16 Minutes on the News: Mobile Malware, Drug Pricing

AI transcript
0:00:06 Hi everyone, welcome to the A6NZ podcast. I’m Sonal and this is our second episode of 16 Minutes,
0:00:12 our new news show where we cover recent headlines of the week, the A6NZ way, why they’re in the news,
0:00:16 why they matter from our vantage point in tech, and share our experts’ views on the trends involved
0:00:21 as well. The first episode covered Neuralink and Brain Computer Interfaces, TikTok influencers
0:00:26 and AI, FaceApp and more. You can listen to that as well, it ran last week. But in this episode,
0:00:31 we covered these two topics that came up in the news this week, a new kind of mobile malware
0:00:36 that’s out there in the wild, and a new bipartisan proposal for lowering drug prices for senior
0:00:41 citizens with a short lay of the land on drug pricing in general. Remember, as we mentioned,
0:00:45 specific companies that none of this is investment advice, nor is it a solicitation for investors
0:00:51 in any of our funds. Please be sure to read a6nz.com/disclosures for more important details. Finally,
0:00:54 you should be able to find the show in the current A6NZ podcast feed, which is probably where you
0:01:00 found it, as its own show, 16 Minutes, in your favorite app shortly, and on our website at
0:01:09 a6nz.com/16minutes. So the first news item is on malware, which sounds very scary and malicious,
0:01:13 aka the mal. So let me actually quickly summarize the news and then I’ll introduce the a6nz expert
0:01:18 joining us to talk about this. So here’s the news. This week, a report was released by
0:01:22 Mobile Security Company Lookout, which also happens to be an a6nz portfolio company,
0:01:26 and basically researchers there discovered some of the most advanced mobile surveillance
0:01:31 wear ever seen. And to quote the Ars Technica article, which is one of my favorite news sites,
0:01:37 by the way, for this type of topic, the malware is called monocle. Sounds like a James Bond character.
0:01:43 And it’s been in the wild since at least March 2016, so over three years ago. And let me just
0:01:47 quickly say what it is. It’s an Android-based application that was developed by a Russian
0:01:52 defense contractor that’s apparently been linked to meddling in the 2016 presidential elections.
0:01:55 And I’m an Android user, but iOS folks, you’re not off the hook because
0:02:00 apparently a version of monocle for Apple’s operating system has been very likely developed
0:02:03 as well. And I’ll go into more details about what it can do, but let me introduce our expert
0:02:08 joining us to have this conversation, a6nz general partner, Martin Casado, who is a
0:02:13 serious expert in software-defined networking and actually has a very long and storied history
0:02:17 and security as well. Welcome, Martin. Thank you. So, Martin, can you just quickly help
0:02:22 break down what this category is? This isn’t practical advice. What is mobile malware? Tell
0:02:28 me about that. Sure. So, traditionally, in security, there’ve been two large markets. There’s been
0:02:32 network security, which are things like firewalls, which try and intercept bad things on the network,
0:02:37 and endpoint. So, endpoint is probably the most familiar. This is like protecting
0:02:42 traditionally at desktop. So, have you noticed things like Mac-A-Pee, Norton-Andy virus,
0:02:47 that’s right, Symantec, Trend Micro. So, this is the traditional endpoint security market where
0:02:52 you had a Windows desktop, typically, and you want to protect yourself from viruses. You’d get one
0:02:56 of these. You would download a package, install it, and run it on your machine. Right. Now,
0:02:59 there’s been a few things that have happened over the last, say, 15 years that have disrupted that
0:03:03 market, right? I mean, there’s been the move to cloud, which means there’s just, you know, fewer
0:03:07 desktops in the same way, and those desktops run fewer applications as opposed to like cloud
0:03:12 applications. But there’s also been a proliferation of operating systems. So, Windows used to be the
0:03:16 dominant personal operating system. Now, we see a lot of macOS, we see Android, which are mobile
0:03:20 operating systems. Right. You know, Chrome OS is another one. But also, like the form factor has
0:03:25 changed from something that sits on our desktops to laptops and, you know, like iPads, mobile phones,
0:03:30 tablets, etc. And by the way, just to emphasize, this is not like a static shift in terms of here,
0:03:33 the underlying secular trends, which I love that you just summed up for me. But we’re also talking
0:03:38 about mobile people, mobile workers. These devices enable them to move around. People are working in
0:03:42 coffee shops, you know, connecting, they’re doing their work with new tools that are letting them
0:03:46 do their work in the cloud. So, all of this affects all of that. It’s very important that
0:03:49 you point that out. Also, like there’s just a different life cycle for a mobile phone and different
0:03:54 behavior behind it. And a lot of detection of malware is behavioral. This is how a desktop
0:03:58 should act. Now, of course, a mobile phone will just be quite different. And so, mobile malware
0:04:04 is focused on that segment. Okay. So, given this recent news, tie it back to Monocle. I mean,
0:04:08 should we be freaking out or what? Actually, we’ve known that there’s, you know, like,
0:04:13 pretty serious malware out there for a long time. Here’s what’s so significant about this to me,
0:04:21 which is, for whatever reason, we’ve decided to use phones as a security device more than we have,
0:04:25 for example, desktops traditionally, right? So, they’ll give you an example of that. Often,
0:04:29 in order to secure an account, we do what’s called two-factor authentication. And the second factor
0:04:33 is an SMS. By the way, two factors, something you have, something you know. That’s right. So,
0:04:37 for example, like, for me to get into my email account, well, I’ll have a password, which is
0:04:42 something I know. But often, if they don’t know that it’s me or they want a second factor, they’ll
0:04:46 send me an SMS text to my phone. So, that’s the second factor, maybe that’s something I have,
0:04:50 which is the device. So, often, we say, well, the mobile phone is something you have. And we’ve
0:04:55 been treating it like a security device. So, like, if this is a bank account, if this is your email,
0:04:59 if this is your Coinbase account, whatever it is, actually, it turns out, like, phones aren’t
0:05:04 that secure even though we’ve been relying on it. And you can see there’s been a huge spate recently
0:05:10 of attacks against phones in order to get access to accounts. And so, this just further proves
0:05:13 that phones are very much a weak link into personal security.
0:05:16 In fact, this would be very specific about what monocle in particular can do, what we are talking
0:05:20 about the broader category. So, here’s some of the things according to the report. It can retrieve
0:05:25 calendar information, including the name of the event, when and where that event is taking place,
0:05:29 and a description of it. It can collect account information and retrieve messages from WhatsApp,
0:05:34 Instagram, Skype, et cetera. It can send text messages to an attacker-specified number.
0:05:38 It can reset a user’s PIN code. And it can download attacker-specified files,
0:05:42 reboot the device, and uninstall itself, and remove all traces from an infected phone.
0:05:44 It’s like it has a life and personality of its own.
0:05:47 Yeah, yeah, yeah, yeah. That’s the attacks I was talking about. Let’s imagine, for example,
0:05:54 like, your bank account was protected via SMS to your phone. If you have malware there that can
0:05:57 intercept that and send that to the bad person, they can reset your password on your bank account.
0:06:01 So, these things are actually very serious. In fact, how many of us authenticate using
0:06:05 SMS as our second factor? It’s very common. The first thing I do when I sign up to a new
0:06:08 thing is I turn off two-factor SMS for exactly this reason.
0:06:12 So, bottom line it for me. How should we think about security in a post-parameter world, which,
0:06:17 by the way, is what Lookout’s tagline is? And you and I talked about that topic in 2016 when you
0:06:22 first joined A6 and Z, and we did a podcast about networking as sexy. Yeah. How does Monocle and
0:06:26 Malware fit into the overall landscape of how security is changing just in the big picture?
0:06:30 I do think that there is a macro trend, which attacks are just becoming more personal and
0:06:34 dealing more with social engineering, right? So, there’s just less about, like, “Oh, I’m going to
0:06:38 have some bad bug that, like, does something malicious,” and more, “I’m going to have something
0:06:42 that’s closer to the human being, so I can trick them into doing something I can pretend to be them,”
0:06:47 because it really is these social aspects that we’re seeing become really predominant when it
0:06:51 comes to these attacks. I think the phone is about as close and personal as the devices we have.
0:06:53 It’s like a body part for many people.
0:06:56 It really is. I mean, it’s an extension. It’s like the coprocessor to our brain.
0:06:59 Yeah. I mean, I just think that the first thing is to realize that attacks are becoming incredibly
0:07:04 personal and they’re focused on us, right, especially if you’re anywhere near, like,
0:07:09 you know, a large company with a lot of assets. And so, I think it’s very important for listeners
0:07:13 to understand best practices for protecting themselves. For example, getting a password
0:07:18 manager is a big deal using hardware tokens where you can, turning off two-factor authentication,
0:07:25 not relying on SMS. I mean, just knowing that there are these targets that are focused on us
0:07:30 as people and understanding, you know, best practices to defend against that will go a long way.
0:07:31 That’s fantastic. Well, thank you for joining, Martine.
0:07:32 That’s a pleasure.
0:07:37 Okay. So, the next item is on drug pricing. So, here’s the news. Just this week,
0:07:41 the Senate Finance Committee released a bipartisan drug pricing proposal that would cap
0:07:47 senior citizens out-of-pocket costs for drugs, as well as, this is really interesting,
0:07:51 limit price increases in Medicare. And according to the Congressional Budget Office,
0:07:56 as reported by the Washington Post, the proposal is projected to save the government about $100
0:08:01 billion over 10 years, save senior citizens about $27 billion in out-of-pocket costs over that same
0:08:07 time period, save $5 billion from lower premiums. And just to be clear, this is one of many proposals
0:08:11 in a couple of months. The House of Representatives is also expected to release a different drug
0:08:16 pricing proposal than this Grassley-Widen one, which would actually allow Medicare to negotiate
0:08:20 the prices of some drugs, and that’s currently prohibited by law. And there’s two other proposals
0:08:25 on the horizon as well. Clearly, it’s a very political, tough topic with many proposals
0:08:30 and many players involved because drugs, the argument goes, should not be so expensive.
0:08:35 They’re life-saving. They’re meant to keep us healthy. It’s insane that drugs can be so expensive.
0:08:39 And I also just want to mention that this is playing out against other recent news, which we’ve
0:08:43 talked about on A6 and Z quite a bit already, which is that in the past month, for the first
0:08:49 time ever, we’ve seen the approval of not one but two gene therapies with approximately $2 million
0:08:55 price tags each. So I’m going to welcome A6 and Z Biogeneral Partner Jorge Conde and A6 and Z
0:09:00 Biomarket Dev Partner Jay Ragani. This is a really meaty topic and something I can’t believe
0:09:07 or even trying to attack as a part of a 16-minute segment. I would just love to start with just
0:09:12 quickly the lay of the land. Why is drug pricing so damn hard? So one of the things that often comes
0:09:17 up, and it’s currently in the headlines right now, is why are drug prices in the United States so
0:09:22 much more expensive than other countries? Why can’t the government and specifically Medicare
0:09:26 use its purchasing power to negotiate against pharmaceutical companies? As you mentioned,
0:09:30 it’s illegal, but the history is interesting. So the Medicare Modernization Act of 2003,
0:09:35 the one that actually established Part D in the first place. What is Part D? Part D is the drug
0:09:40 benefit for Medicare to cover prescription drugs. And what’s interesting in that is
0:09:46 it established the Part D benefit, but it included a provision known as the non-interference clause,
0:09:50 which effectively prevents the HHS from interfering. Department of Health and Human
0:09:53 Services, the government agency that developed here. Exactly. So the Health and Human Services
0:09:58 Secretary from interfering with any negotiations between the drug manufacturer and any of the
0:10:03 other stakeholders in the value chain. Fifteen plus years later today, we have some bipartisan
0:10:09 momentum to give Medicare the ability to negotiate. And I think it’s very important to note that when
0:10:14 we talk about drug pricing, in general, you run the risk of conflating things. What’s being conflated
0:10:19 here? Well, it’s one thing that the price of insulin continues to rise at the rate at which
0:10:24 it’s risen. It’s one thing where sort of things that have been off-patent or have been generic
0:10:29 for a long time all of a sudden get these very, very large price hikes. That’s different than
0:10:33 saying a new therapy like a gene therapy that has the potential to be a cure, you mentioned,
0:10:38 a $2 million price tag. Those therapies are A, expensive to discover. B, they’re very,
0:10:42 very expensive to make. And C, they have real benefit. In this case, they’re potentially
0:10:46 cures. And so you’re not giving someone a dose of a medicine. To be clear, you’re basically saying
0:10:51 that it’s a one-time treatment and cure versus having to see a doctor with chronic therapy over
0:10:55 and over and over again. For example, in the case of Zolgensma, it’s a gene therapy that was approved
0:10:59 to treat children with spinal muscular atrophy, which is one of the leading genetic causes of
0:11:02 infant mortality. Exactly. In that case, you’re not only giving these children health, you’re
0:11:06 giving them life. And so these are two very different things. It’s talking about how we control
0:11:10 rising costs of drugs that may not be on the cutting, still necessary, but not on the cutting
0:11:14 edge of innovation versus the new… And that can get lost in the dialogue because these are
0:11:18 obviously very complex debates. And for the latter, people can listen to your episode. Jorge
0:11:24 did an episode with famous MIT economist Andrew Lowe, who has a really interesting proposal for
0:11:26 thinking about how to fund these. So you can listen to that for more of a deep discussion.
0:11:31 So now let’s go back to the big picture, lay of the land. So let’s remove the deep special
0:11:36 new therapies off this particular discussion and talk about why are drugs so goddamn expensive?
0:11:40 I’ll give you the thrust of some of the more common arguments. The first one is,
0:11:45 they’re expensive because R&D is expensive. Developing a drug is time consuming. It’s risky
0:11:50 and it costs a lot of money. And because there are a lot of failures along the way,
0:11:55 the ones that are approved have to be priced as such to not only make money for that drug,
0:11:59 but also to pay for all of the things that have failed. As Jay mentioned, it’s very clear that
0:12:04 the United States, we pay a far higher price for most drugs than we do in the rest of the world.
0:12:08 For a lot of the reasons that he mentioned, the counterargument from industry would be,
0:12:12 well, for better or for worse, the United States is subsidizing R&D for the world.
0:12:13 Right, the research and development.
0:12:19 So that’s one issue. Another issue is that we do have this question of who has market power and
0:12:24 it is illegal in the United States at the moment for the government to negotiate drug prices that
0:12:27 would be considered price controls here in this country, even though that’s not the case
0:12:32 in many parts of the rest of the world. Number three, we have a very complex industry structure.
0:12:34 Tell me more about that, like the players that are involved here.
0:12:39 Sure. So there are manufacturers who, generally speaking, discover and develop the drugs in
0:12:42 the first place and commercialize them. And probably want to make money off of it.
0:12:46 Then you have distributors and the distributors get paid to move drugs through the channel and make
0:12:50 sure that the drugs get to where they need to go and can be in a hospital, a pharmacy, whatever it is.
0:12:53 There’s a middle layer here. Yeah, there’s a middle layer here, the pharmacy benefit
0:12:58 manager that helps actually the PVMs that helps manage who gets access to the medicines,
0:13:00 who’s eligible versus who’s not.
0:13:03 They sort of consolidate some of the information too, right? They sort of summarize the formularies
0:13:07 for what are the drugs, for which condition, et cetera, et cetera, and that helps influence
0:13:12 what gets prescribed. Yeah, so the B in pharmacy benefit manager, the idea was this sort of layer
0:13:18 of the industry arises to help the insurers, the payers, control who gets access to the drug to
0:13:21 make sure the right people get the drug and the wrong people don’t, and to help manage
0:13:25 the benefits spent, which that’s the idea to the benefit of the insurer. But then, of course,
0:13:29 that layer takes a cut of the economics, and it’s a very complex thing in form of rebates
0:13:33 and otherwise. And then you have the insurers and the payers. The payers obviously want to
0:13:37 minimize costs. They’re, in fact, just tying it back to the news. As I understand it, they’re in
0:13:42 support of this current bill. Because it controls the increase of the cost of the drugs, but there’s
0:13:46 always a risk for an insurer. If you’re reducing your drug spend, is there a potential that you’re
0:13:51 going to have more expensive interventions? As you go through the system, there are various
0:13:56 stakeholders that all get piece of economics, but there’s been studies that have been done that
0:14:02 show that for every dollar of drug spend, the manufacturer gets a percentage that is surprisingly
0:14:05 low. I would never have assumed that, because right now the narrative is like they’re extracting
0:14:09 all the value. Yeah, and the reality is that there’s value taken along the way. So that’s an
0:14:13 amazing breakdown of who the players are and their incentives and motives and just sort of how
0:14:16 they’re thinking about it, because obviously we’re not going to answer and fix this in one
0:14:21 episode. Now, let’s bring it back to the current news. So how does this sort of tie back into what’s
0:14:26 on the table right now? The proposal here is to cap the amount of spend or the amount of cost
0:14:30 that Medicare patients pay out of pocket in any given year and dropping it pretty significantly.
0:14:35 I think it was in the $8,000 range, and now they’re talking about the $3,100 range. Oh,
0:14:39 wow. Big difference. So that’s one big piece. The other one, at least as I understand the original
0:14:44 proposal, is to cap how much you can increase the prices and tie it either to inflation or
0:14:49 other mechanism by which annual price increases can occur over time. Now, the risk, of course, is
0:14:53 having drugs be introduced at even higher prices, because if I’m capped at how much I can grow,
0:14:57 right, I’ll start at a higher price. That’s right. Using maybe a terribly stretch analogy of rent
0:15:02 control and the San Francisco apartment, the rent is going to start off thousands of dollars higher
0:15:05 because you know you can barely incrementally increase it after that if you’re going back on
0:15:09 the market. Yeah, I think the other element to add there is walking through the chain of
0:15:15 stakeholders from the manufacturer to when a medicine ultimately gets in the hands of a patient.
0:15:20 There is also a lot of narrative externally on the list price to net price differential.
0:15:26 Oftentimes, a manufacturer will set a list price for a medicine, but that’s actually not the price
0:15:32 that is paid for by the payer or by the patient. That rebate that is given back by the pharmacy
0:15:37 benefit manager very rarely makes it to the patient or to the payer. So a lot of inflation
0:15:42 without any felt tangible benefits whatsoever. Exactly. And so that’s why I think some criticize
0:15:50 that some of the complexity in the chain and the lack of transparency creates unfair pricing policies.
0:15:54 We can obviously dive into all the solutions, but just at a quick take in the 16 minutes episode,
0:16:00 what are some of the things that technology can do? If you’re an entrepreneur looking at this space,
0:16:05 the opportunity for technology to drive transparency across various different steps in this process,
0:16:11 at least hopefully, and we’re optimists here, can drive down a lot of the waste that happens in
0:16:15 the system. One of the things that people really are challenging, one of the things that we’re
0:16:21 excited about is value-based care contracts or outcomes-based pricing. Yes. For some of these
0:16:26 novel one-time cure therapeutics that have entered the market, you mentioned Novartis Zolgensma,
0:16:31 Bluebirds and Tenglo. What’s challenging there and where there’s a real technology problem
0:16:38 is how do you get the data to actually facilitate that contract? Basically, because if it’s saying
0:16:42 value-based, how do you know it actually is being paid on value versus just some theory that it’s
0:16:46 going to work? It actually works and therefore you pay based on that. Exactly. Manufacturers are
0:16:52 proposing a money-back guarantee, but the data, the infrastructure, the plumbing does not exist
0:16:56 today to effectively arbitrate those contracts at scale. That’s where technology can help.
0:17:01 It’s a critical point because the chain is not only complex, it’s also not transparent,
0:17:05 and so the potential for technology to have an impact there is pretty significant,
0:17:12 but it also requires some help from policy to essentially make transparency, if not an obligation,
0:17:17 at least to write. If you have that, then you can help to drive out some of the inefficiencies,
0:17:20 drive out some of the frictions that exist in the system that ultimately lead to a higher cost.
0:17:24 Well, quite frankly, the argument that I would make here as a believer in free markets is that
0:17:27 they only work if there is transparency of information or symmetry of information and
0:17:31 that that’s the thing that people always forget when these debates become all about free market
0:17:36 economics versus price controls versus X versus Y. That is the key ingredient. The irony is that’s
0:17:39 a very thing you need, yet it’s a very thing that’s being obscured. Okay, so bottom line it for me.
0:17:43 What’s on the horizon here? Look, it’s clear that we as a country need to have a debate on how to
0:17:48 deal with rising cost of health care generally and specifically rising cost of drug spend,
0:17:53 and so I think it’s important that proposals are being made. This is obviously the first step of
0:17:57 what’s going to be a broader and ultimately very complicated conversation because we’re talking
0:18:02 about drugs that can cost tens or hundreds of thousands of dollars a year for chronic therapies.
0:18:06 We need to find a solution to contain those costs and to make sure that the patients are
0:18:09 getting the right therapies and that the system becomes accessible to everybody. Yeah, that access
0:18:14 is taken care of and that the system can support it. But what’s coming down the pipe is that we have
0:18:20 new modalities, new therapies like gene therapies, engineered cells that are really changing the
0:18:25 definition of what a medicine can be. I think it’s a very important thing because the outcomes,
0:18:30 and Jay was just describing value-based contracts and all that, the outcomes of what these therapies
0:18:34 can do are very different than what we’ve seen. Cures are a very rare thing in medicine,
0:18:38 but some of these things start to approach things that look like cures, but they’re very expensive
0:18:44 to make. You mentioned Zolgensma. SMA is a disease where you otherwise did not have an option,
0:18:50 and that can be a 10-year treatment horizon that now can be potentially addressed by one cure,
0:18:55 and the cost that that pulls out in the system from an administration standpoint
0:18:59 is also part of the value of that medicine. So the Center for Medicare and Medicaid Services
0:19:04 Administrator Seema Verma earlier this year highlighted the fact that the current system is
0:19:11 not set up to execute and support these kinds of new medicines. And less than until we have a system,
0:19:16 and this includes policy, this includes technology layers and pipes to have the data of feeds that
0:19:22 we need to understand what’s working and what’s not, and a way to address the cost that is entirely
0:19:26 up front and mismatch with the benefit, which is over a very long period of time. We will find
0:19:30 ourselves, I think, in the very challenging position where we have a healthcare system that is not
0:19:34 able to support innovation, and I think that’d be the worst thing for society. Thank you, Jorge
0:19:38 and Jay, for joining this segment. Thank you. Thanks for having us.

with @martin_casado @jorgeconde @jayrughani and @smc90

This is episode #2 of our new show, 16 Minutes, where we quickly cover recent headlines of the week, the a16z way — why they’re in the news; why they matter from our vantage point in tech — and share our experts’ views on these trends as well.

This week we cover, with the following a16z experts:

  • . mobile malware and a recent report of a new kind in the wild and security in a post-perimeter world — with a16z general partner Martin Casado;
  • drug pricing given recent proposals on the table, sharing a lay of the land for why drug pricing is so damn hard, what is a medicine, and where tech comes in — with a16z bio general partner Jorge Conde and market dev partner Jay Rughani;

…hosted by Sonal Chokshi.


The views expressed here are those of the individual AH Capital Management, L.L.C. (“a16z”) personnel quoted and are not the views of a16z or its affiliates. Certain information contained in here has been obtained from third-party sources, including from portfolio companies of funds managed by a16z. While taken from sources believed to be reliable, a16z has not independently verified such information and makes no representations about the enduring accuracy of the information or its appropriateness for a given situation.

 This content is provided for informational purposes only, and should not be relied upon as legal, business, investment, or tax advice. You should consult your own advisers as to those matters. References to any securities or digital assets are for illustrative purposes only, and do not constitute an investment recommendation or offer to provide investment advisory services. Furthermore, this content is not directed at nor intended for use by any investors or prospective investors, and may not under any circumstances be relied upon when making a decision to invest in any fund managed by a16z. (An offering to invest in an a16z fund will be made only by the private placement memorandum, subscription agreement, and other relevant documentation of any such fund and should be read in their entirety.) Any investments or portfolio companies mentioned, referred to, or described are not representative of all investments in vehicles managed by a16z, and there can be no assurance that the investments will be profitable or that other investments made in the future will have similar characteristics or results. A list of investments made by funds managed by Andreessen Horowitz (excluding investments for which the issuer has not provided permission for a16z to disclose publicly as well as unannounced investments in publicly traded digital assets) is available at https://a16z.com/investments/.

Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others. Please see https://a16z.com/disclosures for additional important information.

Leave a Comment