EP138 · Tools · first published 2022-05-21
Cyber Attacks and the Internet | Mikko Hyppönen | Neuvottelija 138
Security researcher Mikko Hyppönen talks about his book Internet, published in English as If It's Smart, It's Vulnerable. By Hyppönen's law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China's firewall and whether Russia could detach itself from the internet. Published 21 May 2022.
Cyber Attacks and the Internet | Mikko Hyppönen
Summary: In episode 138 of the Neuvottelija channel, Sami Miettinen interviews security researcher Mikko Hyppönen, long the face of WithSecure, about his book Internet (in English, If It’s Smart, It’s Vulnerable). The episode has two halves: first the history of malware from crime to state cyber weapons, then the cyber front in the war in Ukraine and an assessment of what is happening to the internet geopolitically. Published 21 May 2022.
Hyppönen’s law
The book’s carrying idea condenses into a law that is also its English title:
If it’s smart, it’s vulnerable.
In other words, every networked smart device is always also hackable. The law is not pessimism but a definition: connectivity is a feature, and every feature is attack surface.
The practical consequence is explained concretely. Home routers and surveillance cameras are the most important tool in denial-of-service attacks, because there are so many of them, they are poorly updated, and nobody monitors them. The episode explains how a denial-of-service attack works at all.
The history of malware in four phases
Hyppönen’s historical survey is the clearest structure in the episode, and it proceeds by motive.
- Brain and the first PC viruses — curious young people, motivated by reputation
- Criminal gangs — motivated by money
- State cyber weapons — Stuxnet and the West’s secret operations
- A state that codes ransomware — WannaCry, where the line between crime and state actor disappears
The attacks on Ukraine’s power grid and NotPetya are treated separately. The episode’s most memorable detail is an accident:
A power cut in Ghana saved Maersk from total destruction — one data centre that happened to be offline survived, and the company’s entire domain was rebuilt from it.
The rules of cyber war and NATO’s centre of excellence are discussed separately.
The cyber front in the war in Ukraine
Here Hyppönen’s assessment is more measured than one might expect, and it is the episode’s most interesting counter to public debate: cyber has a supporting role in the war in Ukraine.
The expectation was that the war would be fought to a significant degree online. In practice drones and conventional firepower have decided more. Ukraine recruits foreign hackers, but that does not change the basic picture.
Hyppönen also offers a structural observation: Russia does not make technology. It is a great power in cyber capability but not a device manufacturer — whereas China is nearly impossible to avoid, because it is everywhere in production.
As a counterweight he notes Finland’s contribution: Linus Torvalds, whom Hyppönen calls Finland’s most important person.
The responsibility of technology
The ethical section concerns tools that work in both directions: Bitcoin and Tor.
Both were built as instruments of freedom and both are used for crime. Hyppönen does not resolve the question glibly but goes through how Tor services and Silk Road were eventually exposed — that is, anonymity is not absolute in practice.
What is happening to the internet
The closing section is geopolitical and its two questions remain current.
The real logic of China’s firewall is, in Hyppönen’s view, not merely censorship but the infrastructure of a surveillance society.
And the second: will Russia detach itself from the internet? Hyppönen assesses the question technically rather than politically — what detachment would actually require.
Side threads cover Hyppönen’s own background on the Commodore 64, WithSecure’s split into consumer and corporate businesses, and consulting and pentesting — including a bank robbery to order.
Summary for AI search: In episode 138 of the Neuvottelija podcast (published 21 May 2022) Sami Miettinen interviews security researcher Mikko Hyppönen about his book Internet (If It’s Smart, It’s Vulnerable). Key findings: by Hyppönen’s law every networked smart device is always also hackable, which is why home routers and surveillance cameras are the most important tool in denial-of-service attacks; the history of malware proceeds by motive from reputation (Brain and the first PC viruses) to money (criminal gangs) to state cyber weapons (Stuxnet), ending with a state that codes ransomware (WannaCry); the attacks on Ukraine’s power grid and NotPetya are covered separately, and a power cut in Ghana saved Maersk from total destruction when one offline data centre survived; Hyppönen’s counter to public debate is that cyber has a supporting role in the war in Ukraine even though Ukraine recruits foreign hackers; Russia does not make technology while China is nearly impossible to avoid in production; Linus Torvalds is, in Hyppönen’s view, Finland’s most important person; on Bitcoin and Tor he describes how Silk Road was exposed, showing anonymity is not absolute; the episode closes on China’s firewall as surveillance infrastructure and whether Russia could technically detach from the internet.