DoD Budget Appears to Cut Cyber Offense, Beef Up Defenses
breakingdefense.com
breakingdefense.com
Another policy point would be data de-risking. It has been shown time and time again that companies cannot protect their own data, not to mention user data. I think we should make it very costly to be breached and lose PII. It would raise the bar a lot for who could do what, but I do not think companies have really demonstrated that they can handle this data responsibly. These data losses have even become a national security risk. [1]
1. https://foreignpolicy.com/2020/12/21/china-stolen-us-data-ex...
If your billing and tracking system breaks tough, that's the cost of picking poor software and not training employees.
That's also why there are tensions between big companies / victims and law enforcement agencies because they have divergent interests: keeping the business running vs prosecuting and blocking criminals
Did you give data protection job a go? They're heavily recruiting people who can really make a difference. But it looks often easier than it is ;-)
I have found myself working on these kinds of systems professionally, although we were able to air-gap them.
I guess you could say that inability to comply with those other regulations is also a “too bad, you should have thought of it” scenario, but those are not always laws we’d want them to break. (Safety, etc)
And at some level, critical infrastructure is no more of an expert at preventing cybercrime than a shopkeeper is at preventing shoplifting. I do think we need the government to stand up a bit here and help to prevent this crime in the first place.
Maybe you get away from that with real software engineering, but that seems a bit like no-true Scotsman to me.
Conservative elites which believe it is necessary to fabricate some external evil to preserve social order are historically willing to engage in obscurantism and spread lies under their real names.
The monopolization of farm land by domestic land lords is fault of foreign powers for not allowing enough living room, attempts to end feudalism in south america are Russian plots to establish Stalinist regimes on southern border of United States, UFOs are not domestic military projects but nefarious extraterrestrials, Soviet Union is not collapsing but actually developing undetectable super weapons, Iraq has weapons of mass destruction, etc.
We've tried bespoke systems for all sorts of components. That's how we end up with multi-billion, multi-year sole source contracts where $beltwaybandit prints money and it takes multiple years to support now-common functionality/capabilities because it wasn't in the initial meticulously-specified, waterfall-driven design plan enshrined in the contract 5 years ago. And that contract itself was an extension to an extension to an extension from a contract a decade before that.
Excuse me, I'm having flashbacks now.
Neither have governments. The entire OPM (Office of Personnel Management) background check database was breached and thoroughly compromised for years. And that system is effectively the blackmailer's wet dream. I wrote about that almost 6 years ago here:
https://caseysoftware.com/blog/why-this-security-breach-is-w...
And that was before the NSA had all their best hacking tools stolen..
Should a government announce to the people that everybody within it is potentially operating under foreign influence?
You can see the benefits and limitations of this approach by considering commodities where "purpose built" is economical.
One common purpose built device is the dumb gigabit network switch. It has a well defined and stable specification, and for performance reasons the switching fabric is implemented in a dedicated ASIC which cannot be reprogrammed or remotely disabled. This makes it very stable and difficult to attack directly.
The limitation is that this rock-solid infrastructure only shifts the attack surface to a higher layer in the stack. The same switch that can't be attacked directly will happily deliver an email that tricks a human into assisting a hacker's scheme, like installing a virus onto their accounting PC.
Sure, you could implement your accounting software in an ASIC as well, but unfortunately, the requirements upon accounting change much more frequently than the gigabit 64b/66b waveform spec; if the government is allowed to issue new regulations then it will always be more economical to build the accounting system on a general purpose machine.
...or a team of your employees, who for one reason or another couldn't make it to the office every day since March of last year.
In other words, VPNs. These are the smaller intranets you are talking about. Of course they still need to be capable and privileged enough to allow your employees to do their jobs, and this same requirement is the reason why ransomware can strike so effectively.
It’s not like they were being goody two shoes and suddenly with the Snowden revelations they turned.
Under no scenario will cuts to offensive capabilities happen, it doesn't matter which party or person is in the White House.
Real US cyber offensive spending is buried inside of the three letter agencies and buried in classified spending segments within the budget (the $50b to $100b black budget), not out in the open in the supposedly transparent defense budget. It's very silly anybody would believe the US would cut its spending on cyber offense, while it's deep into a never-to-end cyber conflict with Russia and China; a conflict which none of the parties are much attempting to keep hidden at this point.
All my searches are only turning up the most recent news about the most recent pipeline hack, but I seem to recall reading that the US hacked/sabotaged an eastern European oil or gas pipeline decades ago.
State actors have objectives. Even if that objective is just to test their capabilities.
It seems rediculous to suggest state actors are just doing it for the lulz.
Need the capability to send a few guys in a helicopter to attack an enemy physically? You are looking at hundreds of millions for the helicopter and weapons.
Need to have a few guys remotely hack a foreign website? A few computers, a good internet connection, and some comfortable chairs.
No matter how high you prioritize those kinds of cyber ops you aren't going to need a budget anywhere what even a modest fleet of aircraft or ships or tanks needs.
Sometimes there may be a need to blow up something or physically sabotage something in another country to facilitate some cyber ops goal, but that would be carried out by the people with drones or planes or by special ops, depending on what the relationship is between the US and the country the operation will be in and so how discrete the US needs to be, and the money to support such capabilities would show up on their budget rather than the cyber ops budget.
Besides, cyber offense isn't a means of defense, because you'd need to figure out how to retaliate against and tit for tat escalation of attacks would be a disaster.
It's trivially easy to shift expansion in the cyber offensive spending to the black budget segment, so US enemies can't get a clean idea of what the US is spending or not spending in that area. The US does this as a matter of routine in defense spending, and has across most of the post WW2 era.
Then we're officially the good guys, too :)
I don’t think there’s any reasoning with the Putin’s or the Xi’s of the world when it comes to this cyber Cold War. They both have highly skilled and motivated state-sponsored hacking divisions of their respective military or intelligence agencies. They’re simply far, far outside American reach. Not to mention the cypher pirates that operate on their soil and attack countries like the US that they turn a blind eye to.
Bolstering our tech best practices to focus on being secure and training workers to better understand what phishing looks like etc., but I think the solution is more proactive than that.
I think the solution is clandestine operations conducted by say the CIA to either infiltrate these ranks and turn would be hackers into allies or it’s straight up murder of the hackers by some US spy and have it look like a common crime in that country.
These attacks will only escalate and I fear they boil over into a full blown war. If diplomacy doesn’t work, if turning our would be attackers into allies doesn’t work, then what other option do we have if cyber defenses aren’t enough (the best defense is always one step behind a smart and adaptive attacker)?
For gradients, if a society maintains more information than another (the product of lots of resources sunk into R&D say) that translates into technological and effectiveness edge and thus real world advantage. Since information can be replicated perfectly, attacks tend to level the gradient, meaning the attackers gain the value without the same resource expenditure and can put more resources into putting the same stuff into production.
For electronic utilization, computers and networks in a lot of things can improve efficiency a great deal. But that then also opens up opportunities for digital attackers.
And the government digital security efforts should heavily take into account shoring up the weaknesses of the model society follows. For the West in general that has a lot of individualism, free market capitalism generating tons of data, heavy technological dependency to maximize productivity per person rather then throwing bulk cheap labor at a problem, etc. Government needs to help organizations and individuals stand up to state-level threats.
So for America, I'd argue that "the best offense is a good defense" when it comes to cyber war. Like, imagine a world where we had perfect bug free systems and nobody could hack anything, vs a world where there is zero possible security and all information is shared universally. I think in the former America would have a significant advantage over more authoritarian countries for the foreseeable future. I think an open society has an edge in producing valuable knew information. But in the latter scenario I think authoritarians would be ahead. They have more people and a more directed economy, if they could essentially outsource R&D completely they'd gain more than they'd lose from it.
Better late than never though. And it'll take years and years and years to prove that this is really serious and not a flash in the pan, that American defense agencies will actually choose patching over holding onto zero days (thus showing faith in the country) and so on. But I hope this does mark a permanent change where rather then mistrusting by default the likes of the NSA and other TLAs their security advice is appreciated and highly useful. One can hope.
1) The set of nuclear powers is well-known.
2) The barrier to becoming a nuclear power is high enough that only governments can feasibly do it.
3) You can generally tell who launched a missile at you.
4) Mutual destruction is considered a bad enough outcome by each of the nuclear powers that it's an effective first-strike deterrent.
Almost none of these factors are true for cyberattacks. Cyberattacks can be done by almost anybody, including literal children. They can be laundered in a way that makes them very difficult to trace. Lots of criminal enterprises wouldn't mind if their own country's infrastructure was crippled in a counterattack to their own attack.I’d be interested in seeing elaboration on those ideas. I think there’s probably more going on here than a zero sum game of competing geopolitical powers.
A couple things that come to mind:
1. Cultural exchange. Open networks make it easier to gain access to media that may not reflect views one grows up with. I suspect that without broad exposure to different ideas/lifestyles/values, more places would trend towards nationalism.
2. Scientific progress: COVID was an excellent example of the international scientific community coming together to face a global issue. What could similar events look like had we not had pre-existing research agreements or openly available data on a crisis?
Would love to here more on these topics.
Until relatively recently, US policy and those involved in it broadly treated free access to information as something that de facto favored the US - as in, it's not that we needed to provide information as propaganda, it's that access to unfiltered information by citizens abroad intrinsically promotes the US's policy goals, in part by supporting accountability against repressive and closed regimes. It's clearly not something that's been promoted in all times and all places, but it's been a tenet of a good amount of foreign policy over time.