4 ms·
> Russia, we now know, used SolarWinds' hacked program to infiltrate at least 18,000 government and private networks. The question of whether it was Russia is
by blindm 6y ago
> Russia, we now know, used SolarWinds' hacked program to infiltrate at least 18,000 government and private networks.
The question of whether it was Russia is not that interesting.
This thing of countries blaming other countries for attacks is getting boring. In cyber, there are no borders. If something is vulnerable, it's vulnerable. You don't need the prerequisite of APTs or 'sophisticated nation state cyber threat actors' or whatever. Attribution is boring these days and so much emphasis on Russia as if we don't know already they have their fingers in so many American pies.
- coding123 6y agoSure it might be boring to find out any specific hack is China or Russia, etc... but where that becomes important is the fact that whatever secrets that get stolen, the country does in fact matter. Think of it this way - if the government of the country you live in places a bounty of say ($2000 USD or that country's equivalent) for each top secret document - it both places a high value target on us, as well as revealing the things that they DONT know. I mean, specifically do you know of the latest in Fort Knox's security protocols? Do you know the latest in high powered microwave weapons that we're developing (and how to make them)? These are things we really don't want additional countries knowing how to make.
- jc01480 6y agoThe real threat is the IP obtained about leaders in key positions that will be used to blackmail the same. While that’s more of a Chinese tactic, Russia and others dabble here as well. One could say they simply instituted Assange doctrine for institutional purposes.
- naikrovek 6y ago> This thing of countries blaming other countries for attacks is getting boring. In cyber, there are no borders. Technically correct, and very wrong in all other ways. Who performs the attack is a very real concern, because unlike some of us, the attackers likely have lofty goals in the real world which are aided greatly by their successes in "cyber." (I maintain that anyone who uses the word "cyber" seriously today doesn't understand what they're talking about, in virtually all cases. It's fine to not understand stuff, by the way. Just be open to learning more.) If Russia is able to find holes in Windows, the OS used by nearly every business on the planet, they will use those vulnerabilities to their advantage in whatever ways they require. They will obtain personal information about people, blackmail them, maybe. Who knows. Russia and others WANT to take down those who disapprove of them quite strongly. They potentially want to bring low anyone who has spoken bad about them publicly (if so, I'm screwed) or anyone who could have helped them in some way and chose not to. North Korea, Iran, Saudi Arabia, Russia (perhaps to a lesser extent) have real beefs with the US. Information gained via incredibly catastrophic breaches like this one give real countries with real weapons real leverage against others, potentially. Especially if the vulnerability opens more doorways that would otherwise not have been accessible. I've been divorced twice. DO NOT UNDERESTIMATE the lengths that people will go for revenge for even the smallest slights. Some people get absolutely drunk on the slightest bit of power they have over others, and they know that, so they accumulate leverage against their enemies, real or imagined, continually in anticipation of a time when it will be useful. In short: this is a big deal. It matters who is behind it.
- jkhdigital 6y agoYou are absolutely correct. However, as a US citizen, I am much more concerned with harm caused by domestic intelligence services than by foreign actors. Unscrupulous people are everywhere, not just in the “axis of evil” Russia/Iran/NK etc. Furthermore, I am ashamed of some of the things my government has done with my tax dollars and in my name around the world, and I won’t be duped into defending my abuser in some state-level blackmail game.
- naikrovek 6y agoI see your point. I'm not afraid of the CIA or NSA or any other three letter agency in the US. They are doing what Congress has allowed them to do (mostly.) What scares me is people like Mitch Mcconnell who somehow continue to get elected when polls show nearly the entire state of Kentucky wants him out. That is keep-me-awake-at-night level of scary.
- lolinder 6y agoSource? I could only find one 2020 poll on FiveThirtyEight that didn't have McConnell in the lead. In that one, his opponent only had a 1% lead, and in most of the other ones McConnell led by 5+ points. That's a far cry from "nearly the entire state of Kentucky" wanting him out. EDIT: Source: https://projects.fivethirtyeight.com/polls/kentucky/ https://projects.fivethirtyeight.com/polls/kentucky/