96. They Don't Need to Hack You Now. They Just Need to Wait. (with Kevin Kane)

In this episode…

In this repeat appearance, Kevin Kane, co-founder and CEO of American Binary, explains why the encrypted data organizations send today is already at risk: an adversary can capture it now and decrypt it later once quantum computers mature — the threat behind the episode's title. He describes American Binary's work on a new post-quantum key exchange that has completed private peer review and formal verification, the recent addition of Diffie-Hellman co-inventor Whitfield Diffie to the company's advisory board, and the push toward quantum-era VPN, protocol, and zero-trust security. The conversation then turns personal, with Kane sharing hard-won lessons on building deep technology: why it takes decades of accumulated knowledge, why timing matters more than thesis, and why founders shouldn't postpone happiness until after the win.

Key takeaways:

  • "Harvest now, decrypt later" is the core quantum risk: encrypted traffic captured today can be stored and broken once quantum computers arrive, so any data with a long shelf life is already exposed.

  • The Diffie-Hellman key exchange protects nearly all encrypted internet traffic — every email, message, and secure connection — which makes its eventual quantum vulnerability a systemic problem, not an edge case.

  • American Binary says its new post-quantum key exchange and authentication have completed private peer review and formal verification by cryptographers Dr. Thomas Shrimpton and Dr. Joseph Kiniry (of Galois), using verification tools that did not exist two years ago.

  • Whitfield Diffie, co-inventor of the Diffie-Hellman key exchange, recently joined American Binary's advisory board.

  • Kane frames post-quantum migration as a timing problem: the market was not ready two years ago and is only arriving now, but deep-tech founders who start too late cannot catch up.

  • Building genuine deep technology takes roughly 20 years of cumulative knowledge — "you can't wing it on a weekend" — and much of the work is discovering what is actually breaking in novel systems once they run in the real world.

  • On the founder mindset, Kane urges leaders to hold high internal standards, speak with earned authority, and integrate happiness and relationships into the work now rather than deferring them until after success.

Before we jump in, a quick note of who's behind this podcast. Imagine this. You're about to close this massive deal. You've been grinding for it.

You're pumped. And then your customer's legal team decides to make things interesting. What happens if you get hacked? How do you protect your data?

And then your brain just goes blank. That's the nightmare founders deal with all the time. That's actually what YSecurity solves, the sponsor of today's show. There are 40-plus security engineers who've actually done security at Apple, Uber, Microsoft, Robinhood, Brex, and so many more.

And get this, you don't hire them. You rent them. By the hour. No massive salaries.

No expensive consultants. Just real experts embedded in your company, helping you get SOC 2, ISO, HIPAA, whatever it is that you need to close that big deal. Set a monthly cap, know exactly what you're spending, and close the deal. Head to YSecurity.io and book your free strategy call.

Your first eight hours are free. 40 engineers, one full working day, totally free. Go take it. YSecurity.io slash startups.

Hello, everyone, and welcome to another episode of the Security Podcast of Silicon Valley. I'm your host, Jon McLachlan, and we have just an awesome, spectacular, amazing repeat guest. Back on the show, Kevin Cain, co-founder and CEO of American Binary. Thank you for having me, John, on your show.

It's always an honor to talk with you and to be a part of anything that you're doing. I don't know. No, you're too kind. You're too kind.

The honor and the pleasure is all mine. I'm sure all of our listeners are dying to hear all of the stuff that you've been through in the past two years or so. Where's American Binary and what's going on with Kevin? Well, a lot has happened in the last several years.

I co-founded American Binary. It's a network security company focused on post-quantum encryption. One of the things that's unique about our company in the world is that Internet security is generally guarded by encryption for everyone. And there is a particular key exchange called the Diffie-Hellman key exchange, and it guides everything on the Internet.

Every email, every WhatsApp message, every VTC connection that's encrypted uses this key exchange. A key exchange is I'm going to send you encrypted some secret information, and I'm going to send you over a key that you can then use to receive the secret information that's about to come. And that key exchange that dominates everything on the Internet is called the Diffie-Hellman key exchange, invented by Whitfield Diffie and Martin Hellman. Whitfield Diffie joined our advisory board last week.

And one of the things that's unique about our company is we developed a new key exchange that is not theoretical and in the lab, but has completed private peer review and formal verification from two DARPA performers and cryptographers for the U.S. community. And they are really famous people. One is Dr.

Thomas Shrimpton, who is a founder of real-world crypto under the IACR, the International Association of Cryptological Research. That's like the Alan Turing-level smart people who develop encryption for governments and for world Internet security. And then the other one is Dr. Joe Kinnery.

So both of them who were also at Galois, a famous engineering firm that does contracts with DARPA and so on, they did the review. And after six months of review and using some modern tools that were not available two years ago to do this kind of review, we completed a total review of our security claims that are novel. And these security claims include a post-quantum encrypted key exchange, post-quantum encrypted authentication, and then meeting NSA standards for national security networks in a world of quantum computing, which is the latest standard that we're not aware of one company meeting that standard. And if they have it, have not, we're not aware of it.

And if they have, they're definitely not in software, and they're definitely not operating over mobile networks, which are more and more some of the sexy technical claims that my company has positioned itself for. We believe our solution, our VPN and our protocol, and we'll be in zero trust by the end of the year, is the future of Internet security, especially as we go into a quantum era. And as we go into more details, I can tell you more and more and more about that. So much has happened since the last time we spoke.

Well, that's so exciting. That's incredible. You've got these amazing minds that have joined your advisory board. You've met a very rigorous standard for a new type of cryptography that's actually quantum resistant.

That's like an 11 out of 10 on the cool scale. And not to mention, as soon as these quantum computers become cheap, become readily available, can fit in your pocket, it's going to really change the game for how we think about security. Because all of the traditional algorithms are just going to go out the window, right? So, I mean, speaking of how the world is changing, of all of the new advent of AI and AI coding assistants and agentic SDLC processes and all of this stuff, you got a favorite one?

Do you use it in American Binary? We actually have very tight rules on LLM. That's good. That's good.

Make your SOC 2 and all your certifications easier. On a personal level, for personal things, I think they are very fun. One of my latest gripes is I noticed that one of the LLMs, I don't want to get in trouble, started being more factual and less inference-based. And I was like, no, stop, go back.

I don't want cliff notes for the world. I want unexplored latent space. I want high inference that might be wrong. I can do the rest without you.

I don't need you to tell me what I already know. I want you to tell me things that I haven't thought of that might be dangerous to believe, but I want to see anyway. To be honest about that with myself, and then to not allow ourselves to fall short of maybe being the person we want to be seen as. And so that means having a high internal standard and not breaking that internal standard, no matter how much it hurts ourselves.

Yeah. Wow. I mean, like, okay, so being a founder, building new things, doing the zero to one thing, that's extremely difficult in and of itself. But, you know, when you operate within like a set boundaries, these like very high expectations for oneself, do you find that that helps as a founder?

Does that actually make things easier? It's probably harder, isn't it? Having a higher expectation? Yeah.

Yes, it results in long periods of being misunderstood because, you know, there are two things that people often misunderstand from an investor perspective. Following the crowd and trend following are not the same thing, right? So when we follow the crowd, we get crap. That's going to be the outcome, right, is nothing better than the market.

Trend following is supposed to be reserved for following the trend of people whose track records are consistently beating the market, which means you got to be there at the time of trade. You got to be there on the trade with them at that moment. And if you're not in that deal and you're not in that moment with that trade, then you're just speaking thesis garbage, right, about trend following this and following. But if you're not there at the trade, it didn't matter.

If you're not there at the seeding of Facebook, you know, you can say you're following how the thesis or whatever. Theses are meaningless if your trades aren't executing exactly where they need to be. And so the crowd is going to have a bunch of theses they're going to follow. But unless you have the secret sauce to be there at the trade, it's just garbage.

Yeah, I love that. I hear you. It's almost like that saying that timing is everything. It is.

Timing is everything. I've seen it. You know, when we started this company, the time was not here and it wasn't here two years ago. And it's starting to come here now, but two years later, it's going to super be here.

And four years later, super be here. But, you know, if you wait too late to start, you're not going to catch up because tech nowadays, especially in our area, it's to the point where you need 20 years of cumulative knowledge to do something like we're doing. You can't wing it on a weekend or at a meetup with some friends and hack this. It took us years of finding out what was wrong with our systems when they weren't working in the real world two years ago.

And we learned that we were having a problem handshaking, which led us to developing a lot of solutions around our key exchange. But we didn't know that that was the issue. There's such a long road on learning what's going wrong with software that is new, doesn't exist in the wild, except for what you built, and then putting it in a complex system. You know, it could have been any infinite number of problems that was causing it failure.

What's been the proudest moment that you've had since the last time we talked? I think the proudest moment since the last time we talked, for me, being able to speak truth to power without being afraid of how it will be received by people who disagree with it because I have such a foundation that it's not on thin air. You know, it's not on read things. So nowadays, we challenge directly some of the world's most famous cryptographers and leaders from institutions around the world to look at problems in a way that they might not have.

And to be able to speak with that authority, which was earned, is an incredible thing. It's like the three little pigs, right? So we built a brick house and we didn't build a hay house. And the

I'll accept this problem, and I'm not going to face this problem under the cover of an institution. I'm going to face it myself so that the accountability matches the seriousness. And that is how we behave in our company. And as we scale, I'm going to insist that on people.

It's going to filter a lot of people out. That's fine. They don't have to work here. You know, they don't need a purpose on our cost, on our back in life.

They can find that somewhere else. I'm super curious. If you could go back in time and meet your younger self, would you take that opportunity? And what advice would you share with your younger self?

The most, the biggest piece of advice, the one I struggle with the most is people are complicated. And you can have righteous standards for yourself, but be careful of judging other people in front of you for that, because that person might not meet your standard, but can help you in other ways. You know, look for the silver lining in all kinds of people and don't be so quick to kick someone out of, maybe guard yourself against them, but write them off is not useful because they don't meet your standard. So that's something I've learned is that help comes from people sometimes you don't even like.

That's very humbling, right? Because then we're looking into ourself and saying, you know, maybe I'm a little over indexing on this thing I don't like too much. Maybe it's not that much of a threat to me, this character trait or that thing. And for asking for forgiveness, man, I mean, I've grown so much.

And everyone who I have heard, I wish one day they would forgive me, but it doesn't always work like that, right? And even if you are forgiven, the damage is such that you can't be healed. So that's sort of sucks about the journey. You know, not everyone you start with is the person you're going to finish with.

Yeah, no, that's really deep. I really appreciate that. It's... It's humbling.

It's true, too. And you just never know. I've noticed like as a founder myself, you kind of have to get used to being... What's a good word?

Like unsatisfied? Yeah, I mean... There's always something. There's always like more.

There's always like the next piece. There's always the drive or the fire. As a friend of mine put it, what sharpens my senses on those introspective things is that, like think of it like a role-playing game. At my age of 46, I only have a few turns left in the game, and it's over.

And that means your senses then make room for things other than your work. You know, so you have your mission and vision, but is it really worthwhile to live just for that? I don't think it is, actually. And I think that that's a terrible way to live your life is to live for mission and vision.

I'm obsessed on it, but I'm not going to live for that. I live for people I enjoy being around. And if I don't enjoy being around them, I'm going to tell them that I would like... I'd like growth, right?

And I'll grow so that we can be working hard and enjoying each other. Because I don't live long enough for anything else. And I'm not going to wait five years to be happy. I'm going to be happy today.

Integrated into my work. And one of the lessons I would tell 10 years ago to myself is don't postpone happiness. Integrate it into your work now. And if the people around you are not capable of it, demand they grow or find other people.

Don't sacrifice yourself for people who can't match your happiness. That's a colder thing I have to say. Some people will disagree. That's fine.

I mean, when I was young, I worked so hard. And I thought I'm going to come back and show my parents. And they were both dead before I got there. So I always tell younger people, don't count on that.

Don't count on being successful and then coming back and showing people. Either they're going to be dead by the time you get back, or they'll have so moved on, they're not recognizable anymore. So you can't live for that. You've got to integrate in the present piece.

And you've got to integrate them in the present. And you can't, you know, sequence things. You've got to do everything. You've got to do the love part.

You've got to do the relationship part now. You need not wait for it. You have to do it. That's so true.

Well, thank you so much. Kevin Kane, the co-founder and CEO of American Binary. Thanks. No, huge thank you.

Really impactful shares. Huge thank you. Huge thank you. Thank you, John.

Take care. And huge thank you to all of our listeners for tuning in to another episode of the Security Podcast of Silicon Valley. I'm your host, Jon McLachlan, and this has been a Why Security production. One last thing before you go.

Think about who you were 20 minutes ago. Maybe security's been that thing that's on your roadmap, that thing that you'll get to right after the next sprint, the thing that you'll get to after the raise, or after something. But here's the truth. SOC 2 and ISO, these things are not just checkbox.

They're keys. It unlocks enterprise deals. It opens up regulated industries. It's the difference between selling to a 10-person startup and closing Fortune 500s.

That's where Why Security comes in. We don't just advise. We build. SOC 2, ISO, done right the first time.

40-plus engineers from Apple, Uber, Microsoft, Robinhood, Brex. This is not guesswork for us. This is all we do. And maybe you're not the one who needs this, but you know a founder who does, the one trying to break into bigger markets, the one doing the zero-to-one thing.

Send them our way. We have an awesome referral program. We pay for introductions that turn into partnerships. So head to whysecurity.io slash startups.

The first eight hours are free. 40 engineers, one full working day entirely on us. Why Security has your back. See you in the next episode.

This episode covered SOC 2.

YSecurity helps teams get audit-ready without slowing the roadmap, from first scoping call to clean opinion.

Talk to YSecurity