Why do you think China or Russia prefer to hack foreign private competitors rather than sending a bunch of missiles on their infrastructure?
And security via threat of retaliation does not sound like a practical or effective solution either: we already have plenty of capabilities in that area, and it didn't stop east coast oil & gas infrastructure from going down or a sizeable portion of the nation's meat processing from going the same way. These attacks are escalating rapidly, and relying in the free market to find a solution doesn't look like it's going to happen fast enough.
This needs to be a national, not (just) a private corporate issue because of the enormous national security implications involved in cyber attacks against infrastructure. When a single company's security failure can cause national chaos, there needs to be a nation-level approach to this.
I don't see what the public could do better than private entities, besides absorbing their costs. The only way I can see it practically working is if the private sectors would allow government entities full access to their IT infrastructure, submit themselves to random controls, audits and checks, and bear sizeable fines if they're found to be negligent.
Unlike "real war", cyber defense also gets to design the battlefield, everytime time. There will always be social attacks, but the stupid C and Unix stuff that is the bread & butter today is completely preventable
Tbh I trust the FAANG companies to run better security. Government is incompetent in this area.
The fact is that the correct and secure working of computer systems and networks has been severely neglected by companies in favor of their profit. If we are to have state response to such neglect, it should be funded by a huge tax on every copy of Windows.
Are you sure about that? A lot of this stuff is way more than just some bored kid. For the company I work for, there is almost certainly a group of well paid people who sit around every day trying to figure out new ways run scams using our site.
When there is financial motivation, people go through great efforts to get that $$$.
"Security" isn't some catch-all box you can check. It's a non stop game of whack-a-mole where your adversary spends each day getting around whatever you put into place.
The software industry should be ten times bigger than it is, but the economic incentive has been to make it cost less, rather than to make it safer.
I feel this deeply within my soul.
I think it's actually harmful, because people that don't know any better thinks a Qualys scan means something.
I agree with hack-back. I agree with a number of proposed solutions, but at the very end of the day the problem with cybersecurity is that most orgs don't have the fiscal allocation that they need if they were to have any hope of stoping foreign states.
Rather than compare it to armies, I think we should compare it to spies. If this is truly at the army level we could send a couple dozen missiles and the attackers would get the message. But there are reasons we don't do that though. First, we're not always sure who did what. Second, it's a political quagmire. Armies don't come to your house and help secure it from air strikes. Armies understand attack asymmetry and they hit back.
But when it comes to dealing with foreign spies there is a different playbook. The government helps organizations that are critical to national security secure their entry points and resources. They help, but they don't do everything.
This only works if the parties involved are interested in working with the government. Long after Nortel was first told of the Chinese hacking / stealing of their IP they were still woefully insecure. They went from being a third of the Canadian stock index to bankruptcy in a couple of years.
I don't actually think cybersecurity is possible. I've tried very hard to get governments to change, and there is some progress on the most fragrant violations, but the space is growing too fast and the domain is too maneuverable. I don't think it is possible. All we can hope for is some combination of more defence and realignment of incentives of the actors involved limiting the eventual damage.
They can publish best practices, research vulnerabilities, provide educational support, and generally do all the kinds of things governments do to encourage the right behaviors. We have some of this, but at some point, switched to the sexier "the best defense is a good offense". Likely because defense is hard.
How are we going to handle the calls from very angry officials in Ukraine, Belarus, Poland, Hungary, Slovakia, the Czech Republic and Germany?
In meatspace we expect the government to use kinetic force to stop people from attacking us. Like if I leave my door unlocked and some person comes in to start stealing my stuff, the cops really will respond and come stop that person (I have had a home breakin they responded quickly to). They didn't blame me for having bad locks. I pay a lot of taxes so my walls and locks don't have to be perfect.
In cyber land, it's an anarchy. The government offers no defense. But there's no reason someone can't offer a deterrent. Like if you knew who broke into your servers, and there was a goon squad that went and broke down their door either kinetically or electronically I think a deterrent strategy could eventually work. Like it literally does for meat-space security.
(Not totally sure I want that, but I'm just saying it would probably work and we haven't really tried it yet.)
What do you do ? Sending a single missile/drone wont work because Russia has air defense (probably - with them you never know how on top they are, but they will after the 1st one). Sending multiple might work, but Russia might fire back and start a war.
Sending special forces, or whatever would probably work better first few times, until Russia deliberately set's a trap for them.
How about if they are form China, or maybe France or India and you don't relay have prof that would stand in court ?
And then what, it's not like USA doesn't have its own hackers that do shady stuff internationally. Other countries have spacial forces as well.
I am not sure we want to go this way.
In practice that means US doing whatever they want in poor countries (where they already do whatever they want), and not doing much in powerful enough countries where most of those criminals actually are.
Most of the time we don't even know definitively who is behind the hacks, so it's kind of a moot point.
It's not that uncommon.
Spy-craft is notoriously laughable in its effectiveness. InfoOps, on the other hand...
I guess I’m saying comparisons to both Air based warfare and to the propaganda machine are both the most useful analogs, imho.
I love the smell of marginally improved security practices in the morning.
(If you want to argue that this is a realistic response, please explain how doing so would not be acts of war, inviting both retaliation and much worse acts then justified by ours.)
I don't expect the US to start handling this that way any time soon, but I'm not sure it'd be irrational for a nation to decide a cyberattack is, in fact, an act of war.
Even once that's all decided, we'd need to figure out if war would be a reasonable response. I'd propose that one of the main reasons the US hasn't ever escalated the situation with North Korea, even if we ignore China's likely response, is that actually subduing the populace and occupying the country would likely be extremely difficult. It's unlikely that a thoroughly bombed North Korea would be any more stable and friendly than the current North Korea.
War is extremely inefficient at bettering the lives in any of the countries involved - there are times when it is necessary, but it should be avoided whenever possible.
China is literally the only reason the US tolerates North Korea. And China solely tolerates North Korea because it causes all sorts of irritation for the US. Arguably, it would be better off for everyone living in North Korea if one of those two powers annexed it outright, but geopolitics loves backwater proxy wars.
Closer to the active phase of the Korean War, the USSR was also a factor. Today, the US distaste for instability, and naiton-building, and North Korea not having a hoard of oil or something similar to overcome that distaste is also a reason, today.
This is an unpopular opinion, but I feel like we should generally accept nation-building doesn't work well, countries we leave tend to go back to being horrible in a number of years after we set up a new nation there. And accepting that, and accepting sometimes that countries are completely failed, harmful to world security, and larger countries need to intervene: Annexation isn't actually a bad concept. It's absolutely frowned upon today, but I'm not sure is worse than what we've done to half a dozen countries in the past couple decades alone.
The barrier to war should be high, but at the point you obliterate a nation's governing structure, defenses, and likely civic infrastructure, you should accept you have a permanent responsibility for the civilians there. And maybe the best way to be democratic about it is to establish a process that states one annexes can petition and vote for secession after they've reached a more stable position.
> North Korea not having a hoard of oil or something
There's that. North Korea is a property that literally only Kim Jong Un wants. And major powers seem perfectly fine to let him have it as long as he mostlyish behaves.
If US government authorizes the NSA/CIA to infiltrate/attack all bitcoin exchanges that accept payments from wallet ID with ransomware, the problem likely be solved very quickly.
How many people are you ready to kill over ransomware?
And weren't we just splitting hairs the other day over whether or not Belarus forcing an airplane flying over Belarus to land is excessive use of force? Apparently, ballistic missiles targeted at office buildings aren't?
If this continues to happen we are looking at a really bleak future. There is an -insane- amount of money at stake here. How many meat/farm futures got affected by just taking out the meat industry this time? How much money can these people get not just by the ransomware attack, but by also knowing how fucked an industry is about to be and cashing out.
When they can do this shit with impunity it's a problem. And there's potentially a lot of money available.
This is all just ignoring the fact that some of this might be state sponsored.
I think it's time to start getting some sort of cooperation from said nation states and allowing us to help take out some of their trash.
Because the other option is to treat this like state sponsored attacks on our infrastructure and no one is going to like that.
Cyber warfare, whether ransomware or espionage, is largely asymmetric. Why would these other countries want to play ball when they have everything to gain?
The answer tends to be that you make them cooperate by attaching additional costs to the actions, in order to make them less attractive. These costs come in two major forms, which we might want to categorize as passive and aggressive.
Passive costs might include: - Sanctions - Investigation/Arrests
Aggressive costs might include: - Offensive hacks - Military response
The issue here seems to be that the passive responses aren't likely to be strong enough to dissuade the other actors, while the aggressive responses are too costly. Aggressive counter hacks might just normalize cyber hacking and espionage, and the US is on the wrong side of that asymmetric gamble. Normalizing the behavior would be likely to make it worse than it already is!
Military responses go too far. You can't reaaalllly militarily respond to another nuclear power. Not directly. The potential outcomes there are almost uniformly bad. If you want to play the longer game maybe you do some poking and prodding by supporting third party combatants (IE: Soviet support of Vietnam against the Americans) or political opponents. But there aren't really that many great options on that front today for Russia or China.
So that leaves trying to increase the cost of the passive responses. This is kind of troublesome with China, since they'll just throw identical costs right back at you. It's a bit more possible with Russia, but Europe's entanglement with their power sector screws everything up. And it's not like we're lacking on Russian sanctions as it is.
You can try to play a strong defense, but that's kind of like putting a bandaid on a gunshot wound at this point.
Yadda yadda yaddad, I don't know what to do but I think it's an interesting problem!
Edit: Maybe I shouldn't say European entanglement with Russian power sector. I suppose it's more appropriate to say gas sector?
Realistically even with government support, effective cybersecurity is going to require significant private effort and investment as well.
We should regulate and punish, not subsidize. The same way we have dealth with corporate recklessness for decades.
As the parent comment said, I'd like to see the NSA working to get zero day vulnerabilities fixed as opposed to hoarding them for future exploitation. At least this is my perception, to be honest aside from a few examples I've heard of I don't actually know whether I've correctly characterized their activities, they may already be doing this.
I agree to a point, but to continue the physical-security analogy: while private businesses should not be negligent in securing their property, a patrolling police force should also exist to discourage theft and vandalism at large.
I think the private and public sector have both been negligent when it comes to cybersecurity. Both need to improve. (Like you, I'm willing to bet the private sector is hoping to sit back and let the taxpayer foot the bill for everything. This is a problem too.)
Which is it?
This discussion is more policing, which is out of scope.
If you could claim compensation for data lost, if businesses had to foot the bill for everybody who's security and privacy is impacted by data breaches, then it would quickly become something they would have to insure against, then the insurers would demand they take reasonable precautions. A system of fines would work well, for instance - an aggressive enforcement of the GDPR or similar, for instance, could create this kind of virtuous circle.
Tax laws are a different issue, even though I agree some megacorps aren't paying their fair share of "private security" right now.