Loading summary
Tom Uren
Foreign.
Patrick Gray
And welcome to another edition of Seriously Risky Business, the podcast we do here at Risky Biz HQ, which is all about government policy and intelligence in the cyber domain. My name's Patrick Gray and we're going to chat with Tom Uren in just a moment who is our policy and intelligence editor here at Risky Business, about all of the work he's done this week in putting together the the Seriously Risky Business newsletter, which if you have not subscribed to yet, you absolutely should. And you can find that at Risky Biz. All of the subscribe links are there. We would like to say thank you to the William and Flora Hewlett foundation for supporting Tom's work with us. And also Lawfare Media, which syndicates Tom's newsletter and publishes it on their website. And we do have a sponsor this week which is Stairwell, which is a really interesting company that does all sorts of fun stuff in, in malware analysis, you can basically have your own virus total for your enterprise if you want, go threat hunting, do all sorts of fun stuff. It's like file based threat hunt within your org. Very cool stuff. That is stairwell security. So Tom, good to see you. Let's just kick it right off now by talking about. You've covered two things this week. Obviously you've taken a look at TM Signal, Telemessage Signal, which is the not so great messaging app that it turns out senior White House figures are using to have conversations that they shouldn't be having. But we also have a second topic to discuss this week, which is looking at comments out of a White House sort of cyber advisor. This is Alexei Bulazal. I'm probably butchering his name. Sorry to you, Alexei. He is the senior Director for cyber and special assistant to the President. And he's done. He's made a series of comments saying that the Trump admin is about to get more aggressive when it comes to offensive cyber operations. I mean, this is something that you predicted around the time of Trump's inauguration in a previous newsletter edition, which is, yeah, Trump loves to use state power. I think, I think the headline you gave that is like, Trump will flex America's cyber muscles. And yeah, I mean it looks like that's the way it's playing out.
Tom Uren
Yeah, exactly. And I think it is not just like, this is not just a Trump thing. It's a evolution of like pretty consistently successive administrations have gotten more aggressive in using offensive cyber operations. So when I talk about offensive ones, I mean ones that disrupt, degrade, deny, so they actually change things on the ground. And he talks about trying to, I don't know that he would be happy using the word deterrence, but trying to stop other cyber actors by actually hitting them very hard. Now, I think personally, my view is that the US has never really hit back hard against cyber actors. And it's actually a very difficult thing to do in the sense that the example I think of is Chinese intellectual property theft. It's been a wide ranging multi decade campaign and the US has hit back against particular threat actors or small espionage contractors that have been doing that. And it's like trying to deter an army by shooting a few foot soldiers. It just doesn't work. And so at the time it was like, you know, oh my God, we're going to publicly indict them and name them. But like, I guess with the benefit of hindsight, that was never going to work because it really is just, you know, you're naming a cog in a machine, you're not even doing anything to them, you're just calling them out in indictment.
Patrick Gray
Okay, okay. But like, so we agree, indictments haven't worked, right? Name and shame and indictments haven't worked. And indeed, a few days ago I spoke with the vice Chair of the Senate Select Committee on Intelligence, Senator Mark Warner. And that was interesting because he's previously said, America needs to strike back against Volt Typhoon. We need to do to them what they're doing to us. And then I tried to pin him down on those comments. You know, this is earlier this week. People can go watch the YouTube of that or listen to it as a podcast. You know, he politicianed me with his answer because I'm like, ok, you said you need to strike back. You know, he's a Democrat, so as you know, as to your point, this isn't just a Trump thing. But he didn't really say anything. Right. He was just like, you know, hand wavy. Politicians speak, politician answers, nothing about, like, what you would actually do. So when all of these politicians talk about getting serious about striking back against cyber, what, what do they mean? I mean, the United States is in a position now where its economic levers are basically exhausted because they've got a blanket 145% tariff on all Chinese goods.
Tom Uren
Yep.
Patrick Gray
So, so, you know, they've done the indictment thing. What, what does it look like? I mean, he, he absolutely warned and would absolutely not endorse the idea, at least in an interview with me, that they should go and, you know, hack Chinese civilian infrastructure, which is what the Chinese are doing to them, because that's Kind of illegal. So, so what does this mean? Like I guess we've just seen this never ending parade of officials saying it's time to get tough. But what does tough look like?
Tom Uren
Yeah, like I'm bemused as well. So my historical thinking was, is that if in the past the US had been willing to levy very hard, like even tariffs, and said, okay, you're hacking our industry, we're going to sanction or levy tariffs against the industries that are benefiting from this hacking.
Patrick Gray
We have seen that they did do that. I mean, they sanctioned a few targeted companies that they believed were using stolen Western ip. So we did see that it didn't do anything, but we've seen it.
Tom Uren
Yeah, yeah, I think it was still too little too late. Now I think you're right that at the, at this point there's no more sanctions that will make any difference. And so I'm sceptical that throwing harder cyber punches will make much difference. And not because throwing harder punches is a bad idea, but because cyber punches are just not that hard usually. And so it to me is a bit of a mystery as to what that will actually look like and when it, and when, whether it will have any effect. And so you can imagine that for example, against a hacking crew, the US might respond, gain access to their networks and actually do something like a ransomware attack or rmrf.
Patrick Gray
Well, I mean, this is sort of where my head was going as well, which is you would release the RMRF shark into like companies like isoon. Right. And just anyone who's linked to developing tools that are used in these sort of campaigns, you can just RMRF them, you know, and that would seem to be a, you know, not completely insane idea actually.
Tom Uren
No, that would act, that would slow them down and it would make them pay a lot more attention to opsec, which is another way of slowing them down. And so I think it's kind of tactically effective. But it turns, I guess it turns it into a skirmish, which is better than no skirmish at all, where it's. Because it's slower and they're less effective, but it doesn't end the war. I think it just changes the equilibrium. Now, I guess from a US point of view, you would say changing the equilibrium would be good because we've got better cyber operators. And so it'll be.
Patrick Gray
There'S an asymmetry around the defence there too because like what you could do to isoon, like, you know, someone listening to this might think, well, you know, Cyber Command might not want to give away their Beautiful choice. Zero days doing an attack like that against a contractor who might intercept them. Like, a lot of these companies, they're not well secured. Right. You would not need to use your most advanced tools to do that to them. Whereas if they were trying to strike back against America's defense industrial base, like, there are corners of the DIB in the United States that are a little bit shaky, which is why we've seen efforts over the last sort of decade, you know, by like, the NSA Cybersecurity Directorate, to secure the dip. Right. Like, that's within their remit. But you can't. You know, it would be difficult to imagine that a Chinese crew tasked with retaliating for something like this would be able to go and, like, release the RM RF shark at Lockheed Martin. Like, that ain't happening.
Tom Uren
Yeah, no, that's right. I think there's. I think that kind of thing makes sense. I don't think it is a game changer. So they kind of talk about it as a potential game changer. Like releasing offensive cyber hounds will really make a huge difference. I don't think it will. I think it's probably a good idea. I think it's worth trying. I think there's. People always worry about escalation, but there's research that people just don't think of cyber incidents in the same way they think about bombs and bullets. So I think there's like, kind of a natural limit to escalation. So I guess we'll find out.
Patrick Gray
Yeah, Yeah, I guess. I guess it's a case where we might actually find out at this point. But, I mean, you know. Indeed. When Warner made those comments, was that like a month ago or so, saying we should, you know, strike back, or the United States should strike back at China the same way that it's vault typhooning them? You know, we got mail from people who worked in critical infrastructure in the United States saying, we are not ready for an escalation here. You know, like, we really don't want this. So, you know, and again, there are corners of the dip where this could get messy, I guess, is all I'd say on that. So, I don't know. I think it could escalate. I wouldn't rule it out, is all I'm getting.
Tom Uren
Yeah. My first thought, if I was in charge, I wouldn't say, go and hack Chinese critical infrastructure. I would say, go and hack the people who are hacking our infrastructure.
Patrick Gray
Yes.
Tom Uren
And that seems to me to be a middle ground. That's. I don't see how that would Escalate. They've already to some degree done some of that by knocking their botnets offline and trying to attack their tools.
Patrick Gray
Well, and they've been hitting C2s and stuff for a long time. Like that ain't, that ain't new. But I think, you know, they're talking about going one step further. And I, you know, again, like all of these Chinese contractors who are like stealing stuff, this is the funniest thing. They'll steal intelligence when they haven't been tasked to do it and then they'll just try to sell it.
Tom Uren
Yeah.
Patrick Gray
You know, which is just a crazy way to operate. Like going after those entities. Like that seems sane.
Tom Uren
I mean, I do wonder whether there's like the potential for sort of human assets, like just buying those Chinese operators or buying intelligence from them. You know, where are you going to go after just getting ahead of what they're doing because they do seem to be cash strapped and might be amenable to a few extra dollars on the side. I guess these are the sort of ideas that you would want to really brainstorm and pick out the ones that really make sense and are not totally crazy, but are crazier than anyone has thought of actually doing before.
Patrick Gray
It's funny though, when Trump decides to get aggressive in flexing state power. I mean, you think back to a lot of the reporting that emerged after he left his first term around CIA activities in Venezuela, and it sort of seemed like CIA were told to do stuff in Venezuela and kind of half assed it because they didn't really want to do it. Whereas now you get the impression, you might see he's surrounded by loyalists now. So you might see, you know, a more earnest effort that might be half assed more due to incompetence than unwillingness now. So it's just, you know, as the curse says, may you live in interesting times. But look, let's move on to the other topic we're going to discuss today. And we did cover this in the weekly show yesterday. I had a good chat to Adam Boileau about this yesterday. But you know, senior Trump White House officials, and not just Trump officials, let's be clear. We're using this TM signal fork. It's, it's maintained by a company called Telemessage based out of Israel, which is a whole other issue with it. But this is a, a fork of signal that adds message archiving. Now, in many ways this is a good thing because, you know, one of the criticisms that you and I have had of the widespread use of signal groups within government is that, you know, record keeping is probably not up to scratch. So it looks like they're trying to address that, which is great. Unfortunately, the, this app is, for want of a better description, it's a pile of crap. It is the, the way that it's been architected is very insecure. There's source code repos out there with hard coded creds that have allowed people to just, you know, break in, intercept messages and a whole bunch of customer data. It looks like this app was first used by various US Government agencies under the. When, when Biden was president. So for me, I mean, obviously this isn't great, but for me the question, the big question in all of this is when in a world where you do have viable alternatives like Wickr, which is an Amazon product, why on earth, how on earth did this thing survive US Government procurement processes? Because it is not fit for purpose.
Tom Uren
That is just very strange and baffling.
Patrick Gray
It's the million dollar question though, in all of this. Right. And I don't see many people asking that question, which is very bizarre.
Tom Uren
Yeah, yeah. So I looked at aws. Wickr. Wickr was separate and AWS bought it and they've got some pages and they talk about some of the, I guess, certifications or authorization processes that they've gone through and they've got a number and they're actually used by the Department of Defense not for anything that you would describe at all as mission critical, but things like. I think one case study was helping frontline medical staff. So in, in or near conflict zones. So it's information that's very important. But if you know the medical history of an individual is, is leaked, the consequences aren't that great. So even with those assurances, it's still not classified for, suitable for very classified information. I think they said controlled, unclassified information. So unclassified, but stuff that you don't want to get out. So that's the very best. And somehow it managed to get all these authorizations. It's approved in Fedramp, which is the government's list of pre approved cloud services. But somehow that didn't end up translating into sales to all these other agencies. So I looked at the procurement records and Customs and Border Patrol, the Centers for Disease Control, several others were using telemessage instead. And including the National Archive, which was like the, perhaps the. I don't know if that was the root of all evil, but it seems like they're an organization that would be interested in archiving and maybe don't necessarily have the security awareness or nous to choose the right thing. Yet somehow they've sidestepped Wickr and gone to telemessage. Totally baffling.
Patrick Gray
Which seems to be like a fairly small outfit, you know, based out of Israel. And again, like there is a sort of foreign company aspect to this. Like this. There's, as they say, there's a lot to unpack here. And I think, you know, you were sort of dancing around it as well because there's kind of two discussions here. There's the, you know, what app can you put on a civilian device that is suitable for discussing classified material? And there isn't one. There just isn't one. It doesn't matter how good it is, it's just public network civilian devices can't be done. But then there's the second issue which is, well, obviously it's still appropriate actually for policymakers to have signal group chats and discussions. That's just the way that it's done now. And so if you're going to have those non critical, unclassified policy conversations, you can do that from a civilian device, you can do that from a commercial app. But, but you just want to make sure it's a good one and in this case it just isn't. And what makes it even worse is it looks like probably they would the, you know, if Waltz is using this, if he was using this at the time of the original signal gate, you know, it makes our call at the time, which is that these message were messages were almost certainly being observed by, observed by foreign adversaries. I mean it just makes that even more likely.
Tom Uren
Yeah, that's right. Now I think that you say that policymakers should be able to use civilian devices to have those discussions. I'm really torn about that. So I imagine that if you're in Australia, we have a two party system. So if you're in opposition, you don't have the tools of government, you don't have the resources of government. Like you've got no choice. You're having policy discussions about what your, what your positions are. You're probably even talking about what the other side thinks. Maybe they told you, maybe you know, for other reasons. And I think that would all be an intelligence. Landmine. Landmine, land, gold mine.
Patrick Gray
Yes.
Tom Uren
So those kinds of conversations are still valuable and ideally you'd like to protect them the best that you can. Now if you're in opposition, no resources, signal is the best you've got. I think that once you're in the Trump Cabinet, there's a responsibility to do something better than that, because those decisions, I don't know if I use the phrase, but they can affect the fate of nations.
Patrick Gray
Sure, but, but there's no universe in which the Trump Cabinet can go to an agency like NSA and say, can you please give me something that I can carry around with me and use, as I would, a civilian device that's going to allow me to have these sorts of conversations, you know, and this is a problem. So I agree with you that in an ideal world, the. They'd be using something that's much more high assurance, much more controlled. There's also the issue too, of if you are in government, do you really want to be just communicating on devices that are provisioned by essentially a spy agency? And plenty of politicians will say, no, we don't even trust our spy agencies to be in pole position to intercept all of our comms should they want to. So there's all sorts of issues with what you're describing, and I know that, that as someone who worked for the agency in Australia that would do this, which is asd, you're like, well, what's the problem? Why wouldn't they trust them? But, you know, I've known enough politicians where they wouldn't feel comfortable with that. So I think this is, you know, this is a very complicated issue.
Tom Uren
Yeah, I agree. I think there's, I think earlier in, during the campaign, there were a couple of reports about the Trump campaign using particular devices that were theoretically hardened and closed networks. So those are the sorts of things that I was thinking about.
Patrick Gray
So, whereby you've got more certified devices that are not necessarily provisioned by an agency, but approved by an agency, I.
Tom Uren
Think it's up to the government of the day to figure out what they're comfortable with.
Patrick Gray
But in this case, they're comfortable with quite a lot.
Tom Uren
Everything. That's right. But my point was it shouldn't be just taking your usual phone and, and just talking about Cabinet discussions in them from day one, which it appears maybe has happened.
Patrick Gray
Yeah, well, I mean, look, I think there's, I think this is actually an area. And look, as evidenced by the number of hours we've spent talking about this over the last month, you know, this is an area where I think there needs to be some serious policy work.
Tom Uren
Yeah, that's right. I think the. It seems like the Trump administration has, in a way, slept, walked into a huge problem. And it's.
Patrick Gray
But like, let's not, let's not just make it about the Trump admin. Because, you know, as I keep coming back to this is a problem everywhere. This is a problem for policymakers and government ministers and whatever and cabinets all over the world. Like, I don't think anybody's really sat down and thought, like, what should the guidance be like? I know that certainly here in Australia, when people are elected to Parliament, you know, they will get a visit from ASD and they will tell them, you know, about the birds and the bees of using their personal devices to have very, you know, different types of communications. And they're like, you know, I think I said to you, they will say to them, think of it as a Chinese listening device. You know, that's what you're carrying around in your pocket. It's a Chinese listening device. Treat it accordingly. And, you know, that's all well and good, but, yeah, you see what I'm.
Tom Uren
Saying, it becomes very hard to actually treat it like a Chinese listening device.
Patrick Gray
And it becomes very hard to govern if you have to treat your phone like it's radioactive.
Tom Uren
Yeah, that's right.
Patrick Gray
Well, I don't think we're going to fix it right now, but there's plenty of people who are smarter than you and I who might want to kick off some policy work here. But, Tom, you're in. Yeah, we'll wrap it up there. Great to chat to you, as always. Fascinating conversation and I look forward to doing it again with you next week.
Tom Uren
Thanks, Patrick. Sam.
Risky Bulletin Podcast Summary
Episode Title: Srsly Risky Biz: US Cyber Command to be unleashed
Host: Patrick Gray
Guest: Tom Uren, Policy and Intelligence Editor at Risky Business
Release Date: May 8, 2025
In this episode of Seriously Risky Business, host Patrick Gray engages in a deep-dive conversation with Tom Uren, the Policy and Intelligence Editor at Risky Business, to explore two critical topics impacting national cybersecurity. The discussion centers around the evolving role of the US Cyber Command towards more aggressive offensive cyber operations and the troubling use of the Telemessage Signal app by senior White House officials.
Patrick Gray initiates the conversation by referencing Tom's recent analysis of statements made by Alexei Burasal, the Senior Director for Cyber and Special Assistant to the President. Burasal has hinted at an impending increase in the aggressiveness of the Trump administration's offensive cyber operations.
Tom Uren reflects on the historical context, noting, “pretty consistently successive administrations have gotten more aggressive in using offensive cyber operations” (02:15). He elaborates that these operations aim to disrupt, degrade, and deny adversaries, effectively changing the cyber battlefield's dynamics.
Key Points Discussed:
Effectiveness of Offensive Cyber Operations:
Uren expresses skepticism about the US's ability to significantly deter cyber actors through offensive means alone. “The US has never really hit back hard against cyber actors... It's like trying to deter an army by shooting a few foot soldiers. It just doesn't work” (03:51).
Political Challenges:
Gray highlights the political rhetoric surrounding cyber retaliation, referencing Senator Mark Warner's assertion that America needs to "strike back" against threats like Volt Typhoon. However, he points out the lack of concrete strategies, stating, “politicians speak, politician answers, nothing about, like, what you would actually do” (04:53).
Potential Retaliatory Measures:
The discussion moves to possible cyber retaliation methods, such as ransomware attacks or the use of destructive commands (e.g., rm -rf). Uren suggests that while these actions could be tactically effective, they may only alter the cyber conflict's equilibrium rather than ending it: “It just changes the equilibrium. Now, I guess from a US point of view, you would say changing the equilibrium would be good...” (07:37).
Asymmetry in Cyber Defense:
Gray and Uren delve into the asymmetrical nature of cyber defense, noting that while the US might successfully deter low-level actors like Isoon through cyber attacks, targeting more secure and critical infrastructure remains a formidable challenge.
Notable Quote:
The conversation shifts focus to the alarming revelation that senior White House officials are utilizing a forked version of Signal, known as Telemessage Signal, for their communications. This app, developed by Telemessage based in Israel, incorporates message archiving features but suffers from significant security flaws.
Patrick Gray criticizes the app's security vulnerabilities, mentioning, “the way that it's been architected is very insecure. There's source code repos out there with hard-coded creds that have allowed people to just... intercept messages and a whole bunch of customer data.” (13:17). He questions the procurement processes that allowed such an insecure app to be adopted over more secure alternatives like Wickr, an Amazon-owned product approved by the Department of Defense for non-mission-critical communications.
Key Points Discussed:
Inadequate Security Measures:
The Telemessage Signal app's poor security architecture raises concerns about potential foreign adversaries intercepting sensitive communications. “If you're using this, it makes our call at the time, which is that these messages were almost certainly being observed by foreign adversaries.” (16:35).
Procurement Anomalies:
Gray and Uren examine the puzzling decision to adopt Telemessage over Wickr, despite the latter's better security credentials and endorsements from authoritative bodies like FedRAMP. “Somehow they've sidestepped Wickr and gone to telemessage. Totally baffling.” (15:21).
Policy and Governance Gaps:
The episode underscores a broader issue: the lack of comprehensive policy guidelines governing secure communications for policymakers and government officials. “This is an area where I think there needs to be some serious policy work.” (19:46).
Trust Issues with Intelligence Agencies:
The discussion touches upon the distrust some politicians have towards intelligence agencies, complicating efforts to secure communications. “Do you really want to be just communicating on devices that are provisioned by essentially a spy agency?” (17:40).
Notable Quote:
The episode highlights the complexities and challenges inherent in modern cybersecurity policy and operations. On one hand, there is a push for more aggressive offensive cyber strategies, yet the effectiveness and potential repercussions of such actions remain uncertain. On the other hand, lapses in secure communication practices among high-ranking officials expose vulnerabilities that could be exploited by adversaries.
Tom Uren emphasizes the need for a balanced approach: “If I was in charge, I wouldn't say, go and hack Chinese critical infrastructure. I would say, go and hack the people who are hacking our infrastructure.” (19:26).
Patrick Gray concurs, advocating for robust policy frameworks to guide secure communications and effective cyber retaliation strategies. Both speakers underscore the urgency of addressing these issues to safeguard national security interests.
Offensive Cyber Operations:
While increasing aggressiveness in cyber operations is a trend across administrations, its actual impact on deterring cyber threats is debatable. Effective strategies require more than just punitive measures against low-level actors.
Secure Communications:
The adoption of insecure communication tools by government officials poses significant security risks. There is a pressing need for stringent procurement processes and comprehensive policy guidelines to ensure the protection of sensitive information.
Policy Development:
Addressing cybersecurity challenges necessitates collaborative efforts to develop robust policies that balance offensive capabilities with secure communication practices, fostering a resilient national cybersecurity posture.
Timestamp Guide:
This summary captures the essential discussions, insights, and conclusions from the Risky Bulletin podcast episode, providing a comprehensive overview for those who haven't listened to the full episode.