If someone makes tanks with paper for armour, because it cuts costs, they are to blame if those tanks catch fire.
If someone makes tanks with paper for armour, because it cuts costs, they are to blame if those tanks catch fire.
It's fine to have this view that software should be defect free and hardened against sophisticated nation-state attackers, but it stretches the meaning of "defect" to me. A defect would be serving to fulfill that utility it had been designed for, not succumbing to malicious attackers.
because this is the kind of stuff infrastructure things do, along with MANY other things. Im sure not all infrastructure does it, but plenty do.
This is not hardening, its BASIC security. any scriptkiddie from same country could find it and cause problems.
How far would you say they should go to stop domestic script kiddies from messing with it? and if script kiddies from other countries mess with it, is it now cyber warfare?
I’ll therefore decline to comment on your assertions. I will acknowledge it’s time to consider Russian interference as expected if you are designing an internet connected system, fine, but it looks like it’s non trivial to fatally compromise these systems already.
I am not saying whether russians are doing it or not, im just saying that its not just victim blaming, and that anyone operating with this level of security is grossly negligant and should be severely punished as criminals