone. Two individuals, nineteen in Florida and twenty near Toronto, who had met in a gaming community and had been probing several companies in the same sector (21:44). They had contacted around five. LinkedIn went to the FBI; Uber paid. The FBI couldn't locate them. His team did, and he sent a retired CIA interrogation instructor — someone who trains interrogators — to interview the Florida one. The email went to the researcher's real address rather than the anonymous one he'd been using, which is a fairly stark way to open a conversation. The outcome was a multi-page psychological assessment plus verification that the copied data had been destroyed.
Then 2020. He was not arrested, though an FBI press statement read as though he had been — his daughter heard it on NPR while moving into her dorm at UT Austin and called him in a panic while he sat at his desk in Palo Alto on a Zoom. The charges were obstruction of justice and misprision of a felony. His summary: he was personally answerable for the company's failure to be candid with an agency that was already investigating them.
At trial in September 2022, the most striking piece of evidence he describes comes from Uber's own head of privacy and regulatory legal, who testified that her team owned government notification, that she personally knew about the incident, and that they had not told the investigating agency. She was a witness. He was the defendant, masked through COVID, so the jury never saw his face.
The hinge is a jury question about the computer fraud statute, 18 USC 1030 and whether authorization can be granted after the fact (25:08). Every lawyer he'd worked with had treated it like trespass: someone steps into your yard, you say come on in, and legally it stops being trespass. The judge wasn't convinced, the government argued against it, and the instruction that came back — that Uber could not grant retroactive permission — removed the foundation of the defense. He was convicted in October 2022.
The contrast case is Cloudflare, and it's told through one anecdote. First incident there, on a Friday night, he calls the CEO, who responds by asking "Who's writing the blog post?" Not what's broken, not who's on it — who is documenting this publicly. Five minutes later the CTO is on the call, assigned to write it.
A year later a rule pushed to their web application firewall from the London office took a large chunk of the internet offline. Most of the United States was asleep. They called every major customer and published a detailed writeup. A day later the coverage was praising the transparency rather than attacking the outage.
His generalization is that organizations should bias toward openness the way Cloudflare does, and that the alternative — the 2016 choice — produces negativity that keeps boiling. Pressed on what he'd have done differently, his answer is that operationally he'd change nothing: paying the researchers was right, fixing the flaw was right, involving legal was right. What he wanted was more documentation.
The practical mechanism matters more than the principle. His point is that during an incident the security leader has no standing to decide disclosure unilaterally. Legal determines what can be said, communications shapes it, the CEO signs. If you haven't worked that out beforehand, you will not win the argument in the moment. He's an advisor to a startup building tooling to force those functions together, and he joined before they raised seed money, which tells you how strongly he holds the view.
The same theme shows up in how he mentors. He asks new security executives to describe their team, and they talk about detection and application security. No, he says — the other executives are your team. A coach at Facebook told him to spend half his time outside his own function, and he thinks security leaders need to exceed that, because the domain is poorly measured, poorly understood, and mostly surfaces bad news. That pre-built trust is what gets spent during a crisis.
After the conviction, the doors that had opened in 2018 stayed shut. Nonprofits that had previously wanted his involvement couldn't be associated with him.
The Ukrainians could. He'd been helping through his Cloudflare role, and by his own telling they were the only people willing to work with him in late 2022 — partly, he says, because they had nothing to lose and no interest in his case. He became CEO of a nonprofit supporting children affected by the war and started a program built on an observation about every tech company: there's a pile of laptops behind the help desk, because you hire aggressively, half the cohort doesn't last two years, and you don't hand used machines to the next hire. A CISO friend gave him twenty wiped laptops, which he carried onto a plane himself. He's shipped thousands since and has developed strong views about lithium-ion shipping rules.
Distribution runs through military units, so surviving soldiers can hand machines to the children of comrades who didn't come back. A bank donated over a thousand units recently; he'd been in country two weeks before the talk, six trips in three years.
Meanwhile the sentencing process was running. The pre-sentence report ran to roughly seventy-five pages and documented seventeen separate volunteer engagements with the federal government since he'd left it. Probation recommended no prison time. Prosecutors came down from an initial demand of three years to eighteen months. More than two hundred letters arrived, several signed collectively by sixty, fifty, forty people in the security community. He describes the experience as attending his own wake while still alive — and what stayed with him was that people wrote about small things he'd forgotten entirely, like a lunch with a team member's kid who was curious about security.
At sentencing in May 2023 the judge said the word he'd been waiting for: it wasn't a cover-up. He then asked why, if the government wanted to charge a company, it wouldn't charge the CEO who was in the loop and endorsed the decisions. He noted the absence of financial motive. The sentence was probation and a fine.
Rebuilding the reputation took a specific form. He'd been unable to speak for seven years. His first public account came through an arrangement with the founder of DEF CON and Black Hat: an off-the-record talk at the Black Hat CISO summit in exchange for an on-the-record talk at DEF CON. He was genuinely afraid of being booed — a friend had asked him directly what he'd do if the room turned on him. He got a standing ovation from peers instead. He also notes, without complaint, that large companies generally can't be publicly associated with a felon, so some of his work happens under NDA; startups don't care.
The resilience claim follows from all of it. Boxers enter the ring knowing they'll be hit and prepare anyway. Job descriptions in 2026 don't list resilience or crisis management, but the roles are highly visible and the pressure is constant. He points to several people who were knocked down at what felt like their peak and went far higher afterward, and his advice to the room is to run toward the stressful assignments rather than around them, because the judgment that gets you into interesting rooms is manufactured by going through bad ones.
The Q&A covers a lot of ground quickly, and it's where the talk is most useful and least careful.
On AI-generated code, he's on the board of an operational security company and sees wildly uneven adoption: financial services slow, others deep in. One small bank went from about 250,000 lines of code a month to 1.25 million within roughly two months. The subtler problems are organizational — a marketing employee merging vulnerable code to production, where security's usual move of sending a proposed fix to an engineer who understands the surrounding context simply doesn't apply. Non-technical staff using agent tooling will also do things no engineer would, like provisioning their own external servers to obtain an API key. His conclusion is that static permissions can't solve this, because you cannot grant access to a mailbox for one purpose and not another. Agents are toddlers in a house: you can put up gates, but you need runtime anomaly detection. Some firms let everyone loose and clean up after; the ones he respects pilot with engineers and widen slowly.
On quantum, he's calm. Timelines compressed for AI, so 2030 is plausible, but the migration work belongs mostly to the hyperscalers. The real near-term exposure is traffic that states have already vacuumed up and may decrypt later. He expects uneven adoption because the hardware is physically demanding, and he hopes the good actors get there first.
On Anthropic's cyber-focused model, he thinks the company handled the launch well from a reputational standpoint and dismisses much of the community skepticism as tribal. One of his portfolio companies had day-one access and found real value — but with the caveat that pointing a model at your infrastructure does nothing unless you've built the surrounding harness, and that existing public models with a good harness find much of the same material. He isn't critical of the approach, while noting they disclosed eight recipient companies in a way that looks like deliberate winner-picking, and gave access to more organizations than they named. His verdict is that the industry is walking, not running, toward a real release playbook.
On regulation he's neither libertarian nor naive. Public policy teams exist to stop regulation, and bad regulation does obstruct innovation — but at scale, companies built to make money won't protect everyone who touches the product. He cites dissident groups in repressive countries who could only coordinate through Facebook and wanted safety features the business had no incentive to build, and his own daughter telling him he should have regulated social media harder. His counterweight is competence: he praises the official now negotiating with Anthropic on behalf of the Department of War precisely because he came out of Silicon Valley.
The physical-risk section is the most unsettling. The startups he advises worry most about intellectual property theft, and you cannot fully vet employees — you can't know whose relatives are being held by a foreign government. He's seen staff pressured during trips home, and employees arrested abroad as leverage. Crypto executives have had hands severed; some vault keys require two people's fingerprints, so attackers collect fingerprints. Executive protection demand is climbing. He mentions the Sam Altman incident and an Adobe co-founder kidnapped in the East Bay two decades ago.
On ransomware, his history is that it began as state-sponsored destruction rather than extortion — Aramco and Sands taken out by Iran, Sony by North Korea, with his Facebook team doing the attribution work around 2012 or 2013 and handing it to the FBI. It migrated into the private sector and now supports an entire service economy, including negotiators kept on retainer as standard practice. His indictment is that governments were late: Colonial Pipeline was the moment ordinary Americans felt a cyberattack, and UK bailouts plus hospital outages finally moved policy. Structurally, law enforcement arrests after the fact rather than preventing, and cyber never reaches the top of diplomatic agendas dominated by Ukraine or Taiwan. Proposals to let companies go on the offensive he calls frightening and interesting at once.
Three places I'd push back. First, the resilience argument rests on survivorship: the examples are people who got knocked down and came back higher, which tells you nothing about the distribution of outcomes. Second, there's an unresolved tension between the transparency doctrine and some of his own conduct as described — working for large clients under NDA, and treating Anthropic's undisclosed access list as merely awkward rather than as the same failure mode he criticizes in others. Third, the legal core never fully clarified for me. He says the retroactive-authorization instruction gutted the defense, but I came away without a clear account of what the obstruction theory actually required, or why personal liability attached to him rather than to the people who made the disclosure call. That section would have benefited from ten minutes more and a concrete example. Several numbers also arrive without sourcing — the Jaguar Land Rover shutdown length, the UK bailout size, the code-volume figures — which is fine as anecdote and not fine as evidence.
None of that undoes the talk. The durable takeaway is that resilience isn't a personality trait he's recommending, it's a preparation problem: decide who speaks, document everything, build trust with peers before you need it, and accept that the hit is coming.
Content Disclaimer:
This article is for general reference only and does not constitute professional R&D guidance, production process advice or quality certification. All material performance data has specific test premises; readers should verify parameters against actual equipment and working conditions.
All contents below are exclusive to the paid Word file, NOT available on this web page

