Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

Skeptical Thomas

(82 posts)
Sat Jan 2, 2021, 06:29 AM Jan 2021

As Understanding of Russian Hacking Grows, So Does Alarm

Source: New York Times

By David E. Sanger, Nicole Perlroth and Julian E. Barnes
Jan. 2, 2021, 5:00 a.m. ET

On Election Day, General Paul M. Nakasone, the nation’s top cyberwarrior, reported that the battle against Russian interference in the presidential campaign had posted major successes and exposed the other side’s online weapons, tools and tradecraft.

“We’ve broadened our operations and feel very good where we’re at right now,” he told journalists.

Eight weeks later, General Nakasone and other American officials responsible for cybersecurity are now consumed by what they missed for at least nine months: a hacking, now believed to have affected upward of 250 federal agencies and businesses, that Russia aimed not at the election system but at the rest of the United States government and many large American corporations.

At a minimum it has set off alarms about the vulnerability of government and private sector networks in the United States to attack and raised questions about how and why the nation’s cyberdefenses failed so spectacularly.

Those questions have taken on particular urgency given that the breach was not detected by any of the government agencies that share responsibility for cyberdefense — the military’s Cyber Command and the National Security Agency, both of which are run by General Nakasone, and the Department of Homeland Security — but by a private cybersecurity company, FireEye.

“This is looking much, much worse than I first feared,” said Senator Mark Warner, Democrat of Virginia and the ranking member of the Senate Intelligence Committee. “The size of it keeps expanding. It’s clear the United States government missed it.”

“And if FireEye had not come forward,” he added, “I’m not sure we would be fully aware of it to this day.”

Read more: https://www.nytimes.com/2021/01/02/us/politics/russian-hacking-government.html



This is why Biden should wait for the first warm night of the year in Moscow, and shut down the entire city and district's power grid. Provocative? Oh yeah! But, as a child of the Cold War, I can tell you the Russians, who know damn well that their country is a Potemkinesque "power," won't do anything of significance in retaliation. "Probe with a bayonet," goes one of their sayings. "If you encounter mush {Trump}, continue. But if you encounter steel, withdraw!"

28 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
As Understanding of Russian Hacking Grows, So Does Alarm (Original Post) Skeptical Thomas Jan 2021 OP
interesting. Maxheader Jan 2021 #1
Apparently that was ALL they were seeing. Ligyron Jan 2021 #3
We need to begin calling this a war. Joinfortmill Jan 2021 #2
Agreed! lastlib Jan 2021 #5
The only one who trump has never criticized UpInArms Jan 2021 #4
Cybersecurity talent goes to private industry, chasing the money bucolic_frolic Jan 2021 #6
My thoughts also. Hire FireEye. flibbitygiblets Jan 2021 #9
No, No outside contractors. You don't know their motives or objectives or their loyalties. LiberalArkie Jan 2021 #10
Its an issue Sgent Jan 2021 #22
What happens when you're overly reliant on computers Blues Heron Jan 2021 #7
No it it what shared connectivity gets you. Before the public internet everything was dependent LiberalArkie Jan 2021 #11
That would suck Sgent Jan 2021 #23
That is the way it used to be, but you still go to a server hooked to the internet, but can only LiberalArkie Jan 2021 #25
Trump behaves as if he was promised a safe margin of victory Loubee Jan 2021 #8
Got that right. orangecrush Jan 2021 #15
sure does. stillcool Jan 2021 #18
It's a hell of a mess Chainfire Jan 2021 #12
"we so far behind in the computer sciences" Duppers Jan 2021 #21
If we shut down Moscow, do we have any reason to believe that they can't shut down every power plant Renew Deal Jan 2021 #13
This is espionage and not war TomVilmer Jan 2021 #14
"exposed the other side's online weapons, tools and tradecraft." orangecrush Jan 2021 #16
All encouraged or minimally overlooked by the traitor-in-chief. On the 20th we will see the truth. Evolve Dammit Jan 2021 #17
What happened to us is what we do to other governments every day. ancianita Jan 2021 #19
Everything will have to be cleaned up and new Firewalls built pandr32 Jan 2021 #20
I think that would be considered an act of war FakeNoose Jan 2021 #24
K&R Yo_Mama_Been_Loggin Jan 2021 #26
Great plan if your goal is to start World War 3 inwiththenew Jan 2021 #27
"The size of it keeps expanding. It's clear the United States government missed it." - Senator Mark debsy Jan 2021 #28

Maxheader

(4,419 posts)
1. interesting.
Sat Jan 2, 2021, 06:57 AM
Jan 2021


"against Russian interference in the presidential campaign had posted major successes and exposed the other side’s online weapons, tools and tradecraft."

Thought I read where a company that analyzes the IT security of corporations?

Was hacked and their tools stolen. Do you suppose these cyberwarriors are

seeing their own software?...

Ligyron

(8,006 posts)
3. Apparently that was ALL they were seeing.
Sat Jan 2, 2021, 07:33 AM
Jan 2021

I agree that Putin & Co. need to be hit back hard and their possible response given little consideration.

bucolic_frolic

(54,518 posts)
6. Cybersecurity talent goes to private industry, chasing the money
Sat Jan 2, 2021, 08:06 AM
Jan 2021

I suspect it's an area where the government is better off to contract.

Sgent

(5,858 posts)
22. Its an issue
Sat Jan 2, 2021, 03:54 PM
Jan 2021

but Fire Eye only found out afterwards, and we know they also got the crown jewels at Microsoft (source code), so even money by itself wouldn't have stopped it.

Blues Heron

(8,527 posts)
7. What happens when you're overly reliant on computers
Sat Jan 2, 2021, 08:42 AM
Jan 2021

Hey let's put our nuclear plants on the internet!!!!!! what could possibly go wrong

I don't think we should start WWIII over this - who wants to get nuked?

LiberalArkie

(19,494 posts)
11. No it it what shared connectivity gets you. Before the public internet everything was dependent
Sat Jan 2, 2021, 09:19 AM
Jan 2021

on point to point circuits. An ATM was on a line that only went to a bank. Not shared by anything else. All the computers everything were on a lan of just themselves. Not we rely on router to keep your data yours and not let anyone else get to it. Now corporations rely on a VPN to "hopefully" keep their data from being seen by anyone that should not see it.

I say have the federal gov on its own entirely separate network that can get to the public internet and the public internet can not get to it.

Sgent

(5,858 posts)
23. That would suck
Sat Jan 2, 2021, 03:57 PM
Jan 2021

for anyone that has to ever interact with the federal government, like anyone on Social Security, who pays taxes, etc.

VPN's played no part in this attack and were in no way compromised.

LiberalArkie

(19,494 posts)
25. That is the way it used to be, but you still go to a server hooked to the internet, but can only
Sat Jan 2, 2021, 04:10 PM
Jan 2021

do read only to A database but not any further.

 

Chainfire

(17,757 posts)
12. It's a hell of a mess
Sat Jan 2, 2021, 09:46 AM
Jan 2021

We don't know the whole story, but from what we have been told it appears that the Russians could shut us down for any reason they wished; like the start of a shooting war. They could only pull this off if they felt that they were invulnerable to retaliation. to My question is why are we so far behind in the computer sciences that we did not know this for nine months or longer? The Russians have been reading all of our mail for maybe a year or more, it is the greatest intelligence coup in the history of the world. This action is no different from the Russians placing a million man army in landing craft, five miles off of our coast, or overflying our cities armed with bombs.

This will be another legacy of the draft-dodging president. If the Russians wish, they could tank the country any time after Biden enters office, Biden would be blamed, and it would secure Republican/Russian power indefinitely.

We have been seriously attacked and our great leader has remained silent. It is a criminal neglect of his duties.

Duppers

(28,469 posts)
21. "we so far behind in the computer sciences"
Sat Jan 2, 2021, 03:14 PM
Jan 2021

No, we are not behind. We could defend our systems and crush both Russia & China IF we had the political will to do so!

Your are right: it has been "criminal neglect of his duties." 👍


Renew Deal

(84,771 posts)
13. If we shut down Moscow, do we have any reason to believe that they can't shut down every power plant
Sat Jan 2, 2021, 09:53 AM
Jan 2021

in the US?

The US should be more subtle in its response.

TomVilmer

(1,956 posts)
14. This is espionage and not war
Sat Jan 2, 2021, 09:54 AM
Jan 2021

Everybody does it and there are no historic precedence of going to war and answering it as an attack. The most embarrassing thing here is that the attack became public knowledge. A normal reaction is to curse, ban some of the other sides diplomats, and be happy that Russia did not catch the even better US espionage successes inside their institutions!

Evolve Dammit

(21,616 posts)
17. All encouraged or minimally overlooked by the traitor-in-chief. On the 20th we will see the truth.
Sat Jan 2, 2021, 10:53 AM
Jan 2021

I just hope we're strong enough to repel whatever they have planned and encouraged.

ancianita

(43,162 posts)
19. What happened to us is what we do to other governments every day.
Sat Jan 2, 2021, 12:00 PM
Jan 2021

from Tim Cushing at Techdirt, Dec. 22:

These calls for a cyber war by pundits and government officials aren't anything to be applauded. I don't think America really wants to get involved in another forever war -- one whose wins and losses can't be tallied with temporary "liberations" and body bag back orders.

Let's be cautious, says Jack Goldsmith. Better yet, let's be aware of the hypocrisy of the stance some government officials are demanding we take.

The lack of self-awareness in these and similar reactions to the Russia breach is astounding. The U.S. government has no principled basis to complain about the Russia hack, much less retaliate for it with military means, since the U.S. government hacks foreign government networks on a huge scale every day.

Turning a cyber war into a shooting war isn't just an overreaction. It's illegal under international law.
That doesn't mean nothing should be done about it.
It just means the US government can't pretend it doesn't engage in the same activities some now want to go to war over.
What's happened here might be unprecedented in scale, but it's the same thing every government with enough resources has done for years.
It's not a war waiting to happen. It's business as usual.

Peacetime government-to-government espionage is as old as the international system and is today widely practiced, especially via electronic surveillance. It can cause enormous damage to national security, as the Russian hack surely does. But it does not violate international law or norms.

In recent years, the US government has deployed more offensive weapons in hopes of deterring cyber attacks. It really hasn't worked. Meeting escalation with more escalation is unlikely to change the standard operating procedures of espionage, especially since the US government hasn't rolled back its offensive efforts in the wake of massive breaches.

But there may be a way forward -- one almost impossible to achieve but promising enough it shouldn't be dismissed out of hand.

[The US government] has not seriously considered the traditional third option when defense and deterrence fail in the face of a foreign threat: mutual restraint, whereby the United States agrees to curb certain activities in foreign networks in exchange for forbearance by our adversaries in our networks.
There are many serious hurdles to making such cooperation work, including precise agreement on each side’s restraint, and verification.
But given our deep digital dependency and the persistent failure of defense and deterrence to protect our digital systems, cooperation is at least worth exploring.

There's no moral high ground to claim here. And refusing to consider bringing some of our cyber boys back home leaves us with nothing but continuous escalation.
This hack is raising uncomfortable questions about our own practices. Let's see if anyone in the White House is willing to honestly confront the consequences of our own actions and find another route towards safety and national security.

https://www.techdirt.com/articles/20201219/14534745920/solarwinds-hack-is-just-same-sort-espionage-us-government-engages-every-day.shtml

pandr32

(13,969 posts)
20. Everything will have to be cleaned up and new Firewalls built
Sat Jan 2, 2021, 12:37 PM
Jan 2021

The time and money will be immense. If only it were as simple as changing pass-codes which we probably all should be doing since they hacked into many major corporations. We will need to hire competent experts and fill our agency offices again since they've been purged. Perhaps this is what Putin wanted? Maybe he planted that seed of insecurity in 45's ear by telling him he would need to get rid of people not loyal enough to kiss his ass?
My fear is one day they will empty everyone's bank accounts and we will all be freaking the hell out and desperate with no access to money at all. I have had that fear for several years. Of course it wouldn't be safe to withdraw money and stuff a mattress like Granny Clampett did.
Russia is not our friend just because they can invest in our stock markets and real estate and come here and have pictures taken with members of Republican Congress and NRA members. Oh, and Ivanka, Jared, Donny, and Eric.

FakeNoose

(40,769 posts)
24. I think that would be considered an act of war
Sat Jan 2, 2021, 04:01 PM
Jan 2021

Just as the Russians' interfering with our 2016 election should have been considered an act of war. However we would be considered the aggressor if we shut down their power grid. There would be little or no sympathy from our Allies or any neutral parties if we did this.



debsy

(829 posts)
28. "The size of it keeps expanding. It's clear the United States government missed it." - Senator Mark
Sun Jan 3, 2021, 08:01 AM
Jan 2021

Give me a break. This is exactly the reason Donald Trump was elevated to power by the Russians in 2016 - to sabotage as much of the U. S. government as possible and allow for maximum damage. Trump is and always has been the Manchurian candidate. Mitch and the entire GOP knew it and not only gave him and his minions a free pass, they actively participated in the sabotage of our government and the blatant disregard of our Constitution. They are all traitors of the most treacherous kind.

Latest Discussions»Latest Breaking News»As Understanding of Russi...