TRANSCRIPT · CC BY 3.0

DEF CON 30 - A Policy Fireside Chat with Jay Healey

DEFCONConference · Published · 44 min · English · License: CC BY 3.0 · Source: watch on YouTube

Transcript source: creator-uploaded captions on YouTube, unedited. Paragraph breaks and timestamps added by Vidleaf.

[0:00] - We'd like to welcome Jay Healey from the CFP team, and then Fahmida. Welcome to DEF CON. They'll be giving a fireside talk. Please watch your schedules and you'll see the latest information on the Hacker Tracker app. So if you're following which times and rooms you'd like to see, that's the best place to find your updated information. So please give a warm welcome to our panelists. (audience applauding) - [Jay] Fahmida.

[0:33] Yeah. - Thank you for the reminder, Jay. (Jay and Fahmida laugh) Hi, I'm Fahmida Rashid, I'm managing editor of features at Dark Reading, and I am so excited to get a chance to... - [Jay] Yeah, I don't think we have audio for Fahmida? - Or should I just use? Okay. Hi, is this better? There we go. - Yay! - I hear myself now. - Hacking! (Fahmida laughs) - So I'm Fahmida Rashid, I'm the managing editor at Dark Reading, and it is my pleasure to be here at DEF CON to speak with Jay Healey.

[1:09] We're gonna be talking a little bit about the past, present, and the future of info sec, hacking, policy, we're gonna be touching on a lot of different topics. So Jay, thank you so much for joining me today. - Thanks, thanks Fahmida, excited. - Yeah. So I think one of the things that I was hearing is, this is DEF CON 30, but I think you mentioned to me it's also the 50th anniversary of the realization - Yeah. - that hackers will almost always succeed. - Yeah. - So what did that tell you? How did that make you feel?

[1:40] - Yeah, let me push that back on what led to that question. Are we, thank you for those that are giving me the universal sign of, are we doing any better on this one? Okay. - [Staff] Get the mic up to your mouth. - Check one, check two. I was just on this. Check one, check two, test, I'm wearing pants and a shirt. - No, it's not. - Check one, check two. Yes, thank you. We have connected.

[2:12] Great to hear you, or great that you can hear me. So Fahmida's intro, she was talking about how we haven't done as much as we want to as a community. This is DEF CON 30, right? If we look at why a lot of hackers do what we do, right, a lot of it is for curiosity, a lot of it is because we're driven to do so, but a lot of it is to make things better. We're doing this for a purpose, many of us. And I came across this quote that said, "Few, if any, contemporary computer security controls can stop a dedicated red team from easily accessing any information sought."

[2:59] So it's saying the red team is going to get through, right? The hacker is going to get through, the attacker has the advantage. That quote was from 1979. And I found actual quotes that go back to 1972 that say the red team's gonna get through. So, all right. So if we're doing this to try and make things better, it's failing. Using the normal way we go about things. And that's why I'm glad to see everyone here in policy.

[3:30] That's a lot of what we're trying to get done with policy, is to say, all right, the normal things, like hacking things and telling people about it, isn't leading to the success at scale that we wanted, 'cause the attackers, if anything, are just getting better and better. And if you heard, Chris Inglis and others talked about this in this room. And so just think of that, since 1972, right, think about all of the patents, all of the hundreds of billions of dollars, all the worked weekends, all the missed kids' birthdays that we, a community, have done in 50 years.

[4:08] And we haven't changed the most fundamental dynamic, 'cause things aren't better now. - I mean, I'm thinking back, and like you said, it's like all those work weekends, we're thinking, "Hey, what is the purpose of all of this?" So it does get a little bit disheartening. - Yeah, and a lot of the mindset from this community over the last 30 years, I've started, I've been coming since DEF CON 9, I've been on the CFP review board for the last six or seven years, is that if we fuck things up, right?

[4:44] If we hack the planet, it's gonna be better, and it's not working that way. We're hacking stuff and it's not getting better, at least at the speed and scale that we want. If anyone heard Dark Tangent in here this morning, he was talking about how it worked for the Election Village. So we can do better, right? We can make it so that when we break things, it really is gonna lead to better outcomes on the other side. - So, I mean, before we even start figuring out, okay, what are we gonna do differently?

[5:14] Why don't we just kind of go back a little bit. What was the early days of hacking like? I mean, I know some of us have been around, but I know not all of us have been around for that, so what was that like? - Yeah, it's. So I don't have the hacking chops of a lot of the others on the CFP board. I'm there to help out on the policy talks. But it's really interesting to see how DEF CON has been changing as part of that, right?

[5:46] When we started off, you know, the early years at Alexis Park, right? It was about shenanigans. There was cool hacks. There was fucking stuff up and doing cool hacks. One of my buddies, he said to me one morning, "Oh God, how drunk was I last night?" "Oh man, I don't know, like I didn't think you were that drunk. What happened?" "Oh, I found an ATM receipt in my pocket from the Alexis Park." That was considered the height of the stupid thing you could do, is actually using the ATM at the Alexis Park, 'cause it was the most hacked ATM in Las Vegas, and probably the world, and DEF CON was absolutely 100% a hacking conference for hackers.

[6:32] And it still substantially is now, but if anyone heard Jeff here today, I'm sorry, Dark Tangent, especially after Snowden and after Stuxnet, DT disinvited feds coming to the conference. He said, "You are no longer welcome in our conference. We need some time away." And that was around DEF CON, anyone remember that? That was around DEF CON 22? - 22. - Something like that?

[7:05] And just look at how different it is today, right? Not only have we repaired that rift for now, but Jeff has said, DT has said, we need to do better. We're not making a difference as a community of hackers just on our own, but we need to better integrate with the policy makers, not just in the United States, but across the world, so we have an actual policy track to try and make more difference. This is still a hacker conference, but I think you're seeing that commitment at DT that we need to start doing better.

[7:37] We need to start getting defense better than offense. - I think that's actually the more positive aspect that we've seen. Like hackers have always been a little bit on the outskirts, a little bit doing their own thing. But now with policy involvement, we're seeing a little bit more, not necessarily mainstream, but the idea that our ideas matter. So what have you seen in the past few years where you were seeing these kind of solicitation of ideas from the hacker community?

[8:09] - Yeah, and first I have to say, I'm speaking in my personal capacity right now, not with any of my affiliations. And we're starting to see a lot more ways that hackers can get involved. Just that you're here, that we have a policy track here. We heard some great ideas this morning. We had a panel and a lot of folks that are involved in the Policy Village, and some really great ideas came outta that. We heard from Mosfet, who's a fabulous hacker, and she went to Congress.

[8:40] She was part of TechCongress fellow that went to help members of Congress and their staff learn to do better, to have better laws. We had Monica Ruiz here, who was helping out, I think, something called Digital Peace Now, which is a global youth movement to say we're tired of nation states hacking, and everybody else having to pay the penalty, and so what can we do to try and to help make governments more responsible?

[9:14] And they're really well meaning. Is anyone with Digital Peace Now? Anyone signed up to Digital Peace Now? Super well meaning, but they don't understand the tech as well as they might. And so if that sounds like it's something that's of interest to you, they can really use your help in whatever country you're in. Like checking with your city council. There are people there that need your help as a hacker to say, "Good, yes, I need help. I need some advice on how we can do better." Whether that's at your village, your city, your state, your region, whatever those are.

[9:49] We had Jack Cable here this morning who was around, he got involved in Hack the Pentagon, the first bug bounty program against the Department of Defense. That's how he got his start, was finding these bugs in the Pentagon, and then moving on, and then he switched to a job in government to help do things like improve election security in the United States. And he did that 'cause he got in through the front door, in just doing a bug bounty program. So that's a U.S. example, but we're starting to see these "hack the blank" come up in all sorts of country.

[10:27] And the last one I'll mention is the United States Government, as well as other governments, when they're coming out with a new rule, they'll ask for input. So we heard this morning, Harley, who's a former congressional staffer, said, "Look, the FTC is coming out with a new rulemaking on what cybersecurity should be to help protect consumers." That so fits into the kinds of things that we're doing. And rulemaking, it sounds boring, but it's how big things change over time.

[10:59] Not just in the United States, but in other places. So whatever your context is, however it is that's interesting to you, take a look at these things, right? Beau Woods runs I Am the Cavalry with Josh Corman and others. And so take a look at I Am the Calvary. They did this probably, what, how long is it? Six years, maybe? Seven years? - A little bit longer. I mean, - Yeah. - they were around for at least four or five years before all the stuff locked down. - Oh wow, okay.

[11:29] And the message from I Am the Calvary is we can't just hack stuff and wait for someone else to own the responsibility of it. That if you hack something, you're responsible for the result, whether it gets fixed or not. So the name came from the cavalry's not coming, right? There are no adults that are going to come by and say, "Thank you for calling our attention to that. We got it from here." It is not gonna happen. Or at least it hasn't been happening.

[12:00] We're trying to do better. So this whole movement of I Am the Cavalry was to help hackers own up to that moment of good. How can we do better? How can we own the results? Not just for fucking things, but for unfucking them as well, and making sure that they stay unfucked. Technical term. - I think that's actually, when we were talking about all of this and as you were saying this, I'm thinking that is the biggest difference, I think, the early days of hacking and now, there's a little bit of accountability.

[12:31] The hackers are like, yeah, I'm doing all this cool stuff, but let me tell you how to fix it. Or even if I don't know how to fix it, give me someone who can sit down with me and fix it. And that level of accountability is, I think, one of the more positive aspects of what we've done. - I had a real tough moment after, it was probably around DEF CON 22, 'cause anyone, anyone involved with NSA tool set and the folks that would come in doing the talks on NSA tool set? Not if you were actually doing NSA tool set, don't put up your hand.

[13:01] And it was after Snowden revelations, and it was a set of fabulous security researchers that said, "We wanna make... We wanna look at the stuff that Snowden revealed about what NSA was doing, and we wanna make it so easy," this was their words, "that a 10 year old girl could do it." Not sure why they had to gender that, but. And they were doing that for privacy. So their goal, I remember I was saying, they were hacking GSM encryption and they wanted to make hacking GSM so easy, and they were gonna do that for privacy.

[13:32] And I had real difficulty wrapping my head around that. It was a great talk. It was a great goal. But how long, especially back then, that process of we break things and then it will get fixed, it's not a direct causal relationship. Sorry, I'm an academic now. That's what we talk about, causal relationships. If you do something, are you expecting that it's actually gonna, what result does it actually get to? And so that's why I think we've done a lot better now in the community, of looking at that causal relationship.

[14:05] "Good, all right, if we break it, let's make sure it gets fixed." - And it's even just the fact that we have more of a structure, so that even if I can't make that, or I don't know who to, I now have sources to go to, we have bug bounty programs where they will say, "I'll help you make that connection." So I think we have more of an infrastructural support. - And I think the media, and I think the journalists are doing better too, right? - Thank you. - Yes. And if folks heard Jeff at DEF CON, I'm sorry, Black Hat, yesterday, introducing Kim Zetter, about how in the early days the journalists would just buzz in and buzz out and talk about the crazy hair and use the community for their purposes.

[14:50] Now you've got Dark Reading, you've got Kim Zetter, you've got so many other great journalists that are embedded in the community like yourself, deep tech chops in application security, and so help us to tell better stories, so that we get better change on the other side. - The one thing I wanted to actually touch upon, and you kind of hinted at it, I think a lot of the time when people hear, oh, hacking and policy, is, well, I'm not gonna run for office.

[15:22] I'm not a lawyer, so I don't know the laws. So you mentioned how working with the city council and stuff. How do you even start that language? How do you even get the folks in this room who are curious to understand that you don't need to be a legal expert to be involved in policies? - Right, they do that, right? They understand the legal side. They're curious about what you know, and so just have the conversation, right? I mean, for whatever level's comfortable for you, whatever path that you have is gonna be good.

[15:53] There's check out the stack for TechCongress and I Am the Cavalry. There's a lot of good material on this. If you've been out to BSides. BSides Las Vegas is usually a place where a lot of these folks are. If you go down to the policy track, look for Beau Woods, he's got the, he's got the, I think the hair's blue today? - I think so. - And just ask around there. There'll be a lot of folks that can help, not just have general ideas, but have been through it and helped others for whatever context you're bringing with.

[16:25] Just some other tips is one, trying at least, it's gonna take you a while to speak the language, but be forgiving of the language, right? Folks in policy, we say cyber a lot. If you can't forgive us that, (laughs) it's gonna have difficulty. If you wanna be understood, you have to help meet people halfway in how they talk about things. So on the policy side, attribution matters a lot to us, because at the end of the day, it's about what nation is responsible.

[16:55] I worked at the White House for a couple of years, right? I didn't care about attribution. I cared about national responsibility. At the end of the day, the president is gonna have to pick up the phone and he's gonna have to call some prime minister, some president and say, "Knock it off or there's gonna be consequences." That's not attribution. So that stuff matters at places like the White House and Congress or in your national equivalence. So again, if you can't get past the fact that, no, attribution's stupid, in your full Threatbutt and Attribution Dice, like that stuff's funny, and it might not matter much in your context, but it definitely matters when you're thinking about for some aspects of this national security policy.

[17:40] But definitely be yourself, right? If you're angry and you're pissed off, don't lose that. (laughs) Stay angry and stay pissed off. Just, let's keep it channeled and stay energized. - Yeah, I think we have a big problem sometimes when you get angry, when you are just annoyed, you're frustrated, you think, "Hey, nothing's ever gonna change," that we tend to get a little insular. So I think this track is the perfect way of explaining, don't become insular. - And within the course of one year, this was right around 2011, 2012, I had Jeff Moss, Dmitri Alperovitch, Richard Bejtlich, and others say we can't, we're frustrated 'cause we're not making the difference that we wanted to have through technology, but we don't know how to make this happen on policy.

[18:29] I was working for a think tank at the time, the Atlantic Council, sorry. So a lot of folks have been down this road of saying, I need to do differently, I need to figure out other ways to get my voice heard and to bring my knowledge and skills to bear. So this is well trod path. - We're talking a lot about how we are doing things differently now, but if you can even give me one example of something that we are doing better.

[19:00] I don't wanna be just doom and gloom saying we haven't done anything better. - So I consider myself a strategy person, right? It's been a long time since my fingers were on a keyboard in any meaningful way, or that'd be meaningful to y'all, remember the way I said it was went back to 1972, we're 50 years in where we haven't been having the effect that we want. And I was reading a news article maybe five years ago in "The Economist." And they looked at climate change and they said, "What have been the interventions that we have done as a species that's taken the most carbon dioxide equivalent outta the atmosphere?"

[19:40] And they rated them like 1 through 30. And they said, "As far as we can tell, no chuckleheads have ever asked the question in that way before." Here it is, one of the most compelling issues faced by humanity, and no one had ever said, "What have we done that's made the biggest difference at the largest scale and the least cost?" And so I had an epiphany of, (mimics explosion) so what is it that we as a community have done, that's given the defender the greatest advantage over attackers at the larger scale and the least cost?

[20:15] And let's do more of that. The number, any guesses, just shout out, the number one thing that we think we've done at scale and cost as a community? Windows Update, yeah, who said Windows Update? Absolutely. Because instead of doing something that only affects a single enterprise, we could come up with the most perfect widget and it gets all the VC money 'cause it is the most brilliant thing. We still have to buy a billion of them.

[20:46] We've gotta integrate it into the enterprise or our home networks. We have to monitor it. We have to keep it up to date. We have to train people to use the widget. We have to get it to integrate with all the goddamn other tools that we have and do that a billion times. Things like Windows Update, cloud, end-to-end encryption, you do it once and a billion devices or people can take advantage of it. This is why, especially a lot of us on policy are so upset over government folks looking to break end-to-end encryption.

[21:22] It's one of the few things that aids the defenders at scale, easily, if it's implemented right. It's really one of the few things that you can get it and it really makes it hard for adversaries. - And it's actually one of those things that we've seen really become mainstream, because it's become easier to use. Like the number of people I know who say, "Oh, I know nothing about security," and they use Signal, and I'm saying, "There you go! (Jay laughs) Like that right there is an important thing you're doing." - And if I could push on one area.

[21:53] So for me as some of that strategy, we've never had a real strategy. What was the U.S. strategy for the Cold War? It's a single word, containment. Sorry, I'm a veteran, you know, for folks that were in the military, everybody knew what General Petraeus's strategy was for winning. It was win hearts and minds. A different general would have a different strategy, like get in firefights and kill people. Petraeus was very simple. No, we wanna win hearts and minds, more or less.

[22:26] It's a strategy that you can fit on a single small sheet of paper, in this phrase. So mine, since I read that quote from 1972 and 1979, was defensible. We've gotta get defender most advantage over the attack at the largest scale and least cost. Sometimes I like to flip it around and talk about a sustainable internet. Just like we want our grandkids to have an internet, to have clean air and clean water, better than we have today, we can think about the same, right?

[23:00] Let's have our grandkids where they have an internet that's at least as awesome as the one that we have today. 'cause we can get so caught up in adversaries and the rest that we're not thinking about all the amazing things that we wanna do, and we want future generations to do. - Since we are talking about the future, and how we want the internet to be at least available for our grandkids, my children, but there's so many new types of technologies that's coming on. We are barely scratching the surface on understanding how we're gonna use it, how we're gonna regulate it.

[23:35] What are the policy implications that we should be thinking about with emerging tech? - Yeah, just think about, on emerging, because I know what I care about, a defensible internet that has defense better than offense, anytime I get asked about a new X, Y or Z, I always think about, all right, is this gonna preferentially aid the defender or the attacker? It, almost every time we've done anything, it's preferentially aided the attacker. That the attackers have been able to use the scale of the internet more effectively than the defenders have, to add scale to our operations and what we want to do.

[24:15] So anytime I get asked like quantum X, Y, or Z, or the rest, it's almost always, no, that's gonna help attackers more. Cloud, one of those that can definitely help, Beau Woods, Josh Corman, helped talk about it really well, that the original internet was never designed to be secure. We added things to it, and we just slapped Band-Aids on those. And now we've got five decades of Band-Aids all the way down when it comes to the security for the internet. Cloud is one of those opportunities that we can get it right from the start, once we get people trained for it.

[24:47] We really do have to have people more trained so that we're able to... - There's a definite mindset change that we need to make sure that people are not just bringing the same mistake, same ideas forward. - And before we switch, I know we're gonna probably switch to Q&A soon, we had a panel this morning and someone asked, "Who is your favorite trans or female hacker?" And we had a lot of great answers, a lot you'd expect from Grace Hopper to Katie Mou, to Amelia Koran and others.

[25:19] I wanna raise a woman named, her married name was Hilda Mathieu. Anyone heard of Hilda Mathieu? She's on the NSA Hall of Fame, because Hilda came up with the idea, back in the 80s, that NSA, that these new computer networks gave NSA this incredible ability to do amazing digital espionage. And she was doing this as a female technical engineer in the 80s.

[25:50] Just think of how rare that is. And she was the one that figured out, yep, we can, this is gonna be amazing, but she also realized this is gonna be a real problem for the United States, because we're incredibly vulnerable. So they were already understanding that at Fort Meade, in the 1980s. And what I really like about Hilda isn't just that she realized this and she was this real pioneering female engineer whom we've never heard about, but also her name before she got married was Faust.

[26:24] So here we've got this actual real Faustian bargain of wanting to both, NSA to have it both ways, and the U.S. Government to have it both ways, that we can hack shit and we can still secure things well enough. That we can hack it and the adversaries aren't gonna see what we're doing and decide they need to copy us. But also for us here in this room, and the people that have been coming to Vegas every August for 30 years, that we can hack shit and we don't have to worry about how it's going to turn out.

[27:03] It's the original Faustian bargain, (laughs) in part thanks to great engineers like Hilda Faust-Mathieu. - Exactly. So, I mean, we started off all of this conversation with you saying that we've been doing this over and over again, and nothing has changed. We are now talking about a strategy of defensibility. How are we going to change? What are the things that we can start saying, okay, these are the things we're gonna do so that we can get blue team better than the red?

[27:39] - I think you heard a lot of it here from Chris Inglis this morning, right? When I look at that question, so we've looked at, we did this report through the New York Cyber Task Force out of Columbia University, and we went back and we said, okay, what have been the actual innovations that have made the biggest difference at the largest scale and least cost over the last five decades, going back to the original passwords? And we looked at those that tend to operate inside the enterprise and those that operate across cyberspace as a whole.

[28:14] And the vast bulk of things I mentioned were up here in the technical things in the enterprise. So one, we really wanted to emphasize those things that we can get with the larger scale and the least cost. End-to-end encryption, cloud, we've already talked about. I also really want to emphasize the operational innovations. When the Morris Worm hit the early internet in 1988, it took down 10% of the early internet. Now, yeah, that was only like 6,000 computers or something like that, but it took down 10% of the internet, because they didn't have anybody that was there to look for vulnerabilities and patch them beforehand, and they didn't have any coordination mechanism once there was a disaster.

[28:56] The only coordination mechanism they had was the internet itself. So they invented a computer emergency response team. We had to invent a CERT. And now, of course, everybody has a CERT, they're considered part of the environment. We had to invent the role of a CISO, chief information security officer. Vladimir Levin, a Russian hacker, took Citibank for $15 million or so in 1995. And we had to invent a CISO. We had to invent a ISAC.

[29:29] I used to be the vice chairman of the FS-ISAC. We had to invent ISACs in 1999 by a presidential directive. The MITRE ATT&CK framework, Lockheed Martin Kill Chain. This stuff is, like the kill chain or the cyber framework, like, it's almost free, right? It's a doctrine. It's an idea about how you do things. And just think about all the defensive innovations that we've gotten from the MITRE ATT&CK framework, and how it's allowed us to talk about things at scale and implement things that sticks in taxi.

[30:04] So as you're thinking about how we can have the most impact at scale, it's not all about technology. It's a lot of these operational, these process, the organizational innovations. Actually, maybe like CISA, right, is now doing JCDC. - Yeah. - The Joint Cyber Defense Collaborative. - I mean, the thing that really strikes me about the CERT, ISAC, even the MITRE ATT&CK framework, it's actually fundamentally collaboration. It's like, okay, how do I work with you? I can't do this alone.

[30:35] I need to get other people with me. And what is the shared language? And I love the examples you gave, because it kind of goes back to what we were saying earlier, that we need to be working with the community. We need to be engaging with the community. - There there's a guy named Rob Knake who had been with the Council on Foreign Relations. Now he's the deputy for strategy at the Office of the National Cyber Director. And he had a great phrase to it. He called it the Home Depot model. (Fahmida laughs) You can do it, government can, - We all know the Home Depot, that's for sure.

[31:06] - You can do it, government can help. 'Cause when I looked at, how do you get defensible? It's not through government. We're not gonna get there by creating some new government office and hiring more civil servants in any country or in every country. It can help. But it's, the only real change to get defensible is gonna happen through the private sector. And that for the government, for me, is you have to enable them, right? Imagine, sorry to use a sports analogy, say it's American baseball, right?

[31:37] You've got nine players on the field. What we had with General Alexander when he was at Fort Meade, and he tried this here, well he tried it at Black Hat, right? He would run around and say, "Wherever the ball was hit, we got it. We at Fort Meade, we can make the play. Let government do this. Finance sector, y'all are doing a good job, but let me put my sensors on your network so we can collect it for you." But most of the time, whenever the balls hit, it's someone in the private sector that's in the position to make the play.

[32:09] Now, they might not be able to see the ball. They might have an old, and the government has to help them to see the ball. They might have a bad glove, and we might need to help them with some capability. They might be like me when I was in Little League, and they might forget they're in the game until they hear the crack of the ball on the bat, and they need to be reminded. Others don't need the enablement, they need encouragement. They know it's a problem. They've got the capability, but they're not stepping up.

[32:41] And their government has ways that can help. Not just U.S. Government, but others. And last is, at the end of the day, it might come down to enforcing where it already happens, the finance sector, energy sector, publicly traded companies. The enforcing is already happening in lots of regulated industries. And we first said in 1998, presidential directives that said that if the market doesn't work, we might need to regulate. And so it's been 25 years, so maybe we're getting close.

[33:11] - So one thing I wanna touch upon before we go to the audience questions is that there are a lot of people who can't get involved with Congress. They can't get involved with FTC. And I've been hearing a lot of friends who are lawyers, they talk about how they're required by their law firm to do pro bono work, kind of give back - Interesting. - to the community. What would that look like from a hacker community? - It's a great, wow. I hadn't really thought about it. It's a lovely, I love that idea.

[33:42] So imagine, for what Fahmida's raising here, right? If you're working, if you're a CEO of a tech company, and you care about these issues, say election security, or you're worried about the water, you know that your local water utility is probably insecure. Just like a law firm might do pro bono, you're saying that you might say, "Hey, you know what? We're gonna go and we're gonna help out the water utility. And we're gonna do that pro bono, 'cause we're a tech company."

[34:13] And you can imagine that working even not just for the CEO of a tech company, but it's anybody just saying, "Hey, I'm here to help." That's a great idea. - I mean, if you're an incident responder going up to, you know, hey journalists, human rights activists, and being like, "Hey, do you want us to take a look?" I just feel like there's so many ways we can use our skills. - And, you know, and it ties into a lot of corporations are worried about their ESG, right? Their environmental, social, and governance. And they wanna do well doing that. And companies wanna help on their ESG, and people will volunteer.

[34:46] So I worked for a bank, and we would go out and we would do Habitat for Humanity, or we'd clean a park, or we would go on a 5k fund run. Why shouldn't there be a tech aspect of that? And saying, "No, we're gonna get our awesome set of nerds together, and we're gonna go help people." Like a at risk community, like journalists, or Rohingya, or Uighurs. - Go to your local school and help your teachers. - (laughs) Go to school and help teachers. Yeah, it's a great idea to think about that as ESG, to think about that as pro bono work that we should do through our companies and get paid for it as part of making the world a better place.

[35:26] I love it, it's a great idea. - So there's, you have the microphone for the Q&A? So if you have any questions for Jason, please raise your hand, - Or Fahmida. - (laughs) and we welcome any questions here. I can barely see. - Got one. We have one over here. That's why I wear a hat. Yeah. - There's someone over there, and then a gentleman in blue. - [Staff] There you go.

[36:02] - [Audience Member] I mean, this kind of goes way back to the beginning of hacking and computer security. How do we still address the idea of what right do you have to check my doors? You know, if you walk down the neighborhood trying everybody's door, you're gonna get arrested. And there's that analogy to some of what's happening in the hacker community. How do we... Are we still struggling to justify that from a legal perspective and from an acceptance perspective? You know, who are you to check my doors? - Yeah. It's a great, and for those that didn't hear, who are you to check my doors, right?

[36:36] I mean, a lot of, and I think our communities had this from the very beginning. Who are you to tell me not to check your door? It's publicly available, why shouldn't I be able to scan it? I shouldn't even be able to get into your computer because you didn't protect it well enough. That's part of our legacy of being hackers and being in Vegas in this time of year, right? But also saying we also care about privacy and we want to do that. I liked how Chris Inglis put it together up here in that, at least how the government was seeing it, and saying we're all in it together, and just because your side of the boat has a leak, that's affecting the rest of us.

[37:14] And I honestly approached this. I talked about sustainability of how we want our kids and grandkids to have at least as good as we have today. And that's led to all sorts of norms and mindsets to think globally, act locally. But also knowing that the things that we do have externalities and that I can say, good, I have a right to use as much water I want, or I can have as polluting a company or car as I want. But the way I, speaking personally, I say it's kind of a dick move.

[37:48] Like yeah, you've got the right to do it, but you are imposing that on others, and you're making the situation worse for others. And so we are gonna have to think more about how that affects us, that good, your unpatched system. It's not just you getting hacked, but you're imposing that on others because you're gonna be part of a DDoS. And Inglis talks about this new social contract and what it is that we owe each other, what rights and responsibilities we can demand.

[38:18] But what are the concomitant responsibilities that we owe others? And I think it's a great part of that conversation. And for us to really address that afresh, 'cause that's what it's coming down to a lot. What are we owed? Even if we're having unpatched systems versus, you know, FBI going in and patching systems for them like they did for Cyclops Blink, right? Let's address it. I think it's a great question. - Or the, ISP basically saying, "I'm gonna scan and I'm gonna take your computer off the network because you have malware."

[38:52] - And it's a great, and I know they won't happen. I remember there's a great, it was a, or I think it was Arbor Networks did this. And they looked at ISPs of saying, which, and this maybe 10 years ago, ISPs do you monitor for inbound attacks? And like 90% looked for inbound attacks. And they said, "Do you monitor for outbound attacks?" And half of them didn't even bother to monitor for outbound attacks, and those that did, something like half of them did nothing about it. They would just see the attacks going outbound.

[39:23] They said, "Not my problem." What do we think about that? Is that, I mean, that's classic tragedy of the commons, that they either don't, half of the respondents back then didn't know or didn't care that they were imposing problems on others. That's externalities. And at the end of the day, that's where, in the normal social contract, we expect the government to come in and say, "No, you can't impose these costs on others through your own inaction." - Yeah, can we get the next question? - Yeah. - [Audience Member] Hey, good afternoon.

[39:54] So I have kind of an unpopular opinion here, so this might be agitating to some people, but I think one of the reasons why we have issues with policy , and that's really what the gist of this conversation was, is that a lot of people focus on the hackers, so people that are here. But if you actually look at when we actually were good at things like strategy, it was from offset strategies. We had a first offset strategy, nuclear. We had a second offset strategy, ISR. We tried getting a third offset strategy of technology.

[40:24] Ash Carter, Bob Work, and a few other people, Jim Baker, and a few other people that worked at the building were champions of this. And then it fell on its feet for whatever reason, because of a session, we'll just call it. So to me, the biggest problem that we have as a nation, 'cause I wanna take this beyond just the hacking, it's really about cybersecurity and how do you secure things. It's that we do not have a defined offset strategy. And from there that's where your operational tactic, your operations go and your tactics go.

[40:56] My question to you is will there ever be somebody that says "No shit, wake the fuck up and get an offset strategy." Over. - Yeah, cool. And this is probably gonna be the last question, unless you want to take one more and then I answer both? I don't know how we're doing on time - [Staff] Two minutes. - Yeah, you wanna take one more of the question and then we can, yeah. - So he had, the gentleman in the blue, - Awesome. do you still have a question? You're fine? Okay, and then I think the gentleman in the black with the orange lanyard, he was one of the first people to have his hands up. - Thanks, Mike, we'll catch up.

[41:32] - [Staff] We have two minutes left. Two minutes, no rush. - [Audience Member] (laughs) Thanks. Hey, Jason, very good talk as always. You referenced earlier about control effectiveness, that for nearly 50 years, we haven't really seen significant advancement in control effectiveness. I was curious if, especially from a policy standpoint, we can get firms to all agree to improve cyber hygiene, cyber control, capabilities, and effectiveness. How would you suggest measuring control effectiveness and thresholds for essentially defining good.

[42:07] - Perfect, thanks. So first, the first one is a very U.S. Department of Defense strategy. This thing's called the third offsets. And the offsets were a military strategy to say, what are the things that the United States and allies, that are super easy for the United States and our allies to do, but are really hard for our adversaries. I actually thought of it as an encryption problem, (laughs) right? 'Cause encryption is there. It's meant to be really easy one way and really difficult the other way. And it just took that to military strategy. And so we were trying this over the last couple years and people in D.C. would say, "Cyber is a way that we're gonna do this offset strategy."

[42:49] And I had no idea what they were talking about, 'cause it is just as easy, if not easier, for our adversaries to have offensive cyber capabilities as it is for us. What's really hard for them is to work with the private sector. When you look back at almost every major cyber incident that we've ever had, anywhere in the world, it's almost always the private sector that has the agility, the subject matter expertise, and they have their hands deep in cyberspace, and they can fix it. Governments lack that. So we need to do those things that the Russians, the Chinese, the Iranians can't do, is work with the private sector in the rich way that we do in the West.

[43:26] And then to close out on the measurement, it's a fabulous question. I'm really interested, not on a measuring control by control, but how do we measure if defense is getting better than offense at the largest scale of the internet? For example, if we're seeing shorter breakout times, we're probably not doing our job. If we see longer breakout times, if we see them taking longer to get in, those are all the sorts of things that we might imagine if the internet's getting more defensible. - That might have to be a conversation next year.

[43:57] - Yeah, exactly. (laughs) - Jay, thank you so much for joining us today. - Thank you. - And thank you everyone. Thank you for your good questions. - Yep. (audience applauds) Thanks for the questions. Thanks for caring about policy. Stay angry. Go unfuck things.

Open in the Vidleaf workbench

Search the transcript, select lines, copy quotes with timestamps, translate.

Open in the workbench →

Attribution

"DEF CON 30 - A Policy Fireside Chat with Jay Healey" by DEFCONConference (https://www.youtube.com/@defconconference), licensed under CC BY 3.0 (https://creativecommons.org/licenses/by/3.0/). Source video: https://www.youtube.com/watch?v=D_wPMLhXC1w. This page is a text transcript of the video with paragraph breaks and timestamps added; the creator is not affiliated with and does not endorse Vidleaf.

Are you the creator or a rights holder? Request a correction or removal: copyright@vidleaf.app (see About these pages).

Last updated