I think the analogy falls apart because clearly trying to appear secure isn’t deterring Russia/China from hacking US infrastructure.
back
1 comments
That's true, but this almost certainly was not a state-level actor. When Russia or China decide to do damage to our infrastructure, they will almost certainly succeed. The deterrent in that case will be retaliation, not the appearance of security. But in no event can our civilian infrastructure be actually protected. It's just too hard. There's too much of it and there are too many people who legitimately need access.
Russian government has quite successfully attacked our information infrastructure and goaded us into attacking ourselves. They didn't need any hacks; they walked right in the front door of Twitter x Facebook, et al.
>When Russia or China decide to do damage to our infrastructure, they will almost certainly succeed.
What if there are 100 attacks per year, with a 99% success rate?
Maybe they are. But we can estimate that they're not too impactful - otherwise we'd notice either the attempts or the effects. If there are ongoing successful attacks, they do not cross the very important threshold, past which US government officials would start making public noises in the direction of nuclear chain of command.
There'd be 99 hacks and they missed just one.
I don't get what you are asking.
What if there were lots of of successful hacks and this just happened to be the outlier because an admin was online and looking at the system at the exact moment the hack occurred?
Any large adversary would compile a huge number of ways to disable infrastructure, then use them all at once, rather than one at a time.
The quote "When Russia or China decide to do damage to our infrastructure, they will almost certainly succeed," already made that point though.