Security, Resilience, and the Future of Mobile Infrastructure
Episode
41 min
Read time
2 min
Topics
Health & Wellness, Investing, Startups
AI-Generated Summary
Key Takeaways
- ✓Clean-install security architecture: Rather than auditing compromised telecom infrastructure for embedded threats — a process with no clear endpoint — Cape's approach assumes all physical infrastructure is hostile and builds encrypted traversal on top of it. This "clean install" model was validated on Guam before Salt Typhoon became public, and now underpins military exercises in Japan with Rakuten.
- ✓Lawful intercept vulnerability: Every US telecom outsources wiretap compliance (required under CALEA) to a small number of third-party vendors. Cape's SRE team discovered one top vendor shipped an installer containing an unencrypted text file with usernames and passwords for every client — exposing the exact attack vector China exploited in Salt Typhoon three months later.
- ✓World Class Alignment Metrics (WAMs): Before executing any government pilot, Cape and the Navy iterated extensively on specific, measurable success criteria. This upfront alignment — not contract size or timeline — was the mechanism that allowed the Guam pilot to finish ahead of schedule, under budget, and produce an unclassified, shareable 50-page third-party technical evaluation usable across services and with investors.
- ✓Wildcat pilot scaling: The Navy's CTO office shifted from two pilots per year to a target of 25 by forcing program managers and contracting officers through a boot camp on commercial acquisition. The key lever was running side-by-side comparisons (A/B pilots) so that when a crisis like Salt Typhoon emerged, validated technology was already staged and ready to scale rather than starting from zero.
- ✓Defense startup entry strategy: Founders without a specific idea should physically go where military personnel work — ships in San Diego or Norfolk, hackathons, structured challenges now codified in the Defense Authorization Act — and rank problems by pain severity. The Navy prioritizes solutions that replace five legacy systems with one, actively seeking vendors who will decommission old systems as a condition of adoption.
What It Covers
Navy CTO Justin Finelli and Cape CEO John Doyle discuss how China's Salt Typhoon operation fully compromised every major US cellular carrier, how Cape built a secure mobile network that operates on top of hostile physical infrastructure, and how the Navy is accelerating commercial technology adoption through structured pilots and defined success metrics.
Key Questions Answered
- •Clean-install security architecture: Rather than auditing compromised telecom infrastructure for embedded threats — a process with no clear endpoint — Cape's approach assumes all physical infrastructure is hostile and builds encrypted traversal on top of it. This "clean install" model was validated on Guam before Salt Typhoon became public, and now underpins military exercises in Japan with Rakuten.
- •Lawful intercept vulnerability: Every US telecom outsources wiretap compliance (required under CALEA) to a small number of third-party vendors. Cape's SRE team discovered one top vendor shipped an installer containing an unencrypted text file with usernames and passwords for every client — exposing the exact attack vector China exploited in Salt Typhoon three months later.
- •World Class Alignment Metrics (WAMs): Before executing any government pilot, Cape and the Navy iterated extensively on specific, measurable success criteria. This upfront alignment — not contract size or timeline — was the mechanism that allowed the Guam pilot to finish ahead of schedule, under budget, and produce an unclassified, shareable 50-page third-party technical evaluation usable across services and with investors.
- •Wildcat pilot scaling: The Navy's CTO office shifted from two pilots per year to a target of 25 by forcing program managers and contracting officers through a boot camp on commercial acquisition. The key lever was running side-by-side comparisons (A/B pilots) so that when a crisis like Salt Typhoon emerged, validated technology was already staged and ready to scale rather than starting from zero.
- •Defense startup entry strategy: Founders without a specific idea should physically go where military personnel work — ships in San Diego or Norfolk, hackathons, structured challenges now codified in the Defense Authorization Act — and rank problems by pain severity. The Navy prioritizes solutions that replace five legacy systems with one, actively seeking vendors who will decommission old systems as a condition of adoption.
Notable Moment
At a closed-door Davos cybersecurity forum of 60 professional practitioners, a speaker asked how many attendees had heard of Salt Typhoon — China's full infiltration of US cellular carriers. Only five hands went up, revealing that even the security community was largely unaware of a nation-scale compromise already underway.
Episode Transcript
I was at Davos last year in a cyber form, and one of the speakers was talking about Sol Typhoon. It was closed door room of 60 cyber folks. And she said, wait, how many people know about this? It was five out of 60. What we learned was that China has infiltrated major telecommunications carriers in The US for all intents and purposes fully. So they can listen to the phone calls, the lawful intercept plug in points. They have control of those, and they can just flip turn on at any time and listen to I mean, what do you do on your phone? You know, how much of your life runs on your phone? Basically, all of it. And what we continue to learn is that that's true for everybody, everybody in The United States. Rather than trying to ferret through the existing carriers on Guam and find all the China and try and try and get rid of it. Let's just do a clean install of a telco on top of the existing physical infrastructure. Just assume it's hostile. This was literally three months before the salt typhoon news broke, and we learned that China had compromised the x one interface of all these major telecosic. The more folks who are kind of bringing, connecting the dots, speaking the same language, I think the better off we all are from a national security and economic prosperity perspective. In late twenty twenty four, The United States confirmed that Chinese hackers had infiltrated every major American cellular carrier. The operation, Salt Typhoon, gave China access to lawful intercept systems, live phone calls, and the communications of senior government officials. It was not a one time breach. It was the product of an industry wide failure in cybersecurity. Years before the story broke, a former Green Beret and Palantir executive had started building a new kind of cell network. One designed to operate securely on top of compromised physical infrastructure. The Navy was an early partner, testing the technology on Guam before anyone outside the intelligence community fully grasped the scale of the threat. David Ulewicz speaks with Justin Finelli, CTO of the Navy, and John Doyle, founder and CEO at Cape. Thank you guys for being here. We are very lucky to have Justin Finelli, the CTO of the Navy, on his second tour back with the Navy and in this role. And we have John Doyle, the founder and CEO of CAPE, with us, and we're gonna have a terrific discussion about building for the country, building for the Navy, partnering with the Navy, and all the technology transformation work that is going on at the navy. So thanks, guys, for being with us today. Thank you. Thanks for having me. Justin, just give us a quick background on who you are, what's your job today, how long you've worked in this space. Thanks for having me. Often to be with winners. That's actually a big part …
Get the full transcript (8,474 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 38-minute episode.
Get a16z Podcast summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from a16z Podcast
We summarize every new episode. Want them in your inbox?
The Reality of AI-Powered Cyberattacks | Truffle Security & Socket
How Open-Source AI Became Critical Infrastructure
Three Startups Reinventing Critical Infrastructure
OpenAI's Joshua Achiam: Did We Already Reach AGI?
Ruby Thelot on Internet Culture, AI, and the Future of Taste
Similar Episodes
Related episodes from other podcasts
Biotech Hangout
Jan 30
Episode 171 - January 30, 2026
The Joe Rogan Experience
Dec 5
#2423 - John Cena
Latent Space
Nov 25
After LLMs: Spatial Intelligence and World Models — Fei-Fei Li & Justin Johnson, World Labs
The Vergecast
Jul 31
It's time to panic about AI safety
Huberman Lab
Jul 30
Essentials: How to Become Resilient, Forge Your Identity & Lead Others | Jocko Willink
Explore Related Topics
This podcast is featured in Best Business Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Health & Longevity Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into a16z Podcast.
Every Monday, we deliver AI summaries of the latest episodes from a16z Podcast and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime