{"id":219,"date":"2017-05-18T13:59:10","date_gmt":"2017-05-18T13:59:10","guid":{"rendered":"http:\/\/securitycurve.com\/?p=219"},"modified":"2017-05-18T13:59:10","modified_gmt":"2017-05-18T13:59:10","slug":"musings-on-cyber-atomic-bomb","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=219","title":{"rendered":"Musings on cyber &#8220;atomic bomb&#8221;"},"content":{"rendered":"<div id=\"attachment_221\" style=\"width: 310px\" class=\"wp-caption alignright\"><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/05\/Castle_Bravo_Blast.jpg\"><img decoding=\"async\" aria-describedby=\"caption-attachment-221\" class=\"size-medium wp-image-221 lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/05\/Castle_Bravo_Blast-300x225.jpg\" alt=\"\" width=\"300\" height=\"225\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 300px; --smush-placeholder-aspect-ratio: 300\/225;\" \/><\/a><p id=\"caption-attachment-221\" class=\"wp-caption-text\">Castle Bravo Test<\/p><\/div>\n<p>Do you remember <a href=\"https:\/\/www.washingtonpost.com\/blogs\/post-partisan\/wp\/2017\/01\/18\/russias-radical-new-strategy-for-information-warfare\/?utm_term=.563986f0269b\">this comment from\u00a0Andrey Krutskikh<\/a> back during <a href=\"https:\/\/infoforum.ru\/conference\/2016\">Infoforum 2016<\/a>?<\/p>\n<blockquote><p>&#8220;You think we are living in 2016. No, we are living in 1948. And do you know why? Because in 1949, the Soviet Union had its first atomic bomb test. And if until that moment&#8230; the Americans were not taking us seriously, in 1949 everything changed and they started talking to us on an equal footing. \u00a0I\u2019m warning you: We are at the verge of having \u2018something\u2019 in the information arena, which will allow us to talk to the Americans as equals.\u201d<\/p><\/blockquote>\n<p>Basically, he said at the time that Russia was on the verge of developing the cyber equivalent of an &#8220;atomic bomb.&#8221; \u00a0Seems like a fairly significant boast.<\/p>\n<p>So, here it is a year later and\u00a0there have been a few cyberwarfare victories under Russia&#8217;s belt. \u00a0Two of which were pretty significant IMHO. \u00a0I&#8217;ve been trying to see if I can figure out which of the recent Russia cyberwarfare campaigns (or maybe something else we in the public arena don&#8217;t know about yet) is the &#8220;atomic bomb&#8221; that Krutskikh was crowing about.<\/p>\n<p>The way I see it, there are four\u00a0possibilities:<\/p>\n<ol>\n<li><strong>Global election tampering<\/strong><\/li>\n<li><strong>Equation Group Infiltration<\/strong><\/li>\n<li><strong>Something we don&#8217;t know about because it\u00a0isn&#8217;t public<\/strong><\/li>\n<li><strong>Something we don&#8217;t know about because it hasn&#8217;t happened yet<\/strong><\/li>\n<\/ol>\n<p>If he&#8217;s referring to the use of cyberwarfare capability for election tampering, that would be what most folks thought he meant on the basis of the timing. \u00a0Specifically, just a short while after the statement, we started seeing systematic attempts to influence election outcomes: the US, France, and so forth. \u00a0What makes this\u00a0option seem less likely to me though is that election tampering isn&#8217;t exactly new for Russia &#8211; they <a href=\"http:\/\/www.pnas.org\/content\/109\/41\/16469.full\">were tampering with elections<\/a> (their own and other countries) for years. \u00a0 So was it instead\u00a0the method by which they&#8217;ve effected the tampering that makes it &#8220;atomic bomb&#8221; level impact? \u00a0I&#8217;m a little dubious that this was what he meant by &#8220;atomic&#8221; level capability. \u00a0Hiring a bunch of trolls is a far cry from atomic bomb level capability. \u00a0But maybe he&#8217;s into hyperbole. \u00a0Could happen.<\/p>\n<p>It could also be that he&#8217;s referring to the infiltration of the <del>NSA<\/del> Equation Group by the <del>FSB\/GRU<\/del> Shadow Brokers. \u00a0We know that the <a href=\"https:\/\/arstechnica.com\/security\/2017\/05\/fearing-shadow-brokers-leak-nsa-reported-critical-flaw-to-microsoft\/\">Shadow Brokers published the Equation Group toolset<\/a> a while back (if anybody was unclear on this point, see WannaCry.) \u00a0We can intuit since the toolset was dated (2013) that, whatever infiltration they did, it&#8217;s either been uncovered or closed off &#8212; there&#8217;s no way that a covert infiltration could continue after they posted that they had acquired the toolset and also the files were pre-2013. \u00a0But if it was closed of in 2013, why would he be bringing it up in 2016? \u00a0The level of impact (systematic infiltration of the <del>NSA<\/del> Equation Group) seems pretty severe &#8211; maybe &#8220;atomic&#8221; level &#8211; but the timing of this seems off.<\/p>\n<p>The last two possibilities &#8211; i.e. something we haven&#8217;t seen yet &#8211; seem most likely to me in light of the above. \u00a0Specifically, that Russia has an as-yet-undisclosed cyberwarfare capability that we haven&#8217;t seen yet. \u00a0It&#8217;s possible that&#8217;s &#8220;tin foil hat&#8221; territory &#8211; and frankly is the result of wild-ass speculation on my part &#8211; but if so it should be interesting times ahead.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Do you remember this comment from\u00a0Andrey Krutskikh back during Infoforum 2016? &#8220;You think we are living in 2016. No, we are living in 1948. And do you know why? Because in 1949, the Soviet Union had its first atomic bomb test. And if until that moment&#8230; the Americans were not taking us seriously, in 1949 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[10,36,70,102],"class_list":["post-219","post","type-post","status-publish","format-standard","hentry","category-security","tag-atomic-bomb","tag-cyberwarfare","tag-intelligence","tag-russia"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/219","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=219"}],"version-history":[{"count":0,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/219\/revisions"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=219"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=219"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=219"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}