3 ms·
Apple are doing a sensible thing here I think. You won't find much about the craft of attribution engineering on the internet, but it's an important topic. In
by nonrandomstring 2y ago
Apple are doing a sensible thing here I think.
You won't find much about the craft of attribution engineering on the
internet, but it's an important topic. In some DEFCON and CCC videos
you'll find accounts of "attribution engineering kits" in the NSA
toolbag.
Some hacks are not done to extract information, sabotage or compromise
systems... but to make it look like somebody else did.
It's painful to watch official media reports announcing so eagerly
that the "Chinese did it" or "the Russians did it". Unless
representatives of those countries literally called and claimed
responsibility you're probably wrong.
The article says that when people read "state actor" they may jump to
unhelpful conclusions. Probably true, and there's deeper points behind
this. Does it actually matter? Some people want to know who did it
far more than what was actually harmed or remains weak. From a
security stance that's a distraction.
It also leads to the idea of equality before the law. Should it matter
whether a criminal gang or government or corporation broke into your
system? They should receive the same treatment by the courts under
international law.