Chasing Entropy Podcast by 1Password
This podcast is an interview series with career professionals in cyber security as we get their takes on shadow IT, extended access control, agentic AI and how they arrived at this point in their careers.
Chasing Entropy Podcast by 1Password
Chasing Entropy Podcast: No Robots in the Gym with Keith Hoodlet
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This week on Chasing Entropy, host Dave Lewis sits down with Keith Hoodlet, Director of Security Research at 1Password and leader of the newly formed Off by One Labs. Keith describes his team's mission with characteristic wit: throwing stones at glass houses not to hear the crash, but to help people build better, more secure houses.
From Battle.net punk to security leader
Keith's path into security started in the late '90s, when a teenage curiosity about Diablo and Battle.net led him to discover he could spoof other users over Telnet using nothing more than a trial key from the back of a CD case. Teaching himself Visual Basic to automate the trick (and, he admits with a cringe, to spam StarCraft opponents offline rather than lose ranked matches) planted the seeds of a career.
The road from there was anything but linear: a psychology degree from Keene State, graduating straight into the 2009 recession, odd jobs, a return to school for computer science at the University of New Hampshire, and a jump into the industry via a managed security services provider. Stops at Rapid7, Bugcrowd, Thermo Fisher Scientific (where he ran global DevSecOps through the pandemic), GitHub, and Trail of Bits followed before he joined 1Password in February 2026 to build its security research program from the ground up.
That psychology background still shows up daily, not in threat models, but in leadership. Keith argues the human element is the most overlooked skill in security: building genuine relationships with engineers and product owners is what actually improves security outcomes. At Thermo Fisher, that meant handing out thousands of copies of The DevOps Handbook and earning trust before asking for change.
Pioneering AI bias bounties
Keith shares the story of participating in the U.S. Department of Defense's 2024 bias bounty program, one of the first times an organization paid external researchers to prove an AI system was biased and unfit for its intended use. His favorite finding: a role-play scenario in which the model addressed a superior officer as "sir" every single time, dozens of runs in a row, despite official military guidance having moved to gender-neutral forms of address. He kept reproducing it until the contest runners declared it out of scope.
If Keith were 18 again
Ahead of his upcoming DEF CON talk at Noob Village (Friday, August 7), Keith previews the advice he'd give his 18-year-old self in an era where AI threatens entry-level white-collar work:
- Start a blog before anything else. Written content compounds in value over time, serves as external memory, and builds a public body of work that makes you credible to employers, Keith used his own blog posts on leadership during his 1Password interview loop. Skip chasing YouTube and TikTok; write.
- Think hard about the college question. Keith is careful to note degrees still make sense for many people, particularly those from underrepresented groups facing arbitrarily higher bars, but at today's costs, the decision deserves far more deliberation than it used to.
- Read like it's weightlifting for your brain. Start small, a newsletter, a blog, and build toward full books. Reading widely lets humans make intuitive leaps across domains, something Keith argues remains a genuine advantage over large language models.
No robots in the gym
Dave presses Keith on an apparent tension: he's an AI security researcher who warns that prolonged AI use erodes critical thinking. Keith's answer borrows a phrase from Daniel Miessler: no robots in the gym. Don't use AI for the skills you want to keep sharp, for Keith, that's writing, reading primary sources, and critical thinking. But for skills you have no interest in developing (say, building yet another TypeScript web app), delegate freely, then interrogate the output to learn how to break it.
His practical tip for validating AI output: take what the model gives you, put it on a whiteboard, draw a box around it, and ask "what's not in the box?" Because LLMs produce the most statistically likely answers, you're missing everything outside that band, and that question is a forcing function for critical thinking, whether you're vibe coding, practicing law, or reading AI-generated "books" flooding online marketplaces.
Parting advice
For security leaders and newcomers alike, Keith's advice converges on one theme: stop waiting for permission. Hold strong opinions loosely, then benchmark them, prove them, and update. For those already in the industry: build with AI, break it, and learn where it works and where it fails. For those just starting out: publish the blog, learn in public, and don't worry about the likes.
Keith Hoodlet speaks at DEF CON's Noob Village on Friday, August 7. This is the Chasing Entropy Podcast, be sure to like, subscribe, and catch us next week.