The Man Who Was There For Cybersecurity’s Strangest Moments — Mikko Hyppönen
TL;DRFinnish cybersecurity veteran Mikko Hyppönen recounts his career's defining moments: tracking down the Brain virus creators in Pakistan, analyzing Stuxnet, and investigating Finland's Vastaamo psychotherapy data breach.
The first PC virus. The fastest-spreading malware the internet has ever seen. The Manhattan Project moment for cyberweapons. He was there for all of it.
We sat down with Mikko Hyppönen — the man behind Hyppönen's Law: if it's smart, it's vulnerable — to talk through 30 years at the center of cybersecurity's biggest moments, and why he just left it all behind for a new fight.
Watching on video? Here’s our goofy faces. Give it a watch since he brought the real gear with him and bear with us as we navigate a new editing flow.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: Do you have any advice for people trying to have laws named after themselves? Because I keep trying and no one will use mine.
Speaker 2: I I guess it's similar to the question I was asked, I think, by some student years ago. Like, Mikko, how do how does one become a global cybersecurity expert? That was the question. And the answer is very simple. You you simply this works in any field. You just pick a field, then you work in the field forever, and eventually everybody will believe you're an expert. That's what I've done. That's that's my advice.
Speaker 1: For the last thirty plus years, Mikko Hooponen has studied and lived and breathed all of the malicious stuff that people do with technology. And time and time again, he has kept turning up at the center of these remarkable stories.
Speaker 3: Yeah. These stories that we cover on our podcast, he's every story you're about to talk about, we made an episode about, and we talked about Mico in those stories.
Speaker 1: Mhmm. When the first PC virus ever written showed up on computers in Finland in 1986, it goes there. And then twenty five years later, he tracks down the two brothers that wrote it to Lahore, Pakistan using the floppy disk that it got to Finland on. In 2000, when a piece of malware called I love you spread from zero computers to 10,000,000 computers in a single day, one of the fastest moving outbreaks the Internet had ever seen, he was there. And then the big one, what he described as the Oppenheimer moment for cybersecurity when Stuxnet was uncovered in 2010, code built by a government not to, like, steal information, but to physically destroy centrifuges inside of an Iranian nuclear facility. Mikko was one of the first people to, like, pull it apart and understand what the world was actually looking at. And then twist two years ago, he leaves digital security for an entirely different battlefield drones defending against them, probably given to the fact that he lives two hours from Finland's border with Russia.
Speaker 3: Yeah. Helsinki is really close to Russia, and he's from Helsinki.
Speaker 1: He brought stuff from the battlefield to our conversation. If you're watching this on video right now, he shows on camera, combat drones that aren't flying by radio, but are tethered by, like, a hair thin fiber opt optic cable to the pilot. And then we talk about what comes after that cable, drones that don't need a wire or radio or even a pilot piloting them.
Speaker 3: Mikko's spoken, I think, of a number of times on TED. I think he's a multi TED talk speaker, a very interesting person, you know, very diverse background, self taught, really interesting guy. Love the interview. Great depths of knowledge in multiple fields. Just just great great episode. I hope you guys enjoy it.
Speaker 1: If you're interested in learning about, like, technology and security and all the strange things people do with tech, there's a lot in this conversation with you. Murphy has a law. Moore has a law. And since 2016, so does he. Hooponen's law, whenever a device is called smart, it's vulnerable. This was a fascinating conversation, Scott. We're excited to bring it to you, brought to you, of course, by our title sponsor, NordLayer, the network security platform for modern teams. We'll tell you about them more later. Without any further ado, Scott
Speaker 3: Let's do it.
Speaker 1: Let's get into it. Our conversation with Mikko Hooponen here on Hacked. Well, you know what? Why don't we start with, I'm curious to start with Brain. We've told that story in the show before. I love that story. Why don't you, if you don't mind, take us through that.
Speaker 2: So when I started analyzing malware in 1991, there were so few viruses and worms in existence that I simply collected them all. I had a full collection of every single malware in existence. Well, PC malware. I'm I'm certain there were some mainframe cases or Commodore 64 viruses I didn't have. But all the PC viruses, there were less than 200 of them at the time. I had all of those. And then I reverse engineered and decoded and analyzed every single one of them. So I had full expertise to the whole problem of PC viruses, which you could still do back then. Of course, today, it would be kind of hard to collect all of them, however, because there's so many. But one of the viruses that I analyzed in the beginning of my career was brain dot a, which is considered to be the first PC virus in history. And brain is surprisingly advanced to be the first PC virus. For example, it's a stealth virus, which means if you have an infected computer and you try to analyze the malware, it's gonna hide itself. It's it's gonna detect that you're trying to analyze it and show you clean code instead of infected code, which was pretty pretty neat. But the real game changer that really allowed me to later find the orders of BRAIN was that they had left clues inside the malware code. And when we speak about RAIN, we speak about viruses spreading on five and quarter inch floppy inside the boot sector, the first sector on a floppy. So I had loaded an infected floppy into my test computer, loaded the boot sector from the floppy to a hex editor, and I was going through the code, and I found these texts, ASCII text, Basit and Amjad, which are first names, and then Alama Iqbal Town, which is a street in Lahore, Pakistan. And then years later, we were tracking down the history of malware, and and I suggested inside f Secure where I was working at the time that, you know, I could probably find the guys who wrote the first PC virus since we have clues about where they used to be. And we decided to do that. So I traveled to Pakistan, and I followed all these clues, and I did end up finding Basit and Amjad. I I I met the guys. I spoke with them. I left my original infected floppy with them in Lahore in Pakistan, which is where it is still today. And the the wildest thing about the whole case is that they were still at the same address. They were still at Alama Iqbal Town in Lahore, Pakistan after all these years. As far as I know, they're still there today.
Speaker 3: You didn't take the urge to get them to autograph the, your infected floppy? The little collector's item?
Speaker 2: It would have been fun, but I I think it was better to to take the piece of malware back home and leave it with the boys. Leave it
Speaker 1: where it started. They've kind of I remember I watched that documentary of you going back. It's great. They've maintained that they weren't being, like, malicious or anything. They wanted to I think the line was they wanted to expose how insecure early PCs were. Like, you went there. You were part of this. Like, did you believe them?
Speaker 2: Yeah. I do. And I I still stay in touch with the younger brother. He's he's roughly my age, so, we exchange emails regularly. We have to remember these guys are not criminals. They broke no laws because, clearly, this wasn't illegal in 1986 when they wrote brain.a. How could it be illegal because nobody had written PC viruses before? They didn't do more malware or hacking or any of that. These guys were businessmen, and their background was in mainframe programming. And that's why they were so surprised and, as they said themselves, horrified about this insecure PC architecture where anybody could do anything. There were no user accounts, and you could just create malware. And and to prove their point, they did it. That's what they told me, and I believe them.
Speaker 1: Mhmm. It's interesting to think about, like, in 2026 to think about a virus like that spreading on a floppy disk. It's so foreign to today. Like, that if I remember right ended up in Antarctica? Like
Speaker 2: no. BRAIN never went to Antarctica. Form .a did, which was something we found a little bit later. Another boot sector virus spreading on floppy disks. And I think it's it's not that far fetched to think about the spreading speeds of these floppy based viruses because, I mean, if you think about biological viruses, like the flu or COVID or anything, that's exactly the same spreading speed that these early viruses had. They required people to travel. A new flu strain, it takes months to go around the world because people need to travel and spread it manually. Same thing with these floppy based viruses. You have to take the floppy to another city, to another country, and that's how it eventually ends up on weird places like Antarctica, which really did happen.
Speaker 3: Well, I think I think January marked the fortieth anniversary of BRAIN, if I'm not mistaken.
Speaker 2: Yes. I think you're right. So, you know, it's it's been a while.
Speaker 3: It's, the the speed the propagation speed is really interesting because, you know, the, you know, you go from months to propagate on a floppy boot sector virus to worms spreading across the Internet doubling in seconds and milliseconds. The the propagation speeds really becomes a function of the medium that they're able to to transport on. What's the what medium are you kinda watching today? What do you think is of interest?
Speaker 2: Well, we've broken the speed record for malware outbreaks already years ago. I don't think we're gonna have new records there, anymore. The reason being that today's landscape for malware attacks is so very different. Viruses like brain or later email worms or web worms or whatever you remember from the history of of malware cases. For years and years, it was just kids writing viruses for fun, and they were competing with who makes the most destructive malware or or whose malware spread the the the furthest or or fastest. That all changed when money entered the picture around twenty years ago. Money making organized online crime gangs, they were competing about who who makes the biggest headlines or who's the fastest. They wanna make money. They wanna stay below the horizon. And if their malware spreads so quickly that it ends up on CNN news, then they failed. They don't wanna do that. So they, on purpose, try to keep the malware outbreaks below the horizon, and they control and throttle their spreading speed. So I think slammer slammer worm of 2002, I'm remembering, probably still holds holds the record for infecting most devices in fastest time because it scanned the whole IPv4 address space in around in less than twenty minutes, infecting every single computer it could infect, which is pretty neat.
Speaker 3: Was Slammer Slammer was the MSSQL one. Right? That was the one that
Speaker 2: Yeah. That's the one.
Speaker 3: Yeah. Yeah. I remember that one.
Speaker 2: Closely followed by Slapper, which was infecting Linux services. I I forget which vulnerability it was. But, yeah, Slammer was infecting, Microsoft SQL.
Speaker 3: Yeah. I I remember it had a neat thing too where when it penetrated into an intranet, it would then scan the entire intranet looking for other services. So it was just, like, mass replication.
Speaker 2: Sure. Sure. It ended up infecting nuclear power plants in The United States.
Speaker 1: Yeah. I mean, you said something interesting there. I just wanna pull on you have other stories I wanna talk about, but if it ends up on CNN, it failed. Mhmm. And that's super intuitive, you know. You're trying to have something quietly, secretly spread. You don't want it to get a bunch of publicity. Why then do you think so many cyber sick, like, crime groups do tend to almost engage in PR? They they seem to want people to know who they are. They have a brand name. They have a gang name. Talk about that tension between, like, privacy seems intuitive, but why do so many seem to want to be famous?
Speaker 2: Well, there's there's two different things. They don't want their outbreaks to be detected too early, and that's what happens if you if if it's too fast, if it's too noisy. So, you compare these webworms or email worms from from yesteryears, which really did go to CNN because they were so so violent in their spreading speeds, or some newer cases which became huge news items. They were typically ransomware cases which got out of control, and they were spreading faster than the creators thought because they were using some kind of vulnerability which was too successful, and they weren't throttling the spreading speeds. For example, NotPetya or or WannaCry would be examples of those. But you're right. They they do maintain websites. They have a brand. They they they talk to media. They put out releases, But that's a different thing. That's not really about trying to put focus on their outbreaks. It's trying to create a brand that the victims would be scared of. This is exactly the same reason why real world organized crime groups maintain brands. Think about motorcycle gangs or, you know, Cosa Nostra or Yakuza or Triad. They all have a brand, a scary brand. They have a brand that is someone you don't wanna mess with. They're scary. That's the kind of reputation these ransomware gang gangs want to maintain, and at the same time, maintain a brand that these are someone you can do business with. Like, if you pay the ransom and they promise to return your files and they promise not to leak the stolen data and promise to tell you how they got in, they will deliver on their promise. Now it it's not always true. There's ransomware gangs or or extortion scams today, which actually don't follow-up. But from business point of view, it does make sense to to fulfill your promises if you wanna be in this business for years and years. And some of these gangs have been in ransomware business for more than five years. Sure.
Speaker 3: You need to be reputable enough that you can trust that if you pay the ransom that you'll get your get your files back, but at the same time, you need to be afraid of them enough that if you don't pay, you understand that you're about to be punished.
Speaker 2: That's right.
Speaker 1: Yeah. I mean, speaking of ransomware, can you tell us a little bit about, Vistamo? We've talked about that story before, and I know you've talked about it publicly. Can you take us through that a little bit?
Speaker 2: The Vastamo extortion incident in Finland still today is the single biggest crime in the history of our country when you look at the number of victims. Completely unusual case. Technically, it wasn't ransomware because nothing was encrypted. The system was simply hacked, and the patient database belonging to a psychotherapy center was stolen after this breach of their network system. They had built this Vostamo. Vostamo was the name of the, private, psychotherapy center, which went bankrupt because of this hack. And they had built their own IT environment. We know that at least two different attackers were in their network over extended periods of time looking at patient data. And the this is a prime example of the kind of explosive data or or, really damaging data that can leak. Because when you go to a psychotherapy center, you discuss the most private things you can imagine, and that remains damaging forever, for years, for decades. Some of the people in the leagues, and they were tens of thousands of persons in the league. Some of these were children, who were, you know, going through traumatic debriefings or divorces or or abuse. Their reports are there as well, and they are in the dark web right now. They've been there, and they will be there because that's the way dark web works. And, the center was extorted by the attacker to pay a ransom in Bitcoin, which they declined to do. And then the attacker started leaking these patient records, one patient at a time, then he screwed up. He had written a script to leak 100 a day, which then actually had a bug in it, and he ended up leaking all of them, which meant meant that he couldn't extort the place anymore because all of it had already been leaked. The only good thing about the whole incident is that, the person behind it was caught and has been sentenced. As we are recording this, he's actually he was put yesterday on the international wanted list because he he sat in the Finnish jail for a year and a half, then he was released for to wait the, continuation of the trial, and now he's they've tried to find him again to put him back to jail. We we hope they will be able to find him.
Speaker 1: He's on the run right now.
Speaker 2: Well, he was actually communicating with authorities, I believe, over email or phone yesterday, but he's not telling where he is. We don't think he's in Finland.
Speaker 3: Wow. Wasn't there a interesting twist in the story where he tried to ransom the the agency, and then they failed to pay? And then didn't he go after the individual patients asking for individual ransoms?
Speaker 2: You're right. And that rarely happens. There's very few cases that I know of where I mean, there's plenty of cases where where hospitals or or medical systems or similar cases have been been attacked, but, typically, they don't go after individual patients. I know of three or four cases where where something like this has been done before, and the other cases that I know of are, plastic surgery centers where, individuals have been contacted with photos of their operations. Pay us money or we'll leak your photos. But, I mean, that's bad, but it's nowhere near as bad as psychotherapy reports.
Speaker 3: Yeah. Absolutely. Do you think
Speaker 1: that the reason like, just given how sensitive that is, is that why he went after it? Like, he was kind of a teenage hacker gang type figure. Does he go after Vostomo just because of the sheer sensitivity of what they had? Like, did he know what he was getting into?
Speaker 2: We don't really know. It it there's different theories. One theory could simply be that, the the guy who was sentenced for the case, maybe it was passed the information about the hack was passed on to him because it was a Finnish hack, and much of the information was in Finnish language. So he would be able to figure out better what what's the data about and what to do with the data. But we don't know, and he's never commented about this himself. It wasn't hard to get into this service at all. They had exposed, a a, a database server with a blank password on public Internet. So a lot of people found it. How it ended up with this Finnish guy's hands, we don't exactly know. But it could simply be that someone else pointed it at him because he was he was a fin.
Speaker 3: Right. Could have been a crime of opportunity rather than a crime of intent.
Speaker 1: Earlier, you brought up, a nuclear facility, so I'll pivot us a little bit here, Stuxnet.
Speaker 2: Can you can
Speaker 1: you tell us the story of Stuxnet?
Speaker 2: Today, when you think about big words like cyber war or cyber weapons, it's pretty everyday occurrence nowadays. I mean, there's a war in Europe right now where cyber attacks are are happening regularly. But before Stuxnet, which was 2010, it wasn't nearly as common. I mean, we had seen espionage and spying being done by governments. That started around 2003. The first case I worked with was in 2003, and that was the Chinese. But we hadn't seen operational attacks, attacks which would actually, like, destroy things or potentially be lethal. And that's what Stuxnet really changed. And Stuxnet was a highly unusual case. It didn't resemble any malware we had ever seen. We got the original sample in June 2010 from a small cybersecurity company out of Belarus who had been operating in Iran. And they ran into something they couldn't decode, and they shared the sample with the international malware research community. And we all started looking at the sample, and it didn't look like malware. It looked more like an installer for some kind of, factory automation software. It wasn't encrypted. It wasn't packed. It wasn't obfuscated. Normal malware would would look like that. This was huge, unpacked, uncompressed scripts, programming languages we had never seen before, ladder logic files for Siemens s seven PLCs and weird stuff. But when we were looking at the Windows part of it, it had a zero day. Zero day that it used to infect Windows computers whenever you plugged in a USB flash drive. It had a Windows vulnerability exploited through the PIF, PIF file extension. When Windows would try to render the icon for this PIF file, it would actually crash and execute a piece of code from within the file. And this zero day was a work of beauty. It would work on every version of Windows. We had every everything from Windows Windows NT all the way to Windows. Where where were we in 2010? All the way. Everything in Windows version was was vulnerable to that vulnerability. And then when we were digging deeper, it wasn't the only zero day. There were three was it four different zero days? Yeah. Four in single piece of malware, which we had never ever seen before? And the work to decode stocks that was so large, no no way no company could do it by themselves. So we set up this mailing list, which had international researchers from competing cybersecurity companies. We had me and couple of our guys from f Secure, then people from McAfee, from Symantec, from Computer Associates. Even Kaspersky was there. They were still part of the international community at the time. And slowly but surely, we've we decoded different parts of it, and guys started learning the ladder logic language to figure out what's what's it trying to do on this Siemens s sevens, and we started buying these PLCs so we could infect them and figure out how how it all works. It took forever. But, eventually, we did figure it out, and we did, make the assessment that, you know, clearly, this is governmental. Clearly, this is not criminals. Like, who would spend years writing something like this, invest millions, have four different zero days in a single piece of malware? It's gonna be governmental. And then the question is, okay. What's the target? And, I still remember one of the researchers at Computer Associates in Australia, he was the first one to make the call. He he emailed the mailing list saying that, you know, it's it's gotta be the Americans targeting the Iranian nuclear enrichment program, which turned out to be the the case. USA, NSA together with Israelis were behind it as we know now. But it was really paranoid somehow where we were, like, a little bit worried and scared about what we found. And I've I've said it before that if I mean, there's a time before Stuxnet and time after Stuxnet, just like there's a time before the first nuclear weapon and time after the first nuclear weapon. If physicists lost their innocence in 1945 with the first nuclear weapon, then computer scientists lost their innocence in 2010 with Stuxnet.
Speaker 3: Yeah. I I always find this story fascinating just because of the amount of O days used in the payload to deliver it. You know, it really tells who, like, who would have been behind it just given the complexity and severity of it. The did you guys ever find out if it actually it did did hit the Iranian, enrichers, didn't it? Like, it actually did its way.
Speaker 2: It did. Yes. And it destroyed centrifuge. It delayed their enrichment process significantly. It we still don't know, but it could have killed people. Mhmm. It's it's one of the or maybe the first case where the, software attack on physical systems clearly has the potential of killing people. Because when when these centrifuges spin, they spin at the speed of sound enriching uranium gas into uranium. And and and when you start to change their spinning speeds, they start to vibrate and they explode violently. If there's anybody close to them, it is lethal. And we still today don't know if anybody died. I I guess by now, we probably would know if somebody died, but at least it had the potential. And the people behind it, they had to know that this might kill people, and they launched launched it anyway. Yeah. And I actually visited physically the, National Security Agency in Fort Meade, Maryland two, three years before this. I'm guessing 2008. I was there for a day for a completely unrelated project. And I still remember meeting all these researchers and coders and developers throughout the day. Dozens of people who who who I I I spoke with. None of them introduced themselves. None of them gave me their card. And later on, I realized that I probably did meet people who were working on Stuxnet at the time when I was there.
Speaker 3: Yeah. Wow. One thing I found interesting about it is that it, wasn't it replacing the operational control center screens so that everything looked fine? Like, if you were in the control room, like, it had it had knew how to obfuscate itself while also at the same time destroying it. Like, it was very, very well thought out and well rounded piece of True.
Speaker 2: Just like in the movies.
Speaker 3: Exactly. Exactly. Like in the movies. Exactly. Yeah.
Speaker 2: It didn't intercept CCTV and, like, play back, you know, the same video, but close. It was recording network traffic and and playing back the old traffic while, while it was changing the spinning speeds of the centrifuge. So he really really was trying to make it look normal to the people monitoring the operations. And and it did succeed. It was running for for a very long time, and the Iranians couldn't figure out what what was going wrong. They they were clearly aware that something is going wrong, but they couldn't figure out what it was. And we know that people were fired from the the, Iranian nuclear enrichment facilities for failing to do their work or maybe even worse. And, the reason wasn't that they couldn't do their work. The reason was Stuxnet.
Speaker 1: Yeah. Interesting. And, like, you brought up this comparison of of Stuxnet to a nuclear weapon, this before and after kinda thing. And I've I've I've heard you talk about that before, like a a cyber weapon has a much shorter shelf life than a missile or a bomber, any kind of physical weapon. You can't throw a giant parade and run it down the street in the way that you can with certain type of weapons. Like, you've now worked kind of in in both spaces. How do you think of cyber weapons versus physical technological weapons?
Speaker 2: Yeah. It is important to realize that, cyber weapons suck in deterrence. They really don't give you the the, one of the most powerful features of weapons, which is that when your enemy knows what you have, they are less likely to attack you. I live two hours away from the Russian border. Finland has been maintaining a, a very capable army for decades because we are living next to a very large and very unpredictable neighbor, which we have fought before. Both of my grandfathers fought the Russians in the second world war. And when you're in a situation like this, of course, then you have to have a very large artillery, very large amount of trained people, and you have to have your bomb shelters in order, things like that. So what you're trying to do is deterrence, make it clear to the enemy that they shouldn't come knocking. It wouldn't be easy to attack us. And that's what you get with, you know, artillery and fighter jets and tanks and drone capabilities today. Where's cyber? Cyber is missing from this picture because you can show your capabilities on how many, f 30 fives you have or how many aircraft carriers you have. And you can go to Wikipedia, and it's gonna list the basic capabilities of physical armies regardless of the country. But they say nothing about the cyber capabilities. How do you show it? If you have a military parade, it's easy to show your missiles. How do you show your cyber troops?
Speaker 3: Yeah. Also USB key is a little bit less less impressive when you're carrying it through a street.
Speaker 2: Yep. That's the thing. And and and then when you play this thought through, what you have with cyber weapons is that you have expensive weapons that you have to build and maintain, which have a short shelf life. They expire because they target certain systems, which might be in use today, but they won't be in use in five or ten or fifteen years. And even if the systems are in use, the vulnerabilities that you're exploiting, they could have been patched. Maybe somebody found them and reported them and and fixed them, and then you have to, you know, start from from scratch. So you have expensive weapons which have no deterrence power and a short shelf life. That's a pretty bad combination compared to traditional weapons, and that's one of the challenges we have with cyber weapons.
Speaker 3: This episode is brought to you by our title sponsor, Nord Lair. The reality of running a modern team, your people are working from different devices, different locations, different networks, and most businesses have no real visibility into what that looks like from a security standpoint.
Speaker 1: NordLayer is a network security platform that fixes that. It gives you centralized control over who can access your company systems, lets you grant or revoke access in seconds, and keeps every connection fast and encrypted, does all that without any additional hardware or complex infrastructure.
Speaker 3: You can verify users by identity and device, block malicious sites, risky domains, and stay compliant without slowing anyone down. It's built for the way teams actually work now. Check it out at nordlair.com/hackedpodcast.
Speaker 1: That's nordlair.com/hackedpodcast, and thank you again to Nord Lair for their support.
Speaker 3: Well, this is, this is an interesting pivot because, you know, you spent most of your career or all of your career mostly until very recently in the cyber side of that carrying the USB key through the through the streets, and now you're on the other side of it. The I've been fascinated with the Ukraine Russia conflict, just how it's redefining the stage of war, you know, the the the progress and and the just the differences that are coming from the introduction of drones and autonomous vehicles. And I know that's what you're into now. I'm not sure how much you wanna talk about it, but I'd love to I'd love to jump into it with you because it's it's it is fascinating to see how much warfare is changing in real time in front of us.
Speaker 2: Yep. It is changing. And and you're right. I did a, a career shift in the summer of two thousand and twenty five. So after thirty four years of working in cybersecurity or working for cybersecurity companies, I I switched, and now I'm working for a defense contractor, a local company called Sensor Fusion, where we build drone detection and drone defense systems. Now, obviously, I haven't left cyber completely. I still follow cyber very closely, and and, obviously, we have cyber things to worry about inside a Finnish defense contractor as well, but I'm not working in the industry anymore. And, the reason why I make the shift is very, very clear. It's the war. There's a war which isn't, for me, a faraway for a war in a foreign land. It's it's right there. It's not far from me at all, and they're fighting Russia, which is right next as I as I mentioned. And if you think about, like, what defines the Russia Ukraine war, it's not cyber. Like, cyber clearly is has an element there. There's been plenty of attacks. But if something defines this war, it's drones. This is the first drone war, and we've seen the same playbook play out, and it's playing out as we record this in Middle East where, United States, for the first time, used one way attack drones against their enemy in in Iran. In fact, sending yesterday. Drones of Iranian Sahid drones to Iran, which must have been weird for the Iranians once they figured out what they are sending to them.
Speaker 3: Yeah. Yeah. The, the whole like, the drone infrastructure going on in Ukraine, the Brave one marketplace, the way that they're prioritizing military targeting, like, just the entire I don't wanna call it gamification, but it's hard not to, of, like, the of the of the theater of war is it's just it's I don't know. I I I haven't lived through any major, major wars, and, like, obviously, we're a lot farther away than Helsinki. So, so it's hard to be as in touch with it, but it just seems fascinating the way that internationally the community is responding. I know America's prioritizing these, like, new defense style contractors similar to probably what you guys are doing, you know, putting up fabrication facilities able to produce drones at a mass volume versus, you know, the classic. We build an f 35 every every year and shove it in a hangar somewhere and hope nobody bombs it. So so the why don't you give us a little breakdown of what you guys are doing at SensaFusion? That's what it's called. Right?
Speaker 2: Sure. So the company is eleven years old. We do nothing else than drone defense or counter UAS. That's the term you you you see a lot. So UAS, unmanned aerial systems, and we we we fight them. So we don't build lethal power. We're not making weapons. We're building defensive systems which detect drones and then are able to disable drones one way or another. And and drones, I guess, for many people, the first thing that comes to mind when you say drones, they think about quadcopters or something small you can buy from a shop and operate. And, clearly, these are drones. But at the very same time, there's marine drones, ground drones, underwater drones. There's winged drones, which can fly thousands of miles. So it's it's pretty wide range of different things. The only common thing between them is that they're unmanned. So that that's the thing. It's it if it's unmanned, it's a drone. That's that's as we defined it. So I guess you could even claim that, you know, if you have a Tesla on full auto and you take a human out of it, I guess that would be a drone as well. But Yeah. Maybe that that's that's a little bit different. So we try to detect these. Clearly, the focus has been in flying drones, but it doesn't really matter in the sense that if there's a control mechanism that we can detect, we can use that to figure out where the drone is, where the pilot is, and how to shut down the operations. Big part of drones are controlled with with radio. That's the easiest and most obvious link. So the company started from detecting radio waves. And those of you who are actually watching this on the video, I can show you what it what these things look like. They look like this. So this is one of ours. This is called Airfence. It's a software defined radio running linoces inside, rugged, so it operates underwater and in snow and in freezing rain and in scorching hot environments as you might have in different battlefields. You hook that thing up to an antenna and a laptop, and you end up with a map, sort of like Google Maps, which shows you location of the sensors and then location of the drones, where the drones are, what's the direction, what's the height, what's the speed, and where the pilots are. And, obviously, knowing knowing the location of the pilots, which we can't always tell. But in many cases, we can. And that's very valuable information. Clearly very valuable in battlefields, but, also valuable in civilian context. So, for example, if you think about these disruptions we've seen at airports because of hobby who fly their DJI drones too close to the airport. The air traffic control, they don't really care where exactly the drone is. They care where the pilot is, so they can send the cops to the pilot to stop whatever he's doing. And that's the kind of thing we can we can provide with these kind of radio, based detectors. But it, at the same time, opens up this game of cat and mouse. The better we are in detecting these things, the faster they will evolve. They will start to use new kind of protocols, new frequencies, frequency hopping, encrypted protocols, or go out of radio completely, which is one of the things we've seen in the battlefields. Let me show you this. Again, for those of you watching video Yeah. This is what, a fiber optic module for a drone looks like. So the basic idea is that a drone would fly and carry something like this beneath it. And what's it leaving behind itself is this very, very thin line of fiber optic, which is sort of like a hair or a fishing line. It's glass inside with a silicone wrapping on top of it. And the module I have right here, this is like six miles of the fiber optic. It just flies and leaves it behind it flying on the ground. It's undetectable over radio. That's the benefit. But in all other ways, it's much worse as a drone. There's tons of extra weight. It's harder to fly and direct. And as soon as you fly over a road, the next car will cut the wire, and you will lose the drone. So Yeah. It has its benefits, but it also has its downsides.
Speaker 3: I was gonna say fiber optics are notoriously brittle, making a
Speaker 2: They are. Making a
Speaker 3: a 30 kilometer
Speaker 2: It it's actually it's fairly durable, but if you wanna cut it, you just make a knot and pull, and you end up with with a broken fiber and, it's it's gone. And then once you're able to detect drones, then you end up with the next stage, which is to defend against drones. For radio controlled drones, you jam the the radio waves. That's what we do. We have different kind of jammers. We know the frequencies they use. We have higher power than what they're using for the transmission themselves, so we can overpower the frequencies and cut the connection between the drone and the pilot. For hobbies drones, that means typically that they return home. For military drones carrying explosives, they don't return home because they carry explosives. You don't want them back. They typically just crash where they lose the connection with the they might stay on on if it's a quadcopter or an octocopter, it might stay still until it start to run out of battery, and then it will just crash and explode wherever it might be. And for the larger drones, the plane like drones, Shaw heads or Russian Gerans or those, those are typically then taken down with other drones. We speak about interceptor drones. Ukraine has been the, innovator with interceptor drones, and I we have very good contacts with the, military of Ukraine. We have an office in Kyiv ourselves. And, the numbers we are hearing from the operators in Ukraine is that they are I mean, majority somewhere between 50 to 80% of the long range drone, long from Russians are shut down with interceptor drones. And interceptor drones, again, for those with the video, they look like this. So this is, this is what we mean. So this is a rocket like drone, in this case, with four electric motors. This reaches speeds. The the speed record we have for this is 388 kilometers kilometers an hour. I'm trying to convert to miles.
Speaker 4: Hold on.
Speaker 2: You use kilometers in Canada.
Speaker 3: Yeah. We're Canadian. We're okay. But our our listeners are largely American. Let's say, like, 200
Speaker 2: ish. 200 ish is is my my estimate as well. So the idea is that it fly flies faster than the wing drone that is trying to catch. Then we have two cameras right here. So it locks to the engine, the heat source, and, crashes into it breaking the propeller of the the motor that the large drone is using, taking it down. And, this is this has been proven to work by the Ukrainians for a couple of years now. And, the this one that I just showed you, it's made it's made by us at Sensor Fusion. So we are building solutions like this as well.
Speaker 1: Think about the last time you heard a breach story on this show. It always starts the same way. Someone, somewhere, saw something too late, an alert buried, a signal missed, an SoC that just couldn't keep up. Arctic Wolf set out to solve that problem by rebuilding security operations from the ground up for a world where attackers are already using AI. They created the Aurora Superintelligence Platform, a fully agentic system powered by the swarm of experts. Instead of single purpose bots or lucky guest LLMs, this swarm is full of deterministic agents that handle whole entire workflows. Humans stay in the loop and on the loop to validate the critical decisions and keep everything trustworthy. And all of this is just off running on their secure operations graph, a constantly updating intelligence engine fueled by more than 9,000,000,000,000 telemetry events every week and over a decade of real world incident response. The system reasons on real signals and real context, not synthetic training data. And the result is the new Aurora Agent SOC. It's the first SOC that is agent led by design. You get agents that coordinate, agents that investigate, agents that respond at machine speed, and hundreds more that automate the repetitive work that normally buries human analysts. Arctic Wolf didn't try and bolt AI onto an an old model. They rebuilt the model entirely. What makes it even more effective is how it works with Arc de Wolf's concierge experience. The team brings customer specific context directly into the platform so every AI driven decision reflects your environment instead of generic assumptions. The automation frees your concierge security team to focus on higher value strategy and proactive risk reductions while the agents handle the grind. If you wanna see what trustworthy production ready AI and security operations actually looks like, go to arctic wolf dot com slash act.
Speaker 4: This episode is brought to you by Google Chrome. You think you know a browser, but Gemini and Chrome? That's new. It can help you with practically anything on the web, like restoring a vintage motorcycle from a 50 page restoration block, or finally break down that long article you've had open for weeks. Gemini and Chrome is here for it. Ready to make anything online make sense? There's no place like Chrome. Check responses, set up, required compatibility, and availability varies 18 plus.
Speaker 1: Every company says AI will make employees more productive, but most employees are still stuck waiting on IT, waiting for app access, waiting for password resets, waiting for someone to fix laptop issues so they can get back to work.
Speaker 3: That operational drag, it adds up fast, and IT teams are overwhelmed trying to keep up. Servo was built to automate that work. You describe what you want automated in plain English, and Servo builds it for you. No complicated workflow builders, no consultants, just faster support and fewer tickets slowing everyone down.
Speaker 1: Servo enables IT teams to build automations using plain English instead of drag and drop workflow builders. Platform is designed to eliminate repetitive tickets so IT can focus on strategic work instead of constant firefighting.
Speaker 3: Unlike traditional automation tools, Serval doesn't require consultants or long implementation cycles. Serval positions IT as the AI powered operational backbone of the company, not just a support function. The company guarantees customers can automate 50% of IT tickets and backs it up with a free four week pilot.
Speaker 1: Learn more or start a free four week pilot at serval.com/hacked. That's serval.com/hacked. Serval.comslashhacked. So much of the the kind of technical problem it sounds like you're solving is disrupting a connection between a pilot and a drone. There's radio. Let's jam it. There's a line. Let's find a way to cut it. It is where this is going is there's no connection between the pilot and the drone. They pick their own targets. They make those decisions to attack on their own. Like, how far off is that?
Speaker 2: It's not far off at all. Theoretically doable already today. There's some isolated examples of it happening, but, not in large scale yet. But, clearly, that's the direction that we're headed, and nobody likes it. Nobody likes the idea of killer robots making the kill decision on their own, but that's the direction where we're going. And it's pretty pretty obvious, really. Like, if you think about the problem from the point of view of of of the attacker, like, you have a pilot holding some kind of remote control and you have a drone. The weak link is the link, whether it's, radio controlled or fiber controlled or anything. So the obvious solution is to remove the link and just have the thing make everything by itself. You give drone a mission. Go behind the lines. Figure out what's happening. Look at the different targets. Decide what to do with the targets. If you decide to kill a target, then go and kill the target. And another way to define that is indeed a killer robot, and that's unfortunately closer and closer. The the thing that might be limiting it a little bit right now is the computing power needed to have that level of intelligence on a drone. The small quadcopter I keep showing to you here, this is a Hobbies drone, a DJI drone with a battery which weighs 81 grams. Basically, nothing. And I can fly half an hour with something like this, which is one of the reasons these things have been such a success story. Why why why drones became a thing? Battery technology became so good that you're gonna have to fly extended periods of time with a very light battery. Now imagine that you want to put a NVIDIA g 300 here. It by itself is pretty heavy. Then imagine the power consumption. You would need a huge I mean, you couldn't fly it. So Mhmm. What I'm saying is that you can't make it that intelligent and fly it yet. Clearly, power power consumption is gonna get better. Batteries will get better. It's gonna fly eventually. But my guess is that if this killer robot revolution is to start, it's highly likely to start from ground drones and marine drones, which don't have a weight limit.
Speaker 3: Mhmm. Well, there's there's an economic challenge there too because if you're making a like, currently, if you're making a $500 drone, something gee. I'm picking a dollar figure out of midair, but something affordable to reproduce at mass scale, and then you're shoving a $4,000 chip inside of it. And all of a sudden, the economics of the situation changed significantly. But Yep. So
Speaker 1: The, we've talked about, like, Internet of Things, home security cameras that run local models on them for detecting, like, is that a person or is that a dog or is that an ice cream truck? And it seems like that would be a part of this is having a system that can, on the fly, determine what am I looking at? Is that my target? Is that a person?
Speaker 3: Is that a car? Is that a tree?
Speaker 1: On the defensive side, if that shift happens, that shift that no one wants to happen, and I hope it doesn't happen, but if that shift happens, how do you defend against it?
Speaker 2: Let me just first, underline the fact that this image recognition part, it's already happening. We don't it's not like full blown intelligence yet. It's not making the kill decision on its own yet. But, for example, the long range drones that the Ukrainians are flying in to to hit the oil refineries in Russia, they already have image recognition for, to to I mean, they fly close enough, and then there's so much GPS and GNSS jamming and spoofing that they no longer rely on the coordinates that they're following. And they then they just look around with cameras and detect that that's an oil refinery, and they hit it. The downside of that is that there's been two Ukrainian drones so far that we know of which have hit, oil refineries or oil depositories, which were not Russian. So, you know, there was two of them in Latvia right next to Russian border, which were hit by Ukrainians by accident because the camera system recognized them for what they were, and they were spoofed to be on the wrong position. So our, analysis is that, the reason why these these two, depositors of oil were hit by Ukrainians was a mistake from the camera recognition system. But to answer your question on how do you how do you fight AI full AI flying drones, since you can't rely on radio, because there's no radio, since you can't cut the fiber since there's no fiber, then you use everything else. You use radars, especially radars equipped to detect really small things. Normal radars are focused on planes and, missiles. Different kind of short range radars are able to detect, drones. The the main challenge there is is birds. Birds flock of birds look in radars very, very similar to drones. So that's a challenge. But that's that's one thing. Radars, that's one thing. Cameras, another thing. We are working ourselves on event camera technology, which is capable capable of detecting really tiny objects from far away in very poor lighting conditions. And we've trained our models to detect different kind of drones. And we can even detect individual spins of a propeller with these event cameras so we can figure out which direction it's going now and where it's gonna it's gonna turn soon because we can see that one of the propellers is slowing down, things like that. So cameras, that's one thing. Then acoustic. All drums make noise. Some of these are powered by, electric motors. Some of them are powered with gas engines. Regardless of that, they all make noise. So we already have a database of different drone noises. And if you have multiple microphones recording at the same time, you can do triangulation. You can figure out where the noise is coming from, what's the height, what's the speed, what's the direction. And the point here is you have different sensors, and then you fuse these sensors together and you end up with a picture. That's what you call sensor fusion, and that's where the name of our company comes from.
Speaker 3: So you so you're almost creating a bunch of inputs and then running them through a neural net or AI to to determine whether it's a a valid signal or not. Makes sense. Yep. Makes sense.
Speaker 2: But it is a game of cat and mouse, and it does remind my my previous career with hunting malware or hunting online attackers, there's tons of similarities, obviously differences as well. But the idea that you're trying to detect something that doesn't wanna get detected, and then when you find it and you analyze it and you create detection and you ship an update, then when it realizes that, hey. I'm now getting detected, then it changes. And then you have to start you need a new sample, and then you have to start the analysis again. The difference is that instead of getting binaries or EXE files to analyze, what we get are are typically IQ samples, which is recorded radio traffic from the battlefield or or visual or acoustic samples, and then you build detections for that. But we do ship updates regularly. So for example, the air fence system has been updated 275 times during the Ukraine war, which is more than once a week, which is pretty frequent. Not as frequent as an antivirus, which gets updated many times a day, but, you know, close enough. And exactly in the same way as a, an EDR or an antivirus, which hasn't been updated for a year, it's not very useful anymore. Same thing here. If you have an old drone detection system which hasn't been updated, well, it will detect civilian drones because they don't change much much. Mhmm. But it won't detect new military drones.
Speaker 3: The, just to just to hang there for a second, Tempo. You know, coming from the cyber side, you know, antivirus is sure they update every day, but I feel like a lot of them are kind of copycat clones of a specific, system, same with malware. You know, maybe there's a a really big, you know, break in how a malware is launched and how it penetrates every couple months maybe, and then you see it kind of used in a variety of malwares. How have you noticed the tempo difference between an active war and, you know, people evolving and innovating in real time versus what you saw in your cyber days?
Speaker 2: Well, it is pretty frantic on the drone side as well, but we have to remember that this is hardware. So hardware changes slower. You have to you have to get the parts from somewhere. You have to get the radios from somewhere. There might be limitations on the frequencies you can operate in, so they can't change the drones as drastically as you could change software. But they are changing, and they are reacting to whatever you're doing. So it is it is changing, and the stakes are much higher. Like, what's the worst that's gonna happen if your malware gets detected? I don't know. What's the worst that happens if your drone gets detected? Your military operation fails and people might die. So it's a different game, different stakes. But, the one thing that from my point of view, which hasn't changed, the enemy, in many cases, hasn't changed. Most of my life, I've been analyzing Russian malware, and now I'm analyzing Russian drone.
Speaker 3: The, to speak about that, the, do you guys do any, like, remote exploits of the drones? Like, do you have the ability to take control of them? Is that something you wanna talk about? I'm not sure where where we're crossing the line between industry secrets and good stories here.
Speaker 2: Sure. I'll talk about it. No. No. The the this is actually something you regularly see, drone defense companies. There's lots of drone defense companies. Many companies claim that, yeah, we can take over the drone and fly it wherever we want. Yeah. Doable has been done. Nobody's doing it with current systems, not even current common hobbyist systems. So for example, the the DJI, which is by far the largest drone manufacturer in the world, this Chinese system. Their, system the the protocol they use, the OcoSync protocol is is end to end encrypted. It's not that trivial to take over these anymore. It used to be something you could do with hobbies drones. Nobody's doing this with military drones. The closest, you have are are GNSS, jamming or even better GNSS spoofing. So you you, send, wrong location information at the same frequencies as as is really coming from the satellites, whether it's GPS or Galileo or GLONASS satellites. And it's really easy to overpower the signal coming from the satellites because they're 20,000 kilometers high. They're really far away. So if you have something closer, they can easily send much far much stronger signal, and you can change the location information. GPS isn't, signing the location information in any way. You can just send whatever information you want. Galileo, which is the EU competitor to GPS, they have the capability of signing the, the location information, but GPS doesn't. So it's it's easy to make a drone believe it's in the wrong place. But, again, it becomes a game of cat and mouse. We are just looking at some of the crashed Russian drones, which have crashed into Ukraine, and we cut some of the parts to our labs in Finland. They had eight different, GNSS receivers on there. So they were looking into different satellites. They were trying to figure out if if they are sending the same signal or different signals so they know there's jamming or spoofing going on. And as it comes to exploiting these things, that is something we are looking at, not to take over the drones, but to just defend against the drones. Mhmm. So it's fascinating how much easier it is to do hacking of drones as opposed to hacking computers. What I mean here is that if you if you're doing a, a red teaming exercise and you need to break into somewhere and you find a server running some custom software and you you find a vulnerability, you find, you know, a buffer overflow, something classic or or, you know, whatever, SQL problems. In computers, that would be the very first step. Then you would have to create an exploit and somehow get your code running, and then you would have to do the lateral movement and all of that. With drones, if you find an exploitable bug, that's it. Game over. You can crash the computer of the drone. You will crash the drone. It's not gonna fly without the computer. So we don't need to do anything. If we are able to crash the system with any kind of exploit, that's it. And
Speaker 3: that's Lowery.
Speaker 2: We we do that. That's, so much easier for for for now. It's gonna change. But for now, it's, it's a totally different ballgame.
Speaker 1: I feel like this is relevant to both the autonomous drones and your the autonomous drone conversation and your history and security is like, you you've talked about when we reach a point where we can simulate the human brain, humans become the second most intelligent species on the planet. And you've talked about this idea of that being an a basic evolutionary mistake. Yep. You've also talked about AI adoption, cybersecurity at this point is being basically mandatory. Like, you kinda need to be using it to be kept up. How do you think about building and using that thing that might be a basic evolutionary mistake?
Speaker 2: It's not like we would have any choice. Like, right now, in 2026, if you're not using generative AI, what the hell are you doing? Like, the whole world is changing. These tools are so powerful, so useful. Certainly, you could, you know, turn your back to AI, but then you probably could turn your back onto all technology that we've ever seen and just go and live in the woods. And nobody wants to do that. I don't wanna do that. But we have to be honest with ourselves. The the stakes with the upsides and the downsides with generative AI, those stakes are higher than ever before. If we get this revolution right, we will end up with a superhuman intelligence, which will solve all of our problems. If we get this wrong, we will end up with, with the situation where we are no longer calling the shots on our own planet.
Speaker 1: I mean, it it reminds me of your your law about, you know, smart devices and yet the scale and the stakes of it seems so much higher now than before. Like, do you do you have a way of thinking about it? Like, do you have a law for AI? A a sort of a quick shorthand for how you talk to people about it?
Speaker 2: Are you guys programmers?
Speaker 3: I am. Status.
Speaker 2: We're the last generation of programmers. Future generations will no longer program. We represent the last people on the planet who were programmers. Programmers of the future, they will only prompt, and they will very quickly lose the idea of what it even meant to create systems by hand. And, eventually, programmers will look at things like Linux kernel just the way we look at things like the Pyramids in Egypt, wondering how the hell did they ever build it.
Speaker 3: That's yeah. 100%.
Speaker 2: I was I was chatting recently with a professor from a university teaching computer science, and she told me that already today, freshmen in computer science are asking questions about the basic building blocks of the Internet, like like the protocols, HTTP and, you know, SMTP, asking questions like, hey. Did somebody really write all these lines by hand? Like, every single line. Well, yes. Yes.
Speaker 3: We did. They became standards. They evolved over decades of, like, refinement. Yeah. The yeah. It is it is I will say, like, as a programmer, who doesn't do it as much as a career anymore, but was a big hobbyist since I was a kid. I actually have the same origin story as you, bypassing, serial IDs in games, changing the the code. I did the exact same stuff as a kid. The
Speaker 2: The crimes have expired by now.
Speaker 3: The crimes have expired. Yeah. We're okay. But the, it's so the efficacy of the AIs in using them now. Like, I it's it's different. Like, I I I said it on on x the other day. It's like for the first time ever, I actually feel like a software engineer instead of a software developer. Because now I'm spending all my time at the architecture level and the process thing, and, no, I wanna plug in architecture for this subsystem and, you know, discussing the architectural and engineering decisions rather than, you know, here's what I'm gonna do, and then I'm gonna sit down and build the house myself. You know, I'm not nailing up the boards. It's like I for the first time ever, I feel like we've transitioned to an engineer from a from a builder.
Speaker 2: And and it's happening surprisingly quickly. I mean, we've been waiting for this revolution for decades. I I read about AI already in the nineteen eighties, and and we were promised this this this great future, which is really now happening for real. It it's quite quite insane. And I think the best example of how fast things in computer security are changing is that I was doing a talk in in the Australian cybersecurity conference in Melbourne three years ago. And on stage and this is I mean, GPT tweet. Chat GPT had been out for a year. And I was on stage speaking about how these things are evolving and getting better and better and picking up human languages. I was explaining how they already like, both Claude and GPD were now speaking Finnish, which is one of the most difficult languages on the planet. And not just writing it, but, like, speaking. I I can chat, speak with the thing, and it speaks better Finnish than I do, And I'm a, which is remarkable. And then I sit on stage, and now they're gonna pick up programming languages. They already have rudimentary idea. They're not very good yet, but they're getting better. And when they get good enough, they will be able to find zero days. We will have AI systems which which will find zero days. Three different guys throughout the conference came to me after my talk to tell me that I'm full of shit. They didn't tell me that, yeah, Nico. Nice talk. And usually, you make sense. But these things, they're not gonna find zero days. Like, what are you on about? Do you have any idea how hard it is to find a zero day? And look at where we are today. How many zero days have been found with these systems? Thousands?
Speaker 3: Oh, yeah. Well, there there's so many that we don't even know about. Right? Because the
Speaker 2: That's right.
Speaker 3: But the what's the I can't remember the name of it. Wings, something where Anthropic gave Fable access or Mythos access to all those companies, and there's just all these CVEs being posted backdated. Being like, we found all these and, like, we've patched hundreds of bugs. And, they were all security issues, but, you know, we they've been patched for a month now because we've had access to these systems that are just rooting through and finding them and fixing them. Yeah. It's it's a wild wild ride.
Speaker 1: Yeah. You, you talked about that moment of, like, a loss of innocence for scientists and engineers as the nuke, the loss of innocence for cybersecurity professionals being Stuxnet. If you had to imagine the loss of innocence moment for this era of, like, AI and and generative tools, what do you think that's gonna be? Was it zero days, or is it something we haven't seen yet?
Speaker 2: It's gotta be AGI. Like, when when we everybody when all of us will agree that now these things are more intelligent than we are, that's gotta be that moment. And it's kinda hard. Maybe we already passed it. Like, how do you how do you draw the line? And it's interesting when you think about it from his historic perspective. I mentioned that I first read about artificial intelligence when I was a teenager in nineteen eighties. I actually have the magazine, which in 1983 wrote about artificial intelligence. It's a popular science mag in Finland. And this this magazine from thirty three years ago hold on. Forty Forty three years ago. Forty three years ago. They got a lot of things right. Like, they were talking about how in the future, new like, books won't be on paper anymore. They're gonna be they're gonna be data by default, like ebooks or whatever, and PDFs. They they they could see see that in 1983. Obviously, everything was still on paper. Then they said that, you know, one day we're gonna have a hard drive, which is gonna be so big. You can fit all the books and all the papers, all the scientific research, mankind's knowledge on a single hard drive, which is what we have today. We just call it the cloud. And then they imagine that we're gonna have a computer which is which has a CPU, which is so fast, it can read all the books and learn. Well, we we got GPUs, but, you know, close enough. They they really got these things right. The thing they got wrong is how do you measure the intelligence? How how how do you how can you tell that it's smarter than a man? Because the same magazine then describes that if all of this would happen, we would get this super brain, superhuman intelligence, and we would know that it would be more intelligent than a man when it would beat the best chess player in the world in chess. That's what they're right. And, of course, that happened already in nineteen nineties.
Speaker 1: Yeah.
Speaker 2: So maybe that's the hard part. Like, where do you draw the line? When do we know that we're number two?
Speaker 3: Yeah. I feel I feel like we're all holding on to critical thinking as our, like, last gasp. And the second that we get AGI and it starts taking over critical thought, then then
Speaker 2: we get that. And, and creativity, art. I I think that's that's another thing. I I, I have a personal problem with, AI created art, which we all see all the time. We've had now top 10 songs in more than 10 different countries, which have been made with Suno or Odeo where no human did nothing. And, movies are gonna be done by including Hollywood movies will be done by AI from start to finish and and and all kinds of art, including poetry will be done better by machines. And the problem I have with this is that I hate this idea. I hate the idea that the best composers and best poets on the planet will be machines, and I can't explain to myself why I hate the idea. Like, what's the problem for me? Why why why do I feel so offended by the idea that the best poet will be a machine? I I have no illusions that this wouldn't happen. It's gonna happen. The best poet will be a machine. Why do I hate it? The only explanation I have is that I'm a human, so I prefer humans. And that's not a very good explanation, is it?
Speaker 3: The, I could throw a theory out. It's only a theory though that the, art has always been a way to express the human condition. And, if you're a robot making art about the human condition, it doesn't feel as sincere, I guess.
Speaker 2: Sucks, but it's gonna happen. It is.
Speaker 3: Yeah. It's kind of
Speaker 1: a question of what art is for in a weird way. Because if it's what you said, Scott, that it's to see that there's someone else having an experience of the world that's some way recognizable to me. But just different enough that I wanna understand it. When you see a piece of art that makes you think you're experiencing it, and then you find out it was produced by something that didn't have that ghost in the machine, it feels like you've been kind of betrayed or tricked by this thing that's worked really well your entire life. Feels like a
Speaker 2: sound would you even know that it was done by a machine? If you don't know it's done by a machine, it's it's more human, more touching, has more meaning. It's a deeper thing than done by any human. Then then the machine is superior whether we know it or not.
Speaker 1: Sucks. It sucks. It does suck. K. Mico, I really appreciate you you chatting with us. Earlier, you nodded to a a story about WannaCry and Bitcoin. So for all this, I wanna bring it back to just a good old fashioned story. Can you tell us that tale to to sign us off?
Speaker 2: So when WannaCry went around the world in 2017, He was asking for Bitcoin ransom from everybody getting who who got infected. We know now it was the North Korean government. This was their very first Bitcoin ransomware attempt. It didn't work very well, but it caused massive amount of damage, especially in United Kingdom because the National Health Service, the NHS in UK, was hit by WannaCry. So on the evening of the WannaCry outbreak, I get a phone call from UK. It's the BBC. I chat with a journalist for an hour explaining exactly how it worked and what he was trying to do and why it caused all this damage and how it was trying to collect ransom and how does Bitcoin and blockchain work, all of that. At the end of the call, the journalist asks if I could come over to London the next day so we could shoot something for BBC to explain to people what's going on with NHS, and I promise to take the morning flight. And then we talk about what to show on camera because it's hard to illustrate all these cyber attacks and and and blockchain of these. And I I suggest that, hey, no. I could take some physical Bitcoins with me, you know, real coins because I happen to have them. I used to you know, I I bought a stack of Casascius coin when they were $40 apiece.
Speaker 3: Congratulations.
Speaker 2: Unfortunately, I ended up selling them too early, but I had them at the time. So I suggested that I'll just bring some coins so I can show them on screen. And she was really excited about that. She said, yeah. Sure. Come over and bring some coins. Why don't you bring several? So I fly over the next morning with the first flight to Heathrow carrying $1.05 Bitcoin coin, $1.01 Bitcoin coin, and $1.00 dot 1 Bitcoin coin on me. So I had 6 dot 1 Bitcoins. As I landed, I walked through the, the passport check to customs, and then I walked to the red line on customs. And there's a guy, and I go to the guy, and I explained that, hello. I'm entering United Kingdom carrying more than £10,000 worth of monetary units. And he was like, okay. Good. You have to report that. What did you have? I said, well, I have Bitcoin. And his pace changes, and he's like, okay. Let me get a guy.
Speaker 3: And he
Speaker 2: goes and comes back with another guy who understands something about Bitcoin. He's like, okay. 6 dot 1 Bitcoin, he does the conversion that's around £15,000 at the time. Yep. You have to report it. So where do you have the Bitcoins? Are they on your phone? Are they on your computer? And I said, nope. I have physical Bitcoins on me, in my wallet. And he's like, physical Bitcoins. Let me get a guy. So he goes away, comes back with a third guy. And the third guy, he's already mad from the beginning. He doesn't know what to do with me. He's, like, paging back and forth, and he's like, physical Bitcoin. And then he asks me that, mister Hoeponen, these 6 dot 1 physical Bitcoins that you are trying to enter The United Kingdom with, did you report them in Helsinki when you left for United Kingdom? And I tell him, nope. I didn't. And he's like, excellent. You may go. Please go. And they just threw me out.
Speaker 1: He threw you out. He didn't let you into the country or he let you in?
Speaker 2: He let me in. He didn't know what to do with me because but he didn't know he he now knew that no one else knew about me either. So easier just to just disappear, please.
Speaker 1: There wasn't a fourth guy. They didn't bring out a fourth guy.
Speaker 2: No. No. And I wouldn't wouldn't repeat this this rehearse either.
Speaker 1: Thank you so much for taking
Speaker 3: the time to talk with us. That was a lot of fun. Yeah. Appreciate it.
Speaker 2: It was a lot of fun. Cheers.
Speaker 3: That was a lot of fun, Jordan, don't you think? Really interesting guy. Love the stories. Love the show and tell.
Speaker 1: Yeah. We we've never had props on this show before because we've never had a camera on before if you're watching this.
Speaker 3: Yeah. Hello. This is what we look like.
Speaker 1: Jarring face reveal.
Speaker 3: Jarring face reveals.
Speaker 1: Thank you for joining us on the show, and thank you again to Mikko for for showing up and chatting with us. And, again, a big thanks to NordLayer for their sponsorship of Hacked. Check them out at nordlayer.com/hackedpodcast. That was a fun one.
Speaker 3: It was. We'll see you guys soon.
Speaker 1: Catch you in the next one.
Speaker 5: Slot fans, the wait is over. Lightning Link is available online for the first time ever, and DraftKings Casino has it. In fact, DraftKings Casino is your home of Lightning Link. New casino players can play $5 and get 1,000 spins including 500 Lightning Link spins. That's 50 spins a day at varying values for your first twenty days. Strike now to claim your offer. Download the DraftKings Casino app and use promo code elite, then spin lightning link high stakes anywhere, anytime. The crown is yours in partnership with DraftKings Casino. Gambling problem? Call 1800. In Connecticut, help is available for problem gambling. Call (888) 789-7777 or visit ccpg.org. Please play responsibly. 21 and over. Physically present in Connecticut, Michigan, New Jersey, Pennsylvania, and West Virginia only. Void in Canada. Eligibility restrictions apply. Non withdrawal spins issued as 50 spins per day for twenty days valid for select gains only and expire each day after twenty four hours. Spins values vary. See terms at casino.draftkings.com/promos. Ends August 23 at 11:59PM eastern time.