YouSaid · the spoken record
Nicole Perlroth
- lines on the record
- 109
- first
- 2022-02-20
- most recent
- 2022-02-20
- sittings or episodes
- 1
- sources
- podcast
Every line below is reproduced as it was said and linked to the record it came from. Nothing here is summarised or generated. Directory · Search · Corrections
“Yes. I mean, this is the worst nightmare of every chief information security officer out there. You know, social engineering, we work from home now. I saw this woman posted online about how her husband, it went viral today, but it was her husband had this problem at work. They hired a guy named John, and now the guy that shows up for work every day doesn't act like John. I mean, think about that. Like think about the potential for social engineering in that context. You know, you apply for a job.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Protecting sources. I was trying to use PGP encryption. And it's like, it didn't work. You know, the number of mistakes I would probably make just trying to email someone with PGP just wasn't worth it. And then Signal came along. And Signal made it wicker. They made it a lot easier to send someone an encrypted text message. So we have to start investing in creative minds, in good security design. You know, I really think that's the hack that's going to get us out of where we are today.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“To protect people. And yeah, I mean, it's not going to get us away from the password and using multi-factor authentication, but the technology is out there. And we just have to figure out how to use it in a really seamless way because it doesn't matter if you have the perfect security solution, if no one uses it. I mean, when I started at the times, when I was trying to be really good about”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Well, there's a company that I actually will call out, and that's abnormal security, so they work on email attacks. It was started by a couple guys who were doing, I think, ad tech at Twitter. So, you know, ad technology now, like it's a joke how much they know about us. You know, you always hear the conspiracy theories that you saw someone's shoes and next thing you know it's on your phone. It's amazing what they know about you. And they're basically taking that and they're applying it to attacks. So they're saying, okay, you know, if you're, this is what your email patterns are. It might be different for you and me because we're emailing strangers all the time. But for most people, their email patterns are pretty predictable. And if something strays from that pattern, that's abnormal. And they'll block it. They'll investigate it, you know, and that's great. You know, let's start using that kind of targeted ad technology.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“It feels like friction in our frictionless society. It feels like friction. It's annoying. That security is biggest problem. It's annoying. We need the Steve Jobs of security to come along and we need to make it painless. And actually, on that point, Apple has probably done more for security than anyone else simply by introducing biometric authentication first with the fingerprint and then with face ID. It's not perfect, but if you think just eight years ago, everyone was running around with either no passcode, an optional passcode or a four-digit passcode on their phone that anyone think of what you can get when you get someone die phone if you steal someone's iPhone. And, you know, props to them for introducing the fingerprint and face ID. And again, it wasn't perfect, but it was a huge step forward. Now it's time to make another huge step forward. I want to see the password die. I mean, it's goddess as far as it was ever going to get us. And I hope whatever we come up with next.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“And you go test it on their brokerage account and you test it on their cold storage account. That's how it works. But if you have multi factor authentication, then they can't get in because they might have your password, but they don't have your phone. They don't have your Fido key, you know, and so you keep them out. And, you know, I get a lot of alerts that tell me someone is trying to get into your Instagram account or your Twitter account or your email account. And I don't worry because I use multi-factor authentication. They can trial day. Okay, I worry a little bit, but, you know, it's the simplest thing to do. And we don't even do it.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Yes. You know, usually this happens through some kind of text. You know, you get your one time code from Bank of America or from Google. Better way to do it is spend $20. On Amazon. That's a hardware device. And if you don't have that hardware device with you, then you're not going to get in. And the whole goal is, I mean, basically, you know, my first half of my decade at the time was spent covering like the cop beat. It was like Home Depot got breached. News at 11, you know, Target, Neeman Marcus, like who wasn't hacked over the course of those five years. And a lot of those companies that got hacked, what did hackers take? They took the credentials. They took the passwords. They can make a pretty penny selling them on the dark web. And people reuse their passwords. So you get one from, you know, God knows who I don't know, last pass. The worst case example actually, last pass. But you get one and then you go test it on their email account.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Right now. But of course, you know, this is a cat and mouse game, and then the attacker's on to the next thing. But I think right now, that is like Barnaban, that is just the easiest, simplest way to deflect the most attacks. And, you know, the name of the game right now isn't perfect security. Perfect security is impossible. They will always find a way in. The name of the game right now is make yourself a little bit harder to attack than your competitor than anyone else out there so that they just give up and move along. And, you know, maybe if you are a target for an advanced nation state or the SVR, you're going to get hacked no matter what. But you can make cyber criminal groups deadbolt is it. You can make their jobs a lot harder simply by doing the bare basics. And the other thing is stop reusing your passwords. But if I only got”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Factor authentication, multi factor authentication. It's ridiculous how many of these attacks come in because someone didn't turn on multi-factor authentication. I mean, colonial pipeline, okay? They took down the biggest conduit for gas jet fuel and diesel to the east coast of the United States of America. How? Because they forgot to deactivate an old employee account whose password had been traded on the dark web and they'd never turned on two-factor authentication. This water treatment facility outside Florida was hacked last year. How did it happen? They were using Windows XP from like a decade ago that can't even get patches if you wanted to, and they didn't have two-factor authentication. Time and time again, if they just switched on two-factor authentication, some of these attacks wouldn't have been possible. Now, if I could snap my fingers, that's a thing I would do.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Network of private citizens that work at the behest of the Ministry of State Security. So how do you come to some sort of state-to-state agreement when you're dealing with transnational actors and cyber criminals where it's really hard to pin down whether that person was acting alone or whether they were acting at the behest of the MSS or the FSB? And a couple years ago, I remember can't remember if it was before or after Not Petya, but Putin said, hackers are like artists who wake up in the morning in a good mood and start painting. In other words, I have no say over what they do or don't do. So how do you come to some kind of norm when that's how he's talking about these issues? And he's just decimated merck and Pfizer and another, however many thousand companies.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Canon nation state masquerade as a cyber criminal group, as a ransomware group. And that's what really complicates coming to some sort of digital Geneva convention. Like there's been a push from Brad Smith at Microsoft. We need a digital Geneva convention. And on its face, it sounds like a no-brainer. Yeah. Why wouldn't we all agree to stop hacking into each other's civilian hospital systems, elections, power grid, pipelines? But when you talk to people in the West, officials in the West, they'll say we would never, we'd love to agree to it, but we never do it when you're dealing with she or Putin or Kim Jong-un. Because a lot of times they outsource these operations to cyber criminals. In China, we see a lot of these attacks come from this loose satellite.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Quasi norm we've stumbled into is proportional responses. You know, there's this idea that if you get hit, you're allowed to respond proportionally at a time and place of your choosing. You know, that is how the language always goes. That's what Obama said after North Korea hit Sony. We will respond at a time and place of our choosing. But no one really knows like what that response looks like. And so what you see a lot of the time are just these like just short of war attacks, you know, Russia turned off the power in Ukraine, but it wasn't like it stayed off for a week. It stayed off for a number of hours. Not Petya hit those companies pretty hard, but no one died. You know, and the question is, what's going to happen when someone dies?”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“You publish this story, and instead they gave us the opposite answer. They said, We have no problem with you publishing this story. Why? Well, they didn't say it out loud, but it was pretty obvious they wanted Russia to know that we're hacking into their power grid too, and they better think twice before they do to us what they had done to Ukraine. So yeah, you know, we have stumbled into this new era of mutually assured digital destruction. I think another sort of”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Think, okay, if I do this, how am I going to cover up that it came from me because I don't want to risk the response? So people are sort of dancing around this. It's just in a very different way. And, you know, at the time, I'd covered the Chinese hacks of infrastructure companies like pipelines. I'd covered the Russian probes of nuclear plants. I'd covered the Russian attacks on the Ukraine grid. And then in 2018 My colleague David Sanger and I covered the fact that US Cyber Command had been hacking into the Russian grid and making a pretty loud show of it. And when we went to the National Security Council, because that's what journalists do before they publish a story, they give the other side a chance to respond. I assumed we would be in for that really awkward, painful conversation where they would say, you will have blood on your hands.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Nuclear analogies always tend to fall apart when it comes to cyber, mainly because you don't need fissile material. You just need a laptop and the skills and you're in the game. So it's a really low barrier to entry. The other thing is attributions harder. And we've seen countries muck around with attribution. We've seen nation states piggyback on other countries' spy operations and just sit there and siphon out whatever they're getting. We learned some of that from the Snowden documents. We've seen Russia hack into Iran's command and control attack servers.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“It is chaos. I think part of it is to sow the seeds of doubt in their current government. Your government can't even keep your lights on. Why are you sticking with them? You know, come over here and we'll keep your lights on at least. You know, there's like a little bit of that.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“You find a zero day in Windows, you're not just leaving it open so you can spy on Russia or implant yourself in the Russian grid, you're leaving Americans vulnerable too. But zero days are like that is the secret sauce. You know, that's the superpower. And I always say like every country now, with the exception of Antarctica, someone added the Vatican to my list, is trying to find offensive hacking tools in zero days to make them work. And those that don't have the skills now have this market that they can tap into where $2.5 million, that's chump change for a lot of these nations. It's a hell of a lot less than trying to build the next fighter jet. But yeah, the goal is chaos. I mean, why did Russia turn off the lights twice in Ukraine? You know, I think part of...”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“I mean, it's not just zero days. You know, we make it so easy for threat actors. I mean, we're not using two-factor authentication. We're not patching. There was the shell shock vulnerability that was discovered a couple years ago. It's still being exploited because so many people haven't fixed it. So, you know, the zero days are really the sexy stuff. And what really got drew me to the zero day market was the moral calculus we talked about, particularly from the US government's point of view. How do they justify leaving these systems so vulnerable when we use them here? And we're baking more of our critical infrastructure with this vulnerable software. You know, it's not like we're using one set of technology and Russia's using another and China's using this. We're all using the same technology.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“They've just been saying, Can we? Let's do it. And that's a real problem. And this, and just in the last year, we've seen a record number of zero-day attacks. I think there were 80 last year, which is probably more than double what it was in 2019. A lot of those were nation states. We live in a world with a lot of geopolitical hot points right now. And where those geopolitical hot points are are places where countries have been investing heavily in offensive cyber tools.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Have here in the United States. And everyone here is just operating like let's just keep hooking up everything for convenience. Software eats the world. Let's just keep going for cost, for convenience sake just because we can. And when you study these issues and you study these attacks and you study the advancement and the uptick and frequency and the lower barrier to entry that we see every single year, you realize just how dumb software Eats world is. And no one has ever stopped to pause and think, should we be hooking up these systems to the internet?”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“But we have a very soft underbelly when it comes to cyber. 80% or more of America's critical infrastructure. So pipelines, power grid, nuclear plants, water systems is owned and operated by the private sector. And for the most part, there is nothing out there legislating that those companies share the fact they've been breached. They don't even have to tell the government they've been hit. There's nothing mandating that they even meet a bare minimum standard of cybersecurity. And that's it. So even when there are these attacks, most of the time, we don't even know about it. So that is, you know, if you were going to design a system to be as blind and vulnerable as possible, that's a pretty, pretty good, that's what it looks like is what we have.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“No way that these governments and these nation states are not going to use their access to gain some advantage in those conflicts. And, you know, I am now in a position where I'm an advisor to the cybersecurity infrastructure security agency at DHS. So I'm not saying anything classified here, but I just think that It's really important to understand just generally what the collateral damage could be for American businesses and critical infrastructure in any of these escalated conflicts around the world. Because just generally, our adversaries have learned that they might never be able to match us in terms of our traditional military spending on traditional weapons and fighter jets.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“I believe any geopolitical conflict From now on Is guaranteed to have some cyber element to it. The Department of Justice recently declassified a report that said China's been hacking into our pipelines and it's not for intellectual property theft. It's to get a foothold so that if things escalate in Taiwan, for example, they are where they need to be to shed our pipelines down and we just got a little glimpse of what that looked like with colonial pipeline and the panic buying and the jet fuel shortages and that assessment I just mentioned about the diesel. They're there. You know, they've gotten there. Anytime I read a report about new aggression from fighter jets, Chinese fighter jets in Taiwan or what's happening right now with Russia's buildup on the Ukraine border or India, Pakistan. I'm always looking at it through a cyber lens and it really bothers me that other people aren't because there is”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“I thought for a long time, I always labeled it as collateral damage. But actually, just today, there was really impressive threat researcher at Cisco, which has this threat intelligence division called Talos, who said, stop calling it collateral damage. They could see who was going to get hit before they deployed that malware. It wasn't collateral damage. It was intentional. They meant to hit any business that did business with Ukraine. It was to send a message to them too. So I don't know if that's accurate. I always thought of it as sort of the sloppy collateral damage, but it definitely made me think.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“It paralyzed Merck's factories. I mean, it really created an existential crisis for the company. Merck had to tap into the CDC's emergency supplies of the Gardasil vaccine that year because their whole vaccine production line had been paralyzed in that attack. Imagine if that was going to happen right now to Pfizer or Moderna or Johnson& Johnson, you know, imagine. I mean, that would really create a global cyber terrorist attack, essentially.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“And there was the not Petya attack. So, this was an attack by Russia on Ukraine that came at them through a supplier, a tax software company in that case, that didn't just hit any government agency or business in Ukraine that used this tax software. It actually hit any business all over the world that had even a single employee working remotely in Ukraine. So it maresk, the shipping company, but hit Pfizer, hit FedEx. But the one I will never forget is Merck.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“They were turning chemote patients away, cancer patients away. One nurse told us, I don't know why people aren't screaming about this, that the only thing I've seen that even compares to what we're seeing at this hospital right now was when I worked in the burn unit after the Boston Marathon bombing. They really put it in these super dramatic terms. And last year there was a report in the Wall Street Journal where they attributed an infant death to a ransomware attack because a mom came in and whatever device they were using to monitor the fetus wasn't working because of the ransomware attack. And so they attributed this infant death to the ransomware attack. Now on a bigger scale but less personal.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“The worst ransomware talk I've covered on a personal level was an attack on a hospital in Vermont. And you think of this as like, okay, it's hitting their IT networks. They should still be able to treat patients. But it turns out that cancer patients couldn't get their chemo anymore because the protocol of who gets wet is very complicated. And without it, nurses and doctors couldn't access it.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Was $18 million. It's a lot for the city of Baltimore. That's money that could have gone to public school education and roads and public health. And instead, it just went to rebuilding these systems from scratch. And so a lot of residents in Baltimore were like, why the hell didn't you pay the $76,000? So it's not obvious, you know, it's easy to say don't pay. Because why you're funding their R&D for the next go round, but it's too often, it's too complicated.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“My colleague David Sanger and I got our hands on a classified assessment that said that as a country, we could have only afforded two to three more days of colonial pipeline being down. And it was really interesting. I thought it was the gas in the jet fuel, but it wasn't. We were sort of prepared for that. It was the diesel. Without the diesel, the refineries couldn't function. And it would have totally screwed up the economy. And so there was almost this like national security economic impetus for them to pay this ransom. And the other one I always think about is Baltimore. You know, in the city of Baltimore got hit, I think the initial ransom demand was something around 76,000 it may have even started smaller than that. And Baltimore stood its ground and didn't pay, but ultimately the cost to remediate.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“You know, we've seen, for instance, there was an Apple supplier in Taiwan. They got hit and the ransom demand was 50 million. You know, I'm surprised it's only 1.8 million. I'm sure it's going to go up. And it's hard. Obviously governments and maybe in this case the company are going to tell you we recommend you don't pay or please don't pay. But the reality on the ground is that some businesses can't operate. Some countries can't function. I mean, the underreported storyline of colonial pipeline was after the company got hit and took the preemptive step of shedding down the pipeline because they their billing systems were frozen. They couldn't charge customers downstream.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“It's like a zero day, and it's a supply chain attack. You know, you're getting hit from your supplier. You're getting hit because of your vendor. And it's also a new thing for ransomware groups to go to the individuals to pressure them to pay. There was this really interesting case. I think it was in Norway where there was a mental health clinic that got hit. And the cyber criminals were going to the patients themselves to say pay this or we're going to release your psychiatric records. I mean, talk about hell. In terms of whether to pay, you know, that is on the cheaper end of the spectrum.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“The zero day factor is a big one. You know, they are QNAP right now is trying to figure out what the hell is wrong with their system that would let this in. And even if they pay, if they still don't know where the zero day is, what's to say that they won't just hit them again and hit you again. So that really complicates things. And that is a huge advancement for ransomware. It's really only been, I think, in the last 18 months that we've ever really seen ransomware exploit zero days to pull these off. Usually 80% of them, I think the data shows 80% of them come down to a lack of two-factor authentication. You know, so when someone gets hit by a ransomware attack, they don't have two-factor authentication on their employees were using stupid passwords. Like you can mitigate that in the future.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, and I think, you know, what Hacker One has told me was, okay, let's just put away the people that are finding and developing zero-day exploits all day long. Let's put that aside. What about the, you know, however many millions of programmers all over the world who've never even heard of a zero-day exploit, why not tap into them and say, hey, we'll start paying you if you can find a bug in United Airlines software or in Schneider Electric or in Ford or Tesla. And I think that is a really smart approach. Let's go find this untapped army of programmers to neutralize these bugs before the people who will continue to sell these to governments can find them and exploit them.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“He would say he was speaking off the record. He didn't understand the rules of the game. But what I heard from people who did business with him was that the minute that that story came out, he became PNG'd. No one did business with him. You know, his business plummeted by at least half. No one wants to do business with anyone who's going to get on camera and talk about how they're selling zero days to governments. It puts you at danger. And I did hear that he got some visits from some security folks. And, you know, that's another thing for these people to consider. You know, if they have those zero day exploits at their disposal, they become a huge target for nation states all over the world. Talk about having perfect opsec. You know, you better have some perfect opsec if people know that you have access to those zero day exploits.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“A good question, and this is why I'm a print journalist. But, you know, a lot when I've seen people do it, it's always the guy who's behind the shadows, whose voice has been altered, you know, when they've gotten someone on camera, that's usually how they do it. Very, very few people talk in this space. And there's actually a pretty well-known case study and why you don't talk publicly in the space and you don't get photographed. And that's the Gruk. So, you know, the Gruk is or was this zero-day broker, South African guy lives in Thailand. And right when I was starting on this subject at the New York Times, he'd given an interview to Forbes and he talked about being a zero-day broker. And he even posed next to this giant daffel bag filled with cash, ostensibly.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Situation recently. So, you know, I had some of those reality checks along the way. We tend to think of things as is this moral, you know, is this ethical, especially as journalists, we kind of sit on our high horse sometimes and write about a lot of things that seem to push the moral bounds. But in this market, which is essentially an underground market that, you know, the one rule is like fight club, you know, no one talks about fight club. First rule of the zero day market, nobody talks about the zero-day market on both sides because the hacker doesn't want to lose their 2.5 million dollar bounty and governments roll these into classified programs and they don't want anyone to know what they have. So no one talks about this thing. And when you're operating in the dark like that, it's really easy to put aside your morals sometimes.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“And so I went out to lunch with kind of this godfather of the hacking scene there and I asked this really dumb question and I'm still embarrassed about how I phrased it. But I said, so, you know, will these guys only sell these zero-day exploits to good Western governments? And he said, Nicole, last time I checked, the United States wasn't a good Western government. You know, the last country that bombed another country into oblivion wasn't China or Iran. It was the United States. So if we're going to go by your whole moral calculus, you know, just know that we have a very different calculus down here. And we'd actually rather sell to Iran or Russia or China maybe than the United States. And that just blew me away. Like, wow, you know, he's like, we'll just sell whoever brings us the biggest bag of cash. Have you checked into our inflation?”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Who specialize in developing zero day exploits? And I went down to this Argentina conference called Echo Party. And I asked the organizer, okay, can you introduce me to someone who's selling zero-day exploits to governments? And he was like, just throw a stone, throw a stone anywhere and you're going to hit someone. And all over this conference, you saw these guys who were clearly from these Gulf states, who only spoke Arabic. You know, what are they doing at a young hacking conference in Buenos Aires?”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“I went down to Argentina and this whole kind of moral calculus I had in my head was completely flipped around. So just to back up for a moment. So Argentina actually is a real hacker's paradise. People grew up in Argentina and, you know, I went down there. I guess I was there around 2015, 2016, but you still couldn't get an iPhone. You know, they didn't have Amazon Prime. You couldn't get access to any of the apps we all take for granted. To get those things in Argentina as a kid, you have to find a way to hack them. And it's the whole culture is really like a hacker culture. They say like, it's really like a MacGyver culture. You know, you have to figure out how to break into something with wire and tape. And that means that there are a lot of really good hackers in Argentina.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“So, this was another question I wanted to answer. You know, who are these people who would sell a zero-day exploit that would neutralize a Schneider Electric safety lock at a petrochemical plant? Basically, the last thing you would need to neutralize before you trigger some kind of explosion. Who would sell that? And I got my answer. Well, the answer was different. A lot of people said I would never even look there because I don't even want to know. I don't even want to have that capability. I don't even want to have to make that decision about whether I'm going to profit off of that knowledge.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Get to brag about the fact you just found that 2.5 million dollar iOS zero day that no one else did. And if you sell it to a broker, you never get to talk about it. And I think that really does eat up people.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“It's interesting, you know, they shouldn't outpay them because what would happen if they started offering $2.5 million at Apple for any zero-day exploit that governments would pay that much for is their own engineers would say, why the hell am I working for less than that and doing my nine to five every day? So you would create a perverse incentive. And I didn't think about that until I started this research and I realized, okay, yeah, that makes sense. You don't want to incentivize offense so much that it's to your own detriment. And so I think what they have though with the companies have on government agencies is if they pay you, you get to talk about it. You know, you get the street cred.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Yeah, and there have been some of those companies who've risen up to meet that demand and Hacker One is one of them, bug crowd is another synak has an interesting model. So that's a company that you pay for a private bug bounty program, essentially. So you pay this company. They tap hackers all over the world to come hack your software, hack your system. And then they'll quietly tell you what they found. And I think that's a really positive development. And actually, the Department of Defense hired all three of those companies I just mentioned to help secure their systems. Now, I think they're still a little timid in terms of letting those hackers into the really sensitive high side classified stuff. But, you know, baby steps.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“But we can reward them and hopefully get that to that bug earlier where we can neutralize it so that they don't have to spend another year developing the zero-day exploit. And in that way, we can keep our software more secure. But every week I get messages from some hacker that says, you know, I tried to see this zero-day exploit that was just found in the wild, you know, being used by this nation state. I tried to tell Microsoft about this two years ago and they were going to pay me peanuts, so it never got fixed. You know, there are all sorts of those stories that can continue on. And, you know, I think just generally, hackers are not very good at diplomacy. They tend to be pretty snipey, technical crowd, and very philosophical in my experience. Diplomacy is not their strong suit.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Then there wouldn't be a market, you know. Then there won't be a problem. But they continue to write bugs into their software all the time and they continue to profit off that software. So why shouldn't I profit off my labor too? And one of the things that has happened, which is, I think, a positive development over the last 10 years are bug bounty programs. Companies like Google and Facebook and then Microsoft and finally Apple, which resisted it for a really long time, have said, okay, we are going to shift our perspective about hackers. We're no longer going to treat them as the enemy here. We're going to start paying them for what it's essentially free quality assurance. And we're going to pay them good money in some cases. You know, six figures in some cases. We're never going to be able to bid against a zero-day broker who sells to government agencies.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“So, I think there are people who will tell you they would never sell a zero day to a zero day broker or a government. One, because they don't know how it's going to get used when they throw it over the fence. You know, most of these get rolled into classified programs and you don't know how they get used. If you sell it to a zero-day broker, you don't even know which nation state might use it or potentially which criminal group might use it. If you sell it on the dark web. The other thing that they say is that they want to be able to sleep at night. And they lose a lot of sleep if they found out their zero day was being used. Living hell. But there are a lot of people, good people, who also say, no, this is not my problem. This is the technology company's problem. If they weren't writing new bugs into their software every day,”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“That started reaching out to hackers on these forums and saying, hey, I'll pay you six figures for that bug you were trying to get Microsoft to fix for free and sort of so began or so catalyzed this market where governments and their intermediaries started reaching out to these hackers and buying their bugs for free. And in those early days, I think a lot of it was just for quiet counterintelligence, traditional espionage. But as we started baking the software, Windows software, Schneider Electric, Siemens Industrial Software into our nuclear plants and our factories and our power grid and our petrochemical facilities and our pipelines, those same zero days came to be just as valuable for sabotage and war planning.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Should you just dump these things online because any script kitty can pick them up and use it for all kinds of mischief? But don't you want to just stick a middle finger to all these companies that are basically threatening you all the time? So there was this really interesting dynamic at play. And what I learned in the course of doing my book was that government agencies and their contractors sort of tapped into that frustration and that resentment. And they started quietly reaching out to hackers on these forums. And they said, hey, you know, that zero day you just dropped online. Could you come up with something custom for me? And I'll pay you six figures for it so long as you shut up and never tell anyone that I paid you for this. And that's what happened. So throughout the 90s, there was a bunch of boutique contracts.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source
“Thing we're basically told to shut up and stop doing what you're doing. And what happened next was They basically started trading this information online. Now, when you go back and interview people from those early days. They all tell a very similar story, which is they're curious, they're tinkers. You know, they remind me of like the kid down the block that was constantly poking around the hood of his dad's car. You know, they just couldn't help themselves. They wanted to figure out how a system is designed and how they could potentially exploit it for some other purpose. It doesn't have to be good or bad. But they were basically kind of beat down for so long by these big tech companies that they started just silently trading them with other hackers. And that's how you got these.”
2022-02-20 · Lex Fridman Podcast · #266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar · IDENTIFIED FROM THE TRANSCRIPT · source