Interesting People mailing list archives

Re How France's TV5 was almost destroyed by 'Russian hackers'


From: "Dave Farber" <dave () farber net>
Date: Sun, 18 Dec 2016 18:19:57 +0000

 ---------- Forwarded message ---------
 From: Richard OBrien <Richard.OBrien () paymentpathways com>
 Date: Sun, Dec 18, 2016 at 1:06 PM
 Subject: Re: [IP] Re How France's TV5 was almost destroyed by 'Russian
 hackers'
 To: David Farber <dave () farber net>, <herblin () stanford edu>
 
 Dave,
 Herb’s comments spotlight a force multiplier effect when psychological,
 legal and economic boundaries are crossed.
 
 However, we should remain vigilant of *any* use of cyber weaponry.  If DDOS
 attack sources can be taken as a proxy indicator for bad guy geography, may
 I suggest there's nothing unique about attacks from Russia.
 http://www.digitalattackmap.com/#anim=1&color=1&country=ALL&list=2&time=17153&view=map
 
 ‘Building walls’ is a failed doctrine, not worth re-visiting.  Building
 Verified Trust infrastructure is a better doctrine.  To paraphrase
 Friedman’s recent book “Thank You for Being Late"
 <https://www.kirkusreviews.com/book-reviews/thomas-l-friedman/thank-you-for-being-late/>,
 "Verified Trust is the best *performance enhancing *drug on the market.”
 
 Mere Trust is an anachronism. It means “Lack of Knowledge.”  The world
 needs frameworks for new rules to insure access to Verified Trust.
 
 Rick
 
 On Dec 18, 2016, at 8:06 AM, Dave Farber <dave () farber net> wrote:
 
 ---------- Forwarded message ---------
 From: Herb Lin <herblin () stanford edu>
 Date: Sun, Dec 18, 2016 at 6:57 AM
 Subject: RE: [IP] How France's TV5 was almost destroyed by 'Russian hackers'
 To: dave () farber net <dave () farber net>, ip <ip () listbox com>
 
 A chilling story indeed.  But I think the key paragraph is this one:
 
 It was a race against time - more systems were corrupted with every passing
 minute. Any substantial delay would have led satellite distribution
 channels to cancel their contracts, placing the entire company in jeopardy.
 
 In other words, it was customers cancelling contracts that was the ultimate
 threat to the company.  This particular story thus indicates the value of
 destructive cyberattacks in prompting or instigating large scale reaction
 that can
 
 amplify by many times the effect of any given attack.
 
 An interesting question arises – did the attackers know in advance that
 their attack would place the very economic survival of the company at
 risk?  Or had they “merely” intended wreak havoc that they expected would
 have only short term effects?  Was the existential nature of threat to the
 company just fortuitous from their perspective?
 
 If the first (they knew in advance), it seems like an exercise in
 predicting second order effects – this time, second order effects that are
 psychological, legal, and economic in nature, rather than technical.
 That’s a significant expansion of the space that planners of an attack must
 account for – and defenders too.
 
 herb
 
 =======================================================================
 
 Herb Lin
 
 Senior Research Scholar, Center for International Security and Cooperation
 
 Research Fellow, Hoover Institution
 
 Stanford University
 
 Stanford, CA  94305  USA
 
 herblin () stanford edu
 
 650-497-8600 office || 202-841-0525 cell || 202-540-9878 fax
 
 AIM herblin (any time you see me)
 
 Skype herbert_lin (usually by appointment)
 
 Twitter @HerbLinCyber
 
 #safetypin
 
 -----Original Message-----
 
 From: Dave Farber [mailto:farber () gmail com]
 
 Sent: Saturday, December 17, 2016 5:10 PM
 
 To: ip <ip () listbox com>
 
 Subject: [IP] How France's TV5 was almost destroyed by 'Russian hackers'
 
 http://www.bbc.com/news/technology-37590375
 
 Archives <https://www.listbox.com/member/archive/247/=now>
 
 <https://www.listbox.com/member/archive/rss/247/1126973-2040a819>
| Modify
<https://www.listbox.com/member/?&;>

Your Subscription | Unsubscribe Now
<https://www.listbox.com/unsubscribe/?&&post_id=20161218090624:27156D46-C52B-11E6-9670-CC90FC91849D>



<http://www.listbox.com/>












Richard O'Brien // President & CEO // Verification Pathways is a Payment
Pathways, Inc. project // Office: 312-346-9400 // Mobile: 630-715-0956

*This email and any files transmitted with it are confidential and intended
solely for the use of the individual or entity to whom they are addressed.
If you have received this email in error, please notify us immediately by
return email and delete the original message from your email system. If you
are not the named addressee, you should not disseminate, distribute, or
copy this email.Public key fingerprint: C12C 7CD1 347B 9AB7 F392 5D40 B4A6
CFD5 567B D357*



-------------------------------------------
Archives: https://www.listbox.com/member/archive/247/=now
RSS Feed: https://www.listbox.com/member/archive/rss/247/18849915-ae8fa580
Modify Your Subscription: https://www.listbox.com/member/?member_id=18849915&id_secret=18849915-aa268125
Unsubscribe Now: 
https://www.listbox.com/unsubscribe/?member_id=18849915&id_secret=18849915-32545cb4&post_id=20161218132015:9D3B83E8-C54E-11E6-AAB3-C7833E37D085
Powered by Listbox: http://www.listbox.com


Current thread: