The Arc of Warfare – The Inevitability Curve EP6
Stuart and I ponder the long history of information being crucial in human conflict, how we got to where we are, and what the future of social and international conflict may look like.
Transcript
Hello, my name is Chris Blas, and once again, I am your host for another episode of The Inevitability Curve. In each episode, we take a particular topic and look back with an interesting guest on where we've been in this topic, where we are today, and where we're going in the future. Perhaps our guest today is Stuart Phillips, and Stuart and I have worked together for many years in cybersecurity.
Hey, Stuart, how are you doing? I'm doing great, Chris. Great to see you.
Good to see you too. So it's looking very Pacific Northwest, uh, behind you. Thank you.
I live in, uh, lake Stevens, which is a little north of Seattle, and today we're having a great fall day. It's raining and cloudy, you know, As one does. So you and I may have worked together in cybersecurity for many years.
Right. And since, uh, 1998, you know, when I joined Cisco and in all of those contacts, and for both of us before that, you know, there's contact with military organizations and helping them with security and helping private sector organization with security. And, you know, the, this issue of conflict of human conflict and how the lessons of, of all of human conflict apply today.
You know, whether today is your late nineties or the 2020s is a constant, constant topic. Right. And you're, you know, quite a military history buff and history buff in general, kind as I am is.
So let's talk back there a little bit. Right? So in recent, more recent history, without going back to Assyria this time, um, a hundred years ago, 80 years ago in World War ii, uh, most folks, certainly everybody in the cybersecurity world knows about Bletchley Park, right?
The information warfare that both the hacking of, um, of, of access codes, so they read the messages, right? And the manipulate manipulation of physical artifacts and people and things to give, uh, a wrong impression, right? Exceeding the wrong information.
Where would you like to start in the past in mapping into where we are today with, with information warfare and conflicts in general? Well, I mean, you bring up a really good point about, uh, you know, the enigma efforts and all the things, and a lot of it, you know, where there was a combination of human error and technology, right? And so what happens is you have German operators who are sending every message with the same couple words.
And, um, the, I will not repeat on this, you know, call, call. And the also the fact that they were able to create the bomb, the ability to create a, you know, very early computer that was able to decode it by trying thousands or hundreds of thousands of combinations, even though they did have a really good guess. But the advantage of the human error was that they were, had a place to start.
And it interesting because even today you have a combination of human error, which is people clicking on email links, people accepting in invitations for people who are not the person they think they are. And then you also have technology where now you have like the deep fake technology where someone can sound like your boss or someone can sound, you know, present themselves very realistically, uh, or what we're seeing at Reversing Labs where people are creating an individual malware package just for a single target, you know? So instead of 10, 20, 30 years ago, they would create malware and then email it to everybody in the world.
Now they're actually using AI to create a single crafted malware package just for Chris Blak, you know, and so you may be the only person to see it, and a lot of tools or the traditional tools that were like, have you seen this before? Is this in your antivirus type? Things like that, those tools don't really work anymore.
And so we're seeing a lot of, you know, changes in how these, you know, types of attacks. But the other thing that's been really interesting to me lately, of course, has been the conflict in the Middle East and also the, uh, Ukraine where we're looking at, you know, how drones and thermal sites and people riding an e-bike in the woods and coming up on a tank and being able to take it out with a handheld missile, and the, you know, the tank costs several million dollars, and that whole setup for that person costs $2,000. And so you see a huge distinction between these types of traditional military, you know, belief that, you know, having tanks, having big planes, having big missiles and all this kind of stuff makes you invincible.
And somebody coming along with a, you know, $600 commercial drone and dropping a hand grenade on, on, you know, into the cockpit of your $35 million airplane is devastating. And, but, but again, how much of that is, is some of that sounds similar to me, you know, the, the, uh, world War ii, the tanks and the, uh, forgetting the German word for the little, Uh, the pounds are false. Yeah.
Winds Are false. Yeah. Right?
Yeah. You know, so, and knowing where those are the, at the right time, you know, having the intelligence and information right, to get your, you know, asymmetrical advantage out out of is itself not a new thing. No, not at all.
I mean, all of these types of technologies, these advantages, we've seen them, you know, move forward. And that the challenge now is that how do you as a, uh, defender prepare for these things when quite literally the technology's changing quickly. You're seeing a lot of things happening that are unprecedented.
I mean, you in, uh, you know, Yemen, a place that you're familiar with. You have the hoodie shooting ballistic missiles. Um, you know, again, when I, you know, during the Cold War ballistic, only three or four countries had ballistic missiles, right?
And, you know, and when India got ballistic missiles, it was a really big deal. Now, apparently anybody with a tractor trailer can have a, you know, ballistic missile. So, you know, it's not as, it's not a, uh, you know, and again, it's, it's this idea that you could shoot missiles at another country, and there's really, you know, war doesn't break out like you think it's going to, you know?
Well, and, And following that path, Fred, and getting more into the cyber side of it, you know, so we recorded a text Wrong Gang episode this morning and got on the topics of, of mainframes, right? And for most of us in the IT world today, you know, we're, you know, DevOps and DevSecOps, I mean, these are words, words and terms and phrases. If we understand and we think mainframe is like, hang on a second.
But as, as we're talking about there, uh, there's, there's a lot to be learned from that. You know, mainframes were the mainframe platform, the mainframe environment, um, was a very solid and stable and secure thing. And today, mainframes, you and I worked at Unisys where mainframes continue to operate, you know, the entire global financial backbone.
Yeah. And they do that because they're doing things that in the, the broader IT world. Now, we kind of think are impossible, but that's the way they were built all along.
Yeah. And, and again, there's this idea, you know, uh, the centralized system with terminals that really don't have any type of capability on their own. And you see that now though, with virtual systems.
You see that with like, um, you know, systems that boot up, you know, you have a laptop, but there really isn't anything there. You boot up an image that comes from somewhere else, the image runs on your PC while you're doing your work, and then when you shut it off, it's gone. Someone breaks in your house and steals your laptop.
They don't have any of your secrets. So, I mean, that, that mainframe centralized terminals as dumb model is, is very heavily replicated today in a lot of this, you know, systems that do these distributed, uh, you know, deployments. And, you know, having everything in the cloud, which again, is just a computer in another state, um, is not, to me, it's really no different than a mainframe, right?
I mean, the way we, we dealt with mainframes, you know, uh, I think that the main difference now is that your ability to spin up these things is, is quite easy, right? Before to get a mainframe, you know, I would go, when I worked at network systems, we sold front end controllers and all that stuff, you know, back in the mid early eighties, uh, if you wanted to have your own mainframe, that was great, but it was gonna be a five year effort, and you needed a specialized building. Now you just need to go on, um, you know, Microsoft Azure and you have a credit card.
Um, you're good to go. You know, you can have a complete operating data center within a few minutes. Well, yeah.
Which plays right down my, you know, my favorite, you know, inevitability curve sort of thread. You know, the same thing as you said about ballistic missiles. If you have a technology at some point, and it's very exclusive for whatever reasons, if it, it can be made less exclusive, you know, then eventually it will.
Right? So you can think forward into that world and say, okay, by then we need to do what? And, and again, just in our, our, uh, you know, relatively short working, uh, careers, we've seen a lot of this.
While you can't ever do that, 'cause therefore you couldn't do X, Y, Z we're doing already, but we did it anyways. Right? And we find ourselves looping back to the those same, uh, uh, primaries, right?
Right. That, you know, we need to be able to do these things. And well, I think, I think it comes back to the exactly, it's the same idea, right?
That nothing, there's nothing new under the sun. You know, it's, I think that's in the Bible in the back somewhere, you know? Yeah.
Yeah. Anyway, um, but no, that's the idea that there is not, you know, these types of attacks are coming out. I mean, the, the type of email fraud attacks are just very simple.
You know, you know, people were doing that in the 1920s, right? What they were just doing it with e uh, with letters. They were doing it with, you know, then they were doing it with telegrams, and now they do it with email.
It's really not any different. The main difference is now you can, instead of sending 10 e uh, 10 letters a day, you can send a million emails, and then you could have each one of them individually crafted by AI to target the person that you're going after. You know?
And again, uh, human error is still the, the bane of, of cybersecurity, right? You know, the people that will click on things, uh, because they're afraid of getting in trouble. And again, that's company culture, right?
I mean, you know, I get a, uh, at Reversing Labs, we have this, uh, we have all Slack, right? We use Slack for everything. And we have a Slack channel called Mario Needs Help, and Mario's our big boss, and he is, you know, great guy.
And he, he, he, you know, a lot of people know him and talk to him. He's very, uh, he's very present, right? He's one of those, uh, CEOs who's always, you know, you're always talking to him in meetings, and he is always asking really relevant questions.
Um, but Mario needs help. You know, anybody who starts at Reversing Labs within a day or two will get a text message saying, Hey, this is Mario. I need you to go down and buy $1,500 worth of Apple gift cards for this customer.
We don't know who's doing it. We don't care that much. 'cause it never worked.
And the amount of effort to put into it, to, to try and find out who it is. So it's not like we're gonna be able, you know, like I always say, like, you can't really call the police in, you know, these countries and say, Hey, we'd like to bribe you to go arrest somebody. You know, that kind of thing.
So, you know, these people operate in corrupt countries and they have all this thing, and, but it's just a, it's just a thing. And then we, the way we dealt with it is very straightforward. We made, you know, made it really visible within the company.
So it's part of our new hire training. It's very clean. But again, it's also incredibly helpful that everybody knows what Mario sounds like.
Everybody's talked, you know, a lot of people, almost everybody in the company has talked directly with Mario, so they, they kind of know what to do and what they don't. You know? Um, I've worked at companies where I didn't really actually know who the CEO was and the idea that somehow they were wanting me to, you know, do something.
And we see that where people are just afraid of getting in trouble, you know? And they're more afraid of like, you know, somebody being mad at them for not paying a bill or versus paying a fraudulent, uh, invoice. You know?
And then that plays to me. Yeah. So we're talking about the present right now.
So that plays to some of my favorite buttons. Right. You know, and what you described to me sounds like a nice practical human, you know, human trust based solution, right?
Mm-hmm. You hire decent people, you expose 'em to the information, the people in this case, you know, that they need to be able to, to respond to. And you put the technology underneath that to support that.
But you're not basing it on, like you say, you have the fear of being fired for not doing something. So company culture, you know, it, so the Department of Energy and the, the, um, cyber informed engineering initiative, you know, has a term that I just absolutely love, which is radical transparency. Mm-hmm.
Which lines up exactly what, you know, I've been focusing on the last five years or so, the supply chain stuff, right? And you and I have talked this to death, and we're both working in companies that do that stuff these days. And it's just an exercise of the same things we talked about in 1998.
Like, how do you get trust with a market if in that case you're a big faceless company called Cisco, um, by personally doing it and doing things and demonstrating the trust and being visible about it and being transparent. And, uh, and it's not a trick, right? And in the current conflict environment, right?
You know, so everything from misinformation, disinformation campaigns, organized by nation states to influence demographics, and to your point, we, you know, now supported by AI to like, sound just like Iran. Um, you know, what do you do? Right?
And I personally, I think the, the answer is the same as in cybersecurity and supply chain and open source, you know, be absolutely transparent, right? To the people you should be transparent to in the ways you should be transparent to them. Um, yeah.
Yeah, I absolutely agree. And I think that there's a lot of, um, a lot of, a lot of it has to be able to, you know, organizations really need to be able to, uh, quickly respond to changes. And, um, you know, you and I still deal with companies that say, I have a five year, uh, planning cycle, you know, where, you know, we're not gonna be able to do anything for a couple years.
Um, I know like, you know, a lot of the traditional industries have, you know, planning cycles where they, you know, it's like, yeah, I know this thing where drones fly over the, uh, you know, the electrical plant. That's really, really bad. But we really don't have, you know, we can't really address that for like two or three years.
'cause we don't have, you know, now that we don't have the money, we just don't, you know, our methodology, you know, our planning cycle, our, you know, the, uh, security council only meets once a year, you know, that kind of thing. So there's a lot of, a lot of challenges within how companies respond and how are they able to, uh, react to these new types of attacks. But again, we've seen, you know, even in the last year or two with AI and how it's not, you know, it's AI is not smarter or better than us.
It's just able to do the same thing a million times over. So if I, if I'm able to grab a list of email addresses, I'm then able to have a chat GTP program that's able to look everybody up on LinkedIn, figure out, you know, what, what, you know, what kind of, what messages might be appealing to them, and then be able to send those emails. And I could do that in a day, you know, I can get that done, you know, I could be, I could be processing millions of them.
And then again, you know, one of the, uh, you know, you look at traditional, like, you know, I 1950s with the Russian spies, they would send a, a Russian who was, had been born in America, but grown up in Russia, so he had an American passport, and there were very few of those people. And then they would come to the United States, and they would be Russian spies, and then they would do spies stuff, and they eventually would get caught, and then they would be traded for, you know, our YouTube pilots and things like that. And now I don't really need to do that, right?
I can, uh, I can bribe, or I can pay for influencers in a certain country, right? I can literally go online and find influencers who will spout whatever messaging I wanna, you know, give. They, they are local, right?
They speak the local language. They, I don't have to worry about translation. I don't have to worry about, I don't have to send my agents to that country and worry they'll be arrested at the airport because it's, you know, a triple cross type situation, right?
I mean, I can, you know, countries now, like Russia, they can just sit back, pay American influencers to spout their lies, and they don't have any risk, right? What's, they're, they're not sending anybody here. If those influencers get found out, they, you know, may get arrested, they may get charged with tax fraud or some other types of crimes, but there's no risk to the Russians.
There's no, you know, the Chinese, you know, the North Koreans, the people that are doing these types of espionage programs, the traditional risk where, you know, this was gonna cost millions. It was gonna take, you know, all these things. Russia really did have a village that was an American town, and they sent their agents there, and their agents had to speak English only, and they had to drive American cars, and they had to know what an air conditioner is and, and, you know, and all these types of things, because that was the only way to get them assimilated into these countries.
And it costs millions and millions of dollars and took years and years. And, you know, you'd have an agent that you've invested years and years and years of training in, and then he arrives at the airport and gets picked up, uh, because of a problem with his passport. And next thing you know, the whole thing's a failure.
Mm-hmm. So I think, you know, the, the, the way that espionage is being done now, the way the fraud is being committed, there's very, very, there's significantly less risk to the people who are doing it than the way it was in the nineties, right? In the a, you know, when we we're not, we were dealing with criminal gangs.
There was a point where in Russia, you could call the Russian police and they would arrest people. Um, that time is gone, right? And then, you know, traditionally you had criminal gangs that were only interested in money and criminal gang, you know, and intelligence agents and government people, uh, you know, you and I used to do this.
We used to laugh at the Chinese spies because they would work like nine to five, right? They would start work in, they'd be in Beijing, they would start working at nine o'clock locally, and they would quit around five o'clock and they would take lunch. And so when we would look at the activities, we'd actually know, well, okay, based on where these people, you know, the time that they take lunch, this is where we think they're based.
Now this is all done by, you know, AI tools. It doesn't really matter, you know, when it's done, or it's just being outsourced, you know? And so they're, you're going on, you know, these, uh, you know, dark web, uh, mailing, you know, lists and, you know, and, uh, chat boards and things like that, and just hiring people and you don't really care where they are.
And so, a lot of this is, you know, uh, uh, the, the, the challenge, and again, this is just the disappointing part, is things are getting worse, right? I mean, the, you know, the, the risk of being attacked is a hundred percent, and the ability for people to attack you has Dr. Dropped dramatically, right?
So instead of us needing an army and, you know, $20 million to buy a tank and seven months to train somebody how to drive the tank, you can buy an e, you know, e-bike off of TMO for 400 bucks and, uh, you know, a little j and old Javelin missile, which, you know, has a half hour training video that you watch on YouTube, and, um, you know, you're good to go. So, I mean, it's a, a dramatic wr, you know, a dramatic difference in, in know, these types of attacks. Well, and before we get into, you know, uh, uh, even the near term future, much, much less longer, slaughter bots, you know, you remember that, uh, yeah.
Seven minute video put together by some concerned scientists. Oh, was that been five years ago or so now? Something like That.
Yeah. Yeah. And, uh, the, the premise for anybody who hasn't Googled have already, you know, is that terrorists start using drones.
Mm-hmm. And, uh, and, and social media identification information so forth to individually target, you know, uh, um, um, victims, you know, politically or, you know, you're posting on Instagram a certain way, uh, in a drone with an explosives coming after you. And what you're describing is, is perhaps we're getting closer to, or maybe in that phase already, right?
Yeah. I think it's interesting. You know, you think about, um, like in Afghanistan, our opponents there, um, used handheld radios, you know, commercial, you know, available ham radios or, you know, the type of things you can buy, uh, for $50.
And they used those because they did not have location based services, right? If you, you know, we have some in incredible, uh, electronic warfare devices, the, uh, airplanes that, you know, fly around recording everybody's phone conversation, tracking everybody's phone, doing all that kind of stuff. That gives us an incredible view of the battlefield if somebody's using a phone.
And so, you know, they shifted over to handheld radios. Uh, same thing with pagers, right? Um, I, you know, I, uh, took a police sciences course recently, and they were talking about if you catch somebody who has a flip phone, they are a hundred percent a bad guy right?
Now that's a generalization, unfortunately, just turns out to be true. You know, unless it's somebody's great grandmother, you know, people who carry flip phones have, don't not have location based services on them, and they're doing it so that it can't be tracked. So, again, you look at it for two types of behaviors, right?
One is, are you doing this, uh, for these reasons or are you actually a criminal? It's interesting to me though, that because most criminals are just stupid and do stupid things, and that's why they're criminals and they get caught. Yes.
Most of the people I know, thank God, right? Most of the people who have carried flip phone, I mean, you go to the Black hat or you go to RSA or some of these other shows, you'll see guys with flip phones because they're just convinced that the government is tracking them and they're really worried about it. And it's a really big deal to them.
And you can't really, it's not a topic you wanna bring up with them, right? You know, I, I never mention it because they'll just go onto this long rant about how the government is listening to everybody, and it's like, well, they are, but they're not interested in you. You know?
Um, they're interested. Are you not that important? Yeah.
Sorry. I mean, you know, um, you know, unless you're selling drugs or being a terrorist, they're not as interested in you as you might think. Well, you had mentioned, you know, Paige was, 'cause you had to go there in the, in the current tense.
'cause we're, you know, this summer, right? You know, just recently, you know, we all know every there in the world, you know, the supply chain attack against pagers and then walkie talkies, you know, in the Middle East, you know, presumably, you know, uh, affected by Israel, which makes perfect sense. And it's, and you know, I mean, you know, this digital bill of materials thing, you know, that you and I have been talking about since 2019, right?
You know, this is exactly the kind of use case I like running through. And, you know, five years ago it was a bit, you know, you had to scratch your heads. You had to go to Scottish, you know, the National Manufacturing Institute of Scotland to find folks who can really speak to the idea that I may need to know what software was running on the machine tool that made an individual part, like say a battery, you know, this physically inside some device.
I need to know that right now. Right? Um, this is a demonstration that those, it's not just about software security because I would, you know, you talk about you're sending something into space.
I may want to know who made the plastic case at a level of no. That I would can use to put things in space. And we have to build those systems.
It's interesting because, uh, you know, we always talk about the insider threat, right? You know, if you are a criminal, right? And you are, your intention from the beginning was to commit criminal acts, you are the hardest person to deal with it when the organization, right.
You know, if you are an active criminal, sending you to the class where you learn about what emails to click on isn't really gonna help the situation, right? Um, and so, you know, you see this idea that, you know, I can trust but verify, right? How do I know if someone has done this?
I mean, reversing labs, we have comprehensive supply chain, uh, security tools that will actually deconstruct a file. And the main reason being is I can't necessarily trust you if I, I, I'm, and I'm, I I love you like a brother, you know that, right? But if it's my job, I can't say, Hey Chris, we're buying this phone from you.
999% of the time, that's fine, right? The challenge is, what if you don't send me the right software, or you're a criminal and you intentionally send me the wrong software without the malware on it. And when I get the phones, they all have the malware on it, so I can't trust you.
I love you, but I can't trust you. And so I have to, um, I do have to check it myself. I do have to deconstruct the software as it is not as I want it to be.
Or, you know, Hey, send me your, your files and the link to, you know, your Python repository, right? That is, that doesn't really help. I need to see the actual software.
So being able to take the software, deconstruct it with like our assure tools and things like that, that allows you to have a hundred percent confidence in this. And I think the thing that I don't understand, and again, I I will, I will just say this, and again, there's many, many things that you, and I know that there are a lot of lies told by everybody in this industry, right? You know, vendors lie, customers lie, governments don't necessarily represent what happened for various reasons.
And so, you know, we hear the story of these pagers were made in Hungary. They, or, you know, they were made somebody set up a company 15, you know, all that stuff. And, and, and, and as you know, sometimes we're in the deal, right?
And we go and watch tv and you go, that's not what happened, man. Um, I was there, I was in Korea on that day when that attack happened. And that's not what happened.
And it doesn't matter because that's the story, right? That's the story they're gonna go with. So you have to deal with that.
But I find it really hard that nobody, you know, if you received a couple thousand pagers, no one took one apart and looked at it. I mean, is, and, and, and again, if that's true, that's in incredible level of incompetence. You know?
And you know, the idea that I, you know, hiding a piece of plastic explosive and some ball bearings and on inside a pager, I had a, I carried a pager for a long time, right? I was a field engineer and, you know, get pager paid, which I really missed by the way. Um, you know, I could, I knew which pager was mined by how much it weighed, you know?
And, uh, I think that, you know, um, I think it's, it's really hard to understand that what happened there with the idea that somehow these were bought, acquired, distributed in high, in, in, in active use, and at no point over this period of time did one break, and therefore somebody had to take it apart and look at it, or the battery died and somebody took it apart and went, wait a minute. Why is there a little bit of plastic in here with some ball bearings? They just don't understand that.
And that's, and that's and interesting because, but again, having gone through all of these types of things, um, you know, we know that there, the story about what really happened and what didn't happen, it usually comes down to either laziness of corruption. Yeah. I, I, I love that you mention, you know, criminals are stupid, you know?
'cause I, I can't tell you how often I use that because you have to understand, you know, that the, the, you know, evil mastermind from Hollywood, you know, who's got the big brain bigger and everybody else, and, and for some reason invented teleportation, decided not to just get rich on that, doesn't exist. Right. You know, usually people making bad choices are making bad choices 'cause they're not thinking about everything properly.
Right. And we can call that stupid if we want because it works, right? Well, Again, you have, um, you have your two basic types of criminals, right?
You have your typical career criminal who's very much used to going to jail, and you have your, uh, you know, I have, I have friends that are like parole officers and things like that. They, they say there's two types of criminals, right? The one that was never expecting to get caught and is scared to death of going to jail again.
You know, the person has a, like a DUI or criminal DUI or you know, did a little bit of time and now he's just absolutely terrified and shows up early to their parole meeting, you know, and all that kind of stuff. And you have your career gang member who's been and outta jail since he was 11, and is just isn't comfortable in jail as they are at home, and doesn't really, you know, for, would prefer not to be in jail. But the idea that, you know, they're somehow not gonna be a gang member is just crazy.
They, they're, they're gang members, their whole identity, You know? So we, yeah. So with all this, anyways, let, let's look out in the future, right?
You know, so I, you know, I have a ongoing po I keep saying that I can't see a medium term to distant future where some of these problems still exist and not because, you know, morally or ethically, you know, we all love puppies or whatnot because you just can't keep the lights running. You know, we need these systems to, you know, work at a high fidelity to the point that, you know, mainframes, you know, have been working for the last 50 years. Mm-hmm.
Um, but, you know, a much more complicated, much more distributed environment, right? It requires and calls for the kinds of structures that, again, I, you know, I think folks like you and I have a good idea, right or wrong, exactly what they are. But, you know, once they're done we'll, we'll be able to look at it and say, aha, that's how that works.
Right? Right. Makes all this stuff a lot of harder everywhere from the nation state level.
And just to, to seed that, so David Bryn, right? The science fiction off, uh, author was at RSA in San Francisco this, uh, this year. And in the text wrong booth to hang out with him for a bit.
And in one of his favorite books of mine, uh, killing People, one of the basic premises is that crime and, and particularly, you know, complicated, you know, uh, a conspiracy is really, really, really, really hard to the point that it almost doesn't happen anymore. And I, I think that is the direction we're going, how long it takes to get there is a big question. Yeah.
I, I, I, you know, again, I think that the challenge is going to be how quickly can these, uh, organizations adjust to these types of things? We're, we're starting to see people now we're, you know, we're dealing with customers who are saying, uh, before I would only check one or two software packages that came into the company. Now I wanna check everyone.
And, you know, and again, if you and I were, I mean, honestly, you and I have been around doing this so long. I remember you and I going to like a, uh, can't remember what bank it was, but the guy was like, why would we need a firewall? We're never gonna connect to the internet.
People like going to the bank who let, like guy, I remember that guy was like, who let you in here? Like, you know, why, why are we having this meeting? We're never gonna, you know, internet banking, are you crazy?
You know, banks are judged by how many branches they have. You know, that's the most important thing. Uh, you know, even, uh, even when ATMs and things were coming along, it still was, uh, the idea that somehow there was a, uh, you know, it was not gonna be something that people really wanted.
Right? Why would you wanna take money out after the banks closed? That's crazy.
You should have planned ahead. Well, And, and, and to our topic, well, here, you know, and, and I think I have these conversations all the time, basically, you know, anonymizes, but, you know, generalize it. But it's something executives saying, you know, what, you, what do you mean?
You know, my employees can't make most, most of the decisions about, you know, their, their work responsibilities by what they generally pick up on the internet. Right. You know, because that's, you know, to your point about, uh, um, your, your boss, your CEO and so forth, and that, you know, that process you have with employees, it's generally works, right?
Yeah. Works. It's not very scientific works.
I mean, it generally works in until it doesn't anymore. Yeah. And I think, I think you have to, you know, the, you and I were down in, uh, in Columbia Meine, right?
Uh, before the pandemic and so forth. Don't talk About that. No, just kidding.
Keep Going. You know, as I was, I, I said the public information was public, public Information. Uh, Yeah.
Only Ever shared on this Channel. Why didn't we go by canoe? That's what I don't understand.
Right. I should have taken Mark Twain is another topic. But, but you know, in that time, we working with those folks that, uh mm-hmm.
National infrastructure and so forth, and looking out over periods of time, you know, that 25 year plan, right? You know, we're right at about seven years in right now, that seven and 15 years where the sort of break points where we said, you know, by this point, you seriously need to be thinking about, right. These issues.
And one is, you know, how do you really know when you're turning the power off and on, you know? Right. It's, it's gotta be, there's gotta be systems of automation and transparency that don't exist yet, but will exist by then.
Right. And they, and they do. Right?
And you look out, you know, that next, you know how much 18 years on that, on that roadmap, right? And I think that we and the people, you know, involved in that and similar efforts are, are right. You know, to your point, in 15 more years and 18 more years, we're gonna be living in a slightly different world, right?
Where we will have, have had to adopt certain parts of that transparency and clarity, right? Just so we can live in, in conflict environments, Right? And I think it just comes back to experience, right?
I mean, I, like many, many people in the cybersecurity world thought that, um, Russia was going to be able to attack Ukraine and launch a massive cyber Pearl Harbor and wipe out everything and turn all the power off and turn off all communications, and it would just be completely dark and their phones wouldn't work and everything else like that. And it turned out none of that happened. And that the turned out the Ukrainians, because they had been actually experiencing this for years, were very good about defending themselves, right?
And I know a lot of people have been to Ukraine. I know, uh, some of our mutual friends have worked there and tell stories and stuff, but they have, uh, you know, Ukraine was able to turn around their situation. And when these Russian attacks happen and they happen every day, thousands of times a day, they were able to dramatically defend themselves quite well because they had experience, right?
And that's the thing, that's the difference between a lot of these organizations. I think that they should be looking to guidance from people that are having these types of, uh, you know, incidents happening and using them to predict what's going to happen in the future, rather than what they did 10 years ago or what they did 20 years ago when they worked at the NSA, right? I mean, that's, you know, and that you look at, you know, when we look at cybersecurity, some of the best cybersecurity setups are by people who run commercial Minecraft servers, right?
Because you have your own private Minecraft server, you sell that to, to people who are really into Minecraft, who wanna have their own, you know, landscape or world or whatever you call it. And people in the industry will try and knock yours down. Uh, so the, when we look at people who are very good at defending their infrastructure, you know, you wanna look at somebody who's getting attacked every day and doing wallet defending themselves, right?
If you look at the situation in the Middle East where you have hundreds of missiles being fired and hundreds of missiles being shot down, that's incredible, right? That was, that is just science fiction, right? The idea that somebody could launch a hundred, you know, I mean, all those, you know, diagrams, you know, the, the, the Iranians have so many missiles and you know, this is what you need to worry about.
And then they fire most of them and it costs them billions of dollars to do that. And very few actually get through. And, you know, and again, it's a terrible thing.
It's a tragedy. It's absolutely the worst thing in the world. But if you were looking to defend yourself, you would look at something like that and say, okay, how did they do that?
Right? And the same thing you wanna look at, you know, so you look at people who have high level of competence, competence, and at the same time have a high level of ex, you know, direct experience in doing these types of things. So when you're reaching out to, uh, security organizations or looking into with different groups and things like that, you just want to be talking with somebody who's actually done it, right?
Who's actually run a, you know, a system and been under high attack and successfully defended themselves. And now those people are rare and they're hard to acquire, but you should listen to them. You don't, they don't necessarily have to work for you, but you can go, you can, you know, listen to them.
You can listen to people like yourself who have had this experience and have gone through, but you just have to open up and say, you know, what are we trying to do? We're trying to defend our organization. We can't trust anybody.
We need tools that can, uh, do this. And we need policies and procedures to effectively use those tools. 'cause even with the best tools, if you don't have the skills to use them or the ability to use them, uh, that's where you get into the frustration.
And everybody I know who's left cybersecurity, and I'm sure it's the same with you as well, has left because of their frustration with their organization, right? Hey, I, we had a meeting about this six months ago and I told you this was gonna happen, and you know, you told me to shut up and go back to work, or, you know, we needed to work on our, you know, are we done with the budget? Yeah.
We had to, you know, we can't, you know, we can't, uh, we can't go back to our bosses and say we were wrong. We, you know, we can't change may ask for a change in the budget 'cause it'll make it look like we don't know what we're doing. And the reality is, you should be almost fluid.
Like wake up today and say, what are we gonna do? And, and you know, the difference, again, you used to have criminal gangs who were trying to steal money, and that was really straightforward. And then you have government organizations now before you had to steal money and print fake credit cards and hire people locally to go and, you know, cash out crew and go into the local mall and buy TVs and jewelry and things like that.
And then, you know, it would only work for like 20, 20 hours maybe. And after that, the credit cards were no good. And you have to start over.
And now you have crim, uh, you know, bitcoin and cryptocurrency. Now that's very fluid and you know, harder to track and very, you know, easy to do. And then you have a rise of like, you know, North Korea where they're actively stealing money, right?
The biggest cr you know, heist crimes, the bank robberies that if you wanna say in history are done by employees of the, you know, north Korean government, you know, who probably wear a uniform to work, but at the same time they're stealing millions of dollars because they're using it to fund their own country. Right? How long ago there were, that is science fiction, right?
That, you know, 20, 30 years ago that was, I mean, you know, you read Nor Manser, right? The idea of winter moot, and you had the idea of an AI that escaped and went and lived in Antarctica, and that was, you know, and was, you know, hiding from people. That was incredible.
That's as real today as anything you want. You can spin up your own organization, uh, uh, you know, hide it, have, you know, put it, have it running on servers in another country, never have any physical access to them. And the only time you get caught is when, you know, you get tricked into, Hey, Chris, you've won a free trip to Crete.
You know, you wanna come, you wanna come to Cyprus? We wanna a conference. We do come to, and when you land there, there's two FBI agents waiting for you.
Right. You know, it's, that's the, you know, the, the only way that you get caught now is by being tricked, you know? And, you know, but, and the cost of doing that, I, you could do that for $10,000, right?
And, uh, you know, there are countries in the world that don't have jet fighters, but have cyber warfare groups that are very effective. Yeah. And then when you have a merging of that with corrupt government officials who are using this for disinformation, uh, you know, you know, things that have happened in some countries, um, it becomes even worse, right?
You have, you know, it becomes a, uh, uh, a situation where we see that in, uh, where, you know, we have, uh, news people, you know, journalists who get arrested by the government for telling the truth. And so now you see, you know, news organizations actually having virtual, uh, journalists, right? You know, it's an AI representation of a journalist reading a news story story because all of their, you know, otherwise the government guys are gonna come over and arrest you in the middle of the night at your house and no one's gonna see you again.
That, again, it's science fiction, but now it's just as real as can be. And the resources for that are not, I don't need a, a a hundred million dollar, you know, plant and, you know, several top scientists, PhD, AI guys, uh, I can go on App Sumo and, you know, buy something for 90 bucks and it'll do what I wanna do. You know?
So it's just, you know, again, it's just a different world. It is. And we're living in it, and we're moving into, uh, yet another one.
And I wish we had more time, we could do this stuff, uh, until the cows literally come home. So let, thank you for your time today. Thanks for decades of being a good person, good friend, and, uh, everything you've done to help make the world a slightly better place.
Well, thank you. And again, thank you for being able to give me a platform to rant for a little bit, but it, uh, and then be these types of ideas. But I think the main thing again, is that while things are bad, you know, you and I go to these security conferences and it always, it is always doom and gloom, right?
End of the world. This is all terrible. And I'm like, no, no, the lights are on, right?
The right, the internet is working. Um, you know, there's, you know, if, if things are so terrible, then why, why is everything just, you know, as good as it is, right? Global hunger is moving down, it's Global poverty has been halved in our lifetime, right?
You're talking about a billion people moved out of poverty. Uh, that's incredible. And again, it's done because of technology and because of people that really wanna make a difference, but also because of, you know, free markets and capitalism, being able to say, you know, if we raise these people up, then maybe they'll buy, you know, cars.
So, you know, let's do, let's do that. Okay. So again, it's this idea that, you know, things are not that bad.
I mean, just you, you do have to be more flexible and, and be a little more fluid and, and things like that. But that's just 'cause of the way things are, you know, the technology is evolving, but the defenses are evolving just as quickly. And again, it's your ability to be able to use them.
So get some good people around you and get some, you know, get some good on training and get some transparency. Get a few, couple good tools, learn how to use them and take advantage of them. And, you know, everything will be reasonably good.
I agree. Well, thank you again. Thank you out in the world for spending some time with us today.
No problem. Look forward to seeing you again on another episode. Absolutely.
You have a great day. You too. Bye folks.
Bye.


