US Congress often does authorize a US military offensive (Afghanistan, Iraq) though without a formal Declaration of War.
But who are we kidding? This is a covert offensive "skirmish", probably not too different from many that took place in the cold war or in Latin America. While I suppose I'd prefer if Congress authorized actions like these, I certainly don't want to declare war on a nuclear superpower foe.
That doesn't excuse ignoring it, though the CIA generally did. Doesn't make that an acceptable policy, I can't imagine anyone proposing so for other aspects of the Constitution.
> I certainly don't want to declare war on a nuclear superpower foe.
But the current actions are the worst of both Worlds; not officially declaring war, yet waging war. Like throwing rocks at the hornets' nest whilst ducking behind a wall. When the hornets find you they'll sting just as hard.
If something is worth risking war for, then declare war. If it's not worth nuclear annhiliation then ... get on with boring old spying.
Allowing electronic warfare to exist outside of US law and doctrine is not a good idea. That's how things escalate suddenly and unpredictably. Maybe you feel that, because we're being attacked, we must respond offensively. Fine. We should still have rules for how those operations are targeted, conducted and limited.
10 U.S. Code § 394. Authorities concerning military cyber operations
https://www.law.cornell.edu/uscode/text/10/subtitle-A/part-I...
As a "sensitive military cyber operation" this was likely reported to Congress within the required timeframe unless it was defined as a "covert action" which has its own set of laws.
Sensitive military cyber operation: https://www.law.cornell.edu/uscode/text/10/395
Covert actions: https://www.law.cornell.edu/uscode/text/50/3093
Doctrinally, offensive cyber operations have been extensively studied and debated for a number of years and the official joint military doctrine document is publicly available:
Joint Publication 3-12, Cyberspace Operations, 8 June 2018
https://www.jcs.mil/Portals/36/Documents/Doctrine/pubs/jp3_1...
Protecting citizens and companies from foreign governments is one of the explicit purposes of the military.
This isn't the same thing as retaliation. This is the US government deploying its considerable resources to mitigate an obvious vulnerability. Under international law, crews of merchant ships aren't allowed to carry weapons, leaving them defenseless against even the shabbiest of pirates. The navies - US and allied alike - are out there protecting ships that cannot legally defend themselves. Retaliation in this case would involve the American Navy sending landing parties ashore to Somalia, or attacking Somalian cargo ships in a tit-for-tat fashion.
Compare this with infosec vulnerabilities in the private sector. Are companies legally bound to stay vulnerable? No. Most choose to do so - consciously or not - because to date they've gotten away with a weak security posture. This is just the nature of business. An appropriate mitigation would be for Congress to pass legislation requiring companies to safeguard their systems. I would even go as far as commend the government for subsidizing infosec consultants for companies that are considered important for the continued functioning of society.
None of the above jives with retaliating in kind.
That isn't true. It's perfectly legal for an American ship in international waters to carry weapons aboard. Shipping companies hire armed security to protect their ships even though it's not common.
Depending on the country, a very heavily armed ship may have a problem in certain ports, but small arms kept aboard aren't a problem in most places. If you want larger weapons, companies could hire escort boats.
>Are companies legally bound to stay vulnerable? No. Most choose to do so - consciously or not - because to date they've gotten away with a weak security posture. This is just the nature of business. An appropriate mitigation would be for Congress to pass legislation requiring companies to safeguard their systems.
Sure companies need better security, but no security policy will stop a sufficiently motivated attacker. Expecting private citizens to be solely responsible for protecting themselves from foreign militaries is absurd.
>Retaliation in this case would involve the American Navy sending landing parties ashore to Somalia, or attacking Somalian cargo ships in a tit-for-tat fashion.
Retaliation in this case would be the US launching cyber attacks and stealing trade secrets from private foreign companies. Instead they are directly attacking cyber combatants.
At the end of the day, the reason the government exists is to protect the people and their property.
I agree that it's alarming that the US is doing this. But my alarm is because there's no Constitutional declaration of war, or even any apparent invocation of the War Powers Act.
How many individual US states have an economy larger than Russia? https://en.wikipedia.org/wiki/Comparison_between_U.S._states...
And the size of the PR industry? https://www.statista.com/topics/3521/public-relations/
We invented the modern PR industry, AI, and social media. That's our bailiwick.
You think Russia outclassed us at our own game, at home on our own platforms, on the biggest stage, in the highest stakes game of all?
That would be like the Russian basketball team [0] beating the US Dream Team [1] in all of our major sports at once. Not gonna happen.
[0] Russian Basketball https://en.wikipedia.org/wiki/Russia_national_basketball_tea...
[1] US Dream Team https://en.wikipedia.org/wiki/1992_United_States_men%27s_Oly...
I know my analogy is a bit of a stretch, but at least at present it seems like the political parties are at the very core of american civilization (or lack thereof, depending on perspective)
I'd much rather see the country face its problems and fix them, than hope Uncle Sam can paper over security vulnerabilities or the casino mentality on Wall St.
"Prevent it from happening again" is utterly fallacious - there isn't one unique group that is capable of performing such actions, whereby vanquishing them will make everything "safe". Rather, the hacks are entirely in line what we should expect an anti-fragile society to tolerate. Rather than looking to shoot the messenger, we should even thank them when their proceeds align with the self-policing of our own institutions!
Ultimately what we're seeing here is the same old "tell them they're being attacked" technique applied to the information realm. Categorizing the involuntary-opening of societal institutions as an "attack" has only one possible ending, and it is the direct opposite of a democratic society!