Solutions From The Multiverse

Cybersecurity Security | s04 e02

Adam Braus & Scot Maupin Season 4 Episode 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 46:13

Send us Fan Mail

Cybersecurity isn’t failing because regular people are careless, it’s failing because we built the internet like a city with no real police force. Today, banks, hospitals, water systems, power grids, and even elections run on software, yet we still act like cyber attacks are a private problem solved by buying more tools and hoping your team patches fast enough. We make the case that this “everyone for themselves” model is exactly why phishing scams, ransomware, and mass data breaches keep winning. 

We walk through a public-safety approach: massively scale up FBI cybersecurity resources and military cyber capabilities for cross-border threats, then push that capacity down to states and major cities with dedicated cyber police units. The goal isn’t surveillance theater, it’s practical protection: investigate cybercrime, pursue foreign hackers, and proactively test the defenses of major companies and critical infrastructure. If a team can legally break in first, report the holes, and fine repeat negligence, patching stops being optional and starts being routine. 

Then we go after incentives. Should software vendors be allowed to ship vulnerable products and also sell pricey security services to protect them? We argue that’s a built-in conflict of interest. We also explore software liability: if a Microsoft-style exploit leads to a nine-figure loss, should the vendor share part of the cost the way manufacturers can face product liability in the physical world? Along the way we talk AI coding, “vibe coding,” and why simpler software often means fewer doors for attackers. 

If you care about secure software, cybersecurity policy, data privacy, and protecting everyday people online, hit subscribe, share the show, and leave a review so more listeners can find it.

Support the show


Help these new solutions spread by ...

  1. Subscribing wherever you listen to podcasts
  2. Leaving a 5-star review 
  3. Sharing your favorite solution with your friends and network (this makes a BIG difference)

Comments? Feedback? Questions? Solutions? Message us! We will do a mailbag episode.

Email:
solutionsfromthemultiverse@gmail.com
Adam: @ajbraus - braus@hey.com
Scot: @scotmaupin

adambraus.com (Link to Adam's projects and books)
The Perfect Show (Scot's solo podcast)

Thanks to Jonah Burns for the SFM music.

Welcome And The Cybersecurity Claim

SPEAKER_03

Hey everyone, I'm Adam Browse. And I'm Scott Moppen. And this is Solutions from the Multiverse, where we bring you a unheard of new solution to the world's problems.

SPEAKER_01

That's right. We have a brand new episode today. So what is the solution, Adam? What are you bringing us?

SPEAKER_03

Today we're talking about cybersecurity. Fascinating topic in our times.

SPEAKER_01

Sure, of course.

SPEAKER_03

At the very end of a master's degree in cybersecurity. So I've been studying this for more than a year now. My final project is like a peer-reviewed paper that hopefully will get accepted in like one of the cybersecurity journals. So I did some like original research and yeah, and I just I have a solution for cybersecurity. We're going to solve cybersecurity here today.

SPEAKER_01

Do you in order to get your master's in cybersecurity, do you have to like battle through a bunch of like a bunch of hackers one after until you get to a higher level boss?

SPEAKER_03

Yeah, you start out with a white hoodie and then you get like a yellow hoodie, then you get like a green hoodie, and you kind of work your way up. It's the instead of belts, we have the hoodie system. And then once you get a black hoodie, then you get like you know, little like notches in your hoodie underneath, you know, so you're like an eighth degree black hoodie hacker.

SPEAKER_01

That's why you never mess with a cybersecurity who has a black hoodie on.

SPEAKER_03

So my program was like very like policy focused, so we didn't do a ton of like technical, like we did technical stuff like dashboards and how to sort of look at logs and how to deal with different stuff, but we weren't like really doing like penetration testing and like really deep hacking stuff. It was more like policy, like how do you set up policy, how do you be defensive? It's more defensive.

SPEAKER_01

Well, when you say you want to solve cybersecurity, it isn't cybersecurity like meant to solve other things, like isn't that meant to solve it?

SPEAKER_03

Well, I guess I should say I want to solve cyber attacks, right? I want to make it so there are like way fewer cyber attacks. And when there are that, yeah.

SPEAKER_01

How what are you what do you got?

SPEAKER_03

Okay, so this was I kept on feeling

The City With No Police

SPEAKER_03

like I was taking like crazy pills throughout the whole masters, and so about six months in, I just I figured out. I was like, wait a second, wait a second. This is weird. And what I I'll I'll explain it this way Imagine you were making like a new city, and you just didn't make police officers, like you just hadn't gotten around to that yet. So the city had like no police officers, and then there were these like burglaries happening, right? And then everyone was like, oh well, we've gotta you know increase our anti-burglary stuff. So each house and each business and each building would be responsible for like having like security systems and like hiring their own security guards to defend, but no police, just everything completely private. Right. And then you know, the security guards and the people who make like the security systems, they would have been kind of like in this city, in this imaginary city, they would know how all the security systems worked, you know what I mean? So they would have like if they went home, put on black masks, they could like go and like try to and like steal stuff, right? Yeah.

SPEAKER_02

So there's a problem with this here, right?

SPEAKER_01

I've seen this in movies where like the person installs a security system and then comes back and is like, I left myself a back door, get in and steal the jewels.

SPEAKER_03

Right. And so this idea, so so this is how cybersecurity operates today. The budgets for cybersecurity policing by like the FBI is like a pittance. I mean, it's still in the hundreds of millions, right? Now that all systems are online, like water systems, electricity systems, like everything is online. The military cybersecurity budget is nothing, is a fra just a fraction of you know, aircraft carry, like their whole budget is everything. You know, aircraft carries, nuclear weapons. Their cybersecurity budget is vanishingly small. And yet, today, one of the most dangerous things is that other nations could like attack American cyber properties, right? Whatever you want to think of it, banks.

SPEAKER_01

Yeah, would those attacks be like infrastructure or like taking out taking out capabilities of they could screw anything up.

SPEAKER_03

They can screw up social media, they can screw up our elections on social media, right? That's all cyber, you know, hacking, attacking.

SPEAKER_01

They can, yeah, they can attack the stoplights green at the same time. So people smash into each other.

SPEAKER_03

But everybody smashes into the great, the great smash up of 2027.

SPEAKER_01

I have to drive, it's green. I can't. There's a great one, but I will smash into it because the green light tells me to go.

SPEAKER_03

We found the American, the Achilles heel of America. Green lights. All the green lights. There's a 50 million car pile up today on everywhere in America because everyone just went through the green light. Yes. So we're like, so basically the FBI's budget for cybersecurity is like vanishingly. It's very small. The and I and I did a whole like report on this, so I know the and I can't remember the exact numbers, but it's very small. And they like they're like, even like last people who are listening right now who Google me because they don't believe what I say, they'll say, Oh no, look, there's a report that FBI increased their cybersecurity budget by a lot. It's like, yeah, yeah. They increased it from like $10 million to like $80 million. Like they they increased it to it's still a tiny amount of money. It needs to be like many billions of dollars need to be spent to like protect cyberspace. And they just don't. And so it's like a city with no police force where every single individual citizen is told, well, you gotta be careful, passwords, and you gotta like, you know, be careful and like be vigilant. You're gonna have a phishing scam. They're gonna call you and scam you, they're gonna email you back your identity. What why why are we putting this on citizens to just be like these?

SPEAKER_01

You know, they're the security system that's crazy. Yeah, because they're not the average person is not savvy with cybersecurity methods or we don't have time. That's why these scams and stuff work, is because you get people who don't know what they're dealing with, and you have a knowledge advantage and they take advantage of the person. Exactly.

SPEAKER_03

And so the solution today is it sounds crazy because everyone on this podcast knows that I'm kind of left-wing, which means and left-wing people aren't usually like more police officers. Like, usually left-wing people are sort of, you know, I don't know. But I think this is an exceptional case where we need like majorly bigger military cybersecurity budgets and FBI cybersecurity budgets. And actually, all the way down, like I think states, like every state should make its own, just like they have their own like highway patrolmen and polices, like they should have their own cybersecurity force, major cities like LA, Chicago, like they they have cybersecurity people to sort of protect their own city infrastructure, but actually there should be like an LAPD cyber unit that should have like lots of money to protect LA citizens from cyber attacks and cyber problems, right? Because I think we're way underspending. We need to go like crazy on it. And I have another solution too.

SPEAKER_01

It's not just money, I have another thing, but that's what I'm wondering as you say this, is it like, are you saying that the military should have cybersecurity that protects itself harder, or that it like goes out and gets the people?

SPEAKER_03

No, no, it should go out, it should be a cybersecurity that protects Americans, like cops who have cyber attacks from foreign nationals, catching them, and especially state actors, but even foreign nationals. I mean, you know, a foreign national who attacks an American in cyberspace, there isn't really like a police force that can go do that. It's the military.

SPEAKER_01

The military, wouldn't the military be the like Yeah.

SPEAKER_03

What is the rule if like somebody from another country attacks right, you know, like like if uh if uh some like German hacker hacks like a hundred million dollars away from Americans?

SPEAKER_01

Is that I guess you ask the Germans German crime then.

SPEAKER_03

I guess you ask the Germans to extradite them.

SPEAKER_01

Yeah. But what if the Germans aren't doing like happening there, even though the

Why Budgets Ignore The Real Threat

SPEAKER_01

victim is here? It's right, it's confusing.

SPEAKER_03

I think you'd have to say, like, we through cyberspace try to find this guy. Maybe the CIA could do it. Actually, that would be like one useful thing the CIA could do. Because the CIA is like completely useless and BS. Uh, if anyone doesn't believe that, they can just read the book The Legacy of Ashes, which is uh uh basically in the in the 90s, all or in the 2000s, all the because they they have like a kind of uh they give you like 50 years where they won't uh expose anything or 30 years, like everything's locked down. But after 30 years, everything becomes public. So in the 2000s, everything up through the 70s became public about what the CIA was doing throughout the Cold War, all the way up, you know, to the end of the 70s. And basically, if you just look like our journalist just like read all like 50,000 pages of this, and he just found that the CIA was completely incompetent and like failed at almost every mission it tried to do, and is just like completely useless. And I don't think they've gotten any better. I mean, we don't know because it's all like you know, cloaking bags.

SPEAKER_01

That's that's another use for secrecy. I mean, if you are really bad at your job and you're just like, I mean confidential. I would tell you, but it's classified. My incompetence is confidential. So I guess so.

SPEAKER_03

Yeah, maybe the CIA does it or whatever. I don't actually care who does it, but someone needs to be the police force for domestic cyber terror cyber attacks, and somebody needs a police force for international cyber attacks. And if other countries are not living up to it, then we need to just like do whatever we need to do to protect Americans, you know, even if I mean, because this is the world we live in. We we live in this world where the internet crosses borders in this weird way, right? The other thing, so there's a couple things that this police force could do. And there's one other, I'll say, I'll share one other thing too before I go on to the police force because everyone's just gonna say, Oh, you're just saying throw money at it or something. I'm not just saying throw money at it. I'm saying make the budgets adequate to the proportional to the problem, which they currently are not. Let's actually have a police force. This is where it is sort of left-wing or sort of socialist. Like I'm saying, let's have a police force instead of all private security systems, right? Which is like a for all for-profit ventures, you know, provided by the market.

SPEAKER_01

Are these guys actually are they effective are they effective? Like if we scaled up the people chasing, are they able to catch them? Is this a thing that it's just sure? Of course, these guys can't figure out, or I don't even know how you would go about catching these guys.

SPEAKER_03

No, of course, it's it's of course. No, it's perfect. Yeah, though they're very effective. They have computers, they have smart people, you know, these are just systems, and also you can pay the hackers to like switch sides, you know. It's all like it's like organized crime, you know, you have to kind of approach it like organized crime. Like, but the other thing that needs to happen is businesses that sell software need it needs to be illegal for them to sell security services. Like Microsoft sells all of Microsoft software for servers, for personal computers, and they have these huge business systems, all running Microsoft government systems, all running Microsoft Universities, right? And they also sell security services to like do cybersecurity to protect their software, but their software is very buggy and hackable. All the major hacks happen on Microsoft systems. They don't happen on Linux, they don't happen on Apple, they happen on Windows, they happen on Windows servers and Windows computers and Word and Microsoft. You know, it's all my Microsoft is just awful. So the fact that Microsoft can make buggy, vulnerable software and then sell this year, they sold $20 billion in cybersecurity services. No, that should be illegal because you know you're creating your own market.

SPEAKER_01

You're you're like, oh, ship buggy software, then charge people a solution to make your software better. That should be part of your product, yeah, right. Not a separate product that people have to buy to exactly.

SPEAKER_03

And then the people who don't buy your social security services, they're vulnerable. So in a way, you're just extorting people out of their money with with your crappy software. And then there's one other thing we have to add, which is if there's hacks, I think like a hack for a hundred million dollars, the software that was exploited, whoever made that software should be on the hook for a fraction of that hundred million. So like Microsoft would basically be on the hook for like billions of dollars every year because they're the source of like all hacks.

SPEAKER_01

So you're not the source of skin the game and that they can it it incentivizes them to not have buggy software, right?

SPEAKER_03

Right. So if we did those things, if we said and and there are there are precedents for this, like you know, there are precedents for for who you can go after when there's like a problem, right? Like, you know, if a car goes off the road and kills someone, you know, you can go and look at like the manufacturer of the car and be like, wait a second, this car's brake pedals didn't work right. And the manufacturer is now becomes partially liable, you know, even though the driver was behind the wheel, right? Like there are models for this. So and it probably shouldn't, it's not a hundred, obviously, it shouldn't be a hundred percent of the money, is it's their fault, right? There's some it's probably a fifth or something, but some amount of the money needs to come from the the software.

SPEAKER_01

But it depends. I guess it, I don't know. I feel like if somebody is good naturedly writing software that then gets put on something else and somebody misuses it, then they're like, wait a minute, now I owe two billion dollars? I was just writing a like a widget. What do you do? Like, how do I pentagon two billion dollars?

SPEAKER_03

That might be that might make it so that people reviewed their code more and did more reviews of security before they shipped it. It's not that hard to make secure software if you really think about it, and you hire the experts to actually make it secure, and you pay for it.

SPEAKER_01

You just said Microsoft can't do it. They're not gonna be able to do it.

SPEAKER_03

No, no, that's the thing. They can do it, they don't do it. This is the thing that people are deliberately shipping buggy code because there's no cost to them, all the cost is borne by the customer, and they can make money selling security services, right? So they can make secure software. Apple makes secure software. How many times have you heard there was a major Apple breach? How many times? I've never heard of one. I maybe one time I heard like there was a virus on an iPhone or something. I maybe one time in my whole life. Like Apple's the one of the biggest computers, I mean they make the most computers, phones. I never hear anything about any attacks on Apple stuff. What the hell? Right? I you know, that's bizarre, right? I think it would also make it more, I think it would also make it so open source was more popular. Because open source software, you would be like, well, if we get hacked, no one's liable but us because we used open source software. So it would create a premium on closed source proprietary software because the proprietary software would come with a small, like, if you're hacked, we're on the hook hook for a fifth of it. And so there'd be a lot more secure proprietary software and you'd be willing to pay that premium to like have that, you know, security. But if you were just like, ah, we'll just use open source. But right now, open source is more secure than Microsoft. Like if you just use Linux, it's more secure.

SPEAKER_01

If you're you're saying I feel like I'd be less likely to use open source because right, right.

SPEAKER_03

That if we if we put this rule in place, though, like if we said

Cyber Police For Domestic And Foreign Attacks

SPEAKER_03

the software vendor had to pay a fraction, it has to be responsible, right?

SPEAKER_01

Then you're saying people will use less open source? Maybe, yeah.

SPEAKER_03

They'd be like, oh, open source is more risky because we have to cover the whole cost of security. We'll use a proprietary system because we can be safer, right? Like, I mean, that should be the presumption, but it isn't. So what I'm saying basically, I think people might miss the forest for the tree here. My goal is Americans being safer, their privacy being better safe, their software being safer, their money being safer in their banks, the American, you know, government and your city being safer from attack. I'm saying, like, you know, we need to make things like safe for people. This would make human people way safer, and it would end the kind of revolving door, just like profit one hand paying the other hand, kind of corrupt what seems to be like just corrupt. Cybersecurity to me just seems like a corrupt system. That's what I've learned in my studies. I'm just saying this is corrupt and it shouldn't be this way. It should be organized so that there isn't this corruption anymore.

SPEAKER_01

Do like the big players hire their own cybersecurity firms to kind of like be like a private army or a private security force to watch their stuff or have their own security on in the individuals.

SPEAKER_03

Yeah, so you know, Google has a security branch that just does all of Google's security, you know, and that protects Google, and that's it. It's just like, you know, it's just like one of the buildings in the city has a really good security team that protects that building. Well, what about everybody else? You know, and like what about the minor companies like who don't maybe even have the money to spend on that security system? Like the government should provide a baseline level of security that makes everyone safe. Small businesses, people, mom and pop shops, new businesses, you know, private citizens. Everyone should be like safe, and that should be provided by the government. And it just isn't right now. It's crazy. It's totally wild west.

SPEAKER_01

Now, is this a thing that's happening more, do you think, with vibe coding, with people doing like using AI to code, which means it leaves more holes or gaps maybe in the code?

SPEAKER_03

That's a good point. Yeah, so definitely vibe coding stuff comes out pretty insecure usually. Well, I guess it's a mixed bag because AI is actually pretty good at if you say make this more secure, it'll do it. It'll just do it.

SPEAKER_00

Would you just have to do that?

SPEAKER_03

People just I mean, honestly, you can tell it make it more secure and it'll add a bunch of layers of, you know. I mean, you still have to think about like how could someone, you know, misuse this or hack this, but AI can at least put in some of the baseline defenses that'll protect against sort of standard attacks. So that's better than like a really junior engineer who doesn't know those things and like does stupid, insecure things. Like AI will follow the boilerplate per very well because it's good at sort of doing the boilerplate. It won't be able to do like custom stuff as well that really thinks about how human actors might try to hack it. But I would say, I would say the biggest thing is that another thing that these police forces can do is they can go domestically and hack things. And then if they get through, just report to the person, just send them an email and say, We hacked you guys.

SPEAKER_02

Here's your five vulnerabilities.

SPEAKER_03

You're gonna get this small fine. You know, we're fining you $2,000 if you don't have this all fixed in 30 days or whatever, you know what I mean? Oh, or whatever, you know, like, and that's a great thing that police is that's a great role for them is to be the hackers before the real hackers, right?

SPEAKER_01

Yeah, we we found an open window on your house, and we need to let you know you should close it before someone who really wants to get inside and take things exactly as well.

SPEAKER_03

Exactly. So that's a major role that this police force, FBI military, can do is they can be hacking preemptively. Pre-crime. This is the pre-crime unit of the minority report.

SPEAKER_01

Do they call that white hat hacking?

SPEAKER_03

Is that white hat hacking? Yeah, you could call it that. Or just that's just we're like hacking for the good cyber policing. Yeah, I mean white hat hacking. But I mean, white hat sounds like you're doing it just on your own. This is like you'd be paid, your job every day would be like, okay, we're gonna hack like we're gonna try to hack like 30 of the largest businesses in New York City because we're like New York State's cybersecurity team, you know, because we want we're gonna hack, we're gonna try to hack the hell out of these these companies because if we find any vulnerabilities, we're gonna report them directly to the companies and they're gonna fix them, you know. And if they don't fix them, we'll find them because those companies are stewards of their their customers' data. So it's like all coming back to protecting regular people.

SPEAKER_01

This is one of those classic situations where you would catch someone, like you catch a super talented hacker who messed up, and then you would offer them, you'd be like, either you're gonna go to jail for 3,000 years, or you're gonna come work for us and help catch other hackers, and then they have to be conflicted about like, oh man, I'm working for the government, but also I get to hack, but it's not as you know, is it does it lose its shine when it's just trapped on my ankle?

SPEAKER_03

You know, like they try, you know. Yeah, I mean, I think you would have a lot of that actually. I think you would have catch me if you can. You know, the police, these cyber police would catch hackers a lot, and then the hackers they'd be like, hey, plea deal, like come work for us for 10 years, you know. And then and then you'll get paid. We'll even pay you a good salary, but you're working for us now. And, you know, or whatever, 10 years, I don't know, five years, whatever it is, depends on what their crime was. And then the person could be like, Yeah, that's way better than jail. And then you just recruit all the hackers into your, you know, into the fold.

SPEAKER_01

It always feels like criminals are sort of a half a step ahead of the police when they when they're getting away with stuff. I mean, not dumb people who get caught immediately, but you know, like some people are like, We know what the police are gonna do, we'll plan for that. And it always seems like the piracy or the hackers or the the you know, the less legitimate side of internet has always been a half step or more ahead of like the legitimate side of the internet where they're like we're gonna stop you from copying this uh C D and then it's like no, it doesn't stop anything, or we're gonna stop you from downloading the thing, it doesn't stop anything. So is this is this a case do you think where it might be a few cops chasing people like you're in a car trying to chase someone who's in a souped-up sports car who's just gonna be able to run circles around you because they have the better equipment and they have the better funding and they're more nimble and they are not held by the rules or whatever.

SPEAKER_03

Yeah, I mean uh attackers are constantly probing, but that's why if you have this like cyber police force, part of their job needs to be constantly probing too, right? So you want to pay the the cyber police force to be hacking all the time better than the the the you know the criminal hackers. I also think that if you put in place the other rules, you know, where like software vendors couldn't sell security services and software vendors were liable for hacks, I don't think there'd be very many hacks anymore. Like honestly, I don't think many of them would exist. And when they did, it would be, I think, a lot of like open source would become more vulnerable. And then people might just move off open source more or more open source might get taken over by closed source. Like there could be an open source module, and then maybe a closed source company just clones it and says, here's our version of it, you can use that, and now you have it's under our like protection. We confirm that it's secure, and people might be like, I'm just gonna use the proprietary one. I have to pay a you know a nickel every month or whatever, but I'm gonna use the proprietary one. Who knows? But you would have more secure software because there would be more liability on the vendor to make their software secure, and that just means they're gonna say, Did we do a security review on this? And it won't be, oh yeah, we did one. It'll be like, no, like, did we truly do a security review? You know, and often also software can just be simpler. Like Microsoft is this massive, cluesy, overly engineered, overcomplex, a million different things here and there and everywhere.

SPEAKER_02

It's like just make simpler software. It's you know, it takes more time, but guess what? It's more secure.

SPEAKER_03

Just do it, you know. So that would make it so that the pol the jobs of the cyber police would be a lot easier.

SPEAKER_01

I think it works. Yeah. Because I mean, if you build a like you're saying, more simplistic thing, fewer fewer rooms means fewer doors. That's just easier to secure instead of all these random hallways out of nowhere.

SPEAKER_03

Fewer doors. That's right. I mean, you can build a building to be more secure, right?

SPEAKER_01

You know, yeah, you can I mean a panic room

Ban Vendor Security Upsells

SPEAKER_01

is just a concrete box, it's the simplest and most secure thing. I mean, it's a vault, essentially, a vault for people or whatever.

SPEAKER_03

Yeah, and you can double it as a sauna if you put a heater in there and a vent. Ooh. Yeah, panic room sauna, sauna panic room.

SPEAKER_01

Come into my panic sauna. It's panic sauna. Oh no, we're being attacked. Quick into the panic sauna.

SPEAKER_02

Don't go in there. I have it at 115 degrees.

SPEAKER_01

Ah no, it's so hot in here. We'll never survive. The panic room makes you panic less. I didn't understand. We really need to have a dis uh a label distinguishing.

SPEAKER_03

Maybe you can have like a panic mode where when you hit it, it like vents the heat of the room right away. So it it quickly cools down to like 85 degrees. So you're still sweating, but you know, it's not like 110 or whatever.

SPEAKER_01

And if you're stuck in a panic sauna, you probably are being attacked from the outside. So it it launches those hot coals out at your attackers sort of kind of as an offensive to get them out. Isn't that how a sauna works?

SPEAKER_02

You have yeah, it can vent like hot jets of air. Yeah, you have coal. It becomes like a weapon, too. That's good. I like almost like a home alone style.

SPEAKER_01

Perfect. Home alone is a home type of home security system. I would talk security, be a designer of home security.

SPEAKER_03

It should really be home alone, right?

SPEAKER_01

That's our model for home security. That that would be my cybersecurity model, too. I would be like, all right, so if you try to enter the wrong password, then you're gonna step on these really sharp sharp Christmas ornaments.

SPEAKER_02

Paint can falls down.

SPEAKER_03

Paint can swinging paint cans is underutilized in security, cybersecurity, especially. We got to get more swinging paint cans.

SPEAKER_01

We need more pendulum-based security measures. I mean, that's the problem with cannons. You shoot them once, it's gone. You can the end of that cannonball, you could pull it back.

SPEAKER_03

You could just reel it back in, shoot it again. It's like a pop gun. Exactly like a pop gun. Yeah, anyways, I felt like I was taking stupid pills all through or crazy pills. I was just like, I was just like kind of like listening and like reading, you know, doing all my readings, doing all my writings, thinking about it. I read like, I would like Google around, talk to AI, you know. I'd like try, I'm really trying to like understand cybersecurity. And I learned about the policies and the standards. There's all these like standards and policies, blah, blah, blah. And that's all fine. I'm not saying like that's bad or broken. It just seemed like, and then it finally clicked, like, oh my God, you guys built a city with no police force, like, or or no barely a police force, you know. Right. And of course, there's like a ton of crime. It's like, what the fuck? Of course, you know, the incentives are all wrong, and you don't have the right people in charge. Like, you don't have like a monopolist on violence, right? Like it makes like society is good to have like, you know, I mean, police force, you know, people can complain about police forces, but like if you don't have police, things are way worse.

SPEAKER_01

You know, you don't want people to feel like it's free for all and that there's no consequences to their actions because then you have chaos and lots of bad actors, you know.

SPEAKER_03

But so I also think cyber police are like they're like I think they're pretty banal. They're like nerds, you know, hacking things. Occasionally they have to like send in the the enforcers with like, you know, windbreakers and like, you know, to like go like smash the computers of like if they find like the actual location of the bad hackers, then yeah, then they have to like send enforcers.

SPEAKER_01

But most of it is like nerds with like what they have like thick dudes who go in with baseball bats and just start smashing.

SPEAKER_03

Well, the FBI does that too, when they discover some major, you know, someone's doing fraud on the internet and and they and they're doing some kind of you know wire fraud or some kind of fraud. You know, guys show up at your door and knock on there and knock nicely or break down your door and say, Yeah, all these computers are like evidence, and then you're never seeing those computers again. You know, they're gone. So, so I mean you need some enforcers, but most of the work is done just in like, you know, in offices where they're like, I've got to hack these like five businesses today, and they hack them and they say, Oh, I didn't find any vulnerabilities. Probably you find some. I gotta send these fines out, you know. Okay, you got to do these things. I'll check back in 30 days. It needs to all be fixed. And if it's not, then you get a fine, you know, like that would be great. That would be like a major improvement. The businesses wouldn't like it because they'd be like, ah, God, we got to fix all these things. But you know, that could be another thing the vendors could offer, right? So software vendors could be like, hey, if you get hacked by the government, like by these white hat cyber police, we'll cover it if you pay us this like premium or whatever. We'll cover it like an insurance policy. That's not security services, that's like further, you know, further saying how much we trust our own software to protect you. And then that makes the business want to spend even more time and money making sure their software is totally patched and secure and and unhackable, so they can make a profit on selling that like insurance policy against, you know, fines from the government. So there's just a way to do this, like a sensible people would do it. And then there's the way we are doing it now, and it's crazy. I mean, I guess this is just America for like everything, right? Everything we do in America is just like the wrong way to do that.

SPEAKER_01

We do seem to take a peculiar, non-optimal stance every single time.

SPEAKER_03

It's like 15 years ago, we knew climate change was like a major problem, and we ran out of oil, and the oil price spiked really high. And we were like, well, we're a very rich country, we could spend trillions of dollars switching to green energy, or we could spend trillions of dollars inventing and deploying fracking. Yeah, and we were like, fracking,

Make Software Makers Share Hack Costs

SPEAKER_03

it's like cash.

SPEAKER_01

You gotta get those oil crumbs, they're oil crumbs, we gotta just get them out. Yeah, get those oil crumbs. It's insane. So, what would we need to do to make this change? Is this I mean, it doesn't sound like you would need to add funding so much as maybe reallocate it or try to like uh reprioritize where the cybersecurity force is on the like pecking order of like who gets the the funnel of cash? How does it flow down to these people?

SPEAKER_03

Yeah, I mean, I think um, you know, with police, I mean you could try to say we're gonna like we're gonna reallocate police budgets to this or FBI budgets away from other things, I guess, but you might just need to add more. I mean, this would be a case where I don't mind just adding more FBI and Yeah, you might say, like, I think Obama was pretty smart. Like he said, we don't have the budgets for horses and cannons has gone down to zero, right? Like over time, the military's budget should like you know, should change to adapt to the present threat landscape. So the idea that I think I think it was like Romney said, Oh, while you were president, you defunded like an aircraft carrier and this other submarine and this other, you know, fighter pilots. And Obama was like, Yeah, like you have to shift the military to be more effective, you know. So I think you probably could do that. You could be like, well, what where do we actually get more bang for our buck right now? Is it is it another aircraft carrier? Do we need nine aircraft carriers? You know, can we have eight and then use like the whatever how many tens of billions of dollars it costs to man an aircraft carrier? Could we use that? And you can probably sell the aircraft carrier to like Australia or something, and then you know, and then use that money for cybersecurity, probably a good idea. That's what I would do if I were president.

SPEAKER_01

Yeah, I mean, it feels like there uh there would be ways to just funnel it. That would be I I think that might be an easier ask than well. I mean, whenever they ask to do budgets, people pitch a fit about it and they it doesn't really seem to matter. They just increase the defense budget anyway. But yeah, don't give me a lot of it. I don't know. It seems like an easier sell because it's already such a giant chunk of the national.

SPEAKER_03

Yeah. And you know, I think there'd be this like synergy with tech in America, right? Like tech, I mean, America's like you know, we we're the leaders in tech in the world. Well, it'd be nice to have a big, like a somewhat representative private sector tech community that you know would be an interface with tech and be policing tech too. So like if we were like, hey, we need to ask these social networks, we could ask the cyber police to like police the social networks, right? Like if social networks were doing things that were dangerous to children or dangerous to the elections, which we know they are, but there's no police force that's prepared to police these social networks. Well, we would have a police force now that could do that, and so there's there's a there's a lot of things that these cyber police could do, not just stopping hackers, they could also do things like protect teenagers online or you know, protect children online, or protect elderly people online from not just criminals, but the corporations who are you know doing things to take their money or steal from them or confuse them.

SPEAKER_01

Yeah. Do some class action stuff for the good of the citizens. That would be nice.

SPEAKER_03

Yeah. Like, why did it take like private whistleblower, like whistleblower employees and private citizens to bring all this stuff forward that, you know, for for decades Facebook has known that they've been hurting teenagers. Like the cyber police would have figured that out in like a few years, right? I mean, they would have been like, oh shit, like, you know, there's all these people that send us in complaints to us because right where are you gonna send a complaint today? There is no police force to send a complaint about the misuse of tech, right? And the harming your children. You're gonna send it to your local police force. Hey, uh, officer Oli, uh, you know, this thing you can't understand, TikTok. The TikToks is uh, you know, my my daughter is bulimic, and I think it's because of the TikToks. Officer Oli doesn't know what the hell to do with that, right? Like, but a cyber police force. Yeah, the cyber police force might say, you know, we, you know, one complaint like that came in, they might be like, we don't know about that. But if 5,000 come in in a month, they'd be like, we're taking Facebook down. Like, we're gonna go get those guys, right? Because it's you know, it becomes like a it becomes like a police action, you know, rather than this like thing that takes decades, and at the end of the day, it's this whole like victim story of like, oh, these people were taken advantage of by Facebook. It's like, no, the a police force should catch this way earlier on and go after them, you know. Anyways, so cybersecurity is completely stupid. It's not completely stupid. I shouldn't say that. It it's but it's we are fundamentally, it's what it sounds like. Yeah, it's a new thing. We're learning how to do it. It's relatively new. I mean, only been doing it for 30, 40 years, you know. And uh, you know, but we have some major improvements that we could do. And these are things progressives could propose. Like Rokana, Rokana is the congressman from Silicon Valley. He could say, I am adding an amendment to the military budget for this year, and it's to add, you know, $100 million for greater cybersecurity, this, or you know,

Proactive White Hat Audits And AI Code

SPEAKER_03

some kind of increase to cybersecurity for FBI, and he could make this whole case. And it could be a very part, you know, it could be even a bipartisan thing. I think I think Republicans would be a because Republicans like like privacy and they like police forces, they like you've spending money on the military and police. It's true. You know, I I think you could find common ground to make this and it would make Americans safer. Effort. Yeah. Cool. Well, I like it. Takeaway from cybersecurity. That's not what I did my final project on.

SPEAKER_01

I did also say, when do you officially become a master of cybersecurity?

SPEAKER_03

Uh, I think like in a week or two, two weeks. Oh, okay. I'm right at the tail end.

SPEAKER_01

Like right bab basically when this is published, the final project would be the thing.

SPEAKER_03

Hey, I should have a little graduation hat.

SPEAKER_02

Yeah.

SPEAKER_01

You get your black hoodie, I suppose.

SPEAKER_03

Is that is that the I did not get a black hoodie. I'm like yellow hoodie. I'm like big.

SPEAKER_01

Okay, I thought graduating. Yeah. I guess there's levels.

SPEAKER_03

There are well, we just did so little of that. On that end of it.

SPEAKER_01

Yeah. Well, that's cool. Are you going to continue cybersecurity stuff, or do you see yourself turning to a new interest?

SPEAKER_03

Well, I'm just focusing on Elton University now, the whole pretty much uh oh yeah. Yeah, focusing a lot on that. Um, I got the team. Is it gonna be secure?

SPEAKER_01

Cybersecure University?

SPEAKER_03

Yeah, I mean Elton's very secure because it's it's so we use just like we use like pretty simple software and we don't have a lot of secure data. Like we don't have like credit card data or something like yeah. We just have like some student data about like what they learned. It's not very valuable, you know. But we take it seriously, you know. I take it seriously, I make everything really secure.

SPEAKER_01

Oh, we we rated uh Elton's servers, and now we got all this knowledge, we're gonna sell the knowledge on the dark web.

SPEAKER_03

I like built our whole thing and then I it was already secure, and then I went in with like clawed code and I was like, make this more secure, and it it made it like a little more, it was already very secure, but it like patched up, you know, fixed a few things and nice. Yeah, so I I'm not I'm not worried about Elton at all. But if you have something like really valuable, like Equifax, like Equifax was hacked a few years ago. Equifax. I mean, they have all the credit data, they have all the social security numbers, they have all the data of millions and millions, hundreds of millions of people. It's like this is crazy, you know.

SPEAKER_01

These guys need to, you know, go to them. And and they are not, you know, they just go oops and send out an email saying, Yeah, they pay, they pay some I think they have to pay some money, but but everyone else who's compromised, you know, has to kind of guard their own.

SPEAKER_03

And also Equifax didn't make their software. I mean, their software is hosted on, you know, and made with I think those vendors need to pay some of that. You know, it shouldn't just be Equifax, and that's where then the vendors would get way more secure. Um Yeah, it's it's crazy that this I'm not I'm not like people. A lot of people think like the sky's falling, like quantum computing is gonna just like destroy all encryption and quantum computing is gonna destroy Bitcoin. I hope it does, but I don't know, maybe it won't, maybe it will.

SPEAKER_01

People think uh, you know, they think AI is gonna become like super hackers and wait, how did how would quantum computing destroy uh what was the first thing you said? All encryption? Yeah, encryption. I guess just because it can try it so fast.

SPEAKER_03

Yeah, you could just try like 50 trillion different passwords and just hack it because it can do it in like whatever hours or something.

SPEAKER_01

Then how does it how would it destroy Bitcoin?

SPEAKER_03

Bitcoin's just an encrypted ledger. The only reason it's has any integrity is because it's encrypted in a very specific way, and every future transaction is like encrypted in that same way, and that's how you confirm that that transaction is accurate. So if you had a supercomputer that could just decrypt anything, you could just destroy but that like tomorrow you could just say I transfer all crypto all Bitcoin to one address, and then I oops, now I have all the crypto, and no one could no one could go against it. Gotcha because you would have hacked it. So yeah, so it could destroy. I'm not like a sky is falling person. I'm more just like we should make things better, piecemeal. And these are some good solutions for how to make cybersecurity just better so that Americans, you know, in general, would be more secure.

SPEAKER_01

I mean, it's it's constantly an iterative process, right? Like you do a little thing to make it more secure, the attackers do a little thing to make it more vulnerable. It's back and forth, but it's like playing a game of chess, you know. You just have to stay in the advantaged place.

SPEAKER_03

It is that way now, but I really think we could get to a place where it was just not like that. Like where it was just like nope, it's just secure.

SPEAKER_01

You're just like wolves live outside the city now. That's just how it is. They don't wander in the street. Exactly.

SPEAKER_03

Like I think we play it like that because that makes more money for software vendors and security companies and you know, powerful software companies that can defend themselves,

Policing Social Platforms And Protecting Kids

SPEAKER_03

those people benefit more from the current system we have. The system where everyone's safe benefits everyone. And those powerful players actually prefer to have everyone else be vulnerable to attack and have them be secure, right? And be selling the security services to the more vulnerable. Like they prefer that, right? Just like if you didn't have police forces, the security system companies and the security guard companies would not want the citizens to get together and make a police force because they would make less money, right? Yeah. Uh but the citizens would be stupid not to do that. Like, that would be so stupid to have a city with no police. Everyone can agree to that. I mean, everyone, most people, some people don't like the police in principle and they wouldn't agree with that. But I mean, you know, normal people are like, yeah, I got you know, someone starts beating me up, I'm gonna still call the police part of it. And have the police come and save me from the guy beating me up, right?

SPEAKER_01

Right.

SPEAKER_03

Anyways, that's the solution for today.

SPEAKER_01

We can see solved cybersecurity. It's over, it's done. This gives me an idea for my next business because I'll be I'm selling cannons to all these companies now for their for their pancreas. Then then I come back and I sell the cannon-proof vests.

SPEAKER_03

Oh, that's where the real money is both sides.

SPEAKER_01

Because I'm like, yo, everyone out here has cannons now. You're gonna need a cannon-proof vest if you wanna if you want to feel safe walking.

SPEAKER_03

You know, if you sell that to uh pirates, you know what you could call it? What's that? Kevlar. God, it's awful. Nice. Yeah, I like it. Yeah, well, they have cannons, right? Pirates.

SPEAKER_01

They they are the probably the number one users of cannons. That's why they need Kevlar. Yar.

SPEAKER_03

Yar. Yar.

SPEAKER_01

Well, thank you, Adam. That's a great solution. I love it.

SPEAKER_03

Yeah, I'm glad to share what I learned. One thing that I learned through all that cybersecurity. Maybe I'll share this with my colleagues in the class. Maybe they'll have a little discussion about it.

SPEAKER_01

Do you think the problem can we call the problem cyber insecurity now?

SPEAKER_03

Like everyone shift to someone feels like cyber insecure. Yeah, if someone feels that way, though. Like I just feel a little cyber insecure. My passwords are all password one, two, three.

SPEAKER_02

I feel vulnerable to my system. Yeah, vulnerable. My system is vulnerable.

SPEAKER_03

My cyber insecurity. I've been talking to my therapist a lot about my cyber insecurity. Yeah.

SPEAKER_01

I have a lot of exploits that I think are really being taken advantage of. And this is just my cyber insecurities speaking.

SPEAKER_02

Those are just your cyber insecurities talking, Betsy.

SPEAKER_01

Don't you mom, don't you talk about my cyber insecurities?

SPEAKER_02

Just act confident, okay?

SPEAKER_01

You have no idea what it's like. You don't know what this is like. Sure, it's easy for you. It's easy for you, Adeline.

SPEAKER_02

You're incredibly secure on cyberspace. I see your passwords.

SPEAKER_01

But not me. It's hard. It's not natural. I'm not a natural cyber like you are.

SPEAKER_03

You've you've air gapped your servers and distributed your systems, and you have 32 characters passwords.

SPEAKER_02

Adeline? Of course you're secure.

SPEAKER_03

Alright, everyone, tune in next time. We'll be back with another solution that will knock your socks off. Absolutely. Thanks again. Same solution time, same solution channel.

Wrap Up Jokes Graduation And Subscribe

SPEAKER_03

As per usual. And uh subscribe, like, comment, engage. Tell somebody about solutions of the multiverse. Share, share. Your favorite solution. Do all the things, do the things. That's how we grow. That's how more people hear about these unheard of solutions. Unheard of no more. Soon there will be heard of solutions. One by one, we're hearing them out. That's right. That's right. I love it. I think we're gonna do a rewind episode, Scott. We gotta rewind to some of our bangers. Okay. I think for video. Then we can get them on video because they're just bangers from two years ago.

SPEAKER_01

Because there will be new information and new new. I know, there'll be updates.

SPEAKER_03

Okay, we'll do it. Alright. Alright, take care, Scott. Take care, everyone. See you next time. Bye bye.

unknown

Bye.

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.