Following the cyberattacks in Minnesota, many have reached out regarding cyber threats from a national security perspective.
Most successful cyberattacks don’t target critical national infrastructure; they go after individual organizations. Thanks to the decentralized cybersecurity model adopted by the U.S., there is no single system an attacker can compromise to cripple the entire country.
Transcript
Hey, everybody. Peter Zeihan here come to you from the east, east, west, west side of Bison Peak. On my way down, I got buzzed while I was up here that there’s been a cyber attack in Minnesota effecting at least 30 different municipal districts. The information I have to work with is very limited. I have no bars up here.
Got garments to me. Anyway, I thought this would be a good time to talk about cyber because we’ve got the the background and we’ve got the teaser. So short version. This is not something I worry about in the traditional sense, not from a nation state point of view. It’s serious issue. Cyber has been becoming more and more of an issue because the tools that are necessary to do cyber attacks have proliferated massively.
And you can pick up basically a starter toolkit on the dark web for just a couple hundred dollars, and for a few thousand, you can get some really interesting tools. And people have been using those to hack whatever databases they can get into, whatever systems they can, and hold whatever hostage they can. Common attacks are ransomware, where basically you lock up somebody’s database and say, if you don’t pay me X by Y date, I’m just going to delete the whole thing.
And a lot of folks don’t have sufficient backups, so they really don’t have much of a choice to pay. And you can always tell if you’ve got somebody who’s dedicated to cyber defenses by who pays. Of course, anyone who pays has a vested interest in not telling anyone that they’ve paid, because that’ll tank their stock value or confidence in their institution or whatever it happens to be.
From what I understand, with Minnesota, that’s not in play. It doesn’t look like any services were interrupted. People are pointing their fingers at Iran because that’s the flavor of the month at the time. I have no way to say that it’s Iran or something else, but I do want to underline when it comes to national security issues, this is something that, while not minor, is not something that I kind of put in my top tier of concerns.
The reason is the combination of disassociation and concentration when it comes to cyber defense versus cyber offense. Back when computers became a thing back in the 1980s, we had Ronald Reagan and nobody knew what was going to happen with all of this. So there was no institution that kind of take responsibility. So Reagan’s decision was to make the National Security Agency, the NSA, responsible for cyber offense, and their job was to hack everybody all the time, put in backdoors, put in worms, whatever.
Working from the theory that if we ever get involved in a hot war, or if the other side does cyber against us in a way that kills people, we will have the option to go scorched earth. The idea being that the NSA’s would have access to as much as possible, and they could basically implode opposing systems from the inside so they would never carry data again.
Not just a hack, but a physical destruction of the hardware down at the node. But defense wasn’t touched because if you wanted to throw a cyber defense umbrella over the entire country, you would need a massive institution. And how would you determine where the line is? Is it the fortune ten companies?
The fortune 100, the fortune 500? The fortune 5000? Is it everything going down to the mom and pops? And remember mom and pop companies that have employees of 50 or less or half of the employment base? Do you deal with individuals in this way? Do you deal with universities? And rather than try to come up with a solution to that problem, Reagan just everyone else, you’re on your own.
So every government institution at the local, the state and the federal level, and every company, regardless of size and every individual, regardless of wealth, is responsible for their own cyber defense. You fast forward that to the 2020s, and what it means is the same ease in which people can get hacking tools is also available for people to get defense, and especially encryption tools, and off the shelf encryption tools that just cost like 2030 bucks can’t be hacked by anything shy of a semiconductor taking a couple of years, it doesn’t mean that you’re perfectly safe.
Human error is undoubtedly the way the most hackers get into systems, but it does mean at this moment, as long as you have a degree of awareness and put a little modicum of effort into it, the advantage really is for the defender. Will that always be the case? I have no idea that the semiconductor industry and software is evolving in very strange positions, and I can’t underline enough that most successful hacks get in because somebody has been sloppy or hasn’t changed their password, or lets them in because of a fishing attack.
These are all very real concerns, but what it means is, from my point of view, it is impossible for cyber attacks to take down the country because there’s no single defense. There’s no node that an enemy can hack into and take down the whole country, or take down all the power grids. We’ve got thousands of power grids and thousands of water districts across the country.
You have to hack each of them individually and then everyone around them. When they realize there’s a hack, they usually cut their connections. Part of the reason for that was because of, if you remember back to 2001, 2002, right after nine over 11, we had a power outage in the northeast and in eastern Canada because we had interconnections among our power grids.
Well, after that event, everybody basically built firewalls, and that worked not just to prevent cascading power failures, but it also worked to prevent cascading hack access. So anyone who wants to take down the United States has to hack literally tens of thousands, if not tens of millions of things to in order to do it. And even the Chinese, at their height before their demographic bomb went off, never had enough people to do that.
There’s an open question whether AI, as it evolves is going to be more effective as an offensive or a defensive capability. That is part of the handwringing around something called mythos, which is a new clod product that’s anthropic. It’s the company that generates clod because basically mythos is doesn’t have barriers and it hacks things, but it also figures out where the vulnerabilities are so that you can reverse patch everything to.
Bottom line is this is all evolving, but the physical structure that the United States has set into place often operations concentrated, defensive operations dispersed makes it very easy for individuals or individual companies to get hacked, but functionally impossible to do meaningful damage to the US structures even in a time of war. For what it’s worth, in the world these days, that passes as good news.






