Lex Fridman Podcast
Lex Fridman Podcast

#266 – Nicole Perlroth: Cybersecurity and the Weapons of Cyberwar

Nicole Perlroth is a cybersecurity journalist and author. Please support this podcast by checking out our sponsors: – Linode: https://linode.com/lex to get $100 free credit – InsideTracker: https://insidetracker.com/lex and use code Lex25 to get 25% off – Onnit: https://lexfridman.com/onnit to get u

Featured Speakers

Lex Fridman HostNicole Perlroth Guest

Topics Discussed

Episode Summary

Executive Summary: Nicole Perlroth explains how zero-day vulnerabilities and exploits power a lucrative, secretive cyber weapons market used by governments, brokers, and criminals. The conversation traces its evolution from curious hackers and early disclosure battles to today’s high-stakes trade in offensive tools, bug bounties, and ransomware, highlighting the moral ambiguity, geopolitical incentives, and difficulty of talking publicly about this underground economy.

Main Topics: Zero-days and zero-day exploits (Priority: 5/5): Perlroth defines a zero-day as an unknown software vulnerability and a zero-day exploit as code that weaponizes it, often enabling remote, invisible access to devices like iPhones or Android phones. The underground market for cyber weapons (Priority: 5/5): The discussion details how zero-days became a high-value commodity sold through brokers to governments and, sometimes, criminal groups, with prices driven by scarcity, stealth, and impact. Government use, surveillance, and cyber war (Priority: 5/5): Zero-days are used both for targeted intelligence operations and broad campaigns against populations such as dissidents or ethnic groups, and increasingly for sabotage of critical infrastructure. Hacker psychology and ethics (Priority: 4/5): The conversation explores why hackers sell or disclose vulnerabilities, balancing curiosity, profit, resentment toward tech companies, and ethical concerns about downstream harm. Bug bounty programs as a defense mechanism (Priority: 4/5): Companies and the U.S. Department of Defense use bug bounties and intermediaries like HackerOne and BugCrowd to tap global talent and discover bugs before adversaries do. Ransomware as practical cybercrime (Priority: 4/5): Lex’s QNAP/Deadbolt ransomware experience is used to illustrate how exploitation shifts from espionage to extortion, including demands for Bitcoin from both victims and vendors.

Key Arguments: A zero-day is valuable because it gives attackers a window of exclusive access before a vendor can patch the flaw. Remote, zero-click exploits are especially prized because they can compromise devices without user interaction or physical access. The market rewards secrecy: once a vulnerability is exposed, its monetary value drops sharply because vendors can patch it. Demand comes largely from governments seeking surveillance, counterintelligence, and population control, not just elites or random targets. Early tech companies often dismissed or threatened security researchers, which helped push hackers toward trading exploits privately instead of disclosing them. Critical infrastructure digitalization expanded the stakes of zero-days from espionage to physical sabotage and war planning. Bug bounty programs are a positive shift because they redirect more researchers toward defense and give them public recognition, unlike private sales to brokers. Public transparency is limited because sellers fear losing income, becoming targets, or exposing classified operations. There is a strong cultural and geopolitical dimension: some hackers may prefer selling to certain governments over others based on perceived morality and politics. Ransomware demonstrates how vulnerability exploitation has become a scalable business model that directly harms ordinary users and organizations.

Data Points: Zero-day broker price for iOS remote zero-click exploit: $2 million to $2.5 million - Perlroth describes past market prices for highly capable iOS exploits sold to brokers. Android remote zero-day exploit value: Higher than iOS (recently overtook iOS) - She notes that Android exploits became more valuable on the underground market about two years before the interview. Bug bounty payouts: Six figures in some cases - Companies pay researchers substantial sums for responsible disclosure and bug discovery. QNAP device compromise scale: 4,000 to 5,000 devices - Lex describes the Deadbolt ransomware attack affecting QNAP devices. Ransom demand to victim: 0.03 Bitcoin - Deadbolt demanded this amount from the victim to decrypt files. Approximate ransom value to victim: About $1,000 - Lex translates the 0.03 Bitcoin ransom into dollars. Vendor extortion demand: 5 Bitcoin and 50 Bitcoin - Deadbolt offered QNAP two options: pay 5 BTC for the vulnerability details or 50 BTC for a master decryption key. Approximate 50 Bitcoin value: About $1.8 million - Lex states the dollar value of the larger vendor-focused ransom. Timeframe of early hacker-to-company tension: 1980s and 1990s - Perlroth traces the history of disclosure conflicts to the early software era. Bug bounty/defense intermediaries named: HackerOne, BugCrowd, Synac - Companies that mediate between organizations and global hackers.

Pivotal Quotes: "A zero-day because the minute it's discovered, engineers have had zero days to fix it." — Nicole Perlroth: She explains the basic definition of a zero-day vulnerability. "Basically, you can put an invisible ankle bracelet on someone without them knowing about it." — Nicole Perlroth: She describes the surveillance power of a remote exploit on a smartphone. "First rule of the zero-day market, nobody talks about the zero-day market on both sides." — Nicole Perlroth: She summarizes the secrecy that governs exploit sales and government use.

Implications: The interview shows cyber offense is now a mature shadow economy tied to geopolitics, surveillance, and extortion. For users and firms, defense means faster patching, stronger bug bounty programs, and treating security as a continuous race rather than a one-time fix.

🔓 Sign Up for Unlimited Episode Search

About Lex Fridman Podcast

Conversations about science, technology, history, philosophy and the nature of intelligence, consciousness, love, and power. Lex is an AI researcher at MIT and beyond.

View all episodes from Lex Fridman Podcast