It's worth mentioning that the most expensive and extensive malware attack in history was caused by one of such Russian cyberattacks hitting systems which (at the time) they weren't intended to. Causing severe shipping delays and billions of dollars in damage.
https://www.wired.com/story/notpetya-cyberattack-ukraine-rus...
If such attacks were intentional, you could cause much worse problems.
For example, doing this
https://www.cisa.gov/news-events/news/attack-colonial-pipeli...
except without offering a ransom fee to undo the damage, and doing it in parallel across more industries.
cyberattacks, even significant and disruptive ones, are abstract. it's hard to draw a line from shutting down a pipeline to an individual's sense of mortality. it's not an efficient way to get their message across.
ofc it would be a different situation if terror groups could use a cyberattack to drain the capital out of an entire bank or cause a power plant to go chernobyl.
If the attacks were targeted, were destructively motivated instead of financially motivated, there was no "kill switch", government threats ceased to work, etc... it'd be pretty bad.
However as a fellow european, having worked for large "national/eu important companies", this article resonated a lot with me and my frustrations. Granted I don't do anything "security" related.
Everything in "it infrastructure" has been outsourced to India, at best Poland. You have competent people in eu offices that don't have the power to use their own hardware. You have to beg for weeks to barely skilled ticket masters from outsourcing companies, endless meetings.
All eu staff is relegated to feature factories or process managers. Zero ops. "It's not our core competency."
I refuse to ever again work for the large "of national security" european companies. It's soul crushing. And it is very clear nobody cares.
It hurts me everytime I read how tens of billions are allocated for whatever EU soverignity. I have been in way too many 10 managers 2 engineers teams with way too many long meetings begging teams from $indian_outsourcing_company to let me do my job.
Surely it's no problem that their food supply depends entirely on a finicky and easily jammed system of satellites.
0: https://www.404media.co/solar-storm-knocks-out-tractor-gps-s...
There is one story I would like to clarify. The transcript says
> there were 4,000 wind turbines that could no longer be operated.
I tried to learn more about this. What I have found differs in some key details, suggesting that the turbines did stay in operation, and that the number was 5,800 turbines, not 4,000. What was lost appears to be the ability to do remote monitoring and remote control.
https://cyberconflicts.cyberpeaceinstitute.org/law-and-polic...
Can you comment on these differences? It's worth resolving them, as I will definitely be sharing your transcript with other people.
The basic problem is fundamental: outsourcing is a very common thing you find in all walks of life, it is often the most reasonable choice due to comparative advantage. This is the reason I eventually gave up on "decentralization" as a worthwhile technical goal (after years spent working on Bitcoin). Everyone is trying to outsource everything that isn't their key competitive advantage, and that's because specialization is the heart of progress. The costs of centralization are obvious in terms of loss of resiliency, but when people aren't actually needing that resiliency for entire lifetimes it's hard to convince anyone to take the loss of progress that decentralization may appear to entail.
So what to do? As you found with your 1,600 line imgur alternative just starting over to make stuff be secure is ... hard. You wrote in C++ (not the most security conscious choice) and some of those vulnerabilities are very basic, like the one where you discover that due to a bug some users are getting empty passwords. You also sort of assume that your users will keep your app up to date, but we know they won't. So simply demanding programs be smaller isn't going to work. You'll just speedrun the history of vulnerabilities. Indeed, one reason to outsource stuff to a handful of giant providers is that they do a much better job of security overall. Yeah Microsoft may have problems with Chinese hackers, but government IT routinely has problems with greedy teenagers. So MS is still ahead of the pack.
IMO the most critical thing is really whole-systems analysis to find sources of unnecessary complexity and fix it. That won't necessarily turn the tide, but it can at least help. As a trivial example, HTTP stacks don't understand the concept of load balancing. They're still stuck in a world where every website is run by a single computer. That entails a lot of server-side complexity like dedicated LBs, maybe even DNS LB, replicated databases, health checks, drain periods etc just to avoid users seeing little dinosaurs due to normal maintenance. The complexity of this is overwhelming. When users accepted things like "This service will be offline on Sunday due to maintenance" you could get away with it but now people expect everything to be 24/7, so that complexity drives people to the cloud where it's somewhat handled for them.
Thus an obvious quick win - extend HTTP and DNS to understand IP address globbing and maybe even static route matching. If a connection to a server fails, have the stack transparently fail over to another one. Now you can scrap your server side LBs and reverse proxies but still have an HA service.
Is that really true?
Shifting infrastructure to the cloud makes it cheaper, it reduces the incidence of security problems, but it magnifies the impact of security problems when they do occur.
Is that a "better job". How do you measure that?
I don't think it's accurate to describe it as "loss of progress", either. It just makes progress more expensive. There's no reason why e.g. those support & maintenance jobs cannot be located in the same country, or at least a friendly one - it's not like there's something magical about China that makes Chinese inherently better at 5G maintenance. Nor is there any reason why the data centers cannot be run by different companies in the same country.
1. They work for far less money.
2. They designed the equipment that's being managed.
Those two reasons are sufficient on their own to make them inherently better at managing 5G networks. The first reason in particular is lost if you relocate the jobs to the west.
The second reason is largely the consequence of the first. There's no reason why that equipment couldn't be designed locally, either, except that costs of labor would be higher.
Tangentially I will also note that the main reason why costs of labor are lower in China is because the quality of life is so much shittier. I think it behooves us all in First World countries to consider what it really means for our societies if they truly cannot function without relying on the kind of cheap labor elsewhere that we made impossible in our own countries, largely for ethical reasons (labor rights, social welfare etc).
Do you have any thoughts on the role and practicality of deterrence in this space?
Anyone tried using the new csp alpine.js build?