Hello, I am Lena Kassel from podcast "Fußball MML Daily" and I say that you k...
So, besides the end of the song and the new "Bundestliga" song, as far as the "Türstet", "Mutigreach-mental" and "Sport Directors". Because all the games are played, then it's even more like the kick-based side. And if there is a kick-based song, what is that?
The kick-based is the fourth fan of "Fußball Manager", and that's the first one.
It would be very simple, you could have a little bit of an opponent. You could even have a little bit of an opponent. And then you would have the right "Bundestliga" profile in your card. So, as long as you know, "Fußball MML" and "Fußball MML" is the sound of the "Bundestliga" song on the tag.
“It is an "Orgust, Trommet" song, that is the most important part of the song.”
And it is from "Tuck 1" on "Mitterball", the kick-based side. Just download and let's go. Good kick, and what is it? On "Tooks Cutters", "Check", "Internet" on "Melten", "Check", "New Address", "Check",
and then "Strowman Bitter".
With "Melten" and "Mabel" on "Bow" the "Strowman Bitter" song is the best part. Then you can download the "Orgust, Trommet" in the "Gun" version, which is often very expensive. With "Orgust, Energy, Vexels, You" you can download it completely. Now, on "Orgust, Energy, D.E. Wexel" and "Bundestliga" with "Octopus, 1, 1, 5", a 115 Euro-vexel bonus.
Your house, one on your computer, three on your neighbor's house, one on the doorbell,
“you just said, "Yeah, would have stood out like a sore thumb".”
Now, you probably walk into your office at any point in time and you don't even notice those things. You wouldn't be aware that there's microphones or that somebody's phone's laying out if you potentially be recording you.
It's the "Law Fair Podcast".
I'm Jonathan Cedarbaum, "Law Fair's Booker" you editor with "Collin Clark" and "Chad Serena". Senior researchers at the Sioux-Fawn Center. Think about what the Chinese did with "Volti-Foon", pre-positioning itself within various U.S. utilities, transportation hubs. But instead of just immediate disruption, these kind of penetrations are more likely to
pre-cursors to a future pre-position cyber attack. Today, we're talking about their new report, closing the gap, software understanding and U.S. National Security. Your report talks about the software understanding gap. What do you mean by that term? Yeah, I would say just very briefly, that's our ability to, the way we've explained it to
understand, to verify, to reason about software, which has been, you know, dramatically outpaced by its production and uptake and implementation that created a gap and in our report we have a graphic that kind of shows this and because of the increasing prevalence and importance of software to really everything we can do, U.S. National Security interests, U.S. military, U.S. intelligence agencies, but also every civilian function you can think of, there's tremendous risk that is built into
this gap. And the gap continues to grow. It is exacerbated by a number of different factors. The newest monkey wrench is artificial intelligence and how we can see that. Very good. So, is the problem of the software understanding gap
“principally about the quality of software and how it's developed?”
Is it one about how users of software have limited understanding of how software works? I think it's an all of the above Jonathan in terms of the, on the understanding side, it's the, what is the software going to do? How is it going to perform under different circumstances as Colin talked about? But it's also then, how is it the, what are user expectations, what are users do? What are different types of users do with it? And I see this
spanning across a range of different types of users and organizations. So if you have chief technical officers or engineers or software engineers at one place, they're going to understand this problem very well. If you have your individual users, like say any of us that are on this podcast right now, or understanding of how this works is going to be radically different. And I see that, I see that in terms of thinking about the differences, again, between how security
professionals would deal with this subject and how individuals civilians would deal with this subject. But now the difference between what of those applied to the national security ecosystem, those civilians who don't have quite the same understanding of this and the way they think about, you know, the implications of how secure things are, this becomes more problematic. So for instance, one of the examples that we cited in the report was smart home devices. So things like
Your thermostat, or your refrigerator, or elsewhere, those could be tapped in...
the IT systems that are governing those and the infrastructure that is then connected to those could be accessed through things in a person's home. This is inconceivable 20, 30, 40 years ago
where you would never even stop to think about, is there something in my house that could
conceivably be tied back to national security or maybe even just a security issue, a local security issue. Now that is certainly on a table on something that's possible, got it. So one of the recent seminal studies about this issue that you mentioned is the 2023 software understanding for national
“security initiative. What was that? And has it led to any practical initiatives?”
So the Treasury port is we understand it and we don't have, I can tell you this is one of those questions that we don't have a great answer for Jonathan, but we can probably write a little bit of understanding of this. I think of this as a see you as, you know, what was that report about what was
this? That was that was generated. I think the national need for software understanding was generated
from a 2023 workshop that was held by San Diego Laboratories, Alden New Mexico. That then led to a number of different initiatives. So one would have been the LNCD report, the Office of the National Cyber Director, back to the building blocks, that report, and then another report through San Diego Laboratories, but with others on closing the software understanding gap. And that came out in June 2025. And why I say we don't have the best answer to
“some of these questions like this is a lot of this is very new, not just to us as security practitioners,”
but also to people to work in this area. I call in and I spent some time asking different people
we knew, just anecdotally, how well do you understand this concept of software understanding gap,
and what do you know about software understanding, and a lot of people just didn't have an answer for us. They didn't know what the terminology meant. And we're sort of there too, we understand most more than the next priority average person, but at the same time it's something that's only a couple years old and it's mostly been dealt with by people that are technically gifted and understand the subject very well and hasn't been explored in depth by people that understand
the policy and security side of it. And I would add to that, I would say, you know, this is one of those cases of we don't need to reinvent the wheel, right? So the sunset initiative, this group has already done substantial work on the topic, 2023 ran systematic research agenda, published the technical roadmap, it helped coordinate the closing the software understanding gap report, and there you had real interagency, you know, buy it, right? You had SSA, NSA, OUSD, R&E, DARPA,
and so there's been a lot of work and in some ways I look at our reports kind of building on the shoulders of that and bringing some of these issues to the forefront and one of the things that we really tried to do here was connect this tangibly to what's happening in the operational environment geopolitically. So how does this impact the United States, VZV, or adversaries, right? We're in an era of great power competition, China, Russia, Iran, North Korea, a range of non-state actors,
and other adversaries with lesser capabilities, but that are improving each day. I mean, you know, my, by background is in studying transnational geohdus groups and I've been spending a lot of time for the past year, year and a half, looking at the lowering to barriers of entry into using a range of emerging technologies. Now, I don't think, you know, violent non-state actors are at the low end of that spectrum and China would be at the high end, nation states, but as we've seen
with Iran, right, and their proxies, this kind of tacit knowledge transfer to a range of tourists and insurgent and militia groups can be quite effective. It extends the battlefield in many ways, and it keeps us, I be not at states, busy at places further afield. Understood. I want to go more deeply into those geopolitical risks with you, but before we do so, I'd like to spend just another few minutes on the software, understanding of international security initiative,
as you mentioned, a gathering of the Scandinavian national labs in 2023, a report from the Office of the National Cyberdirector in 2024, then a follow along report in 2025 with proposals about addressing the software understanding gap involving interagency collaboration. Are there some
“highlights from that 2025 report that you think are most important for folks focusing on this”
issue to be aware of? You know, for me, I think it's a lot about the potential that's there,
Playing almost a convening role, right, because it's been out the center of the
narrations, so how do we elevate this to provide a kind of coherent, coordinated
research agenda across the federal government? Particularly for a topic that, as Chad mentioned, is technical, and, you know, we've seen this, our backgrounds, you know, we spent years of the ran corporation of doing some work on cyber warfare, and any time you mention certain terms, cyber, cyber anything, cyber security, cyber warfare, and now software understanding, you're going to get a lot of people that just wholly back off, put their hands up and say,
"Oh, that's too technical for me. I don't understand it." And so, you know, one of the things we're trying to discuss here is elevating that, how to bring this out into the mainstream, and, you know, really diffusing this across the federal government where you have the authorities,
“the resources, the institutional support needed to elevate this to, I think, the priority should be.”
Well, from what you're describing, the kind of interagency coordination and elevation of the issue across the federal government, it sounds to me like the sort of issue of a sort of task that is suited for the work of the Office of the National Cyber Director, because of course the function of that office is to engage in as such coordination around the government about
essential issues concerning cyber security. So, is the ONCD carrying forward the initiative you've
described, whether based on that 2025 report, or otherwise do you know if the ONCD has an active effort going on to work on these issues? I think there are active efforts within the government. ONCD would be a chief player there. I do think this is one of the rare areas where we have seen bipartisan agreement. I've spent some time recently on Capitol Hill talking to lawmakers about this. And so, I am a little bit optimistic that this is something that we can continue to move
forward. But, you know, in terms of which office does it with my researcher had on, you know,
“I'm less concerned about advocating for a specific office. ONCD seems well positioned. And I think”
one area that we've talked a lot about is the need for public private partnership. Well, let's talk a little bit more about the nature of the problem and the nature of the risks that you identify in your report as arising from the software understanding gap. You talk about six dimensions of national security risks. I would be happy to hear you just guess any of them.
But, I want to focus on two first that struck me as less well appreciated than some of the others.
The first I wanted to highlight is what you call a nerd blindness. What do you mean by an actor on and how does it come out of this problem of software understanding gap? So, I tend to think of this question when we were developing this report. We're trying to think about how to categorize some of the things that have come out of the growth of the software
“understanding gap. Cyberspace in general, things becoming more technical over, especially since”
the end of the Cold War. And one of the things that stood out of us when we were kind of looking backwards through this were some really recent examples of blindness and what we would consider then to be in your blindness. It's something we've developed blindness because we just don't pay attention to our circumstances anymore. Now, if I were to say to anyone here, 40 years ago, would you have noticed if there were two cameras inside your house,
one on your computer, or three on your neighbor's house, one on the doorbell, you'd have said, yeah, would have stood out like a sore thumb. Now, you're probably walking your office at any point in time, and you don't even notice us saying, you wouldn't be aware that there's microphones or that somebody's phone's lying there to get potentially be recording you. It's not something it really occurs to you anymore, and that's the in your part.
This is no different than, say, driving down the road and discovering traffic camps anymore. I would say 20 years ago, that would have been something that would have popped out immediately. Now, there are probably on every traffic light or intersection that we drive through, and we don't even notice it anymore. So that's being Europe's ahead. The application that are the operational side of that is to think about what happened recently in Iran. We've read reports
about how the Israelis had tapped into various cameras throughout Iran to be able to do pattern of life monitoring of people coming in and out of various buildings to figure out what they were doing, who is there, who they were meeting with. We've seen it with Kartsels, as well being able to tap into these various systems in order to gather information and be able to track people. Apparently Russia was also doing this and Ukraine as well to try logistics, things coming
in and out of different logistics hubs like train stations, and then Hamas apparently also was
Able to use these different types of systems in order to gather information.
particularly interesting about this is the break where if you think back to say any of the movies
or novels we had read in the 50s, 60s or 70s, you start to think about how gathering this type of information would have been a really low density, jade some born, James Bond type of activity where you'd have to spend all this money to sneak a 30-year train professional into a country to gather this information. Now it's completely different. You have established the infrastructure, put it in place, put in things that are like microphones, cameras, and everything else,
that I don't even have to pay for, I just have to access them and make sure you don't catch me accessing them. You've set up the surveillance and intelligence system that I then want to
exploit in order to be able to engage in various activities against you, whether that's an actual
kinetic strike, or whether it's gathering information for information operations purposes, or or something else, and that's completely different. But the New York part is we don't even know that this is going on around us anymore because we're surrounded by so much technology.
“I would add to that, I think, you know, when you think about the concept of prepositioning,”
you look at the scale and the complexity of all the software-defined systems that undergird US national security, they can hide intrusions for extended periods. They allow adversaries kind of freedom to act strategically at a place in time of their choosing before defenders even know what's occurred. So if we go back to kind of the solar winds, supply chain intrusion perpetrated by the Russians, there you had kind of malicious code injected
through into third-party software, updates distributed to thousands of government agencies
and private companies, and it went undetected for nearly a year. So what did that allow the Russians to do? I think we still don't know, really the intelligence that they gained from that, but certainly that long-term covert access to sensitive systems was a boon, one with suspect
“act for the Kremlin. And those are the breaches that we know about. I think, you know, it gets into the,”
oh, it's a ways I'm reminded of the Rumsfeldian unknown unknowns, which I realize is a kind of different rabbit hole, but you know, and there's been other examples from a range of different adversaries as well, including some that, you know, we would maybe consider less sophisticated cyber actors, but that are getting into different targets. And some benign targets, right, civilian targets, water clans, and, you know, random parts of the United States, what's the purpose of that?
Is this the kind of equivalent of a weapon status? Is it just get in, hang out, see how long you can be in there before you're undetected, and then try to replicate that in a different system? You know, when you think about the vast realm of possibilities, they can get quite dizzying. Your favorite playlist makes you really good. Your new brille of many people, too, because with us,
“you always get the best price. Really? Well, why are we so sure?”
Because we have a lot of people who have a guarantee for you. Do you have the same brille later, or do you still have the value for the world? Do you have the price or do you get your money for it? And that's up to six weeks after. Find your brille for the best price now online, or book your costs in Los Angeles, you'll find your brille. How do you think this problem of a neurodblindness in the United States compares to the same issue in other countries? Certainly,
I see what you're saying about the pervasiveness of software-enabled systems that pervasiveness leading us to forget how we are surrounded by these systems. But certainly the United States is not the only country where ever more of the systems are controlling many physical infrastructures around us. How does the U.S. compare to either our allies or our adversaries when it comes to this issue of a neurodblindness? Are they also suffering from these kinds of issues? I think in part,
it's a matter of scale. So simply put, it's the how much technology you have of different stripes, whether it's surveillance or other types of things. But here we're generally talking about surveillance that are insecure or that we don't know how they're going to behave and then could also be accessed for these purposes. So in that regard, although we haven't done an actual count of these types of devices, I'd have to expect that the United States is probably a leader in the
US, but certainly Western Europe, too, if you think that the United Kingdom certainly has a lot of different surveillance set up throughout London and other other cities within England. Certainly these are things that could then be tapped into. So any of the more sophisticated countries that use these things for other purposes, whether it's traffic control or even detecting and evaluating
Criminal behavior or watching people getting on the subways, where there are ...
it would seem to make sense that there would be more opportunity for these things to be exploited.
“And then if you were to go to countries where things were more sparse or people aren't that”
densely populated or you don't have the equipment around, it would seem that there'd be less of a risk to that. We've been talking about one dimension of the risks you identify in your blindness. I wanted to switch and focus a little bit on one of the other ones next. That is what you call the tacit--oh, becomes the strategic. What do you mean by that? That's right. Again, thinking about how the scale and scope of these things have changed over time, what we mean by a tactical
becoming a strategic is that if you think of some of the things that have been taken over or manipulated in order to generate either actual or potential effects, the way that we have to think about these now would be different. Again, and I hate to keep referring back to Cold War period or them, but it's a good reference point because a lot of the stuff has changed since the end of the Cold War and a lot of these problems have emerged since the end of the Cold War and
they increased use of software and software-enabled devices and software-defined systems. But if you think about something like an industrial control system, which we reference in the report and talking about that, if one of these were to be taken offline, say either deliberately or accidentally in a local environment like the Iranian tried to do with the system in Aleppo, Pennsylvania, if that were to occur, it's at the smaller scale problem. It's a tactical problem. However,
when you have all sorts of industrial control systems scattered throughout the country that are then controlled by software or software defined, now if those things could be penetrated at scale, you could have that same type of disruption occur, except you could have it occur a thousands of different water treatment facilities. Now what would have been a tactical problem at one point
that we never would have even considered really in a national security sense, unless it were to
happen to the military installation or somewhere else? Now that simple tactical problem becomes a strategic issue. If these things were to be manipulated at scale or simultaneously. It identifies two for other places where whether it's transportation hubs, if you were to look at airports, you could take something that would be a very simple problem like interfering with the computer systems or communication systems at airports and then all of a sudden not going to be able to have
airplanes taking off from a bunch of different places. That problem then compounds, if people can't move, if people aren't able to move, if logistics aren't able to move, you could see where the
“problems just cascade onwards. Yeah, I would add to that, I think, you know, it's kind of”
deaf by a thousand paper cuts, right? You have these low-level attacks that, you know, when taking an aggregate or coherently they produce strategic consequences. So think about what the Chinese did with volt-type phone, pre-positioning itself within various U.S. utilities, transportation hubs. But instead of just immediate disruption, these kind of penetrations are more likely to, you know, precursors to a future pre-position cyber attack. And obviously when when we talk about this it's hard not to
think of a Taiwan scenario, some kind of a future Taiwan scenario. But you know, play that out across a range of different adversaries and not even necessarily U.S. adversaries. But as these capabilities, you know, are kind of enhanced in other theaters of conflict, right, in other interstate rivalries, you know, whether it's India Pakistan or is really Iran or Turkey. I mean, this is
“really, I think, something we're going to be saying a lot more in the foreseeable future and”
probably not in the distant future. It's important to point out to Jonathan that we tend to think of this calling an I both were certainly guilty of it because of our perspectives on the subject. We tend to think of this as a security issue. This is something that's going to happen during an attack or an adversaries going to do this. This can also happen accidentally. And sometimes it's difficult to determine whether it was an accident or whether it was an attack to cause it in
first place. So if you were to look at something like the Iranian hacks into gas stations and the
digital control devices on those. Normally, if you're a person working at a gas station, you wouldn't think, well, I'm sitting here at the head of an international attack on a system that controls the pumps at my local gas station. You might be thinking something else. But at the same time, it could also be an accident. Either way, if the attack or the disruption, it's a L-equip or some other water treatment facility was Iranian or it was accidental, it can still lead to cascading
effects. So some of this is about the software. If it doesn't perform correctly, you still could have these cascading interdependencies of different systems failing or being unable to support each other,
Or you could have this done because of an attack where the software is manipu...
have the same result. Understood. We've talked a little bit about how the government is beginning
to address this very consequential problem. One of the elements of response that you mentioned in your report is a provision in last year's National Defense Authorization Act, the big annual statute that provides guidance to the Department of Defense. And you mentioned that there's a provision in last year's NDAA that directs the department to develop, quote, a comprehensive strategy for transitioning DARPA's formal methods research investments into production environments across
the department. Can you translate that a little bit for a folks who may not be familiar with what
“formal methods research investments mean? What is that directive telling DOD to do? So I think in some”
ways because National Security functions and systems are so deeply software to find and the risks
that are posed by, as we kind of talked about in the intro, the software understanding gap continue to grow, this is about actually putting our money where our mouth is. So evaluating the potential and actual effects of the gaps, but okay, we're not just observing these kind of, you know, throwing our hands up and saying, oh well, I wish we could do something about this. This is kind of trying to mobilize the cavalry if you will developing the policies, you know, software development
requirements and the capabilities and practices, for example, formal methods, but also the procedures, data sharing agreements that can help at least mitigate the effects of the gap, right? We're not
“saying that formal ethics is the be all end all, but it certainly puts us in a better position to”
close this gap. You know, and one of the things we've talked about not only in the paper, but
again, Shannon, I've been colleagues going back for a very long time now, I guess 20 years, almost, and we have these kind of long running sometimes philosophical, you know, conversations and debates. As you kind of close out or mitigate vulnerabilities, new ones will arise as well, but this is trying just to kind of, again, I guess I'd go back to the putting your money where your mouth is and getting this language introduced into legislation. Formally, you know, added as
requirement for the government to move forward. Well, you mentioned how the nature of vulnerabilities changes and that leads me to think about the issue that hovers over every issue related to digital systems stay and that is the impact of AI. How will the increasing ability of AI systems both to identify and apparently to repair software vulnerabilities affect this problem of the software understanding gap? So I think in some ways it's both in the identification of risks,
whether you're doing that from the position of being an attacker or a defender is important.
“As we understand it is more difficult to defend certain things because you have to be right all the”
time as the phrase goes, you have to be correct all the time about what it is that you're trying to defend whereas the attacker will need to be right once in order to weaken your defenses. Thinking about AI, this produces a, produces quite a challenge in terms of the speed and the depth and the sorts of things that AI would be able to find for both sides. So both on the offensive anti-fence of side. So it opens up a lot of capabilities in terms of being able to find
vulnerabilities and to test software and to really use AI to enable formal methods in order to get towards a greater software understanding but then on the other side too to use this as a means of exploring vulnerabilities in different systems and thinking about that at a macro level you start to say, well, I'm going to secure X, Y and Z, you will see and we would expect to see an adaptation amongst the different aggressors in this that as you start to secure a target to
make targets harder, you're then going to expose software targets that haven't necessarily been defended in the same way or haven't been evaluated in the same way. AI will just speed that up and make that sort of exploitation that much more difficult. We would also expect to see some sort of competition not just amongst the different larger like the United States, China, Russia or nation states in terms of using AI to do these things. We would also expect for other organizations
and states that are less thought of non-state actors and others to be able to use these things in order to amplify their capabilities and to do things that we wouldn't expect them normally to be able to do. I would add to that AI has become a force multiplier in so many different ways but the
Advantages naturally, you know, they're not always distributed evenly.
to find a single, exploitable flaw, defenders much more difficult task. They have to identify and
“remediate all of these. So I think AI accelerates both tasks but the attackers is fundamentally”
easier, gives them a structural advantage and I think there's going to be different, you know, this isn't a kind of static race or competition, if you will, it's highly dynamic. There's going to be different developments on both sides and you know, I think when you think about the potential for AI, and I talked before about public progress partnerships, you know, one of one of these areas when we're specifically dealing with closing the gap is going to be our adversaries, whether those
are nation states or non-state actors, they're operating under different set of rules, right? They're not in many ways governed by the same laws authorities, policies, procedures that, you know, that governments are, that the US government is in that tech companies are. So I think there's so much uncertainty in this area, it's really difficult to predict where where this is going to go and how the gap kind of, you know, diverges or kind of absent flows over time, if you
will. In some ways, you can think of this as a boon for organizations that don't have rules or have lessons rules. So if you think of Russia, Russia's Russia's control over this and how it is that people that act on Russia's behalf or with the Russian government, whether they're non-state or semi-state actors, this allows them a greater amount of flexibility like calm was saying in order
“to engage in these types of behaviors. Part of the challenge here is in why it's so important that”
this needs to be organized while in the United States through Sunsack and through interagency cooperation is we don't have, whether and when I say we either is the United States or organizations with the United States, we don't have that sort of flexibility to operate out of the law and do whatever it is that we want to do in order to defend ourselves or to protect ourselves. So it's important that these steps be taking these first steps and trying to
at least get a coordinating body together to think about how it is that the software understanding gap can be closed because you're going to be perpetually behind the curve if you're trying
to very slowly impeached meals, establish laws across a country with 330 million people when
you're thinking about these non-state actors that have nothing preventing them from doing what it is that they want to do and in many cases having state support and doing what it is that they're going to do. That is a tough dichotomy when you're thinking about being a defender, when you're on the side that has to follow the law and you're fighting against people that just have no interest, what's however, I'm following any of the rules that you would like to establish.
The way it was described to me by one intelligence official was in many ways about non-state actors, terrorists and surgeons are able to stay one or two steps ahead of us. There's growing concern that AI will make that three or four steps ahead and that it becomes impossible to close that gap over time. Well on that, troubling note, I think we're going to close for today, chat and comment. It's been a pleasure talking with you about this very urgent problem
of the software understanding gap and I hope your report will get the wide readership that it deserves. Thanks very much. Thanks for having us. Yeah, thank you.
“The law fair podcast is produced by the Law Fair Institute. If you want to support the show”
and listen add free, you can become a law fair material supporter at lawfairmedia.org/support. Supporters also get access to special events and other bonus content we don't share anywhere else. If you enjoy the podcast, please rate and review us wherever you listen. It really does help. And be sure to check out our other shows, including rational security, allies, the aftermath, and escalation. Our latest law fair presents podcast series about the war in
Ukraine. You can also find all of our written work at lawfairmedia.org. The podcast is edited by Jen Potchev, with audio engineering by Noam Osban of goat rodeo. Our theme song is from
"Arabine Music" and as always, thank you for listening.


