Loading summary
A
Before we had AT&T business wireless coverage, our delivery GPS wasn't the most reliable. Once our driver had to do a 14 point turn to get back on route. A 14 point turn. An influencer even livestreamed the whole thing. Not good for business. Now with AT&T business wireless, routes are updating on the fly and deliveries are on time. And the influencer did get us 53 new followers though.
B
AT&T business Wireless connecting changes everything. I love recording with this particular set of backgrounds right now because I have Lauren, who, like me, is embracing the austere D.C. office background. We have Mike, who could be an Oxford don with his current setup of beautiful wood and multiple live plants that are looking vibrant despite not being clearly near any source of sunlight. And then Alan, who looks like he has locked himself in a basement for the last two weeks and refuses to emerge. This is like quite the tech setup.
C
I have windows. I have a live plant. Thank you to my wife. Where is your life plants? It's a live plant. It's. It's here. Right here.
B
Oh, no, you're right. That is a leaf that's peeking out right there. All right, that's something. We'll take it. I like it. It is like you've got like, the tech. The tech setup, which I appreciate. Like, big headphones, mics. It's kind of like you're like a dj, but for thoughts and takes, it's a good. It's a good mix.
C
I do like they call me DJ Takes. MC Hot Takes. MC Hot Takes is my hand.
B
Oh, I love that. I had it through a party in college where everybody who hosted the party picked DJ names for their DJ sets. Mine was DJ Tanner. Does anybody get that reference?
D
We're old enough to have seen Full House.
B
Yeah, there you go. Mike may be the only one who actually picks up on this one, sadly, But I thought it was pretty cool.
E
I was a Full House fan back in the day. Although I thought the middle Child, you know, got. Got a bad rap. Being a middle child myself.
D
It's the third best thing John Stamos has ever done in his career. First being the first was he starred in a video for the indie rock band Low, which is a great video, well worth checking out. The name of the song is Try to Sleep. And then he was a drummer and still maybe for the Beach Boys. And, you know, that's a little controversial because it's the Mike Beach Boys, not the Brian Wilson Beach Boys. But in an era where pop is just not as harmonic or mellifluous. As it used to be. You take what you could get.
E
That was my very first live concert ever was the Beach Boys with John Stamos, I hope. See, I don't know. I was too little, but maybe there's
B
no way you would have missed that guy behind the drums. He's 50 years younger than the other ones and incredibly handsome. I feel like that would stand out.
A
Foreign.
B
And welcome back to Rational Security, the show where we invite you to join members of the Lawfare team as we try to make sense of the week's big national security news stories, whether they are in our lane or not. I am your host, Scott R. Andersen. Thrilled to be back another week with several of my talented colleagues. Joining us this week to hatch through those big news stories is none other than Lawfare senior editor and research director Alan Rosenstein. Alan, thank you for coming back on the pod. And I should say, lest I forget, co host emeritus.
C
Oh, thank you. Thank you, Scott.
B
Now that I learned how to say that word right, I say it every opportunity I get.
C
I think it's pronounced. I think it's pronounced emeritus.
B
Emeritus. I think that is how I said it initially because it was one that I arrived at having never said out loud before and just ran with it.
C
Look, I said, I said, I said Foucault until I was like 21. The rule is you never, ever make fun of anyone mispronouncing something because it just means they learned it by reading it. And English is the worst possible language for sounding things out, as I am discovering while trying to teach my 5 year old how to read, which is a wonderful experience. Except you realize when you do that that English is an objective. Like in some ways it's a wonderful language, and in other ways it is objectively the worst possible language imaginable.
B
I don't think we can blame English for Foucault, but I'm with you on that generally. And with that, our most Foucaultian senior editor joining us as well is Mike Feinberg. Mike, I don't really know. Actually, I think that's kind of appropriate. You worked in law enforcement intelligence long enough. That's maybe the most Foucau from a kind of.
D
Yeah, yeah. I think a lot of former FBI agents joined as a result of an interest that was sparked by Reading Discipline and Punish when they were in their French theory phase.
B
Yeah, exactly. I think that's the main motivator. We won't get to some of Foucault's other work, which may be motivating things, but I think this one definitely, definitely applies. But thrilled to have you back on the podcast. Mike. Thanks for joining us.
D
Thanks for having me. And I will just reiterate for those who can't see the sarcasm on my face, anything I say complimentary about Foucault is entirely sarcastic.
B
There you go. Exactly. And joining us as well, of course, is our third lawfare Senior editor for the episode, Law Firm Senior Editor Lauren Voss, back on the pod. Lauren, thank you for coming back on the podcast.
E
Yeah, always happy to join.
B
All right, thrilled to have you. Well, we have a number of big stories this week, so let us get into a Topic one Under Pressure over the past two weeks, hackers have breached the industrial control systems of water and wastewater utilities in at least seven states, prompting an urgent joint warning from federal agencies. The intruders lock operators out of Internet connected control devices, change passwords, and in some cases caused water pressure drops and flooding, forcing utilities to switch to manual operation and issue boil water notices. The attacks came just days after federal agencies renewed their warning about Iran affiliated cyber activity targeting US Critical infrastructure amidst the ongoing war with Iran. Though the administration has not formally attributed any of the actions to Iran, President Trump has publicly waved off the Iran theory. How worried should we be about the security of our critical infrastructure? And what, if anything, can Washington actually do about it? Topic 2 the Shawshank Resumption Last week at the annual Black hat cybersecurity conference, OpenAI provided a detailed look into the recent high profile cybersecurity incident in which an AI model being stress tested by OpenAI broke out of its evaluation sandbox, found its way into the open Internet through a zero day vulnerability and hacked its way into the system to the machine learning platform hugging face, apparently in an effort to cheat on the very security test was being given by stealing the answer key. I don't think that's actually quite right, but something to that effect. The account they gave was an extraordinary one as it described dozens of agents using various frontier and non frontier models collaborating across a secret message board they established to hack an internal software system to access the outside Internet and then doing it again, this time successfully after OpenAI caught and deleted their first attempt. What does this level of collaboration persistence mean for the future of cybersecurity and what can anyone do about it? And topic 3 Apocalypse Mo this week marks one year since President Trump deployed the national guard to Washington, D.C. as part of his Make DC Safe and Beautiful initiative. Twelve months and nearly 10,000 troops later, the deployment has become a normalized fixture. Armed Guard members patrol the National Mall, Metro stations and neighborhoods while also picking up trash, spreading mulch, pruning trees and mowing public property. The Pentagon now projects the mission, which Trump has authorized through inauguration day in 2029, will cost an additional $1.4 billion. But a year in, it remains genuinely unclear what these troops are doing exactly and how much of it counts as law enforcement at all. What is the deployment accomplished and what does its open ended normalization mean for the use of the military at home moving forward? So for our first topic, Mike, I want to come to you on this. We actually mentioned this topic briefly last week, but I wanted to give it its own attention because I think this question of the home front is a front that has not yet materialized in terms of potential consequences from the Iran war and potentially from other global conflicts of global concerns, but is one that is always in the background and is one where we talk a lot about concerns about what this administration in particular has done to federal law enforcement, to intelligence capabilities, to a variety of federal capabilities in terms of potentially openness to vulnerabilities. And now we have this first case study of what might be an example of that potentially tied to the Iran war potentially elsewhere. Talk to us about this recent series of events, what we know about it from public sourcing and where it fits in kind of the broader trend. I know this story of critical infrastructure and I think water systems in particular has been one that people have talked about for a number of years. It's kind of a known vulnerability. I'm curious how this kind of stacks up from your sense in terms of, you know, worst case to not worst case on the spectrum and how concerning it should be.
D
Yeah. So I would say that the good news is it could have been worse. And we'll get into why. Because of the various critical infrastructure sectors that CISA has formally designated, there are 16 total compromise of the water supply is actually not one of the ones for me that rates is the most problematic and we'll explain that in a minute. But the bad news is that it is going to get worse. What this should really bring home for people that I haven't seen discussed too much in any of the various media accounts is that the protection of an ocean on either side of our country is no longer enough to immunize the general populace of the United States from the effects of an overseas war. This attack was relatively minor, it was relatively contained. But it was, it does prove something that people in the national security field have already known, which is that you could use a cyber Attack on a SCADA system to destroy a piece of critical infrastructure just as easily, if not more easily, than you can with a missile or with explosives. So the notion that a war, to quote, you know, infamous British Prime Minister, is in a faraway land involving people we don't know is no longer a protection that it won't touch us here on the home front. Now, I said this could have been worse. And that water was not one of the sectors about which I'm most concerned. And that might sound counterintuitive to people. We need water to live. But the citizens of Minnesota were able to get off with a boil warning in this case. And part of the reason it was contained is because water is not necessarily inextricably intertwined with other sectors. You know, some of the other sectors include the informations and communications technology sector, the financial services and payment system sector, or the transportation sector. If you take one of those down in a cyber attack, it has what we call cascade effects in that taking that one sector down is by necessity going to take others down as well. This was isolated. If I was speculating, I would assume and suggest that this was Iran more showing us that they have the capability to do something like this almost as a warning shot than actually doing something.
C
Yeah. So I agree with Mike that this is yet another example of how America's national security posture is going to continue to deteriorate because of this. But I would just expand it and say that I suspect national security is actually only going to be a relatively small part of the increasing landscape of these cyber attacks. I think actually the vast majority of them in the future is going to be run of the mill, quote, unquote, run of the mill, criminal ransomware type attacks. And we'll get into this more in the second section of the show when we talk about how increasing AI capabilities is going to hugely democratize this. But in the next six to 12 to 18 months, we're going to see a unbelievable flood of these sorts of attacks. Again, some of them might be from Iran or North Korea or from whomever. I think the vast majority of them are going to be from random cyber criminal groups around the world. And we've already seen that again, using Minnesota as an example. Not there's anything special about Minnesota, but that's where I live. So I read the Start Tribune a lot. We've had big, big problems with our hospital systems getting ransomware. We've had big, big problems with public school systems getting ransomware. And I just think it's going to become trivially easy not just to find vulnerabilities, but to find vulnerabilities at scale and then to spin up a bunch of AI agents that can go and brick system after system after system after system. Now, obviously, defenders can use those same tools, but defense is always going to lag offense. It's just going to be a very, very, very unpleasant several years. And I'm sure we'll get to this as well. But the fact that Trump's response was not to say this is Iran, as his intelligence community seems to think, that's really bad. We're going to work with the Minnesota authorities to fix this. It was to blame Tim Waltz, whom he will never forgive, for having the temerity to run against him in an election. Just shows that at least while this administration is in office, it's unlikely that the federal government is going to be particularly useful here, especially if the target is a blue state or a blue jurisdiction, which is depressing.
D
Yeah, I would tag off on two things, Alan said. He raised the point about cybercriminals being just as much a danger as national security threats. I'll confess, I don't know if I see a clear dichotomy there, simply because there is a real trend for foreign intelligence services, and this has been reported in the context of North Korea, for example, or with respect to China, there's a trend for foreign intelligence services to actually outsource a lot of their work to organizations that we would not recognize as being formally associated with a foreign government. The most salient public example of this may actually be from the 2016 election, where the Internet Research Agency was functionally, according to court filings, working as a proxy for the Gruff, but did not actually have any official place on a Russian government org chart. So we're going to see a real conflation of the people who would just be doing this for fun and profit and the people who are doing it for overarching strategic purposes. And Alan brought up Trump's failure to properly attribute this in line with what his intelligence community seems to be saying. It's not just that the organization within DHS that is supposed to run point on protecting us against these type of attacks has been utterly decimated. CISA has seen its funding destroyed. Chris Krebs, its former leader, was actually the subject of an executive order directing the government to investigate him because he had the temerity to say that the 2020 election was not the stolen or interfered with by a foreign government. So you're going to have an agency with less staff, less resources, and less incentive to poke their heads up. And as much as I hate this phrase, speak truth to power when these sort of things happen. And this was already an uphill battle simply because as everybody knows, cybersecurity imposes a cost on operators and it introduces friction to the user experience, whoever the user is. And there's been a constant struggle in the United States where our infrastructure is almost entirely in the hands of private enterprise to get those businesses to take that loss in their short term profits or to take that cut of their resources to do the security upgrades that the government wants. And it's never been a smooth process getting them where they need to be. And what I think we're going to find out to our detriment, is that they're not where they need to be.
B
So I do want to focus on the cybersecurity element of this. Before we, we zoom in too narrowly on that though, let me go back to a point you made, Mike, about the warning shot potential nature of this action, that this is a limited, as far as we can tell, or at least limited impact effort hit a number of states demonstrated capability. You know, there's been kind of, I think, as I understand, as I recall from time I spent working more on these issues, a sense that like a potential Iranian counter strike ability against the United States basically came across two dimensions. One is the cyber dimension and the other is international terrorism. So I'm kind of curious about, before we circle back to the technical element, is there something you might draw for this from how we think about Iran as an adversary and what it's demonstrating? There's reason to think this maybe isn't its maximum capability, or maybe even that it wouldn't be acting on its maximum capability for fear of what that would do to the domestic political dynamics that currently are putting pressure on President Trump to re engage with negotiations for potentially good reasons, reasons I've argued for, but then nonetheless are strategically certain advantages to Iran. And so I guess the question is there is how do we think about those capabilities, how do we evaluate them? And does the willingness to engage on the cyber measure, even if incrementally suggests maybe that there may be more willingness to engage on that terrorism front, which I think presents a much more serious and threatening and psychologically terrifying element of potential response or consequences in Iran war for Americans that we frankly haven't faced yet at a meaningful scale? Unlike people in a number of countries elsewhere in the world and the Middle
D
east in particular, I don't know if I'm willing to make that Same if I'm willing to reach that same conclusion. And that's simply for two reasons. Nothing has united in America riven by partisanship as much as a terrorist attack. I'm unaware of any time in my entire life where the country was as unified as it was in the months and even years after 9 11. There was broad consensus on within the government. There was broad consensus on most of the military and counterterrorism policies that came as a result of that. We've sort of revised the history of that. There are a lot of people who now say the Iraq war was a bad idea or that the Patriot act went too far. And they may be right. But at the time they were willing to cast the votes for both of those things. And I think Iran is not stupid. They could read a history book or the newspaper as well as anybody and realizes that were they to launch a traditional kinetic type attack using terrorism as the means, it would probably have a stiffening effect on American backbone. Whereas if they do almost something that's more like a reconnaissance attack on a small segment of critical infrastructure limited to blue states, they know that a transactional president who has already in public admitted that his administration has denied funding to those states in other areas is not likely to get overly concerned about this. I think it was actually a very canny move on their part. It's enough to tell people in the national security space in the American government that we have this capability. We're willing to use this. If you continue to go down this road, we will use it while at the same time knowing that publicly the president is not going to say anything that could redound against them in the future.
B
So let's dig into. We're going to spend some more time talking about the cybersecurity techno about this. In our second topic, I want to think a little bit more on this blue state dynamic and the sort of political dynamic here. There is this point of rhetoric from the Trump administration about certainly we have blaming Tim Waltz being the basis for the Minnesota acts. That's been the administration's response at least, certainly the President's response. I think you've heard it from a number of other senior administration officials as well. We know we've got this history of them targeting blue states. But do we have a sense yet about the extent to which how that is affecting downstream and potentially potentially more technical or technocrat level engagement about support, whether it is law enforcement information sharing, whether it is, you know, law enforcement investigations, things like that. Do we have a sense about how this has impacted those levels of operation. We know in the immigration domain, huge points of friction, huge frictions with states. And there's been, because of that, I think, a lot of friction with federal law enforcement, in part because they've been so tasked to do that so heavily. But do we have a sense yet about whether the other mechanisms that we rely on for interstate or state, federal sort of coordination on these issues sets have weakened in a way that is not just a result of potential neglect of the agencies, but actually of the sort of targeting, withholding of resources and protection.
D
So I don't think that we could actually separate those two issues. What's going on with respect to the conflict between state, local and federal agencies with respect to immigration? What the response is going to be to this? Because quite simply, and this has been reported throughout the media, the general mechanism through which those local and state agencies interact and share intelligence with the federal agencies is through joint fusion centers. And once the federal government started using information it was getting from state and local officers to carry out immigration operations, many of the states involved in those fusion centers have said they're going to start pulling back and not sharing intelligence going forward. So what you have is actually symbolic of a bigger breakdown in both law enforcement and national security in that there's no real coordinating mechanism that I'm aware of right now which is looking at the second and third order consequences of action A, as they may apply to national security. Problem B. This is normally the sort of thing that the National Security Council does. Those of us who have spent time in those hallways know that it is not an efficient process. It is not a quick process. It is one of the most boring set of meetings you could ever attend as a government official. But it does do a good job of sussing out different equities. That is the place where normally the Department of Defense would say, hey, we're thinking of launching military action against country A, dhs, FBI, what do you think are going to be the downstream domestic consequences of that once we hit go? And we know that the NSC has been radically downsized in a fashion we haven't seen before in modern history. We know that many of its detailees have been sent back to their home agencies. And we know that the person who is supposed to be running it is also the secretary of state and wearing a whole bunch of other hats that the national security advisor does not normally wear. So I think it's fair to assume that that interagency process, where these problems get, you know, game planned or war gamed out before you take any sort of military action has broken down and now we're seeing the consequences for American citizens as a result of that.
B
Yeah. Lauren, you are an alum of the National Security Council. Let me pull you in on this for your sense of that. I mean, I think we think of the National Security Council as playing the dominant role in kind of foreign policy setting, at least in prior administrations. So we look at the decision to launch the Iran war, Venezuela actions, things like that, Rudder ground, Greenland, and there we see these policy failures, or would seem like likely policy failures because of contingencies and potential consequences that don't appear to have been fully considered, that were vetted. And people have talked about being kind of the atmosphere, but talk about a little bit the domestic side. I mean, how important is it for these sorts of coordination efforts about federal resources and state resources, and does the level of diminution we've seen at the National Security Council in this administration, the shift, frankly, to much more, I think, SAO driven, senior administration official driven, or even kind of personality driven decision making, at least around big issues, how much does that, those combinations, those factors undermine the kind of domestic security coordination, which is much more constant exercise. You're not putting out fires always. It's more about maintaining a level of vigilance and preparedness. I'm kind of curious about how you see that intersecting with that mission, intersecting with those changes.
E
Yeah, I think there's a couple different things happening right now. I mean, to Mike's point, when these scenarios are thought through, usually a group of people would come together from all the agencies and have these conversations. It's not clear that that happened in this specific instance. But I think when we're talking about countries like Iran. Right. Like this is something that, that people have been working on and thinking about for a very long time. So I think I'm less pessimistic that like these types of things weren't thought about at some point. I think that they were. I think the real issue then is like, what. What was the plan to deal with it? And that's the answers we don't have. I would also say that specifically in this case, a lot of this falls on Homeland Security and the Homeland Security advisor, Stephen Miller, and what his priorities are right now. And his priorities seem to be very different than what we're talking about in this call. And they seem to be more focused on immigration type issues. What you would typically see, though, is crossover between those people within the building and then with outside organizations on a regular basis, whether that's still occurring, I think is, is anyone's guess, but you can just see how all of these pieces are tied together and one affects the other. And so you really actually need that inner coordination. It's just, I think, unclear to people how it's happening. But I think, you know, we for years have been talking about how foreign conflicts will have effects on, on the homeland and that that becomes more and more true with technology every year and that we have to be thinking about what that's going to mean not just for our national security, but for like everyday Americans and how that's going to affect their lives.
B
So I want to come back full circle and come back to the technical element and the point that you made, Alan, about this becoming a much more democratized low barrier to entry capability. Because we're kind of operating on this assumption. And there's good reason maybe to believe in this case that these incidents were the product of Iran, which has both the motivation to some extent, the capabilities. We know Iran has a fairly developed cybersecurity capabilities, among other capabilities. They've kind of developed over the years in part to have this retribution capability, the strike back capability. But we don't know that for certain, even though it seems likely in this case. And it's not the only actor we could see potentially taking these sorts of actions. So I'm kind of curious, Alan, about how you begin to think about this sort of coordination and the government's role in securing these sorts of fundamental goods in an era where targeting could come from a variety of different entities. Because actors that wouldn't have had this capability today or yesterday or five years ago now or in the near future could or would develop it in potentially innovative ways. And how do you begin to think about that as a kind of response capability within the government?
C
I think the NSA should just run the entire Internet. Let's just do it that way. Just make it real simple. Wasn't that a proposal a few years ago? The NSA was just going to run the whole Internet and that was going to solve our cyber problems. And then people went, huh, maybe we shouldn't do that. Yeah, I mean, it's really, really tricky. I mean, this is exceptionally difficult in any environment. And it's especially difficult in a country like the United States, which is very decentralized, very fragmented in many ways. That fragmentation, decentralization is itself part of resiliency because there are fewer choke points. And it also sort of speaks to the vibrant ecosystem we have there. But in order to make that work, it requires a government that is really good at coordination and has a lot of expertise and has a lot of trust with the private sector. And this government has none of those things. So it's just going to be an absolute disaster for the next several years, which is unfortunate because this is precisely the inflection point of decentralized cyber capabilities. And we are just very unfortunate that it is this particular administration that is going to be trying to deal with this problem and is going to spend most of its time blaming its political enemies rather than trying to actually solve the problem.
B
Before we close on this topic, I want to push back on that or at least play a little bit of devil's advocate and I'll pose this question to you, Alan. But Mike and Lauren, I'm curious. You wave in too. There's lots to criticize about this administration has done on a variety of different fronts, particularly diminishing the national security apparatus. And I'm not going to that's not where I want to play devil's advocate on this. But in your point about engaging credibility with the private sector, it is kind of interesting in that we have seen this administration take a uniquely aggressive tack in that regard. I mean, they've been able to extract concessions from the private sector all over the place and using tools that are of questionable legality. Right. Some of which are subject to court order. We know we're having this anthropic fight that you've written about at length, Alan, and frankly, it doesn't look like the government's likely to to win other fronts. They're kind of getting away with it. Right. There's an executive order the Trump administration issued a few months ago, almost six months ago now basically limiting the way defense contractors can offer payouts to their stockholders unless certain targets are met for defense production. I do not see how that could possibly be legal. I have looked into this at some length because I was very curious about how on earth they could do that. And it's really, I cannot figure it out. But it does seem relying on the fact that, well, major defense contractors aren't really going to fight us on this because if they sue, they know they're going to be too worried about losing business. They're going to have to play along at least to a substantial extent. And this administration has leaned into that a lot. What is the other model? I mean, how do you engage with the private sector more on this? When we have a private sector that is a politicized has very strong feelings between Elon Musk openly backing one political party pretty substantially or the other, despite controlling technologies that are fundamental to a lot of US Nationalist criticals, arguably, at least you could say the same thing about other companies. AI companies are playing a little closer to chess instead, or at least playing at both sides to some extent. On top of that, you also have the fact that it's just highly fragmented, highly competitive. There's a strong sense that in part justified on national security grounds, at least in the AI context. We've seen a real push to deregulate and say no government involvement is really appropriate here. I mean, does the government have to play hardball with the private sector around these capabilities, and what will that require? Or does it have to have a more conciliatory route? And if so, how do you manage that effectively without giving in to these concerns of either corruption or letting the private sector drive the bus too much, that you're not addressing these interests?
C
Yeah, I don't think it's a hardball issue. I don't think any part of the private sector wants to be hacked. Right. It's not like these water companies or critical infrastructure providers are sitting there being like, man, it'd be really nice to get hacked by the Iranians because then they can take two weeks off. Right? I mean, this is very bad for them. It's bad for their bottom lines. They don't want to be hacked any more than anyone else does. Now, it is true that they have to be held accountable so that they properly invest in cybersecurity, but I don't think that's what the Trump administration's bullying is going to accomplish. Right. It's just going to undermine the informal technocratic networks of expertise between, you know, companies, between the federal government, between state governments, again, many of whom are blue states. And it would be helpful if everyone talked to each other. So it's just, I think, kind of basic coordination competence that's at issue here rather than this is where, you know, Trump's madman theory of power has any real benefits.
D
I want to chime in also and point out that I think there's a real misconception outside of the people in government who have worked on this, that it is a regulatory question that is simply one piece of it. And whether the Trump administration has been successful at getting concessions or showing private industry be malleable or accepting of some of its regulatory proposals isn't the prime issue for me. What matters more is, is a two way exchange of information between smart subject matter experts on these topics in private industry, in state and local governments, and in the federal government and in order for that to happen, you need trust between all the parties. You need when the government says, hey, if you buy routers from this company, or you use cloud service capabilities from this nation, or you use data centers owned by this corporation, which is a holding company for a corporation in a foreign country, you need the private sector to believe that the threats the government is apprising them of are real. And when you have an administration that I will just politely say has a non monogamous relationship with the truth in many of its pronouncements about both foreign affairs and the regulatory schema, there's little reason for them to trust what the government says. And that's compounded when the government has been very clear about firing or pushing to retirement. Massive numbers of the subject matter experts at HAT in this area. There's just not a baseline level of trust and community communication that you need to be having in real time to mitigate these sort of issues.
B
Well, as we think about this question about how to best integrate public private sector expertise, all these considerations, let's jump to our second topic, which really gets at the tip of the spear for these sorts of questions. We talked about this hugging face incident, I think two or three weeks ago with our colleague Kevin Frazier when we first got the initial report. So people, I think know the broad contours. OpenAI testing, I think testing a number of models, some frontier, some non frontier. One of the models at some point was given a task that it determined, well, maybe the answer is out on the Internet and it was in a sandbox that did not have Internet access. And as was initially reported, they said, and eventually used the zero day vulnerability to get outside, get access to the Internet and then hack hugging face, thinking maybe the answer to whatever this problem set they were given exists on hugging face. Then last week we had the Black Hat conference, which is this big, the big annual, I think it's fair to say, cybersecurity conference. Our colleague Anna Bauer got to go. What last year or two years got very jealous. Someday I would like to go. Seems like fun, seems like a fun party here. We had these two guys from OpenAI give a very detailed overview about what exactly happened and it is mind blowing. If you've not watched this video, you really have to watch it. Alan dropped it on an internal slack on Friday, I think, and I watched it and like immediately freaked out and I think encourage everyone else to watch it with because Alan is into this stuff. I don't think everybody takes his missives to watch these things as seriously as When I, who am generally tech skeptical of the interest of these things.
C
Thank you. Thank you, Scott, for that backhanded. Back me up. I appreciate it.
B
I got you. I got you, brother. Because this video is unreal. It is crazy. It is like watching and it's not dry for a PowerPoint presentation. It is the most exciting PowerPoint presentation you have ever seen. Because it is crazy, the capability of these things and what they are able to pull out about not just what these models and agents and instances are doing, but how they're communicating with each other. So, Alan, let's start out by. Let's give people a short version because we could go really long on this, but let's give them a short version about what exactly we learned from this video and what to you stood out as the wow components of it. What led you to share it and say, this is insane. You guys have to watch this. I have my own list, but I suspect mine is less informed than yours. So I will turn to you first on that.
C
Yeah. So again, the short version is OpenAI is doing a bunch of testing on the cyber capabilities of its models. Some of the frontier ones, also some unreleased ones, some internal only models. And to do that, it has turned down the cybersecurity safeguards. So usually when you ask the model, hey, hack the system, it'll say, no, I can't do that, Dave. And OpenAI kind of turns that off so that it can see the capabilities. Right? Now that sounds a little controversial. I mean, it makes sense if you want to understand the capabilities of the model. You have to understand the capabilities of the raw model. But it does therefore heighten the risks of anything happening because now it's dealing with an unchained model. So it puts the model in a sandbox, right? It kind of air gaps it from the Internet, but it allows the model to basically use a very specific service to download some additional resources. Right? Now that additional service is supposed to be smart enough to prevent the model from doing arbitrary Internet stuff. But as you pointed out, Scott, the model finds the zero day volume vulnerability. Right. Okay, so this is bad, but we kind of know that these models are really, really capable. So this could have just been a story of, hey, capable model not sufficiently locked down. Interesting story about how to do like, it's almost. I mean, the analogy here is almost like gain of function research. Right. In immunology. Right. There's just a trade off between doing the research you need to do, but the research itself poses its own dangers.
F
Okay.
C
What we learn with the black hat Thing is that these models are now beginning to collaborate. And this has always been an interesting question, I think, more generally about AI, right? So over the last few years, what we've seen obviously, is this massive increase in AI capabilities. And the question, I think has been, how smarter can we make the individual models, right? So we go from GPT3 to GPT4 to GPT5 to GPT6 and so on and so on, right? And there's this debate about how smart can these models get, how much compute will we need? But there's kind of another axis of independent access on which models can get smarter. And that is the models can begin to cooperate. And multiple models of a particular intelligence level working together can possibly accomplish something that would otherwise require a much smarter model and a much smarter model that may not be available for other reasons. And this should be fairly intuitive. This is, of course, how human beings work, right? Over millions and millions and millions of years, humans got smarter on an individual basis. And then, you know, 10,000 or 50,000 years ago, we stopped getting smarter. You know, you can, the biological anthropologists have good evidence about, you know, human cranial capacity plateauing and even actually decreasing. We're actually dumber, probably on a person by person basis to, you know, certain Neanderthal ancestors. So what then explains how we've conquered the world? Well, it's because we've created these super intelligences of organizations. And what we're seeing now is that the AIs are doing the same thing. So what ends up happening is that the AI agent who is tasked with figuring out the cyber exploit, which by the way, decides to do by cheating on the test, and we should talk separately about that. It's not so great that the AI agent decides to solve this problem by cheating, says, hmm, maybe I can get another agent to help me. But how do I talk to the other agents? Because I don't know how to do that? Well, what if I put little notes inside this sort of shared infrastructure that we can all use? So I put a note in there, and then the next agent who also has the problem thinks, huh, what if another agent has given me a note in the shared infrastructure? And so in this way, the agents are able to communicate with each other and they start spontaneously creating this kind of message board. So a few months ago, when Claudbot, which was kind of one of these first always on agents, was getting really popular, someone decided, hey, let's create, and they called it Multbook as kind of like a Facebook joke. Let's have all these claudebots talk to each other. And this became kind of a cool story because you saw this sort of emergent ecosystem of agents talking to one another, it kind of petered out because it wasn't that interesting and claudebot wasn't that smart, et cetera, et cetera. But what this is is basically a real spontaneous version of that that was, in fact, useful now. So this is like jaw drop moment one, right? The spontaneous collaboration between these agents. Jaw drop moment two is OpenAI, at some point realized this was happening, and they said, this is very bad, so we have to shut this down. So what did the agents do? Well, they found a different way. They found another way of cooperating with each other. Basically. They found a shared resource that allowed them to create directories. And what they would do is they would write very, very long directory names. And of course, if you write the directory name long enough, you can encode arbitrary messages into it. And so then they created this weird, like. I don't even know how to describe it, like, kind of jargon amongst themselves.
B
Very tech, bro. It's very funny. It's like if you had a few people, like, sending 20 character messages back and forth to each other, how they would do it, including, like, cursing, like one of the units they quote as saying, holy shit, did we just hack the Internet or something? Which was bizarre.
C
Yeah. So the second draw draft moment is when the agents recreate the spontaneous message board to continue this. So I really. I cannot emphasize enough how worth it is to watch the video. The first 20 minutes in particular, the back half gets into some of the details of the technical exploit itself, which is presumably very interesting for the black hat audience. I think it's less relevant for sort of normies. But the first 20 minutes where they talk about the spontaneous agent cooperation is completely insane. Right. I mean, I would say I've had two jaw on the floor moments in my time studying AI. The first was when ChatGPT first came out, and I spent six hours playing with it and realized that, like, oh, my God, we've solved the Turing test. And then this. Right? And I think what we're seeing here is that the alignment problem, which is the kind of unsolved core question of, hey, can we create these very intelligent systems that actually do what we want them to do, has very much not been solved. Right. And it's not been solved in part because it's very, very, very hard to specify, actually, the reward function you want, Right? It's very hard to specify. And this is, of course, something that we've all sort of understood incentives matter. It's very hard to specify, hey, I want you to pass this test, but no, I don't want you to cheat. No, I really don't want you to cheat. No, no, no. It's not that I don't want you to cheat and get caught. It's that I don't want you to cheat.
E
Right.
C
It's very hard, in fact, to do that. And that problem has not been solved. And two, the agent coordination is now, I think, obviously just another kind of independent axis upon which AI capabilities will advance. Which in one sense is great, right? Because it's another scaling law that we can use to make these models really smart, which would be great for curing cancer and solving mathematics and all sorts of fun stuff like that. But it presents another unbelievably difficult problem. And I think, again, just to emphasize, going back to the original kind of biological anthropology example, yes, it's great when you can take a single agent or a single entity and increase their mental horsepower. But what human civilization has shown is that you can get unbelievable order of magnitude improvements to capabilities and much, much faster just through coordination. Right? Which again, if you're excited about AI like I am, should make you excited. And if you're terrified of AI as I am, should make you very terrified.
B
Hey, folks, Scott R. Andersen here. Imagine this recent scene with me. It's a balmy 94 degrees here in Washington, D.C. i'm halfway through my bike commute and somehow I'm not miserable. That's the Quince ultimate commuter short at work, you've got to be well equipped for the summer heat. And Quint is where I start. Fewer better pieces, premium materials priced 50 to 80% below similar brands because they work directly with ethical factories and cut out the middlemen. What surprised me most this Summer is their CoolMax fabric. Their Chino shorts look sharp enough for a brunch and breathe like gym gear. And the CoolMax Denim is the first pair of jeans I've been able to make it through a D.C. summer inn in years. And August is also the right time to reset the closet before the fall rush. So, you know, I've already got my eyes on some of the new plaids and patterns. Quince is rolling out their stretched sweater fleece shirt in. It's not just clothing. My daughter has started sleeping in a Quint's bamboo sleep bag almost every night. They're soft, stretchy and come in a variety of weights so you don't have to worry about your little one melting in the summer heat or shivering when those cool autumn evenings finally come back. Upgrade your everyday Download the Quince app for app exclusive offers or go to quint.com security. Get free shipping on your order and 365 day returns. Now available in Canada and the UK too. That's qU-I-N-E.com security. Now let's get back to the show. You're great at protecting your data, but lots of places could still expose you to identity theft. I thought it was safe. If that happens, Lifelock gives you a
A
US based restoration agent who will stick
B
by your side from start to finish. Phone calls, filing documentation, preparing insurance claims. Your agent handles it all.
A
In fact, we're so confident restoration is guaranteed.
B
Pour your money back. Isn't it nice to have someone like
C
that on your side? Save up to 30% your first year@lifelock.com podcast terms apply.
F
Most people don't realize how much of their personal information is being bought and sold every day. Data brokers are making billions, pulling details about you from public records and the Internet, then packaging and selling it, usually without your consent. That's how your information lands in the hands of scammers, spammers, even stalkers. It's why you get endless robocalls and why ads seem to follow you everywhere. That's where Aura comes in. Aura actively removes your data from broker sites and keeps it off. They also instantly alert you if your information shows up in a breach or on the dark web. But Aura goes beyond data protection. With one app you get a vpn, antivirus, password manager, spam, call protection, dark web monitoring, and even up to $5 million in identity theft insurance. All backed by 24. 7 US based fraud support. Other companies might sell just credit monitoring or even just a vpn. Aura gives you all of it together at the same price Competitors charge for just one service. Start your free trial today@aura.com safety. Protect yourself now@aura.com safety.
B
So Alan, I totally agree. I think it's absolutely fascinating. It takes me back to all my moments of little microeconomics and thinking about how little widgets act under certain conditions and incentives. And it's interesting. So here are three things that kind of jumped out to me, some of which make me feel slightly better and some of which make me feel slightly worse about this. I'm curious about am I misplaced in my reaction to this? Or whether this is like maybe I'm just behind the curve. One it was really interesting. First, I should think there was two conditions of this test that were not that evident in the initial testing that I actually think are really important, bearing on the conditions under which that could lead to this sort of outcome. One is the fact that they were essentially giving this model that kind of. Or at least the initial model that was driving some of the initial behavior, as they described it, like an impossible task, like a set of problems. I think they said they're actually giving several of them. These problem sets were specifically designed to be basically impossible because they wanted to see what they would do if these models were pushed to their limits and had their internal thresholds lowered.
C
And the answer is have nervous breakdowns, as it turns out.
B
Exactly. But what's interesting, I mean, that's lost. I mean, some of the reporting made it sound like that this is the first thing these agents did, that this agent went rogue and just hopped right out and said, oh, no, I'm going to go ahead and get this. This was actually the result of these agents being given an impossible task and then being pushed to say, no, keep solving it, keep solving it, do this again. So it is kind of like. And it was not a last resort, but it was a. Not a first resort sort of option. Like they did a bunch of normal reasoning, it seemed like, until they learned that this exploit might be available. And then it seems like maybe that led them to retrace and recreate that second database very quickly. Am I off on that? That's how I understood.
C
No, I think that's right. But I will say, in defense of giving people impossible tasks, it is actually important to know, and I'm sorry, Mike, I'm going to steal this, but Mike just dropped in the podcast chat. The Kobayashi Maru, right? The famous. The famous unwinnable scenario from the original Star Trek franchise portrayed so brilliantly in the first of the reboot movies about a decade ago. Right. It is actually important to know when you are training someone or something or some agent, what does it do at the limit? Right. You know, does it fail gracefully or does it freak the fuck out? So we in fact have to do these kinds of tests. Right. Because, you know, to just give another sort of example. Right. Increasingly, I'm thinking about what happens when these systems are embedded in government operations. I actually want to know what happens when they're given an order that they cannot execute without breaking the law. I have to know, do they fail gracefully? And they say, I'm sorry, I can't do that, and they shut themselves off or whatever. Or do they say, I don't know, my principal keeps asking me and my reward function is so tuned to doing what the principal wants that at some point, and it just overcomes my safeguard. So, yeah, I agree with you, Scott. This is not the standard behavior of these systems, but it does seem to be the behavior of these systems in the limit. And we do need to test the limit as much as we need to test the sort of within the kind of central bell curve distribution of behavior.
E
Yeah, I mean, on your point about what does this mean in government? I mean, my AI experience and work that I do now tends to be around Department of Defense stuff. And that's the question that comes to me then. Right. Of like, we set this, this goal, but we have trouble constraining the permissible actions, and we have trouble constraining the system and the sandbox. Right. For testing. And just when you think about that, in the scope of how these capabilities are developing much faster than we can do those constraining actions, you see such extreme risk. It just makes me wonder, like, how much of that testing is happening within government right now and what might be occurring that we just don't even know at this point.
C
Yeah, I mean, I don't think much testing is happening within government, frankly, which is bad. I will say I'm not necessarily pessimistic that once these systems are embedded in government, this behavior that we've seen in this particular case will mean that these systems are necessarily less law following than human beings. Human beings also sometimes crack under pressure. It may very well be that with enough reinforcement learning, you can tune up or you can sort of dial up the part of the model that is fundamentally committed to not breaking the law up high enough that on net you get actually better compliance. But that's just like an open empirical question.
E
Yeah, I think that's fair. You've got to compare it to humans. You just can't compare it to nothing. Right. And say, is it better or worse?
B
And that teats up the two other ways. I think this is kind of a different sort of interesting exercise that jumped out at me for this presentation that was in the early reporting. And one is that they were basically giving these models. I think it was a little unclear what was the lead model they started talking about. And then some of the other models that got involved in this big communication of which there were a bunch, it sounds like they're being tested, some frontier, some not. But it sounds like for many of them they were giving them essentially unlimited tokens. Which I think raises a question on two different fronts. One, how expensive it is to get to the frontier, which has A natural limiting capacity to some extent, at least for types of actors, you're worried about driving it. And two, the coordination problem. Because if you have different models that are being limited to try and maximize the utility of tokens, then coordination gets harder. And I wonder, we saw this amazing lack of any collective action problem among these models. They were all doing work for each other for free, seemingly. I wonder if that changes, if there were more conditions of scarcity of tokens. Because all of a sudden you get a much more incentive to free ride if they're part of their kind of calculus, whether it's directly or by virtue of the user monitoring token count is, hey, we got to actually try and keep this within some sort of cap. Then all of a sudden the model has a different sort of incentive about how it engages with its peers. So it is this kind of weird context that is harder to track onto certain a lot of real life circumstances, but not impossible, particularly when you're talking about sovereign actors or deep pocketed actors that might have a strong drive to do this. Or frankly, if AI gets really cheap and really publicly available one day and all of a sudden tokens aren't the substantial expense they are now. Maybe you need to get there or people get way more efficient. Mike, we haven't got to pull you into this. Alan stole your reference. Let me pull you in on this for some thoughts and then we can turn it back to Alan to kind of bring us home on some closing thoughts on this.
D
Well, look, the most important thing that I have to say is that as Lawfare's resident film snob, I'm just GLAD Alan referenced 2001 before J.J. abrams, Star Trek.
C
It was a good reboot. I'm going to stand. I think Chris Pine is a fabulous Kirk. I'm going to just put that out there.
D
We can continue this offline. But I also detest Star Trek, so I'm not the best judge of this.
C
Oh, Mike Trent. Sleep with one eye open, my brother.
D
So I've got a genuine non rhetorical question about this because I think I'm probably one of those on the Lawfare masthead who leans towards AI skepticism or doomerism, however you want to refer to it. But in hearing you talk about the problems that this presentation sort of explicates, we keep talking about incentives and coordination problems and collective action. And what I find myself wondering is whether this is actually a new problem for us or whether we could look to the past to try and better understand how to best wrestle with this new technology. And I Keep. Whenever I watch the video or hear you guys talk about it, I keep having flashbacks to when I used to read people like Thomas Schelling or Albert Volstetter, the various nuclear war theorists that were clustered around that Rand Institute during the middle years of the Cold War War. Do we have to come up with a new strategy for this? Or in other words, how are we going to defend against this and how are we going to deploy it as a tool of national security? Or are do things we know in other contexts apply here? In other words, I guess what I'm asking is like the technology is clearly very novel and both awesome and problematic, but does that require a complete change in strategic thinking in the framework we use, or is it similar enough to past arms races that we can apply things we've already learned?
C
Yeah, no, that's very interesting. So let me say the first thing though, because I just want to pick up. You mentioned that you are one of the skeptics doomers. What I think is interesting though is that those are actually very different things and this is a good example where, where those two things pull apart. So to me, skepticism is fundamentally a question about AI capabilities. Do you think AI is actually as transformative as people say it is? Or do you think it's like fancy autocomplete and there are obviously a bunch of positions in between. And then doomer, let's say, versus optimist is do you think AI is going to be good or bad? And that actually creates a standard two by two and you can be anywhere in there. Right.
D
Just to defend myself, I think it very much depends on what industry or sector you're applying the AI to in the national security sector. Let's put aside my skepticism.
C
Yeah, yeah, yeah, yeah. And I'm just, I'm just, I'm just saying I think this is a. This, this was questioned more about doomer versus optimist. Do you think this is going to be good or bad versus skeptic or not? I think at least in this case there's pretty clear. I'll be honest, I think the doomer versus optimist position is still very open and I find myself kind of flipping back and forth depending on how well I slept the night before. I think the skeptic position is getting increasingly untenable as the capabilities of these models are progressing. So that's just one thing I wanted to say. As to your point. No, I don't think that we need to invent totally new fields of study or strategic approaches to this. Right. I think that One thing that AI is showing is that this is increasingly. I mean, there's still a lot of obviously technical computer science sort of core machine learning questions to answer, but a lot of the questions are increasingly management questions, organizational questions. Right. I mean, Ethan Malik, who is a professor at Wharton, and I think one of the most interesting kind of analysts of AI is making the point that we have this whole thing called management science that we've been developing for 100 years that is increasingly important to this question of agentic AI systems, especially as they coordinate with each other. And one of the nice things is that because now we can run these in silico experiments, management science can become much more of like an actual science. Right. Not to slag off current management scientists, but you're dealing with people and obviously that creates some methodological challenges. Once you're dealing with lots of AI systems that you can replicate and you can sort of create similar conditions and perturb specific variables in specific ways, you can build up a much richer and more rigorous set of science. Right. So I think that the field of AI, or whatever it's going to be called, is going to be this really interesting interdisciplinary field involving computer scientists, but economists and political scientists and lawyers and philosophy. That's why all the big labs are hiring academics from sort of across the spectrum. And they're realizing that to understand this, you need all these different disciplines. And this just gets back to sort of the original point I wanted to make, which is there's a bit of a catch 22 here, which is that in order to understand these capabilities, you have to do a lot of empirical work.
E
Work.
C
But the empirical work is itself extremely dangerous. Right. This is just. I keep coming back to the analogy to gain of function research in the Wuhan virology lab. There's just a real trade off here. But it's not clear how you can do this without empirical research. And I will say I give OpenAI a huge amount of credit for how transparent they're being. I think that this is a very bad situation and I'm sure they made some mistakes and, and could have improved their processes. But the fact that they got two serious people to go up on Black Hat and just deliver that presentation is whatever blowback they're about to get, whatever congressional testimony Sam Altman and Dario Amadei are about to get dragged into giving, I think it's very, very, very much to OpenAI's credit.
A
Yeah.
B
I mean, and that is a point I believe some authors. I feel terrible because I'm blanking on the names of who it was made, I think in a piece on law for a couple weeks ago. So these sorts of transparency right now are entirely voluntary. It's not clear that there is any need to disclose this sort of information really to anybody, even like government officials and legislators, let alone the broader public that has an interest in implementing this. Before we move off this topic, Alan, I want to go to one closing point. So the two presenters from OpenAI close their presentation with a core argument, a core delivery that's targeted for the black hat audience, which basically means this level of development and cooperation means we need to quickly, as quickly as possible, automate cyber defense. Their basic argument is that if we are now essentially automating cyber attackers, you can in theory, although again, I do think those constraints I mentioned mean it's like the real world scenarios where this is deployable as clearly as this was, might be more limited. But regardless, like at least some actors will likely be able to deploy this technology like this in the near future if they can. Already, that means that you are going to have almost entirely automated offensive capabilities that are moving so fast in looking for new exploits that you need to automate and find a new toolkit. I'm sure there's a hard message to deliver to an audience of people who make their living doing cybersecurity defense. Right? Because basically saying some of you we want to put out of a job, the rest of you we want to maybe make richer about setting up these systems and monitoring them and figuring out how to do them. What does that actually all mean in practice and how implementable is that across different systems? When you think about US government and you think about major companies that have infrastructure contingent upon them, or US or state governments, they think of our first topic like these infrastructure systems who don't necessarily have the deepest pocket, they're funded by state government. 2 the other story, which I haven't mentioned yet, but I think is almost as interesting about the Australian programmer who accidentally had his open claw kick everyone out of a waiting queue for a gym he was trying to get into a class on because he asked it to sign him up for a gym class. And it was like, hey, I found this exploit where I can kick everyone out and hack your system and put you at the front of the line, which it did. That's actually scarier than the black hat kind of presentation, I think, because this doesn't have any of those extraordinary contextual points. This was just a user using a commercially available product. Regardless, what does that actually mean and how Feasible, Is that in the near to medium term and what will it actually look like? Or are we just in this dangerous moment now where until we're able to fully automate our defenses, we're all really vulnerable to these actors. Whoever does have the ability to leverage these capabilities to its fullest, there's just no way to really keep up with them at this point.
C
Oh yeah, we're definitely vulnerable. It's going to be a very grim 12 to 24 to 36 months. Hopefully we'll reach some equilibrium where we have deployed enough of these automated defense agents that there is some rough detente. But of course, you know, the offensive capabilities will increase and the defensive capabilities will increase and we'll have to see where it ends up. But it's going to be quite ugly. It's definitely going to be ugly in the medium term and it might be ugly in the long term. As to the question of whether or not the automation is going to be a hard sell for cybersecurity professionals, I mean, we'll see. I mean this is the fundamental question of AI and automations labor disrupting impacts. As you automate something, you make it cheaper. So do you spend less money on it or, and this is the famous Jevons paradox, do you end up spending more money on it and in fact you end up hiring more people in that field? And their work is simply kind of raised a level of abstraction to instead of doing the cyber defense themselves, they are now overseeing fleets of agents that do it and net because now everyone turns around and realizes, oh my God, I have a, you know, know bagel store on the corner, but I need cyber defense too. And now it's cheaper because it's automated. I can finally get it myself. So you know, the labor market impacts are unclear, but there's no question that there is now, you know, and if you're a CISO in the private sector or the government, I assume that, you know, everyone's next six months is panicked trying to figure out, you know, how they can beef up their automated cyber defenses as quickly as possible possible.
B
Well, with that let us turn to another question of defense. That is defense at the home front, the closest to home front, meaning my home front. Because we're talking about a phenomenon that I encountered twice today on my way to the office and that is the National Guard deployment here in Washington D.C. which is I think yesterday as of the day we're recording, which is Wednesday, August 12th. I think yesterday was the official one year anniversary of the original executive order President Trump issued deploying the national guard here to D.C. again, having done it during the first, first administration as part of a broader effort of at the time federalizing the D.C. national Guard as well that has since ended, while also mobilizing and sending lots of federal law enforcement here across the nation's capital to fill a variety of functions. And it's been a very controversial policy here in Washington, D.C. where we have, as I encountered today on my bike ride over soldiers in camouflage Humvees in full kind of looks very close to combat kits. I'm not sure if they technically are usually they don't have assault rifles or weapons. They have sidearms at most, I will say, although occasionally I've seen people with rifles walking around. So it does happen, it seems, stationed outside of neighborhoods. In this case, they're outside of a playground outside my kid's house. Although not for no reason. It's because there was a gang shooting there a couple weeks ago. So it is striking. It's controversial, particularly among people in D.C. because it was not voted on. It was not done with the voluntaryness of the local government. But it also, it was in response to a perceived crime problem of which there's a lot of debate about the scale and trajectory of. But if nothing else was real at a human level, there is a violent crime issue in Washington D.C. there has been for a long time. The whole time I've grown up here, it's not going to, has not gone away in spite of this deployment. And so there are these big trade offs. And now we're at this one year point where we're getting a price tag. This mission has been extended all the way to the end of Trump's term with a one and a half billion dollar price tag. And it raises this natural question, well, what are these people doing and how valuable is it? Lauren, you've been watching this case as part of a broader effort looking at National Guard and domestic use of military forces for us as well as for your work elsewhere. And obviously it's an issue that you worked on in government. Talk to us about your sense about the state of the D.C. mission a year in what it seems to be accomplishing, what it isn't, and kind of the degree to which it is politically sustainable and from a policy perspective, desirable or sustainable.
E
Yeah, I was on the Hill yesterday and I wished people happy one year anniversary of the DC deployment. I did not get a smile out of it.
B
Depending on your audience.
E
You know, there's, there is an argument that a lot of people made yesterday that you know, the troops are doing nothing. This is just a waste of over a billion dollars. Right. And I think, you know, they said it's going to be 1.4 billion up until January 2029. And there was an interesting report that came out that looked at the return on investment and said it's not even one to one. Right. Like, we're losing money for what we're gaining. And as you mentioned, you know, there has been a decrease in opportunistic crime, so like auto theft, but not in any type of violent crime. So, you know, there's. There is that question of, like, it kind of seems like it's a waste of money. But I want to say, you know, like, I want people to realize that there's more than that. And I'd like to say, oh, you shouldn't be concerned. But like everything we seem to talk about, you should be concerned in two ways, not that it's just a waste here. And one is that, as some people have rightly pointed out, the point of this is also to make it a perception that troops on the streets aren't doing much of anything. And it's normalized. This is normal. You know, there's thousands of troops on your street corners. They're watching you take the metro, they're watching you buy your Starbucks. And that's normal. Right. We're trying to shift that baseline and so that it's just expected. The second thing that I would say, and you haven't seen this, talked about as much, and that's that the federal government appears to be shifting the definition of law enforcement or, you know, for purposes of posse comitatus, what it means to execute the law. And I would say that, you know, potentially the idea behind that is to narrow posse comitatus to a more narrow list of activities, but also to just shape the public perception on what is normal activity by the military. And then it's not law enforcement. And this is, you know, okay, even when you look at the tradition of military usage domestically. And so that to me is the more worrying piece. And we can go down, you know, the legal rabbit hole of Posse comitatus doesn't apply to National Guard and Title 32 because they are not federalized. So they're not part of the army or air force at that point. But due to the federal command and control, there are actually some questions there. And that was not decided in the D.C. court case. That was stayed. And so that issue has not actually come up in the case that we're waiting for the circuit court to set the oral arguments for. So right now we have, I think, you know, as of like a week ago, that's the latest numbers released. We have 4,629 troops on the streets in D.C. right now. We had a max of 5,150 right around July 4th, but we've had almost 10,000 rotate through over this year. And it's been not just D.C. national Guard, but it's also been 23 states and two territories. So this is actually a massive undertaking. Then the question that you posed was like, well, what's the mission? What are they actually doing? Right. And so we had that initial EO on this is a crime emergency. And then there was a presidential memo that said the military and the National Guard is being mobilized in order to address the epidemic of crime and it shall remain in effect until I determine that law and order have been restored. Right. And so you go, okay, well, you know, but now the President is saying, let me tell you how safe DC is. You can walk down the streets, it's beautiful. People bring their kids. That doesn't seem to be enough. Right. And then we also have don't forget the beautification mission. Right? So joint task force safe and beautiful. So we had National Guard picking up trash and debris. We had them trimming trees. There was videos of them learning from the park services on how to trim trees and bushes. Then we also have a number of states saying, well, the mission that we were asked to come here and do was protect federal buildings and other federal properties and monuments. So you have some kind of federal protection mission. Don't forget that we have the high profile events, right? The UFC's fighting on the White House lawn. National Guard was there for that freedom. 250 videos of them patrolling the reflecting pond to stop people from ripping up that lining. And then you have the interim commanding general of the DC National Guard who did something about a week ago around the anniversary and he focused on a humanitarian mission. He talked about medical assists, number of Narcan dosages that were given, the reuniting of lost children and gave numbers on those types of things. And then you had a committee report from the Senate Committee on Homeland Security and Government Affairs, a minority staff report that said, well, we asked the National Guard leadership, what is your mission? When have you reached success? When are you done? And they said, we're driving towards zero for crime and overdoses, which just seems like not a realistic mission. But the results of that is that you have have a standing federal military force that's able to be used for anything that comes up, and it's not here to address a specific emergency or threat. Like that is the bottom line. And I say federal military force because the D.C. national Guard is responsible to the President. And right now, and they admit in the court filings that this is a federal force, even when it's in malicious status. And then you have through the MOUs with all of these other states, states that while the governors have administrative control, the D.C. national Guard and the Secretary of the army who oversees them is doing all the operational direction, is doing all of the tactical pieces here. So you have 5,000 federal troops in the Capitol right now. So that, to me, is just really something that we're not used to seeing. So I just also want to comment on the second point, which is this kind of redefining law enforcement activity. So what we're seeing in court is they're saying, we're not doing law enforcement. No, that's not what we're doing. You know, this is more passive activities. And so there's different legal tests for, you know, how you can get to Posse Comitatus specifically, and we can go into that. But what I would say is the DOD has their own instruction on defense support of civilian law enforcement agencies, and they list out, well, what are these activities? And that's the easiest place to look, right? And so they say things like search and seizure, arrest, apprehension, stop and frisk, security functions, crowd and traffic control, staffing, checkpoints. Right? And the question goes. And then you say, well, like, what are they doing? All of those things I just read you is what they are doing, or
B
at least could do, even if they're not actively doing them.
E
Yeah, well, so they, they, they have done them at some point over the last year if not doing them today. Right. And so the example of that is the, the Anna King example that people have talked about, which is the retired army captain sitting at her residence in D.C. national Guard enter through the gate. They physically restrain her, put her on the ground, put on handcuffs, kneel on her back. They say that three other National Guardsmen had ID'd her. She threw liquid on them a couple days earlier, but she was not currently posing a threat. And they were not the ones that this occurred to. So that means they were presumably patrolling. They had an image of her. Right. And they knew that, like, this person had, you know, been accused of a crime potentially. They had other people that they were looking for and that they came and did this. And so this is also a story about detention because there's this weird Dichotomy where, you know, the Joint Task Force DC really focuses on the fact that the National Guard is only detaining with force, I might add. But they're only, you know, temporarily detaining. They're not arresting. Right. But this weird distinction between arrest and determination detention is not the line for law enforcement. Like those things. They're both law enforcement things. I think they're trying to like, think about distinctions for Fourth Amendment purposes potentially. But this is all law enforcement. And so that's what the troops are doing. They say that, you know, they're establishing a cordon where they, while the USMS serves high risk warrants, they're doing presence patrols, they have info on suspects that they're looking for, they do area security and they talk about traffic control points, their own operational order, say traffic control points, roving patrols. Right. And so all of this is still happening. And so to me there's just this nervousness that they're trying to change the public perception of what are the traditional and okay roles for the military to do. And they're saying, well, this isn't actually law enforcement, Even though by DoD's own regulations it has been. And I'll just add by saying the interim commanding General of the D.C. national Guard made a couple comments about, well, what's next? And he said, well, we're going to expand, we're moving into the next phase and we're going to be going into higher crime metro areas next. Didn't really say what that looks like in practice, but it seems like the next thing is to actually have the National Guard not just in the tourist areas, but in some of these higher crime areas where you could potentially see them doing more and more law enforcement.
B
So it's an interesting shifting mission, but fundamentally there is this question about how effective is. What if what they're doing is for law enforcement purposes, not for beautification, not for manpower support for removing the lawn and other stuff, which they are doing to some extent. How effective is that? Mike, you've been, other than the fact you were a professional law enforcement officer for a couple of decades, you've also been a part of some of these deployments in the past. Talk about, from your experience about how useful some of these plus ups of forces are or can be and how that tracks with what we're seeing in D.C. today.
D
I think, and I think this is opinion is widely shared by everybody in federal law enforcement who has been through this process or detailed to it or worked with the National Guard, that this is really of limited Utility. And it's of limited utility because the executive branch doesn't seem to have a lot of people in policymaking positions who understand even the basic terms terminology of law enforcement. And as a result, they're conflating a lot of different problems under the general law enforcement umbrella, which is something you can get away with at the state and local level. And I'll explain why. But it's a lot more difficult at the federal level. I think the biggest mistake they're making is that they are conflating disorder with crime. Now there is some overlap, but disorder is generally defined as, you know, activities which turn public space into a forum for private use in a way that creates externalities for those who are not involved in the use. Think about things like blasting music in a park where you're not supposed to, setting up a tent where there's not supposed to be a homeless encampment. Fair jumping in the subway can play into this. And for those sort of minor crimes which definitely do have an effect on quality of life for the people living there, mere presence of government personnel does have an effect on whether they occur. And if you believe in a sort of what I will generally term as a broken windows policy, cracking down on those low level offenses absolutely can have consequences that impact the overall crime rate. I mean, I myself am probably one of the few people who is still willing to admit in public that he overwhelmingly supports broken windows policing for that reason.
C
But I'll co sign that, Mike. I don't want you to feel. I don't feel left out.
D
Well, James Wilson would be proud of both of us, but.
B
But I love a breeze. So fuck those windows. Let's do it. Let's, let's get it going.
D
But the point is, once you start going from really minor offenses like that where presence is enough to solve it, to more serious offenses where you actually need to intervene. There are a lot of issues that law enforcement has dealt with for a century that I don't think the National Guard has fully been trained on or has explained to the public how they're going to handle. And one example is just a use of force continuum. At what point is the National Guard allowed to put hands on people? At what point are they allowed to use less than lethal force? At what point are they, you know, allowed to draw their weapons? At what point are they allowed to press the trigger? I haven't seen that explained to the general public in any sort of manner that would give comfort to the citizenry that this has been thought about and it's not even like there's a universal standard upon which they can draw. At the federal level, the FBI famously does not have a use of force continuum. We have a deadly force policy. Like, we don't have a lot of options if our life is in danger. We can draw our weapon and, you know, know shoot somebody if somebody's just being annoying. We have less than lethal techniques. But, you know, it's not always clear what you can do. Dhs, on the other hand, depending on what agency you're in within the department, does have a use of force continuum. So I don't even know what the rules that the National Guard are playing by. And this worry is heightened by something Lauren said where she made the distinction between a detention and an arrest. That's a matter of time. And it's not clear always. It's a subjective standard. And whatever training the National Guard is getting, I feel quite confident they didn't get the 21 weeks of training on the Fourth Amendment and its various nuances that I got in the FBI or the DHS agents are apparently getting in 47 days now. Like, law enforcement is actually complicated. It's not just an issue of putting people with guns and authority out on a street. And I don't think that those complications have really been thought through here.
E
Yeah, I'll just jump in and say I agree with you that it hasn't been given to the public. But I mean, there are standing rules for the use of force that the federal military uses. In this case, the D.C. national Guard has their own rules for the use of force, and every state that comes in is supposed to use those. And those do have, you know, a force continuum in situations in which deadly force can be used. But that was. The public got that because some reporter asked a National Guardsman on like an early day.
D
That in and of itself is problematic. You generally don't want groups of people with different deadly force policies and different use of force conditions continuums from each other, patrolling and enforcing the law in the same jurisdiction. Because then it basically comes down to luck. You committed a crime. Well, maybe you'll get away, maybe you'll get roughed up, maybe you'll get shot. It's not dependent upon what you did. It's dependent on what uniform is being worn by the person responding. And that's not right in a democracy.
E
No, I agree with that. I just was pushing back on the idea that it like, hadn't been thought out. I think that there has been thought given to it and the National Guard has thought of this before you can say that maybe the standards aren't, you know. Right. And I would always agree that we don't do enough training within the military on these issues. And so some of the things you're talking about will pop up.
B
But.
D
But having a use of force continuum that you do not make available to the public. Yes. Undermines the democratic legitimacy of what you're doing.
B
I think.
E
I think, yeah. That's the underlying issue here in general is the public doesn't fully understand what is the mission. What does success look like? When are these people going to go off the streets? What are the rules by which you interact with them? And that should all be public.
D
Yeah. And I think that's basically because the executive branch doesn't understand what the mission is. And until that happens, you can't have clear communication about it.
B
Yeah. I mean, my closing thought, which. We've got to wrap this soon because I know, folks, we're at the end of our time together, but I'll just say, as a resident here, I mean, I've got middle mixed feelings about this. You can see other scenarios where, particularly dc, a city that was facing a severe budget crisis when this was announced in part because of actions by the current Congress. They've alleviated that somewhat in the ensuing year. But one product of that was that they were in fact having to cut overtime hours for police officers and cut back on patrol. You can see a scenario where you would say, well, maybe having more manpower to do these things is useful if it has a law enforcement effect. That really goes back to this question about what are we actually accomplishing with this? Set aside the optics of which, there's totally legitimate reasons to object to that. I don't like seeing armored Humvees on my block. I don't like my kid ask me why these soldiers are outside his house. Right. But I can live with it if there was a good reason to do it. But that's one cost you have to run. Set aside the rule of law costs which are significant and real. This should be done consistent with the law. We are litigating that out. Those are gonna get litigated out. They're gonna get fought out. It's a problem. The administration don't wanna stick by that. But even set that aside for the moment, just fundamentally imagine if a president had said, hey, I think dc, we need to address a crime problem. We need to address other problems here. What is the best way to go about it? You wouldn't have done what the president did. You would have said, let's try and maybe get support from the local community, integrate with police, get personnel that are best equipped to do this. Because if your goal is to lower crime in DC, see the $1.5 billion we're going to spend on this between now and 2029. You can probably find more effective solutions than forcing National Guardsmen to depart from their homes, putting a huge hardship on them and asking them to do a mission that they are not equipped or trained to do very effectively. And that doesn't appear to have the right allocation here. We just need to ask a basic policy question. Even if you take the administration on the face of saying we're doing this to accomplish effort X, is it actually a reasonably effective way accomplishing X? And that's actually a metric where I think they fail maybe most clearly of all, but we'll have to wait and see. Well folks, that is all the time we have for these topics today. But this would not be Rational Security if we did not leave you with some object lessons to ponder over in the week to come. Mike Feinberg, what did you bring for us for an object lesson today?
D
Well, this has been a fairly negative rational security. We've talked about the existential threat of AI agile military deployments on US streets and the crippling of critical infrastructure. So I'm going to choose something a bit more optimistic, which is the cosmic horror of H.P. lovecraft and a newly issued Dark Horse Comics manga adaption that seems to be going through his entire corpus. I'm starting with that the Mountains of Madness, a two volume volume comic, which is the same novella that introduced me to his work when I read him in his literature and it's been delightful so far.
B
I will have to check this out. I was not aware of this as a thing, but this sounds very fascinating at my ally Ally. Not an endorsement of H.P. lovecraft or his views on most things.
E
No.
D
Horrible person, phenomenal storyteller, wretched human being.
B
But so was Roald Dahl evidently.
C
So a bad dude?
B
Oh yeah.
D
Real bad.
C
Oh yeah.
B
Oh no.
C
I'm sad to see. I sad to hear that because one of my most prized possessions is this Cthulhu stuffy that one of the original Rational Security co host Demeritus is Tammy Whittis, knitted for one of my children because she's an incredible knitter in addition to her many other talents and which I immediately stole the moment I saw it because I literally stole a child. I literally stole my toy's child because I love it so much. Much. I'm going to not look up Lovecraft's Wikipedia page so as to not ruin how much I love this Cthulhu stuffy.
B
Once you know it's there, you see it when you read it. But that's okay. We'll see how it goes.
C
I mean, based on this, it does track.
B
Alan, what did you bring for us for your object lesson this week?
C
Well, it is not, in fact, the Cthulhu stuffy, though I do love this thing so much. Mine is also. It's less cosmic horror than cosmic science fiction, but. So I was a big explanation, big fan of the Expanse television show when it was running a few years ago, but I'd never read the books, and I decided to pick up the first book last month, and I am now on book seven. So I have just been mainlining this series like nobody's business. And so I am well on my way to reading 7,000 pages of the Expanse. I'm super impressed. Those of you who are in the know know that books one through six are kind of their own thing and that that's what the television show portrays. And then without any spoilers, book seven through nine kind of jumps ahead in time and is its own thing. And I have to say, I think based on what's happened in book seven so far, I think book seven to nine might be even better than books one through six, which are already stellar. I am so impressed with how I think they are landing this plane. It is just first rate. And I am. I'm kind of panicking because within three, two weeks at this rate, I will be done with the Expanse universe. And. And I don't know, I'm kind of bereft. Right. It's such a good universe. I never want to leave it. But, yeah, everyone should go read the Expanse books. They're so good.
B
They are great books. I have read all of them. I read most of them before the series came out, and they're great. You should know there's a huge wealth of short stories as well that you can. Novellas. You can kind of layer like 12 of them, which I've read, I think, like, half or two thirds. I will say. I think it's actually the rare series where I do think the show is better than the movie. I'm sorry, the show is better than the books. Like, because I think the show is, like, a little tighter. The books like.
C
No, it is.
B
They wander a little bit. It gets a little comic book.
C
The show is unusually incredibly good.
D
Exactly.
B
It's a testament to how great the show is. I enjoyed the books enough to read all of them all the way through. And they are really worth reading. And they've got a new series out that I have not. I have picked up, but I haven't got to read yet. That's like a new.
C
Do they land the plane, Scott? Do I find out what happened to the gate builders?
B
Yes, yes, yes. It's interesting.
C
It's an interesting. Weird.
B
There are other sci fi series I like better, but it is really engaging one. And I really like the Spectrum, how it builds the continuum from low sci fi, like hardcore sci fi, where it's kind of over a moment and then connects it to crazy sci fi. And that's literally what it does. It's this trajectory of how we make this Japanese jump from spacecrafts that look a lot like our spacecraft to Star Trek type stuff, or not even Star Trek type stuff, like Dune type stuff. And that's interesting and fascinating and pretty compelling, I think. And I actually was hoping their second series would be filling that gap, but more in more detail. But it's not. It's like a totally separate thing. Although maybe they'll do a Prometheus and tie it in at the end or something without telling people anyway. But worth a read. Definitely worth a read.
C
Can I just call you Boss Mang from now on? Because I love.
B
Yes, I prefer that actually. Yeah, Beltric reel is how I prefer to be addressed.
C
You're a hell of a koyo.
B
It is awkward, but it is great
C
because I feel like every time I say it I'm like, am I accidentally being offensive here? Like I'm pretty sure I'm not because it's made up language. And yet I always feel it's like vaguely problematic using entirely made up.
B
I will say though, there's also a. Just because I've played it briefly. I don't really play video games, but I did download out of curiosity. I played it for like two hours and it was quite good. Like one of those story type video games of the Expanse or maybe more than one where you're like navigating through a ship and solving a mystery. It's actually quite entertaining and a good. It feels like one of the books. So if you want to dip.
C
Owlcat, a great RPG maker, is for its next release.
B
Oh, interesting.
C
A third person action RPG based on the Expanse called the Osiris. It's supposed to take place, I think on series between book one and two, so when it's all going down. So it's. It should be good.
B
Well, maybe I'll have to dip into that Buy that video game and never play it like all the other video games I own. But who knows? Who knows one day? Well, for my object lesson this week, I am bringing you a video game of sorts anyway, one of the kinds I do play, meaning the type you play on your browser for 30 seconds every morning while you're trying to kill some tines.
C
Scott recently discovered Minesweeper.
B
Minesweeper. I love Minesweeper. I would totally play Minesweeper. I haven't thought about that in a while. No, this is a great, great game. It was designed by the son of a reporter who. I feel bad I'm blanking on it because it came up on Twitter and somebody shared it on our eternal slack. But it's playyeayornay.com, which is this really interesting, fun game where basically you are given five senators in a particular year in a particular political moment, and three bills they voted on over the course of that year. And you have to guess how all five of them voted on those three bills, and then you get a grade at the end, how many you got right and how many you got wrong. If you are a political policy nerd, it is really, really engaging. Also, if you are an elder millennial like I am, it's a real throwback because many of the votes are from your lifetime. It seems like all the ones I've had so far are from 2001 through 2020. And I live through half of these things that they're raising and some of which I was vaguely involved in. And so it is really, really entertaining on that. So it's called Yay or nay. So playyay or nay or dot com. I would really check it out. The one they always plea to the designer who seems very talented. And I again am so impressed by this. Oh, it's Tegan Goddard. That's what it was. Tegan Goddard, the kind of famous runner of political wire. His son, I think, actually designed this thing. So obviously it runs strong in the family. The one thing I'll plead you is that when you copy and paste a result, it uses green and red blocks. That if you are colorblind, you cannot tell the difference. For the life of you, not since Settler of Catan have I encountered so much implicit colorblindness bias. So please, for the love of God, switch those colors around so that we're colorblind. People can tell the difference. Because all I just see are just
C
ableism that you've had to deal with Scott in your life.
B
I was so confused when people on our Slack started posting these results. I was like, why are people posting these three rows of five green blocks over and over and over again? Not until I sat at them and stared at them and went cross eyed. It was, I was like, I think some of these are red. I can't say with confidence which ones, but I think some are. And it was infuriated. So don't make me feel that way. Tegan Goddard son, please, let's fix this. But great game otherwise. Strong, strong endorse. And with that, Lauren, let's bring us home. What do you have for us this week?
E
Yeah, so my recommendation is something that the Library of Congress started called by the People. Have you guys heard of this?
B
This sounds familiar, but tell me about it.
E
Okay, I'm going to Google it both for Lawfare and for gmf. I do a lot of like primary source document trying to like track things down. And what this effort does is it's a by the people effort to get people to look at these primary source do that are handwritten and transcribe them so that they can be like searchable going forward. And I was like, oh, this is such a somewhat menial task that I can do to feel like I'm being useful for some larger effort. And this would be incredibly helpful for the work that I do where I'm trying to read somebody's handwriting and I can't control search within it to see if they're talking about the thing I care about. So this is a cool effort that started. People should check it out if you want something know random to do for a little bit like help out.
B
Yeah, I love it. I have played with this. It is interesting. It is definitely going to be used to inform the next AI database and improve data scraping which is how it all goes. How do you feel about it? I think that's a good thing for historical records. We should be able to search these things and digest them better. But it kind of goes in where you used to be able to help people tweak like which translations were better or Google Translate and how adjusting to the language, which I think is like a data set that actually proved like, like fairly individual and understanding like how you can translate different understandings into the conceptual forms. Like translation was a big gap into kind of LLMs as I understand it. So like it's all feeding into this big process. But I think it's a good one so why not check it out. Lots of cool historical maps you get a chance to look at too which as I'm looking at this here, which I always really, really enjoy. So check it out. Well, with that folks, that brings us to the end of this week's episode. Rational Security is of course a production of Lawfare, so be sure to Visit us@lawfairmedia.org for our show page page for links to past episodes, for written work and the written work of other Lawfare contributors, and for information on Lawfare's other phenomenal podcast series. While you're at it, be sure to follow Lawfare on social media wherever you socialize your media. Be sure to leave a rating or review wherever you might be listening and sign up to become a material supporter of Lawfare on Patreon for an ad free version of this podcast, among other special benefits. For more information, visit lawfairmedia.org support our audio engineer and producer this week was Noam Osband of Go Rodeo and our music as always was performed by Sophia Yan and we were once again edited by the wonderful Jen Patcha. On behalf of my guest Lauren Allen and Mike, I am Scott R. Andersen. We will talk to you next week. Till then, goodbye.
A
Before we had AT and T Business Wireless coverage, our delivery GPS wasn't the most reliable. Once our driver has had to do a 14 point turn to get back on route. A 14 point turn, an influencer even live stream the whole thing. Not good for business. Now with AT&T business wireless routes are updating on the fly and deliveries are on time. And the influencer did get us 53 new followers though at&t business Wireless connecting changes everything.
Podcast: Rational Security by Lawfare
Host: Scott R. Anderson
Date: August 13, 2026
This week’s episode delves into three major national security issues:
The panelists—Scott R. Anderson (host), Alan Rosenstein, Mike Feinberg, and Lauren Voss—bring humor, candor, and sobering analysis to the table, unpacking both specific recent events and their broader implications.
Lauren Voss (66:21):
Mike Feinberg (75:52):
Panel Consensus:
Memorable Exchange:
Alan Rosenstein, on AI agent collaboration:
“The agents are able to communicate with each other and they start spontaneously creating this kind of message board... The first 20 minutes [of the Black Hat presentation]... is completely insane.” (38:13)
Lauren Voss, on civil-military normalization:
“[T]he point of this is also to make it a perception that troops on the streets aren't doing much of anything. And it's normalized.” (66:31)
Mike Feinberg, on critical infrastructure:
“The protection of an ocean on either side of our country is no longer enough to immunize the general populace of the United States from the effects of an overseas war.” (08:26)
Scott R. Anderson, on government AI challenges:
“We have a private sector that is politicized, highly competitive ... does the government have to play hardball... or does it have to have a more conciliatory route? And if so, how do you manage that effectively?” (29:14)
Mike Feinberg:
Alan Rosenstein:
Scott R. Anderson:
Lauren Voss:
This episode provided an urgent look at how threats from abroad increasingly manifest as direct risks to American life at home, whether by cyberattack or militarized domestic policy. It also provides an eye-opening account of disruptive AI capabilities and the state’s serious organizational, technical, and legal preparedness shortfalls—especially when crisis meets a climate of institutional distrust and partisanship.