Facebook CTO blasts security industry for focusing on 'stunt hacks'
Alex Stamos' opening keynote at Black Hat skewers security industry


Facebook CTO Alex Stamos has told the security industry it needs to spend more time focusing on real-world problems, rather than worrying about high-concept 'stunt hacks'.
During his opening keynote at the Black Hat security conference in Las Vegas, Stamos pointed out that while complex technical demonstrations of how to bypass security measures are interesting for security professionals, they don't really help anyone.
According to Neowin, he said: "Adversaries will do the simplest thing they need to get the results they want, but we focus on the really sexy difficult problems. It's cool to see someone bypass a hard problem, but that's not something you'll probably see in the real world."
In a similar vein, he noted that while data breaches, hacks and vulnerabilities are all front-page news, no-one takes the time to celebrate when companies successfully repel an attack. Facebook has set aside a $1 million fund, which will be awarded to this year's best USENIX paper on defense research.
He also claimed that the security industry has a tendency to focus on the mechanics of cyber security, such as patching and zero days, while ignoring less technical but more harmful behaviour like spam, doxxing and social media abuse.
Stamos skewered attendees, saying that the security industry lacks empathy with users and blames them when its own unreasonable expectations aren't met.
He called out common industry expressions and attitudes like "PEBKAC: Problem Exists Between Keyboard And Chair", which occupies a similar space to the ID10T error, as being counterproductive and argued that security professionals shouldn't expect users to automatically follow security best practises if they don't have the technical expertise to know better.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The pessimism that's often common among cyber security professionals was also raised, which Stamos dubbed "Security nihilism". This concept, he said, "is an overlapping set of beliefs that include the assumption that all attackers are perfect, that everybody faces the worst possible threat scenario or that any compromise to make a security feature more widespread should be considered a bug."
Stamos also echoed the concerns of many within the industry about the growing skills gap. "Things are not getting better, they are getting worse," he said, according to the BBC. "That's because we do not have enough people and not the right people to make the difference."
Stamos' keynote can be watched in full here.
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Meta to pay $725 million in Cambridge Analytica lawsuit settlement
News The settlement closes the long-running lawsuit into how Facebook's owner, Meta, handled the Cambridge Analytica scandal
By Ross Kelly Published
-
Meta's earnings are 'cause for concern' and 2023 looks even bleaker
Analysis Calls for investor faith in metaverse tech only emphasise the worries that its investment strategy won't pay off
By Rory Bathgate Published
-
Microsoft and Meta announce integration deal between Teams and Workplace
News Features from both business collaboration platforms will be available to users without having to switch apps
By Connor Jones Published
-
Facebook is shutting down its controversial facial recognition system
News The move will see more than a billion facial templates removed from Facebook's records amid a push for more private applications of the technology
By Connor Jones Published
-
'Changing name to Meat': Industry reacts to Facebook's Meta rebrand
News The rebrand attempts to provide a clearer distinction between Facebook and its umbrella company
By Connor Jones Published
-
Facebook's Oversight Board demands more transparency
News Board bashed the social media giant for its preferential treatment of certain high-profile accounts
By Danny Bradbury Published
-
Facebook claims AI managed to reduce hate speech by 50%
News The social media platform has hit back at claims the tech it uses to fight hate speech is inadequate
By Sabina Weston Published
-
Facebook to hire 10,000 workers across the EU
News The high-skilled jobs drive is a “vote of confidence” in the European tech industry
By Jane McCallion Published