Fireside Chat - The Dark Tangent and DNSA Anne Neuberger

The Dark Tangent, Anne Neuberger

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

The DEF CON 32 Fireside Chat featured a rare and significant dialogue between The Dark Tangent (DT), founder of DEF CON, and Anne Neuberger, the Deputy National Security Advisor for Cyber (DNSA) at the White House. This event marked a pivotal moment for the conference, as it was the first time a sitting Deputy National Security Advisor for Cyber from the White House had addressed the DEF CON community. The talk aimed to bridge the often-perceived gap between the grassroots cybersecurity community and the highest echelons of national security policy-making, underscoring the critical need for collaboration in an increasingly complex global digital landscape.

Watch on YouTube

Visual summary for Fireside Chat - The Dark Tangent and DNSA Anne Neuberger by The Dark Tangent, Anne Neuberger
Visual summary for Fireside Chat - The Dark Tangent and DNSA Anne Neuberger by The Dark Tangent, Anne Neuberger

Key moments

  1. 0:00 Introduction: Anne Neuberger's historic DEF CON appearance.
  2. 1:39 DT introduces the 'sorting process' of nations.
  3. 2:00 DT explains 'sorting war' and global tech stack choices.
  4. 7:22 Anne Neuberger finally speaks after technical difficulties.
  5. 7:30 Neuberger highlights critical cyber threats and community need.

Fireside Chat - The Dark Tangent and DNSA Anne Neuberger

Speakers: The Dark Tangent; Anne Neuberger, Deputy National Security Advisor for Cyber

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=TUbpJ-voI8Y

Overview

The DEF CON 32 Fireside Chat featured a rare and significant dialogue between The Dark Tangent (DT), founder of DEF CON, and Anne Neuberger, the Deputy National Security Advisor for Cyber (DNSA) at the White House. This event marked a pivotal moment for the conference, as it was the first time a sitting Deputy National Security Advisor for Cyber from the White House had addressed the DEF CON community. The talk aimed to bridge the often-perceived gap between the grassroots cybersecurity community and the highest echelons of national security policy-making, underscoring the critical need for collaboration in an increasingly complex global digital landscape.

The core of the discussion, as framed by The Dark Tangent, revolved around an emerging "sorting war" in the global technological sphere, where nations are increasingly aligning with either "rule of law" or "authoritarian" tech stacks and digital ecosystems. This geopolitical fragmentation, accelerated by technological dependencies, was presented as a fundamental challenge impacting everything from international relations to individual freedoms. Anne Neuberger, despite initial technical difficulties, reinforced the urgency of the situation by highlighting real-world cyber threats—from sophisticated supply chain attacks like the CrowdStrike incident to destructive ransomware campaigns targeting critical infrastructure and healthcare facilities.

The significance of this fireside chat lies in its explicit recognition by the U.S. government of the hacker community's indispensable role in national and global cybersecurity. Neuberger's presence at DEF CON underscored a shift towards greater transparency and engagement with experts outside traditional government channels. The conversation served as a high-level call to action, emphasizing that the collective expertise of the DEF CON community is not merely valuable but essential in safeguarding digital resilience, protecting critical services, and shaping a future where technology serves democratic values rather than autocratic control.

Background

▶ Watch: Introduction: Anne Neuberger's historic DEF CON appearance. (0:00)

The context for this fireside chat is rooted in a rapidly evolving geopolitical landscape where technology has become a primary battleground for influence and control. The Dark Tangent initiated the discussion by outlining a long-observed trend: the global "sorting process." He described this as an increasing division among nations into two primary camps: those adhering to the "rule of law" and those operating under "authoritarian" or "autocratic" principles. A crucial third group consists of "undecided nations" in regions like Africa and Central America, whose allegiance is actively sought by both sides through diplomatic, economic, and increasingly, technological means.

This "sorting process" is profoundly accelerated by technology. DT emphasized that it's no longer just about political alignment but about "picking our tech stack or their tech stack," and deciding whether to integrate "our App Store or their App Store." This technological fragmentation has direct implications for data sovereignty, information control, and national security. A stark example provided was Russia's response to the Ukrainian war, where the government actively attempts to filter and slow down access to platforms like YouTube, pushing its citizens towards a state-controlled domestic tech ecosystem. This demonstrates a deliberate effort by authoritarian regimes to sort their populations into a specific digital sphere, restricting access to external information and reinforcing internal narratives.

Anne Neuberger's initial remarks, though brief in the provided transcript, immediately anchored this abstract geopolitical framing in concrete, immediate threats. She cited several high-profile incidents that underscore critical gaps in digital resilience and the severe real-world consequences of cyberattacks. These included the CrowdStrike incident, which exposed vulnerabilities in digital supply chains, and persistent hacks by Iranian and Russian actors targeting vital water infrastructure and power infrastructure in the United States. Furthermore, Neuberger highlighted the pervasive threat of ransomware attacks, particularly those affecting hospitals, often perpetrated by groups based in Russia. These attacks, she stressed, lead to tangible harm: canceled medical services, ambulances being turned away, and direct impacts on human lives, especially in communities reliant on a single healthcare facility. This background collectively paints a picture of a world where technological choices are geopolitical choices, and where cybersecurity is not an abstract concern but a foundational element of national security, economic stability, and public safety.

Key Findings

▶ Watch: DT introduces the 'sorting process' of nations. (1:39)

The fireside chat, even in its introductory phase, unveiled several critical insights into the current state of global cybersecurity and geopolitical dynamics. The most prominent finding, articulated by The Dark Tangent, is the concept of a "sorting war" or "tech stack sorting". This describes a fundamental global realignment where nations are increasingly compelled to choose between technological ecosystems aligned with either democratic, rule-of-law principles or authoritarian control. This isn't merely a political or economic division; it's a deep structural divergence in how digital infrastructure is built, governed, and utilized, with profound implications for freedom of information, privacy, and national sovereignty. The Russian government's explicit efforts to control its citizens' access to global platforms like YouTube and promote its domestic alternatives serves as a clear, real-time example of this "sorting" in action.

A second key finding, powerfully underscored by Anne Neuberger, is the direct and often devastating human impact of cyberattacks. By citing incidents such as ransomware disrupting hospitals, leading to canceled medical services and turned-away ambulances, Neuberger brought the abstract threat of cyber warfare into sharp, personal focus. This highlights that cybersecurity failures are not just about data breaches or financial losses; they are about tangible consequences for public health, safety, and the functioning of essential services. The mention of attacks on water and power infrastructure further emphasizes that critical national functions, upon which daily life depends, are under constant threat, revealing significant gaps in digital resilience.

Finally, the very occurrence of this fireside chat and Neuberger's presence at DEF CON itself represents a key finding: a formal recognition from the highest levels of the U.S. government regarding the indispensable value of the hacker community. Her remarks about the necessity of "this community" to address complex challenges like digital resilience and critical infrastructure protection signal a strategic shift. It indicates a willingness to engage with non-traditional partners and leverage the unique insights and technical prowess of the cybersecurity grassroots in formulating national security strategies. This acknowledges that effective defense against sophisticated, state-sponsored, and criminal cyber threats requires a broad, collaborative effort extending beyond government agencies.

Technical Deep Dive

▶ Watch: DT explains 'sorting war' and global tech stack choices. (2:00)

Given that the provided transcript covers an introductory segment of a fireside chat, a traditional "technical deep dive" into specific exploits, protocols, or architectures is not present. However, the speakers' framing of the global "sorting war" and the threats to digital resilience provide a conceptual framework for understanding the underlying technical implications.

The concept of "tech stack sorting" implies a deep technical divergence. On one side, "rule of law" nations generally favor open standards, interoperability, and a multi-vendor approach to technology, which ideally fosters innovation, competition, and a degree of inherent resilience through diversity. This approach supports a global internet model where data flows relatively freely, and users have choices in their applications and services. Technically, this means reliance on internationally recognized protocols (e.g., TCP/IP, HTTP, DNS), open-source software, and diverse cloud providers, albeit with their own security challenges. The security model often emphasizes defense-in-depth, shared responsibility, and incident response frameworks based on international best practices.

Conversely, "authoritarian" tech stacks, as exemplified by Russia's efforts to control YouTube access, often lean towards closed ecosystems, nationalized platforms, and a greater degree of state control over network infrastructure. This involves technical mechanisms for deep packet inspection (DPI), content filtering, and potentially the development of national equivalents to global services (e.g., a "Russian YouTube"). From a technical standpoint, this requires significant investment in national internet infrastructure, including Internet Service Providers (ISPs), content delivery networks (CDNs), and possibly national root DNS servers that can be manipulated for censorship or surveillance. The security model in such environments often prioritizes state control and surveillance capabilities over individual privacy or open access, potentially introducing backdoors or mandated vulnerabilities for government access, while simultaneously attempting to isolate the national network from external threats (a "splinternet" concept). These choices have profound technical implications for supply chain security, as reliance on a single, state-controlled vendor or a limited set of domestic providers can introduce systemic vulnerabilities that are difficult to detect or mitigate.

Neuberger's reference to the CrowdStrike incident implicitly points to the criticality of supply chain security in modern software architectures. While the details of the specific incident were not elaborated upon, such events typically involve the compromise of a trusted software vendor or service provider, allowing adversaries to distribute malicious code through legitimate updates or services. Technically, this highlights the need for robust software bill of materials (SBOMs), stringent vendor vetting, continuous monitoring of third-party dependencies, and advanced endpoint detection and response (EDR) capabilities.

The attacks on water and power infrastructure involve a complex interplay between information technology (IT) and operational technology (OT) systems. OT environments, which control physical processes, often feature legacy systems, specialized protocols (e.g., Modbus, DNP3), and unique security challenges due to their direct interface with the physical world. A technical deep dive into such attacks would typically involve exploring vulnerabilities in Programmable Logic Controllers (PLCs), Human-Machine Interfaces (HMIs), SCADA (Supervisory Control and Data Acquisition) systems, and the insecure interfaces between IT and OT networks. These attacks often exploit poor network segmentation, default credentials, unpatched vulnerabilities, and inadequate access controls, leading to potential physical damage or disruption of critical services.

Finally, ransomware attacks on hospitals, while seemingly a straightforward technical exploit, involve a complex chain of events. Technically, these often begin with phishing or exploitation of known vulnerabilities (e.g., unpatched VPNs, exposed RDP ports) to gain initial access. The attackers then perform network reconnaissance, move laterally through the hospital's IT network, escalate privileges, and ultimately deploy encryption malware across critical systems, including electronic health records (EHRs), imaging systems, and administrative networks. The technical defense against such attacks requires comprehensive patch management, multi-factor authentication (MFA), robust network segmentation, endpoint protection platforms (EPPs), diligent backup and recovery strategies, and a well-practiced incident response plan to minimize downtime and data loss. The lack of these foundational technical controls makes healthcare organizations particularly vulnerable.

While the talk did not delve into the specifics of these technical mechanisms, the implications of the discussed threats necessitate an understanding of these underlying technical challenges and the security controls required to address them. The "sorting war" fundamentally dictates the technical architecture and trust models within national digital spaces, directly influencing how these threats are perceived and defended against.

Demo / Proof of Concept

▶ Watch: Anne Neuberger finally speaks after technical difficulties. (7:22)

The provided transcript covers an introductory segment of a fireside chat and does not include details of any specific demonstration or proof of concept. The discussion remained at a high-level strategic and conceptual plane, focusing on geopolitical shifts and the broader landscape of cyber threats rather than showcasing particular tools, exploits, or defensive techniques.

Defensive Implications

▶ Watch: Neuberger highlights critical cyber threats and community need. (7:30)

The insights shared by The Dark Tangent and Anne Neuberger carry significant defensive implications for nations, organizations, and the cybersecurity community alike. Understanding the "sorting war" is paramount: defenders must recognize that technological choices are not neutral; they align with geopolitical values and can dictate the level of control, transparency, and resilience embedded within digital infrastructure. This means actively advocating for and investing in open, interoperable, and secure "rule of law" tech stacks and digital ecosystems, rather than passively allowing authoritarian models to gain dominance. This includes influencing international standards, promoting responsible AI development, and supporting open-source initiatives that align with democratic principles.

For organizations, the recurring themes of digital resilience and critical infrastructure attacks highlight the urgent need to bolster fundamental cybersecurity postures. The CrowdStrike incident serves as a stark reminder of supply chain vulnerabilities. Defenders must implement rigorous vendor risk management programs, demand Software Bill of Materials (SBOMs) from suppliers, and continuously monitor the integrity of third-party software and services. This proactive approach helps mitigate risks introduced by external dependencies, which can be exploited by sophisticated adversaries.

The threats to water and power infrastructure underscore the necessity of securing Operational Technology (OT) environments. Defenders in critical sectors must implement network segmentation between IT and OT networks, deploy industrial control system (ICS) specific security solutions, conduct regular vulnerability assessments on OT assets, and develop tailored incident response plans that account for the unique characteristics and potential physical impacts of OT compromises. Furthermore, legacy systems, often prevalent in these environments, require specific strategies for isolation, monitoring, and virtual patching.

The pervasive threat of ransomware attacks, particularly against hospitals, demands a multi-layered defensive strategy. Organizations, especially those in healthcare, must prioritize basic cyber hygiene: robust patch management for all systems, widespread implementation of multi-factor authentication (MFA), comprehensive endpoint detection and response (EDR), and strong email security to thwart phishing attempts. Crucially, maintaining immutable and segmented backups is non-negotiable, ensuring that data can be restored even if primary systems are encrypted. Regular security awareness training for all employees is also vital, as human error often serves as the initial entry point for ransomware.

Finally, Neuberger's presence at DEF CON itself implies a critical defensive strategy: collaboration and engagement. The White House is signaling that the expertise residing within the hacker community is a vital national asset. Defenders, whether in government, industry, or independent research, should actively seek opportunities to share threat intelligence, contribute to policy discussions, and participate in initiatives aimed at strengthening collective digital defenses. This collaborative approach is essential to address the complex and evolving threat landscape, ensuring that the collective "team rule of law" can effectively counter adversaries who seek to exploit digital vulnerabilities for geopolitical gain and human harm.

Key Takeaways

  • The "Sorting War" is a Defining Geopolitical Challenge: Nations are increasingly dividing into "rule of law" and "authoritarian" camps, with technology stacks and digital ecosystems serving as a primary battleground for influence and control over global information flow.
  • Cyber Threats Have Severe Human Impacts: Attacks like ransomware on hospitals directly lead to tangible harm, including canceled medical services and turned-away ambulances, highlighting that cybersecurity failures are not abstract but affect real lives and critical public welfare.
  • Digital Resilience is Paramount: Incidents such as the CrowdStrike compromise and attacks on critical water and power infrastructure reveal significant gaps in the ability of systems and organizations to withstand and recover from sophisticated cyberattacks.
  • The Hacker Community is a Crucial Partner: The presence of the Deputy National Security Advisor for Cyber at DEF CON underscores the U.S. government's recognition that the expertise and insights of the cybersecurity community are indispensable for national security and digital defense.
  • Technological Choices Reflect Geopolitical Values: The selection and development of tech stacks are not merely technical decisions but strategic alignments that dictate levels of privacy, freedom of information, and control, with profound implications for global power dynamics.
  • Urgent Focus on Critical Infrastructure and Healthcare: Ongoing and persistent threats to vital sectors like water, power, and healthcare demand immediate and sustained attention, robust defensive measures, and specialized security strategies to protect public safety and essential services.

About the Speaker(s)

The Dark Tangent (Jeff Moss) is widely recognized as the founder of DEF CON, one of the world's largest and longest-running hacker conventions, and the Black Hat Briefings. His role at DEF CON positions him at the nexus of the grassroots cybersecurity community, providing a platform for technical exchange, ethical hacking, and critical discussions on emerging threats and digital freedoms.

Anne Neuberger serves as the Deputy National Security Advisor for Cyber at the White House. In this high-level position, she plays a critical role in shaping the United States' cybersecurity policy, coordinating national efforts to defend against cyber threats, and engaging with international partners. Her presence at DEF CON highlights a significant effort by the U.S. government to connect with and leverage the expertise of the broader cybersecurity community in addressing complex national and global digital challenges.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This fireside chat, featuring The Dark Tangent and the Deputy National Security Advisor for Cyber, delivered significant high-level strategic signal. DT's 'sorting war' framework provides a brutally honest lens on global tech fragmentation, while Neuberger's presence at DEF CON itself, coupled with her concrete examples of critical infrastructure threats, legitimizes the hacker community's role in national security. It's a crucial conversation that provides actionable understanding for anyone navigating the geopolitical tech landscape.

Heather Calloway (CISO) — MUST SEE

This fireside chat, featuring Anne Neuberger at DEF CON, is a crucial strategic dialogue for any CISO or security leader. It transcends technical specifics to frame the overarching geopolitical 'sorting war' that dictates global technology choices and supply chain integrity. Neuberger's presence itself signals a critical shift in government engagement, while the discussion powerfully grounds abstract threats in tangible human and business impacts, making it essential viewing for those accountable for institutional resilience and strategic direction.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage