Published: 2021
Author: Nicole Perlroth
Genre: Cyber Thriller / Investigative Journalism / Tech Non-Fiction
Audience: Grades 11–12 (Advanced High School) & Adults
Number of Stars: ★★★★☆ (4/5)
Goodreads Link: This Is How They Tell Me the World Ends
Themes: Cybersecurity Vulnerabilities, The Zero-Day Grey Market, Geopolitical Warfare, Stuxnet Legacy, Infrastructure Fragility.
Review by: Evan Waugh
Publisher’s Summary
THE NEW YORK TIMES BESTSELLER * Winner of the Financial Times & McKinsey Business Book of the Year Award * Bronze Medal, Arthur Ross Book Award (Council on Foreign Relations)
“Written in the hot, propulsive prose of a spy thriller” ( The New York Times), the untold story of the cyberweapons market-the most secretive, government-backed market on earth-and a terrifying first look at a new kind of global warfare.
a software bug that allows a hacker to break into your devices and move around undetected. One of the most coveted tools in a spy’s arsenal, a zero-day has the power to silently spy on your iPhone, dismantle the safety controls at a chemical plant, alter an election, and shut down the electric grid (just ask Ukraine).
For decades, under cover of classification levels and nondisclosure agreements, the United States government became the world’s dominant hoarder of zero-days. U.S. government agents paid top dollar-first thousands, and later millions of dollars-to hackers willing to sell their lock-picking code and their silence. Then the United States lost control of its hoard and the market. Now those zero-days are in the hands of hostile nations and mercenaries who do not care if your vote goes missing, your clean water is contaminated, or our nuclear plants melt down.
Filled with spies, hackers, arms dealers, and a few unsung heroes, written like a thriller and a reference, This Is How They Tell Me the World Ends is an astonishing feat of journalism. Based on years of reporting and hundreds of interviews, Nicole Perlroth lifts the curtain on a market in shadow, revealing the urgent threat faced by us all if we cannot bring the global cyberarms race to heel.
Review
In her masterclass-level non-fiction narrative, This Is How They Tell Me the World Ends, investigative journalist Nicole Perlroth meticulously details the terrifying proliferation of cyberweapons throughout modern history. She anchors her chronological tale around the historical development of the notorious Stuxnet bug—a highly sophisticated computer worm engineered in a joint covert operations effort between the United States and Israel to physically infect and destroy Iran’s underground nuclear centrifuges at Natanz.
What follows this historical case study is a fascinating—and also downright disturbing—firsthand account of the buying and selling of lethal cyberweapons around the world. Shockingly, Perlroth exposes how this hyper-secretive industry was originally built and funded directly by the United States government. The specific kinds of cyberweapons up for sale on the global black and grey markets are primarily software exploits known as zero days. These vulnerabilities form the foundation for systemic hacks that grant bad actors—ranging from despotic regimes and greedy individual hackers to major global military powers—invisible access to our personal information and national data, which can then be weaponized or sold to the highest bidder.
Reading this book completely forced me to rethink my day-to-day relationship with consumer technology. It caused me to reflect on just how incredibly vulnerable ordinary citizens are in an increasingly digital, interconnected world. This existential dread feels especially heavy on the heels of recent alerts from the U.S. intelligence community warning that state-sponsored threats, such as China’s Volt Typhoon hacking collective, have been quietly embedded within America’s critical civilian infrastructure networks for the past five years.
Perlroth does a tremendous job reporting on this complex topic, feeding readers just enough foundational technical information about computer networks, software exploits, and national cybersecurity structures to make them fully knowledgeable. The remainder of the book reads like pure, unadulterated espionage storytelling, and I was absolutely hooked from the very first page. It is a vital, eye-opening four-star read.
💻 The Cyberweapons Market Framework
Perlroth pulls back the curtain on a market economy built around software flaws, tracking how a simple line of broken code transforms into a million-dollar geopolitical asset.
- The Stuxnet Rubicon: The narrative frames the Stuxnet deployment as an irreversible historical pivot point. Before Stuxnet, cyberattacks were restricted to data theft and digital defacement. By bridging the gap between digital code and physical destruction—physically ripping apart uranium centrifuges—the U.S. and Israel demonstrated that code could serve as a proxy for kinetic military air strikes, inadvertently triggering a global cyber arms race.
- The Hoarding Dilemma: Perlroth highlights the systemic paradox of the National Security Agency’s (NSA) Vulnerabilities Equities Process. When the U.S. government discovers a security flaw in consumer software (like Apple’s iOS or Microsoft Windows), it faces a conflicting choice: patch the flaw to protect American citizens, or keep the flaw secret so American intelligence agencies can use it to spy on foreign adversaries.
🎒 Classroom & Curricular Connections
- AP Government, Civics, & International Relations (The Ethics of Cyber Sabotage):
- Activity Idea: “The Vulnerability Equity Debate.” Organize a classroom debate centered on the U.S. government’s hoarding of software vulnerabilities. Group A defends the intelligence community’s need to keep bugs secret to track hostile entities and counter foreign threats. Group B argues from a consumer civil liberties perspective, demonstrating that leaving flaws unpatched exposes civilian cellphones, hospital networks, and utility grids to domestic exploitation.
- Computer Science & Digital Literacy (Demystifying the Technical Mechanics):
- Activity Idea: “The Anatomy of an Exploit.” Help students understand how a zero-day functions by utilizing a technical flow diagram illustrating network penetration vectors.
- Have students write a non-technical summary explaining the difference between standard computer malware and a zero-day vulnerability, analyzing why a zero-day is considered a sovereign weapon rather than a routine computer virus.
- Modern World History & Media Literacy (Investigating the Volt Typhoon Infrastructure Intrusion):
- Activity Idea: “The Critical Infrastructure Audit.” The reviewer notes warnings about Chinese state actors lurking within domestic networks.
- U.S. Critical Infrastructure Vulnerability Context: According to multi-agency cybersecurity advisories issued by CISA, the NSA, and the FBI, advanced persistent threat (APT) groups like China’s Volt Typhoon have shifted from traditional corporate espionage to pre-positioning themselves within U.S. critical infrastructure. Investigative data reveals these groups utilize “living off the land” techniques—using built-in network administration tools rather than installing custom malware—to evade detection. Security metrics track their presence across 16 critical infrastructure sectors, including municipal water treatment facilities, regional electrical grids, and transportation control hubs, raising concerns over potential sabotage during a geopolitical crisis.
- Have students analyze these warnings alongside Perlroth’s book, writing a mock national security brief outlining actionable steps a city must take to defend its power grid and water supply from foreign digital infiltration.