Collateral Damage

In an era of antiseptic war, one fought with drones and precision weapons that limit to an amazing degree the collateral damage done by these limited strikes executed during very limited conflicts, we’ve gotten spoiled. We expect war generally to be antiseptic.

And our “leaders” in DC have gotten spoiled, too.

Several large-scale cyberattacks in recent months have prompted a number of lawmakers and policy makers to call for a more forceful response, including suggestions that the US engage in counterattacks that would disable or limit the culprits’ own networks.

But White House officials and some technology security experts remain skeptical that such “offensive” cyberattacks would work, saying they are concerned about the difficulty in targeting specific hackers without causing widespread spillover, among other things.

And so, in the face of this wide-open cyber war being waged against us, these White House officials and those “some others” insist that we do nothing, since what we would do would be imperfect and cause collateral damage.

…cybersecurity experts are mostly split on the merits of retaliation, with some saying it could distract companies from doing more to prevent breaches.

Because defense and offense cannot possibly be carried out simultaneously. Yeah.

Bob Gourley, late of the Defense Intelligence Agency:

Once the planners and everyone looks [into retaliation], it puts it on an escalation ladder we don’t want to be on. The first thing we need to do is protect our systems. Until we do that, we’re almost inviting them to attack, saying “Come on, take our stuff.”

Wait, what? You’re saying that after years of suffering cyberattacks from Russia, the People’s Republic of China, northern Korea, Iran, individuals, you still haven’t bothered to “protect our systems?” How does that work, exactly?

 

Certainly collateral damage should be limited to the extent possible, from both moral and efficiency perspectives. But this is war. Collateral damage is part of the messiness of war. If we let our fear of collateral damage paralyze us, we will lose the war, with catastrophic consequences to us, completely subsuming any collateral damage done us by this war.

It’s for those who sit in leadership chairs in DC to stop wasting their energy looking for excuses to do nothing and instead direct their energy to responding. Forcefully. As tidily as possible, but with recognition that there will be messes, sometimes big ones.

That response must include actually defending our systems, and it must include correcting this failure:

Businesses are largely prohibited by law from a practice known as “hack back,” which could either be done to punish a cyberthief or take back information that was stolen from any specific firm. That has left companies relying on the government’s response, which so far largely has come in the form of sanctions or criminal indictments.

Personal Data Encryption vs Convenience

It appears Anthem Inc may have made a poor decision.

Recall that Anthem, the health insurer, got hacked a few days ago, giving up Social Security numbers and other personal data for 80 million customers to those hackers. It turns out that Anthem had deliberately chosen not to encrypt those data. At all.

Scrambling the data, which included addresses and phone numbers, could have made it less valuable to hackers or harder to access in bulk. It also would have made it harder for Anthem employees to track health care trends or share data with states and health providers[.]

Apparently, the company considered convenience more important than the sanctity of the personal data which those 80 million victims had entrusted to Anthem.

Naturally, Kristin Binns, Anthem’s Vice President of Public Relations, as cited by The Wall Street Journal, is excusing the failure:

Anthem encrypts personal data when it moves in or out of its database but not when it is stored, which is common in the industry.

Everybody does it, therefor it’s OK. No, Madam, everybody doing it just makes the failure widespread.

She added

We use other measures, including elevated user credentials, to limit access to the data when it is residing in a database[.]

Plainly inadequate measures. Your IT department could have told you that. If they did not, that omission would seem grounds for their termination. If they did, and senior Anthem management chose to ignore them, that would seem grounds for termination of senior management.

Naïve or Incompetent?

The European Union is targeting 19 individuals linked to the fighting in eastern Ukraine, including five Russians, in a new list of sanctions set for approval on Monday [9 Feb].

Yeah, that’ll show ’em.

The EU now has visa bans and asset freezes on 132 individuals and 28 entities.

This latest is in response to Russia’s and their rebels’ in Ukraine renewed offensives to expand the Donetsk Oblast territory they hold and to seize Mariupol, a key Ukrainian port on the Sea of Azov and a key city on the land bridge to Russian-occupied Crimea that Russia wants so desperately.

Never mind that these hand slaps haven’t bothered Russia’s MFWIC, Vladimir Putin. Never mind that he doesn’t think like western Europeans or Americans, and so is never likely to be bothered by the things that would bother western Europeans or Americans.

On the contrary, Russia has reacted with threats and so much sterner actions by the EU and the US are required. Unfortunately, the leaderships are too naïve or incompetent to take them. This…foolishness…is illustrated by our own Secretary of State John Kerry:

We are not interested in a proxy war. Our objective is to change Russia’s behavior[.]

All while ignoring the fact that to change Russia’s behavior, it’s necessary to (to coin a phrase) incentivize them to change their behavior: arm Ukraine so they have the wherewithal to defeat the Russian and Russian-backed rebels, drive the former out of occupied Ukraine, and recover their national integrity.

Update: The EU has chosen to delay even this latest round while French President François Hollande and German Chancellor Angela Merkel travel to Minsk, the capital of Belarus, to beg Vladimir Putin anew for peace.

A Fatal Flaw

In a piece for Wired, FCC MFWIC Tom Wheeler offered rationalization for his decision to dismantle the Internet. He opened his apologia with this remarkable claim:

This proposal is rooted in long-standing regulatory principles….

That’s the problem. Regulatory “principles” proceed from the assumption that government regulation is a universal and primary good.

Of course, that’s precisely backward—and backwards. A free market is almost universally self-regulating: make a bad product, people find out and stop buying—the producer goes out of business. Lie about a product, people find out and stop buying—even if the product itself might be sound—and the producer or seller goes out of business. And so on.

Almost universally: yes, there are conditions within which government regulation is warranted. But such regulation must proceed from the fundamental assumption that regulating is bad or unnecessary, and the regulation proposer must prove—not merely justify—why this proposed regulation is necessary (not merely useful in some sense).

Wheeler’s regulatory travesty must be halted. Even its mere suggestion is sound reason for Congress to act—perhaps unsuccessfully until 2017 with a Republican President, too—now to reign in, to severely circumscribe, the regulatory authority of all Departments and Agencies.

The Party of Stupid on the Right

A group of young conservatives, dubbed “reformicons,” are making inroads among Republican presidential candidates by arguing the party’s traditional reliance on broad-based tax cuts…isn’t enough to cure middle-class woes.
Instead, they are calling for crafting subsidies, tax credits, and other public-policy tools based on conservative philosophies and tastes to help the unemployed and other struggling middle-income households.

And

“For the past 10 years, our biggest issue was whether the top tax rate was 35% or 39.5%. I don’t care anymore,” said Michael Strain, 33 years old and an economist at the American Enterprise Institute think tank. One of his ideas gaining fans on the right: let employers pay some workers less than the minimum wage as an inducement to hire them and use the federal tax code to bump up salaries.

Leaving aside the abject surrender inherent in that “I don’t care” bleat, Strain’s small point—letting employers pay below-minimum wage rates under certain circumstances—is better achieved by curbing yet another government interference in the market, by getting rid of the minimum wage altogether.

Bob Davis’ article in The Wall Street Journal goes on in this vein, but you get the idea.

The larger point, though, is that these reformicons’ ideas are foolish. Using the tax code for social engineering or for favoring some Americans—which can come only at the expense of other Americans—is an inefficient and immoral use of people’s money. Even when it favors those Americans whom Republicans and Conservatives favor.

Government interference in the free market only inhibits the market, only caps what used to be equal opportunity, only reduces prosperity to the lowest common denominator rather than increasing the general prosperity by elevating the lowest common denominator.

These reformicons’ policies, worse, will only exacerbate the byzantine structure of our tax code and make it even harder to get to a single, low tax rate that every citizen pays; a rate based on all income, regardless of source and devoid of special treatment based on that income’s source; a rate devoid of gerrymandering with tax credits here, subsidies there, loopholes over there. A fair tax rate.