El Dorado News-Times

Russia hack seen to point up U.S. lapses

Cyberdefen­ses prove inadequate even after billions spent on latest technology

- DAVID E. SANGER AND NICOLE PERLROTH

WASHINGTON — Over the past few years, the U.S. government has spent tens of billions of dollars on cyberoffen­sive capabiliti­es, building a giant war room at Fort Meade, Md., for U.S. Cyber Command, and installing sensors all around the country — a system named Einstein — to deter the nation’s enemies from picking its networks clean, again.

It now is clear that the broad Russian espionage attack on the U.S. government and private companies, underway since spring and detected by the private sector only a few weeks ago, ranks among the greatest intelligen­ce failures of modern times.

Einstein missed it — because the Russian hackers designed their attack to avoid setting it off. The National Security Agency and the Department of Homeland Security, which focused on protecting the 2020 election, were looking elsewhere.

The new U.S. strategy of “defend forward” — essentiall­y, putting American “beacons” into the networks of its adversarie­s that would warn of oncoming attacks and provide a platform for counterstr­ikes — proved little to no deterrence for the Russians, who have raised their game significan­tly since the 1990s, when they opened an attack on the Defense Department called Midnight Maze.

The national security adviser, Robert O’Brien, cut short a trip to the Middle East and Europe on Tuesday and returned to Washington to run crisis meetings to assess the situation.

Asked Tuesday whether the Defense Department had seen evidence of compromise, the acting defense secretary, Christophe­r Miller, said, “No, not yet, but obviously looking closely at it.”

At the very moment in September that President Vladimir Putin of Russia was urging a truce in the “large-scale confrontat­ion in the digital sphere,” where the most damaging new day-to-day conflict is taking place, one of his premier intelligen­ce agencies had pulled off a sophistica­ted attack that involved getting into the long, complex software supply chain on which the entire nation now depends.

“Stunning,” Sen. Richard Blumenthal, D-Conn., wrote Tuesday night. “Today’s classified briefing on Russia’s cyberattac­k left me deeply alarmed, in fact downright scared. Americans deserve to know what’s going on.”

He called for the government to declassify what it knows and what it doesn’t know.

On Wednesday morning, Sen. Dick Durbin, D-Ill., called the Russian cyberattac­k “virtually a declaratio­n of war.”

The National Security Agency has been largely silent. Even the Cybersecur­ity and Infrastruc­ture Security Agency, the group within the Department of Homeland Security that defends critical networks, has been quiet on the Russian mega hack.

Blumenthal’s message on Twitter was the first official acknowledg­ment that Russia was behind the intrusion.

Trump administra­tion officials have acknowledg­ed that several federal agencies — the State Department, the Department of Homeland Security, parts of the Pentagon as well as the Treasury and Commerce department­s — had been compromise­d. Investigat­ors were struggling to determine the extent to which the military, intelligen­ce agencies and nuclear laboratori­es were affected.

The same questions are being asked inside many Fortune 500 companies that use the network management tool, called Orion and made by Austin, Texas, company SolarWinds. Los Alamos National Laboratory, where nuclear weapons are designed, uses it, as do major defense contractor­s.

“How is this not a massive intelligen­ce failure, particular­ly since we were supposedly all over Russian threat actors ahead of the election,” Robert Knake, a senior Obama administra­tion cyberoffic­ial, asked Wednesday on Twitter. “Did the NSA fall in a giant honey pot while the SVR” — Russia’s most sophistica­ted spying agency — “quietly pillaged” the government and private industry?

Government officials have yet to say what the Russians were seeking or what they stole — and perhaps that has not been determined.

Newspapers in English

Newspapers from United States