Loading summary
Tom Uran
Hello, everyone, this is Tom Uran. I'm here with the Grok for another between two Notes discussion. G'day, Grok. How are you?
Grok
Good day, Tom? Fine, and yourself?
Tom Uran
I'm very well. This week's episode is brought to you by Device. I've got an interview with Device CEO Shane Harding out on the podcast channel this week and we talk about two big shifts in the market that they're seeing. So be sure to catch that. So the topic for today, we've been thinking about whether cyber can be strategic. So that's the question. But the first thing that occurs to me is that mostly people don't know what strategic is. Now, do you have a pithy definition? I think people tend to think of it as something big and important.
Grok
Yeah. So I think the context of what we were discussing is things that can influence states. It is these big actions that have some way of influencing the behaviors of states. So that's what we're going to mean when we're talking about it today. There's a lot of other definitions which are not relevant.
Tom Uran
Everyone who believes those is wrong. It seems like we've got a couple of examples that spring to mind immediately. One of them in the context of war is in the beginning of the invasion of Ukraine, where Russia invaded Ukraine. This is. This is foreshadowing for something we might talk about later. The. The Russians launched operations to disrupt Ukrainian communications. A couple of different ones, they sort of semi came off. Now it seems to me that if they had come off and had supported successful Russian conventional military action, that's really where it fell down, is the conventional action, then I would say, okay, that facilitated or supported a strategic outcome which would have been if the Russians were successful, it would have been the capture of Ukraine, the takeover, replacement of leadership. So is that a yes?
Grok
Yeah, yeah. Start with the easy one, why don't you? No, I think that that's what people think when they think of strategic cyber.
Tom Uran
That's what they've got in their head.
Grok
Yeah, that's the sort of. That's the sort of idea that they have this big bolt from the blue, cracking down, disrupting a major pillar of civilian infrastructure or a state infrastructure that then somehow can be exploited and cause a thing. And I'm not convinced that that exists. I think it could exist, but it feels to me that everyone that's done something like that has achieved six hours, eight hours of disruption. And that doesn't feel strategic to me. That doesn't feel that big of a deal overall.
Tom Uran
So the overall operation was A strategic operation. The operation failed. The cyber role was in no way strategic. Like.
Grok
Right.
Tom Uran
They could conceivably have achieved what they wanted to achieve without the cyber operation at all.
Grok
Right.
Tom Uran
It seems that there was some action, like literal action on the ground that prevented the Russians from achieving their goals.
Grok
Yes. So I mean, the one thing I'd say is that if Russia's strategic actions on the ground had actually succeeded, everyone would be teaching the cyber operations as here is proof that cyber is a strategic capability and was probably the pivotal linchpin in helping Russia achieve their war aims. Starting with the DDoS attacks against the websites in January, followed by the defacements in early February and then this huge cyber strike. That would be the narrative if it worked out. And I think that the counter narrative, which is that cyber is useless, is going too far the other way. But this is something we've touched on before, which is that cyber was just not relevant. That's the issue here, is it's not in the critical path in any way.
Tom Uran
Right? Yeah. So after we sort of talk about it for a minute, we've relegated it to a supporting, a minor supporting role, but that wasn't consequential one way or the other.
Grok
It's the Rosencrantz and Guildenstern of strategic capabilities. Okay, that's a deep cut.
Tom Uran
See, I don't even know what that means.
Grok
Okay, so in Shakespeare's Hamlet there's two characters, Rosencrantz and Guildenstern, and they are so minor that you can switch the lines between them like it doesn't matter, like you can be either one saying either thing and it has no impact on the story.
Tom Uran
Okay, so another example perhaps, which people have talked about a lot recently is Vault Typhoon. So that's a Chinese state backed actor that is hacking U.S. critical infrastructure. And the U.S. government is sure that they're pre positioning to be able to disrupt US critical infrastructure in the event of a conflict, probably over Taiwan. So obviously that conflict hasn't happened and God forbid, doesn't happen. Yeah, but that seems like it could be an effort to have some sort of impact on the US's decision making, like the US government as a whole, to deter them from getting involved if, if the PRC should decide to invade Taiwan.
Grok
Right. So I think that they're doing what people believe strategic cyber is. I think if you talk to generals or academics or people at think tanks and said what is strategic Cyber? It would absolutely be Vault Typhoon sort of activities. This pre positioning in critical infrastructure that you can pull the plug when you need to, etc. Etc. And it's again, it feels to me like it's just, it's not that big a deal. Like maybe it's because I live in a country where like the electricity goes out fairly regularly. Like it's just, that's the thing that happens. And it's annoying. Like the air conditioner stops working and the fans don't work, but I don't break into the apartments of my neighbors because we're, it's anarchy. Like it's just, it's a slightly frustrating thing that you get through. It's not the end of the world, you know.
Tom Uran
Right. The temptation from all sorts of people is to emphasize the world shattering possibilities. I guess. So it's ironically, I guess it's both the people doing the hacking, if they're trying to demonstrate that they're doing a good job, it's like we've hacked all these facilities. You know, we're poised at a moment to disrupt their power and their bosses. Oh yeah, good job. And from the US Cyber security community, it's the exact same dynamic because you want to motivate people to take action. It's like, oh my gosh, they're poised to disrupt our water and there's no one who's the curmudgeonly downer except for yourself, which is, come on, come on people, this is not such a good grip. So to me, I think we've spoken about this before. I think that if you're in a conflict and people target civilians, especially with stuff that doesn't just kill them straight away, there's a very strong rallying around the flag unite against a common enemy. And most of the cyber disruptions are also short lived.
Grok
Absolutely. And this is exactly why when I was talking about the sort of attacks that one should be doing, it's where you're nice to the population rather than attacking them. Because if you're nice to them, they're not going to rally around the flag against you. They're going to rally against people who try and take that away from them again.
Tom Uran
Right, right. I guess it's interesting in the context of the recent Trade War One phenomenon I've observed is a whole lot of Chinese factories on TikTok offering to sell their wares direct to the US consumer. Because even with a massive tariff, the wholesale price is a lot less than the price you would Pay.
Grok
Yeah, like $2 for a handbag. Like. Yeah, it's going to be $4 after tariff.
Tom Uran
Yeah, that's right. And so that's. I Guess you know, it's not a cyber operation, but it's. It's sort of being nice to the population, offering them something like a good deal, to be honest.
Grok
Right. Like, this is the sort of thing I'm trying to get at, is that the dynamic here is quite different than if China said, all right, that's it, no more handbags. We're not going to sell you any stuff. Then people will be angry at them, but instead they're going like, yeah, here you go, super cheap.
Tom Uran
Haven't we got a deal for you?
Grok
Right. How do you get angry at people like that? You can't. It's very hard to drum up support for attacking people who are being nice to you.
Tom Uran
And I think there's a dynamic where TikTok actually sort of supports that, because the ones who become popular are actually, like, they're super entertaining. Like, that's why they're successful in the algorithm. Like, you don't need to. You don't need to diddle the algorithm to define.
Grok
Yeah, you don't need to put that much of a thumb on the scale. I don't think you want to leave it entirely to chance, but let's put a pin in that, because I do want to come back to this later, but first we have to trash Strategic Cyber as it's known in the west, right?
Tom Uran
So to me, it's not even clear that Vault Typhoon is perceived by the Chinese as Strategic cyber. So there was this really interesting report in the Wall Street Journal where they talked about a meeting the US Officials had with Chinese officials. It turns out that one of the purposes of the US Officials was to try and figure out or tell Chinese senior leadership, hey, this Vault Typhoon stuff, it's your stuff, and we really don't like it. And so that implies or. Or tells us that the US Government isn't convinced that Xi Jinping knows that Vault Typhoon is a thing. And so, like, if he doesn't know, can it be Strategic Cyber? Like, can there be something that looks like it's the, you know, top level trying to deter someone when the leadership doesn't know it exists?
Grok
Yeah, yeah. I mean, this speaks to an important thing is intent.
Tom Uran
Right.
Grok
So it's very hard to say what a cyber operation is supposed to do before it's done it, because generally speaking, the implant that you install just allows you to run a command or, you know, it allows you to do arbitrary commands, read files, upload files. It's, you know, these very, very basic actions that you can build on to create something. And because that could be anything. It's very hard to tell beforehand what the intention is. So, yeah, like how do you determine that it's meant to be this destructive strategic act? Probably because you're not going to do a lot of crypto mining.
Tom Uran
Yeah. I think that in the case of Vault Typhoon, it was because what else are you doing there? Like there is no right purpose. And I think if I remember rightly, they were looking for documents about how the systems were put together and how to maintain them. And so all the strands of evidence were indicative of we want to learn this system. To be able to do what? Well, you can only there's no intelligence to be had.
Grok
Right. If you're going to manipulate the system, you're not going to try and make it more efficient and save the electrical company some money.
Tom Uran
And it seemed to me that whoever is directly responsible intends it to be a strategic operation. They intend it to put the US at risk. So I mean, in that sense it seems like whoever is doing it, whether it's a middle manager, low down in the PLA or the top of the PLA or Xi Jinping, whoever, like they think it's strategic, right?
Grok
Yeah. The US obviously thinks it's strategic. I mean, it caused high level talks between these high ranking officials. Like that's how you respond to a strategic thing, not to a minor inconvenience.
Tom Uran
Yeah.
Grok
So it was certainly perceived as strategic. And you know, I'm willing to concede that it would be very disruptive and you know, it wouldn't be fun. But I, I think it's very much along the strategic bombing lines that we've talked about. The strategic air power idea of like if you do terror bombing against civilians, they will surrender because they don't like being bombed. And as we've said, it's, it just makes people bond together against the common enemy.
Tom Uran
So it's the strategic cyber. When you think you're doing strategic cyber, but you're not.
Grok
Yeah. I mean strategically it does have an influence on the state. It makes the state more unified and aggressive. That's what I would say. The strategic effect is not the one that you want. It doesn't achieve the outcome that you're intending.
Tom Uran
Right. So it's actually counterproductive.
Grok
Right, right.
Tom Uran
So a while ago I did a book review for. I thought it was a very good book. It's by Ben Buchanan. Yep. The Hacker in the State. So I can't, I don't know where Ben is now, but he was in academia and then he went into the Biden Administration. I think he was involved in AI policy or something like that. And so he talks about how states have used cyber operations. Basically the thesis of his whole book is that cyber operations are really good for shaping, but not for signaling.
Grok
Yeah. So this is. It's a little bit brave of him because so much of the academic literature and theory is around how you can use cyber for messaging and signaling. And I think that that's a terrible. Like, that doesn't work very well.
Tom Uran
Signaling doesn't work very well.
Grok
Yes.
Tom Uran
So the question I have, I think you buy his thesis that operations can shape.
Grok
Yes.
Tom Uran
And this book was written, the review I'm looking at, published in 2020. So it must have been around that time.
Grok
Yeah, 2019 or 2020. I think it came out just before COVID Right now.
Tom Uran
Does consistent shaping end up being strategic?
Grok
Yes, but I also think that shaping is harder than people think.
Tom Uran
So perhaps I should give an example. So one of the examples that I tend to think of, and maybe this is a good example of maybe this is strategic, is Stuxnet. So Iran, in a nutshell, trying to develop nuclear weapons. They have a nuclear enrichment facility. Stuxnet was the malware that got onto centrifuges and basically broke them. And so the logic of the operation was that by breaking their centrifuges, we'll slow down their production of enriched uranium. That'll increase the amount of time it'll take for Iran to develop nuclear weapons because they won't have any fissionable material.
Grok
I've got a great counterfactual take on that, which is, I think that the state that was shaped and influenced by Stuxnet was Israel. Right, Right. So I think that Israel was gearing up to go kinetic, and by creating this cyber thing that made space for the treaty to be put in place, this kept Israel from escalating. It said, you know, here we go. Here's a way that we can do what you want without causing an all out war, Right?
Tom Uran
Yeah. So Israel had bombed nuclear facilities in the past before. Yeah, yeah, yeah. So the thing I was going to say is that there's conflicting reports on how successful it was. Like, some people think it made a small amount of difference, like months, others think longer.
Grok
I think in terms of the impact that it had on Iran, it's a little bit difficult to tell in terms of how long it delayed them on their actual timeline, but because it created space for their goals to be shifted, I think it's impossible to actually determine. Right. Like that nuclear treaty came into place in the time that was created by the Stuxnet operation where Israel didn't go kinetic. Iran came to the table and reached a deal and the US didn't have to support Israel going kinetic. It created the space for Iran to do something else. And so saying that Stuxnet delayed them for 10 years or 10 weeks is impossible to tell simply because their goals shifted. And so since they weren't pursuing that anymore, you can't say how long they were delayed in pursuing that because, like, obviously they're not perceived.
Tom Uran
So that sounds to me like you're giving it a very, very skeptical.
Grok
No, I think it was very important, but I think that the importance was less about stopping Iran's physical capability of developing a nuke and more about creating the diplomatic space to keep either side from escalating by delaying them long enough and giving a non kinetic option to an aggressive player at the T. That's.
Tom Uran
Strategic cyber, making the space for more meetings. So there's another example that Ben actually talks about in his book. It doesn't feel like a traditional cyber operation. Well, traditional intellectual property theft, Chinese intellectual property theft over, I don't know, it's probably 20, 30 years now. And so China's become a manufacturing powerhouse. And that is a huge difference in the trajectory of states. Would you call that kind of intellectual property theft?
Grok
Oh, yeah, that was strategic. Absolutely.
Tom Uran
Yeah. And doing it from one company on one day, that's not a strategic outcome. But if you're doing it over 20 years. So you say.
Grok
Yes, yes. I'd say that the state was. They were investing in R and D by stealing someone else's. Right, right. And you would call like investments in the sciences, investments in R and D. Like those are strategic investments that a state makes. And in this case, they were making them in sort of two prongs. One was into the universities and the other one was into the pla.
Tom Uran
Well, I think it was so that.
Grok
They could bootstrap higher and faster.
Tom Uran
Yeah, yeah. Well, I think it was an all encompassing strategy. So because we're cyber people, we tend to think about the cyber espionage part.
Grok
The most important part of the whole thing.
Tom Uran
But it was also, you know, market access. Western companies had to give up IP to access the Chinese market. There was the university research, there was joint factory ownership. Exactly.
Grok
Everything. Yeah.
Tom Uran
A whole suite of strategies that all work together. So I, I would push back in the sense that I would say espionage was an element of a very successful strategy. But if you took it out, I think it would have slowed them a bit, maybe significantly.
Grok
Yeah, that's what I was going to say. I think it would have slowed them significantly just because of the sheer volume that they were able to do with cyber. But I would say in a lot of cases that's like we don't do victim blaming on this show, but it was entirely the victim's fault.
Tom Uran
Well, the other thing I want to say is that you could steal everything on my computer and you wouldn't be able to produce a seriously risky business news next week. So there's a lot of tacit knowledge, I think is the terminology that goes into building anything. Like there's a lot of intellectual property in people's heads. And I think that's true for even hard manufacturing businesses as well. And hard, I mean like physical, physical objects.
Grok
So that's one of the things I have right now where like all of the people that used to make missiles and nuclear bombs are retiring and they have all the procedures like this is how you assemble a nuclear bomb. Yeah, but you kind of need the guy who's been doing it for 20 years to still be there to show the guy who's been there for a week how to do it. Because he can't just read, you know, step by step.
Tom Uran
Yeah, no, I don't think there's any job in the world where you just go, here's Emmanuel, see you later, new guy. You'll be right.
Grok
Yeah. So I mean there's always a huge amount of implicit knowledge that you need to have to make these things work.
Tom Uran
So maybe that's a good example of something that's achieved, something strategic. But it took a long, long time and it's not as good as maybe we think it is perhaps.
Grok
So there's a Russian joke that encapsulates this. Where the CIA gains access to a Russian factory that's producing the new Sukhoi, whatever generation fighter. They install all of these microphones so they can capture the people discussing how it's put together and built. After six months they get all the recording logs and they start going over it. It's absolutely useless because the whole thing is just hey dickhead, get me that little whatchamacallit for the thing.
Tom Uran
So I guess so far we've gone through quite a few examples where we're moderately ho hum about some.
Grok
I would like to bring up some examples now of real strategic cyber.
Tom Uran
That's what I'm waiting for.
Grok
Yeah, let's just for the sake of argument, talk about hard cyberpower and soft cyberpower, where hard cyberpower is sort of the access based, doing things on boxes effect based operations. Yeah, hacking like that stuff is hard. And soft is the information stuff where it might be enabled by a hack and leak would enable a soft power, a soft cyber power operation. So the sort of more information warfare thing and my, my take on all of this is that the real strategic power in cyber is soft cyber, this information warfare stuff. So I think that WikiLeaks, for example, had strategic level effects and some of that was enabled by hacking in the broadest possible sense. The least sophisticated of all that, but it was at least hacking adjacent. And I think that that had a strategic impact. That was an actual strategic cyberpower. And so that's where I think you start seeing real impact from cyber operations. So I would say that the information operations during 2016 had strategic impact in the US election, not so much in Brexit, that was much more just corruption and money. But similarly, I think that that's where you see actual strategic effects.
Tom Uran
Okay. So in the 2016 election, people talk about things like Cambridge Analytica targeting on Facebook, and I'm going to guess you'll.
Grok
Say no, I think that those, those were less impactful than people give it credit for. What I think had the most impact was the emails. And not for the emails themselves, but rather because they dominated the news cycle so much.
Tom Uran
Right? Yeah. There was two or three email related stories that got a lot of press. There was. Hillary's server was one, and I think these tend to get conflated in people's heads. And there was two separate Russian operations hacking into the Democratic National Convention. And those. One of those was leaked to WikiLeaks, I think. Right. Or were both, I can't remember.
Grok
Yeah, it's not clear what the origin was, whether it was the GRU or the fsb.
Tom Uran
Right? Yeah. So two separate Russian intelligence agencies were in the DNC at the same time. Some of those emails.
Grok
What would you do if you had a million dollars to Russian intelligence agencies at the same time? Dude.
Tom Uran
And then there was also that campaign where Hillary's chief of staff, what was his name? He got caught up in a fishing.
Grok
Podesta.
Tom Uran
Podesta, yeah, John Podesta. And some of those emails got leaked as well. And the leaking of those emails had. Was amplified a tremendous amount by the mainstream media.
Grok
Yep.
Tom Uran
And so your contention is all that stuff, all those three or four separate strands had some significant impact?
Grok
Yes, I think that they shaped the discourse and they created the media space like the, just the information space that dominated that election. And sort of at the 11th hour, the sort of the comey statement that they'd found a new laptop that had emails. Yeah, right. Because emails had been so dominant all the way through, that sort of kicked it over the line. It took it that last little bit of the way. So, yeah, I think that there was cyber stuff that had strategic impact and, um, I'm not sure it could have been done without cyber is what I'll say. Like Brexit cyber wasn't as important, but I think in the US it was, it was pivotal. But not in the way that you think.
Tom Uran
Yeah, yeah. I personally think the Facebook stuff was inconsequential, but the mail was like pretty significant.
Grok
Yes, yes.
Tom Uran
So it also seems in that election though, the election was just extremely finely balanced.
Grok
Yeah. It didn't cause like a 10 point swing or anything. Like it wasn't a. It wasn't this titanic shift. It certainly didn't do that.
Tom Uran
But again, there was quite a bit of time where emails and leaked emails were playing into the narrative. So it's, you know, maybe a small shift over a long time does add up to something. Absolutely. So that's one where we both agree. And those examples are kind of a mix of hacking and information operations. So they're probably relatively hard in terms of that spectrum from information operations is soft and hacking is hard.
Grok
Yeah. And they're difficult to do as well. Right. When Saudi Arabia and the UAE were trying to do information operations against Qatar in 2017, and it just like it was not working for them, they did things like they stole the email spool of an ambassador from one of the states and sent it to a journalist like the Washington Post, the New York Times, and the only thing he wrote about it was that someone sent him an email spool as if he was supposed to cover it.
Tom Uran
So it seems to me that if you're taking leaked material from Saudi Arabia and trying to get it into the US press, like that's you're going to.
Grok
It's a lot of work.
Tom Uran
It's not a topic that they care about.
Grok
Right, exactly. And also it was just the whole raw spool. Right. So it's something they don't care about. And now the guy has to do all the work to try and find something. Like the way you have to do it is you have to find an interesting narrative that they can cover and then show here's the emails in the spool that support this narrative. Right. You have to do all the work for them so that they can cover it. The more of a press release that you send to a journalist, the More likely they are actually run it.
Tom Uran
So at this point we've decided that there is such a thing as strategic cyber. It's just not what everyone thinks it is.
Grok
Right. So I would say, you know, if we come back to Ukraine and look at what has been a strategically impactful cyber operation, we've dismissed the, the start of the invasion, like those were not impactful. I would say that what has actually worked has been the information operation around Ukraine that Russia has sort of been able to successfully dominate the information space. So I would argue, for example, that at the beginning of the war, Ukraine was dominating the information space. In this, when you had all those TikToks and, you know, telegram channels, all of that stuff was very effective. But Russia is, you know, maybe not quite the 800 pound gorilla in this space, but definitely much, much larger than Ukraine. And they've been able to absolutely dominate since then. I think that's worked out very, very well for them that it has had strategic impact. Right. The, the US has shut off aid several times now.
Tom Uran
Yep, yep. And you've regularly got the President saying that Ukraine started, started the Russian invasion. I'm not quite sure how that.
Grok
Yeah, yeah, yeah, exactly. So I think that the part of the cyber operation that's been most effective is the part that isn't the cyber operation.
Tom Uran
Right. No one in Cyber Command or NSA would think of as a cyber operation.
Grok
Right. Particularly from the Western paradigm of effects based operations or intelligence, where there's very much this view that even with the theory that all cyber operations is an intelligence contest, it tends to get viewed in the can we stop them from stealing stuff and can we steal their stuff? Not can we whisper sweet nothings into the ears of their leaders.
Tom Uran
There you go. That's the real strategic cyber. Thanks, Craig.
Grok
Thanks a lot, Tom.
Risky Bulletin: Episode Summary – "Between Two Nerds: The Fate of Nations"
Podcast Information:
In this episode of Risky Bulletin, hosts Tom Uran and Grok engage in a deep dive into the concept of strategic cyber operations and their impact on global geopolitics. The discussion navigates through various real-world examples to dissect whether cyber capabilities can truly influence national outcomes in a strategic manner.
Tom Uran initiates the conversation by questioning the strategic nature of cyber operations:
“We’ve been thinking about whether cyber can be strategic. So that’s the question. But the first thing that occurs to me is that mostly people don’t know what strategic is.” [00:11]
Grok offers a refined definition:
“These big actions that have some way of influencing the behaviors of states.” [00:51]
They agree that strategic cyber is often misunderstood, typically envisioned as grandiose attacks capable of causing significant disruptions or influencing state behaviors profoundly.
Tom Uran discusses Russia's cyber operations during the invasion of Ukraine:
“The Russians launched operations to disrupt Ukrainian communications... if they had supported successful Russian conventional military action, it would have facilitated a strategic outcome.” [02:16]
Grok critiques the actual impact:
“I think everyone that’s done something like that has achieved six hours, eight hours of disruption. That doesn’t feel strategic to me.” [02:28]
They conclude that while cyber operations were intended to be strategic, their limited impact rendered them ineffective in achieving broader military goals.
Tom Uran brings up Vault Typhoon, a Chinese state-backed initiative aimed at disrupting U.S. critical infrastructure:
“…pre-positioning to be able to disrupt US critical infrastructure in the event of a conflict, probably over Taiwan.” [05:44]
Grok evaluates its strategic significance:
“It feels to me like everyone that did that just achieved minor disruptions... not the end of the world.” [06:40]
They discuss the exaggerated perceptions of such operations, emphasizing that while these actions are viewed as strategic by governments, their practical effects are often limited.
Tom Uran and Grok explore China's long-term cyber espionage efforts to bolster its manufacturing sector:
“China's become a manufacturing powerhouse... that's a huge difference in the trajectory of states.” [18:35]
Grok adds:
“They were investing in R and D by stealing someone else’s... strategic investments.” [18:37]
This prolonged cyber espionage has significantly contributed to China's economic and technological advancements, illustrating a successful strategic cyber operation through sustained efforts.
Tom Uran references the Stuxnet malware targeting Iran’s nuclear facilities:
“By breaking their centrifuges, we'll slow down their production of enriched uranium.” [15:00]
Grok offers a counterfactual perspective:
“The state that was shaped by Stuxnet was Israel... it created space for the treaty to be put in place.” [16:13]
They debate whether Stuxnet effectively delayed Iran's nuclear ambitions or simply shifted diplomatic dynamics, highlighting the complexities in measuring strategic outcomes.
Tom Uran discusses Russian interference in the 2016 U.S. elections through cyber means:
“Emails and leaked emails... had some significant impact.” [25:22]
Grok concurs:
“They shaped the discourse and created the media space that dominated that election.” [25:31]
They acknowledge that while cyber operations influenced the election narrative, the overall impact on the election result was nuanced and not as disruptive as often portrayed.
Grok introduces the distinction between hard and soft cyberpower:
He emphasizes that real strategic impact often stems from soft cyberpower:
“The real strategic power in cyber is soft cyber, this information warfare stuff.” [22:19]
Tom Uran and Grok agree that soft cyberpower, through shaping information and narratives, tends to have more profound strategic effects than traditional hacking.
Misconceptions of Strategic Cyber:
Soft Cyberpower’s Strategic Influence:
Intent and Perception:
Long-Term vs. Short-Term Effects:
Tom Uran and Grok conclude that while strategic cyber operations exist, they are frequently mischaracterized. Effective strategic cyberpower often lies in shaping information and influencing narratives rather than causing immediate, large-scale disruptions. The episode underscores the importance of understanding the nuanced roles cyber operations play in global geopolitics and challenges listeners to reconsider prevalent assumptions about the power and impact of cyber tactics.
Notable Quotes:
This comprehensive exploration by Tom Uran and Grok offers listeners a critical examination of what constitutes strategic cyber operations, utilizing historical and contemporary examples to illustrate the nuanced interplay between cyber capabilities and national strategy.