Caveat 3.20.25
Ep 254 | 3.20.25

Turning CISA’s recommendations into action.

Transcript

David Weissman: I think if we look at it from just an individual keeping their data private -- and by their data, because we need to talk about this more in a moment, I really mean, you know, what they're saying to people, what they're sharing. I think it's within reach. You know, I think the, you know, vast majority of people are, if they're already doing texting, you know, that they can use a messaging app.

Dave Bittner: Hello, everyone, and welcome to "Caveat", N2K CyberWire's privacy, surveillance, law and policy podcast. I'm Dave Bittner, and joining me is my co-host, Ben Yelin, from the University of Maryland Center for Health and Homeland Security. Hey there, Ben.

Ben Yelin: Hello, Dave.

Dave Bittner: On today's show, Ben discusses the U.K. implementing a new strict online safety law. I've got the story of a surveillance success for law enforcement in Baltimore and a new-to-me forensics tool. And later in the show, David Weissman, Vice President of Secure Communications at BlackBerry, is here to discuss making CISA's encrypted communications guidelines actionable. While this show covers legal topics and Ben is a lawyer, the views expressed do not constitute legal advice. For official legal advice on any of the topics we cover, please contact your attorney. [ Music ] All right. Well, lots to cover here today, Ben. You want to start things off for us?

Ben Yelin: Sure. So as we're recording, yesterday was St. Patrick's Day.

Dave Bittner: Right.

Ben Yelin: Across the, what is it, the English Sea?

Dave Bittner: The pond.

Ben Yelin: The pond. Yeah. I was going to say between Ireland and England.

Dave Bittner: Oh, that pond. Gotcha.

Ben Yelin: Yeah. I was going for a transition there that I just completely botched.

Dave Bittner: Sorry. Yeah, I hijacked it. My apologies.

Ben Yelin: No, no, no. You're all good. In the United Kingdom, a new online safety law went into effect. It is called the Online Safety Act. It forces big tech companies to detect and remove dangerous online content. The penalties are very significant if they fail to comply. So fines of up to 10% of global profits. And in extreme cases, the U.K. government reserves the right to ban that platform within its jurisdiction if there has been a particularly egregious violation. So what is prohibited under the Online Safety Act? Things you would normally think about that are illegal both here and abroad. Support for terrorism, child sexual exploitation, human trafficking, illegal drugs. But then there are things like animal welfare, so like abuse of animals that might violate the terms of service of some of our online platforms. But it's not necessarily one of the things that always gets taken down. And then there are some more legally gray areas. So extreme pornography. And it's kind of hard to define what that is. I know we know it when we see it. Harassment and/or controlling behavior. It also provides potential criminal penalties to social media executives.

Dave Bittner: Go on.

Ben Yelin: Yeah. And one of the hammers of this law is that if a decision maker with one of these tech companies fails to take down content per instructions in the law, they could be jailed. So in theory, Elon Musk, if he were to be jettisoned to the United Kingdom or extradited to the United Kingdom, and he refused to take down online content, he could potentially be jailed. So that's never going to happen.

Dave Bittner: Right. He'll just go to Mars.

Ben Yelin: Yeah. He'll get on a SpaceX rocket.

Dave Bittner: There's an extradition agreement with Mars.

Ben Yelin: So he will get out of there.

Dave Bittner: Yeah.

Ben Yelin: So this is a pretty extreme law. I mean, I'm not sure if a law enacted like this in the United States would necessarily violate the First Amendment. It would certainly come close. The U.K. doesn't have a First Amendment. They have more latitude to restrict free speech.

Dave Bittner: Right.

Ben Yelin: Elon Musk himself is an important player in this story because he hates this law and has been criticizing it. And he's made enemies in the U.K. government. And has accused them really without evidence of like child sex trafficking or I guess covering up evidence of child sex trafficking on the part of the elected Labor government.

Dave Bittner: Yeah. I mean, that's kind of been in his playbook before. I remember there was a -- wasn't there -- there was a bizarre story a few years ago about something with like a rescue submarine and like someone was trapped in a cave and Elon accused someone of being a pedophile with no evidence. You know, just --

Ben Yelin: It's his playbook. Yeah.

Dave Bittner: Swung it around.

Ben Yelin: Yeah. He'll always dial it up to an 11. It's just kind of his shock and awe strategy of everything he does in life.

Dave Bittner: Yeah.

Ben Yelin: Which I get. So what is going to happen now? Is Elon Musk really going to get arrested? What about the rest of these tech companies? What about users whose potential free speech rights are going to be violated in the United States if there's possibly subject to some type of extradition to the United Kingdom for violating the law? Interestingly, a deal could be in the offing because the United States is threatening to impose tariffs. I don't know if you've heard about this in the news.

Dave Bittner: I've heard something about that.

Ben Yelin: Yeah, not just on Canada and Mexico and China to a lesser extent, but also on the European Union and the U.K. So the U.K. government is hoping to avoid a 25% tariff on aluminum and steel. And that could be a leverage point for negotiation on enforcement of the Online Safety Act. Trump, according to the article from Ars Technica, which is going to be in our show notes, has been hesitant to publicly push for changes to the Online Safety Act. But he has apparently been in talks with the U.K. government hoping to reach some type of deal. I think maybe not Trump himself, but his team and particularly Musk see this law as Orwellian. And it's in Trump's interest to water down the law to the best he can. And he has this threat of tariffs as a way for him to gain some leverage. What analysts are saying, though, is that even if he does come up with a deal, it's really not going to be as drastic of a concession from the U.K. as people like Elon Musk would like. The U.K. government is not planning to offer a significant watering down of the bill as part of negotiations over tariffs. They've been even hesitant to interact with Donald Trump based on these tariff threats. It's also already the law. It's already being implemented. And they're in the process of introducing even stronger protections. So it's unclear if the threat of the tariff is enough of an incentive for the U.K. to drastically change this law. So I just thought it was a really interesting international story here. It certainly goes much farther than I think our constitution would allow regulations of online speech to go. And there are certainly risks of over-enforcement for something like this, taking down politically disfavored content, and using the threat of jail time or massive fines to censor online companies. But also, this is another -- somehow everything these days becomes an Elon Musk story. And I think this, too, has become an Elon Musk story.

Dave Bittner: So here's what I wonder. I'm trying to think of any of the major online platforms or providers that are U.K.-based, and I can't think of any. Can you?

Ben Yelin: I'm sure there are some, and our U.K. listeners are banging their heads against the wall.

Dave Bittner: Right.

Ben Yelin: But no, I don't associate any of the big tech companies we usually talk about with the United Kingdom.

Dave Bittner: So if that is the case, and that means that the big names are basically out of reach of the U.K., so your Elon Musks, you're Mark Zuckerbergs, who is this really aimed at? Like, who are they -- what's the next tier of people who might be U.K. residents that would be at risk here for not complying?

Ben Yelin: I mean, I think the biggest risk is that the platform would be taken down.

Dave Bittner: Okay.

Ben Yelin: I don't think a CEO is going to be -- especially in the Trump era -- is going to be extradited to the United Kingdom for the purpose of an arrest.

Dave Bittner: Right.

Ben Yelin: I'm not sure they'd even go after criminal charges anyway. It's such a drastic step.

Dave Bittner: I see.

Ben Yelin: But I think the ultimate threat is that the platform would be illegal in the app stores within the United Kingdom the way that TikTok was supposed to be illegal in the United States, and then we just didn't do that.

Dave Bittner: Yeah.

Ben Yelin: But I think that would be the enforcement mechanism. Again, just like the TikTok incident in the United States, you face the potential of a public backlash. There isn't as much democratic, small-D democratic accountability in the United Kingdom. The parliament can basically do whatever it wants. They don't really have a system of checks and balances the way we do. U.K. just had an election.

Dave Bittner: I'm sorry. You said checks and balances, and I couldn't help but laughing a little bit. Go on.

Ben Yelin: Yeah, right. Yeah. This is all in theory, of course.

Dave Bittner: Right.

Ben Yelin: And there's not going to be another election, a general election in the United Kingdom, until probably 2029. So they're in some ways kind of insulated from this. I'm sure they don't want to become unpopular, and if they start removing popular applications in the U.K., they're going to become unpopular. And sometimes it's like you don't want to get yelled at by your constituents when you're going to Harrods or trying to throw down my U.K. references here.

Dave Bittner: Yeah.

Ben Yelin: That might be a little out of date.

Dave Bittner: Going to the local football match.

Ben Yelin: Yeah, exactly. Or maybe a cricket match.

Dave Bittner: Yeah. I mean, is this a matter of having the big guns but hoping to never have to use them? You know, kind of a nuclear weapons kind of thing where we've upped the ante here for the things we can do to you, so don't make us do that?

Ben Yelin: Yes, in some ways, but I think there could be some edge cases where we might see some significant conflict, where there's something that in the United States we would consider free speech, but the U.K. might consider harassment. One thing I think of is language used towards LGBTQ people.

Dave Bittner: Oh.

Ben Yelin: That's something that used to violate the terms of service in the pre-Elon Twitter. Now there's only one word you can't say, and it's cisgender. Try typing that on your Twitter account and see what happens.

Dave Bittner: Huh.

Ben Yelin: He's determined that that is hate speech.

Dave Bittner: Okay.

Ben Yelin: But everything else you can pretty much say. So misgendering people who are trans, anti-gay bigotry, all of that is now legal on X/Twitter in the United States at least.

Dave Bittner: Yeah.

Ben Yelin: And so it's possible that the U.K. could seek to remove content that they consider to be harassment, but that Elon and his fans in the United States might say that's just free speech. We are politically against transition or particularly transgender rights or whatever in the United States.

Dave Bittner: Yeah.

Ben Yelin: And that it's a live policy issue and that they shouldn't be censored for it. I think that's where we're going to see the conflict. And it's just like kind of a game of chicken, you know, who's going to fold first.

Dave Bittner: Right.

Ben Yelin: The U.K. will try and levy fines. Musk will resist. They'll try and take the platform down. Musk will rally his army of superfans to attack the U.K. government, and then we might end up at sort of a standstill. So that's kind of what I'm waiting for is just the first major mano-a-mano battle between X/Twitter and the U.K. over the Online Safety Act.

Dave Bittner: I wonder to what degree are these major platforms prepared for this because of the restrictions they already have, say, in Germany. You know, years ago, I remember somebody sharing the tip that if on Twitter you didn't want to see any Nazis in your feed, just set your location to Germany, and they disappear.

Ben Yelin: Right, because it's against the law in Germany.

Dave Bittner: Right.

Ben Yelin: I think there's certainly some overlap, but the overlap is not exhaustive. And I think when we're talking about particularly this language of harassment, that's where the gray area starts to become unclear. And things that might not count as harassment, according to the policies of the European Union, may qualify as harassment under the Online Safety Act. It kind of depends on how they choose to implement this law and where they choose to levy fines. But that seems to me to be the most likely point of conflict here.

Dave Bittner: Okay. All right. Yeah, that's interesting. We'll have a link to that story in the show notes. Again, some reporting from the folks over at Ars Technica. My story this week, Ben, came in a kind of a roundabout way. I was making my way, just browsing some things on Mastodon, and the great Orin Kerr came up on my feed.

Ben Yelin: For once, you were the one who found the Orin Kerr story.

Dave Bittner: That's right. So a well-known constitutional scholar and a person for which Ben is an ultimate fanboy, Orin Kerr. Where is he a professor, Ben?

Ben Yelin: He's now at Stanford University.

Dave Bittner: Okay.

Ben Yelin: And just a plea, Orin, if you're listening, please come on this pod.

Dave Bittner: We'll promote your book.

Ben Yelin: We'll promote whatever. He does have a new book out.

Dave Bittner: That's right.

Ben Yelin: We will promote.

Dave Bittner: I know our producer, Jen, is working on it behind the scenes to try to get him to come on to promote his book.

Ben Yelin: And we'll ask you the softest questions to prop yourself up. We'll do anything. Anyway, continue.

Dave Bittner: So the point of what Orin Kerr was sharing was highlighting a case in Baltimore from a few years back. This is from 2021. And it was basically a success story about surveillance. And I'll just give a little summary of what was going on here. Back in 2021, in March of 2021, there was some surveillance footage that captured a masked shooter arguing with a wheelchair-bound man outside of a little grocery store. The shooter pulled a gun from his vest pocket and killed the man in the wheelchair before fleeing with an accomplice. So detectives tracked the suspects using multiple surveillance cameras. And eventually, this led them to a silver Maserati with a temporary Virginia tag. Now, side note here. If you're going to commit crimes, drive a common car, right?

Ben Yelin: Yeah, that Maserati is going to stand out.

Dave Bittner: How many silver Maseratis with temporary Virginia tags could there possibly be in the state of Maryland?

Ben Yelin: Right. I mean, like --

Dave Bittner: One.

Ben Yelin: Yeah.

Dave Bittner: Right.

Ben Yelin: If you have a Honda Civic or something, you can really get away with it.

Dave Bittner: Exactly.

Ben Yelin: Yeah.

Dave Bittner: Exactly. So there was more footage from gas stations nearby and the University of Maryland Hospital that saw the movement of this silver Maserati before and after the crime. And so the police were able to track down a lead and they traced it to the car. But there was a witness who was able to identify the driver and name the driver who turned out to be the witness's daughter's boyfriend. Okay?

Ben Yelin: Quite a connection.

Dave Bittner: Quite a connection. All right. But the point is, we think we found our guy. They searched the Maserati and sure enough, this person's fingerprints are on the vehicle and GPS data confirmed that the car was at the location of the crime scene. And additional footage from the suspect's apartment complex linked him to the vehicle and the crime. So there was an arrest warrant issued and he was charged with first degree murder and multiple firearm offenses and had a jury trial that began back in 2023. So I say all that because there was a footnote in the case files that Orin Kerr linked to that mentioned something called a Berla warrant, said the police had used a Berla warrant.

Ben Yelin: Sounds like something that ChatGPT would make up, but it's actually a real thing.

Dave Bittner: So here's my question to you, Ben. Before I brought up the story, had you ever heard of a Berla warrant?

Ben Yelin: I had, just because I'd read, at least a reference to the article that's mentioned in the footnote here.

Dave Bittner: Okay.

Ben Yelin: Tesla Meets the Fourth Amendment.

Dave Bittner: Okay.

Ben Yelin: I don't think I read that actual article, but I saw a reference to that article. I learned about the Berla warrant.

Dave Bittner: So this was news to me. I had never heard of a Berla warrant. It turns out a Berla warrant refers to a company called Berla, who are a technology provider. They provide to law enforcement and the military, they only sell to those sorts of organizations, they provide forensic tools to plug into vehicles and gather all sorts of information. Because modern vehicles are gathering all sorts of information and storing all sorts of information. The obvious things that we would probably think about are GPS information. Where is this vehicle? Where has it been? When has it been from place to place? But there's a lot of other stuff that gets stored.

Ben Yelin: Music tastes.

Dave Bittner: Music tastes. If you have your phone connected with, say, your address book, all that gets stored.

Ben Yelin: Yep.

Dave Bittner: So you think your mobile device is locked down and encrypted, and it is, but you've shared a lot of information from your mobile device with your vehicle that the vehicle makes accessible to this sort of forensic tool. They provide hardware to be able to remove the storage devices from vehicles, to be able to then download the information into their forensic system. So being that you and I are kind of obsessed and fixated with this sort of hardware, I thought this is the kind of thing we need to talk about.

Ben Yelin: Oh, for sure. So I think it's a really interesting tool and a really interesting case. I think Berla warrants run into two potential constitutional problems for me.

Dave Bittner: Okay.

Ben Yelin: The first is that this could be somewhat analogous to Carpenter in that you're doing potentially long-term location monitoring. So in Carpenter, it was historical cell site location information. You could see where a person had gone over a period of, I think it was seven days in that case.

Dave Bittner: Yeah.

Ben Yelin: It's not the exact same thing because a person isn't always in their Maserati, although if I had a Maserati, I'd probably try and just live in there because it's so cool. Whereas you always have your phone in your pocket.

Dave Bittner: Right.

Ben Yelin: But at least it's similar enough that I'm wondering if any court that analyzes this would say that this is a violation of the Fourth Amendment pursuant to Carpenter, that a person should have a reasonable expectation of privacy in the whole of their movements over a long period of time.

Dave Bittner: Yeah.

Ben Yelin: Which is something that I think is at stake in this case. The other thing that comes up is the Kyllo case. So seemingly an unrelated case, I believe it was 1989, 1990, something like that, where law enforcement was using infrared technology to measure heat emanating from a house.

Dave Bittner: Oh, yeah.

Ben Yelin: And it turns out a person was growing marijuana and using heat lamps and they arrested that person who sought to suppress the evidence. And what the Supreme Court held, among other things in that case, is a person should have a reasonable expectation of privacy against the use of technology that's not generally available to the public. That's not something that most people would have, let alone know about. And I think that's particularly relevant here. I would say most people don't realize that this Berla warrant is a thing.

Dave Bittner: Right.

Ben Yelin: It is only a thing as it comes to cars, at least with updated entertainment systems.

Dave Bittner: Right.

Ben Yelin: But it is a thing.

Dave Bittner: Yeah.

Ben Yelin: And at least at this point, it's not well known enough that that might be a potential defense, that a person does have a reasonable expectation of privacy in that. This gets really circular because if Orin Kerr publishes 10 more articles about Berla warrants and there are Supreme Court cases about Berla warrants and law review articles about Berla warrants, then people might actually have kind of constructive notice that this type of warrant exists.

Dave Bittner: Right.

Ben Yelin: But that hasn't happened yet. So I think that could potentially be a viable defense in a case like this.

Dave Bittner: Does it put your mind at ease at all? Because for me, it did. The fact that the word Berla was followed by warrant, that the police are getting warrants to execute this type of forensics.

Ben Yelin: Are they getting warrants? I guess it is a Berla warrant, right?

Dave Bittner: Yeah.

Ben Yelin: So they do have to get judicial approval to get the warrant. Yeah, I mean, that certainly makes a big difference. I feel like there's going to be some case where there's an exigency or where some law enforcement agency doesn't have the type of probable cause they need to secure a warrant so they use an administrative subpoena. And that's when it's going to become a live issue. You're on much firmer constitutional ground if you do end up getting a warrant.

Dave Bittner: Yeah.

Ben Yelin: But the type of surveillance still exists, right? So I feel like there's going to be some case where a warrant isn't issued pursuant to probable cause. And that's where we're going to see a clash of Fourth Amendment case law and these constitutional issues.

Dave Bittner: Yeah, it's interesting. The folks over at CyberScoop did a story on the company Berla, who, by the way, is right up the road from us. They're in Annapolis. They're a Maryland company.

Ben Yelin: Very Maryland-centric story here.

Dave Bittner: That's right. So CyberScoop's story talked about how Berla partners with the automotive manufacturers and in exchange for providing the automotive manufacturers with security consulting, the automotive manufacturers ensure that the data will be accessible by law enforcement. So it won't be encrypted on the device the way that, for example, Apple says the data is encrypted and so not even we can access it. The deal that Berla has with the auto manufacturers is we'll give you security consulting. Please don't make this data inaccessible.

Ben Yelin: It's frankly awesome for law enforcement across the country.

Dave Bittner: Right.

Ben Yelin: I mean, you can see why this would be a very, very promising tool. Again, it's a somewhat limited universe. I drove here in a 2012 Honda Fit. I don't think you could glean much from my entertainment system.

Dave Bittner: Right.

Ben Yelin: Except maybe that my USB connection is very shaky sometimes.

Dave Bittner: That's right.

Ben Yelin: But it's going to become more ubiquitous as these entertainment systems get more sophisticated, as more people are buying, as President Trump called it, a car run on computers.

Dave Bittner: That's right.

Ben Yelin: So I do think this is going to become more of an issue. And I think it's just a fascinating issue.

Dave Bittner: I would say my favorite iPhone accessory is my car.

Ben Yelin: Totally. I mean, it's extremely useful when you connect your iPhone to the car.

Dave Bittner: The other thing I'll just add to this, in the CyberScoop story, they had a quote from Berla's CEO. His name is Ben LeMere. He was talking about the partnerships with the automotive manufacturers. And he said, it's been kind of nice. It's been kind of a double-edged sword when we give presentations and everyone is immediately scared to death and doesn't want to plug anything into their cars ever again. But hopefully you guys aren't going to murder anybody. So it'll work out now. Yeah, I'm going to give Ben the benefit of the doubt here and just say he's being a little flippant and he's making light of the situation. But inherent in that statement is the, you know, hey, if --

Ben Yelin: Got nothing to hide.

Dave Bittner: Right. Why do you care if we come look around at your stuff if you got nothing to hide?

Ben Yelin: That always raises the hair on my arms.

Dave Bittner: I'm sure it does. I'm sure it does. Well, like I said, this was interesting to me. I did not know that this technology existed. So we'll have several links to this story in our show notes. We'll link to Orin Kerr's original mention of it, the story from CyberScoop, and then a link to Berla themselves if you want to check out the company. Looks like they have some very interesting offerings, like I said, for law enforcement and the military. All right. That is my story this week. And of course, we would love to hear from you. If there's something you'd like us to consider for the show, you can email us. It's caveat@n2k.com. [ Music ] Ben, I recently had the pleasure of speaking with David Weissman. He is the vice president of Secure Communications at BlackBerry. And we were talking about some of CISA's encrypted communications guidelines and techniques to make that actionable. Here's my conversation with David Weissman.

David Weissman: I think there's two sets of guidelines, and they're both actually pretty pragmatic. So the first is for telecom carriers, networking equipment organizations. And the second is more for the general public. So maybe we kind of focus on that second one for a moment.

Dave Bittner: Sure.

David Weissman: And what they've really done is summarize, you know, the risk of Salt Typhoon, which is, you know, any typical phone call that you make, any use of SMS, whether for communicating with someone or using it as a tool to validate identity is at risk at this point in time. So they recommend that people move to encrypted applications, end-to-end encryption. For the general public, they recommend, you know, using some of the popular, you know, free applications that people are aware of, things like Signal, WhatsApp, those types of things. And then they also give guidance on, you know, what are some basic security configuration settings you should put on your phone, whether you have an iOS phone or an Android phone. And so, you know, I think what they provided is very consumable for the most part. There's some areas getting into authentication that, you know, maybe you probably need a bit more of a tech background to really understand what they're talking about. But for the most part, you know, they're providing a solid advice that I think, you know, the typical person on the street can take advantage of.

Dave Bittner: Yeah, that's what I wanted to dig in with you a little bit on. I mean, from your perspective, how achievable is this for folks who are, you know, just going about their lives, trying to keep their messaging private? Are these apps within their reach?

David Weissman: I think if we look at it from just an individual keeping their data private -- and by their data, because we need to talk about this more in a moment, I really mean, you know, what they're saying to people, what they're sharing. I think it's within reach. You know, I think the vast majority of people, if they're already doing texting that they can use a messaging app. And I think by doing that, you know, that they are increasing their own levels of privacy for their information. But at the same time, they need to be aware of, you know, it's a public system. Anyone can sign up. You still need to really think about how do I know for sure who I'm talking to? Is that really the right person? You still have that risk. You had that risk before. And also it's free. So what's the cost? Well, the cost is you're giving up control over your communications metadata, who you're communicating with, you know, different sets of information about yourself, even though they're protecting what you're actually saying. There's a lot of information around that.

Dave Bittner: How do you recommend that folks go about choosing what app they want to use here? I mean, I think for a lot of folks who are coming from just regular text messaging, SMS messaging on their phone, which is sort of effortlessly cross-platform and interoperable, not all of these platforms talk to each other.

David Weissman: For the most part, they don't. That's starting to evolve. There's some new regulations coming out of the EU that are, you know, pushing these applications once they reach a certain size. They have to support interconnectivity between the platforms, but that's a new emerging area. You know, I think it's going to still take a few years to see how that plays out. But I think for most people, the answer to the question which one should I use is, which one are their family members and their friends already using. And I think the other thing to think about is you probably want to segregate what you might use for business from what you might want to use personally, just as a good data hygiene technique to one, just keep yourself from, you know, accidentally sending things to the wrong people. But also keeping, you know, your business information, your company information separate from your personal information is just a good practice in general.

Dave Bittner: Yeah. How about people protecting themselves from things like identity spoofing, deepfakes, things like that? Any recommendations there?

David Weissman: Yeah, there's some in the CISA guide that really have to do with authentication techniques and using things like, you know, hardware devices. And that's what that's the part of the advice that I think the vast majority of people are going to find difficult to act on. Now, the part of it is, hey, don't use just a simple text message for authentication. You know, so there are, you know, I think people are becoming more comfortable with authentication apps where you scan the QR code, you get a two-factor authentication. But a lot of times that's driven by -- it's not necessarily the consumer's choice that's driven by the website or the application that they're using. But that's still the biggest risk, I think, that people are still exposed to. The end-to-end encryption does a lot to protect the privacy of your data. But the more people start to use these applications, the more exposed they're going to be to spoofing attacks. I think, you know, even if you use popular apps today, you know, you get messages that says, hey, you know, I found your number in my book. You know, who are you again? Or, you know, something along those lines. Those happen even in these encrypted applications. So that's a risk. And then the other risk is, particularly with the Salt Typhoon and the information that's already been exposed, when you use AI techniques, it's now going to be, even going forward, it's going to be easier for these to be very compelling. And what I mean by that is, if you want to target a particular person, the data is available to identify what are their communication patterns, who do they typically message, what time of day might they message these people. And if you're trying to do an attack based on that, if you mimic those patterns, the person is going to be much more open to accepting that I'm really talking to who I think I'm talking with. And then you layer on the next level of that, which is since the Salt Typhoon was able to actually read SMS messages, actually listen in to voice calls, that data is there forever now. And people don't really typically change their phone numbers. You know, if you have someone's number, it's probably going to be good for a decade or more.

Dave Bittner: Right.

David Weissman: And so since the data was already there, the AI models can take that and not just the when you engage and who you engage with, but the tone of your message that, you know, how do you text, right? Or, you know, your voice that sounds like you if you leave a message. And all of these things mean that people are just going to have to be much more skeptical, if anything seems off at all, that they're communicating with who they think they are. And that's something the advice of moving to an encrypted commercial app doesn't really help with.

Dave Bittner: I wonder, too, you know, if we all if we need some sort of a buddy system here, you know, particularly I think about my own elderly parents and how much they rely on me and my siblings and their friends to just check in with on these things. You know, hey, does this seem real? Is this a bill I need to pay? Is this a message I should return? Those sorts of things. It seems to me like you're much better off not trying to go at this alone.

David Weissman: Definitely. And unfortunately, you know, you know, elderly people, people with certain disabilities are more susceptible, I think, to these to these type of attacks. And a lot of times they're targeted for financial crime, particularly. You know, you read cases, you know, hey, your kid's in the hospital. They were in a really bad crash. Need to send some money right away so the doctor can take care of them.

Dave Bittner: Yeah. Where do you suppose we're headed here? I mean, this is always a game of cat and mouse, right? You know, the good guys adjust and the bad guys pivot in reaction to that. People embracing encryption here. How do you suppose we might see the bad guys adjust to that?

David Weissman: You know, I think they're going to double down on two areas. One is the spoofing and the smishing and all these types of identity attacks. And in fact, that's been the most popular technique to date. But now it can be even more effective. Some of these new attack tools that are being done and the data from those and how it can be generated. But second of all, I think the focus on harvesting the metadata around the communications and using that for, you know -- if you think about a lot of these popular messaging tools, they know a lot about you. And now there's whole new sets of area beyond just the telecom carriers that could be mined for that information. And with that information, I think they're going to come up with new creative ways, whether it's to extract information, extract, you know, money or whatever their goals are from people. So as you mentioned, it's kind of cat and mouse. But I think maybe the focus of it changes a bit to, okay, they know we're in the carrier networks. Now let's go to these other platforms and see if we can attack those platforms.

Dave Bittner: You know, as we head into this new year and we're getting a new presidential administration coming in, do you expect there to be any big changes when it comes to these sort of things with the second round of a Trump presidency?

David Weissman: You know, I think that some of the work, for example, CISA is doing in the U.S. is fairly independent of the administration. I mean, this is practical type of advice that, you know, I don't think it becomes a very political topic per se. So in that aspect, no. But the other aspect of it is I do get a sense that from a big tech or social media perspective, that the incoming administration has a different viewpoint on how those should be regulated, you know, what rights they might have to the information. You know, there might be changes to opt in policies around data protections. So I think it's going to be more how the oversight of the actual media companies, the social media companies, the communication companies, that's going to change more than the advice that is being given to the general public and how to protect themselves. [ Music ]

Dave Bittner: So interesting conversation, huh, Ben?

Ben Yelin: I think it was a really interesting conversation. One thing I thought was particularly interesting is how so much of this is about future expectations and methodologies of threat actors.

Dave Bittner: Yeah.

Ben Yelin: So understanding what our enemy's next move is going to be and then making our defenses agile against those potential threats. So I thought that aspect was really interesting.

Dave Bittner: Yeah, absolutely. All right. Well, again, our thanks to David Weissman from BlackBerry for joining us. We do appreciate him taking the time. [ Music ] And that is "Caveat" brought to you by N2K Cyber Wire. We want to thank all of you for listening. Our executive producer is Jennifer Eiben. The show is edited by Trey Hester. Our executive editor is Peter Kilpe. I'm Dave Bittner.

Ben Yelin: And I'm Ben Yelin.

Dave Bittner: Thanks for listening.