"most notable attacks have been traced near-exclusively to foreign actors"
Most criminals are "foreign" because most of Earth's population is foreign.
"The attack surface is vast."
Because we made it vast. It could have been small.
"We're literally veering into cartoon territory here"
Yes we are, because spying on millions of people and then leaving that data unprotected is childishly irresponsible.
Ordinary citizens are the injured party, not companies. They have given up privacy and control over their devices. Even the software that runs on voting machines is copyrighted and secret, and when inspected, it turned out even the basics of security have not been followed.
Now that the chickens are coming home to roost, why are you so vehemently looking to absolve them of all responsebility?
Your last comment shed more light on the narrative you're attempting to establish.
Here's the "foreign" part of the discussion from our "sub-thread" to make things clearer:
Me: These are attacks by foreign actors on a variety of our companies, government agencies, infrastructure, etc.
You: We have plenty of our own hackers and ransomware, i am not seeing how foreign-angle adds anything to the debate
Me: The overwhelming majority of the recent, most notable attacks have been traced near-exclusively to foreign actors, including the one that is the subject of the actual thread here...It has everything to do with the debate. Specifically, with how we respond/deter.
You: Most criminals are "foreign" because most of Earth's population is foreign.
Some hardcore goalpost-moving there. You went from "it's domestic and doesn't matter" to "it's foreign, but only due to a statistical artifact". You're talking in circles in your effort to absolve the attackers. And, it's made clear here that you're not just trying to lay the blame on U.S. companies; you're actively working to absolve/divert focus from the foreign adversaries who are attacking us.
Maybe you can explain why you find it so important that we blame only U.S. entities, whether they be companies or criminals. It's that criminal bit that gives up the game. This isn't just about a crusade against negligent companies. Your narrative seeks to lay blame with U.S. actors and absolve foreign actors.
But, FWIW, a disproportionate number of these attacks come from one country with a population less than half the size of the U.S. It's a country that has been engaged in asymmetric warfare with us. So, you're wrong there too: the foreign nature of the attacks is not a statistical artifact.
>Because we made it vast. It could have been small.
No. It's vast because it's vast. Complexity + interconnectedness.
Fallible humans are responsible for this and it's a problem that's grown over time. Probably every person who's written any significant amount of production code can be said to have contributed to the problem.
And, of course, there's no degree of effort that can defend with 100% efficacy, which is why we also need a deterrent approach.
>why are you so vehemently looking to absolve [companies] of all responsebility?
I've specifically stated that companies need to do better. You, on the other hand, have not assigned an iota of culpability to the actual criminals who attack us. Instead, you've worked against all-logic to absolve them (or, failing that, to place the criminals in the U.S.). It's a simple thing to say "criminals are doing bad things and should be held accountable". Odd that you refuse to say it. Odder still that, to the extent that you even acknowledge criminals exist in this problem-scope, you find it necessary to relocate them to the U.S.
"No. It's vast because it's vast. Complexity + interconnectedness."
Firstly, thats not an argument, its a tautology.
Secondly Attack surface is vast because we have shipped several billion locked down phones with known vulnerabilities and priprietary binary blob drivers, meaning they can't be updated. We could fix the problem overnight by voiding copyright protection on all software where vendor has abandoned uodates for a year or more.
It's not american companies, its the entire shithead industry.
"You, on the other hand, have not assigned an iota of culpability to the actual criminals"
Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
Whats the point of banging on about them like a broken record?
Even if Russia and China magically dissapear tomorrow, the problem will remain: if you have vulnerable systems someone will hack them.
Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
No, it's a correction. You suggested that "we made the attack surface vast". The point is that you're wrong. It's vast due to actual complexity and interconnectedness. It's vast by definition.
>Secondly Attack surface is vast because we have shipped several billion locked down phones...
This again illustrates that you don't understand what the attack surface is, thus you believe fallacies such as "we made it vast". It's not a phone or single entry point. It's every bit of software that a system touches or is comprised of, including custom, commercial, and OSS. It's firmware and hardware and networks and configs. It's social. And, to some extent, it's those same vulnerabilities in systems that connect to a system.
Again, it's vast by necessity b/c our modern world depends on software, technology and interconnectedness.
>Mate, they are criminals, they are culpable by definition, its in the Oxford dictionary. They have always existed and always will.
So, this is your grand rationale for focusing all ire on the targeted companies vs the actual criminals? Your overall position then is that we should have no deterrent (why have laws at all?) and just lock our doors/secure our systems. If the inevitable criminals get you, then it's your fault.
>Whats the point of banging on about [criminals]?
Pretty obvious: to acknowledge they exist, are the actual cause of the problem, and need to be deterred/punished as part of any comprehensive solution.
>Even if Russia and China magically dissapear tomorrow, the problem will remain:
Actually, the problem would be substantially reduced to relatively nil. Just removing Russia alone would have a massive impact.
And, the solution-set becomes vastly different when fighting domestic criminals vs deterring state-sanctioned attacks from foreign adversaries.
But, here you are working hard to absolve the U.S.'s foreign adversaries again, "mate". Very curious.
>Ita like if someone is always stealing stuff from your house, and I tell you maybe you should try locking the door.
Another straw man. I've acknowledged repeatedly that we should lock the door. That discussion is over. What we're discussing is your position that we should not attempt to deter criminals (especially if they are foreign). Instead, they should be able to try breaking your locks with impunity and, if they succeed, then it's your fault.
Most criminals are "foreign" because most of Earth's population is foreign.
"The attack surface is vast."
Because we made it vast. It could have been small.
"We're literally veering into cartoon territory here"
Yes we are, because spying on millions of people and then leaving that data unprotected is childishly irresponsible.
Ordinary citizens are the injured party, not companies. They have given up privacy and control over their devices. Even the software that runs on voting machines is copyrighted and secret, and when inspected, it turned out even the basics of security have not been followed.
Now that the chickens are coming home to roost, why are you so vehemently looking to absolve them of all responsebility?
It's breathtakingly hypocritical.