Window Snyder: Building Security Into the Software We Use
Window Snyder isn't a handle. It's the real name of the woman who, more than almost anyone else, made the software you use every day harder to break into.
As a junior employee she sat in Microsoft's daily "war room," where the engineering lead often wouldn't accept a change unless she said it was okay. She ran security at Mozilla when Firefox was the safe alternative to Internet Explorer. At Apple she pushed for encryption on by default and for end-to-end encrypted iMessage, even before Signal and WhatsApp did it.
Then, after Fastly, Intel and Square, she walked away from the big-company corner office to fix the one thing nobody wanted to fix: the forgotten devices in your closet that never get an update.
Window Snyder at a Glance
- Born in New Jersey in 1975 to a Kenyan-born mother who taught herself COBOL and debugged mainframe printouts at the kitchen table, Snyder got her first computer, a TI-99/4A, at age five.
- At Boston College in the early 1990s she studied computer science and math, haunted hacker IRC channels under the handle RosieRiv and hunted old DEC hardware at the MIT flea market, where she met the L0pht.
- She became the tenth employee at the consultancy @stake at the end of the 1990s, part of the "dream team" sent to Microsoft, and co-wrote the 2004 book Threat Modeling.
- Microsoft hired her, put her in the war room for Windows XP Service Pack 2 and the x64 edition, and let her create Blue Hat, the conference that brought outside hackers to Redmond.
- After co-founding Matasano Security she ran security at Mozilla, leaving in December 2008.
- At Apple from 2010 she drove iMessage end-to-end encryption, FileVault on by default and the first public iOS security whitepaper in 2012.
- She was chief security officer at Fastly, became Intel's chief software security officer in June 2018 and was chief security officer at Square by 2019.
- In 2020 she founded Thistle Technologies to give device makers plug-in security; True Ventures backed it with a $2.5 million seed in 2021, and Infineon's security chips joined its Secure Edge AI stack in 2025.
The Life of Window Snyder
Kitchen-Table COBOL
Window Snyder was born in 1975 in New Jersey to an American father and a Kenyan-born mother, Wayua Muasa. Muasa grew up in Machakos, in rural Kenya, so poor that she and her sister shared one sweater, wearing it in shifts to school. A scholarship took her to a Boston university in the mid-1960s.
By the time she was raising her daughter, Muasa had taught herself to code and worked as a mainframe software engineer writing COBOL. Snyder's childhood memories include her mother at the kitchen table with a stack of green-bar printouts, debugging with a pencil. When Snyder was five, a Texas Instruments 99/4A arrived in the house.
Growing up in California, she wrote basic programs on her mother's machines, but computers felt like a tool rather than a calling. In 1989 she left for Choate Rosemary Hall, a boarding school in Wallingford, Connecticut, where she struggled so badly that an advisor asked whether she might be happier somewhere else.
She stayed. "I never worked so hard for anything in my life," she told Choate students in 2023, accepting an alumni award. "And then after leaving Choate, nothing was ever hard again."
RosieRiv Buys a VAX
At Boston College in the early 1990s Snyder chose computer science and mathematics, and discovered the hacker scene growing up around MIT. She moved from bulletin boards to IRC channels like #NewHackCity and started pulling apart a DEC machine running Ultrix.
"My question was: what's keeping my data separate from everyone else's? What's keeping my process separate from the kernel?" she recalled. She even named her cat Digital Equipment Corporation.
Old DEC hardware came from eBay and from the MIT flea market, where the hacker collective L0pht sold off surplus gear. In his 2023 book, L0pht member Cris "Space Rogue" Thomas remembers a young woman walking up to ask, "Are you the guys with the VAX?" She was after their 1985 MicroVAX II, and she didn't match the ripped-jeans, leather-jacket crowd at all.
Online she went by RosieRiv, after Rosie the Riveter.
The @stake Dream Team
At the end of the 1990s Snyder became the tenth employee of @stake, one of America's first security consultancies and a roll call of future legends: Alex Stamos, Peiter "Mudge" Zatko, Dave Aitel, Katie Moussouris and Chris Wysopal of the L0pht.
Microsoft was the big client. Wysopal remembers that whenever Redmond called, the answer was "let's send in the dream team," and Snyder was on it.
With colleague Frank Swiderski she turned the loose art of thinking like an attacker into written, repeatable method: threat modeling, which traces entry points and data flows to find where an attacker gets the most leverage, and the security development lifecycle that builds security in from the first line of code. Their book, Threat Modeling, came out from Microsoft Press in 2004.
"She was like a pioneer for our industry," said @stake colleague Frank Heidt. "None of this existed."
Inside Microsoft's War Room
Microsoft poached Snyder and Swiderski outright. The company was reeling from viruses and public embarrassments, and Bill Gates had launched the Trustworthy Computing push to make security everyone's job.
Snyder worked on Windows XP Service Pack 2, the 2004 release that switched on a firewall, hardened Outlook Express and patched up Internet Explorer. For Windows XP Professional x64 Edition, shipped in 2005, she was chosen to represent the security team in the daily war room where every group reported progress and fought over trade-offs.
She was still junior. "It was an assignment that one would give to a senior program manager," said Steve Lipner, her manager at the time. Clyde Rodriguez, who ran the project, put it more bluntly: "Many times I would not accept anything unless Window said it was okay."
She also pitched executives on inviting outside researchers to Redmond to explain how they broke Microsoft's products. She called it Blue Hat, after the blue badges that got you in the door, and it grew into a public conference that still runs today.
Mozilla's Security Chief
Snyder co-founded the consultancy Matasano Security, then moved to Mozilla to lead security for Firefox at the height of its reputation as the browser that wouldn't get you owned. A 2008 video introduced her by her playful title there: "Chief Security Something."
She left Mozilla in December 2008, worked as an independent consultant and in March 2010 joined Apple as a senior product manager in its security group, her third browser maker in five years.
Apple Doesn't Have Your Data
At Apple, Snyder was the lone product manager responsible for the privacy and security of every product the company sold. Three years after the first iPhone, people were putting their whole lives on the thing, and she wanted a radical answer.
"If the data's on your infrastructure, if you're the custodian of that data, then you have a duty to protect it, and protecting it is hard," she reasoned. "So let's minimize our own access to it." She called the project "Apple Doesn't Have Your Data."
The results shipped over the next few years: iMessage encrypted end to end, FileVault full-disk encryption turned on by default for Macs, and iPhone contents locked behind a passcode that not even Apple could bypass. In 2012 she persuaded the company to publish its first iOS security whitepaper, and in 2013 she was part of the push to make macOS upgrades, and therefore security updates, free.
Veteran cryptographer Jon Callas credits her with being "quiet and relentless" in advocating for it all. Moussouris goes further about the FBI's later court fight to unlock an iPhone: "The FBI would not have needed that had Window not worked at Apple."
Fastly, Intel, Square
At Fastly, Snyder built the security team at a content delivery network she says carried roughly 10% of internet traffic. After three years as its chief security officer, she was named Intel's chief software security officer in June 2018, less than a week after CEO Brian Krzanich resigned, with a mandate covering the security roadmap for every business unit.
By 2019 she was chief security officer at the payments company Square. Colleagues quoted in TechCrunch's 2023 profile of her reached for words like "relentless" and "like a swan — so graceful on the surface, but paddling like hell underneath."
Thistle
In 2020 Snyder founded Thistle Technologies, named for the plant whose prickles deter grazing animals. "It's a defense mechanism," she said. The problem she picked is the Internet of Things: routers, cameras, thermostats and industrial controllers shipped with default passwords and no way to receive a patch.
Thistle sells the plumbing device makers skip: secure boot, secure update and a modern security architecture they can drop in and forget. True Ventures put in a $2.5 million seed round in April 2021, the platform launched publicly in February 2023, and in September 2025 Infineon paired its OPTIGA Trust M security chip with Thistle's Secure Edge AI offering to add hardware-based protection for AI models and data. At Embedded World in March 2026 the company announced Secure Edge AI support for Qualcomm-based modules.
"She's trying to change the whole industry," Aitel said, "the industry of those stupid routers that we all have, and they have no security update, and we never thought they would."
Window Snyder: Security Built In, Not Bolted On
Snyder's career is the clearest argument there is for building security into software from the start instead of bolting it on afterward. Her legacy, as Aitel put it, "is about changing big companies and moving big ships."
Today she runs San Francisco-based Thistle Technologies, still speaks plainly about how alienating the hacking scene has been for women, and has gone back to her old school to tell students that, after Choate, nothing was ever hard again.
The handle was RosieRiv, after Rosie the Riveter. The job turned out to fit: build it properly, then make everybody else do it too.
QUOTE:
"Amateurs hack systems, professionals hack people."