Chasing Entropy Podcast: No Robots in the Gym with Keith Hoodlet

Chasing Entropy Podcast by 1Password

Chasing Entropy Podcast by 1Password
Chasing Entropy Podcast: No Robots in the Gym with Keith Hoodlet
Jul 10, 2026 Season 2 Episode 6
Dave Lewis, 1Password

This week on Chasing Entropy, host Dave Lewis sits down with Keith Hoodlet, Director of Security Research at 1Password and leader of the newly formed Off by One Labs. Keith describes his team's mission with characteristic wit: throwing stones at glass houses not to hear the crash, but to help people build better, more secure houses.

From Battle.net punk to security leader

Keith's path into security started in the late '90s, when a teenage curiosity about Diablo and Battle.net led him to discover he could spoof other users over Telnet using nothing more than a trial key from the back of a CD case. Teaching himself Visual Basic to automate the trick (and, he admits with a cringe, to spam StarCraft opponents offline rather than lose ranked matches) planted the seeds of a career.

The road from there was anything but linear: a psychology degree from Keene State, graduating straight into the 2009 recession, odd jobs, a return to school for computer science at the University of New Hampshire, and a jump into the industry via a managed security services provider. Stops at Rapid7, Bugcrowd, Thermo Fisher Scientific (where he ran global DevSecOps through the pandemic), GitHub, and Trail of Bits followed before he joined 1Password in February 2026 to build its security research program from the ground up.

That psychology background still shows up daily, not in threat models, but in leadership. Keith argues the human element is the most overlooked skill in security: building genuine relationships with engineers and product owners is what actually improves security outcomes. At Thermo Fisher, that meant handing out thousands of copies of The DevOps Handbook and earning trust before asking for change.

Pioneering AI bias bounties

Keith shares the story of participating in the U.S. Department of Defense's 2024 bias bounty program, one of the first times an organization paid external researchers to prove an AI system was biased and unfit for its intended use. His favorite finding: a role-play scenario in which the model addressed a superior officer as "sir" every single time, dozens of runs in a row, despite official military guidance having moved to gender-neutral forms of address. He kept reproducing it until the contest runners declared it out of scope.

If Keith were 18 again

Ahead of his upcoming DEF CON talk at Noob Village (Friday, August 7), Keith previews the advice he'd give his 18-year-old self in an era where AI threatens entry-level white-collar work:

  • Start a blog before anything else. Written content compounds in value over time, serves as external memory, and builds a public body of work that makes you credible to employers, Keith used his own blog posts on leadership during his 1Password interview loop. Skip chasing YouTube and TikTok; write.
  • Think hard about the college question. Keith is careful to note degrees still make sense for many people, particularly those from underrepresented groups facing arbitrarily higher bars, but at today's costs, the decision deserves far more deliberation than it used to.
  • Read like it's weightlifting for your brain. Start small, a newsletter, a blog, and build toward full books. Reading widely lets humans make intuitive leaps across domains, something Keith argues remains a genuine advantage over large language models.

No robots in the gym

Dave presses Keith on an apparent tension: he's an AI security researcher who warns that prolonged AI use erodes critical thinking. Keith's answer borrows a phrase from Daniel Miessler: no robots in the gym. Don't use AI for the skills you want to keep sharp, for Keith, that's writing, reading primary sources, and critical thinking. But for skills you have no interest in developing (say, building yet another TypeScript web app), delegate freely, then interrogate the output to learn how to break it.

His practical tip for validating AI output: take what the model gives you, put it on a whiteboard, draw a box around it, and ask "what's not in the box?" Because LLMs produce the most statistically likely answers, you're missing everything outside that band, and that question is a forcing function for critical thinking, whether you're vibe coding, practicing law, or reading AI-generated "books" flooding online marketplaces.

Parting advice

For security leaders and newcomers alike, Keith's advice converges on one theme: stop waiting for permission. Hold strong opinions loosely, then benchmark them, prove them, and update. For those already in the industry: build with AI, break it, and learn where it works and where it fails. For those just starting out: publish the blog, learn in public, and don't worry about the likes.

Keith Hoodlet speaks at DEF CON's Noob Village on Friday, August 7. This is the Chasing Entropy Podcast, be sure to like, subscribe, and catch us next week.


Episode Artwork Chasing Entropy Podcast: No Robots in the Gym with Keith Hoodlet 36:21 Episode Artwork Chasing Entropy Podcast: Jaya Baloo on AI, Security Debt, and Why Curiosity Still Wins 35:10 Episode Artwork Chasing Entropy Podcast: Matt O'Leary on M&A, Partnerships, and Security Risk 30:27 Episode Artwork Chasing Entropy Podcast: Dustin Heywood on Agentic AI, Quantum Risk, and Why Identity Still Breaks First 32:11 Episode Artwork Chasing Entropy Podcast [Season 2 episode 002]: Allie Mellen on Code War and The Real Logic Behind Cyber Conflict 37:04 Episode Artwork Chasing Entropy Podcast [Season 2 episode 001]: Bob Lord on Hacklore, Secure By Design, and Why Incentives Matter 34:07 Episode Artwork Chasing Entropy Podcast 027: Building Zero Trust and Human-Centric Security with Kane Narraway 35:39 Episode Artwork Chasing Entropy Podcast 026: Identity, AI, and the Future of Trust with Joseph Carson 32:31 Episode Artwork Chasing Entropy Podcast 025: Heidi Potter on Building Community and Leading with Kindness 36:09 Episode Artwork Chasing Entropy Podcast 025: "Agents, the Legacy Web, and Logins that Don’t Leak” with Paul Klein IV 34:33 Episode Artwork Chasing Entropy Podcast 024: Dhillon of Hack in the Box on Conferences, Chaos, and the Future of Security 40:04 Episode Artwork Chasing Entropy Podcast 23: Cybersecurity Meets M&A with Cole Grolmus 36:00 Episode Artwork Chasing Entropy Podcast 022: Michael Farnum on building security communities & navigating agentic AI 36:40 Episode Artwork Chasing Entropy Podcast 021: Cybersecurity in M&A with Brian Levine 40:01 Episode Artwork Chasing Entropy Podcast 020: Trey Ford on Research, Risk, and the Rise of Agentic AI 31:02 Episode Artwork Chasing Entropy Podcast 019: Balancing Security, IT, and Human Outcomes with Jacob DePriest 31:34 Episode Artwork Chasing Entropy Podcast 018: From Game Genie to Global Security. A Conversation with Rob Fuller 34:09 Episode Artwork Chasing Entropy Podcast 017: The Storyteller’s Journey with Bill Brenner 39:13 Episode Artwork Chasing Entropy Podcast 016: Seeing Beyond the Hype with Fernando Montenegro 37:04 Episode Artwork Chasing Entropy Podcast Episode 015: Herding Chaos with Jeffrey Wheatman 34:03 Episode Artwork Chasing Entropy Podcast Episode 014: Hats Off to the Hacker Ethos with Emil Tan 34:49 Episode Artwork Chasing Entropy Podcast Episode 013: Jack Daniel: A Life in Security, Sock Puppets, and Community-Building 42:03 Episode Artwork Chasing Entropy Podcast Episode 012: Dr. Grigorios Fragkos on Agentic AI, CISO Evolution, and Global Cybersecurity Insights 33:33 Episode Artwork Chasing Entropy Podcast Episode 011: Humour, Human Nature & Hacking Communication with Javvad Malik 33:23 Episode Artwork Chasing Entropy Episode 010: Empathy, AI, and the Evolution of Security with Mark Hillick 35:45