Loading summary
Tom Uren
Hello everyone, this is Tom Uren. I'm here with another between two nerds discussion with the gruff G'.
Gruff G'
Day.
Tom Uren
How are you?
Gruff G'
Gruff G' Day Tom. Fine, and yourself?
Tom Uren
I'm well. This week's discussion is brought to you by. Knock Knock Knock Knock makes a just in time network access solution where you authenticate and then it opens up the IP addresses and ports that you need to access so it drastically reduces your attack surface. Find them at Knock Knock Knock IO so Gruk, about a week or so ago, Winona de Sombra produced this report for the Atlantic Council and it's basically a comparison of the US exploit acquisition pipeline from the whole world to US national security agencies. And she compared that to the Chinese system of acquiring exploits. Patrick and I spoke about it a few weeks ago. We thought we'd dive in a bit deeper at some of the things that you in particular have extra thoughts on.
Gruff G'
Right.
Tom Uren
Just as a very brief summary, she interviewed a whole lot of Western people at different levels of the exploitation acquisition, I'll call it a pipeline, researchers, senior officials, people who own or work at exploit development companies. And she wrote up this picture which I thought was quite nice and it matched with my understanding of what goes on, what I've heard. And then she also did a similar thing but for the Chinese system. And my feeling was that had a question mark associated with it because it didn't rely on direct sources for obvious reasons, but it was a interpretation of what we think is going on over there. And so that part add to me a few caveats. The overall thrust of the paper argues that the US needs to do things differently for various reasons.
Gruff G'
Right. I'd say off the bat that I overall very much agree with the paper. Several of the policy recommendations are things that we've either addressed here repeatedly or in other forums. Like I don't feel that she's proposing anything here that we think is necessarily completely wrong with. I mean one, one caveat which I think we'll get to. But like, I think just generally speaking it's a very clear eyed and good write up of the state of play as things are and how one sort of legacy system is maybe not fit for purpose anymore and another system is probably more suited to at least the way that the Chinese are operating, for example.
Tom Uren
Yep, yep. It felt to me that she's describing a system where for the US it's like a club where most of the people who sell, write, develop exploits are either former intelligence officials or they know people who have worked in the business. And it's somewhat incestuous and it's who you know. And that has worked up until now. But as exploits get harder and harder to find and develop, it means that you're limiting your pool unnecessarily.
Gruff G'
So this, I think it's very similar to just the defense industry market in general. Right. So I saw a thing recently about how they've done a lot of innovation in DRD acquisition pipelines to try and become more nimble and agile and gain access to the like the existing commercial market because you can get something in six months instead of six years and it will be cheaper and all this stuff and sort of they're looking at Ukraine and going like, we can't compete at that level. And so the historical problem that they've had is like the way that you gain access is you have to be able to do 250 pages of paperwork to apply to get access to a contract bid that favors the incumbents. And then it tends to also favor the people who have the three star generals on their board of advisors and things like that. So you get these people who have these long relationships and have departments set up just to handle the stuff and it's very hard to break in. It's very much an old boys club. And the way that they changed that was they made this streamlined process where for things of like less than $5 million or I mean like it's some astronomical price for an individual, but it doesn't register for like a Raytheon. Right? Yeah. And so they had the streamlined process of like several weeks turnaround and like longer commitment contracts. Like if you do a thing, we buy it, we like it, we'll do several years of purchases from you. Like we guarantee that it's not going to get stolen. And that was important because no one could do startups in the defense sector because it was just such a bad market and so no one would invest like they were literally investors would say, if you do that, we won't give you money because it's like it's useless now that it's changed. The defense sector is booming as a startup environment. I think what she's suggesting in a way is that needs to happen with the exploit acquisition pipeline is that the same sort of problem exists where there's very much this old boys club, there's very much this established network of this is how we've always done things. And while it made sense historically, it's no longer fit for purpose. It doesn't meet the needs of today's modern cyber battle. Space.
Tom Uren
Yeah. I mean, that was exactly what I thought as well, the similarity between like drones versus F35s.
Gruff G'
Right.
Tom Uren
And. Yeah, yeah, yeah. So I think that's a good description of the conclusion of the paper.
Gruff G'
Right.
Tom Uren
And what I liked is that it just sort of sets it out in a way that you read it and you go, oh, yeah, actually that's pretty obvious.
Gruff G'
Right.
Tom Uren
That just totally makes sense now. However, there were some things that.
Gruff G'
It's not all sunshine and roses.
Tom Uren
There were time for Spanish Inquisition.
Gruff G'
Now bring out the comfy chair.
Tom Uren
Yeah.
Gruff G'
Yeah. I don't think any of these things that we're going to bring up detract from the paper.
Tom Uren
Right. They're not.
Gruff G'
I don't think they're invalid. Yeah, yeah. They're criticisms.
Tom Uren
They're BTN quibbles.
Gruff G'
So it's not a criticism of the paper overall. But there are certainly things that I don't completely agree with. And I think one of the ones that stood out to me a lot was the idea of burning odes, of having these competitions to find bugs, to kill them, to deny them to the adversary or the adversaries. Right. So the idea that given that it's much harder to find bugs and there's sort of few of them to go around, if you can find and burn them, then it's very likely that you are finding and burning ones that your enemy would be using. And I think that is true, except that the enemy doesn't operate the same way you do. And she addresses this when she talks about end days where the Chinese are perfectly willing to use something if it works, even if it's not an O day. Whereas in the west, that's just not acceptable, from what I understand. Right. It's just they have very different ways of operating. So China will take something like they will happily take a CVE from 2019 that has been patched for, you know, six years now. And if it works to get them access, they will use it and they will be fine with it. Like, it won't bother them that they had to use something that was old and publicly known and can be, you know, detected by IDS or EDR or whatever. Like, that's not a problem for them. And so adding to that stockpile just increases the number of bugs that they can use, is what I'm saying.
Tom Uren
Right, right. But I mean, leaving it as zero day doesn't seem like a good idea either. Aren't you sort of attacking there the entire premise of what someone like Google's, what's it called, Project Zero or tag would do. Maybe I should read the recommendation. So it's at the back of the paper. There's a number of recommendations in different categories. One of them is catch and burn capabilities. And basically she proposes that the US Intelligence community should actively identify offensive capabilities not just leveraged by adversary states, but also offensive capabilities likely being sold to adversary states to either disclose them to vendors who can fix them or use them in false flag operations. This will assist US companies in making their products more secure while also imposing costs on an adversary. Right. So you're saying that doing that will just result in more N days which they'll just continue to use, but isn't an end day. At least you then have a chance.
Gruff G'
Of patching it in theory. I mean, you have a chance, but people don't is what I'm getting at. I don't think it's the wrong move, but I don't think it will have the impact. So I think overall, sure, making fewer O days does improve security in a way. Right. But I don't think the way that it does that is by reducing the arsenal of what's available to China. Right. Like, I don't think that that is sort of like the major win that you're getting out of it.
Tom Uren
I also kind of think that countries do this already. So I guess I'm thinking about.
Gruff G'
Absolutely.
Tom Uren
Like, like. And so this doesn't to me feels like a new thing that would be totally novel, it seems like if it maybe it's not actively pursued, but it.
Gruff G'
Also probably doesn't have as much. It's not emphasized as a thing so much as a, you know, if the opportunity comes up, let's go for it.
Tom Uren
Yeah, yeah. And I'm thinking something like Kaspersky Publishing Operation Triangulation, which was a campaign targeting iPhones and affected allegedly thousands of iPhones of Russian officials and Kaspersky Publishing a lot of details and getting it patched by Apple. That seems like exactly what's going on here.
Gruff G'
Right.
Tom Uren
And Cyber Command was publishing malware to VirusTotal for a while.
Gruff G'
Yeah.
Tom Uren
And I think that's helped, but for no particular.
Gruff G'
People do this all the time. Like it's not a novel suggestion. Absolutely. And also just very briefly, the idea of using these things for false flags is like there's a lot more to attribution than exploit use.
Tom Uren
Right.
Gruff G'
It's far more complicated. Like you can't just say, oh, they used this exploit, but then they used all the NSA tooling afterwards. It was probably China.
Tom Uren
Yeah, that part to me it felt like, oh, that's probably a lot more effort than it's worth almost all of the time. And as a policy recommendation, it struck.
Gruff G'
Me as I'm not sure what the benefit would be.
Tom Uren
That's something you'd think about for a particular operation where you've got a very specific goal in mind. But that doesn't feel like a policy recommendation so much as a brainstorming.
Gruff G'
Yeah. And what's the thing that we could do with this? Oh, we could, as part of a false flag, it could help with. I don't even know what the vocabulary is for these things where it's like, add to the costume, improve the deception. It could help improve the very similitude of the deception. Like, you could make it seem more realistic. But, like, I, I don't think that that's a problem that we have right now. Like, I don't think anyone doing a false flag is going, you know, if only we were running a hacking competition to get access to more exploits.
Tom Uren
Well, like, like this is a bit of a segue. I'm not even aware of any Western false flag operations.
Gruff G'
Triangulation. That was actually a Chinese false flag operation.
Tom Uren
This seems like a thing people talk about all the time. And I know that there have been, and I'm not even sure if they would call them false flags, but Russian operations that have taken advantage of Iranian operations.
Gruff G'
But I don't know whether it's like.
Tom Uren
Purpose was fourth party.
Gruff G'
Collection, I think, is the thing that happens. Right?
Tom Uren
Yeah, but it's like collection. It's not false flag. It's just taking advantage of someone else's work.
Gruff G'
It's cheating.
Tom Uren
It's like. I think that's exactly what I was going to say. I was going to say it's like stealing someone else's homework and claiming it as your own.
Gruff G'
I was thinking, like, it's the chatgpt of cyber espionage.
Tom Uren
Yeah. So, I mean, there have been a couple of Russian destructive operations where they tried to masquerade as the North Koreans. I think it was the Winter Olympic Games or something.
Gruff G'
Yeah, it was very sloppy. Yeah. Intentionally so. Right. Because the point was that the Russians had been excluded from participating, so they wanted to throw a hissy fit, but they couldn't actually throw a hissy fit because that would be an international incident. So it had to be plausibly the North Koreans without being too authentically the North Koreans, because the point was to be like, yeah, it's us, but you can't prove it. That's what they were going for.
Tom Uren
Yeah. The sort of implausible deniability of just enough.
Gruff G'
Yeah, no one believed it, but that was sort of the point. Right. No one was supposed to believe it. False flag recruitment is a thing that happens in HUMINT all the time. You don't like the Russians, but if the Israelis tried to recruit you, you would say, okay, so the Russians would approach you as the Israelis and be like, you know, I can't say who I'm working for, it's Mossad. And so you would cooperate with them under the impression that you are helping out the people that you wanted to help. That's where false flags are very useful because the deception is helping you achieve something by manipulating people's perception. So that makes sense. But attribution is such a weird and weak thing and it's not used for anything in cyber anyway. It doesn't seem to me like you're accomplishing something useful. I don't see the end goal. I'm probably too stupid, but it's just. I don't know why you would do that. Moving on. That seems more like a throwaway anyway.
Tom Uren
Yeah. So another thing you mentioned was East Asia.
Gruff G'
Yeah. Right. So there's a couple of things that she brought up which I'd like to discuss. China has actually invested very heavily in their exploit development pipeline in a way that the US has not. And this is a thing that we've like we've brought this up multiple times in different ways. So all the pone to own competitions used to be absolutely dominated by China because they had these huge teams. Like there are 300 people just at Tencent, Alibaba and Kihu. 360 like they each had 100 people working on oday development like exploit dev. And if you look at what the US has commercially, similarly in that it's a large tech company that's investing in this. You have the 10 people at Project Zero at Google.
Tom Uren
Yep.
Gruff G'
So any one of Those companies has 10 times the number of people working on it, right?
Tom Uren
Yeah, yeah.
Gruff G'
Right. And there's three of them. So there's 30 times as many people working on this stuff. Right. So they just absolutely dominated these contexts.
Tom Uren
One thing that came out in the paper is that in China there is a real proper pipeline from school, university to immediately to jobs. Whereas in the US there's this kind of gap where it's really people seem to either use hacking competitions to develop skills or are self taught or whatever. There's no explicit abcd. It's like a B G somehow.
Gruff G'
Right.
Tom Uren
And this part felt right to me.
Gruff G'
Yeah. And I think, again, this is a thing that we've. Like, I feel like we've talked about this before and that how China has invested heavily in education and creating this pipeline of, like, if this is a thing that interests you, here's a career path that can be very rewarding. And these are all the steps that you take. And it's all laid out. You've got a lot of options to pursue it and all that. Whereas in the us, I think if you wanted to do exploit development, you'd sort of either have to learn it yourself or somehow get recruited by NSA after you've gotten your Ph.D. in math.
Tom Uren
Yeah. Like in the U.S. i'm just thinking of Charlie Miller, who worked for NSA and then went and did the hacking contests and did quite well at them.
Gruff G'
Right.
Tom Uren
It's the kind of reverse process.
Gruff G'
Right. And he got his PhD in math and then he got hired and then they were like, we're going to send you to the hacking training.
Tom Uren
Yep.
Gruff G'
And from there he learned how to hack. He didn't show up as like, I'm a good hacker, you should let me in.
Tom Uren
So one of the things you mentioned before was that you didn't think that the Chinese were getting many exploits from East Asia. So the paper says.
Gruff G'
Right.
Tom Uren
That China is attempting to expand its offensive hacking talent pool to researchers in East Asia, South Asia and the Middle east. And so that it's trying to develop a much broader aperture, I guess.
Gruff G'
Yeah.
Tom Uren
Fish in a bigger pool.
Gruff G'
Yeah. Like, they might be trying, but I'm very dubious about whether that's a significant source of bugs or anything or talent for them for a number of reasons. Like, basically, if you look at Southeast Asia, there's Singapore, which they no longer dance with the Chinese on this one. Like, there's that very public sanction against Thomas Lim for allegedly. So they're not.
Tom Uren
Patrick interviewed Thomas, I think, many years ago, but Thomas was quite mercenary and he would say, yes, I would sell to the Chinese, their money is green or red or whatever. I don't think he used those words. But he was subsequently sanctioned two or three years ago, something like that.
Gruff G'
I think it was a bit more. But yeah, he was sanctioned for allegedly selling things to China. Right. And so you're saying if he did or didn't. But that's the impression that people have, like, because one of the things is they don't tell you why you were sanctioned. Right, right. Like, they don't say, we're sanctioning you for this specific thing. Like, it. It tends to be like, Just in general, we don't like what you're doing.
Tom Uren
Right, right.
Gruff G'
So in this case, they didn't say, you know, on March 4th when you sold this thing to them. But the impression that everyone had was he was selling to China, he got caught, he got sanctioned. We won't do that.
Tom Uren
So that sanction had the desired effect from the US Point of view.
Gruff G'
Right. And I think it's because it was very targeted and specific in going after an ally rather than an adversary. So that Singaporeans are aligned with the US Anyway. So it's not a. It's not a difficult decision for them.
Tom Uren
Well, I mean, I think that they would say that they're not aligned with the US but.
Gruff G'
Right. I mean, they're not necessarily aligned, but they're certainly friendly. They're open to them.
Tom Uren
And yes. You know, they're not openly disaligned.
Gruff G'
Right. They're not an Axis of Evil member. Yeah. And. And they get hacked by China all the time. So there's a little bit of an adversarial relationship, even though there's. There's obviously quite a lot of ties.
Tom Uren
I actually wrote about the sanction of Thomas lim back in November 2021, and what I said at the time is that he was sanctioned because, and I quote, traffic in cyber exploits used to gain access to information systems, threatening the privacy and security of individuals and organizations worldwide. So that is from the U.S. government. So it doesn't say China, it just says trafficking. But yeah, right.
Gruff G'
He wasn't trafficking them to the US and they were suddenly like, oh, my God, NSA is using this. You've done bad. That's right.
Tom Uren
I think we can safely assume that.
Gruff G'
So, yeah, look, there's Singapore, but I don't think anyone in Singapore is going to be adding to the Chinese pipeline. Laos, Cambodia and Myanmar we can kind of ignore because those are not sort of hotbeds of exploit development. Thailand is not super great for this. And then you've got Vietnam, where actually, while there is quite a lot of security talent, they don't have the best relationship with China.
Tom Uren
Right.
Gruff G'
Like they were invaded by the Chinese. They have a thousand years of fighting the Chinese. They still get constantly hacked by them. So I don't think they would be super thrilled to do that. But also there's a lot of. There's a lot of very lucrative technology opportunities there that aren't security related. You can make a lot more money if you go into like the, the Vietnamese Facebook or the Vietnamese Instagram or the, the Vietnamese WhatsApp and stuff like that like they, there's just like you could, you could do this thing that makes you like a hundred thousand dollars a year, which is great money, or you could do this other thing where you get stock options and you can retire in a few years with millions. And it's not a choice at that point. So I don't think there's a lot of surplus talent available. Right. So there's. That Malaysia actually does have a very good, very rich security community. But my understanding is that they don't really like China very much. I don't see them developing exploits and selling them to China as a big thing. Like they're, they're closer to Singapore and they're aware of what happened to Thomas Slim as well. Right. So they're going to see the same sort of threats. This would go for Indonesia, which has a much smaller community, but it's similarly like they've seen what happened. Right. So like China might be throwing out feelers, but I don't think they're getting a lot of. I don't think it's a rich pool for them to be fishing in.
Tom Uren
Right, right, right.
Gruff G'
I just don't think anyone's interested.
Tom Uren
I guess that raises the natural question of is this a pool that should be looking to absolutely fish in.
Gruff G'
Yeah, absolutely.
Tom Uren
Because a lot of those dynamics you've described are one, we just don't like the Chinese, or two, there's, there's better alternatives.
Gruff G'
So if there, there's any alternatives, then those would be more attractive, just inherently like, so you, you could have price parity and then all of the soft power stuff around it would make it more attractive. You could possibly even have lower prices and still be more attractive.
Tom Uren
Right. So for many of those countries, the South China Sea is an issue that they might care about, whereas I think that probably the average US citizen doesn't care about it. Particularly there's a contested area where the Philippines, Vietnam, China, Malaysia, Singapore are all worried about this area of sea.
Gruff G'
Yeah, there's a lot of things would.
Tom Uren
Have some sort of impact.
Gruff G'
Absolutely. I don't think any of these places have friendly relationships. It's sort of neutral to suspicious. And I think that goes for the population as well. China, it's not been very good at doing outreach and building Chinese soft power.
Tom Uren
Doesn'T really seem to be a thing.
Gruff G'
Yeah, the wolf warrior diplomacy thing is sort of, it's not doing them any favors, I think.
Tom Uren
Yeah, yeah. So selling to China seems like a non starter, obviously with individual exceptions, because there's always individual exceptions. But selling to The US or its allies, I guess, which is right.
Gruff G'
NATO in general, the West.
Tom Uren
Seems like it's a possibility.
Gruff G'
Yeah. I think that that would be attractive. And it's unlikely to get censure from the local government as well. It's not addressed in this paper, but it's one of the things to remember is that governments have a tendency to look at this sort of thing as a strategic interest for the state. So they might not be paying attention to it beforehand. But if they find out that all of these capabilities are being developed by a company headquartered in their capital but being sold to the US rather than being offered to them first, they could take a very dim view of that. There tends to be a sort of like, we will allow you to do this, but we should have first dibs. It's unlikely that they'll be super thrilled to find out that all of the stuff that's being developed by their people is being shipped overseas.
Tom Uren
Right, right. But that seems an argument against selling to the US as well, or Australia, for example.
Gruff G'
Yes, yes, yes, it'd be an argument. Again, let me rephrase it. It's not necessarily an argument against. It's that it's not as easy as it seems. It's not like you can just show up and be like, hi, we're the more attractive option. You should sell to us. Because actually the most attractive option is the local government. And if they're bypassed, they might take offense. So the dynamics are a lot more complex than just like, are the good guys you should sell to us. Right. But there's certainly an opportunity that does exist that can be taken advantage of. It's not necessarily that there's a huge pool of surplus skill and talent that's waiting to be tapped. Right. It does exist, but it's not necessarily.
Tom Uren
Right. Yeah. I mean, the US has intelligence relationships with many, many countries. So it seems like that there might.
Gruff G'
Be basically the 150 eyes or something.
Tom Uren
And I would describe many of them as tactical relationships based on particular purposes. But it seems that there might be a way to square that circle of acquiring exploits and giving up something in return.
Gruff G'
I think if you're interested, it can easily be done.
Tom Uren
Now, one of the things that Winona wrote in her paper that we both took exception to was she says US big tech companies, and this is the subtitle as a strategic counterweight. And her argument, if I'm understanding it right, is that because the US big tech companies work so hard to fix their products and plug security gaps, this is actually a net Negative for the US because they're so dominant worldwide relatively, that that actually makes it harder for the U.S. intelligence agencies.
Gruff G'
Oh, I think in a very, very narrow view, you could see it that way from an absolute frontline operator perspective. Maybe like, you're making my personal job harder, but. But as soon as you get to anyone above frontline, it's like, yeah, you're making it easier for us overall and harder for our enemies.
Tom Uren
Yeah. So what she explicitly says is US domestic technology companies, cybersecurity measures are a strategic obstacle to US offensive cyber goals. And I think narrowly, I'd say it's.
Gruff G'
A tactical obstacle at best. Certainly not strategic.
Tom Uren
Yeah. So I kind of think narrowly that's true. Better security makes it harder, but that, I think, doesn't mean it's a net loss for the US as a whole.
Gruff G'
Right. I think strategically it's a net win. Tactically, it might make certain things harder, but it makes it harder for everyone.
Tom Uren
Yeah, yeah. So she particularly talks about the mobile phone market, where iOS and Android are relatively dominant globally. And she's arguing because those companies, Apple and Google, have been so good at fixing things, that this has made it much harder and the US is a net loser. I'm not sure that she actually explicitly says.
Gruff G'
I just. I fundamentally disagree in that I think that the ability for NSA to find exploits in iOS, like, even if the difficulty ramps up, the ability for NSA will still be there. They'll still be able to find something as long as there's something to be found. I don't think that holds true for everyone. Right. So I think it might be more of a problem for, say, France or Germany or the uk and I think that disproportionately affects adversarial nations, possibly not China, given their depth of exploit development talent. But that just suggests that there needs to be even more investment in security to keep China out.
Tom Uren
Right. Well, what is interesting to me is that you mentioned the Huawei os, and I think there is increasingly other markets which don't use Android or iOS, and I think, you know, having domestic companies that make a very secure operating system is a net win. And if somebody else uses something else, well, it's like.
Gruff G'
After Operation Triangulation, like Russian diplomats and that are banned from using iOS. So improving iOS is not a strategic problem at all anymore because the adversary is not using it. Yeah. I think overall it's much better strategically for the US to have secure stuff. I don't think there's a downside other than individual cases of, like, frustration and difficulty yeah.
Tom Uren
For a target that is entirely using iOS devices, for that team prosecuting that target, I think it's a net loss. But I think for the broader enterprise and for the broader US Strategic interests, it's not.
Gruff G'
Yes, absolutely. So I think one of the things that we didn't bring up how the US acquisition program is it's a legacy system, but it's also, it plays into the US strategic culture of how they do their cyber operations, which is sort of these bespoke, tailored, very, you know, it's a unique access solution that is a capability exclusive to us that we paid a bajillion dollars for that allows us to do this magical thing. And China does not have that same strategic culture.
Tom Uren
Right.
Gruff G'
They don't have the same approach. And so obviously they're not going to have the same exploit acquisition pipeline. It's just. It doesn't match the strategy. So, yeah, I think that that's something that wasn't addressed in the paper and I wouldn't expect it to be, but I do think it's worth raising in that they're just these fundamental cultural differences. And while I think that the US can adapt their culture and their pipeline maybe to be more flexible and better than it is, they're not going to have China's pipeline. It's just. It's not going to happen. They can, they can get something that fits the American culture and it's more flexible and takes advantage of their strengths. And it's probably something along the lines of what she's recommended. But it's not the Chinese system.
Tom Uren
Yeah, I guess they're looking for the Chinese system with American characteristics.
Gruff G'
Thanks a lot, Tom.
Tom Uren
Thanks God.
Episode Release Date: July 7, 2025
Host: Tom Uren
Guest: Gruff G'
Description: An in-depth discussion on Winona de Sombra’s report comparing the US and Chinese exploit acquisition pipelines and the strategic implications for cybersecurity.
The episode kicks off with Tom Uren introducing the topic of discussion—Winona de Sombra’s recent report for the Atlantic Council, which provides a comparative analysis of the exploit acquisition pipelines in the United States and China. Tom sets the stage by mentioning a previous conversation with Patrick and expressing the intent to delve deeper into areas where Gruff G' has additional insights.
Notable Quote:
Tom Uren [00:12]: "The overall thrust of the paper argues that the US needs to do things differently for various reasons."
Winona de Sombra’s report examines the mechanisms through which both the US and China acquire cybersecurity exploits. The US system is portrayed as an "old boys club," relying heavily on former intelligence officials and established relationships, whereas the Chinese system is characterized by substantial investment and a structured pipeline from education to exploit development.
Notable Quote:
Gruff G' [02:52]: "The historical problem has been how to gain access, favoring incumbents and long-established networks."
Tom and Gruff discuss the US exploit acquisition pipeline's reliance on a limited pool of talent, often sourced from within intelligence circles or through established companies. This exclusivity, while historically effective, is now seen as restrictive, especially as the difficulty of developing new exploits increases.
Notable Quote:
Tom Uren [03:27]: "It's the way that you gain access is you have to be able to do 250 pages of paperwork... it's very much an old boys club."
Gruff elaborates by comparing this system to the broader defense industry, highlighting efforts to streamline processes to attract startups and innovate, drawing parallels to the exploit acquisition context.
The conversation shifts to China's approach, which involves significant investment in exploit development. China’s strategy includes establishing a direct pipeline from educational institutions to jobs in exploit development, resulting in a much larger and more organized talent pool compared to the US.
Notable Quote:
Gruff G' [14:42]: "China has invested very heavily in their exploit development pipeline in a way that the US has not."
Tom underscores the disparity by noting the sheer number of professionals China employs in exploit development versus the limited personnel in US companies like Google's Project Zero.
Winona's report suggests that the US needs to adopt new strategies to enhance its exploit acquisition capabilities. One such recommendation is the "catch and burn" approach, where the US actively identifies and neutralizes offensive exploits potentially used by adversaries.
Notable Quotes:
Tom Uren [08:16]: "US Intelligence community should actively identify offensive capabilities not just leveraged by adversary states..."
Gruff G' [09:45]: "I don't think that that is sort of the major win that you're getting out of it."
However, Tom and Gruff express skepticism about the effectiveness of these recommendations. They argue that while reducing zero-days can improve security, it may inadvertently benefit adversaries like China, who operate differently and may continue to exploit known vulnerabilities.
The discussion delves into the complexities of false flag operations in cybersecurity. Gruff points out that attributing cyberattacks is inherently difficult, making such operations less effective and unreliable.
Notable Quote:
Gruff G' [10:35]: "Attribution is such a weird and weak thing and it's not used for anything in cyber anyway."
They debate the practicality and strategic value of using exploits in false flag operations, ultimately questioning the tangible benefits of such tactics.
Tom and Gruff explore the potential for expanding the exploit acquisition pipeline to other regions in Asia. While China poses a clear adversary, the possibility of sourcing talent from countries like Singapore, Vietnam, and Malaysia is scrutinized. They highlight geopolitical tensions and economic incentives that influence the willingness and capability of these countries to contribute to exploit development.
Notable Quote:
Gruff G' [21:01]: "There's a lot of lucrative technology opportunities that aren't security related... there's just like you could do this thing that makes you like a hundred thousand dollars a year, which is great money."
Despite some opportunities, the overall sentiment is that the pool of willing and capable talent in these regions is limited due to adverse relations with China and more attractive career paths in other technology sectors.
The report controversially suggests that US big tech companies, due to their robust cybersecurity measures, may inadvertently hinder US offensive cyber capabilities. Gruff counters this by arguing that while frontline operations might face challenges, the broader strategic advantage of secure products outweighs these drawbacks.
Notable Quotes:
Gruff G' [27:11]: "As soon as you get to anyone above frontline, it's like, yeah, you're making it easier for us overall and harder for our enemies."
Tom Uren [28:05]: "She argues that because big tech is so good at fixing things, it makes it harder for US intelligence, but I think strategically it's a net win."
Tom emphasizes that secure operating systems like iOS and Android enhance US strategic interests by limiting adversaries' exploitation capabilities, despite potential tactical challenges in specific operations.
A significant part of the conversation focuses on the cultural disparities between the US and China in conducting cyber operations. Gruff notes that the US has a legacy system and a strategic culture that emphasizes bespoke, tailored cyber capabilities, contrasting with China's systematic and heavily invested approach.
Notable Quote:
Gruff G' [31:02]: "China does not have that same strategic culture... they don't have the same exploit acquisition pipeline."
Tom agrees, suggesting that while the US can adapt its pipeline to be more flexible and effective, it won’t mirror the Chinese system but will instead develop a uniquely American approach.
Tom and Gruff wrap up the discussion by acknowledging the depth and validity of Winona de Sombra’s report while also highlighting areas of disagreement and skepticism. They emphasize the need for the US to evolve its exploit acquisition strategies to remain competitive against China's more expansive and structured approach. The conversation underscores the complexity of cybersecurity strategy, where policy recommendations must balance tactical advantages with overarching strategic goals.
Notable Quote:
Gruff G' [31:53]: "The US can adapt their culture and their pipeline maybe to be more flexible and better than it is... they can get something that fits the American culture and it's more flexible and takes advantage of their strengths."
Final Thoughts:
This episode of Risky Bulletin provides a comprehensive analysis of the differing approaches between the US and China in cybersecurity exploit acquisition. Through insightful dialogue, Tom Uren and Gruff G' dissect the strengths and weaknesses of each system, offering listeners a nuanced understanding of the strategic landscape in cybersecurity. The discussion not only highlights the immediate implications of the report but also encourages ongoing conversation about adapting strategies to meet evolving global threats.