State Department to pay up to $10M for information on foreign cyberattacks
darkreading.com
darkreading.com
This has less to do with tracking down cybercriminals, and more with creating a case for foreign policy agenda.
Remember it was WMD informant "Curveball" testimony to then Secretary of State Powell, that was used as one of the key pretexts to invade Iraq.
Essentially if an administration comes with an agenda to start a new war, they put the right people inside the State Department and then those guys just need to comb for anything (validated or not) to find "informants" to make the case for cyber attack. Followed by making the case in media that cyber attack is military attack and it requires military retaliation.
This will bypass the entire US intelligence system to validate the source of threat. It just needs one person to claim they were involve in cyber attack against US and it was sponsored by the government of Iraq, Iran, Venezuela, or any other country we want to go after.
I highly recommend watching this portion of the town hall with former US Congressman Dennis Kucinich talking about how non disclosure rules prevented the Congress from speaking out against US State Department spreading false information to American public [1].
[0] https://apnews.com/article/technology-joe-biden-europe-busin...
That’s a very oversimplified odd narrative. Unlike Iraq and mysterious nuclear related material objects, cyber attacks are happening. And it’s quite evident US is lacking in this area. The US doesn’t need “one person” when there are clear signatures and traces that are substantiated not only by the US intelligence system but also by non-government entities.
How clear are they really? How hard is it to pin an attack on another group or country?
https://en.wikipedia.org/wiki/Vault_7#UMBRAGE
Even HN has torn a few of the analyses apart, e.g. when the auditors looked at Bezos' phone and claimed that a file from MBS might be malicious, HN called them out on the claims that it couldn't be decrypted:
https://github.com/ddz/whatsapp-media-decrypt
Given that their entire analysis hinged on this one file being a malicious executable that couldn't be decrypted, well... suffice it to say I'm quite mistrustful of these things, especially when politics is involved.
The thing with cyberattacks is that they are even easier to misattribute. All it takes is for some country to use another countries tool, and then you've got actual evidence you can easily twist. That's how it works nowadays, you start with a kernel of truth or evidence, like the aluminium tubes in Iraq, and exaggerate wildly what suits your narrative. And it works, even to those that can know better.
Are you seriously going to post that without a source?
USA armed 'rebels' in afghanistan: https://en.wikipedia.org/wiki/Operation_Cyclone
I mean it's pretty commonly accepted at this point that Iraq was a US proxy for waging war in the middle east (similar to the mujihadeen against the russians)..I don't think it's too much of a stretch to arrive at the conclusion that the USA facilitated the sale of weapons of mass destruction (anthrax) to Iraq.
My assertion was imprecise - the chemical weapons and the equipment to make them was technically bought from Italy Germany and the UK, but the US arranged for their sale to Iraq to go through and have advice to Iraq on how and where to use them.
Could even encourage would be hackers to go white hat
But valid point on “proper”.
>it makes the whole business focus more on opsec
and that is bad?
[1] https://www.uscis.gov/working-in-the-united-states/permanent...
But it could get you hacked or worse.
Usually notifyingthe police is something they would do for physical situations. It could get tricky on the internet when dealing with jurisdiction. You would likely have to file something with the local police, state police, and DOJ/FBI/?. Honestly, the level of competence is not stellar. You could still be searched/raided/arrested and inconvenienced for days to years. Just look at how long Crosby was in prison with an all-star level legal team and protective agreement with the DA...
Somehow, the problem seems to have been dealt with.
[1] https://www.nytimes.com/2021/07/13/us/politics/russia-hackin...
Now that I've root caused it, I prefer next-day ACH if possible. PM for my bank details, thank you!
The problem with Russian hackers is the law there doesn't give a damn, so they're untouchable.
Why not ignore the law then? Put a price on their heads and use the same Russian criminal elements to take them out. Do that a few times and the problem will magically vanish. Nobody will be willing to work for these gangs.
It also makes the Russian courts have to consider whether they'd rather handle this inside the law or deal with consequences of it happening outside the law.
Is it not the case that no Russian criminal offence has taken place?
Not that I’m saying that’s great, but that might be the excuse needed to look the other way whilst carnage ensues ?
Plus the USA has enough control over global financial systems and extraditions from third party countries that the US government can make life difficult for individuals if they ever want to travel outside of Russia, spend/store money outside of Russia, or buy things directly from companies that are outside of Russia.
USA can do these things without inviting potential assassinations within its borders.
Fine. The United States as a country is also impossibly wealthy, Texas alone is worth more than the country of Russia GDP-wise. Therefore, go on with your oligarch selves and you can just compete with the State Department, bribe against bribe, payoff against payoff. Have fun.
Seems clever and practical to me. If you're up against folks who can put a price on anything, outbid 'em and you're fighting with their weapons on their terms.
And what countries are we at war with? Please be specific. This is not a trick question.