Special Editions 5.10.26
Ep 96 | 5.10.26

CyberWire Daily at 10: The evolution of geopolitics and warfare.

Transcript

Maria Varmazis: Hello. Maria Varmazis here, and thank you for joining me today. The party is still going strong for our celebration of 10 years of the CyberWire Daily. So, in today's N2K CyberWire special edition episode, as we look back at 10 years of the CyberWire, I am, of course, chatting with Dave Bittner, host of the CyberWire Daily. And in this chat, we are talking about the complexities of geopolitics and warfare as we look back on the last 10 years of cybersecurity headlines. Well, it is my distinct honor yet again to bring back Dave Bittner, host of the CyberWire. Hi, Dave!

Dave Bittner: Hello. Good to be back!

Maria Varmazis: Yes. Imagine, we're talking to you today, of all days, about your show.

Dave Bittner: It's Maria, right?

Maria Varmazis: It -- yeah. Nice to meet you.

Dave Bittner: Nice to meet you. Pleasure is mine.

Maria Varmazis: I appreciate that, Dave. And the occasion that brings us together is, as we've been covering for quite a little bit now, the 10-year anniversary of the CyberWire Daily and all of the incredible stories that the show and you have been covering over the last decade. And for our chat today, we're going to take a focused look at geopolitics in the last decade as it relates to cybersecurity and the many, many stories in that realm that you have taken a look at in that time. So, gosh, to start to cover geopolitics, I think a few things have changed in the last decade.

Dave Bittner: One or two.

Maria Varmazis: Just a few. I mean, 2015, 2016 was a millennia ago.

Dave Bittner: I know. Well --

Maria Varmazis: Not literary but kind of.

Dave Bittner: Yeah. Well, I'm still battling the reality that post-COVID time has no meaning. But I really enjoyed looking back as I was prepping for our conversation today. There were a lot of things that I hadn't really considered in a while, and when you kind of lay them all out in front of yourself, you see that, yeah, there has been a lot of change over the past decade when it comes to a lot of this geopolitical stuff.

Maria Varmazis: It's a feedback loop, isn't it?

Dave Bittner: It is. It is. I think one of the things that strikes me is just that it's become constant. Like, it used to be that you'd have something like the OPM breach, which was more episodic. "Ooh, something happened," and, "Ooh, there was a breach," or, "Ooh, data got stolen," or, "Ooh, there was some ransomware." And it's just -- it's everywhere now. It's daily. Thank goodness for us. Yeah, there's a low-level drone of this stuff that is all the time now. And so that's the new reality. That's where we are.

Maria Varmazis: Yeah, was there anything -- leading question, but anything that contributed to that shift? Because that is quite a change from what the landscape looked like, at least for the civilian side of things, that, you know, now, as you said, that drone of continuous threats, especially on that international scale, it is quite a shift. What do you feel has contributed to that?

Dave Bittner: I think geopolitically, it's the reality and the recognition from nation-states that cyber is a domain without the usual borders, and also, you get a huge return on your investment if you -- you don't have to build an aircraft carrier to force your influence around the rest of the world. And we've seen that with things like influence operations from the Russians and the Chinese stealing information from our companies, our organisations. Supply chain issues, all those kinds of things. Again, they're a day-to-day thing now, and they weren't always.

Maria Varmazis: That's for sure. Yeah, I think as we start thinking about, you know, specific incidents and threats, the one that definitely -- I'm sure for most of our listeners, would come to mind as we look back the 10 years, NotPetya, and how seismic Petya and then NotPetya truly were, and everything that has come after that. Can you talk us through that one a little bit? Because that was such a huge, huge thing when it landed.

Dave Bittner: Well, I think it was the one that sort of opened everybody's eyes and thought. It can happen to us, right? You have a global disruption of the supply chain. You know, major supplier gets hit, and everybody starts worrying that maybe our global economy is a little more fragile than we thought it was. So it certainly got everybody's attention, made everybody feel like it was real, and, you know, it's in everybody's consciousness ever since.

Maria Varmazis: That's very true. That's very true. And another thing, as we look back on the last 10 years, 2022 was the start of the war in Ukraine, and still ongoing. The fallout from that is certainly global, especially when we're talking within the cyber realm. What are the geopolitical shifts within the conflict that you think have fed into the cybersecurity realm, as it were, like the nature of the threat?

Dave Bittner: Yeah, I mean, there's this whole idea that the war in Ukraine has been a bit of a laboratory for cyber war, for modern cyber war. The integration of cyber and kinetic battle, using cyber alongside your battlefield operations, again, information operations, which is top of mind for the Russians. You know, they've always -- it's always been something they've had up their sleeve, but it feels like cyber has been an accelerant for that, for them to be able to do the things they do. And then also, sort of related to -- I think it started in Ukraine, but related to what we're seeing now in Iran, is seeing inexpensive technology being used in warfare, little consumer drones, consumer electronics, routers, Starlink, all these things that are not mil-spec, you know.

Maria Varmazis: Such as it is.

Dave Bittner: Right. Whatever that means. But they're off-the-shelf tools that hose themselves up to the cyber and have allowed folks to be -- to have an unfair advantage or at least maybe not as much of an outsized disadvantage against a larger, more capable adversary.

Maria Varmazis: Speaking of adversaries, and again, we're based in the United States, so this is our very US-centric point of view, so just owning up to that. But when we think about -- yeah, in case that wasn't obvious. When we think about, you know, the adversarial nation-states, often Russia, China, North Korea, those are the names that commonly come to mind. Iran, of course, is part of that as well, has been. But things have shifted in that arena as well, in terms of nation-state strategies against other nation-states and also against private enterprise. It's all in the mix. Over the last 10 years again, big shifts, anything notable that you want to highlight on that front?

Dave Bittner: Well, let's look at China, who famously, I think, they play the long game, and we're in the middle of that long game. Who knows how long it is? We might be in just the beginning of it. But we've seen that they have positioned themselves in our infrastructure. They have access to the supply chain. So many things get manufactured in China that it's -- and the manufacturers are obligated to do what the Chinese government wants them to do. So I think there's a legitimate concern from nations like ours to think about what might be in the firmware, what might be in our supply chain. We certainly -- we've found them in our telecommunications infrastructure with the various typhoons, Volt Typhoon, Salt Typhoon, and those sorts of things. So they're more looking for long-term economic influence and advantage rather than turning the lights off, which I think is the fear that we have from, say, Russia or Iran of messing with our critical infrastructure. It seems like China is really interested in gathering information, knowing what we're up to, so they can leverage that knowledge to their own advantage.

Maria Varmazis: And it leaves defenders in a really -- in a bit of a bind, truly, when you're thinking about potential supply chain attacks or just issues from within the supply chain, and specifically, if we're talking about devices from China, in many cases, they're the only source for some of these -- many things that are made. We don't -- there is no domestic supplier for some -- not just some, many of the things that a lot of modern IT infrastructure relies on. So it leaves defenders in a quite difficult position, and I'm wondering what is the advice that defenders should be applying in their day-to-day, or what can we tell them? What should they be doing in light of all that?

Dave Bittner: Well, I think, ultimately, I mean, it's defense in depth, right? So you can't rely on only one thing to protect yourself, so you do your due diligence to check to make sure your supply chain is as secure as it can be, but then have defenses in place on the chance that it's not, because it might not be. And so look, we're seeing again to the present day, who thought we would see the rest of the world being so interested in digital sovereignty because of the actions of the United States? The major players -- the Microsoft, Google, Amazon -- we're seeing other nations building their own infrastructure because they're not sure they can depend on us as good partners in a way that they had assumed that they could in prior years. So I don't know the degree to which people saw that coming. I certainly didn't. I don't know about you.

Maria Varmazis: That was a blindside for a lot of us, yeah. I did not. I'm still reeling from it personally, honestly. And given the conversations that you've had, especially in the last few years, I'm wondering if the nature of what you're hearing from people that you've interviewed, when geopolitics, but maybe also specifically, supply chain issues, has the nature of that conversation changed? I mean, are there new worries, anxieties? What are you hearing that is trend-wise that has changed?

Dave Bittner: Yeah, I mean, I think it's top of mind for a lot of people. They understand that the threat is real. They understand that there's only so far down the supply chain ladder that you can go to trust but verify. And like you said, so many things come out of other nations who are potentially adversarial. I mean, look at how many of us are carrying iPhones around, right? And who makes the iPhones? Where do they come? Now, so, who are we trusting? We're trusting Apple to do their due diligence. But -- right? The thing is -- so, at some point, you have to trust someone.

Maria Varmazis: I want to let that marinate for a second because, like, it's an important point, but it's also -- makes me kind of recoil. I don't know why, just viscerally it makes me go, yeah, but ooh, but --

Dave Bittner: And yet, what is probably the most, you know, popular thing that we've seen -- or one of the, let's say, top five things that's come to the fore in terms of strategies, is zero trust architecture. So you don't want to trust anybody, right?

Maria Varmazis: So, where does that leave us truly?

Dave Bittner: Right. Well, you have to strike that balance. And, you know, I guess it's the old Reagan saying, "Trust, but verify." Only trust so far and do your due diligence. And zero trust is a way to be constantly challenging the trust to make sure that people are only getting access to what they need to when they need it. And I think that's wise. So the rise of zero trust and its adoption by governments, you know, the feds really jumping in with both feet with zero trust, I think, shows that that's probably where we're headed, going forward.

Maria Varmazis: When I think on the last 10 years -- I think we talked about this in our last chat -- the rise of ransomware and its efficacy, and also where we're seeing it, the systems that it's taking out. I think if you had asked me 10 years ago where it would be most effective, I'm not sure I would have said, oh, definitely, you know, on a large-scale nation-state level would we be seeing ransomware being a serious threat. I would have thought maybe enterprise only. And yet these lines have become so blurred. I don't know if that's maybe a theme of the last 10 years, but truly critical infrastructure is in the crosshairs with things that we might have thought of as sort of business-level nuisances. Where do we go with that? What do we do with that? Just thinking about the lines being blurred between things that are critical military or government-level infrastructure and the commercial world. I don't know. I have this mentality of these two worlds being more bifurcated, but that is a very outdated model, clearly.

Dave Bittner: Yeah, I've wondered for several years now, and I remember this being a question that I was asking early on with, you know, folks who know way more about this than I do, was why don't we see brighter lines drawn in the sand when it comes to a lot of these things? And the answer seems to be that governments don't want those lines to be there. They want to have the flexibility to do -- I'm putting air quotes -- "what needs to be done" when they decide something needs to be done. So if your ransomware operators are to your advantage to have them around when you need them, then you're going to let them operate. We -- and I'm just saying us, the US, I'm going to put us in the good guys category here. I know people will --

Maria Varmazis: Careful there.

Dave Bittner: Perhaps people -- perhaps justifiably, take me to task for that, but for the sake of this particular argument, let's accept that. That we don't want to draw sharp lines ourselves because we want to have the flexibility to use whatever tools we think we need to use against our own adversaries. So there are things that I continue to scratch my head over, like why aren't hospitals off-limits? There seems to me like there are some basic rules of humanity that we should be able to all agree with. And if there was a way, for example, you know, the Russians are famously forgiving and tolerant of their ransomware operators. Well, if the Russians said, "Okay. We're tolerant, but no hospitals," right? I think we could all agree on -- I don't see the controversy there. It's a basic law of warfare, right? You don't bomb hospitals. And yet here we are.

Maria Varmazis: And yet here we are, yeah. I know.

Dave Bittner: Right. So I think there are frustrations because I think there are -- there's low-hanging fruit that people could agree on, perhaps if we wanted to start with some international treaties over cyber things, that ransomware not going after hospitals would probably be a great first step.

Maria Varmazis: Nice place to start, yeah. Agree with that.

Dave Bittner: Yeah, but we're still resisting that. And on the one hand, I get why, but on the other hand, I sure would love it if we could do better.

Maria Varmazis: Yeah. Amen to that. When I think about geopolitics, last 10 years as we are right now, "attribution" is another word that comes up for me as something that has really changed. Again, this is just my recollection from before the last 10 years, but I remember people being a lot more cagey about attributing anything, especially to a nation-state. And that seems to have gone completely out the window, at this point. It's almost like there's a rush to attribute. That feels like a big change to me. I'm curious your thoughts on that.

Dave Bittner: Yeah, I think that's -- I think that's right on. And I think we have all these named threat groups now, whether they're, you know, one of the Fancy Bear or one of the UNCs or, you know, depending on who's naming them, they have all kinds of different names. And that's another point of frustration where I wish, yes, I wish we could settle on it. And I have my own thoughts about giving bad guys cool names that sound like they're out of Marvel movies, but we'll set that aside for the moment. Yeah, I think you're right. People are less cagey. There's a greater expectation. We know what sort of tradecraft comes out of different places, so we know what to expect. And I think it's easier to put a label on things. There's still organizations out there who are intentional about not signaling attribution. There are people who still think it doesn't matter.

Maria Varmazis: Yeah. Yeah.

Dave Bittner: I don't know that I agree with that. I think it's helpful to know where something is coming from so that you can use that context to help inform you and help you defend yourself and so on. But I think you're absolutely right that attribution has become much more routine and just a part of the daily back and forth. It is interesting to me how -- however, again, being in the US and being US-centric and everything that we do, pretty much flowing through our own news organizations, how unusual it is for the US to be tagged as --

Maria Varmazis: I was just thinking that! I was just -- I was like, "Do I say something?" I'm like, "When's the last time I've heard, 'oh, this was a US-based attack'?" I'm going, "I can't really -- " I mean, it's happened, but not as much as we hear --

Dave Bittner: Oh, it happens. Every now and then, you'll hear somebody allude to it or, you know, a lot of times, just when something gets uncovered that's been around for a while, like we had the thing just in the past week or so, it was something that predated Stuxnet. It was --

Maria Varmazis: Yes, I remember. Yeah.

Dave Bittner: They were sneaking in faulty versions of simulation software that would spit out bad answers. And clearly, that came from us, but it's been a long time since whatever that was went out. So I don't know, it's interesting to me that we don't see attribution to ourselves to the degree that we see the other folks. That makes sense. But I wonder, you know --

Maria Varmazis: I imagine that's going to change.

Dave Bittner: Yeah. And if the Chinese or the Iranian or the Russian version of the CyberWire Daily, every day talking about, you know, Screaming Eagle or -- -- something -- some --

Maria Varmazis: Orange Cheeto. I mean, no --

Dave Bittner: Yeah. Some American name. Right. Something -- right. Something that's hilarious to them but slightly offensive to us.

Maria Varmazis: Yeah. No, I bet that's just maybe a language barrier on our side, but I also have to imagine, given the lag in understanding about Stuxnet, for example, eventually more is going to be uncovered, and we'll update our understanding retroactively. But I think, if I was going to make a prediction, I imagine that would be a big thing that will change. But I'm curious about your predictions, Dave, as you look to the next 10. See what I did there?

Dave Bittner: Well, obviously, the big thing is AI, and we can't go --

Maria Varmazis: Everybody drink! He said it!

Dave Bittner: We were so close to getting through this one without summoning it. Oh. Oh. And it's a wildcard, isn't it? Because we don't know how viable it is. We're throwing all this money, we're throwing all these resources, all this electricity, all this water at AI, and I think there's general agreement that it can't go on the way that it's going on right now. In this -- right now, we're in the land grab part where everybody is trying to be the dominant force in this. I understand that. But at some point, it's going to shake out, and people are actually going to have to make money. So what does that mean for the future of it? Who will be able to afford to have these tools? And what does that look like as we go forward? Will certain tiers of AI tools only be available to nation-states? Maybe. Maybe not. And we've got quantum computing, which is, you know, we joke about always 10 years out, no matter when you ask. But it feels like it is closer than we've ever thought it was before. I think it was, I think Google pushed up their timeline for being quantum-safe on some things, so they're getting some signals that, "Hey, folks. This is probably real." So we'll see.

Maria Varmazis: So Q-Day sometime in the next 10 years. That's a prediction. You heard it here first. Yeah, it's --

Dave Bittner: But what is -- right. Right. But I'm not sure we all know exactly what that means. You know, some of the folks I've talked to have said be careful at how much you place on Q-Day because while quantum computers are very, very good at certain things, there's a lot of other things that we rely on computers to do that it's not particularly good at. So it's, in other words, not going to be a huge game changer to many of the areas of computing that we rely on day to day, just turns out it's really good at cryptography, which is important.

Maria Varmazis: So good thing we don't use cryptography for literally anything, so, you know.

Dave Bittner: Right. Right.

Maria Varmazis: Yeah. It'll be seismic for sure. I'm sure on a international basis for statecraft and all that kind of thing, and -- I mean, that would be my prediction. But for the average folk, they may not see any change at all, so who knows?

Dave Bittner: Right. Will we have a Sputnik moment where all of a sudden there's a beacon that everybody else can't ignore? Right. And do you -- and you know, I mean, Sputnik led us to putting men on the Moon, so if we have a Sputnik moment with quantum computing, do we find ourselves in some kind of new arms race or Cold War or who knows? Hard to tell, as Yoda said, always fuzzy, the future, always unclear.

Maria Varmazis: Well, any other wit or wisdom, Dave, that we should add before we close out?

Dave Bittner: Look, I really appreciate this episode because, as I said at the outset, looking back on this stuff was really interesting and a lot of fun. You lose perspective, I think, as you're doing this day to day and you're looking to the immediate future, which is, I think, what we all tend to do in the news business. So to take a 10-year look back and really see some of the big arcs that we've seen has really been interesting, gives me good perspective, and hey, I'll talk to you again in 10 years.

Maria Varmazis: Maybe a little bit before then, but yeah.

Dave Bittner: Hope so.

Maria Varmazis: Same. Well, Dave, thanks as always, yet another fascinating conversation. Thank you for letting me pick your brain yet again, and thank you for everything you've done for the CyberWire over the last 10 years, and long may it continue.

Dave Bittner: No, it's my pleasure. Thanks to our listeners for making it possible. It's been great fun. Talk to you soon.

Maria Varmazis: Thank you for joining us today. See you back here next time. [ Music ]