---
title: "Cyber Attacks and the Internet | Mikko Hyppönen | Negotiator 138"
titleOriginal: "Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138"
episodeNumber: "138"
guest: "Mikko Hyppönen"
datePublished: 2022-05-21
duration: "49:13"
youtube: "https://www.youtube.com/watch?v=Q12y-qmgygc"
originalLanguage: "fi"
topics: ["ai_enterprise_tech","geopolitics"]
subtitleMethod: "none"
provenance: "Owner page assembled from YouTube metadata, the neuvottelija.fi episode record and the publisher's own chapter marks, translated one for one. The marks are genuine: nine of them, with gaps from 108 to over 800 seconds, tracking the recording rather than a grid; two of the Finnish titles carry stray timestamp prefixes that do not match their own positions, and those have been dropped in translation because each mark's own timestamp is what is published. No transcript is published here — the channel has no English caption track for this episode and the Finnish one is YouTube's automatic track. The episode is built around the guest's book, published in English shortly before recording, and the guest worked for F-Secure, whose split into two listed companies is discussed in it. One chapter compares the guest's 1980s coding history with the host's own."
fiCanonical: "https://www.neuvottelija.fi/fi/episodes/188-kyberhyokkaykset-ja-internet-mikko-hypponen-neuvottelija-138"
canonical: https://www.neuvottelija.com/podcast/episodes/ep138-kyberhyokkaykset-ja-internet-mikko-hypponen/
---
# Cyber Attacks and the Internet | Mikko Hyppönen | Negotiator 138

English subtitles are not available on this page. This is an episode summary, not a curated transcript.

## Chapters

- [00:00](https://www.youtube.com/watch?v=Q12y-qmgygc&t=0s) Internet (WSOY 2021) and If It's Smart, It's Vulnerable (Wiley, 2022): selling the book abroad. Hyppönen's law. Do smart devices and IoT connections create a Black Mirror dystopia? Denial-of-service attacks. Where the book's title came from, and what the TED talk did for it
- [07:05](https://www.youtube.com/watch?v=Q12y-qmgygc&t=425s) Elon Musk's VIC-20 programming and the game Blastar. The Commodore 64 architecture. Mikko and Ari Hyppönen's 1987 Finnish adventure game Paha Juttu against Sami and Topi Miettinen's EPROM coding. The manic gaming and coding era of the 1980s. Musk's aims for Mars and for AI, and Iain M. Banks's influence. Mark Shuttleworth, SSL and the certificate authority business, Ubuntu
- [13:10](https://www.youtube.com/watch?v=Q12y-qmgygc&t=790s) F-Secure and WithSecure splitting into listed B2C and B2B companies. The nSense and MWR acquisitions. Norton, 2NS, Nixu. White-hat hacking and security consulting. 'Robbing' a Danish bank — that is, a security audit that reached the server room
- [18:00](https://www.youtube.com/watch?v=Q12y-qmgygc&t=1080s) A short history of viruses, worms and malware: Brain in 1986, internet viruses, email, and making money from malware from 2003 on. Ninety-eight per cent of malware now exists for money
- [19:48](https://www.youtube.com/watch?v=Q12y-qmgygc&t=1188s) The other two per cent: state espionage and cyber war. Russia's cyber war against Ukraine, NotPetya against A.P. Møller. The American and Israeli Stuxnet attack on Iran's nuclear plant
- [26:19](https://www.youtube.com/watch?v=Q12y-qmgygc&t=1579s) The rules of cyber war, such as a kill switch. NATO's centre of excellence in Tallinn. North Korea's WannaCry ransomware
- [28:55](https://www.youtube.com/watch?v=Q12y-qmgygc&t=1735s) Bitcoin, the dark web and the Tor network. The responsibility and ethics of technology. Hidden services inside Tor. The Torilauta and Silk Road cases
- [42:51](https://www.youtube.com/watch?v=Q12y-qmgygc&t=2571s) Linux, GitHub, Android. 'Finland's most important person', Linus Torvalds
- [44:21](https://www.youtube.com/watch?v=Q12y-qmgygc&t=2661s) China's internet infrastructure: slowing software down rather than blocking it. Russia will not leave the internet. Does the Neuvottelija community know any China specialists?

## Summary

The security researcher Mikko Hyppönen talks about his book Internet, published in English as If It's Smart, It's Vulnerable. By Hyppönen's law, every smart networked device is always also hackable, and the episode explains why surveillance cameras and home routers are the most important tool in denial-of-service attacks. The conversation runs through the history of malware from the first PC virus to state cyber weapons such as NotPetya, Stuxnet and WannaCry, and how a power cut in Ghana saved Maersk. It closes on the logic of China's firewall and whether Russia could detach itself from the internet.

## The law is about design, not risk

Hyppönen's law says that if a device is smart, it is vulnerable. Read as a warning it is unremarkable; read as a statement about design it is sharper — the network connection that makes the feature possible is the same thing that makes the attack possible, so the exposure cannot be engineered away while keeping the feature.

## Ninety-eight against two

Almost all malware exists to make money, and a small remainder serves states. That ratio is the most actionable number in the episode, because it tells an ordinary organisation which adversary it is actually facing — and it is not the one the headlines describe.

## Maersk was not the target

NotPetya was aimed at Ukraine and took down a Danish shipping company, which stayed in business partly because a power cut in Ghana had left one domain controller offline. The anecdote is memorable; the general point is that a state cyber weapon does not stay inside the country it was aimed at, and cannot be built so that it would.


## Watch

The recording lives on the Neuvottelija channel: [Kyberhyökkäykset ja Internet | Mikko Hyppönen | Neuvottelija 138](https://www.youtube.com/watch?v=Q12y-qmgygc).
A Finnish edition of this episode is published at [www.neuvottelija.fi](https://www.neuvottelija.fi/fi/episodes/188-kyberhyokkaykset-ja-internet-mikko-hypponen-neuvottelija-138).

## In depth

The Neuvottelija AI editions carry a long-form write-up of this episode:
[English](https://www.neuvottelija.com/ai/ep138-kyberhyokkaykset-ja-internet-mikko-hypponen/) · [suomeksi](https://www.neuvottelija.fi/tools/ep138-kyberhyokkaykset-ja-internet-mikko-hypponen/).

## Explore the ideas in depth

- [Enterprise AI Agents: Economics, Governance and the Shift From Tools to Workers](https://www.neuvottelija.com/guides/enterprise-ai-agents-economics-and-governance/): A guide to enterprise AI agents — the real cost model behind agent work, why owning your own stack is becoming a strategic question, a working governance framework with approval gates and audit trails, the agent risk matrix, the EU AI Act timeline as it stands, and who captures the productivity gains. Grounded in a real multi-agent lab, two 2026 keynotes, and Neuvottelija conversations.
- [Negotiation Strategy, Leverage and Power: Reading the Counterparty You Actually Have](https://www.neuvottelija.com/guides/negotiation-strategy-leverage-and-power/): A negotiation guide from the co-author of Neuvotteluvalta — the sources of leverage, BATNA and anchoring in practice, using information asymmetry, breaking deadlocks, and what to do when the counterparty negotiates on power rather than consensus. Grounded in Neuvottelija conversations and two decades of negotiation writing.
- [Nordic SaaS Valuation & M&A: How AI Reprices Software Companies](https://www.neuvottelija.com/guides/nordic-saas-valuation-and-ma/): How software companies in the Nordics are valued and sold as AI moves inference into the cost of goods sold — where multiples stand in mid-2026, the metrics that get repriced, why vertical SaaS defends its premium, AI due diligence, and the shift from seats to outcomes. Grounded in Translink's SaaS valuation work and Neuvottelija conversations.

---

Cite as: Sami Miettinen, Neuvottelija — Cyber Attacks and the Internet | Mikko Hyppönen | Negotiator 138, https://www.neuvottelija.com/podcast/episodes/ep138-kyberhyokkaykset-ja-internet-mikko-hypponen/, 2022-05-21. For quotes include episode 138 and timestamp.
