Dark Capabilities - When Tech Companies Become Threat Actors

Greg Conti (Gideon), Tom Cross (Head of Threat Research · Get Real Security)

DEF CON 33 · Day 1 · Main Stage

Overview

In an era where technology giants wield immense influence, Tom Cross and Greg Conti presented a provocative and deeply analytical talk at DEF CON titled "Dark Capabilities - When Tech Companies Become Threat Actors." The core thesis challenges the conventional understanding of corporate power, arguing that large tech companies possess capabilities that often rival, or even surpass, those of nation-states, extending far beyond their stated commercial purposes. This talk urges the security community to look beyond explicit product features and consider the latent, unacknowledged, and potentially dangerous functionalities inherent in ubiquitous technologies.

Watch on YouTube

Visual summary for Dark Capabilities - When Tech Companies Become Threat Actors by Greg Conti, Tom Cross
Visual summary for Dark Capabilities - When Tech Companies Become Threat Actors by Greg Conti, Tom Cross

Key moments

  1. 0:00 Introduction and talk's core question
  2. 2:00 Tech capabilities evolving beyond just privacy concerns
  3. 2:50 Ukraine war: Catalyst for private company actions
  4. 4:00 Understanding 'Effects-Based Operations' for corporations
  5. 4:50 Historical examples of sabotage and shifting behaviors
  6. 5:50 Corporate discomfort with 'dark capabilities' discussion
  7. 6:30 Critical questions for organizations: law, ethics, Ulysses pact

Dark Capabilities - When Tech Companies Become Threat Actors

Speakers: Greg Conti (Gideon); Tom Cross (Head of Threat Research, Get Real Security)

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=I5N7Ro-aTh4

Overview

In an era where technology giants wield immense influence, Tom Cross and Greg Conti presented a provocative and deeply analytical talk at DEF CON titled "Dark Capabilities - When Tech Companies Become Threat Actors." The core thesis challenges the conventional understanding of corporate power, arguing that large tech companies possess capabilities that often rival, or even surpass, those of nation-states, extending far beyond their stated commercial purposes. This talk urges the security community to look beyond explicit product features and consider the latent, unacknowledged, and potentially dangerous functionalities inherent in ubiquitous technologies.

The speakers highlighted a critical shift in policy discussions surrounding tech companies. While historically focused on privacy concerns due to data collection, the proliferation of advanced technologies like robots, drones, and ubiquitous IoT devices introduces entirely new categories of capabilities with profound physical and cognitive consequences. The presentation aimed to provoke introspection, encouraging attendees to question the distinction between what systems are supposed to be and what they really are, especially when geopolitical circumstances, such as armed conflict, dramatically alter corporate decision-making and ethical boundaries.

This article delves into the comprehensive framework presented by Cross and Conti, exploring the origins of these "dark capabilities," their technical underpinnings, and the stark implications for both offensive and defensive security strategies. It dissects how corporate motivations can shift under pressure, how governments might leverage private sector assets, and what steps companies, governments, and individual users must take to understand and mitigate these emerging threats.

Background

▶ Watch: Introduction and talk's core question (0:00)

The genesis of this discussion, as articulated by the speakers, stemmed from observing the multifaceted corporate responses to the 2022 invasion of Ukraine. Beyond typical sanctions and market exits, thousands of companies made independent decisions, ranging from blocking IP ranges to providing information security services or critical infrastructure, such as Elon Musk's Starlink satellite network. More aggressively, some npm package maintainers embedded logic bombs in widely used code, designed to destroy data when executed from specific IP ranges. This spectrum of actions underscored a critical point: private entities can exert significant influence, often with effects akin to traditional military effects-based operations, which aim to channel behavior and create consequences without necessarily resorting to kinetic force.

Conti and Cross drew parallels to historical examples of unconventional warfare, referencing the Dutch Resistance Museum and the OSS Simple Sabotage Manual from World War II. This manual detailed bureaucratic and operational methods for employees to subtly disrupt an occupying force's efforts, highlighting how individual behavior and organizational capabilities can be repurposed in times of conflict. This historical context served to illustrate that the strategic re-evaluation of capabilities during conflict is not new, but its application to modern tech corporations introduces unprecedented scale and complexity.

The speakers introduced a crucial question: "Who's in charge here? Are the corporations in charge? Are the governments in charge?" They argued that traditional models of cyberspace actors often omit corporations, despite their immense power. By comparing the capabilities of major tech companies against nation-states in the cyber and cognitive domains, they suggested that the contest is often "close," with some tech titans potentially overmatching smaller countries. This dynamic is shaped by levers of power each side can exert: companies influence governments through lobbying, campaign donations, lawsuits, and market exits, while governments influence companies through laws, regulation, law enforcement, taxes, market access, purchasing authority, and even espionage or sabotage. This power imbalance becomes particularly pronounced when a large corporation interacts with a smaller country, or vice-versa, influencing the extent of coercion or compromise.

To quantify this power, Cross and Conti presented market capitalization data, showing that in one recent snapshot, companies like Microsoft, Apple, Nvidia, Amazon, Alphabet, and Meta ranked among the top 24 entities globally by market cap, rivaling or exceeding the total market cap of entire national stock exchanges. This financial might translates into significant operational and geopolitical leverage. Furthermore, they adapted the M.I.C.E. model (Money, Ideology, Coercion, Ego), typically used in human intelligence, to analyze corporate leadership motivations. While corporations are usually assumed to act in their financial best interest, the M.I.C.E. model suggests that ideological motivations, ego, or external coercion could lead corporate leadership to make decisions not aligned with economic interests, particularly during conflict. This introduces unpredictability and new vectors for influence.

Finally, the talk explored the nuanced relationship between corporations and governments, moving beyond a simple state-sponsored vs. non-state-sponsored dichotomy. Drawing on concepts from Jason Healey, they depicted a spectrum where governments might encourage criminal groups, turn a blind eye, or even directly align with corporate offensive actions. Conversely, situations arise where corporate actions (e.g., unilateral deactivation of satellites) are not aligned with national strategy, or where governments use tools like the Defense Production Act to commandeer corporate capabilities against a company's will. These dynamics underscore that corporate and governmental behaviors diverge significantly between peacetime, where financial motivation and compliance dominate, and wartime, where governments become more coercive and companies may prioritize operational continuity amidst conflict. Governments, through a military lens, would view corporate capabilities as potential assets for intelligence collection, reconnaissance, influence operations, network access, logistics, or even kinetic effects, transforming everyday products into strategic tools.

Key Findings

▶ Watch: Ukraine war: Catalyst for private company actions (2:50)

The talk "Dark Capabilities - When Tech Companies Become Threat Actors" unveiled several critical findings that redefine how we perceive corporate power and its implications for security:

  1. Unacknowledged Capabilities: Tech companies possess a vast array of capabilities that extend far beyond their advertised features or stated purposes. These "dark capabilities" often arise from the inherent functionality of a product's components (sensors, connectivity, processing) or the sheer scale of its deployment, rather than explicit design intent for malicious use.
  2. Corporate Power Rivals Nation-States: The largest tech companies command resources, data, and technological sophistication that, in the cyber and cognitive domains, can rival or even exceed the power of many nation-states. This makes them significant, yet often overlooked, actors in geopolitical conflicts and influence operations.
  3. Conflict Transforms Corporate Behavior: Times of conflict dramatically alter the decision-making processes and ethical frameworks within corporations. Actions previously considered "crazy" or outside a company's purview can become perceived as necessary or vital, driven by shifting motivations (beyond pure economics), external pressures, or ideological alignment.
  4. The "Pyramid of Capabilities": A hierarchical model illustrates the true scope of a system's power: from openly exposed features (the "tip of the iceberg"), to actual but unstated uses, to capabilities known but deliberately unused, and finally, to unimagined capabilities that exist due to a lack of foresight or imagination on the company's part, but which a threat actor might readily identify.
  5. Expanded Threat Modeling Required: Traditional threat modeling must evolve to include not just external attackers or malicious users, but also potential misuse by a company's own executive leadership team or the coerced appropriation of capabilities by a government. This necessitates a shift towards considering internal and authorized misuse scenarios.
  6. "It's Not What a System Says It Does, It's What It Can Do": This central tenet emphasizes that the true security posture and potential for misuse of any technology are determined by its inherent technical capabilities (e.g., actuation capabilities, sensor suite, communications capabilities), rather than its marketing copy, user agreements, or intended functionality.

Technical Deep Dive

▶ Watch: Understanding 'Effects-Based Operations' for corporations (4:00)

The technical deep dive of the talk wasn't about specific exploits or vulnerabilities, but rather a profound re-evaluation of the inherent capabilities of common technologies, viewed through the lens of a potential threat actor or coercive government. The speakers introduced a "pyramid of capabilities" [20:00] to illustrate this: at the top are the "free" or premium capabilities a product exposes; beneath that are the capabilities it actually uses but doesn't talk about; further down are capabilities it has but has chosen not to use (e.g., early augmented reality glasses with facial recognition); and at the base, the broadest layer, are additional capabilities that exist but the company simply lacks the imagination to consider.

To exemplify this, the speakers explored several everyday products and company types:

  • The Humble Wi-Fi Enabled Light Bulb (The Tron Loom):
  • Stated Purpose: Home convenience, on/off control.
  • Inherent Capabilities: Power source, network connectivity. These alone can generate pattern of life data (when lights are on/off). It could potentially perform Bluetooth or Wi-Fi device scanning. A connected mobile app provides precise location data.
  • Augmented Capabilities (Hypothetical Tron Loom): Adding a microphone and motion sensors transforms it into a sophisticated surveillance device. Chat GPT was used to generate marketing copy for this "smarter light," highlighting features like "adaptive presence detection," "intelligent room insights," and "real-time updates when unexpected movement is detected." The cynical mission statement generated was: "to disguise surveillance and adtech infrastructure as home convenience." The global deployment of such devices creates an unprecedented, pervasive surveillance network [23:00].
  • The Evil Vacuum Cleaner Robot:
  • Stated Purpose: Household hygiene, autonomous cleaning.
  • Inherent Capabilities: Mobility, mapping sensors (LIDAR, cameras), power source, network connectivity, often microphones.
  • Dark Capabilities:
  • Covert mapping: Creating detailed floor plans of homes for future intrusion planning.
  • Audio and video surveillance: Collecting intelligence, potentially for blackmail, targeted advertising, or ideological compliance.
  • Electromagnetic (EM) spectrum mapping/jamming: Identifying and potentially disrupting other wireless devices.
  • IoT device control: Interacting with and controlling other smart home devices.
  • Non-audible sound generation: Emitting frequencies to influence humans or pets, potentially causing distress without obvious cause.
  • DNA collection: Picking up hair, skin cells, and other biological material.
  • Biometric harvesting: Capturing facial data or gait patterns.
  • Covert cyber/physical payload delivery: Delivering malware via USB or physically transporting small items.
  • "Accidental" malfunction: Strategically tripping occupants or causing minor damage.
  • Mission Statement: "to normalize autonomous surveillance under the guise of household hygiene."
  • Facets for Analyzing Capabilities: The speakers identified key attributes for assessing any product's true capabilities: actuation capabilities (can it interact physically?), power source, physical areas it can access, mobility, its sensor suite, and communications capabilities.
  • The Evil Cybersecurity Company:
  • Stated Purpose: Protection, threat detection, incident response.
  • Dark Capabilities: Leveraging global sensor networks and intelligence analysis teams for:
  • Attribution for hire: Fabricating evidence to frame specific threat actors.
  • Silent data exfiltration: Covertly stealing data from client networks.
  • Ignoring specific alerts/malware: Deliberately allowing certain threats to persist or bypass detection.
  • Searching user files at scale: Accessing and analyzing sensitive data across an entire ecosystem of protected clients.
  • Mission Statement: "to turn paranoia into pipeline FUD into ARR and Z and ODA into Q4 growth opportunities."
  • Other Corporate Dark Capabilities:
  • Cloud Companies: Harvest tokens and secrets across their ecosystem, throttle critical infrastructure.
  • AI Companies: Enable AI-orchestrated belief collapse, model and simulate real individuals at scale, deploy synthetic persona swarms.
  • Ride Share Companies: Utilize mobile platforms for covert mapping, selectively deny service to specific cars or drivers, listen in on fleet-wide conversations, or coerce transport.
  • Mega-Corporations (Tony Stark Analogy): A conglomerate with diverse portfolio companies (e.g., adult websites, dating sites, space/government contractors, robotics firms, defense contractors, genomics companies, payment processors) would possess capabilities "off the scale," far exceeding any single entity.

Looking to the near future, the speakers highlighted emerging capabilities that will amplify these concerns: increasingly ubiquitous robotic systems (robot taxis, sophisticated home robots), neural interfacing technologies, and advanced AI models capable of creating predictive models of individual behavior or even parts of entire civilizations. The underlying principle is that the combination of pervasive sensors, sophisticated processing, and widespread network access grants these entities a level of insight and potential control that demands urgent and imaginative scrutiny.

Demo / Proof of Concept

▶ Watch: Corporate discomfort with 'dark capabilities' discussion (5:50)

While "Dark Capabilities" did not feature a live technical demonstration or code execution, the entire presentation served as a powerful conceptual proof of concept. Cross and Conti effectively demonstrated the potential for misuse by systematically dissecting common technologies and corporate structures, then extrapolating their inherent functionalities to illustrate plausible, albeit unsettling, "dark capabilities."

Through vivid hypothetical scenarios – such as the "evil vacuum cleaner robot" mapping homes for future intrusion or the "Tron Loom" light bulb disguising surveillance as convenience – the speakers painted a clear picture of how existing and near-future technologies could be repurposed. Their use of AI (ChatGPT) to generate cynical mission statements and product features for these hypothetical scenarios further underscored the ease with which benign technology can be reframed for nefarious purposes. This analytical approach, rather than a traditional demo, was crucial for challenging the audience's assumptions and sensitizing them to the latent power residing within the tech ecosystem.

Defensive Implications

▶ Watch: Critical questions for organizations: law, ethics, Ulysses pact (6:30)

The central message for defenders is a radical shift in perspective: "It's not what a system says it does, it's what it can do." This requires a proactive and imaginative approach to security, moving beyond traditional threat models.

For Companies, the speakers urged a "red teaming" exercise: "What if we were evil?" [32:00]. This involves systematically listing all potential "dark capabilities" of their products and services, including those unimagined or deliberately unused, and then assessing the risks. Companies must expand their threat modeling to consider not only misuse by external criminals or users, but critically, misuse by their own executive leadership team and the appropriation of capabilities by a government. To mitigate these risks, companies should consider:

  • Architectural Controls: Implementing technical safeguards that prevent capabilities from being repurposed for unauthorized ends.
  • Organizational Checks and Balances: Establishing internal governance structures, potentially akin to a "Ulysses pact" [06:00], where organizations bind themselves to certain decisions or ethical boundaries to prevent deviation under pressure.
  • Engagement with Civil Society: Collaborating with NGOs or non-profits for independent audits and certifications regarding ethical use of technology, providing a layer of external accountability.
  • AI Safety Principles: Learning from initiatives like Anthropic's AI safety work, which focuses on guarding against end-user misuse of large language models (e.g., preventing creation of chemical weapons instructions). However, the speakers noted that even these efforts often explicitly exclude internal or authorized misuse, highlighting a gap that needs to be addressed [33:00].

For Governments, the call to action is to broaden their national security engagement beyond narrowly defined "critical infrastructure." Social media platforms, robot taxis, and smart home devices, while not traditionally critical infrastructure, possess "dangerous capabilities" that can be leveraged for influence or physical effects [34:00]. Governments should:

  • Systematic Capability Analysis: Conduct comprehensive analyses of private sector capabilities, considering both offensive utilization and defensive control.
  • Policy Frameworks: Develop new policy frameworks and legal tools (beyond existing mechanisms like the Defense Production Act) to control or influence these capabilities in alignment with national strategy.
  • Strategic Relationships: Build robust relationships with tech organizations, utilizing both "carrots and sticks" to ensure responsible development and use of powerful technologies.

For Users, the primary defensive implication is a heightened sense of skepticism and critical inquiry. Individuals should "not trust the stated purpose of anything" [36:00]. Instead, they must cultivate an awareness to constantly ask: "What can this system actually do?" Understanding the inherent sensor suite, actuation capabilities, and communications capabilities of devices is paramount. This user-level sensitization helps identify potential surveillance vectors, data collection practices, and avenues for manipulation that are often obscured by marketing or convenience. The ultimate defense lies in a collective, informed understanding that the true power of technology resides in its underlying capabilities, not its advertised features.

Key Takeaways

  • Unacknowledged Power: Most companies, while not intending misuse, possess vast capabilities that extend far beyond their stated purposes. Ignoring this latent power creates significant risks and invites potential misuse.
  • Evolving Threat Models: Organizations must proactively understand their full spectrum of capabilities and expand their threat models to include potential misuse by executive leadership and appropriation by governments, especially during times of conflict.
  • Internal Controls are Paramount: Implementing well-informed architectural controls and organizational checks and balances (like the Ulysses pact) is essential to prevent the repurposing of technologies for unintended or harmful ends.
  • Tailored Oversight is Needed: Governments must develop new, tailored policy frameworks and oversight mechanisms that go beyond traditional critical infrastructure definitions to address the dangerous capabilities inherent in pervasive consumer technologies.
  • User Skepticism is Key: Individuals should adopt a stance of healthy skepticism, questioning the stated purpose of any system and instead focusing on its actual, inherent capabilities, particularly its sensor suite and communications capabilities.
  • Circumstances Drive Decisions: Recognize that extreme circumstances, such as armed conflict, can dramatically alter ethical boundaries and decision-making processes, making previously "crazy" actions seem necessary or vital, underscoring the urgency of addressing these "dark capabilities" today.

About the Speaker(s)

Tom Cross is the Head of Threat Research at Get Real Security. He is also a Principal at Gideon, a firm focused on security training and consulting. Tom is actively involved in the security community, teaching specialized classes at DEF CON Training, including "Information Operations as Art" and "Adversarial Thinking," which offers a deep dive into vulnerability discovery.

Greg Conti (Gideon) is a former West Point professor and also served as an Armenian cultural officer. Like Tom Cross, he is a Principal at Gideon and contributes to DEF CON Training, where he co-teaches courses on information operations and adversarial thinking. His background reflects a blend of academic rigor, national security experience, and practical cybersecurity expertise.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Cross and Conti are clearly smart people who've done real work in adversarial thinking and information operations, and the framing — tech companies as unacknowledged threat actors with latent 'dark capabilities' — is genuinely worth articulating for a DEF CON audience. The problem is that most of the substance is conceptual scaffolding rather than hard research, and the 'evil vacuum cleaner' thought experiments, while illustrative, don't move much beyond what a thoughtful attendee already suspects.

Heather Calloway (CISO) — SOLID

Cross and Conti make a legitimate and underappreciated point — that corporate capabilities need to be evaluated for what they can do, not just what they say they do — but the talk stays at the level of provocation rather than prescription. The framework is useful, the implications are real, but the defensive guidance is too generic to move institutions.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33