Episode 138 · 2022-05-21 · 49:13 · Original in Finnish
Cyber Attacks and the Internet | Mikko Hyppönen | Negotiator 138
Originally published as “Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138”
The security researcher Mikko Hyppönen talks about his book Internet, published in English as If It's Smart, It's Vulnerable. By Hyppönen's law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China's firewall and whether Russia could detach itself from the internet.
Core theses
- Hyppönen's law is a design claim, not a warning: connecting a device is what makes it attackable, so the vulnerability arrives with the feature.
- Ninety-eight per cent of malware exists to make money and two per cent for states — a ratio that decides what most defenders should actually prepare for.
- NotPetya shows collateral damage is the normal outcome of a state cyber weapon, not an accident of one: Maersk was not the target.
- China slows software down rather than blocking it, which is a more durable control than a firewall because it produces no visible moment of censorship.
Watch and listen
Key moments
- 00:00 — Internet (WSOY 2021) and If It's Smart, It's Vulnerable (Wiley, 2022): selling the book abroad. Hyppönen's law. Do smart devices and IoT connections create a Black Mirror dystopia? Denial-of-service attacks. Where the book's title came from, and what the TED talk did for it
- 07:05 — Elon Musk's VIC-20 programming and the game Blastar. The Commodore 64 architecture. Mikko and Ari Hyppönen's 1987 Finnish adventure game Paha Juttu against Sami and Topi Miettinen's EPROM coding. The manic gaming and coding era of the 1980s. Musk's aims for Mars and for AI, and Iain M. Banks's influence. Mark Shuttleworth, SSL and the certificate authority business, Ubuntu
- 13:10 — F-Secure and WithSecure splitting into listed B2C and B2B companies. The nSense and MWR acquisitions. Norton, 2NS, Nixu. White-hat hacking and security consulting. 'Robbing' a Danish bank — that is, a security audit that reached the server room
- 18:00 — A short history of viruses, worms and malware: Brain in 1986, internet viruses, email, and making money from malware from 2003 on. Ninety-eight per cent of malware now exists for money
- 19:48 — The other two per cent: state espionage and cyber war. Russia's cyber war against Ukraine, NotPetya against A.P. Møller. The American and Israeli Stuxnet attack on Iran's nuclear plant
- 26:19 — The rules of cyber war, such as a kill switch. NATO's centre of excellence in Tallinn. North Korea's WannaCry ransomware
- 28:55 — Bitcoin, the dark web and the Tor network. The responsibility and ethics of technology. Hidden services inside Tor. The Torilauta and Silk Road cases
- 42:51 — Linux, GitHub, Android. 'Finland's most important person', Linus Torvalds
- 44:21 — China's internet infrastructure: slowing software down rather than blocking it. Russia will not leave the internet. Does the Neuvottelija community know any China specialists?
Summary
The security researcher Mikko Hyppönen talks about his book Internet, published in English as If It’s Smart, It’s Vulnerable. By Hyppönen’s law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China’s firewall and whether Russia could detach itself from the internet.
The law is about design, not risk
Hyppönen’s law says that if a device is smart, it is vulnerable. Read as a warning it is unremarkable; read as a statement about design it is sharper — the network connection that makes the feature possible is the same thing that makes the attack possible, so the exposure cannot be engineered away while keeping the feature.
Ninety-eight against two
Almost all malware exists to make money, and a small remainder serves states. That ratio is the most actionable number in the episode, because it tells an ordinary organisation which adversary it is actually facing — and it is not the one the headlines describe.
Maersk was not the target
NotPetya was aimed at Ukraine and took down a Danish shipping company, which stayed in business partly because a power cut in Ghana had left one domain controller offline. The anecdote is memorable; the general point is that a state cyber weapon does not stay inside the country it was aimed at, and cannot be built so that it would.
Watch
The recording lives on the Neuvottelija channel: Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138. A Finnish edition of this episode is published at www.neuvottelija.fi.
In depth
The Neuvottelija AI editions carry a long-form write-up of this episode: English · suomeksi.
Go deeper
Explore the ideas in depth
Guides connected to this conversation, with frameworks and further reading.
Enterprise AI Agents: Economics, Governance and the Shift From Tools to Workers
A guide to enterprise AI agents — the real cost model behind agent work, why owning your own stack is becoming a strategic question, a working governance framework with approval gates and audit trails, the agent risk matrix, the EU AI Act timeline as it stands, and who captures the productivity gains. Grounded in a real multi-agent lab, two 2026 keynotes, and Neuvottelija conversations.
Negotiation Strategy, Leverage and Power: Reading the Counterparty You Actually Have
A negotiation guide from the co-author of Neuvotteluvalta — the sources of leverage, BATNA and anchoring in practice, using information asymmetry, breaking deadlocks, and what to do when the counterparty negotiates on power rather than consensus. Grounded in Neuvottelija conversations and two decades of negotiation writing.
Nordic SaaS Valuation & M&A: How AI Reprices Software Companies
How software companies in the Nordics are valued and sold as AI moves inference into the cost of goods sold — where multiples stand in mid-2026, the metrics that get repriced, why vertical SaaS defends its premium, AI due diligence, and the shift from seats to outcomes. Grounded in Translink's SaaS valuation work and Neuvottelija conversations.
People and topics
Guests: Mikko Hyppönen
Topics: AI & Enterprise Tech Geopolitics
