This is about cybersecurity reporter Nicole Perlroth's view: zero-day vulnerabilities (undisclosed software flaws) are now bought and weaponized by governments, while defenders are far behind. She warns that ransomware has evolved into supply-chain attacks. Key examples: **QNAP** (network storage devices) exploited by ransomware, affecting 4,000+ units; **Colonial Pipeline** shut down due to a single old employee account without two-factor authentication (an extra login step); **Merck** (pharmaceutical company) had its vaccine production halted by the NotPetya attack, forcing use of emergency CDC stockpiles.
This conversation focuses on cybersecurity and cyber warfare weapons, discussed by cybersecurity journalist Nicole Perlroth (author of This Is How They Tell Me The World Ends) and Lex Fridman. The core view argues that zero-day vulnerabilities have become state-level offensive weapons, and the cyber
Nicole Perlroth is a cybersecurity journalist and author of This Is How They Tell Me The World Ends. This conversation begins with the mechanics of zero-day vulnerabilities, delving into the uncontained state of the cyber arms race among nations, the ethical dilemmas of the underground zero-day market, and the real threats facing critical infrastructure. Nicole Perlroth's core judgment is that zero-day vulnerabilities are no longer accidental security flaws but strategic assets systematically procured and weaponized by state actors, while defenders (software companies, governments, and enterprises) lag behind attackers across the three dimensions of talent, capital, and institutions—and this imbalance is accelerating rather than converging.
Nicole Perlroth argues that the formation of the modern zero-day market is not a resource misallocation, but the inevitable result of years of game-playing between tech companies and governments.
She traces the historical arc: In the 1980s-1990s, hackers who discovered vulnerabilities would proactively contact Microsoft, Sun Microsystems, and other companies. The response they received was not thanks but "Touch our software again and we'll sue you." This hostility pushed hackers into underground forums, where they began privately trading vulnerabilities. Subsequently, government contractors started "fishing" on these forums, purchasing at six-figure prices the vulnerabilities that hackers had originally wanted to report to Microsoft for free.
"Government agencies and their contractors exploited this frustration and resentment," Perlroth said. "They started quietly contacting hackers on forums, saying, 'That zero-day vulnerability you just disclosed, can you make a custom version for me? I'll pay you six figures, as long as you keep your mouth shut and never say it was me who paid.'"
She specifically points out that the "moral duplicity" of this market is most extreme in Argentina. At the Echo Party hacker conference in Buenos Aires, she asked a local hacker leader, "Surely these people only sell zero-days to good Western governments, right?" The answer: "Nicole, last time I checked, the United States is not a good Western government. The last country to blow another country to smithereens was not China or Iran, it was the United States. So if we go by your moral standards, our standards here are completely different — we would rather sell to Iran, Russia, or China than to the United States."
Deduction and Falsification Conditions: If U.S. tech companies significantly increase bug bounties (e.g., Apple raises the iOS remote zero-day bounty from $2.5M to $10M), they would face the risk of internal engineers leaving to become independent bug hunters — "you would create a perverse incentive." Therefore, software companies can never compete with governments on price, but they can offer something governments cannot: public acknowledgment and industry reputation.
Perlroth uses her own experience as an example to point out that ransomware attacks have evolved from "data encryption" to "supply chain attacks + psychological warfare," and their impact on society far exceeds public awareness.
She comments on the Deadbolt ransomware attack that targeted Lex Fridman. Deadbolt used a zero-day vulnerability to attack QNAP network storage devices, affecting 4,000–5,000 devices. The attackers demanded 50 Bitcoin (approximately $1.8M) from QNAP for the master decryption key and 0.03 Bitcoin (approximately $1,000) from individual users. Perlroth notes: "This is the first time in 18 months that we have actually seen ransomware use a zero-day vulnerability to carry out an attack. Typically, 80% of ransomware attacks come down to a lack of two-factor authentication."
She cites the Colonial Pipeline case as a more extreme example: the company was breached due to an old employee account (password already circulating on the dark web and without two-factor authentication enabled), forcing it to shut down the largest fuel pipeline on the U.S. East Coast. Perlroth and her colleague David Sanger obtained a classified assessment: "As a country, we could only afford to have Colonial Pipeline down for another two to three days. It wasn't about gasoline or jet fuel—it was about diesel. Without diesel, refineries can't run, and the entire economy would grind to a halt."
The most disturbing case is NotPetya—a Russian supply chain attack on Ukraine in 2017. It spread through Ukrainian tax software, not only paralyzing Ukrainian government departments but also hitting any company globally that had remote employees in Ukraine: Maersk, Pfizer, FedEx, Merck. Merck was forced to tap into the U.S. CDC's emergency vaccine reserve (Gardasil) because its entire vaccine production line was crippled. "Imagine if this happened to Pfizer or Moderna now," Perlroth warns, "that would essentially be a global cyber-terrorist attack."
Supply, demand, and competitive landscape: The attackers' strategy has shifted from "monetization" to "coercion." Attackers no longer simply lock up data; they directly exploit zero-day vulnerabilities to attack supply chains (as in the QNAP case) or transmit pressure to individuals (e.g., after a Norwegian mental health clinic was attacked, hackers directly contacted patients to extort them). Falsification signal: If government legislation mandates that companies disclose breaches and sets minimum security standards (such as two-factor authentication), the success rate of ransomware attacks would drop significantly. However, Perlroth believes the U.S. is currently "systematically designed to be in its most fragile state"—"there is no law requiring those companies to share breach information; they don't even have to tell the government."
Nicole Perlroth argues that cyberwarfare has entered a tacit phase of "limited retaliation," but this balance is extremely fragile and lacks the clear deterrence framework of the nuclear age.
She points out that traditional military power cannot effectively deter cyberattacks because the barrier to entry is extremely low: "You don't need nuclear material, you just need a laptop and skills." The attribution problem further complicates matters: state actors can disguise themselves as cybercriminal groups, or use "outsourced hackers" (such as China's "loose satellite networks," Russia's "hackers are like artists, they start painting when they feel good in the morning"). She quotes Putin's own words—"Hackers are like artists, they wake up in a good mood and start painting"—to illustrate how this ambiguity makes international agreements difficult to reach.
In 2018, Perlroth and a colleague reported on the U.S. Cyber Command's intrusion into the Russian power grid. She expected protests from the National Security Council but instead received a response of "We have no problem with you publishing this story"—"They wanted Russia to know that we were also infiltrating their grid. They should think twice before doing to us what they did to Ukraine."
She defines the current state as the embryonic form of "Mutually Assured Digital Destruction," but with three fundamental differences from nuclear deterrence: 1) Low barrier to entry (no need for nuclear material); 2) Difficulty of attribution (can be disguised as criminal groups); 3) No clear red line where "use triggers full-scale retaliation."
Scenario Analysis: Perlroth believes the most dangerous scenario is "when someone dies as a result." Take NotPetya as an example: although it paralyzed countless companies, "no one died"—this is the boundary of self-restraint on the attacker's side. But whoever crosses that line first will push the world into uncharted territory. Falsification Condition: If a country crosses the "lethal" boundary in a cyberattack (e.g., causing patient deaths by attacking a hospital), will the international community establish a cyber red line similar to the "nuclear taboo"? Currently, there is no evidence that such a red line exists.
| Target | Guest Attitude | Key Data |
|---|---|---|
| QNAP | Risk Warning | Attacked by ransomware using a zero-day vulnerability, affecting 4,000–5,000 devices; ransom demand for individuals 0.03 BTC (~$1,000), for companies 50 BTC (~$1.8M) |
| Colonial Pipeline | Risk Warning | Breached due to an old employee account without two-factor authentication enabled; ransom amount $50M; the national level can only sustain a 2–3 day shutdown |
| Merck | Risk Warning | NotPetya attack paralyzed the vaccine production line, forcing the use of CDC emergency Gardasil stock |
| Risk Warning | Saudi Arabia had planted spies inside the company to monitor users who criticized the regime | |
| Abnormal Security | Bullish | Uses advertising technology (behavioral pattern analysis) to detect abnormal emails and defend against social engineering attacks |
| HackerOne / BugCrowd / Synac | Neutral/Bullish | Bug bounty platforms, already hired by the U.S. Department of Defense (DoD) to assist with security reviews |
| Piano | Bullish | Created the concept of a "personal information vault," enabling companies to avoid storing user PII and only confirm identity via one-time tokens |
| TRM Labs | Neutral/Bullish | Blockchain intelligence company, helps track cryptocurrency ransomware payments, real-time tracking of fund flows |
1. The "Monoculture Law" of the Zero-Day Market
Nicole Perlroth argues that the cybersecurity problem is essentially a "monoculture" problem — when Windows or iOS holds absolute dominance, a single zero-day can affect hundreds of millions of users. This is analogous to the vulnerability of a single crop in agriculture: if all crops are the same, one disease can destroy the entire harvest. Corollary: The lack of software diversity is itself a systemic risk, but this risk is currently completely obscured by the "software is eating the world" narrative.
2. "Defenders Can Never Outbid Attackers"
Perlroth explains why companies like Apple cannot raise bug bounties to the level of government buyers ($2.5M level): if Apple engineers realize that "doing iOS security for a year earns $200K, but selling one zero-day earns $2.5M," they would quit. Therefore, defenders must compete with other means — public recognition and industry reputation — while government buyers can only offer "silent money."
3. "Hackers' Ethics Depend on Their Country's State"
Perlroth illustrates this with the example of Argentine hacker culture: in Argentina, you cannot buy an iPhone, do not have Amazon Prime, and must "make do with wire and tape" — which turns the entire country into a hacker incubator. And economic instability ("check our inflation rate") makes these hackers more inclined to sell zero-days to the "highest bidder," regardless of the buyer's political stance.
4. "NotPetya Was Not 'Collateral Damage' — It Was Intentional"
Perlroth, citing a Cisco Talos analyst, revises her long-held understanding: Russia knew which enterprises would be affected before deploying NotPetya. It was not "accidentally hitting the world while attacking Ukraine," but "intentionally sending a signal to any company with business ties to Ukraine."
5. "Multi-Factor Authentication Can Block 80% of Attacks"
Perlroth believes this is what she would choose if she "could fix one thing with one finger." "The Colonial Pipeline case was because of an old employee account (password already circulating on the dark web) and no two-factor authentication enabled. A water treatment plant was breached for the same reason — no two-factor authentication." Falsification condition: MFA cannot defend against state-level APTs (advanced persistent threats), but it can block 90% of ransomware and criminal attacks.
6. "Whether to Pay Ransomware Demands Has No Simple Answer"
Perlroth uses the example of Baltimore: the city rejected a $76,000 ransom demand, but the subsequent remediation cost $18 million — "that money could have been used for public schools, roads, and public health." Conclusion: It is easy to say "don't pay," but if you pay, you are funding the attacker's next R&D; if you do not pay, you may be using public funds to cover much higher replacement costs.
7. "A Digital Geneva Convention Is Nearly Impossible"
Perlroth explains why the "Digital Geneva Convention" pushed by Brad Smith (Microsoft President) is difficult to implement: state actors can "outsource" attacks to cybercrime groups and then claim "hackers are like artists, I can't control them" (Putin's original words). When it is impossible to distinguish between "state action" and "criminal group action," any interstate agreement becomes meaningless.
8. "Cybersecurity's Biggest Enemy Is Not Technology, But Friction"
Perlroth points out why Apple's Touch ID and Face ID are the biggest security advances of the past decade — not because they are unbreakable, but because they eliminate the friction of "typing a password." "The biggest problem with security is that it's annoying. We need someone like Steve Jobs to make it painless."