One of the more interesting diplomatic processes in our space right now is the Pall-Mall process , a joint British and French effort to tackle commercial spyware from a nation-state norms and unified regulatory angle. Just as in the Pall-Mall game in Bridgerton, this kind of large political effort is complicated by every government hitting the ball all over the place, engaging in their own…
Introduction As you were reading the latest Research Handbook on Cyberwarfare (edited by Tim Stevens and Joe Devanny) you probably felt, like I did, that the same authors were being cited over and over again. Then, like me, you probably did a bunch of work loading the paper citations into a graph database to see if those intuitions were right. Findings: Each paper is connected to a lot of citation…
So yesterday I read with interest a Project Zero Blog detailing their efforts to understand a pressing question: Will LLMs Replace VulnDev Teams? They call this " Project Naptime ", probably because running these sorts of tests takes so much time you might as well have a nap? This comes as a follow on from other papers like this one from the team at Meta, which have tried to use LLMs to solve…
I spent some time looking at which open source packages have not been maintained or updated, and how depends on those packages. The answer is YOU :) I really like this quick Reagent query as an example. There's three hundred and fifty Pip packages in the top 5000 Pip packages with no updates since 2020? Perfect for JiaTaning! I'm not printing all of them because that's not great as a format for a…
People are having a big freakout about the Jia Tan user and I want to throw a little napalm on that kitchen fire by showing ya'll what the open source community looks like when you filter it for people with the same basic signature as Jia Tan. The summary here is: You have software on your machine right now that is running code from one of many similar "suspicious" accounts. We can run a simple…
I want to start by saying that Sergey Bratus and DARPA were geniuses at foreseeing the problems that have led us to Jia Tan and XZ. One of Sergey's projects at DARPA, SocialCyber , which I spent a couple years as a performer on, as part of the Margin Research team, was aimed directly at the issue of trust inside software development. Sergey's theory of the case, that in order to secure software,…
Paper linked here . One thing I liked about the new Cyber Statecraft paper is it had some POETRY to the language for once! Usually these things are written by a committee that sucks all the life out of it. I have a number of thoughts on it though. First of all: Defend Forward is not the totality of the shift in thinking that is happening out of the DoD, which is more properly labeled "initiative…
The news is filled with cyber hot takes on Ukraine. As someone said to me a few decades ago though - "When it's in the news, it's operations. Our job is the future." And at some level, the war in Ukraine has been stamped out already in the astonishing fortitude of Ukraine, economic and political realities, and the also frankly mind-blowing efforts of various intel groups, only visible with the…
Dave has kindly agreed to turn the keys to his blog over to me for a brief discussion of what may yet come to pass, as we consider the wars and rumours of wars that are the constant drumbeat which forms the backdrop of what has turned vulnerability discovery, weaponization, and employment from an obscure specialist niche to front page headlines (and barely disguised polemic all too popular in the…
I've read several cyber policy papers on "Culture" and how to address that when trying to recruit and retain cyber security talent, especially within the US Government, and within that, especially at CISA and DHS, which are struggling to grow. A lot of times, this comes from a military background, where people talk about lowering fitness standards or letting people grow long haircuts, which is…
The other day I read an article about cyber signaling. Signaling in international relations contexts confuses me because so much of it is about an uncertain reality, and the truth behind intensions is never know, and it weaves so much geopolitical and military context together. I pasted a section of the article, including links to the authors, below. To quickly summarize the article's arguments,…
Until recently I hadn't realized just how terrible I was at playing video games. And now after finishing Cyberpunk and watching a bunch of "spoiler" reviews I realize most people think the goal of these games is to increase some stats numbers so that the already braindead enemy AI is somehow even easier to beat up. Anyways, here's how you play open world video games, or as they will be known in…
Kyle Langvardt ( @kylelangvardt ) recently wrote a piece for Lawfare on Platform Speech Governance - in a sense, how and when can the Government make censorship decisions for social media companies. He drives the argument with theories on how the First Amendment is interpreted and applied (as he is, in fact, a legal specialist in First Amendment law). Editing (by social media companies) is not…
Progress is cyber policy is mostly apolitical and organic and international. A mistake we in the US have sometimes made is viewing our cyber policy as being purely domestic, when the key feature of the cyber domain itself is to transcend borders and to be interlinked. If you look at what works for other countries, one policy effort in a major ally stands out as being something we desperately need…
There are methods of cyber policy and strategy thought that various countries keep quiet about the way ADM/TESO kept their 0day. When it takes a long time to integrate information warfare into your techniques and operationalize it and test it and learn from the practice of it, then knowing its relative weight in hybrid warfare before your adversary does is useful enough to hide. But of course, the…
Recently I read an interesting paper by Michael Fischerkeller, who works at IDA (a US Govt contractor that does cutting-edge cyber policy work). The first concept in the paper is that the Chinese HAD to implement a massive program of cyber economic espionage in order to avoid a common economic trap that developing countries fall into, the " middle-income trap ". One thing that always surprises me…
So many articles come out decrying Europe's inability to create another Google or AWS or Azure or even a DigitalOcean, Oracle Cloud, IBM Cloud, Rackspace, Alibaba, or Tencent. Look, when you list it out loud, it's even more obvious how far behind Europe is in this space compared to where it should be. And of course, projecting power via regulatory action only gets you so far. Governments like to…
The Vulnerability Equity Process’s original sin is that it attempts to address complex equities on a per-bug basis. But the equities involved are complex and interlinked. You cannot reduce a vulnerability to a list of components with a numerical score and make any kind of sane decision on whether to release it to a vendor or not. The VEP shares this weakness with the often maligned CVSS…
Cyber Lunarium Commission #001: The Case for Cyber Letters of Marque Introducing The Cyber Lunarium Commission The Cyber Lunarium Commission was established to propose novel approaches to United States cyber strategy grounded in technical and operational realities. The commissioners of the CLC “moonlight” in cyber policy, drawing upon their experiences in government, military, industry, and…
Like many of you, my kids love Doom Eternal, Valorant , Overwatch , Fortnite, Plants Vs Zombies, Team Fortress 2, and many other video games that involve some shooting stuff but mostly calling each other names over the internet. I, on the other hand, often play a game called "Zoom calls where people try to explain what IS and IS NOT critical infrastructure". Back in the day (two decades ago) when…
Imagine you were a bipedal alien scientist studying creatures on Earth and you had never seen any before. Like that 50 First Dates movie with Adam Sandler, but instead of fart jokes from a walrus, science. Almost certainly as you examine things with your ultra-sophisticated tools, you are going to become obsessed with cause and effect or command and control. You're going to map every system and…
So the Cyberspace Solarium articles [ 1 ] and many other pieces talking about "Defending Forward" have been quite confusing, and I wanted to draw upon a few decades of history to put this strategy in context. In summary, however, defending forward is a complex and expensive tactic that has a perhaps outsized space in our national strategy, especially as espoused by the Cyberspace Solarium. The…
This is a non-trivial part of being in offense or high level defense . I recently wrote on the technical mailing list DD about the vulnerability treadmill, which essentially is the huge workload taken upon every technical person in the industry to keep up with vast amount of exploit information that is released daily. This firehose of information is distinct from the databases set up by various…
I want to talk about my experience working for the Federal Government, but also look at some wrinkles in the Cyberspace Solarium's efforts to address recruitment and retainment. At some level, every government proposal to address this problem is a twelve-dimensional remastering of Groundhog Day . You can see this in the supporting document on Lawfareblog , which focuses on the military talent…
Most comprehensive reviews of government policy have little-to-no impact, because they involve complex unpopular legislation, or implementation by an unwilling executive branch, or more often, both. That's why it's understandable that the members of the Solarium have embarked on a marketing tour, doing podcast after podcast and panel after panel to sell not just the ideas in their paper, but the…