If Existing Cyber Vulns Magically Disappeared, What Next

Dr Stefanie Tompkins

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

Dr. Stefanie Tompkins, the Director of the Defense Advanced Research Projects Agency (DARPA), delivered a thought-provoking keynote at DEF CON 32, challenging the cybersecurity community to envision a future beyond the persistent vulnerabilities that plague today's digital landscape. Her talk, titled "If Existing Cyber Vulns Magically Disappeared, What Next," wasn't a technical deep dive into a specific exploit, but rather a strategic call to action for disruptive innovation. Dr. Tompkins emphasized DARPA's mission to make "big bets" on high-risk, revolutionary technologies that deliver "5,000 times better" improvements or entirely new solution spaces, rather than incremental enhancements.

Watch on YouTube

Visual summary for If Existing Cyber Vulns Magically Disappeared, What Next by Dr  Stefanie Tompkins
Visual summary for If Existing Cyber Vulns Magically Disappeared, What Next by Dr Stefanie Tompkins

Key moments

  1. 0:19 Dr. Tompkins introduces DARPA and its achievements
  2. 1:18 DARPA's director shares her biggest concern
  3. 2:19 Def Con community's historical impact on the Internet
  4. 3:30 The ARPANET's first message and immediate crash
  5. 4:00 DARPA aims for 5,000x improvement, not incremental changes
  6. 4:40 DARPA's philosophy: celebrating failures for innovation

If Existing Cyber Vulns Magically Disappeared, What Next

Speakers: Dr Stefanie Tompkins

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=edM1SvSz6pc

Overview

Dr. Stefanie Tompkins, the Director of the Defense Advanced Research Projects Agency (DARPA), delivered a thought-provoking keynote at DEF CON 32, challenging the cybersecurity community to envision a future beyond the persistent vulnerabilities that plague today's digital landscape. Her talk, titled "If Existing Cyber Vulns Magically Disappeared, What Next," wasn't a technical deep dive into a specific exploit, but rather a strategic call to action for disruptive innovation. Dr. Tompkins emphasized DARPA's mission to make "big bets" on high-risk, revolutionary technologies that deliver "5,000 times better" improvements or entirely new solution spaces, rather than incremental enhancements.

The core of Dr. Tompkins' message was a profound question: what if all classes of existing cyber vulnerabilities—the memory corruptions, buffer overflows, and command injections that have persisted for decades—were to vanish overnight? Her concern is that while such a scenario might seem utopian, it immediately raises a critical strategic challenge: the adversary would not simply disappear. New problems would inevitably emerge, and the mission to protect national security would continue, albeit in a radically altered threat environment. This talk served as an urgent invitation for the hacker community, with its unique expertise and problem-solving perspective, to collaborate with DARPA in imagining and building the next generation of truly resilient systems.

Dr. Tompkins underscored the historical partnership between DARPA and this community, citing the evolution of the ARPANET into the modern Internet as a prime example of how external insights and relentless probing of system weaknesses led to a transformative technology. She expressed a deep concern that DARPA might be missing out on "amazing national security ideas" because the community's focus remains predominantly on current vulnerabilities. By posing this hypothetical future, DARPA aims to stimulate visionary thinking and encourage proposals that tackle foundational problems, pushing the boundaries of what cybersecurity can achieve.

Background

▶ Watch: Dr. Tompkins introduces DARPA and its achievements (0:19)

DARPA, the Defense Advanced Research Projects Agency, has a storied history of incubating technologies that have fundamentally reshaped modern life and national security. Beyond well-known contributions like the Internet and stealth technology, DARPA was instrumental in establishing material science as an academic discipline, which in turn spawned innovations like semiconductors and advanced alloys. More recently, the agency played a pivotal role in the development of miniaturized GPS, graphical user interfaces (GUIs), and even the computer mouse. This track record exemplifies DARPA's core philosophy: to make "really big bets" on high-risk, new technologies that are truly revolutionary and disruptive, aiming for improvements that are 5,000 times better, or even entirely new solution paradigms, rather than mere incremental gains. The agency actively embraces failure as a critical learning opportunity, understanding that audacious goals inherently carry high risks.

The speaker highlighted DARPA's deep, albeit often unrecognized, historical ties with the hacker community. The ARPANET, DARPA's precursor to the Internet, was initially designed for specialized computers to communicate resiliently across distances, leading to innovations like packet switching and the TCP/IP protocol. Dr. Tompkins explicitly credited the DEF CON community and similar groups with "poking and prodding at strengths and weaknesses," identifying vulnerabilities, and ultimately helping to "graduate" the ARPANET into the robust, ubiquitous Internet we know today. This collaboration, she argued, fundamentally changed how the world lives and communicates.

A poignant anecdote shared by Dr. Tompkins perfectly encapsulates the enduring challenge: the very first attempt to log into the ARPANET was meant to be "log in." The system received "L," then "O," and then promptly crashed. This "LO crash" was attributed to a memory corruption issue—a fundamental software defect that, remarkably, continues to manifest in various forms today. This historical echo underscores the persistent nature of many cyber vulnerabilities. Dr. Tompkins observed that many of the security flaws encountered today, such as buffer overflows and command injections, are essentially "variations on the same themes" that have plagued software for decades. Despite the exquisite sophistication of modern exploits, they often leverage these same foundational classes of software defects. This persistent cycle of discovering and patching variations of old problems forms the critical backdrop for DARPA's challenge to the community: to transcend this reactive paradigm and envision a truly secure future.

Key Findings

▶ Watch: Def Con community's historical impact on the Internet (2:19)

The central "finding" of Dr. Tompkins' talk is less a discovery and more a profound strategic question, serving as a critical insight into DARPA's forward-looking approach to national security. The core premise she laid out is: What if all classes of security vulnerabilities—those fundamental software defects like memory corruption, buffer overflows, and command injections—were to magically disappear tomorrow? This hypothetical scenario is not merely an intellectual exercise but a serious inquiry into the future of cyber defense.

The immediate and most critical implication derived from this question is that the adversary does not simply pack up their bags and quit. Even in a world devoid of current vulnerabilities, malicious actors would adapt. They would seek out new weaknesses, exploit human factors, or pioneer entirely novel attack vectors in the reconfigured digital landscape. This means the mission for national security would persist, demanding a new level of strategic foresight and innovative defense.

Dr. Tompkins conveyed DARPA's significant concern that the agency might be "missing out on amazing national security ideas" because the broader community's focus remains largely on identifying and mitigating existing or immediately emerging threats. While crucial, this reactive stance may inadvertently divert attention from truly revolutionary concepts that could fundamentally alter the security posture. DARPA's role, as she reiterated, is to identify and fund these "big bets" – ideas that are so transformative they move beyond incremental improvements (5% or 50% better) to achieve a "5,000 times better" state or even entirely eliminate existing problem domains by shifting to new solution spaces. By challenging the community to imagine a post-vulnerability world, DARPA seeks to uncover these paradigm-shifting ideas that address not just today's problems, but the unknown challenges of tomorrow.

Technical Deep Dive

▶ Watch: The ARPANET's first message and immediate crash (3:30)

While Dr. Tompkins' talk was a high-level strategic address rather than a demonstration of specific technical exploits, it implicitly called for a deep technical re-evaluation of how we approach software and system security. The persistent nature of vulnerabilities like memory corruption, buffer overflows, and command injections highlights a fundamental challenge in current computing paradigms. These aren't just isolated bugs; they represent systemic flaws often rooted in low-level programming language design (e.g., C/C++'s direct memory access), inadequate input validation, or a lack of robust trust boundaries within system architectures. The "LO crash" on the ARPANET, caused by memory corruption, serves as a historical echo demonstrating that these issues have been present since the dawn of networked computing.

DARPA's historical contributions, such as the development of packet switching and TCP/IP for the ARPANET, represent radical technical shifts from circuit-based communications. Similarly, their instrumental role in the transition from IPv4 (with 4 billion addresses) to IPv6 (with 340 trillion addresses) showcased an ability to engineer foundational changes to critical infrastructure. This historical context provides a blueprint for the type of "5,000 times better" technical solutions DARPA is now seeking for cybersecurity. It's not about patching individual vulnerabilities, but about developing entirely new frameworks, languages, or hardware architectures that make entire classes of vulnerabilities impossible.

For instance, addressing memory corruption fundamentally might involve widespread adoption of memory-safe programming languages (like Rust or Ada/SPARK), or the development of hardware-enforced memory safety mechanisms that prevent unauthorized memory access at the CPU level. Eliminating buffer overflows could involve compilers with built-in bounds checking that are performant enough for critical systems, or operating system designs that rigorously enforce memory segmentation and access controls. Countering command injections could necessitate a complete overhaul of how applications process user input, perhaps through universal adoption of formally verified input sanitization libraries or new execution environments that strictly separate data from control flow. The technical deep dive, in DARPA's vision, moves beyond vulnerability management to vulnerability prevention at the architectural, language, or even hardware level. This requires exploring areas like formal methods for software verification, provably secure hardware designs, zero-trust architectures implemented at a foundational level, or even entirely new computing paradigms that abstract away the low-level complexities that currently give rise to these defects. The challenge is to identify and develop these truly disruptive technical solutions that redefine the baseline of system security.

Demo / Proof of Concept

▶ Watch: DARPA aims for 5,000x improvement, not incremental changes (4:00)

This keynote address by Dr. Stefanie Tompkins was a strategic call to action rather than a demonstration of a specific exploit or security tool. Therefore, there was no traditional demo or proof of concept presented in the conventional sense of a technical conference talk.

However, Dr. Tompkins did provide a powerful historical anecdote that served as a conceptual "proof of concept" for the talk's central theme: the persistence of fundamental software defects. She recounted the very first login attempt on the ARPANET, where the intended command "log in" resulted in a system crash after only "L" and "O" were transmitted. This incident, caused by a memory corruption bug, highlighted that even at the dawn of networked computing, the core types of vulnerabilities that plague systems today were already present. This historical example underscored her point that many contemporary exploits, despite their sophistication, are merely "variations on the same themes" of fundamental software defects that the industry has been grappling with for decades. It illustrated the deep-seated nature of the problem DARPA is challenging the community to solve definitively.

Defensive Implications

▶ Watch: DARPA's philosophy: celebrating failures for innovation (4:40)

Dr. Tompkins' talk carries profound implications for cybersecurity defenders, urging a significant shift in mindset and strategy. The most critical defensive implication is the need to move beyond a purely reactive stance—patching vulnerabilities as they are discovered—towards a proactive, foundational approach that aims to eliminate entire classes of vulnerabilities. Defenders must start asking not just "How do we fix this vulnerability?" but "How do we design systems where this type of vulnerability cannot exist?"

This shift demands investment in revolutionary research and development. Instead of focusing solely on threat intelligence, incident response, and incremental security tool improvements, organizations and research institutions should dedicate resources to exploring and implementing truly disruptive technologies. This includes adopting secure-by-design principles at every layer of development, from hardware to applications. Considerations should be given to:

  • Memory-safe programming languages: Proactively transitioning away from languages prone to memory errors to those that offer inherent memory safety, thereby eliminating a vast category of critical vulnerabilities like buffer overflows and use-after-free bugs.
  • Formal verification and provable security: Employing rigorous mathematical methods to prove the correctness and security properties of critical software components and hardware designs, making entire systems more resilient to logical flaws.
  • Hardware-assisted security: Leveraging modern processor features and trusted execution environments to enforce security policies at the lowest possible level, creating stronger roots of trust and isolation.
  • New architectural paradigms: Exploring entirely novel system architectures that fundamentally change how components interact, how data is processed, and how trust is managed, potentially moving beyond current operating system and network models.

Furthermore, the talk serves as a stark reminder that the adversary is persistent and adaptive. Even if current vulnerabilities were eradicated, malicious actors would pivot to new attack surfaces, whether through social engineering, supply chain compromises, or exploiting entirely novel system behaviors. Defenders must therefore cultivate a strategic foresight to anticipate these future threats and build systems with inherent resilience, not just against known attack patterns, but against unforeseen ones. This requires fostering a culture of continuous questioning and innovation within security teams, encouraging them to think like DARPA: to identify the "hard problems" that feel impossible to solve and seek "5,000 times better" solutions. Ultimately, the defensive implication is a call to collaborate, innovate, and think beyond the horizon of current cyber threats, actively shaping a more secure future rather than merely reacting to it.

Key Takeaways

  • DARPA challenges the cybersecurity community to think beyond current vulnerabilities and envision a future where fundamental software defects no longer exist.
  • The agency seeks "5,000 times better" or entirely new solution spaces for national security challenges, not just incremental improvements.
  • Many prevalent cyber vulnerabilities, such as memory corruption, buffer overflows, and command injections, are variations of persistent software defects that have existed for decades.
  • Even if all current vulnerabilities disappeared, adversaries would adapt, meaning the mission for national security would continue and new problems would emerge.
  • DARPA encourages the security community to propose revolutionary, high-risk ideas that tackle foundational problems and anticipate future threats.
  • The historical collaboration between DARPA and the hacker community, exemplified by the evolution of the ARPANET into the Internet, serves as a model for future transformative innovation.

About the Speaker(s)

Dr. Stefanie Tompkins is the Director of DARPA, the Defense Advanced Research Projects Agency. In this role, she leads the U.S. Department of Defense's agency responsible for making pivotal investments in breakthrough technologies for national security. Her leadership focuses on DARPA's core mission: to make "big bets" on high-risk, high-reward research that can lead to revolutionary and disruptive capabilities, rather than incremental improvements.

Dr. Tompkins highlighted DARPA's legacy in creating foundational technologies such as the Internet, stealth technology, material science as an academic discipline, miniaturized GPS, graphical user interfaces, and the computer mouse. She emphasized the agency's commitment to engaging with diverse communities, including the hacker community, acknowledging their crucial role in past innovations like the development of the Internet from the ARPANET. Her talk underscored her commitment to identifying and fostering "amazing national security ideas" that might otherwise go unheard, advocating for a proactive, long-term approach to solving complex challenges. The mention of "Mudge" (Peiter Zatko) as a former DARPA program manager further illustrates the agency's history of drawing talent from the hacker community.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This keynote from DARPA's Director, Dr. Stefanie Tompkins, is a potent strategic challenge to the cybersecurity community. It skillfully leverages a hypothetical "post-vulnerability" world to compel researchers to move beyond incremental fixes and pursue foundational, disruptive innovations. While not a technical deep-dive, it provides a clear signal on DARPA's priorities for "5,000 times better" solutions, backed by the agency's storied history of fostering revolutionary technologies. It's a call to action for those capable of making "big bets" on truly resilient systems, directly from the source.

Heather Calloway (CISO) — STRONG ACCEPT

Dr. Tompkins' keynote is a vital call for strategic foresight, challenging the cybersecurity community to move beyond reactive vulnerability management toward foundational, disruptive innovation. By posing the hypothetical disappearance of all existing vulnerabilities, she compellingly argues that the adversary's persistence demands a paradigm shift in how we design, build, and secure systems. This isn't incremental improvement; it's a powerful directive for leaders to invest in revolutionary solutions and cultivate a proactive, secure-by-design future.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage