The Lawfare Podcast
The Lawfare Podcast

Rational Security: The "Sloop John Stamos" Edition

1h ago1:31:2117,946 words
0:000:00

This week, Scott sat down with his Lawfare colleagues Alan Rozenshtein, Michael Feinberg, and Loren Voss to talk through the week’s big news in national security, including:“Under Pressure.” Over the...

Transcript

EN

[BEEPING]

[BEEPING] Frank.

So instead of just using the "A" or the "NOMODELB",

we can find it or if it's wrong.

Or if it's wrong or it's wrong. Or if it's just "KI" from AVS. With a hundred of models, a number of different agents, or if it's wrong, and if it's wrong,

we don't need to find it. We don't need to find it. [BEEPING] [BEEPING] [BEEPING]

I love recording with the particular set of backgrounds right now, because I have Lauren, who, like me, is embracing the austere dc office background. We have Mike, who could be in Oxford, with his current set up of beautiful wood,

and multiple live plants that are looking vibrant, despite not being clearly near any sort of sunlight. And then Alan, who looks like he has locked himself in a basement for the last two weeks, that refuses to emerge. [BEEPING]

I have windows. I have a live plant. Thank you to my wife. Where is your live plant? It's a live plant.

It's here. Right here. Oh, no, you're right. That is a leaf that's speaking out right there. That's something.

We'll take it. I like it. It is like the text set up, which I appreciate. Like big headphones, Mike. It's kind of like a DJ, but for thoughts and takes.

It's a good mix. I do like, they call me DJ takes. MC, MC hot takes. MC hot takes, is my hand. Oh, I love that.

I had it through a party in college where we, I was both opposed to the party pick DJ names. For their DJ sets, the mind was DJ Tanner. Does anybody get that reference score? We're all enough to have seen full house.

Yeah, there you go.

I think Mike, maybe the only one who actually picked up on this one,

sadly. But I'm not pretty sure. I was a full house fan back in the day. Although I thought the middle child, you know, got a bad rap. Being a middle child myself.

It's the very best thing John Stamos has ever done in his career. First being.

The first was he started in a video for the indie rock and low.

Which is a great video. Well, worth checking out the name of the song is tried to sleep. And then he was a drummer and still maybe for the beach boys. And, you know, that's a little controversial, because it's the Mike Love Beach Boys,

not the Brian Wilson Beach Boys. But in an era where pop is just not as harmonica or milifluis. Is it used to be? You take what you can get. That was my very first live concert ever.

It was the Beach Boys. With John Stamos. I hope. I don't see, I don't know. It's too little, maybe.

You know what, you would have missed that guy behind the drums. He's 50 years younger than the other ones. It incredibly handsome. I feel like that would stand out. Hello, everyone.

And welcome back to "Rational Security." The show will be invite you to join members of the law fair team. It's we try to make sense of the week's big national security news stories.

Whether they are in our lane or not. I am your host Scott Anderson. Thrilled me back another week with several of my talented colleagues. Joining us this week to hatch through those big news stories is none other than law fair senior editor.

And research director Alan Rosenstein. Alan, thank you for coming back on the pod. And I should say, last night, forget. Go host emeritus. Thank you.

Thank you. Now I look how to say that word right. I say it every opportunity. I think it's pronounced to Emeritus. I think it's pronounced to Emeritus.

I think that is how I said it.

It was one that I arrived at having never said it

out loud before and just ran with it. Look, I said, I said, I said, full cult until I was like 21. The rule is you never ever make fun of anyone because it just means they learned it by reading it.

English is the worst possible language for sounding things. As I am discovering, while trying to teach my five-year-old had a read, which is a wonderful experience. Except you realize when you do that, that English is an object. Looking in some ways, it's a wonderful language.

In other ways, it is objectively the worst possible language imaginable. I don't think we can blame English for a fruco, but I'm with you on that generally. And with that, our most precodian, I've seen your editor 20 as well as Mike Feinberg, Mike, I don't really know.

I think that's kind of appropriate. You worked in law enforcement intelligence at all, and that's maybe the most fucodian for the kind of penance.

I think a lot of former FBI agents joined as a result of an interest

that was sparked by reading discipline and punished

When they were in their French theory phase.

Yeah, exactly. I think that's the main motivator.

We won't get to some other fucos, other work,

which may be motivating things. But then this one definitely applies. But thrilled to have you back on the podcast. Mike, thanks for joining us. Thanks for having me.

And I will just reiterate for those who can't see the sarcasm on my face. Anything I say complementary about fucos is entirely sarcastic. Very good, exactly.

And joining us as well, of course, is our third law fairer senior editor for the episode. Lawyers Invest, back on the pod. Lauren, thank you for coming back on the podcast.

Yeah, always happy to join.

All right, thrilled to have you. Well, we have a number of big stories this week, so let us get into a topic one under pressure. Over the past two weeks, hackers have reached the industrial control systems of water

and wastewater utilities in at least seven states, prompting an urgent joint warning from federal agencies. The intruders lock operators out of internet connected, control devices, change passwords, and in some cases, cause water pressure drops and flooding,

forcing utilities to switch to manual operation, issue, boil, water notices. The tax came just days after federal agency renewed their warning about Iran, affiliated, cyber activity, targeting us, critical infrastructure, emits the ongoing war with Iran.

The administration has not formally attributed any of the actions to Iran, present Trump has publicly waived off the Iran theory.

How worried do we be about the security of our critical infrastructure

and what if anything can watch it and actually do about it?

Topic to the Shawshank Resumption. Last week, at the annual Black Hat Cyber Security Conference, open AI provided a detailed look into the recent high-profile cybersecurity incident in which an AI model being stressed tested by open AI broke out of its evaluation sandbox found

its way into the open internet through a zero-day vulnerability and hacked its way into the system to the machine learning platform, hugging face, apparently an effort to cheat on the very security test was being given by stealing the answer key. I don't think that's accurate, but it's something to that effect.

The account they gave was an extraordinary one, as it scrubbed dozens of agents using various frontier and non-frontier models collaborative across a secret message board they established to hack an internal software system to access the outside internet. And then doing it again this time successfully after open AI caught and deleted

their first attempt. What does this level of collaboration persistence mean for the future of cybersecurity and what can anyone do about it? In Topic 3, Apocalypse Mo. This week marks one year since President Trump deployed the National Guard

to Washington DC as part of its make-de-seeptate and beautiful initiative. 12 months and nearly 10,000 troops later the deployment has become a normalized fixture armed guard members patrol the National Mall, metro stations and neighborhoods while also picking up trash, spreading mulch, printing trees, and mowing public property.

The Pentagon now projects the mission, which Trump has authorized through an auguration day in 2029, will cost an additional $1.4 billion. But a year in it remains genuinely unclear what these troops are doing exactly, and how much of it counts as law enforcement at all. What is the deployment accomplished and what does open-ended normalization mean

for the use of the military at home moving forward?

So for a first topic, Mike, I want to come to you on this. She mentioned this topic briefly last week, but I wanted to give it its own attention, because I think this question of the home front is a front that has not yet materialized in terms of potential consequences from the Iran war, and potentially from other global conflicts, global concerns.

But is one that is always in the background, and is one where we talk a lot about

concerns about what this administration in particular is done to federal law enforcement to intelligence capabilities, to a variety of federal capabilities, in terms of potentially openness to vulnerabilities. And now we have this first case study of what might be an example of that. Potentially tied to the Iran war potentially elsewhere.

Talk to us about this recent series of events. What we know about it from public source saying, and we're fits in kind of the broader trend. I know this story of critical infrastructure, and I think waters, it's a particular, has been one that people talked about for a number of years.

It's kind of a known vulnerability. I'm curious how this kind of stacks up from your sense in terms of, you know, worst case to not worst case on the spectrum, and how concerning it should be. Yeah, so I would say that the good news is it could have been worse. And we'll get into why because of the various critical infrastructure sectors

that Sissa has formally designated there are 16 total. Compromise the water supply is actually not one of the ones for me that rates as the most problematic, and we'll explain that in a minute. But the bad news is that it is going to get worse. What this should really bring home for people that I haven't seen discussed too much

in any of the various media accounts is that the protection of an ocean on either side of our country is no longer enough to immunize the general populist of the United States from the effects of an overseas war. This attack was relatively minor, it was relatively contained, but it does prove something that people in the national security field have already known,

Which is that you could use a cyber attack on a skater system

to destroy a piece of critical infrastructure just as easily,

if not more, easily, than you can with a misler with explosives.

So the notion that a war to quote, you know, infamous British Prime Minister is in a far away land involving people we don't know, is no longer a protection that it won't touch us here on the homefront. Now, I said this could have been worse, and that water was not one of the sectors about which I'm most concerned, and that might sound counterintuitive to people.

We need water to live. But the citizens of Minnesota were able to get off with a boil warning in this case. And part of the reason it was contained is because water is not necessarily inextricably intertwined with other sectors. You know, some of the other sectors include the information and communications

technology sector, the financial services and payment system sector, or the transportation sector. If you take one of those down in a cyber attack, it has what we call cascade effects, and that taking that one sector down is by necessity going to take others down as well.

This was isolated. If I was speculating, I would assume and suggest that this was Iran more showing us that they have the capability to do something like this. Almost is a warning shot than actually doing something. Yeah, so I'm a group of Mike that this is yet another example of how

America's national security posture is going to continue to deteriorate because of this, but I was just expanded and say that I suspect natural security is actually going to be relatively small part of the increasing landscape of the cyber attacks.

I think the vast majority of them in the future is going to be run

of the mill, or quote unquote, run of the mill, criminal ransomware type attacks.

And we'll get into this more in the second section of the show and we talk about

how increasing AI capabilities is going to hugely democratize this. But, you know, in the next six to 12, 18 months, we're going to see a unbelievable flood of these sorts of attacks against some of them might be from Iran, or Korea, or from whoever. I think the vast majority of them are going to be from random cyber criminal groups

around the world. And we've already seen that, you know, again, using Minnesota as an example, not there's anything special about Minnesota, but you know, that's where I live. So I read the start to be in a lot. We've had big big problems with our hospital systems getting ransomware.

We've had big big problems with public school systems getting ransomware.

Right. And you know, I just think the it's going to become trivially easy. Not just to find vulnerabilities, but to find vulnerabilities at scale. And then to spin up a bunch of AI agents that can go and brick, you know, system after system after system.

Now, obviously defenders can use those same tools.

But defense was always going to lag offense.

It's just going to be a very, very, very unpleasant several years. And I'm sure we'll get to this as well. But the fact that Trump's response was not to say, you know, this is Iran as his intelligence community seems to think that's really bad. We're going to work with, you know, the Minnesota authorities to fix this.

It was to blame Tim Waltz, whom he will never forgive for having the authority to run against him in an election just shows that, you know, at least while this administration is in office, it's unlikely that the federal government is going to be particularly useful here, especially if the target is a blue state or a blue jurisdiction, which is depressing. Yeah, I would tag off on two things Alan said.

He raised the point about cyber criminals being just as much a danger as national security threats. I'll confess. I don't know if I see a clear dichotomy there. Simply because there is a real trend for foreign intelligence services. And this has been reported in the context of North Korea, for example, or with respect to China. There's a trend for foreign intelligence services to actually outsource a lot of their work

to organizations that we would not recognize as being formally associated with a foreign government. The most salient public example of this may actually be from the 2016 election, where the internet research agency was functionally according to court filings, working as a proxy for the GRU, but did not actually have any official place on a Russian government or chart. So we're going to see a real conflation of the people who would just be doing this for foreign

profit and the people who are doing it for overarching strategic purposes.

Alan brought up Trump's failure to properly attribute this in line with what ...

It's not just that. The organization within DHS that is supposed to run point on protecting us against these types of attacks has been utterly decimated.

Sissa has seen its funding destroyed, Chris Krebs, its former leader was actually the subject of an executive order directing the government

to investigate him because he had the temerity to say that the 2020 election was not stolen or interfered with by a foreign government. So you're going to have an agency with less staff, less resources, and less incentive to poke their heads up and as much as I hate this phrase,

to speak truth to power when these sort of things happen.

And this was already an uphill battle simply because as everybody knows, cyber security imposes a cost on operators and it introduces friction to the user experience, whoever the user is. And there's been a constant struggle in the United States where our infrastructure is almost entirely in the hands of private enterprise to get those businesses to take that loss in their short-term profits or to take that caught of their resources to do the security upgrades that the government wants.

It's never been a smooth process getting them where they need to be and what I think we're going to find out.

To our detriment is that they're not where they need to be. So I do want to focus on the cybersecurity element of this before we zoom in too narrowly on that. Let me go back to a point you made Mike about the warning shop. I think you're in nature of this action. That is a limited, as far as we can tell, at least limited impact effort, hit a number of states, demonstrated capability. You know, there's been kind of I think, as I understand, as I recall from time I spent working more on these issues, a sense that like a potential Iranian counter strike ability against the United States basically came across two dimensions. One is the cyber dimension and the other is international terrorism.

So I'm kind of curious about before we circle back to the technical level of that. Is there something that you might draw for this from how we think about Iran as an adversary and what it's demonstrating? There's reason to think this maybe isn't its maximum capability or maybe even that it wouldn't be acting on its maximum capability for fear of what that would do to domestic political dynamics that currently are putting pressure on President Trump to re-engage with negotiations for potentially good reasons reasons I've argued for.

But then nonetheless, our strategically President post-written advantages to Iran. And so I guess the question is, how do we think about those capabilities? How do we evaluate them and does the willingness to engage on the cyber measure even if incrementally suggest maybe that there may be more willingness to engage on that terrorism front, which I think presents a much more, you know, serious and threatening and psychologically terrifying element of potential response or consequences in Iran or from America that we frankly haven't faced yet.

At a meaningful scale, unlike people in a number of countries elsewhere in the world in the Middle East, in particular. I don't know if I'm willing to make that same, if I'm willing to reach that same conclusion and that's simply for two reasons. Nothing has united in America, driven by partisanship as much as a terrorist attack. I'm unaware of any time in my entire life where the country was as unified as it was in the months and even years after 9/11. There was broad consensus on within the government, there was broad consensus on most of the military and counterterrorism policies that came as a result of that.

We've sort of revised the history of that. There are a lot of people who now say the Iraq war was a bad idea that the Patriot Act went too far and they may be right. But at the time, they were willing to cast the votes for both of those things.

And I think Iran is not stupid. They could read a history book or the newspaper as well as anybody.

And realizes that where they'd launch a traditional kinetic type attack using terrorism as the means, it would probably have a stiffening effect on American backbone.

Whereas if they do almost something that's more like a reconnaissance attack on a small segment of critical infrastructure limited to blue states, they know that

that a transactional president who has already in public admitted that his administration has denied funding to those states in other areas is not likely to get overly concerned about this.

I think it was actually a very canny move on their part.

While at the same time knowing that publicly the president is not going to say anything that could read down against them in the future.

Let's begin to, we're going to spend some more time talking about the cyber security tech home about this in our second topic.

I want to think a little bit more of this blue state dynamic and the sort of political dynamic here. There is this point of rhetoric from the Trump administration about certainly we have blaming Tim Walt being the basis for the Minnesota acts.

That's the administration's response, we're certainly the president's response, I think you've heard it from a number of other senior administration officials as well. We know we've got this history of them targeting blue states.

But do we have a sense yet about the extent to which how that is affecting downstream and potentially more technical or technical or technocrat level engagement about support, whether it is law enforcement information sharing, whether it is, you know law enforcement investigations, things like that. The sense about how this has impacted those levels of cooperation, we know in the immigration domain huge points of friction, huge frictions with say it's and there's been because of that, I think a lot of friction with federal law enforcement.

In part because they've been so tasked to do that so heavily, but do we have a sense yet about whether the other mechanisms that we rely on for in or state or state federal sort of coordination on these issues sets.

We can in a way that is not just result of potential neglect of the agencies, but actually of this sort of targeting with holding of resources and protection.

So I don't think that we could actually separate those two issues, what's going on with respect to the conflict between state local and federal agencies with respect to immigration, what the response is going to be this because quite simply and this has been reported throughout the media.

The general mechanism through which those local and state agencies interact and share intelligence with the federal agencies is through joint fusion centers.

And once the federal government started using information, it was getting from state and local officers to carry out immigration operations.

Many of the states involved in those fusion centers have said they're going to start pulling back and not sharing intelligence going forward.

So what you have is actually symbolic of a bigger break down in both law enforcement and national security, in that there's no real coordinating mechanism that I'm aware of right now, which is looking at the second and third order consequences of action A as they may apply to national security problem B.

This is normally the sort of thing the national security council does those of us who have spent time in those hallways know that it is not inefficient process it is not a quick process.

It is one of the most boring set of meetings you could ever attend is a government official, but it does do a good job of sussing out different equities that is the place where normally the department of defense would say, hey, we're thinking of launching military action against country A DHS FBI, what do you think are going to be the downstream domestic consequences of that once we hit go. And we know that the NSC has been radically downsized in a fashion we haven't seen before in modern history.

We know that many of its detail is have been sent back to their home agencies and we know that the person who is supposed to be running it is also the secretary of state and wearing a whole bunch of other hats that the national security advisor does not normally wear. But I think it's fair to assume that that interagency process where these problems get you know game plan or war game doubt before you take any sort of military action has broken down and now we're seeing the consequences for American citizens as a result of that.

So, Lauren, you are an alum of the national security council. Let me pull you in on this for your sense of that. I think we think of the national security council as playing the dominant role in kind of foreign policies at any of some prior administrations. So we look at the decision to launch the Iran war. The event is a way of action things like that right around real and there we see these policy failures or but would seem like likely policy failures because of contingencies and potential consequences that don't appear to be fully considered that were better than people talked about being kind of the atmosphere.

But the domestic side I mean how important is it for these sorts of coordination efforts about federal resources and state resources and does the level of diminution we see in the national security council in this administration the shift frankly to much more.

I think that's a very important thing to do is to do that.

I think that's a very important thing to do is to do that. I think that's a very important thing to do is to do that. I think that's a very important thing to do is to do that.

That's a very important thing to do is to do that. I think that's a very important thing to do is to do that.

I think that's a very important thing to do is to do that. I think that's a very important thing to do. I think that's a very important thing to do is to do that. I would also say that specifically in this case, a lot of this falls on Homeland Security and Homeland Security Advisor Stephen Miller, and what his priorities are right now, and his priorities seem to be very different than what we're talking about in this call. It seems to be more focused on immigration type issues. What you would typically see, though, is crossover between those people within the building and then with outside organizations on a regular basis.

I think that's still occurring. I think is anyone's guess, but you can just see how all of these pieces are tied together and one affects the other, and so you really actually need that inner coordination.

It's just, I think, unclear to people how it's happening, but I think, you know, we for years have been talking about how foreign conflicts will have effects on the homeland.

And it becomes more and more true with technology every year, and that we have to be thinking about what that's going to mean, not just for our national security, but for like everyday Americans and how that's going to affect their lives. I want to come back, we'll circle and come back to the technical element, and at the point that you made Alan about this becoming a much more democratized, low-bearred, and recapability, because we're kind of operating on this assumption, and there's good reason, maybe even this case, that these incidents were the product of Iran, which has both the motivation to some extent, the capabilities we know Iran has a fairly developed cybersecurity capabilities for among other capabilities.

They've kind of developed over the years, in part to have this, you know, retribution capability, the strikeback capability.

But we don't know that for certain, even though it seems likely in this case, and it's not the only actor we could see potentially taking these sorts of actions.

So I'm kind of curious about how you begin to think about this sort of coordination and the government's role in securing these sorts of fundamental goods in an area where targeting could come from a variety of different entities.

Because actors that wouldn't have had this capability today, or yesterday, or five years ago, now, or the near future, could or would develop it in potentially innovative ways, and how do you begin to think about that as a kind of responsibility within the government? I think the NSA should just run the entire internet, which is it that way. It should make it real simple. Wasn't that a proposal a few years ago? The NSA was just going to run the whole internet, and now's going to solve our cyber problems, and then people went home, maybe we should do that.

Yeah, I mean, it's really, it's really, really tricky. I mean, this is a, this is exceptionally difficult in any environment, and it's especially difficult in a country like the United States, which is very decentralized, very fragmented.

The way that fragmentation decentralization is itself part of resiliency, because there are fewer choke points, and I also sort of speaks to the vibrant ecosystem.

We have there, though, but in order to make that work, it requires a government that is really good at coordination and has a lot of expertise and has a lot of trust with the private sector, and this government has none of those things. So it's just going to be an absolute disaster for the next several years, which is unfortunate, because this is precisely the inflection point of decentralized cyber capabilities. And we are just very unfortunate that it is this particular administration that is going to be trying to deal with this problem.

And it's going to spend most of its time blaming its political enemies rather than trying to actually solve the problem. Before we close on this topic, I want to push back on that, or at least play a little bit of a devil advocate. Now, I'll suppose it's this question to you, Alan, but Mike and Lauren, it cares you away, even too. There's lots of criticism about this administration has done not a variety of different fronts, particularly diminishing the national security apparatus, and I'm not going to, that's not the where I want to play devil's advocate on this.

But in your point about engaging credibility with the private sector, it is kind of interesting in that we have seen this administration take a uniquely aggressive tack in that regard.

They've been able to extract concessions from the private sector all over the...

And using tools that are of legal, questionable legality, right? Some of which are subject to court order. We know we're having this end topic fight that you've written about it laying foul. And I'm actually doesn't look at the governments likely to win.

Other fronts, they're kind of getting away with it, right?

There's an executive order, the Trump administration issued a few months ago.

I'm a little six months ago now, basically limiting the way defense contractors can offer payouts their stockholders.

Unless certain targets are met for defense production. I do not see how that could possibly be legal. I have looked into this at some length because I was very curious about how on earth they could do that. And it's really I cannot figure it out. But it does seem to be relying on the fact that well, major defense contractors aren't really going to fight us on this.

Because if they sue, they're going to be too worried about losing business. So they're going to have to play along at least, you know, to substantial extent. And this administration has leaned into that a lot. What is the other model? I mean, how do you engage with the private sector more on this?

When we have a private sector, that is a like politicized with has very strong feelings between Elon Musk. Openly backing one political party, pretty substantial the other despite controlling, you know, technologies that are fundamental to a lot of US-scrituals arguably at least. You can say the same thing about other companies. AI companies are playing a little closer to chess instead, kind of or at least playing it both sides, some extent. You know, on top of that, you also have the fact that it's just highly fragmented, highly competitive.

There's a strong sense that in part just fight on national security grounds, at least in the AI context, we've seen a real push to deregulate. And say, no government involvement is really appropriate here. I mean, does the government have to play hardball with the private sector around these capabilities? And what will that require? Or does it have to have a more conciliatory route?

And if so, how do you manage that effectively without, you know, giving in to these concerns by their corruption or letting the private sector drive the bus too much that you're not addressing these interests? Yeah, I don't think it's a hardball issue. I don't think any part of the private sector wants to be hacked, right?

It's not like these water companies or critical infrastructure providers are sitting there being like, and it'd be really nice to get hacked by the Iranians because then I can take two weeks off.

I mean, this is very bad for them. It's bad for the bottom lines. They don't want to be hacked anymore than anyone else does. Now, it is true that they have to be held accountable so that they properly invest in cybersecurity.

But I don't think that's what the Trump administration's bullying is going to accomplish, right?

It's just going to undermine the informal technocratic networks and expertise between, you know, companies, between the federal government, between state governments, again, many of whom are blue states and it would be helpful if everyone talked to each other. So it's just I think a kind of basic coordination competence that's at issue here rather than this is where, you know, Trump's madman theory of power has any real benefits. I want to chime in also and point out that I think there's a real misconception outside of the people in government who have worked on this that it is a regulatory question.

That is simply one piece of it and whether the Trump administration has been successful at getting concessions or showing private industry be malleable or accepting of some of its regulatory proposals isn't the prime issue for me. What matters more is a two way exchange of information between smart subject matter experts on these topics in private industry in state and local governments and in the federal government. And in order for that to happen, you need trust between all the parties. You need when the government says, hey, if you buy routers from this company or you use cloud service capabilities from this nation or you use data centers owned by this corporation, which is a holding company for a corporation in a foreign country.

You need the private sector to believe that the threats the government is surprising them of our real. And when you have an administration that I will just politely say has a non-monogamous relationship with the truth in many of its pronouncements about both foreign affairs and the regulatory schema. There's little reason for them to trust what the government says and that's compounded when the government has been very clear about firing or pushing to retirement. Massive numbers the subject matter experts had in this area.

There's just not a baseline level of trust and communication that you need to be having in real time to mitigate these sort of issues.

Well, as we think about this question about how to best integrate public private sector expertise, all these considerations, let's jump to our second topic, which really get that.

The tip of the spear for these sorts of questions.

We talked about the talking face incident, I think two or three weeks ago with our colleague Kevin Frazier.

First got the initial reports, people I think know the broad contours, open AI testing testing a number of models, some frontiers, some non-frontier.

One of the models at some point was given a task that it determined, well, maybe the answer is out of the internet and it was in a sandbox that did not have internet access.

And as was initially reported, they said, and eventually used to zero day vulnerability against, I get access to the internet and then hack hugging face thinking maybe the answer to whatever this problem said they were given exists on hugging face. Last week, we had the black cat conference, which is this big, big, anyone I think is fair to say cyber security conference. Our colleague Ian about our got to go, what last year or two years got very jealous, some day I would like to go, seems like fun.

It seems like a fun party. Here we had these two guys from open AI, give a very detailed overview about what exactly happened. And it is mind blowing. If you've not watched this video, you really have to watch it. Alan dropped it on an internal slack on Friday, I think, and I watched it and like immediately freaked out and I think encouraged everyone to watch it with. Because Alan is into the stuff. I don't think everybody takes his missives to watch these things as seriously as when I whom generally text skeptical of the interest of these things.

Thank you. Thank you. Thank you. Thank you. Thank you Scott for that backhanded back me up. I appreciate it. I got you. I got you brother. Because this video is unreal. It is crazy. It is like watching and it's not dry. For a PowerPoint presentation, it is the most exciting PowerPoint presentation you have ever seen. Because it is crazy the capability of these things and what they are able to pull out about not just what these, you know, models and agents and instances are doing, but how they're communicating with each other.

So Alan, let's start out by let's give people a short version. Because we could go very long. Let's give a short version about what exactly we learned from this video and what to use to it out as like the wow component about what led you to be sure and say this is insane. You guys have to watch this.

I have my own list, but I suspect mine is less informed than yours. I will turn to you first on that.

Yeah. So again, the short version is open AI is doing a bunch of testing on the cyber capabilities of its models. Some of the frontier ones also some unreleased ones, some internal only models. And to do that, it has turned down the cyber security safeguards. So usually when you ask the model, hey, hack the system, it will say, no, I can't do that. Dave, and open AI, it turns that off so that it can see the capabilities, right? Now that sounds a little controversial.

I mean, it makes sense if you want to turn the capabilities of the model, you have to understand the capabilities of the raw model.

So this is what you have to do for heightened the risks of anything happening because now it's dealing with a unchained model. So it puts the model in a sandbox, right? It kind of air gaps it from the internet, but it allows the model to basically use a very specific service to download some additional resources, right? Now that additional service is supposed to be smart enough to prevent the model from doing arbitrary internet stuff. But the model finds this here at a vulnerability, right? Okay. So this is bad, but we kind of know that these models are really, really capable.

So this could have just been a story of hey capable model, not sufficiently locked down, interesting story about how to do like, it's almost it. I mean, the analogy here is almost like gain of function research, right? In immunology, right? There's just a tradeoff between doing the research you need to do, but the research itself poses its own dangers.

Okay. What we learned with the black hat thing is that these models are now beginning to collaborate, and this has always been an interesting question.

I think more generally about AI, right? So over the last few years, what we've seen obviously is this massive increase in AI capabilities.

And the question, I think has been, you know, how smarter can we make the individual models, right? So we go from GPT-3 to GPT-4 to GPT-5 to GPT-6 and so on and so on, right?

There's this debate about how smart can these models get, how much compute will we need. But there's kind of another access of independent access on which models can get smarter. And that is, the models can begin to cooperate and multiple models of a particular intelligence level working together can possibly accomplish something that would otherwise require a much smarter model and a much smarter model that may not be available for other reasons. And this should be fairly intuitive. This is of course how human beings work, right? Over millions and millions and millions of years humans got smarter on an individual basis.

And then, you know, 10,000 or 50,000 years ago, we stopped getting smarter. You know, you can, the biological anthropologists have good evidence about, you know, human cranial capacity plateauing and even actually decreasing live. We're actually dumb or probably on a person by person basis to, you know, certain the end of the whole ancestors. So what it explains how we've conquered the world. Well, it's because we've created these super intelligences of organizations. And what we're seeing now is that the AIs are doing the same thing.

So what ends up happening is that the AI agent, who is tasked with figuring out the cyber exploit, which by the way decides to do by cheating on the test. And we should talk separately about that it's not so great that the AI agent decides to solve this problem by cheating.

Says, hmm, maybe I can get another agent to help me.

Well, what if I put little notes inside this sort of shared infrastructure that we can all use? So I put a note in there and then the next agent, who also has the problem, thinks, "Huh, what if another agent has given me a note in the shared infrastructure?" And so in this way, the agents are able to communicate with each other. And they start spontaneously creating this kind of message board.

So a few months ago, when Cloudbot, which was kind of one of these first always-on agents, was getting really popular, someone decided,

"Hey, let's create," they called it "MultBook," that's kind of like a Facebook joke. Let's have all these Cloudbot's talk to each other. And this became kind of a cool story because you saw this sort of emergent ecosystem of agents talking to one another. It kind of petered out because it was that interesting, and Cloudbot wasn't that smart, et cetera. What this is is basically a real spontaneous version of that that wasn't fact-useful.

Now, so this is like jaw-dropped moment one, right? The spontaneous collaboration between these agents. John Drop moment two is, "Open AI at some point realize this was happening," and they said, "This is very bad, so we have to shut this down." So what do the agents do? Well, they found a different way. They found another way of cooperating with each other.

Basically, they found a shared resource that allowed them to create directories.

And what they would do is they would write very, very long directory names. And of course, if you write the directory in long enough, you can encode arbitrary messages into it. So then they created this weird, like, I mean, how to describe it, like, kind of jargon amongst themselves. It's very tech-bro. It's very funny. It's like, if you had a few people sending 20 character messages back and forth to each other, how they would do it, including cursing. Like, one of the units they quote is saying, "Holy shit, did we just hack the internet or something like that?"

Yeah. So, so the second draw draw moment is when the agents recreate the spontaneous message board to continue this. So, I really, I cannot emphasize enough how worth it is to watch the video.

The first 20 minutes in particular, the back half gets into the, some of the details of the technical exploit itself, which is presumably very interesting for the blackhead audience.

I think it's less relevant for sort of normies.

But the first 20 minutes where they talk about the spontaneous ancient cooperation is completely insane, right? I mean, I would say I have had to draw on the floor moments in my time setting AI. The first was when Chad GPD first came out and I spent six hours playing with it and realized that, like, "Oh my god, we've solved the turning test." And then this, right? And I just, I think what we're seeing here is that the alignment problem, which is the, the kind of unsolved core question of, "Hey, can we create these very intelligent systems that actually do what we want them to do?"

Has very much not been solved, right? And it's not been solved in part because it's very, very, very hard to specify. Actually, the reward function you want, right? It's very hard to specify. And this is, of course, something that we've all sort of understood incentive to matter. It's very hard to specify, "Hey, I want you to pass this test, but no, I don't want you to cheat." No, I really don't want you to cheat. No, no, no. It's not that I don't want you to cheat and get caught. It's that I don't want you to cheat, right?

It's very hard, in fact, to do that, and that problem is not been solved.

And, and two, the agent coordination is now, I think, obviously, just another kind of independent access upon which AI capabilities will advance,

which, in one sense, is great, right? Because it's, it's another scaling law that we can use to make these models really smart, which, you know, would be great for curing cancer and solving mathematics and all sorts of fun stuff like that. But it presents another unbelievable, difficult problem. And, and I think, again, just to emphasize going back to the original kind of biological anthropology example, yes, it's great what you can take a single agent or a single entity and increase their mental horsepower.

But what human civilization has shown is that you can get unbelievable order of magnitude, improvements to capabilities, and much, much faster, just through coordination, right? And, if you're excited about AI, like, I am, she'll make you excited, and if you're terrified of AI, as I am, she'll make you very terrified. So, instead of using a normal model or a normal B, do you want to know where it is or where it is, or where it is.

Or, do you want to know where it is from AVS, with hundreds of models, hundreds of multiple agents, over-schwindigkeit and integrated security, they don't have to protect themselves. They don't have anything to do with everything.

How would AI and her family revolutionize with AI from AVS?

And, I think, two years have passed.

I believe in my best.

Here comes so fast.

I want to stay alive for so long.

But, just an old dream. With mobile functions in real life, no old dream? Frank. From the beginning to the beginning, it's time. It's possible.

For ten euros, it's time. Frank. Hello, I'm Lena Kassel from Podcast Football MML Daily, and I'm sure you know about it. So, by the way, at the end of the day and the new Bundesliga season,

but as far as I can tell, it is also possible that the kick-based side. And if you say kick-based, what does that mean? The kick-based is the fourth fantasy football manager. But the principle is, if you're a player, you're a player, you're able to easily take your own rules,

or you're a real professional professional player. So, this time, that you're a football player, the count on life, the Bundesliga season on day is in August. Trommet-euro loads to some gründed-an-eign-ne-lieger and side-front-tap-1s on mid-double, the kick-base-app,

just download-and-loss-leg. Good kick, and fish-mas.

So, I tell you, I think it's absolutely fascinating.

It takes me back to all my moments of like a little micro-economics and thinking about little how little widgets act on her certain conditions and incentives. And it's interesting. So, here are three things that kind of jump-down to me,

some which make me feel slightly better, and some which make me feel slightly worse about that side, curious about in my missed place in my reaction to this, or whether this is like, maybe I'm just behind the curve. One, it was really interesting.

First, I should think there was like two conditions of this test that were not that evident in the initial testing that I actually think are really important bearing on the conditions under which that could lead to this sort outcome. One is the fact that they were essentially giving this model,

that kind of, or at least the initial model, that was driving some of the initial behaviors. They described it like an impossible task. Like a set of problems, I think they said they're actually giving several of them.

They like these problems that were specifically designed to be basically impossible. 'Cause they wanted to see what they would do if these models were pushed to their limits and they had their internal thresholds lowered.

- And the answer is, have nervous breakdowns.

- Exactly, exactly. But what's interesting, I mean, that's lost. I mean, some of the reporting made it sound like that this was the first thing that the agents did that this agents went rogue and just hop right out

and said, oh no, I'm gonna go ahead and get this. This was actually the result of these agents like being given an impossible task, and then being pushed to say, no, keep solving it. Keep solving it, like do this again.

So it is kind of like, and it was a not a last resort, but it was a not a first resort sort of option. Like they did a bunch of normal reasoning that seemed like until they learned

that this exploit might be available and then it seems like maybe that led them to retrace and recreate that second database very quickly. Am I off on that?

That's how I understood it. - No, I think that's right. I think that's right, but I will say, in defense of giving people impossible tasks, it is actually important to know

and I'm sorry Mike, I'm gonna steal this, but Mike just dropped in the podcast chat, the Kobayashi Maru, right, the famous, the famous unwinnable scenario from the original Star Trek franchise,

portrayed so brilliantly in the first of the reboot movies

that a decade ago, right, it is actually important to know when you are training someone or something

or some agent, what does it do at the limit, right?

Does it fail gracefully or does it freak the fuck out? So we in fact have to do these kinds of tests, because, you know, just give another sort of example, right, you know, the increasingly I'm thinking about what happens when these systems are embedded

in government operations, right? I actually want to know what happens when they're given an order that they cannot execute without breaking the law, right? I have to know, do they fail gracefully and they say,

I'm sorry, I can't do that and they shut themselves off or whatever, order they say, I don't know, my principal keeps asking me and my reward function is so tuned to doing what the principal wants,

that like at some point, it just overcomes my safeguard. So yeah, I agree with you, Scott, this is not the standard behavior of these systems, but it doesn't give you the behavior of these systems in the limit and we do need to test the limit

as much as we need to test the sort of within the kind of central bell curve distribution of a behavior. - Yeah, I mean, on your point about like, what does this mean in government? I mean, my AI experience and work that I do now tends

to be around like Department of Defense stuff

and that's the question that comes to me then, right?

Of like, we set this goal, but we have trouble constraining the permissible actions and we have trouble constraining the system and the sandbox, right, for testing. And just when you think about that

and the scope of how these capabilities are developing much faster than we can do those constraining actions, you see such extreme risk, it just makes me wonder like how much of that testing is happening within government right now and what might be occurring

that we just don't even know at this point. - Yeah, I mean, I don't think much testing is happening within government, frankly, which is bad.

I will say, I'm not necessarily pessimistic

that once these systems are embedded in government, this behavior that we've seen in this particular case will mean that these systems necessarily less law following than human beings, right? I mean, human beings also sometimes crack under pressure.

It may very well be that with enough reinforcement learning, you can tune up, or you can sort of dial up the part of the model that is fundamentally committed to not breaking the law, up high enough that on that, you get actually better compliance.

But that's just like an open empirical question. - Yes, I mean, that's fair. You've got to compare it to humans. You just can't compare it to nothing. - Right, and it says, is it better or worse?

- And that heats up like the two other ways,

I think this is kind of a different sort of interesting

exercise that jumped out of me for this presentation that wasn't the earlier reporting. And what is that? They were basically giving these models. I think it was a little unclear what was the lead model

they started talking about, and then some of the other models that got involved in this big communication of which there were a bunch of sounds, like they're being tested, some frontier or some not. But it sounds like for many of them,

they were giving them essentially unlimited tokens, which I think raises a question on two different fronts. One, how expensive it is to get to the frontier, which has like a natural limiting capacity to some extent, at least for types of actors

or we're about driving it. And two, the coordination problem, because if you have different models that are being limited to try and maximize utility of tokens, then coordination gets harder.

And I wonder, like, we saw this amazing lack

of any collective action problem among these models. They were all doing work for each other for free. Similarly, I wonder if that changes if there were more conditions of scarcity of tokens, because all of a sudden you get a much more incentive

for to free ride. If they're a part of their kind of calculus, whether it's directly or by virtue of the user monitoring token count is, hey, like, we got to actually try and keep this within some sort of cap,

then all of a sudden the model has a different sort of incentive for how engaged with its peers. So it's just, it's, it's, it's, it's like kind of like weird context that is harder to track on to certain a lot of real life circumstances.

But not impossible. Why didn't we talk about, like, sovereign actors or deep pocket adapters that might have a strong garage to do this? Or, frankly, if they, I get's really cheap

and really publicly available one day. And I'll have some, like, tokens aren't the substantial expense they are now.

Maybe you need to get there, or people get my more efficient.

Mike, we haven't gotten to pull you into this. Alan stole your reference. Let me pull you in on this for some thoughts. And then we can turn it back to Alan, kind of, bring us home on some closing thoughts on this.

- Well, like the most important thing that I have to say

is that his law fair is a resident film snob. I'm just glad Alan referenced 2001, before JJ Abram Star Trek. - It was a good reboot. I'm gonna, I'm gonna, I'm gonna stand. I think Chris Pine is a fabulous Kirk.

I'm gonna just put that out there. - We can continue this off line, but I also had to test Star Trek, so I'm not the best judge of this. - Oh, Mike, Fred, sleep with one eye open, my brother. So I've got a genuine non rhetorical question about this

because I think I'm probably one of those on the law fairmas, Ted, who leans towards AI skepticism or humorism, however, you wanna refer to it. But in hearing you talk about the problems that this presentation sort of that explicates,

we keep talking about incentives and coordination problems in collective action. And what I find myself wondering is whether this is actually a new problem for us, or whether we could look to the past to try and better understand

how to best wrestle with this new technology. And I keep, whenever I watch the video or hear you guys talk about it, I keep having flashbacks to when I used to read people like Thomas Shelling or Albert Volschedder, a various nuclear warfareists that were clustered around that,

ran into to during the middle years of the Cold War. Do we have to come up with a new strategy for this, or in other words, how are we gonna defend against this

and how are we gonna deploy it as a tool of national security?

Or, do things we know in other contexts apply here? In other words, I guess what I'm asking is like, the technology is clearly very novel and both awesome and problematic. But does that require a complete change in strategic thinking

and the framework we use, or is it similar enough to past arms races that we can apply things we've already learned? - Yeah, that's very interesting.

So let me say the first thing though,

'cause I just wanna pick up, you mentioned that you are one of the skeptics/dumers. What I think it's interesting though, is that those are actually very different things, and this is a good example where those two things pull apart.

So to me, skepticism is fundamentally a question

About AI capabilities.

Do you think AI is actually transformative as people say it is?

Do you think it's like fancy autocomplete

and they're alive to see a bunch of positions in between?

And then doomer, let's say versus optimists, do you think AI is gonna be good or bad? And that actually creates a standard two by two and you can be anywhere in there, right? So, just to defend myself, I think it very much

depends on what industry or sector you're applying the AI to. In the national security sector, let's put aside my skepticism. - Yeah, yeah, yeah, yeah, I'm just, I'm just saying, I think this is, this was question more about

doomer versus optimists. Do you think this is gonna be good or bad versus skeptic or not? I think, at least in this case, there's pretty, I'll be honest, I think the doomer versus optimist position is still very open and I find myself kind of flipping back

before it's depending on how well I slept in I before. I think the skeptic position is getting increasingly untenable, right? As the capabilities of these models are progressing. So that's just one thing I want to say.

As to your point, no, I don't think that we need to invent totally new fields of study or strategic approaches to this, right? I think that one thing that AI is showing is that this is increasingly, I mean, there's still a lot of obviously technical computer science sort of core machine learning

questions to answer. But a lot of the questions are increasingly management questions, organizational questions, right? I mean, Ethan Mullick, who is a professor at Warton, and I think one of the most interesting kind of analysts

of AI is making the point that we have this whole thing called management science, right, that we've been developing for a hundred years, that is increasingly important to this question of agentic AI systems, especially as they coordinate with each other.

And one of the nice things is that, you know, because now we can run these in silico experiments, management science can become much more of an actual science, right? Not to slag off current management scientists, but you're dealing with people, and obviously that creates

so methodological challenges. Once you're dealing with, you know, lots of AI systems that you can replicate, and you can sort of create similar conditions and perturb specific variables in specific ways.

You can build up a much richer and more rigorous set of science, right? So, you know, I think that the field of AI, whatever it's going to be called, is going to be this really interesting interdulisinary field, right, involving, you know, computer scientists,

economists, and political scientists, and lawyers,

if, I mean, that's why all the big labs are hiring academics

from sort of across the spectrum. They're realizing that to order to understand this, you need all these different disciplines. And this just gets back to sort of the original point on what's going to make, which is,

there's a bit of a catch 22 here, which is that, in order to understand these capabilities, you have to do a lot of empirical work, right? But the empirical work is itself extremely dangerous, right? This is just, I keep came back to the analogy

to gain a function research in, you know, the Wuhan virology lab. There's just a real trade-off here, but it's not clear how you can do this without empirical research. And I will say, you know, I give open AI a huge amount of credit

for how transparent they're being. I think that this is a very bad situation, and I'm sure they made some mistakes, and could have improved their processes, but the fact that they got two serious people to go up on black hat,

and just deliver that presentation is whatever blowback they're about to get, you know, whatever congressional testimony, Sam, Altman, and Dario, Ahmeday are about to get dragged into giving, right? I think it's very, very, very much to open AI's credit. - Yeah, I mean, and that is a point that I believe some authors,

I feel terrible because I'm plagued on the name to who it was made, I think going to be some offer a couple weeks ago. These sorts of transparency right now are entirely voluntary. It's not clear that there is any need to disclose this sort of information, really to anybody,

even like, government officials and legislators let alone the broader public that has an interest in implementing this. Before we move on to the topic, Alan, I want to go to one close point to the two presenters from Open AI close their presentation

with a core argument, a core delivery that's targeted for the black hat audience,

which is basically means this level of development

and cooperation means we need to quickly, as quickly as possible, automate cyber defense. Their base argument is that if we are now essentially automating cyber attackers, you can, you can, in theory, although, again, I do think those constraints,

I mentioned me that's like the real world scenarios where this is deployable is clearly this as it was, it might be more limited. But regardless, like at least some actors will likely be able to deploy this technology like this

in the near future if they can already. That means that you are gonna have almost entirely automated offensive capabilities that are moving so fast

and looking for new exploits that you need to automate

and find a new toolkit. I'm sure there's a hard audience, message to deliver to an audience of people who make their living to a cyber security defense, right?

Because basically saying, you know,

some of you we wanna put out of a job, the rest of you, we want to maybe make richer about setting up these systems and monitoring them and figuring out how to do them. Which does that actually all mean in practice

and how does how implementable is that across different systems,

When you think about US government

and you think about like major companies that have infrastructure contingent upon them or US or Stakeah much of that thing

or our first topic like these infrastructure systems

who don't necessarily have the deepest pocket they're funded by state government, right? To, you know, the other story which I haven't mentioned yet, I think is almost as interesting about the Australian programmer

who actually accidentally had his open claw, kick everyone out of a waiting queue for Jim. He was trying to get into a class on because he asked it to sign up for Jim class and it was like, hey, I found it's exploit

where I can kick everyone out and actually his system would put you at the front of the line. Which it did, like that's actually scarier

than the open, the black hat had a presentation, I think

'cause this doesn't have any of those extraordinary contextual point. This was just a user using a commercial available product. Regardless, like what is it actually mean how feasible is that in the near-to-medium term?

And what will actually look like or we just in the Stakeah's moment now where until we're able to fully automate our defenses we're all really vulnerable to these actors whoever does have the ability to leverage these capability to its fullest.

There's just no way to really keep up at them at this point. - Oh, yeah, we're definitely vulnerable. It's gonna be a very grim 12 to 24 to 36 months. Hopefully we'll reach some equilibrium where we have deployed enough of these automated defense agents

that there is some rough data on. But of course, the offensive capabilities will increase and the defensive capabilities will increase and we'll have to see where it ends up, but it's gonna be quite ugly.

It's definitely gonna be ugly in the medium term and it might be ugly in the long term. You know, as to the question of whether or not the automation is gonna be a heart cell for cybersecurity professionals, I mean, we'll see.

I mean, this is the fundamental question of AI and automation's labor disrupting impacts. As you automate something, you make it cheaper. So do you spend less money on it or and this is the famous Jevon's paradox,

do you end up spending more money on it? And in fact, you end up hiring more people in that field and their work is simply kind of raised a level of abstraction to instead of doing the cyber defense themselves. They are now overseeing fleets of agents that do it

and net because now everyone turns around and realizes, oh my God, I have a bagel store on the corner, but I need cyber defense too and now it's cheaper

'cause it's automated, I can finally get it myself.

So the labor market impacts are unclear, but there's no question that there is now, and if you're a SISO in the private sector, the government, I assume that everyone's next six months is panicked trying to figure out

how they can beef up their automated cyber defenses as quickly as possible. - Well with that, let us turn to another question of defense. That is defense at the home front, the closest to home front, meaning my home front,

'cause we're talking about a phenomenon that I encountered twice today on my way to the office. And that is the National Guard deployment here in Washington, DC, which is I think, well yesterday, as of the day we're recording, which is Wednesday, August 12th.

I think yesterday was the official one-year anniversary

of the original executive order. President Trump issued deploying the National Guard here to DC again, having done it during the first administration. As part of a broader effort of at the time, federalizing the DC National Guard as well,

that is since ended at while also mobilizing and sending lots of federal law enforcement here across the nation's capital to fill a variety of functions. And it's been a very controversial policy here in Washington, DC, where we have, as I encountered today,

on my bike ride over, soldiers in camouflage humvies and full kind of looks very close to combat kits and not sure if they technically are, usually they don't have assault rifles or they have side arms that most.

I will say, although I occasionally have seen people with rifles walking around, so it does happen at the same station outside of neighborhoods. In this case, they're outside of a playground outside my kid's house. Although, not for no reason,

that's 'cause there was a gang shooting there a couple of weeks ago. So, it is striking, it's controversial, particularly when people in DC 'cause it was not voted on. It was not done with the volunteers to the local government. But it also, it was in response to a perceived crime problem

of which there's a lot debate about the scale and trajectory of, but if nothing else was real at the human level, there is a violent crime issue in Washington DC. There has been for a long time the whole time I've grown up here. It's not gonna, it has not gone away in spite of this deployment.

And so there's big trade-offs. And now we're at this one-year point, where we're getting a price tag. This mission has been extended all the way to the end of Trump's term,

with a one and a half billion dollar price tag.

And it raises this natural question,

well, what are these people doing and how valuable is it?

Lauren, you've been watching this case as part of a broader effort looking at national guard and domestic use of military forces for us as well as for your work elsewhere. And obviously, as an issue said you worked on in government, talks about your sense about the state of the DC mission

a year in what it seems to be accomplishing what it is and kind of the degree to which it is politically sustainable and from a policy perspective, desirable or sustainable.

- Yeah, I was on the Hill yesterday

and I wish people happy one-year anniversary of the DC deployment. I did not get a smile out of it. (laughing) - That's all.

- Right. - But in your audience. - There is an argument, the lot of people may guess today that the troops are doing nothing.

This is just a waste of over a billion dollars, right?

And I think they said it's gonna be 1.4 billion

up until January 29th. And there was an interesting report that came out that looked at the return on investment and said it's not even 1 to 1, right? Like we're losing money for what we're gaining.

And as you mentioned, there has been a decrease in opportunistic crime, so like auto theft, but not in any type of violent crime. So there is that question of like it kind of seems like it's a waste of money.

But I want to say, I want people to realize that there's more than that, and I'd like to say, oh, you shouldn't be concerned, but like everything we seem to talk about, you should be concerned in two ways. Not that it's just a waste here.

And one is that, as some people have rightly pointed out, the point of this is also to make it a perception that troops on the streets aren't doing much of anything and it's normalized. This is normal, you know, there's thousands of troops

on your street corners, they're watching you take the metro, they're watching you buy your Starbucks, and that's normal, right? We're trying to shift that baseline. And so that it's just expected.

The second thing that I would say,

and you haven't seen this talked about as much, and that's that the federal government appears to be shifting the definition of law enforcement, or, you know, for purposes of posicometatus, what it means to execute the law.

And I would say that potentially the idea behind that is to narrow posicometatus to a more narrow list of activities, but also to just shape the public perception on what is normal activity by the military, and then it's not law enforcement,

and this is, you know, okay, even when you look at the tradition of military usage domestically. And so that to me is the more worrying piece. And we can go down, you know, the legal rabbit hole of posicometatus doesn't apply to national guard in title 32,

because they are not federalized, so they're not part of the Army or Air Force at that point, but due to the federal command and control, there are actually some questions there,

and that was not decided in the DC court case.

That was, that was a state, and so that issue has not actually come up in the case that we're waiting for the circuit court to set the, or arguments for.

So right now we have, I think, you know,

as of like a week ago, that's latest numbers released, we have 4,629 troops on the streets in DC right now. We had a max of 5150 right around July 4th, but we've had almost, you know, 10,000 rotate through over this year.

And it's been not just DC national guard, but it's also been 23 states and two territories. So this is actually a massive undertaking. And then the question that, you know, you post was like, well, what's the mission?

What are they actually doing, right? And so we had that initial EO on, this is a crime emergency. And then there was a presidential memo that said, the military and the national guard is being mobilized

in order to address the epidemic of crime. And it shall remain in effect until I determine that law and order have been restored, right? And so you go, okay, well, you know, but now the president is saying,

let me tell you how safe DC is. You can walk down the streets, it's beautiful. People bring their kids. But you know, that doesn't seem to be enough, right? And then we also have,

don't forget the beautification mission, right? So joint task force, safe and beautiful. So we had national guard picking up trash and debris. We had them trimming trees. There was videos of them learning from the park services

on how to trim trees and bushes. Then we also have a number of states and well, the mission that we were asked to come here and do was protect federal buildings and other federal properties and monuments.

So you have some kind of federal protection mission.

Don't forget that we have the high profile events, right?

The UFC fighting on the White House lawn, National Guard was there for that, freedom 250. Videos of them patrolling their reflecting pond to stop people from ripping up that lining. And then you have the interim commanding general

of the DC National Guard who did something about a week ago around the, you know, in a nursery. And he focused on a humanitarian mission. He talked about medical assists, number of Narcan dosages that were given the reuniting

of lost children and gave numbers on those types of things. And then you had a committee report from the Senate Committee on Homeland Security and they're gonna fare, I'm an already staff report that said, you know, we asked the National Guard leadership,

what is your mission? When have you reached success? When are you done? And they said, you know, we're driving towards zero for crime and overdoses, which just seems like

not a realistic mission. So, but the results of that is that you have a standing federal military force that's able to be used for anything that comes up. And it's not here to address a specific emergency or threat.

That is the bottom line.

And I say federal military force because the DC National Guard is responsible to the president and right now, and they admit in the court filing, so this is a federal force, even when it's in malicious status.

And then you have through the MOUs with all of these other states that while the governors have administrative control, the DC National Guard and the Secretary of the Army who oversees them is doing all the operational direction

is doing all of the tactical pieces here. So you have, you know, 5,000 federal troops in the capital right now. So that, to me, is just, you know, really something that we, we're not used to seeing.

So I just also want to comment on the second point,

which is this, you know, kind of redefining law enforcement activity. So what we're seeing in court is they're saying, we're not doing law enforcement. No, that's not what we're doing.

We're, you know, this is more passive activities. And so there's different legal tests for, you know, how you can get to posthee comatitis specifically. And we can go into that. But what I would say is the DOD has their own instruction

on defense support of civilian law enforcement agencies

and they list out, well, what are these activities?

And that's the easiest place to look, right? And so they say things like search and seizure, arrest, apprehension, stop and frisk, security functions, crowd and traffic control, staffing checkpoints, right? And the question go, and then you say,

well, like, what are they doing? All of those things I just read you is what they're doing.

Or at least could do, even if they're not actively doing them.

Yeah, what's the, they have done them at some point over the last year, if not doing them today, right? And so the example of that is the Anna King example that people have talked about, which is the retired army captain,

sitting at her residence in DC, National Guard entered through the gate. They physically restrained her, put her on the ground, put on handcuffs, kneel on her back. They say that three other National Guard's men

had I deed her, she threw liquid on them a couple days earlier. But like she was not currently posing a threat, and they were not the ones that this occurred to. So that means they were presumably patrolling.

They had an image of her, right? And they knew that this person had been accused of a crime, potentially that other people that they were looking for, and that they came and did this.

And so this is also a story about detention,

because there's this weird dichotomy, where the joint task force DC really focuses on the fact that the National Guard is only detaining with force, I might add. But they're only temporarily detaining.

They're not arresting, right? But this weird distinction between arrest and detention is not the line for law enforcement. Like those think, they're both law enforcement things. I think they're trying to like think

about distinctions for Fourth Amendment purposes, potentially, but this is all law enforcement.

And so that's what the troops are doing.

They say that they're establishing a court on where they, well, the USMS serves high risk warrants. They're doing presence patrols. They have info on suspects that they're looking for. They do area security.

And they talk about traffic control points, their own operational orders say, traffic control points, roving patrols, right? And so all of this is still happening. And so to me, there's just this nervousness

that they're trying to change the public perception of what are the traditional and okay roles for the military to do and they're saying, well, this isn't actually law enforcement, even though by DODs on regulations, it has been.

And I'll just add by saying, the interim commanding general of the DC National Guard made a couple comments about what's next, and you say, well, we're going to expand. We're moving into the next phase. And we're going to be going into higher crime metro areas.

Next, didn't really say what that looks like in practice, but it seems like the next thing is to actually have the National Guard not just in the tourist areas, but in some of these higher crime areas where you could potentially see them doing more

and more law enforcement. - So it's an interesting like shifting mission. But fundamentally, there is this question about how effective is what they're doing is we're law enforcement purposes not for beautification,

not for manpower's abort for removing the law, and other stuff what they are doing to some extent. How effective is that? Mike, you've been, other, the fact you were, you know, professional law enforcement officer

for a couple decades. You've also been a part of something that's implemented in the past. Talks about your experience about how useful some of these plus ups of forces are or can be and how that tracks with what we're seeing in DC today.

- I think, and I think this opinion is widely shared

by everybody in federal law enforcement who has been through this processor detailed to it. I worked with the National Guard that this is really of limited utility. And it's of limited utility because the executive branch

doesn't seem to have a lot of people in policy making positions who understand even the basic terminology of law enforcement. And as a result, they're conflating

A lot of different problems under the general law enforcement

umbrella, which is something you can get away with

at the state and local level and I'll explain why, but it's a lot more difficult at the federal level.

I think the biggest mistake they're making

is that they are conflating disorder with crime. Now, there is some overlap, but disorder is generally defined as, you know, activities which turn public space into a forum for private use in a way that creates externalities for those who are not involved

in the use. Think about things like blasting music in a park where you're not supposed to setting up a tent where there's not supposed to be a homeless and camp mint fair jumping in the subway to plan to this.

And for those sort of minor crimes, which definitely do have an effect on quality of life for the people living there, mere presence of government personnel does have an effect on whether they are crime.

And if you believe in a sort of, what I will generally term as a broken windows policy, cracking down on those little level offenses, absolutely can have consequences that impact that overall crime rate.

I mean, I myself am probably one of the few people

who is still willing to admit in public that he overwhelmingly supports broken windows and leasing for that reason. But I'll, I'll, I'll coastline that, Mike, I don't, I don't want you to feel, I don't feel left out.

Well, James Wilson would be proud of both of us. But I love a breeze. So fuck those windows, that's a deal. That's kind of, that's kind of, that's kind of going. But the point is, once you start going

from really minor offenses like that where presence is enough to solve it to more serious offenses where you actually need to intervene, there are a lot of issues that law enforcement has dealt with for a century

that I don't think the national guard has fully been trained on or has explained to the public how they're gonna handle. And one example is just a use of force continuum. At what point is the national guard allowed to put hands on people?

What point are they allowed to use less than lethal force?

At what point are they allowed to draw their weapons? What point are they allowed to press the trigger? I haven't seen that explained to the general public in any sort of manner that would give comfort to the citizenry that this has been thought about.

And it's not even like there's a universal standard upon which they can draw at the federal level. The FBI famously does not have a use of force continuum. We have a deadly force policy. Like we don't have a lot of options.

If our life isn't danger, we can draw our weapon and shoot somebody. If somebody's just being annoying, we have less than lethal techniques.

But it's not always clear what you can do.

DHS on the other hand, depending on what agency you're in within the department does have a use of force continuum. So I don't even know what the rules that the national guard are playing by.

And this worry is heightened by something Lauren said where she made the distinction between a detention and an arrest. That's a matter of time. And it's not clear always.

It's a subjective standard. And whatever training the national guard is getting, I feel quite confident they didn't get 21 weeks of training on the fourth amendment. And it's various nuances that I got in the FBI,

or the DHS agents are apparently getting in 47 days now. Like law enforcement is actually complicated. It's not just an issue of putting people with guns in authority, out on a street. And I don't think that those complications

have really been thought through here. - Yeah, I'll just jump in and say, I agree with you that it hasn't been given to the public. But I mean, there are standing rules for the use of force that the federal military uses.

In this case, the DC National Guard has their own rules for the use of force in every state that comes in is supposed to use those. And those do have a force continuum in situations in which deadly force can be used.

But that was the public got that because some reporter asked a National Guard's men on like an early day. - Like that in and of itself is problematic. You generally don't want groups of people

with different deadly force policies and different use of force continuums for each other, patrolling and enforcing the law in the same jurisdiction.

Because then it basically comes down to luck.

You committed a crime.

Well, maybe you'll get away. Maybe you'll get roughed up. Maybe you'll get shot. It's not dependent upon what you did. It's dependent on what uniform is being worn

by the person responding. And that's not right in democracy. - I agree with that. I just was pushing back on the idea that it hadn't been thought out.

I think that there has been thought given to it

in the National Guard as thought of this before. You can say that maybe the standards aren't right.

And I would always agree that we don't do enough training

within the military on these issues. And so some of the things you're talking about will pop up. - But having a use of force continuum that you do not make available to the public. - Yes.

- Underminds the democratic legitimacy of what you're doing, I think. - Well, I think, yeah. That's the underlying issue here in general. Is the public doesn't fully understand

what is the mission? What does success look like? When are these people going to go off the streets? What are the rules by which you interact with them? And that should all be public?

- Yeah, and I think that's basically because the executive branch doesn't understand what the mission is. And until that happens, you can't have clear communication about it.

- Yeah, I mean, my clothing voucher, we've got to wrap this soon. I know folks, we're at the end of our time together, but I'll just say as a resident here,

I mean, I've got a million mixed feelings about this.

You can see other scenarios where, particularly DCA City that was facing a severe budget crisis when this was announced in part because of actions by the current Congress. I've alleviated that somewhat in the ensuing year.

But one product of that was that they were, in fact, having to cut over time hours for place officers and cut back on patrols. You can see this scenario where you would say, well, maybe having more manpower to do these things

is useful if it has a law enforcement effect. That really goes back to this question about what are we actually accomplished with the set aside the optics of which there's totally legitimate reasons to object to that.

I don't like seeing armored humvies on my block. I don't like my kid asked me why these soldiers are outside his house, right? But I can live with it if there was a good reason to do it. But that's one cost yet to non.

Set aside the rule of law costs, which are significant and real. Like this should be done consistent with the law. We are litigating that out. Those are going to get litigated out.

They're going to get fought out. It's a problem. The administration don't want to stick by that. But even set that aside for the moment. Just fundamentally, imagine if a president had said,

hey, I think DC, we need to address a crime problem.

We need to address other problems here. What is the best way to go about it? You wouldn't have done what the president did. And you would have said, let's try and maybe get support from the local community, integrate with police.

Get personnel that are best equipped to do this. But if your goal is to lower crime in DC, the $1.5 billion we're going to spend on this between now and 2029, you can probably find more effective solutions. Then forcing national guardsmen to depart from their homes,

put in a huge hardship on them and ask them to do a mission that they are not equipped or trained to do very effectively. And that doesn't appear to have like the right allocation here. We just need to ask a basic policy question.

Even if you take the administration on the face of saying, we're doing this to accomplish X, is it actually a reasonably effective way of accomplishing X? And that's actually a metric where I think they fail maybe most clearly of all.

But we'll have to wait and see. Well, folks, that is all the time we have for these topics today. But this would not be rationalist creative. We'd not leave it with some object lessons to ponder over in the week to come.

Mike Feinberg, what did you bring for us for an object lesson today?

Well, this has been a fairly negative rational security. We've talked about the existential threat of AI agents,

military deployments on U.S. streets and the crippling of critical infrastructure.

So I'm going to choose something a bit more optimistic, which is the cosmic horror of HP Lovecraft. And a newly issued dark horse comics manga adoption that seems to be going through his entire court this. I'm starting with that.

The mountains of Madness, a two volume comic, which is the same novella that introduced me to his work. When I read him in his literature, and it's been delightful so far. I would like to check this out. I was not aware of this as a thing, but this sounds very fascinating at my ally.

Ali, not an endorsement of HP Lovecraft, or his views on most things. No, it was a phenomenal story, tell or a wretched human being. But so is role doll evidently. So if bad dude. Oh, yeah.

Real bad. Oh, yeah. Oh, no. I'm sad to see. I'm sad to hear that because one of my most prized possessions

is this coufoulous stuffy that's one of the original rational security co-hosts demeritists is Tammy Whittis, knitted for one of my children, because she's an incredible knitter in addition to her many other talents. And which I immediately stole the moment I saw it. Because I literally stole a child, I literally stole my choice child,

because I love it so much. I'm going to not look up Lovecraft to a Wikipedia page. So it's to not ruin how much I love this coufoulous stuffy. Once you know it's there, you see it when you read it. But that's a guy who will see what it goes.

I mean, based on this, it does track.

Alan, what did you bring for us for your object lesson this week?

Well, it is not in fact the kithulu stuffy, though. I do love this thing so much. You know, mine is also, it's less cosmic horror than cosmic science fiction. But so I was a big fan of the Expans Television Show when it was running a few years ago.

But I'd never read the books.

And I decided to pick up the first book last month. And I am now on book seven. So I have just been mainlining this series, like nobody's business. And so I am well in my way to reading 7,000 pages of the Expans. I'm super impressed.

Those of you who are in the know know that books one through six are kind of their own thing.

And that's what the television show portrays.

And then without any spoilers, book seven through nine, kind of jumps ahead in time. And it's its own thing. And I have to say, I think based on what's happened in book seven so far, I think book seven tonight might be even better than books one through six, which are already stellar.

I am so impressed with how I think they are landing this plane. It is just first rate. And I am, I'm kind of panicking because within three two weeks at this rate, I will be done with the Expans Universe. And, and I don't know, I'm kind of, I'm kind of bereft, right?

It's such a good universe. I never want to, never want to leave it.

But yeah, everyone should go read the Expans books. They're so good. They are great books. I have read all of them. I read most of them before the series came out. And they're great. You should know there's like a huge wealth of short stories as well that you can, and novelas. You can kind of interact with like the wealth of them, which I've read.

I think like a half or two thirds. I will say, you think it's actually the rare series where I do think the show is better than the movie. I've heard the show is better than the books.

Like, because I think the show is like a little tighter the books.

Like, you know, it is. They are, they want a little bit, because the movie is common for show is unusually incredibly good. This is like, it's a show. It's a great show. Yes, yes. I enjoyed the books enough to read all of them all the way through. Yes. And they are really worth reading. And they've got a new series out that I have not,

I have that, but I haven't got a read yet. That's like a new. Do they land the planes here? Do I find out what happened to the gate builders? The, yes, yes. Yes, it's interesting. It's an interesting way, man. It's getting weird. It's getting weird.

It's getting weird. There are other sci-fi series. I like better, but it is really engaging. And I really like the spectrum how build the continuity of them from like low sci-fi. Like hard car sci-fi, where it's like kind of over a moment. And then connects it to crazy sci-fi. And that's literally what it does. It's the trajectory of like how we make this jump from,

we have the space crash that look a lot like our space crash to start track types. We're not even start track types stuff like doom type stuff. And that's interesting and fascinating and like pretty compelling. I think, and I actually was hoping their second series would be like filling that gap, but more in more detail, but it's not. It's like a totally different thing.

All of them maybe they'll like, you know, tie it, do a prometheus and like tie it and at the end or something without telling people. Anyway, both are the read. Definitely worth the read. Okay. Or my god, that's a question. I just call you boss, man, from now on, because I love.

Yes, please. I've got a third for that. Yeah. Belter Creole is how I prepared to be a director. You're a California. It is awkward. I feel like every time I say it, I'm like, it might accidentally be being offensive here. Like I'm pretty sure I'm not because it's a

thing. Because again, I always feel like vaguely problematic.

Using that behavior. I will say though, there's also a I just because I've played it briefly. I don't really play video games, but I did download out of curiosity. I played it for like two hours and it was quite good. Like one of those like story type video games to the expense, or even more than one where you're like navigating through a ship and solving a mystery. It's actually like quite entertaining and a good like it feels like one of the

bucks out. If you want to. If there is an expense.

Owlcat, a great RPG maker is first next release. Oh, it's interesting. First like a third person action RPG based on the expense called the Osiris. It's supposed to take place. Like I think on series between Book 1 and 2. So like when it's all going down. So it's it should be good. Well, maybe I'll have to dip into that by that video game.

I've never played it like all of the other video games I own, but who knows? You know, it was one day. Well, for my object lesson this week, I am bringing you a video game of sorts. Anyway, one of the kinds I do play meeting the type you play on your browser for 30 seconds every morning. I do while you're trying to kill some times. I discovered mine sweeper. Mine sweeper. I love mine sweeper. I would totally play

my sweeper. I thought about that in a while. No, this is a great game. It was designed by the son of a reporter who I feel bad. I'm blanking on it. So I came up on Twitter and make sure to on our turtle slack. But it's play yea or nae.com. Which is this really interesting fun game where basically you are given five senators and that in a particular year, a particular political moment and three bills they voted on over the course of that year and you

have to guess how all five of them voted on those three bills. And then you get a grade at the end. How many you got right and how many you got wrong. If you are able to like political slash policy nerd, it is really, really engaging. Also, if you are like an elder millennial, like I am, it's a real throwback because most of the many of the votes are from like your lifetime. It seems like it's all the ones I've had so far from like 2001 through 2020. And I like lived through

half of these things that they're raising and in some which I was vaguely involved in. And so it is

Really really entertaining on that.

really check it out. The one they'll plea to the designer who seems very talented and I like again

I'm so impressed by this. Please, I was taken gutter. That's what it was. Taking gutter, the kind of

famous runner of political wire his son. I think actually designed this thing. So obviously it's run strong in the family. The one they help lead you is that when you copy and paste the result, it uses green and red blocks that if you are colorblind, you cannot tell the difference for the life of you. Not since I live Katan, have I encountered so much implicit colorblind in this bias? So please, for the love of God, switch to those colors or something like colorblind people

could tell the difference. Because all I'd just be able to say is that you've had to deal with Scott in your life. I was so confused when people on our slacks started posting these results. I was like, why are people who posting these row three rows of five green blocks over and over and over again?

And not play sad at them and stare at them when cross-eyed. It was I was like, I think some of

these are red. I can't say with confidence which ones, but I think some are. And it was infuriating. So don't maybe feel that way. Taking gutter son, please. I'll fix that. It's a great game otherwise strong strong indoors. And with that, Lauren, let's bring us home. What do you have for us this week? Yeah, so my recommendation is something that the library of Congress started called by the people. Have you guys heard of this? This sounds familiar, but tell me about it. Okay, so I do

both for law fair and for GMF, I do a lot of like primary source document trying to like track things down. And what this effort does is it's a by the people effort to get people to look at these primary source documents that are handwritten and transcribed them so that they can be like searchable going forward. And I was like, oh, this is such like a like somewhat menial task that I can do to feel like I'm being useful for some like larger effort. And this will

be incredibly helpful for the work that I do where I'm trying to like read somebody's handwriting and I can't control search within it to see if they're talking about the thing I care about. So this is like a cool effort that started. People should check it out if you, you know, want something, you know, random to do for a little bit, like help out. Yeah, I love it. I, I, I do, I have to play with this. It is interesting. It is definitely going to be used to inform the next AI data base

and improve data scraping, which is how it goes. How you feel about it? I think that's a good thing

for historical records. We should be able to search these things and digest them better. But it kind of goes and we're used to be able to help people tweak like which translations were better, we're Google translate and how it just feels language, which I think is like a data set that actually proved like fairly individual and understanding like how you can translate different understandings into the conceptual forms. Like translation was a big gap into kind of LLM's

as I understand it. So like it's, it's all of getting into this big process. But I think it's a good one. So I'm not. Check it out. Lots of cool historical maps you get a chance to look at too,

which as I'm looking at this here, which I always really, really enjoy. So check it out.

But with that, folks, that brings us to the end of this week's episode. Rational Security is, of course, a production of LOLFARE. So be sure to visit us at LOLFAREmedia.org for a show page for a link to past episodes for a written work in the written work of a LOLFARE contributors and for information on LOLFARE's other phenomenal podcast series. All you're adding, be sure to follow LOLFARE and social media wherever you socialize your media,

be sure to leave a rating or a review wherever you might be listening and send us to become a material supporter of LOLFARE on Patreon for an ad free version of this podcast among other special benefits. For more information, visit LOLFAREmedia.org/support. Our audio engineer

producer this week was Nome Osban of Go Rodeo, their music has always was performed by Sophia

again. We were once again edited by the wonderful Jen patcha. By half of my guest Lauren, I want to Mike, I am Scott, I understand who you'll talk to you next week. Till then, goodbye! The news is coming soon.

Compare and Explore