The Big Hack — Update

On Friday, I wrote about the hacking into a wide variety of federal agencies by Russia that started back in March but was only recently discovered. The full scope and consequences of the cyber attack remain unknown and intelligence officials are still hard at work trying to find answers.

Secretary of State Mike Pompeo said on Friday …

“This was a very significant effort, and I think it’s the case that now we can say pretty clearly that it was the Russians that engaged in this activity. I can’t say much more as we’re still unpacking precisely what it is, and I’m sure some of it will remain classified. But suffice it to say there was a significant effort to use a piece of third-party software to essentially embed code inside of U.S. Government systems and it now appears systems of private companies and companies and governments across the world as well.”

Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) confirmed it has found evidence that the hackers had found multiple ways to sneak into federal agencies’ computer networks, including pathways it may not know about yet.  Our experts are not even sure just yet how to go about removing the invasive ‘bugs’ …

“Removing this threat actor from compromised environments will be highly complex and challenging for organizations.” – from a statement issued by CISA

But, of course, there is one person who has all the answers, who knows exactly what happened and he is telling us not to worry …

“The Cyber Hack is far greater in the Fake News Media than in actuality. I have been fully briefed and everything is well under control. Russia, Russia, Russia is the priority chant when anything happens because is [sic], for mostly financial reasons, petrified of discussing the possibility that it may be China (it may!)  There could also have been a hit on our ridiculous voting machines during the election, which is now obvious that I won big, making it an even more corrupted embarrassment for the USA.”

Yep, you guessed it, the outgoing lame-duck president, Donald Trump.  Is there nothing he can keep his mouth shut about?  Nothing at all?  He likely has been fully briefed, as would be right and proper, but it’s highly doubtful that he paid close attention or even remotely understood what he was being told.  All evidence points to Russia as being the instigator, and no, everything is definitely not ‘well under control’.

The hack began as early as March, was just discovered this month, and security experts are still very much in the dark, so we have no idea at this point what dangers may be lurking.  And lastly, no, the voting machines were not a part of the hack.  First, if Putin had hacked our voting machines, he would almost certainly have done so in Donald Trump’s favour, in order to keep his puppet in office.  Second, hand counts in many states have confirmed the machine tallies.  And third, Chris Krebs, former head of CISA (who Trump fired for simply doing his job and being honest) stated that this was the most secure election in the history of our nation, and frankly I trust Chris Krebs at least a thousand times more than I trust Donald Trump.

Pompeo concluded by saying …

“We have lots of folks that want to undermine our way of life, our republic, our basic democratic principles. Russia is certainly on that list … You see the news of the day with respect to their efforts in the cyber space. We’ve seen this for an awfully long time, using asymmetric capabilities to try and put themselves in a place where they can impose costs on the United States. So yes, Vladimir Putin remains a real risk to those of us who love freedom.”

Hmmmm … any bets about Pompeo’s job status for the next 32 days?

Bottom line here, my friends, is that Russia is in control of some information that involves a wide variety of our federal agencies, including the Department of Energy and the National Nuclear Security Administration.  I won’t offer any possible scenarios, but let your mind wrap around that one for a while.  No, Donald Trump, everything is definitely not “well under control”.  Not by a long shot.

The Big Hack … and Other News

We are all so wrapped up in the election, in Donald Trump’s utterly ridiculous behaviour, his inane ramblings and threats, the surging number of daily new cases and deaths from the pandemic, and the upcoming runoff elections in Georgia, that few seem to be paying attention to what would ordinarily be the biggest story of the day:  The Big Hack.

Thus far, hackers working for a Russian intelligence agency have breached the following:

  • Department of Energy (including Federal Energy Regulatory Commission (FERC) and National Nuclear Security Administration (NNSA)
  • Department of Treasury
  • Department of Homeland Security
  • Department of Agriculture
  • Department of State
  • National Institute of Health (NIH)
  • Commerce Department’s telecommunications policy agency

Officials have spent days scouring federal networks for more information about the breaches but are still unsure of what the hackers took.  Federal agencies were not the only victims, as at least three states were also breached.  The true scale of the breach is still unknown but looks to have extended beyond the US government. On Thursday, Reuters reported that Microsoft was also hacked as part of the suspected Russian campaign.

The hack began as early as March, when malicious code was snuck into updates to Orion, a network safety tool used extensively by government agencies.  So far, the hackers are known to have at least monitored email or other data within the US departments of defense, state, treasury, homeland security and commerce.

Now, I don’t pretend to understand the mechanics here, but I know that anytime such agencies as Homeland Security, the Nuclear Security Administration, and Department of Energy are compromised, there is a very real threat to our nation, to our safety, to our very lives.  This is too important to ignore … yes, folks, it’s even more important than Trump’s babbling rants.

There are far more questions than answers:

  • What are they seeking?
  • What have they already obtained?
  • Why?
  • How?
  • Why now?

The timing … I’m not given to conspiracy theories, and frankly don’t have a theory about it, but I have to be suspicious of the timing.  We are very vulnerable right now in many ways, given that we essentially have no coherent leadership, and given that we are largely distracted by the surging pandemic and the post-election chaos.  There is some reason for these hackings, and some reason for the timing … but what?  Former homeland security advisor Tom Bossert chillingly predicts …

“It will take years to know for certain which networks the Russians control and which ones they just occupy.”

The FBI and other agencies have scheduled briefings for members of Congress today, and we may learn more after that, though I’m not holding my breath.  Not surprisingly, Trump has been too busy making threats and accusations to be bothered commenting on the situation.  This must not turn into a political game … our members of Congress must all pull together to give the agencies involved the tools they need to figure out the what, why, when, where and how of the breaches, and to minimize the damage.  My hope is that once Joe Biden takes office in 33 days, our security will once again be considered a top priority.

For now, however, it is important that we keep our eye on this ball.  People refusing to wear masks because they say it violates their civil rights, a lame duck president acting like a toddler, political arguments and name-calling should fade into the background until we understand just what the threat here is and how dangerous it is.


In other news …

  • In Kentucky, Governor Andy Beshear issued an order requiring all K-12 institutions to temporarily cease in-person classes because of rising coronavirus cases. A religious school, Danville Christian Academy, joined by Kentucky’s attorney general, said it should not be subject to the order, and they took their case to the Supreme Court.  The Court, in an unsigned order noted that schools are about to begin their holiday breaks, and Governor Beshear’s mandate expires before schools reopen Jan. 4. If Beshear reissues the restriction, the court said, the plaintiffs could return to court.  My thoughts?  A school is a school is a school.  Why should a religious school be exempt from a mandate that is intended to protect teachers, students, and their families.  Good grief, people … do we have to tie you to a tree to make you understand that these mandates are for your own protection?

  • This morning at 8:00 a.m., Mike Pence and his wife Karen are scheduled to receive the coronavirus vaccine … live on television.  Ho hum.  First of all, who really wants to see somebody’s bare arm have a 4-foot long needle plunged into it?  Seriously?  Secondly, to what purpose?  Allegedly, it is to assure the people that the vaccine is perfectly safe, so that more people will be willing to take it.  But … since 90% of us will not even be able to receive it until next autumn, it really doesn’t matter, does it? And anyway, the after-effects that worry me most, given the haste with which the vaccine was developed, may well be long-range, such as people developing cancer 3-4 years from now.  And what if Mike or Karen have an anaphylactic reaction like the nurse up in Alaska … on television?  Then how assured are we going to feel?  Nice try, Mikey, but keep your arms to yourself and stop the voyeurism, please.