Unhedgeable: EMP and lessons for living with risk

Custodying cryptocurrency invites the contemplation of tail risk: low-probability, high-impact events. These are the feverish Hollywood disaster-movie plots that feed into enterprise disaster recovery playbooks: Category 5 hurricane takes out the company headquarters. Flooding renders parts of the country inaccessible by road, making it impossible to operate offline systems that require physical access. Terrorists sabotage the data-center housing production servers. (That one is less improbable given Iran’s recent statement around targeting US tech companies in the Middle East.) Novel pandemic forces social distancing, stressing dual-control policies that require 2 or more employees physically present at the same time to execute critical operations. By definition force majeure events are unpredictable: before COVID-19 few organizations had contingency plans for a world when employees are forced to work from home and no one wants to be in a room with their colleagues when that could increase their chances of catching a mysterious infection.

One of the more misunderstood items in these sum-of-all-fears scenarios concerns EMP or electromagnetic pulse. An EMP is a short (often nanoseconds to milliseconds) and highly concentrated release of electromagnetic energy. These intense bursts of radiation can damage electronic equipment or even bring down entire power grids depending on the scale. As with most risks better understood by contemporary science, major EMP events were observed long before humanity understood how electromagnetic waves operate. In the first recorded major incident known as the Carrington Event, a major cloud of plasma ejected from the sun reached the Earth’s atmosphere in 1859. According to NOAA:

“Powerful electrical currents flowed through telegraph machine wires, causing them to shock their operators and igniting small fires in some offices because of the surge in electrical currents. Some even sent messages without being plugged in or received nonsensical messages that no one had sent.”

It’s not that major solar events never happened before the Carrington Event. But it was industrial age dependence on electrified systems— specifically the telegraph— that manifested these disruptive effects. In a way the timing was fortunate for team humanity: 1859 predates the widespread adoption of power grids in the late 19th and early 20th centuries. In modern terminology a CME or “coronal mass ejection” carries massive magnetic fields spanning hundreds or thousands of miles that can induce electrical currents on anything vaguely resembling a wire made out of conducting material. One of those objects of course are the high-voltage power transmission lines designed to carry electricity in the first place. A more modern demonstration arrived in 1989 when a geomagnetic storm knocked out the Hydro-Quebec grid for several hours, taking the industry by surprise.

Starfish Prime

Chunks of plasma sent our way by the daystar is one type of EMP, but not the only one modern doomsday planners must contend with. The United States accidentally stumbled into an understanding of what EMP can do to modern grids during a 1962 nuclear weapon test. Codenamed Starfish Prime, the 1.4 megaton thermonuclear weapon exploded at a very high-altitude, 250 miles above the surface of the planet. To put that into perspective, the Kármán line marking the unofficial boundary of outer space sits at 62 miles. At such altitudes a nuclear explosion looks nothing like the classic mushroom cloud. Because the fireball never touches the ground, it does not pick up surface material to mix with fission products and precipitate as fallout.

But 900 miles away in Hawaii, residents of Oahu did notice something else: street lights went out and a microwave repeater was knocked out. It turned out even more extensive carnage occurred in the other direction: high up in orbit, where sending a repairman is tricky. Roughly a third of orbiting satellites were damaged by the artificial radiation belt created by the massive explosion, including the very first commercial satellite launched by AT&T after the initial event, because it stumbled into the residual field.

That was the first observed case of HEMP, for High-altitude EMP caused by a nuclear detonation. HEMP briefly occupied the popular imagination with the 1995 Bond movie “Golden Eye,” as remarkable for special-effects as its complete disregard for actual physics. Our fearless 007 faces off against a villain colluding with a rogue Russian general to take over a secret Soviet satellite designed to trigger HEMP events. Their grand plan is to aim this powerful contraption at London and cause havoc in financial markets. Plot construction aside, the portrayal of HEMP leaves much to be desired. Judging by the comical depiction of a narrow beam of light aimed from the satellite down to earth— is this where MTG got her idea of “space lasers” igniting wildfires?— the screen-writers believe HEMP can be precisely aimed at a specific target: the ground station in Russia operating the satellites or even a city on the scale of London. As the Hawaii incident demonstrates, the effective range is hundreds or even thousands of miles. (It depends both on the altitude where the weapon is detonated and the geographic latitude because the earth’s own magnetic field warps the propagation of the one generated by the blast.) And contrary to the widespread destruction inflicted on the Russian base in the opening sequence, HEMP by itself can not cause kinetic damage to anything on the ground. The explosion happens too far away for destructive shock waves to register.

Illogical threat models

Returning to the question casually asked about so-called high assurance systems in finance: “what if our data-center is hit by an EMP?” That often leads into a misguided wild-goose chase for improvised Faraday cages and heavy-duty surge protection equipment with nanosecond response times. The threat model is muddied because the original question conflates two completely different scenarios:

  • EMP caused by natural sources. In other words, a solar disturbance that happens to be precisely aimed in the direction our planet
  • Golden Eye/HEMP variety, a deliberate act initiated by a hostile nation— and quite possibly the beginning of the end for all involved.

CME resistance at scale comes down to grid resilience. The jury is out on the question of whether North American utilities have done enough to safeguard the national grid against an EMP spike from natural causes. Regardless, these risks are best addressed upstream from the data-center floor, covering all customers.

Resilience against HEMP is a much higher bar than CME. It is also very difficult to achieve with garden-variety IT equipment intended for 24/7 operation in a standard data-center rack. Standard enclosures are likely to have gaps for air circulation and running cables to connect power/networking. Even tiny breaks in a continuous surface can act as an antenna and allow the intense initial pulse (called “E1”) from the HEMP to pass through and fry everything of value inside.

For most threat models, HEMP resistance is also completely beside the point. All bets are off when nuclear weapons are being detonated high up in the atmosphere by a hostile nation to damage US infrastructure. There are only a handful of systems that must be designed to absolutely survive that scenario: they are precisely those necessary for continuity of government and for effective military command & control. Their resilience follows from the logic of nuclear deterrence: the country must retain credible retaliation capability in the event of an unexpected first-strike. (Incidentally HEMP would make for a lethal prelude to a decapitation strike: unlike ICBMs, an overhead satellite detonation will not come with a 20-30 minute warning window.) But the systems that need credible survival story in the face of a surprise attack are few and far between. No one cares about their sports-betting site experiencing an outage when the country is on the verge of DEFCON 1.

Trying to design around apocalyptic scenarios is not only a waste of time: it results in a dangerously misguided mindset that these situations can be planned for or hedged against. Cryptocurrency is no stranger to the doomsday mindset, although the standard villains of the narrative are misguided government bureaucrats debasing the currency or too-big-to-fail banks imploding in a final cataclysmic crisis that ushers in a Greater Depression. It is one thing to seek an insurance policy against runaway inflation or money-printers churning out of control. Pretending that existential risk to civilization is somehow a survivable business disruption— another line item in the corporate disaster recovery & incident response plan to impress SOC2 auditors— is delusional.

That effort is best redirected into public-sphere advocacy to help ensure those tail-risks are either contained or never materialize in the first place. Some of the organizations contemplating EMP protection and wrapping servers in tin-foil are influential players in the policy arena. They can afford to devote significant amounts to lobbying for specific policy outcomes. For anyone concerned about CME, the most effective solution is regulation of grid operators: raise the bar on design and implementation of safeguards for transmission lines. For those worried about HEMP, the equivalent policy objective is nuclear deescalation. Reasonable people may well disagree on how that outcome is best achieved. Scale back the arsenal, renew the expired New START treaty or shift the nuclear triad towards submarines and away from use-it-or-lose-it ICBMs? But that is exactly the policy debate that needs to play out in the open and stands a meaningful chance of reducing risk globally, instead of cosplaying at an IT-themed version of Doomsday Preppers.

CP