3 ms·
> So Caceres is now arguing that it’s time for the US to try the P4x approach: that a part of the solution to foreign cybersecurity threats is for the American
by generalizations 3y ago
> So Caceres is now arguing that it’s time for the US to try the P4x approach: that a part of the solution to foreign cybersecurity threats is for the American government’s own hackers to show their teeth—and to use them far more often.
I wonder if we don't because we are far too vulnerable. How secure is our basic public infrastructure? (Power grid, water purification, home networks of political figures, etc.) In terms of political strategy, I'd bet we use our military might to compensate for our relative vulnerability on the 'cyber' front.
- trinsic2 3y agoThat's how people in governments want it. Vulnerabilities in our infrastructure allow government entities to justify there existence. The population rely way too much on political institutions. People in positions of political power will, in most cases, have agendas that run counter to the will of its people.
- thelittleone 3y agoOr maybe US keeps it more quiet. Goals might be different. Command and control vs disrupt?
- p4x_real 3y agoit’s true and we do. It’s a really astute observation. But it’s not because it’s a strategic move by NSA or CYBERCOM or DoD in general. We have more than enough bandwidth (both metaphorical and in the technology sense) to conduct loud attacks concurrent with other operations. Why we don’t is a pretty amazing reason: bureaucracy. Literally everyone i’ve talked to about it has told me it’s because of “authorization this and authorization that” and by the time they MIGHT get approval (rare) the point is already moot. It also just makes us look incompetent in the field on the world stage IMHO. These brazen attacks by other countries have been extremely effective. Why not treat it like another sanction? We’re the big dick US, if they retaliate we can rereretaliate even harder. And yes i know that’s not a word and yes this is actually p4x from the story (can prove however you want)
- tevon 3y agoStuxnet was us. And there have been zero days that we know the NSA has had for years. I'd say we are more rarely being caught, our goal isn't to knock their internet offline for weeks but to be inside their machines for years. The rarity of "being caught" could certainly mean that we're very good at this.
- gpjt 2y agoI got the impression at the time that stuxnet was Israel (albeit likely with US involvement). Has it been shown to be the US for sure? Or are there still competing theories?
- RobotToaster 3y agoIt would probably expose all the NSA backdoors built into US made hardware and software (I'm looking at you, intel IME), then the rest of the world would stop buying computer products made by American companies.
- p4x_real 3y agowe absolutely do compensate. Our power grid is horribly insecure and people have been ranting about it for a decade and a half. Critical infra like that is on ANCIENT systems that go down if you look at them the wrong way. However i don’t think that’s what leads to inaction because other country’s same critical infra is EVEN WORSE. I think that’s really why we just in general don’t see those kinds of attacks
- generalizations 3y agoYeah, it seems like it could be construed as an attack on civilians - take down the power grid somewhere hot like AZ, and all the elderly would die of heatstroke. Maybe just an implicit agreement similar to MAD - we'd all be so completely screwed that no-one even wants to go first.
- p4x_real 3y agooh and yes this is actually p4x / Alejandro / _hyp3ri0n