Russia confirms US cybercommand cyberattack; RAID controllers destroyed
blog.lukaszolejnik.com
blog.lukaszolejnik.com
https://www.nytimes.com/2018/06/17/us/politics/cyber-command...
Don't get me wrong, I'm not saying the two countries don't ever attack each other's computer systems. I think they do it all the time. I'm just saying that when someone says "this particular attack was definitely from country X" they're usually full of shit.
Disclosure: I'm Russian-American.
To a certain degree, if your server has malware X, and you can identify malware X (or something very similar) as belonging to actor A, and you know actors B, C, and D don't have X in their arsenal, then you can guess with high probability that you were attacked by A.
Intelligence is probably the most high stakes guessing game in history, and there are definitely smart people at the top who know that simple IP correlation is not enough to make this claim - but they likely have access to sensitive (confidential) data that further justifies that claim.
If she's well connected, she does have access to almost everything that's available, short of something that offers no plausible deniablity because it's custom made for a particular system, like Stuxnet, or something that's full of zero days nobody else knows about yet. And the only thing you can conclude in these two cases is that you're _probably_ dealing with a state-level attacker, but you can't say which state unless there's something to further narrow things down, such as unfettered access to controlled nuclear technology in the case of Stuxnet.
Notice also how we are always expected to accept these reports on faith, and no _verifiable_ evidence is ever presented.
Then why talk about it at all? I'll tell you why. It's propaganda. Someone is trying to shit into someone else's head.
Nope. Propaganda has higher stakes.
Coming from your average sysadmin that may be true but that's because they have little intel to work with. Some ssh logs implicating China in a brute-force attack, some malware with Cyrillic characters and linguistics, CNC in Iran, operational hours coinciding with a Brazilian workday...attribution is more an art than a science, hence the number of false positives.
That said, the government agencies have more metadata and packet tampering capabilities than they let on. When they need to make a point, they don't tip their hand-- evidence is fabricated through parallel reconstruction or we get just vague assertions with no evidence at all.
So who knows. At this level the question is less about technical ability and more about how much we trust our respective governments. Ours has certainly lied to us as the pretense for a military campaign before.
No matter which option you pick, you set up yourself to be deceived.
In other words, better to just consider character set doesn't convey much information at all.
You want to bomb Iran: just say that there were Farsi letters in the malware. Or the first infection happened in Iran. Or some Iranian was in the country where malware was spotted for the first time. It's not possible to prove or deny.
And nobody will ever be able to confirm anyway. US can say: "We have experts on Russian malware that said new virus contains a string "Сделано в СССР в помощь Трампу. С 23 февраля!", so Trump is definitely a Russian agent". There's zero logic or proof in this, but with strong propaganda almost everybody will believe it anyway.
In contrast, I'd say people who believe mass media in Russia 100% are in the minority. It's not even a question there in the minds of most Russians that they're being lied to.
Here in the US if it's in one of the main news outlets (all of which are controlled by like 5 people, who in turn are controlled mostly by the political establishment) easily 90% will take it at face value and won't see the narrative behind it.
Yes this information can be faked, which is why they try to confirm with other intelligence
Just to keep in mind:
> It was from the RAND study that the false rumor started claiming that the ARPANET was somehow related to building a network resistant to nuclear war. This was never true of the ARPANET, only the unrelated RAND study on secure voice considered nuclear war. However, the later work on Internetting did emphasize robustness and survivability, including the capability to withstand losses of large portions of the underlying networks.
Edit: I see what you mean. This is the source after fixing the link: https://www.armed-services.senate.gov/imo/media/doc/Nakasone...
Extracting the obvious destination from the url (and sometimes correcting for e.g. a missing / in http://) results in urls that work:
https://www.nytimes.com/2018/10/23/us/politics/russian-hacki...
https://www.armed-services.senate.gov/imo/media/doc/Nakasone...
https://www.washingtonpost.com/world/national-security/us-cy...
https://riafan.ru/1155441-kiberataka-ssha-na-fan-podrobnosti...
https://www.rbc.ru/technology_and_media/08/02/2019/5c5c51069...
etc
Protecting citizens and companies from foreign governments is one of the explicit purposes of the military.
This isn't the same thing as retaliation. This is the US government deploying its considerable resources to mitigate an obvious vulnerability. Under international law, crews of merchant ships aren't allowed to carry weapons, leaving them defenseless against even the shabbiest of pirates. The navies - US and allied alike - are out there protecting ships that cannot legally defend themselves. Retaliation in this case would involve the American Navy sending landing parties ashore to Somalia, or attacking Somalian cargo ships in a tit-for-tat fashion.
Compare this with infosec vulnerabilities in the private sector. Are companies legally bound to stay vulnerable? No. Most choose to do so - consciously or not - because to date they've gotten away with a weak security posture. This is just the nature of business. An appropriate mitigation would be for Congress to pass legislation requiring companies to safeguard their systems. I would even go as far as commend the government for subsidizing infosec consultants for companies that are considered important for the continued functioning of society.
None of the above jives with retaliating in kind.
That isn't true. It's perfectly legal for an American ship in international waters to carry weapons aboard. Shipping companies hire armed security to protect their ships even though it's not common.
Depending on the country, a very heavily armed ship may have a problem in certain ports, but small arms kept aboard aren't a problem in most places. If you want larger weapons, companies could hire escort boats.
>Are companies legally bound to stay vulnerable? No. Most choose to do so - consciously or not - because to date they've gotten away with a weak security posture. This is just the nature of business. An appropriate mitigation would be for Congress to pass legislation requiring companies to safeguard their systems.
Sure companies need better security, but no security policy will stop a sufficiently motivated attacker. Expecting private citizens to be solely responsible for protecting themselves from foreign militaries is absurd.
>Retaliation in this case would involve the American Navy sending landing parties ashore to Somalia, or attacking Somalian cargo ships in a tit-for-tat fashion.
Retaliation in this case would be the US launching cyber attacks and stealing trade secrets from private foreign companies. Instead they are directly attacking cyber combatants.
At the end of the day, the reason the government exists is to protect the people and their property.
I agree that it's alarming that the US is doing this. But my alarm is because there's no Constitutional declaration of war, or even any apparent invocation of the War Powers Act.
How many individual US states have an economy larger than Russia? https://en.wikipedia.org/wiki/Comparison_between_U.S._states...
And the size of the PR industry? https://www.statista.com/topics/3521/public-relations/
We invented the modern PR industry, AI, and social media. That's our bailiwick.
You think Russia outclassed us at our own game, at home on our own platforms, on the biggest stage, in the highest stakes game of all?
That would be like the Russian basketball team [0] beating the US Dream Team [1] in all of our major sports at once. Not gonna happen.
[0] Russian Basketball https://en.wikipedia.org/wiki/Russia_national_basketball_tea...
[1] US Dream Team https://en.wikipedia.org/wiki/1992_United_States_men%27s_Oly...
I know my analogy is a bit of a stretch, but at least at present it seems like the political parties are at the very core of american civilization (or lack thereof, depending on perspective)
I'd much rather see the country face its problems and fix them, than hope Uncle Sam can paper over security vulnerabilities or the casino mentality on Wall St.
"Prevent it from happening again" is utterly fallacious - there isn't one unique group that is capable of performing such actions, whereby vanquishing them will make everything "safe". Rather, the hacks are entirely in line what we should expect an anti-fragile society to tolerate. Rather than looking to shoot the messenger, we should even thank them when their proceeds align with the self-policing of our own institutions!
Ultimately what we're seeing here is the same old "tell them they're being attacked" technique applied to the information realm. Categorizing the involuntary-opening of societal institutions as an "attack" has only one possible ending, and it is the direct opposite of a democratic society!
Allowing electronic warfare to exist outside of US law and doctrine is not a good idea. That's how things escalate suddenly and unpredictably. Maybe you feel that, because we're being attacked, we must respond offensively. Fine. We should still have rules for how those operations are targeted, conducted and limited.
10 U.S. Code § 394. Authorities concerning military cyber operations
https://www.law.cornell.edu/uscode/text/10/subtitle-A/part-I...
As a "sensitive military cyber operation" this was likely reported to Congress within the required timeframe unless it was defined as a "covert action" which has its own set of laws.
Sensitive military cyber operation: https://www.law.cornell.edu/uscode/text/10/395
Covert actions: https://www.law.cornell.edu/uscode/text/50/3093
Doctrinally, offensive cyber operations have been extensively studied and debated for a number of years and the official joint military doctrine document is publicly available:
Joint Publication 3-12, Cyberspace Operations, 8 June 2018
https://www.jcs.mil/Portals/36/Documents/Doctrine/pubs/jp3_1...
US Congress often does authorize a US military offensive (Afghanistan, Iraq) though without a formal Declaration of War.
But who are we kidding? This is a covert offensive "skirmish", probably not too different from many that took place in the cold war or in Latin America. While I suppose I'd prefer if Congress authorized actions like these, I certainly don't want to declare war on a nuclear superpower foe.
That doesn't excuse ignoring it, though the CIA generally did. Doesn't make that an acceptable policy, I can't imagine anyone proposing so for other aspects of the Constitution.
> I certainly don't want to declare war on a nuclear superpower foe.
But the current actions are the worst of both Worlds; not officially declaring war, yet waging war. Like throwing rocks at the hornets' nest whilst ducking behind a wall. When the hornets find you they'll sting just as hard.
If something is worth risking war for, then declare war. If it's not worth nuclear annhiliation then ... get on with boring old spying.