Military Leaders Are Starting to Freak Out Over Russia’s Info Warfare Dominance
taskandpurpose.com
taskandpurpose.com
Eh, it's more than people are suseptible to confirmation bias, and the meme ads on facebook re-enforce the beliefs imparted upon them by <insert preferred single "news" source here>.
> If people didn't vote for your party, it's because people were not attracted by your party, mkay?
May the most entertaining party win!
This doesn't surprise me as they need to play on an asymmetrical board.
The West has no need to resort to underhanded tricks, and should not resort to a mirror version of Russian information warfare.
Right. Have you looked at the CIA's budget lately? How about the MI6?
History suggests otherwise.
Fake news seems to be effective in Cold War 2.
Hopefully the efficacy of truth outweighs fake news moving forward.
I disagree. US LE and intelligence services are at least as good at subverting the security of US information systems as Russians. State and local governments have taken all practical and legal measures to make it worse for my entire life by:
--banning and nerfing crypto (from the old export ban to present),
--hoarding vulnerabilities,
--prosecuting whistle-blowers who threaten to embarrass large companies,
--chilling research with vague and draconian hacking laws (CFAA),
--turning an indifferent eye to dangerously invalid security assumptions underlying telecom, payment systems, data brokers (cellular, ACH, CC/MCVISA, Experian et. all)
--and then getting into turf wars over who gets to exploit those defective systems in secret...
...and just hoping no one outside our jurisdiction will notice.
The military has made mistakes like this too. Remember that time that they used unencrypted video transmission for the MQ-9 predator drone? Someone noticed.* The strategy that “the best defense is a good offense” is probably not appropriate for information security.
Part of this is an economic problem as described, for example, by Schneier in his recent Op-Ed. There is little short term incentive for vendors to accept the opportunity cost of building secure systems; if you can’t write it yourself a parade of ethically questionable, bumbling contractors (HBGary?) will sell you after the fact solutions.
Hopefully the US military takes it’s own operational security seriously enough to keep soldiers from carrying off-the-shelf commercial cell phones, as the Ukrainians reportedly did. Maybe this is harder than it sounds; it’s apparently hard even to keep presidents from trying to do this. It appears demonstrably unrealistic to expect that government personnel will remain unaffected by the insecure systems used by unwashed masses of civilians. The actual attacks discussed in the article are mostly against large scale public infrastructure. The root of these problems is not really something you can shoot at.
The article offers a number of quotes like the following, by Major General Gedney: “It’s got to be operationalized down into a genuine multi-domain battle.” I really have no idea what this means, but I sure hope it means “instead of government agencies undermining civilian infosec and then using the vulnerabilities to advance our parochial interests, let’s help the private sector fix it, or at least get out of the way.”
* “In 2009, it was discovered that insurgents successfully intercepted video feeds from unmanned platforms using cheap software to exploit the use of unencrypted data links between the unmanned system and the ground control station.” RAND Corporation. 2014. (https://www.rand.org/content/dam/rand/pubs/research_reports/...)
‘Internet Hacking Is About to Get Much Worse’. Schneier. https://www.nytimes.com/2018/10/11/opinion/internet-hacking-...