**Feross Aboukhadijeh** (0:00)
When he joins the Slack channel, the attackers were pretending to be a legitimate company. So they had stolen the brand and the name of a real company. They got him on a Microsoft Teams call. During the call, the call just cuts out, and a message shows up in the interface that says, your Microsoft Teams is out of date. You need to click this file to update it. And it turns out that file was not legitimate. Why we started building the company was we wanted to make sure that we could really help people understand what is the full scope of the open-source software that we're depending on and all the parts of that supply chain, and then how do we make good decisions about whether to trust it or not, and how do we be more proactive at responding to these threats.
**Anne Dwane** (0:47)
Hello, and welcome to the Village Global Podcast. I'm Anne Dwane, and today we're pleased to welcome Feross Aboukhadijeh, who's a security expert and an open-source developer who's very renowned, who started Socket in 2021 to support the tidal wave of supply chain attacks that are happening now in software. Socket detects over 1,000 attacks every week, and they protect over 20,000 organizations from OpenAI to Anthropic to Vercel and many startups. So without further ado, welcome Feross. Welcome everyone, and welcome Feross Aboukhadijeh.
First, congratulations for us on your Series C at a billion-dollar valuation.
**Feross Aboukhadijeh** (1:35)
Thank you. I appreciate it. It's a really exciting time for the whole Socket team right now.
**Anne Dwane** (1:39)
Yes, exactly.
So as background, you're a serial founder and you're yourself a prolific open-source creator and maintainer. In fact, I think one of your claims to me is your packages are downloaded a billion times a month. Is that right? Wow. So you're an open-source billionaire. That's pretty good.
**Feross Aboukhadijeh** (2:03)
Yeah. We also have a lot of others on the socket team as well, like on our engineering team that are similarly prolific open-source maintainers.
**Anne Dwane** (2:11)
Amazing. Well, thank you, the unsung heroes of the internet in the open-source community.
But I actually would love to understand where your cybersecurity career began. And from what I've heard, it began as a child with a microwave. Can you tell that story?
**Feross Aboukhadijeh** (2:27)
Sure thing. Yeah.
I did not know that this story was going to come up in this interview. So good job. You did really deep research.
**Anne Dwane** (2:34)
Yeah.
**Feross Aboukhadijeh** (2:36)
Yeah. So the story is, just when I was, I think I was like five, my mom and dad got a new microwave. And one of the things I had a habit of doing then was I would read everything. I could get my hands on, especially if it was technical. So I'd always read instruction manuals. There wasn't like internet or much to read. So I would just read the manuals from front to back. And so one of the things I learned about this microwave was, I can't remember the exact age now. Don't quote me on being age five.
But yeah, I read the manual and found that there's this child lock feature. And so it was a pretty easy sequence of buttons, and I would just use it whenever I was upset at my mom, and just sort of lock her out of the microwave, and she'd get so upset and didn't know how to undo it, and so, you know.
**Anne Dwane** (3:18)
Well, holding them hostage for their hot food. Well, I'm glad now that you use your Smarts for good and not evil. And let's go back to 2020, when you started Socket.
And what did you see then?
**Feross Aboukhadijeh** (3:31)
Yeah, so before starting Socket, like you said, I spent a long time in open source. And one of the things that I started seeing more and more of was just like how the way we write software had changed. And so we went from a world where applications had maybe a few hundred open source dependencies total, to a world where you can't even get Hello World to show up on the screen without installing a thousand plus dependencies.
And this isn't a joke, right? This is people who build JavaScript apps today know this is the reality. And so we've kind of gone from this world where you had maybe a handful of projects you use that had teams behind them, foundations, you know, this lot of support infrastructure, to a world where you have individuals like myself who have individual authors of hundreds of packages. And so that meant that you kind of, the amount of people you have to trust as you're building your software has just ballooned dramatically.
46 more minutes of transcript below
Try it now — copy, paste, done:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090
Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000778039016