Defendable internet¶

These lectures argue that in IT security, offensive problems are technical, while most defensive problems are political and organisational. An attacker has the luxury of focusing on the technical; a defender navigates budgets, incentives, and committees. The talks are old by internet standards. The incentives they describe have aged rather less.
Black Hat 2017: Why we are not building a defendable internet¶
In an earlier talk, Rearchitecting a defendable internet, Thomas Dullien (aka Halvar Flake) explored what technical measures could yield defendable devices, deliberately setting aside politics and economics. The 2017 keynote picks up the other half: who is incentivised by whom to do what, and how those incentives fail to produce the security level anyone claims to want. CISOs, security vendors, computer manufacturers and cyber insurers each appear, along with an alternate reality where the incentives line up, examined for its differences from the reality of 2017.
🎥 External video: Keynote, Why We Are Not Building a Defendable Internet (opens YouTube)
Black Hat 2022: Our kryptonite, a defendable internet¶
Daniel Cuthbert follows up five years on, which in internet years is a long time. What changed for the better or worse? Does good security mean a lock-in approach, or is an open, transparent, and still secure internet buildable? Can the cycle of building tools to fix the tools that were not secure enough be stopped?
The argument runs roughly so: the industry keeps producing reactive tools to cover for the shortcomings of earlier insecure products, web application firewalls to patch what the firewalls missed, until the patch itself needs patching. Meanwhile most successful attacks still arrive by run-of-the-mill techniques rather than zero-days, and blaming Dave from accounts for clicking is easier than asking why one click could sink the ship. The lever Cuthbert reaches for is the buyer: procurement that asks vendors hard questions about threat modelling, supply chains and memory-safe languages, a baseline security regulation, and a kitemark worth competing for.
🎥 External video: Keynote, Our Kryptonite: A Defendable Internet (Black Hat 2022) on YouTube
Thank you both for mentioning the unmentionables. The recurring argument is that this appears systemic rather than a loose confederation of separate disciplines and individual choices, and if that is so, improving the parts will not, by itself, improve the whole. Every problem is part of The Mess, and the Big Security Mess includes all the messes that besiege globalising complex capital, and the incentives it instills.
The clerk’s note¶
From the clerks, on why this file is not updated often
Reviewed July 2026. This file is deliberately older than the others. The lectures above, from 2017 and 2022, describe incentive structures rather than incidents, and the clerks have found nothing in the intervening years that retires them. They do note, with some interest, that the 2022 lecture’s asks, a baseline security regulation and a kitemark, resemble what later arrived as the Cyber Resilience Act and its CE marking, chronicled in the regulatory file; whether resemblance amounts to influence is beyond the file’s competence. Europe is, either way, testing whether law can supply the incentives the market did not. When a talk appears that makes these two obsolete, it will be filed here with some relief.