Maiffret returns to eEye Digital Security

News
Jul 13, 20104 mins

Marc Maiffret has left FireEye and is back at the company he helped launch, three years after breaking away.

Three years ago, Marc Maiffret was tired. He had been running hard as CTO of eEye Digital Security since co-founding the company at age 17. So after a decade, he walked away.

He recently resurfaced as chief security architect at FireEye, and did an extensive interview with CSO about how security threats have changed since his eEye days. He also rolled out a new site called ModernMalwareExposed.org, designed to help companies keep better track of evolving malware architecture and mount a more effective defense.

So it might come as a surprise that Maiffret has returned to eEye, reclaiming his title as CTO.

In an interview Friday, Maiffret said that even though he left the company, his affection for it never abated. “I left, but when you’re a co-founder it’s always going to be your baby.”

After he’d gotten enough time off from the industry and was ready to resurface, FireEye was the best opportunity before him. Recently, however, a place for him at eEye opened back up, and he jumped at the chance to go back.

“About a month ago I met with the new eEye management team and we immediately hit it off,” he said. “We found common ground in terms of what we could do by way of innovation.”

Contrary to some reports, he said, his decision to leave eEye three years ago was not about a problem with the rest of the management team at the time. He needed time to refocus. Pure and simple. He noted that Steve Jobs left Apple for a time for the same reason, and “has done his best work since returning to the company.” It’s a feat Maiffret hopes to duplicate at eEye.

He said he left on good terms with FireEye management, and he will stay on as a member of that company’s advisory board.

During the interview with CSO in May, Maiffret talked about how the threat landscape has changed in 10 years from one in which the main target was Microsoft Windows to one in which the bull’s eye has moved to products sold by Adobe, which faces growing criticism for widely exploited flaws in its software, and Apple, which is increasingly the focus of malware writers even though it hasn’t seen the level of attacks Microsoft and Adobe have.

He also offered this take on the security industry as a whole:

“When you look at the industry and the mainstay players, they’ll even tell you that their [malware] signature technology doesn’t work anymore but that hey, ‘we have all this great behavior-anomaly technology,'” he said. “What they don’t tell you, and what the IT community can see, is that with those technologies you are either at one end of the spectrum or the other. If you tune the technology up you may catch a lot of things, but that includes a lot of false positives. At the other end, the admins tune it down to reduce the false positives but then they end up missing stuff. At the end of the day, you really can’t have either of these scenarios, but everyone knows we can’t have a utopia, either. The reality is that we’re at the point where it’s not even the sophisticated attacks that cause all the problems. We’re seeing it with every-day spyware. It’s very hard to tell the two apart from a threat perspective. In the process, we’ve seen a massive failure of the vendor community to grasp these things.”

He said his perspective hasn’t changed since May, though his focus on the solutions to the problem have shifted somewhat: “The focus at eEye is on the flaw itself and providing remediation tools,” he said.

Read more about application security in CSOonline’s Application Security section.