3 ms·
Remember 6 months ago when Christopher Krebs insisted that DHS had successfully protected US infrastructure? Since that time, we've discovered the Solar Winds b
by caseysoftware 5y ago
Remember 6 months ago when Christopher Krebs insisted that DHS had successfully protected US infrastructure? Since that time, we've discovered the Solar Winds breach which had gone on for 9+ months and then the Colonial Pipeline. And those are just the ones we know about. :|
However behind/compromised we think the US Feds+private infrastructure is, seems like it's even worse.
- dataflow 5y ago> Remember 6 months ago when Christopher Krebs insisted that DHS had successfully protected US infrastructure? I remember his statements about election integrity specifically, but not a general one about infrastructure... what was his statement exactly? Protected what against what?
- tw04 5y agoKrebs didn't say anything about infrastructure. He said: > Chris Krebs: I have confidence in the security of this election because I know the work that we've done for four years in support of our state and local partners. I know the work that the intelligence community has done, the Department of Defense has done, that the FBI has done, that my team has done. I know that these systems are more secure. I know based on what we have seen that any attacks on the election were not successful. https://www.cbsnews.com/news/election-results-security-chris-krebs-60-minutes-2020-11-29/#app https://www.cbsnews.com/news/election-results-security-chris... Based on op's post history this is some odd attempt at turning a thread about infrastructure security into "the election was stolen" nonsense. I doubt you'll get a response because there appears to be 0 evidence to back up that claim.
- dataflow 5y agoGotcha, thanks!
- caseysoftware 5y agoNo, I don't believe and have never promoted that the election was stolen. Paper ballots - as noted by Krebs - are a great audit trail. I believe DHS Cybersecurity didn't know - and still doesn't know - the depth and severity of what's going on or even how to get a handle on it as evidenced by the last year+. Therefore, when that agency makes a claim, we should be skeptical until there's evidence otherwise.
- tw04 5y ago>Therefore, when that agency makes a claim, we should be skeptical until there's evidence otherwise. "I'm not saying the election was stolen, I'm saying we should investigate whether it was stolen" is a tired and repeated talking point. This has been investigated exhaustively and in every instance the system worked exactly as it was supposed to. Continuing to cast doubt without a shred of evidence quickly ventures into the grounds of morally questionable behavior. You also have failed to provide any quote from Krebs to backup the original claim. If you want people to assume you're acting in good faith, this isn't the way to go about it.
- EricE 5y ago> This has been investigated exhaustively and in every instance the system worked exactly as it was supposed to. It has? The vast majority of court cases were thrown out on procedural issues, not basis of fact. If there was nothing to see, there wouldn't be near the fireworks over the audit in Arizona as is currently happening :p
- tw04 5y ago>It has? The vast majority of court cases were thrown out on procedural issues, not basis of fact. If by "procedural issue" you mean a complete lack of evidence, I suppose? https://lawandcrime.com/2020-election/rudy-giulianis-disgraceful-courtroom-rant-about-voter-fraud-didnt-resemble-trump-lawsuit/ https://lawandcrime.com/2020-election/rudy-giulianis-disgrac... >If there was nothing to see, there wouldn't be near the fireworks over the audit in Arizona as is currently happening :p There are fireworks in Arizona because of the way the recount is occurring with massive gaps in normal procedure. All of the things we have learned over the years and put in place to ensure there is no fraud, are being completely ignored for the recount. In other words: the recount is introducing gaps that would allow fraud to occur that never existed during the actual election. If you wanted to be assured that the original tally was correct, this is literally the exact opposite of what you're asking for. >One of the biggest red flags for her, she told me, came not during the counting, but afterwards, when workers entered the aggregated total tallies from counts into computers. Morrell was deeply worried that there was only a single person responsible for entering the data and no one to check that they weren’t inadvertently entering a wrong number or accidentally switching the candidates. >“There’s nobody verifying that what they entered was correct. There’s no reading out. These are things that you would typically see in an election office whether they were doing an audit, recount, where you want some sort of quality control mechanism in place,” she said. https://www.theguardian.com/us-news/2021/may/13/arizona-audit-recount-votes https://www.theguardian.com/us-news/2021/may/13/arizona-audi...
- jimbob45 5y agoIt doesn’t seem like it’s worse for anyone in the industry. It’s readily apparent to see how underfunded cyber security departments are. Doesn’t take a genius to figure out that a single man hired for the entire department isn’t going to do an adequate job.
- hoppyhoppy2 5y agoNot to mention all the recent attacks on hospitals.[1] My local hospital's electronic patient records systems were down for literally a month[2] after a cyberattack. You can probably imagine how disruptive that is when it's the largest hospital in the state. Sorry, but we lost everyone's prescription information! We can't look up anybody's drug allergies, either! I guess we'll just have to guess the details of what treatments our current dialysis and cancer patients need? It was quite the mess. [1] https://newsroom.ibm.com/2021-02-24-IBM-Security-Report-Attacks-on-Industries-Supporting-COVID-19-Response-Efforts-Double https://newsroom.ibm.com/2021-02-24-IBM-Security-Report-Atta... [2] https://vtdigger.org/2020/11/23/a-month-after-cyberattack-uvm-medical-center-restores-access-to-electronic-records/ https://vtdigger.org/2020/11/23/a-month-after-cyberattack-uv...
- raxxorrax 5y agoThat amount of downtime isn't acceptable. Modern incremental backups should protect against ransomware at least. Out the box solutions are expensive, but it would have been the good investment for this downtime alone.
- qeternity 5y agoIt’s pretty trivial to setup Postgres with very high frequency wal shipping to append-only S3 which gives you point in time recovery and prevents your data from being ransomed.
- thaumasiotes 5y agoAs with all forms of backup, it's difficult to do retroactively.
- tidydata 5y ago>Remember 6 months ago when Christopher Krebs insisted that DHS had successfully protected US infrastructure? No, maybe you should edit your post by linking to what you’re referring to. Seems like a broad claim to make.