Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
Isn't a primary responsibility of government to protect its citizens and businesses from other states' militaries?
The NSA has since turned away from this responsibility, and has done the exact opposite. When Dual_EC_DRBG was developed [2], there was a similar choice of constants, with the final values having been chosen by the NSA. In this case, rather than protecting against a attack method known only by the NSA, the constants were chosen to allow an attack method known only by the NSA.
[0] https://en.wikipedia.org/wiki/Data_Encryption_Standard
[1] https://en.wikipedia.org/wiki/Differential_cryptanalysis
https://en.m.wikipedia.org/wiki/Bullrun_(decryption_program)
stop simping for the nsa
Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility.
It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the company's decisions.
Of course I'm not sure that's how it's playing out anyway, as I'm certain that the relevant three letter agencies are interested in foreign state actors digital incursions, it's just a very delicate situation and not as simple or clear cut as the Walmart example.
There is no _must_ here. The police _must_ deter and punish crime. A private entity _may_ hire security if they find the police to be ineffective at stopping certain crimes. If walmart was robed while the security guard was off duty, it is still the police's job to investigate and arrest the criminal.
It's just a criminal act, of which Walmart are the victim, and it's the state's job to find and prosecute and deter that kind of thing from happening again.
Defending internet infrastructure from foreign government's attack is not "basic security".
Besides, what ever happened to "provid[ing] for the common defense?"
For example:
We also have a tendency to conflate the requirements on software systems with respect to security threats as being somewhat similar to the requirements on other kinds of engineering with respect to safety and environmental threats, and I think that does a disservice to the vastly different scope of responsibility involved.
When I see people arguing that software engineers need to treat security as seriously as, say civil engineers treat structural stability when designing a bridge, or mechanical engineers treat vehicle crash safety, I agree to an extent, but I also think it’s worth considering:
Most bridges are not designed to actually survive being deliberately attacked with the kinds of weapons nation states can bring to bear on them. When militaries get involved, bridges tend to fail.
Likewise, civilian car safety testing does not make cars that are able to survive attacks that nation state actors can carry out with things like tanks, mines, or drones.
We need to be realistic in our expectations for what level of military threat civilian systems can reasonably be expected to deal with unaided.
Dropping bombs on a walmart store is clearly unwelcome, sending traffic to walmart's website? Much less clear. You can guess based on the traffic pattern but the only way to really know is to ask walmart if this is welcome traffic (not just a burst because some new product came out). Especially since many cases are DoS with encrypted TLS traffic that looks much like any other traffic to an outside observer.
However much of the protection is threat of retaliation ("if you drop bombs on us we will flatten your country"). So maybe that is the solution here, the government should treat these attacks as real threats and punish those responsible.
People can't do that, and it's a very basic defense.
It provides the first part of my post, authenticating the packages.
The second part is cutting out misbehaving connections. On this case on the article, it would be trivial, and governments should be on the ISP shoulders making them make call everywhere and cutting some of their clients. But there are many attacks where the ISPs don't have enough information to act if they implement something like BCP38.
In that context instantly jumping to "state-sponsored!" strikes me not only as a needless, but particularly dangerous escalation.
It's like people forget that "cyber" is most of all asymmetrical and attribution is usually more of a guessing game than an exact science.
Yet nearly every larger hack is very quickly labeled as some kind of "state sponsored offense!" to serve foreign policy narratives, and most of all; Excuse the incompetence that often enabled such attacks in the very first place.
Now ask yourself this question, would you like to give your military the full access to your infrastructure together with command and control capabilities to do with your devices and the software on them as it pleases according to the situation? If you actually think that in fact you are not okay with 24/7 monitoring and management from a centralized government institution, you should own up to your desires and get your defense together.
Of course, this is a simplistic and extreme scenario. Much of the missed part is about availability and basic institutional capability for military cyber operations, but the fundamental question is: when one demands something from the government, what exactly they wish to give up as a consequence of the proposed solution.
If you can't or don't want to secure it, don't put it online.
For one, we need to hold commercial vendors accountable - that means especially to refuse to provide security updates for the reasonably expected life time of a piece of software or hardware.
But especially, we need the companies using IT systems to be held accountable. The magic word is "defense in depth" - the scenario of the post we're talking about is a piece of equipment that was not supposed to be reachable from the Internet and despite that knowledge it was made accessible to the Internet. Seriously, anyone caught exposing dangerous stuff to Shodan should be fined to hell and back. Or to continue using your military comparison: most governments have laws that call for harsh punishment for "aid to the enemy" or similar. Time to update the law to the new digital world.
The government provides for the common security. That's one of it's most fundamental jobs.
Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.
Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable.
Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished.
We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.
Let's not say that. Suggesting that civilians have defence duties on par with members of the military is ridiculous.
Yes! Because if you are a member of the state operated defense force, then defense is your responsibility. The state is responsible for defense.
If on the other hand, you are a civilian who just happens to own property near a border, you have absolutely zero obligation to defend the border yourself. The same is true for businesses near a border.
> We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.
Man, if only society had a way to form some sort of governance body which could provide defense against other nations and provide some sort of justice system to protect against and punish crimes. Oh well, I guess its every man for themselves ¯\_(ツ)_/¯
Not aware of any country in the world that is currently in a declared state of war with Russia and China.
Just how much evidence do you need to realize that the actions of both Russia and China have been - for years now - to undermine Western societies and the global set of rules?
Another example of a government agency that fails at their job: the FDA. The FDA is supposed to protect consumers from harmful foods and medications, but the fact that you can walk into any store and grab a can of food or bottle of vitamins/supplements contaminated with heavy metals is a huge red flag [0][1][2][3][4][5]. The FDA does 0 product screening whatsoever. If the FDA actually did their job, healthcare revenues would be at an all time low in America. It pays off big time to have a diseased population.
[0] https://www.consumerlab.com/answers/supplements-and-foods-th...
[1] https://www.consumerlab.com/answers/do-zinc-supplements-cont...
[2] https://www.consumerlab.com/news/metals-in-seaweed-snacks/12...
[3] https://www.consumerlab.com/recalls/11882/herbal-supplements...
[4] https://www.consumerlab.com/news/contamination-in-greens-who...
[5] https://www.consumerlab.com/news/caution-with-spirulina-supp...