Neuvottelija.com

Episode 138 · 2022-05-21 · 49:13 · Original in Finnish

Cyber Attacks and the Internet | Mikko Hyppönen | Negotiator 138

Originally published as “Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138”

The security researcher Mikko Hyppönen talks about his book Internet, published in English as If It's Smart, It's Vulnerable. By Hyppönen's law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China's firewall and whether Russia could detach itself from the internet.

Guest: Mikko Hyppönen · Host: Sami Miettinen

Core theses

  1. Hyppönen's law is a design claim, not a warning: connecting a device is what makes it attackable, so the vulnerability arrives with the feature.
  2. Ninety-eight per cent of malware exists to make money and two per cent for states — a ratio that decides what most defenders should actually prepare for.
  3. NotPetya shows collateral damage is the normal outcome of a state cyber weapon, not an accident of one: Maersk was not the target.
  4. China slows software down rather than blocking it, which is a more durable control than a firewall because it produces no visible moment of censorship.

Watch and listen

Watch on YouTube JSON Markdown

Key moments

  1. 00:00 — Internet (WSOY 2021) and If It's Smart, It's Vulnerable (Wiley, 2022): selling the book abroad. Hyppönen's law. Do smart devices and IoT connections create a Black Mirror dystopia? Denial-of-service attacks. Where the book's title came from, and what the TED talk did for it
  2. 07:05 — Elon Musk's VIC-20 programming and the game Blastar. The Commodore 64 architecture. Mikko and Ari Hyppönen's 1987 Finnish adventure game Paha Juttu against Sami and Topi Miettinen's EPROM coding. The manic gaming and coding era of the 1980s. Musk's aims for Mars and for AI, and Iain M. Banks's influence. Mark Shuttleworth, SSL and the certificate authority business, Ubuntu
  3. 13:10 — F-Secure and WithSecure splitting into listed B2C and B2B companies. The nSense and MWR acquisitions. Norton, 2NS, Nixu. White-hat hacking and security consulting. 'Robbing' a Danish bank — that is, a security audit that reached the server room
  4. 18:00 — A short history of viruses, worms and malware: Brain in 1986, internet viruses, email, and making money from malware from 2003 on. Ninety-eight per cent of malware now exists for money
  5. 19:48 — The other two per cent: state espionage and cyber war. Russia's cyber war against Ukraine, NotPetya against A.P. Møller. The American and Israeli Stuxnet attack on Iran's nuclear plant
  6. 26:19 — The rules of cyber war, such as a kill switch. NATO's centre of excellence in Tallinn. North Korea's WannaCry ransomware
  7. 28:55 — Bitcoin, the dark web and the Tor network. The responsibility and ethics of technology. Hidden services inside Tor. The Torilauta and Silk Road cases
  8. 42:51 — Linux, GitHub, Android. 'Finland's most important person', Linus Torvalds
  9. 44:21 — China's internet infrastructure: slowing software down rather than blocking it. Russia will not leave the internet. Does the Neuvottelija community know any China specialists?

Summary

The security researcher Mikko Hyppönen talks about his book Internet, published in English as If It’s Smart, It’s Vulnerable. By Hyppönen’s law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China’s firewall and whether Russia could detach itself from the internet.

The law is about design, not risk

Hyppönen’s law says that if a device is smart, it is vulnerable. Read as a warning it is unremarkable; read as a statement about design it is sharper — the network connection that makes the feature possible is the same thing that makes the attack possible, so the exposure cannot be engineered away while keeping the feature.

Ninety-eight against two

Almost all malware exists to make money, and a small remainder serves states. That ratio is the most actionable number in the episode, because it tells an ordinary organisation which adversary it is actually facing — and it is not the one the headlines describe.

Maersk was not the target

NotPetya was aimed at Ukraine and took down a Danish shipping company, which stayed in business partly because a power cut in Ghana had left one domain controller offline. The anecdote is memorable; the general point is that a state cyber weapon does not stay inside the country it was aimed at, and cannot be built so that it would.

Watch

The recording lives on the Neuvottelija channel: Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138. A Finnish edition of this episode is published at www.neuvottelija.fi.

In depth

The Neuvottelija AI editions carry a long-form write-up of this episode: English · suomeksi.

Go deeper

Guides connected to this conversation, with frameworks and further reading.

People and topics

Guests: Mikko Hyppönen

Topics: AI & Enterprise Tech Geopolitics

AI and agent resources


Source and content status

Provenance: Finnish source: Owner page assembled from YouTube metadata, the neuvottelija.fi episode record and the publisher's own chapter marks, translated one for one. The marks are genuine: nine of them, with gaps from 108 to over 800 seconds, tracking the recording rather than a grid; two of the Finnish titles carry stray timestamp prefixes that do not match their own positions, and those have been dropped in translation because each mark's own timestamp is what is published. No transcript is published here — the channel has no English caption track for this episode and the Finnish one is YouTube's automatic track. The episode is built around the guest's book, published in English shortly before recording, and the guest worked for F-Secure, whose split into two listed companies is discussed in it. One chapter compares the guest's 1980s coding history with the host's own.. English subtitles: not available on this page; this is an episode summary, not a curated transcript. QA coverage 0% (metadata only). Original episode: neuvottelija.fi. Imported 2026-09-20 · last reviewed 2026-09-20. Passages the source audio left genuinely ambiguous are marked [unclear] rather than guessed.