Odd Lots - Here's What Cyber War With Russia Would Actually Look Like

Episode Date: March 10, 2022

Russia’s invasion of Ukraine has set off a new wave of concern about cyber attacks. Indeed, there were already reports of some in the run up to the war—like when hackers reportedly targeted U.S.... gas producers. But while worries about cyber attacks have been around for a long time, it remains hard to get a handle on the actual threat. Such attacks aren’t all that visible and information on them is often difficult to get, or comes long after the fact. On this episode of Odd Lots, Joe Weisenthal and Tracy Alloway speak with Matt Suiche, a famous hacker and co-founder of Comae Technologies, about what a cyber war between Russia and the West may actually look like.See omnystudio.com/listener for privacy information.

Transcript
Discussion (0)
Starting point is 00:00:00 Thanks for listening to Oddlots. Follow the show on Amazon Music for more future episodes or just ask Alexa play the podcast, Oddlots on Amazon music. Hello and welcome to another episode of the Oddlots podcast. I'm Tracy Alloway. And I'm Joe Wisenthal. So Joe, clearly a lot still going on with Russia's invasion of Ukraine. But one of the big talking points in the past couple of weeks has been this idea of a retaliatory response. from Russia, not necessarily in the sense of traditional warfare, but in the form of cyber warfare. Right. So this has always been a source of concern going back for several years long before the existing conflict. What are Russia's cyber warfare capabilities? How weak is the rest of the world? How exposed is critical infrastructure and so forth? As of now, you know, I don't think this
Starting point is 00:01:09 has been a huge aspect of the current conflict. Traditional violent warfare is sort of been the story, but it is always lurking out there as a risk. Yeah, there have been some rumblings of potential attacks. I saw something in Der Spiegel this morning about possibly a hack of satellites that might have been impacting Ukraine. So there are sort of rumblings of this, you know, some accusations lurking in the background. But we haven't seen anything, let's say we haven't seen anything major yet. And I feel like cyber security risks, it's one of those things that you always see people mention as a sort of left tail risk. You see lots of analysts notes about it. But no one really talks about it in concrete terms.
Starting point is 00:01:57 It always seems to be just this vague threat lurking in the background. Yes. And I think it's in part because, as you exactly say, no one precisely knows what it would look. like. I mean, obviously, companies are regularly getting hacked. We've seen an increase over the years in malware and ransomware and companies losing data, companies having to pay to bring factories and infrastructure back online. Of course, I think it was late 2020 or maybe early last year. There was that pipeline, the central part of the United States. So these things recur, but I think it's very nebulous what that risk actually looks like. So today, I'm very pleased to say we are going to
Starting point is 00:02:38 try to get a firmer handle on what cyber warfare risk might actually look like. And we're going to do it maybe a little bit differently to what we normally do. But today on the show, we're going to be talking to a hacker about what it actually means to, you know, do cyber warfare, to hack into someone's systems, what the threat actually looks like and what is possible from a technological perspective. I'm really looking forward to this. sort of different from our normal path, but something important to be, to learn more about. Yep. So we are going to be speaking with Matt Suish. He is the founder of Comey, an incident response startup based in Dubai, which is where I met him. And I have to say he's definitely an expert on all of us. Matt, welcome to the show. Hi, Tracy. Hi, hi, Joe. Thanks for inviting me. Looking forward
Starting point is 00:03:30 talking with you about what cyber war might look like. Yeah. So you have a bit of expertise in this. I mean, not just from the hacking perspective, but there are some Russian hackers who seem to be obsessed with you. Is that right? Yeah. So I assume you're referring to the group called the shadowbrokers
Starting point is 00:03:54 that mentioned me a few years back. Yeah. So just for background, Matt and I met when I was working in Abu Dhabi and Dubai and Dubai. And this was back when shadow brokers had a major attack, and there was a lot of talk about them. And they allegedly were a Russian group of hackers. And they seemed to really, I don't know, just focus on you, Matt. Yeah.
Starting point is 00:04:20 So I guess one of the main reason for the focus at the time was mainly due to the fact that I was analyzing a lot of the documents that they were releasing to date. That's one of the group that released some of the most significant documents in cybersecurity, like partly as significant as the Snowden document to give some context for the audience. And as part of the release, they release operational notes and exploits that belong to the US government, particularly to the NSA, which is the main intelligence agency in the US. where they were exposing U.S. intelligence capabilities. So those documents were released. I was part of the main people who were analyzing them.
Starting point is 00:05:13 And like you said, they've been mentioning me a few times. So far, like the main assumption is that that group is affiliated to the Russian government. And like many times, you know, and I'm sure we're going to talk about it more in details. With cyber, it's very hard to know who is doing what. Sometimes it takes years to find enough evidence. Sometimes governments know about something, but they would not necessarily like release the information because they may burn some source that they have to collect additional intelligence.
Starting point is 00:05:52 So it's always like very complicated when it comes to cyber, especially with attribution. So usually you have to use common sense. But in terms of timing, these shadowbrokers were really active around 2016 and 2017, which is around the time where we started to see a lot of attacks from Russia and Ukraine also. When you say attribution is difficult, I mean, intuitively, of course, that makes a lot of sense. What are the type of evidence or what do the certain like fingerprints? Because you hear that a lot. There's a hack and people suspect often suspect Russians.
Starting point is 00:06:30 sometimes Chinese. Are there certain characteristics of attacks or certain things you look at to start to sort of gauge the origin of an attacker? Yeah, definitely. Different attackers have different motives and different groups organized differently. So when it comes to here, when we are talking about hackers, we are talking about national states. We're not talking about someone who is like alone in their bedroom trying to hack a video game, right? So just to make sure it's clear for the audience, we're talking about nation states, carrying intelligence or military operations against other like nation states or companies, sometimes critical infrastructures. So when it comes down to what it looks like in terms of fingerprints when you're doing an investigation,
Starting point is 00:07:21 it is a good question because at the beginning in the introduction chat, you're wondering what cyber war, cyber warfare might look like. And there is this conception that people have that cyber war is going to be like completely different, something we haven't seen before, that, you know, it's just going to be like in the medieval time where you see like people riding a horse and instead of having swords, you know, they're going to have antennas and they're going to start stabbing each other and then you use that as forensic evidence. The reality is we have been seeing a lot of, of those happening over the past years, probably more than 10 years, you know, like even
Starting point is 00:08:04 back in the 2000s when China hacked Google, you know, that was a pretty significant one. And it was one of the first time we saw nation states attacking like an actual company and being able to track it. So what we have been seeing more and more is often like patterns between attacks, but also like motives. So whenever it comes to attacks on critical infrastructure in, let's say, like Ukraine, so there is a very short list of suspects that comes to mind. Same thing when there is an attack happening like Not Petia in 2017.
Starting point is 00:08:46 That gets released on the Independence Day. So often like the timing is very suspicious. Same thing with the article that you mentioned that you saw. is moan in Tracy with Vyassat, which is an American company, when the satellites have been like attacked, like the initial suspicion back, so we're talking like back on February 24 when like around the same time of the invasion, one of the suspicion was while that's happening the same day that Russia is invading Ukraine. So that was also one of the suspicion. So often you would use like common sense when it comes to nation state attackers and then you would backtrack based on what you have found
Starting point is 00:09:35 and see if your assumption makes sense or not. But it can be, you would find a malware that's on the system. And in some cases, like people kind of assume that once you are hacked, you know, like your screen is going to change color, it's going to become right or green. Most of the time, Cyber is often used for like intelligence gathering. So you not even know that people are in your system. In some cases, it may take like years before an attacker is infected. So when you get hacked, a face doesn't come up on your screen and start laughing. Exactly.
Starting point is 00:10:17 Yeah. Exactly. Okay. Thank you. So now you know, Joe. So you mentioned, Matt, that this has been ongoing for some time. And this is something that I've wondered about for a long time. But why, I mean, if you know that Russia is doing a lot of hacking, I mean, along with some other countries like China, North Korea, maybe, but you know that this is happening.
Starting point is 00:10:43 Why do nation states tolerate it? Like, why hasn't this become a bigger area of concern for the U.S. in recent years? Or is it that it is a major area of concern, but we just don't see the response because it's all happening, you know, at the back end of technological systems and with the NSA and, you know, in sort of secret offices? It is a good question. Actually, it is happening. If you go on the state department website, you're going to find a lot of indictment against, like, for instance, like Russian officers that work for the GRU or other like intelligence agencies. So, for instance, like a lot of the attacks from 2017, there is an indictment where six officers are being mentioned for a lot of the damage that they have. done, including like the Olympic Games that have been, you know, one of the targets, including
Starting point is 00:11:51 like the visitors, the host of the Olympic Games, one of the electricity grid in Ukraine being in target. Also the election in France at that time when the emails from Emmanuel Macron had been released. TV five months also, which was a TV channel that was hacked in the past, you know, it was linked to the Russian government. So the actual proof and accusation I've been like published. A lot of it is usually like policy work and done at a political level. So that would explain why it takes so much time.
Starting point is 00:12:31 And often very little can be done in a short period of time. And often what we would see in response would be sanctions. on some of the governments. So it is happening, but I think it's happening at a pace where there are so many attacks happening from different countries like you mentioned, like North Korea for instance, that had been like very active, mostly for like financial gains. Like we remember the attack of the Central Bank of Bangladesh, for instance, where they try to steal like $1 billion.
Starting point is 00:13:08 And where money laundering like happened in casinos in the Philippines. So a lot of information is public and known around like modus apparently from like different like either groups that are working independently or like some independently like for like a nation state. But it's such a complex problem that it's very hard to fix a bit like conflict all around the world. A lot of short daily news podcasts focus on just one story. But right now you probably need more. On up first from NPR, we bring you three of the world's top headlines. every day in under 15 minutes because no one's story can capture all that's happening in this big, crazy world of ours on any given morning. Listen now to the Up First podcast from NPR.
Starting point is 00:14:11 What separates good leaders from transformational ones? I'm Jessica Chen and in season two of leading by example, we'll sit down with executives like Grace Chen of Bertie Gray to find out. It's important to understand where you spike, but also really acknowledge where you don't and find people who can fill those gaps. Listen to leading by example, executives making an impact on the IHeart radio app, Apple Podcast, or wherever you get your podcasts. So a nightmare scenario in the U.S., but I guess, but anywhere, is this idea of they're going to, hackers could shut down critical infrastructure. or maybe the grid in New York City just goes dark because of some hack attack. Is that a realistic threat in your view? I mean, that I think comes to mind or we can't log into our banks or how like big pieces of
Starting point is 00:15:12 infrastructure that could disrupt society. A, is that a plausible threat? And B, is that something that these types of hacker groups could conceivably work on? Yeah, no, definitely. And like I mentioned before, it happened in the past with the Ukrainian like power grids. It happened like in 2015 and 2016. At some point, the electricity grid was down for like a few hours. But one of the things to keep in mind is like I ask those attacks that have been happening over the past 10 years.
Starting point is 00:15:48 Defense capabilities, you know, also from like different companies and like countries also like became more and more. efficient because on one side you have the attackers that are like polishing their craft and becoming more efficient but also on the defense side people are becoming more aware of what type of attack to expect they are becoming more resilient like if something happens no like if any incident happens like oh do you investigate it so that's what you would usually call like incident response but also like how do recover like a system for especially for like critical infrastructure. So regarding targeting like critical infrastructure, so we saw it like around two weeks ago with the satellites. So that company VESAT. So a lot of the actual like users that
Starting point is 00:16:41 have been targeted were like partly the Ukrainian military. So that's one of the attempt of like interfering with the infrastructure for like the target to like kind of slow down or make communication like more difficult. But during that that hack, you know, like unexpectedly, like there's like 3,000 like wind turbines in Germany that were shut down, you know, as like the German government was calling it cyber collateral damage, you know. So sometimes it may come in unexpected ways. But in that scenario, what it meant is the access internet was not available anymore, but the actual actuarine, for instance, why not damage is just the communication link, you know, it's like if someone would shut down like a cell phone
Starting point is 00:17:37 tower, it will not damage your phone. You would just not be able to communicate. And we saw that also at the beginning of the invasion, because there's also this very weird aspect of the Russian military since the beginning of the invasion. And that's kind of why a lot of people are a bit skeptical on the planning and the logistics of the Russian military on that aspect is mostly around communications. They are still not necessarily like using like military equipment. They still use like analog communications, but also like cell phones with like Russian numbers. So at some point, some of the Ukrainian teleco operator rejected like Russian numbers. And they were not able to communicate and that to take over like cell phone of
Starting point is 00:18:24 civilians just to be able to still communicate with each other. But there's a lot of like communication aspect of UCA when you conduct like a military operation. So like and that's a completely different field. You know, that's not my specialty. But we do see it happening because cyber war on its own does not really like exist. You know, like cyber is a component of war. And that's what we are seeing now. So instead of seeing like a conventional war, we see like this.
Starting point is 00:18:54 hybrid warfare happening in front of our eyes where there's multiple aspect to it. And a lot of the actual attacks that we have seen also with Russia and that Russia is pretty well known for. And I'm sure as journalists you are like very like familiar with it is also like disinformation and misinformation. Like we have seen what they call like active measures being used for a long, long time. Russia today and Sputnik news have been. like banned in the EU now. So it took like the invasion, you know, of an European country for them to shut down those media.
Starting point is 00:19:33 So like to answer your question of before, like, how come we don't see like more sanction or response from the governments? Well, that's a perfect example. Like we knew that was happening. And it took the invasion of an European country for them to do something about it. Yeah. I want to ask you, this is, it might be a tricky question. I don't know.
Starting point is 00:19:53 but could you maybe walk us through a timeline of what actually happens if, say, a nation state like Russia hypothetically launches some sort, let's say some sort of malware attack on a Western company or infrastructure utility type thing? Like, what happens? So the attack starts. And then can you walk us through what the actual response looks like and when the attack stop? Yeah, I can even give you an example. So around Christmas 2020, there is a company called Solar Winds that was targeted. I think it targeted around like 20,000 of their customers. So and you have to keep in mind.
Starting point is 00:20:47 So like let's say if you have 20,000 customers companies using the same software. And that was a massive problem. It means that all of them have been hacked. So what happened is what they did is what we call a supply chain attack, you know, where they managed to distribute a malicious update to all their customers. And whenever that update was distributed to all their customers, that was their infection vector for all of those companies. And that was probably like to date the largest hack of foreign countries.
Starting point is 00:21:23 That was a huge scandal, obviously, like the White House blamed the SVR agencies, which is like the foreign intelligence agency of Russia for that attack. So in that case, yeah, governments have been blaming and pointing fingers to Russia. but out of that we didn't see like much coming out of it in that case. And in that scenario, he took one cybersecurity company to be a victim that found out that they've been infected by luck. And then more and more people started to investigate and that they realized, oh, wow, like 18,000 customers from that company have been targeted. And the malware was like spreading undetected. Are companies good at sharing cyber information with each other? Because it is such a sensitive topic.
Starting point is 00:22:26 And when you're under attack, on the one hand, I imagine you don't necessarily want to broadcast it to the world. But on the other hand, you could argue that you have a responsibility to your customers, clearly, but also to other companies to flag a threat that is actually happening. Yeah, a very good question, actually. So in the case of solar wins, if that cybersecurity company that was a victim of the hack didn't raise the alarm saying, oh, we found this, that's suspicious. Then people followed up and were like, oh, that's actual malware. We found it present in other places.
Starting point is 00:23:04 People would not have been able to conclude that so many customers were targeted. And in that scenario, like you're saying, like the information sharing was very beneficial. Often for cyber security, so you have like few companies that are like the anti-virus providers or endpoint security companies that have a lot of visibility because of the telemetry they have on millions of machines. So for them, it's pretty good and pretty easy to see if something new happens, you know. In the case of Microsoft now, which is probably like the biggest cybersecurity company in the world, are only, They have very, very good telemetry. Before the invasion, so a wiper, which is a malware that's designed to erase the computer, was detected. So a few different security vendors managed to detect it.
Starting point is 00:24:04 Microsoft was one of them because that really good telemetry, they were able to detect it within a few hours. In that case, you know, like what we notice so far when it comes to like cyber is there is a huge focus on cyber before the war become actually kinetic. So either to destabilize the enemy or to gather information. How often, you know, you mentioned, and I remember the Solar Winds hack that used a patch update to distribute malware to SolarWinds clients. How often are cybersecurity companies themselves the target of hackers? And this technique of using a cybersecurity update patch to distribute malware, how common is that? And just in general, how much are these companies themselves the target of attacks?
Starting point is 00:25:01 Very good question. So often does it happen for security companies to be like targets? It probably happens all the time. because of the assets that they have either like toolings, like the tools, you know, or the human resources they have, you know, that could include being targeted at conference or not. Like I was telling, like I was giving an example to Tracy. So for instance, I was supposed to give a keynote at a security conference in Russia a few years ago before COVID. So one year before COVID.
Starting point is 00:25:40 And I got denied of entry in Russia, so at the airport. So I was not able to deliver the keynote at that conference. The official reason is because my visa was not valid. Although I told them, I was like, you are the one who should meet the visa. What do you mean? It's not valid, you know? And I had to fly back on the next flight back to Dubai. So in that case, you know, like, and often, you know, like, there's always stories in security conferences where, like, security researchers, you know, like, are either, like, being followed or, like, someone, like, went into, like, the hotel room, you know.
Starting point is 00:26:20 There is a bunch of, like, different stories like that. So when it comes to, like, often, like, security companies or security researchers are being targets, it happens a lot. It also happened, like, last year where, like, a bunch of security researchers were, like, active. targets by North Korean hackers, mostly to try to steal tools from them or if they had any exploits. So for the audience, an exploit is what like groups or nation states can use to directly like target a machine so they can get unauthorized access to a machine. So usually they have, if you have a security vulnerability in a software and you have,
Starting point is 00:27:05 the software that can take advantage of it, that's what we call an exploit. You have different categories of them, including what we call like zero-day exploit, that even software providers are not aware of. So that could be like Microsoft, Apple, and in some cases, it may not even require like any user interaction to be enabled. And in the case of the nation state type of hacking, because that requires a lot of R&D, it is very expensive.
Starting point is 00:27:36 Some of those exploits like go for sale on the like gray market for like millions of dollars. And also like it's very complicated to do because unlike traditional weapons that's not something that you can replicate. Each security vulnerability bug is going to be different
Starting point is 00:27:53 and it requires a specific set of a skill set to be able to find and write an exploit. So in the case of a full on like cyber war, a lot of people were kind of expecting countries to stop to use, like, exploit, like left and right at each other. But to go back to your other question, it's something that's very difficult to measure because there's no, like, proper unit of measures for, like, often it happens. That's only, like, when you know it happens, it's only a small subset of the information
Starting point is 00:28:29 that you have. sometimes like what's happening over the past two weeks and over the next months. I'm pretty sure we're still going to be analyzing it like, you know, in three, four years. Like some of the tools that have been released by the shadow brokers, a lot of the exports were like four or five years old in that case. And when they got released, you know, it was, you know, like pretty, it got a lot of attention. some of them have been even like repurpose into some new malware, including NotPetya, which was targeting Ukraine at the time. So it's very difficult to have, yeah, pretty ironic.
Starting point is 00:29:12 Yeah. It's pretty difficult to have like data on those things. And keep in mind, like you said before, when you get hacked, you know, you don't get like some face like showing up on your screen and some guy laughing. But it is very important to highlight actually because cyber is mostly used for intelligence. So you want to know what your target is doing.
Starting point is 00:29:36 Unless you just want to steal money, you know, that's a completely different category of a cyber attack. So like, do you have a clear goal? You know, you're like, oh, okay, money is gone now. Like if a crypto exchange is being hacked or a swift service bureau is being hacked. But most of the time, it is for intelligence. And whenever you have access somewhere, you want to make sure you keep your access. So whatever door you use to enter the machines that you have been targeting and where you are like fitting form in terms of intelligence, you don't want to lose that access. And that's also one of the big suspicion.
Starting point is 00:30:15 Like there is cyber, there are cyber attacks happening now, probably on both sides, but we don't necessarily see them. In January, there is a Belarussian group called the Cyberpartisan. I don't know if you have heard about them. But they are very organized. They're all like independent, all anonymous, dis centralized, around like 20 to 30 people. But what they did back in January, when they started to see that Russia started to ship military equipment from Belarus. Belarus, they started to target the railway system of Belarus. And this is pretty interesting and very important to notice because so far when you hear
Starting point is 00:31:07 about like independent groups, you know, kind of like really anti, like counterattacking or doing something, it's mostly like shutting down website, changing a website. But here you have an independent group that actually managed to create a dent into like a big enemy to affect their logistics. So by slowing down, well, by shutting down the railway system, they were able to slow down the transportation of military equipment. And the second objective, which is like suspected, is also to create a doubt with, the enemy in that case with Russia, with the leadership. So to show that the Belarusian allies were not necessarily like that reliable, but also on their side, once they realized that it actually had been hacked to create a doubt saying,
Starting point is 00:32:10 well, if their railway system have been hacked, what makes our own railway system like immune to such an attack? So they would spend additional like few days or weeks investigating their own infrastructure, postponing like the transportation of military equipment and assets. That's interesting. I want to ask more about retaliatory hacking. But before we do, I just want to go back to something you said about exploits. Is there a marketplace for exploits? Like how are these things actually sold or dealt?
Starting point is 00:32:46 I just have this vision in my head. head of like a guy with a briefcase in a hotel room opening it up and there's like different exploits in the briefcase. But obviously it wouldn't happen like that. It depends, you know, like if Nicholas Cage was like selling exports, you know, I'm sure it would like this. But in some cases, you have to keep in mind that some of the transactions don't necessarily want to be like traced. So using cash actually would make sense. using payment over like cryptocurrency would make sense using wire transfer would make sense
Starting point is 00:33:21 as long as there is a transaction for something you know like everything you can imagine does make sense right so like that image you have in mind I'm sure it happened in some scenarios but regarding like outside of what a transaction might look like what the marketplace may look like.
Starting point is 00:33:45 Obviously, it's not like a Fiverr or like a Facebook marketplace where you're just selecting what you want. So you have companies that are brokers doing this. Some of them, you know, like are quite public in the US or in Australia. Usually they would work with their own government. In the case of each government is going to have different stories. like in the case or for instance like China there's a competition that was organized
Starting point is 00:34:18 a few years back called the Tianfu Cup where as part of the competition they were saying okay like if security researchers like find a bug you know like we're going to report it to vendors etc but one of the exploits was actually linked to another exploit very similar that was used against the Uyghos. So regarding like all people by exports, you know, like there is a demand that's higher than the supply in that scenario.
Starting point is 00:34:53 So most of the time and the buyers are always the same. You know, it's going to be like governments like either like NATO members or like, you know, like China like or like Russia, etc. So most of the main governments would just buy those exports. I'm sure they also have some researchers, like internally finding their own bugs and writing their own exploits. But yeah, like you have a bunch of brokers like in different countries. The news doesn't stop on the weekends. Context changes constantly.
Starting point is 00:35:42 And now Bloomberg is the place to stay on top of it all. Hi, I'm David Gurra. Join us every Saturday and Sunday for the new Bloomberg. this weekend. I'm Christina Rafini. We'll bring you the latest headlines, in-depth analysis, and big interviews, all the stories that hit home on your days off. And I'm Lisa Mateo. Watch and listen to Bloomberg this weekend for thoughtful, enlightening conversations about business, lifestyle, people, and culture. On Saturday mornings, we put the past week's events into context, examining what happened in the markets and the world. That on Sundays, we speak with
Starting point is 00:36:13 journalists, columnists, and key political figures to prepare you for the week ahead. Join us as soon as you wake up and bring us with you wherever your weekend plans take you. Watch us on Bloomberg Television. Listen on Bloomberg Radio, stream the show live on the Bloomberg business app, or listen to the podcast. That's Bloomberg this weekend. Saturdays and Sundays starting at 7 a.m. Eastern. Make us part of your weekend routine on Bloomberg Television, radio, and wherever you get
Starting point is 00:36:39 your podcasts. What separates good leaders from transformational ones? I'm Jessica Chen and in season two of Leading by Example, we'll sit down with executives like Grace Chen of Bertie Gray to find out. It's important to understand where you spike, but also really acknowledge where you don't and find people who can fill those gaps. Listen to leading by example, executives making an impact on the IHeart radio app, Apple Podcast, or wherever you get your podcasts.
Starting point is 00:37:20 So I don't want to get sidetracked on this too much, but I do want to ask one question because you mention use of crypto for payments. And, of course, there seem, you know, the two sides of this question take out very maximalist viewpoints. I don't really trust either. And so you have government saying, oh, crypto is just used for money laundering and crime and stuff like that. And that seems to be an exaggeration to say the least.
Starting point is 00:37:45 And then you have the sort of crypto defenders who go to the extreme and say, no, crypto is terrible for any of this stuff because you can all see it on the blockchain. and so don't point finger at us. As someone who is sort of watching this, where do you come on in this question and how do people in the hacker community think about the advantages or disadvantages of using crypto for transactions?
Starting point is 00:38:10 Well, it depends for what. In case of ransomware, which is a malware that's going to infect machines, encrypt files, and ask for like a ransom in exchange, of decrypting the files usually those transactions are happening happening over crypto like in that specific scenario for ransomware like crypto uh currencies literally like created the whole like new market uh for like criminal hackers uh because otherwise like if crypto was not around you know like you not see like ransomware you can just you could not ask for a payment over
Starting point is 00:38:49 wire transfer or, you know, like all over PayPal. Although, like, in some attacks, you know, for like fishing emails, you know, when they change invoices, you know, they put the fake bank account. You still end up doing like a wire transfer and a large amount of money are being transferred. But if that would be the case, you know, for law enforcement, it's much easier to actually like trace who is behind it and to find, okay, like, that attacker was there. Those are like the people who opened the account. to get their mules and then to like trace back efficiently.
Starting point is 00:39:23 We're getting like, yeah, cryptocurrency in the context of Ukraine and Russia. Like there is very like there's a bunch of interesting things happening. For instance, like the money that the Ukrainian government has been raising over crypto. Right. Like a bunch of like the founder of Ethereum donated, the founder of Solana donated, the founder of Polka dot donated. and they managed to like buy equipment with it and invest, etc. They're also talking about launching their own NFT campaign, you know,
Starting point is 00:39:57 like in exchange for like people, etc. So they're like using like crypto in a way that makes sense for like financial transactions. But my personal opinion also, it's also like what we are witnessing is obviously there is an actual conventional war where people are being killed in that sense. But on the other side, Ukraine has been doing very well in terms of fighting disinformation, which is widely used by the Russian government. Like when they are spreading fake news about, like, Ukrainian soldiers, like, being defeated to kind of like reducing the moral of the troops.
Starting point is 00:40:47 But instead what we see is Ukraine promoting news of like, oh, like, look at those farmers. I've been stealing a tank with their tractor and they're sharing videos that are going viral. And we see them, oh, we're using crypto to raise money. Like, hey, people from the internet, like we need your support. Oh, we're also going to do an NFT, you know, like support Ukraine NFT. So I think it's also part of the response to Russian attacks, but not only from like the actual like cyber attack point of view, but also like from a disinformation point of view. Because if you keep the news like positive around it and people engage, people on your side, while sanctions are happening on your enemy, that's very efficient. And I think that's like the way where Ukraine has been very innovative in how to use crypto since the bargaining of.
Starting point is 00:41:43 the invasion. I want to go back to Russia and Ukraine specifically. So you mentioned the one group and its attacks on Belarusian railways. What are the options for retaliation from either the West or from independent groups who want to create trouble for Russia? in the case of like what's happening with yes so we have the German government saying okay like we think we've been a victim of a cyber collateral damage from the conflict so they recognize they've been a victim from that I guess we're going to see like the response to it we're getting that I'm sure a lot of NATO countries are also like really a thing in private, not necessarily like communicating about it.
Starting point is 00:42:44 That's what I was saying. A lot of the things we're probably going to like see more, you know, like in a few years actually. And actually I'm glad that a podcast is happening like a few weeks after the invasion because it also gave us some time to kind of what shot was happening instead of just speculating
Starting point is 00:42:59 of like, okay, are we going to go in full on like cyber war? Are like all the countries, you know, in Europe going to have like the electricity being shut down? for like days, you know, so far that's not the case. And regarding the response from the governments, so there are like few aspects to it. I think a lot of government so far also realizing that they have been overestimating the capabilities of Russia.
Starting point is 00:43:31 And that's not necessarily like only from a cyber point of view because like I was saying at the beginning, there is what we can see now is like the poor planning and the logistics since the beginning of the invasion from Russia. In terms of cyber, yes, more can be done from both sides. But like I was saying, most of it is for intelligence. At the beginning, for instance, the satellites that were hacked, you know, was mostly to disrupt the military infrastructure. But as we see now, like two weeks later, the military. military infrastructure of Ukraine is still like functioning like pretty efficiently.
Starting point is 00:44:13 So if they could have done it, they probably would have done it by now instead of just like dragging the, you know, like in the conflict like longer. But yeah, in terms of response from like NATO and in general for like cyber attacks, you know, I think we're going to see a lot of like policy being changed, you know, over like the next month, you know, probably like new bills being passed, you know, uh, that it's becoming, uh, one of the priority for governments and there's probably some cases,
Starting point is 00:44:46 you know, that didn't listen to, uh, before, but I would not expect much, uh, in terms of like traditional response. Like,
Starting point is 00:44:54 you know, I think it's just like response in the sense of like, okay, there is a war happening, potentially like a world war. Like, are we going to respond? And it's probably going to be like more sanctions.
Starting point is 00:45:06 Like, what we are witnessing now. Those are like part of the actual response. And it also implies, you know, like if they obviously like hack the NATO governments. So that may be like, like we have seen like Russia being disconnected from Swift. Then some tech companies, you know, like Apple or Microsoft not selling their softwares anymore. At the month is still unclear. If software updates, it's going to be like deployed in Russia.
Starting point is 00:45:35 because if they are not deployed, it means they will not have access to security updates also. So so far, they're just talking about payments and selling. So like Steam, you know, like a video game company was like that, Microsoft, Apple, you know, like stop providing access to the app store. But those are like the response we are seeing so far, like Swift, mostly like sanctions, either by governments or like major tech companies. You know, we talk about Russian hacking teams, mentioned North Korea, China. Is it safe to assume that anything that's being done by those countries that US and NATO government have the equivalent teams and capabilities?
Starting point is 00:46:25 Oh, yeah, definitely. I mean, one of the big release from these shadow brokers was to show the capabilities of the U.S. government. and some of that was also including, you know, like, targets from the U.S. government. Same thing when Snowden released some of the documents. We also saw some of the targets from the U.S. government, including European, like, telco companies, although they are allies. They are not enemies. Spies are just continuing to spy, you know?
Starting point is 00:47:00 It's just like spying stuff everywhere. So that actually leads to a question that's been on the back of my mind this whole conversation. The spies are always going to be spies. Is it worth thinking of cyber warfare as a sort of discrete event? And so, of course, when we think of conventional warfare, there's often a start. There's an invasion. Maybe there's a ceasefire. Hopefully at some point soon the war ends.
Starting point is 00:47:30 Is cyber warfare an event? or is it an occurring sort of ongoing persistent element of the interaction between nations these days that doesn't have any sort of like starter end? I would say it's a component of wall. So I at the beginning I was talking about like hybrid wall versus like conventional wall. And mostly it is used here for intelligence gathering, so to collect information. on troops, enemies, capabilities. It may be used for disruption, like we've seen with the satellite,
Starting point is 00:48:10 like a few weeks ago, all of the cyberpartisan in January, but in that case, working as an independent group because their goal is like to protect the Belarusian democracy. So it may have some strategic objective. like in the case of like the railway system in Belarus. But it may also just be like intelligence.
Starting point is 00:48:40 And I think here it is mostly used for intelligence. For disruption, it does not make that much sense once you enter in a kinetic mode. Because if you can just, if you have soldiers like physically present in the country, you can just shut down like cell phone towers. You can engage in electronic water. in electronic warfare. You can start jamming, you know, like, whatever, like, ways of communication there is.
Starting point is 00:49:07 So you don't necessarily need to use, like, cyber. Cyber makes sense before the kinetic, like, war happening because you're going to collect information. You may do some light disruption. But at some point, like, once the war is starting, it becomes more of a conventional war where, well, you need a winner and a loser, you need an agreement,
Starting point is 00:49:32 or you have like a ceasefire, and then cyber, just like, you know, kind of like this background element, depending if you include, you know, like disinformation, propaganda and misinformation as part of cyber or not, because as we can see now on social media,
Starting point is 00:49:50 a bit like when the Arab Spring was happening, when a lot of people were like sharing information on Twitter, now we can see people sharing a lot of information on Facebook, Instagram, Twitter, around the war, you know, like the donation, like the stories, you know, like the stories like I was saying about the tanks being stolen and being shared, going viral. That's part of the information warfare. And that's a very new component because like things like TikTok, et cetera, didn't use in the past and now they're having also like their role.
Starting point is 00:50:27 within this information warfare. Does that mean that those of us sitting in the U.S. or Europe, we don't need to be worrying about, you know, an attack on critical infrastructure that suddenly takes away our electricity or empties out our bank accounts or something like that? Yeah, no, I would not be worried about it. And even if it would happen, you know, I'm sure, like, you know, electricity would be done for, like, a very short period of time
Starting point is 00:50:53 because there's process in place on how do you recover, like, system just like if something is faulty, especially for like critical infrastructure. So I would not really worry. One of the big stories we're getting like critical infrastructure was like the Stuxnet story, which is more than 10 years old now back in Iran when that joint operation between Israel and the US was targeting one of the nuclear central. They kind of just stopped it. And then back then, you know, like some movies like came out. What was the name? with Chris Sandsworth, Black Hat, you know, where like this, this nuclear central that's exploding at the end, et cetera. It's like the Hollywood version. But in reality, okay, like, it's
Starting point is 00:51:36 down, you know, like, what are the guys doing, you know, because they already have, like, process in place. And if you are, like, the US or Europe, you know, like, you definitely, like, plan for, like, faulty issues, regardless if it's like cyber or something that's not working anymore. But, yeah, in terms of, like, money being drained from your account, although. you won't have your money like being drained directly but you know like how low like stock markets
Starting point is 00:52:05 are going to go down now or is it going to affect like you know like the inflation like we can sit with the rubble now like it's completely crashing so technically money is not running out of your account but you know you can do less with your money or like you're like whatever you have
Starting point is 00:52:19 is less valuable you know so I think that's kind of like one of the side consequences that we would see last question for me me is what is the skill set of a good hacker and thinking about, okay, if you're Russia or any government, you're recruiting, what do you look for? What makes a good hacker? Well, I just want to clarify, I'm not recruiting like hackers for the Russian government, you know, because of the way you first question.
Starting point is 00:52:46 What would they be looking for? Or what would any government be looking for? Yeah, yeah, or like private companies, no, because actually most of like, most of really good like security researchers I know are just like either independent or working for like tech companies because they tend to pay like the best you work on building cool technologies and yeah usually people are like really good just like end up doing a lot of research so you want to work with the very very best and no it's such it's a field that's moving like so fast that at the end of the day you know like you need to like surround yourself with the best otherwise like you won't learn like everything right so
Starting point is 00:53:26 I don't know if there is like, you know, like the, there is no like equivalent of like Wall Street bet for like hackers per se, you know, where like people are just like sharing like random information around. But in terms of skill set, you know, like I keep reminding people that hacking or being a hacker is a skill set first, you know, it's not an ethical or political position that comes like secondary. It's like if you're a lawyer, you know, like you don't ask him if it's like ethical and ethical.
Starting point is 00:53:53 And we have seen in the past with like Panama Papers and all those things, you know, like you could ask the question as well for like lawyers. But yeah, most of like good security researchers or hackers, you know, they all have different background, different skill sets, because it can go from physical security to radio frequency,
Starting point is 00:54:13 to like software security, hardware security, firmware security, like open source intelligence, you know, we see more and more people, even like groups, you know,
Starting point is 00:54:24 like Belling cat, you know, like that tracking a lot of the military activity, you know, from online resources, you know, like on the different groups. That's, you know, like those are like all like different fields that come from like information security. So I mean, like, yeah, everyone who is curious, you know, and like likes to put the time into the research is a good hacker. You know, I've seen like journalists were like really good at doing their research, you know, etc. They're like sometimes they have more knowledge and more skills than some of actual professionals.
Starting point is 00:55:04 So it's really something that's very across like multiple disciplines. Well, Matt, I think that's a good place to leave it. Thank you so much for coming on odd lots and spending time with us to explain hacking and what it could actually look like in those contexts. Thank you. Thank you. So, Joe, I really enjoyed that conversation. I don't think we talked about it, but the shadow brokers actually called Matt a fun guy at one point.
Starting point is 00:55:46 And he is a very fun guy. He's really good at explaining some of the more technical aspects of this. But I thought his framing of cyber as a component of conventional warfare, I mean, that seems right, at least so far, like, given what we've seen so far. I think that's right or two. Or let's put it this way. I think I found that to be really helpful because when I think of you know, when you think of cyber attacks, I think we often have these very dramatic visions of some big grid being taken down. And obviously that's possible. And you mentioned examples.
Starting point is 00:56:20 You mentioned the example of the Belarusian Railway of the Ukrainian grid. But that more the more common impulse is intelligence gathering. And that's the big thing. Collecting data is sort of a useful way of thinking about its right. Yeah, and the other thing that it sort of coalesced for me was the idea of a lot of governments have been tolerating these attacks for a long time. And this seems like a crunch point, at least when it comes to Russia, right? Like I was reading Goldman Sachs put out a note right before we came on to record this talking about cyber warfare. And they had a stat in there, something like 60% of state-sponsored cyber attacks are thought to have come.
Starting point is 00:57:06 from Russia, which seems extreme. But for some reason, no one really did anything about it. Yes, there were some sanctions in place, but now we've seen, you know, a very dramatic form of sanctions rolled out. And it seems doubtful that that kind of behavior is going to be tolerated going forward. Yeah. And but on the other hand, it's so nebulous. It's so difficult to know what you're going to do about it. And the point, you know, as Matt was saying, a tax that are happening right now, of which they're certainly going on. We'll be talking about in three or four years, perhaps. So when we learn about them and how difficult it is to know often when you're being hacked
Starting point is 00:57:44 or what the scope of the damage is. That in that element, very different. I think here's the word, you know, maybe I don't know if here's the word metrics, but this idea we have metrics to measure the devastation of conventional warfare. We don't have, and it seems very implausible that we would have anytime soon, sort of equivalent metrics for cyber warfare. Yeah, it seems like it. All right.
Starting point is 00:58:10 Well, shall we leave it there? Let's leave it there. All right. This has been another episode of the All Thoughts podcast. I'm Tracy Allaway. You can follow me on Twitter at Tracy Allaway. And I'm Joe Wisenthal. You can follow me on Twitter at The Starwort.
Starting point is 00:58:25 This episode was produced by Magnus Henrickson, who is smartly not on Twitter. Follow the Bloomberg head of podcast, Francesca Levy, at Francesca today and check out all of our podcasts at Bloomberg under the handle at podcasts. Thanks for listening. You can get the news whenever you want it with Bloomberg News Now. I'm Amy Morris.
Starting point is 00:59:17 And I'm Karen Moscow here to tell you about our new on-demand news report delivered right to your podcast feed. Bloomberg News Now is a short five-minute audio report on the day's top stories. Episodes are published throughout the day with the latest information and data to keep you informed. Yes, there are other products like this from a variety of news organizations, but they usually rerun their radio newscasts throughout the day. That's not what we do. We create customized episodes that can only be heard on Bloomberg News Now. And we don't wait an hour to publish breaking news.
Starting point is 00:59:51 When news breaks, we'll have an episode up in your podcast feed within minutes, so you're always getting the latest stories and developments. Get the reporting and the context from Bloomberg's 3,000 journalists and analysts. we're all over the world. Listen to the latest from Bloomberg News Now on Apple, Spotify, or anywhere you listen. What separates good leaders from transformational ones? I'm Jessica Chen, and in season two of leading by example, we'll sit down with executives like Grace Chen of Bertie Gray to find out. It's important to understand where you spike, but also really acknowledge where you don't and find people who can fill those gaps. Listen to leading by example executives making an impact on the IHeart radio app, Apple Podcast, or wherever you get your podcasts.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.