Government Cyber Storm Ends
Bemmu writes "Mainichi Daily News and BBC News are reporting that the 'Cyber Storm' operation, for testing how prepared America is for fending off cyber attacks, has now concluded. Apparently they even used bloggers as part of the operation, as relayers of misinformation!"
Are you trying to tell me bloggers aren't reliable??? My whole worldview has come crashing down.
Clearly it han't ended and slashdot is just being used for misinformation!
Sounds realistic...
Man, I am so linking to this.
If the exercise Hurricane Pam is to Hurricane Katrina as Cyberstorm is to an actual cyber attack, then we're in deep doodoo. No smiley.
Trusted by cats.
The exercise had given the US "an excellent opportunity to enhance our nation's cyber security," the US said.
What? they finally told Microsoft to release a secure OS or else...?
Seriously, most "cyber-attacks" are as much the result of criminals, professional spammers and teenage virus writers as it is the result of the single shoddy OS they target. Both are needed for an attack to work. The rest can easily be taken care of by training IT professionals better and by selecting more secure OSes.
And no, before you ask, I'm not trying to push *nix or MacOS against Windows: while I do believe Windows is badly designed at core and will always be insecure one way or the other, if Microsoft could make it secure, it would most certainly give a lot less headaches to the DHS folks.
"A door is what a dog is perpetually on the wrong side of" - Ogden Nash
After thinking that the Internet had doged a bullet from the Cyber Storm of the century, reports are now coming in that several cyber levys have been breeched and the internet is filling with spam.
I lost my sig...
I wonder what happens when they use crackers instead of hackers.
"The war game drew in 115 agencies from the FBI and CIA to the Red Cross, the Department of Homeland Security said."
"IT companies and state and foreign governments also played a role in responding to the mock attacks."
These "simulated" attacks are all well and good, but they are being performed by entities meant to keep the system secure. Isn't that only attacking from one angle? Did these groups attack the systems like scriptkiddies would? Like seasoned professionals not skewed or influenced by "standard corporate security measures"? Did they take into account social engineering and attacks from the inside?
"The Internet survived, even against fictional abuses against the world's computers."
I've got this picture of DHS undercover agents running around screaming "the sky is falling, the sky is falling!", and then making chicken-clucking noises. Nobody panics, and they proclaim "Right then, all is well".
My tax dollars hard at work...
"We are all geniuses when we dream"
- E.M. Cioran
Seriously, though... I think the do this all the time. They've been testing the public and the media for decades to see who calls bullshit. Their lies and obfuscation have slowly gotten more outrageous, and people have been conditioned to think nothing of scandals that just a generation or two ago would have resulted in civil war.
How many comments do we need asking "what if this", "what about that", "why don't they make Microsoft fix their insecure OS", etc? I for one, am excited that the government even attempted this exercise. The smart folks who were involved with this definitely learned valuable lessons. Likely, as was seen with hurricane Katrina, communication was the biggest obstacle. Even the PHB's will notice the major problems. Please keep in mind that the government is a large bureaucracy and as such, is large and hard to change.
Also keep in mind that the information security profession is still very immature. Remember that doctors and lawyers "practice" their professions. Do we "practice" information security? Engineers are legally required to submit their designs for peer review for all municipal projects. Is that same level of review required for information security for government efforts?
We still have quite a way to go, but we are making steps forward.