Bruce Schneier, an esteemed technologist and security expert, returns to discuss pressing cybersecurity issues. He dives into the CrowdStrike incident, exploring the complex relationship between government regulation and tech accountability. The conversation highlights the need for transparency in electoral processes to restore public trust. Schneier also examines the interplay between artificial intelligence and democracy, advocating for ethical frameworks to safeguard election integrity. His insights echo the importance of corporate responsibility in today's digital landscape.
The podcast celebrates its 400th episode with a reflection on its journey and appreciation for listeners and supporters over eight years.
Bruce Schneier highlights lessons from the CrowdStrike incident, emphasizing accountability and the need for improved cybersecurity practices in tech infrastructures.
The discussion addresses AI's dual potential in enhancing democracy while cautioning against ethical challenges related to bias and responsible governance.
Deep dives
Milestone Reflections and Gratitude
A notable milestone is celebrated with the release of the 400th episode, prompting a reflection on the journey since the podcast's inception in 2017. The host expresses genuine appreciation for the listeners and supporters, acknowledging the importance of recognizing personal accomplishments. There is a desire to engage the audience in celebrating this achievement, encouraging them to share past favorite episodes on social media. The emphasis on gratitude highlights the communal spirit cultivated throughout the podcast's history.
Interview Tradition with Bruce Schneier
The episode features an interview with Bruce Schneier, a renowned expert in security and cryptography, marking the fourth time he has joined the show for the 100th episode milestones. The host recounts how he initially pursued Schneier for an interview, showcasing dedication to bringing valuable perspectives to his audience. The mix of past and present topics discussed emphasizes the evolving nature of security challenges and technology. This ongoing tradition illustrates the strong rapport and mutual respect developed between the host and Schneier over the years.
CrowdStrike Incident Analysis
The conversation delves into the CrowdStrike incident that caused widespread outages due to a faulty update, highlighting the critical lessons to be gleaned from such failures. Both CrowdStrike and Microsoft are scrutinized for their roles in the situation, emphasizing the need for rigorous testing and responsible access controls. The discussion raises broader concerns regarding systemic fragility in technology infrastructures shaped by a profit-driven market. Emphasizing accountability, the dialogue points to the necessity for transparency and better design practices to enhance cybersecurity resilience.
Election Security Challenges
As the U.S. election approaches, the episode explores the current state of election security amid rising public concern and skepticism. The complex interplay between actual system vulnerabilities and public perception creates a challenging landscape where trust in elections is critical for democracy. Historical context is provided, contrasting contemporary security with past elections while underlining the significance of local control over the electoral process. Recommendations for enhancing trust include improved transparency and audit mechanisms, recognizing the nuanced relationship between technology and democratic integrity.
AI's Impact on Democracy
The discussion turns to the transformative potential of artificial intelligence (AI) and its implications for democracy, with a focus on both opportunities and risks. Various applications of AI within political and legal systems are examined, emphasizing its capacity to aid in legislation and citizen engagement. The need for responsible usage, particularly concerning bias and discrimination, is underscored as a critical challenge for future governance. Ultimately, the conversation advocates for regulatory frameworks that prioritize ethical AI deployment while harnessing its benefits for democratic processes.
The first episode of Firewalls Don't Stop Dragons Podcast aired on March 8, 2017 - almost 8 years ago now. Over that time, I've interviewed over 135 unique and amazing people, covered countless cybersecurity and privacy stories, and offered 100's of tips for protecting your devices and data. To celebrate this momentous occasion, world-renowned cryptography guru Bruce Schneier has returned to for our traditional Podcentennial interview! We discuss several timely topics including the Crowdstrike incident, the pager bombing and supply attacks more generally, US election security, the open market for cyber vulnerabilities, US intelligence agencies' focus on offense versus defense, how AI might actually benefit democracy and much more!
Interview Notes
Bruce Schneier’s blog:https://www.schneier.com/
Inrupt’s Solid concept: https://www.inrupt.com/solid
Data and Goliath (book): https://www.schneier.com/books/data-and-goliath/
Bruce’s NY Time article on pager bombs: https://www.schneier.com/essays/archives/2024/09/israels-pager-attacks-have-changed-the-world.html
Joseph Cox “Anom” interview: https://podcast.firewallsdontstopdragons.com/2024/06/10/anom-the-fbis-phone-company/
WaPo detailed analysis of pager bomb attack: https://www.washingtonpost.com/world/2024/10/05/israel-mossad-hezbollah-pagers-nasrallah/
Restoring Trust in Elections: https://podcast.firewallsdontstopdragons.com/2023/12/11/restoring-trust-in-elections/
Hacking election systems w/ Harri Hursti: https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/
Hacker Halted conference info: https://hackerhalted.com/agenda/#day-two-october-31st
Further Info
Help me reach more people! https://fdsd.me/awareness2
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Become a patron! https://www.patreon.com/FirewallsDontStopDragons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:03:53: Interview setup
0:06:21: What should we have learned from the Crowdstrike incident?
0:11:21: Why is it more profitable for products to be brittle?
0:13:59: Do regulations stifle innovation?
0:15:27: Should intelligence agencies focus more on cyber offense or defense?
0:22:29: Should it be legal to buy and sell zero-days on the open market?
0:26:44: How secure are our election systems today? How do we get people to trust the outcomes?
0:35:41: What's your take on the arrest of Telegram's CEO?
0:39:18: How do we convince lawmakers not to subvert encrypted communications?
0:43:48: How did the exploding pager attack change our views of supply chain security?
0:49:26: In what ways might AI actually benefit our democracy?
0:58:03: Should there be any guardrails on AI systems?
1:01:17: What's next for you? What's the latest on the Solid project?
1:03:49: Interview wrap-up
1:07:51: More info for new listeners
1:13:38: Meet me at Hacker Halted Conference!
1:14:14: Looking ahead
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode