Obama Sequester Cluelessness

Here are two examples.

DHS Budget Undersecretary Rafael Borras, just last Tuesday, on the sequester:

There was an expectation that the sequester would not come to pass.  We’re doing everything we can to limit the impact.

House Democrats are whining about President Barack Obama and his administration being hectored about the sequester’s budget impacts before his Cabinet and agencies have had a chance to begin dealing with it.  Also last Tuesday, Congressman Gerry Connolly (D, VA) bleated

Did we expect [the sequester] to kick in within 19 days?  No!

Crap.  They’ve had 19 months since the sequester was passed—and signed into law by Obama.  On what basis do these folks think a law was not to be obeyed?

They All Could Learn from the Poles

In the aftermath of the Cyprus Parliament’s rejection (wholly correct IMNSHO) of the troika’s “bailout” offer—a “one time” “tax” on bank deposits held by Cyprus banks—talks are failing (breaking down?) within the government, between the government and the troika, and between the government and Russia on a Plan B to avert Cypriot bankruptcy.

Amid this crisis, and exacerbated by the rejection and potential failure of the subsequent talks, panic is growing in the EU, and especially in the euro zone, that a Cypriot bankruptcy will force Cyprus out of the euro zone, and that will lead to the doom of the euro.

That panic is both palpable and foolish (see here, also).

Polish Foreign Minister Radoslaw Sikorski has the right of it.

There is no obligation to accept help.  Cyprus has the possibility of living with its own mistakes.

He knows—Poland does not use the euro.  Greece and the EU should take this advice to heart, also.

Why Not Just Take It All?

Spiegel International Online notes that the Cypriot government may be figuring out some of the foolishness of the troika’s (ECB, EC, and IMF) demand concerning the latter’s “offered” bailout as well as some of the variants under discussion.  Some of those variants include reallocating the confiscationtax according to more deposit account sizes than just two, and hitting the highest—still those over €100,000 with a 15.6% claim.

[C]oncerns have emerged that a large number of foreign investors and depositors will withdraw their money from the country en masse.  Critics warn this would devastate Cyprus as a financial center and also threaten the country’s entire economy.

Well, yeah.

Still, even the current proposal has central bankers nervous.  Officials at the Cypriot central bank are still fearing a massive capital flight.  Central bank head Panicos Demetriades said he expects that at least 10 percent of deposits will be transferred abroad during the first few days after the banks reopen, according to lawmaker Roula Mavronikola who attended the session.

Demetriades is optimistic.  The Cypriot banking system would be fortunate to retain a single euro, were this institutionalized theft to go through.  The only way to stop the capital flight would be for the government to steal it all.

In the event, though, the Cypriot Parliament rejected any sort of levy, rather resoundingly.

A Cyber First Strike

John Wohlstetter in The Wall Street Journal defines cyberspace as the software that controls the operation of networks linking computers in the governmental and private sphere.  This is incomplete, though.  Cyberspace includes that, but it also includes the software running on individual computers, whether they are linked into a (the) network or are operating in isolation.  Even those isolated computers, after all, are susceptible to cyber attacks, with many of them (unless they are physically disconnected from any network at all) susceptible to being hijacked into cyber attacks against other computers/networks through such means as social engineering, a process whereby hackers, or hostile governments, or terrorists, or… convince, usually through subterfuge, the human operator of those computers to load malware onto them.

Wohlstetter then identifies the People’s Republic of China’s “military’s massive continuing cyberspying” as an example of one type of cyber attacks that may be simple spying, or that may be preparation for further adventuring.  People’s Liberation Army spies, he notes, have stolen “volumes of documentation on the ultra-advanced F-35 Lightning, the only fifth-generation fighter still being produced by the US,” and they’ve penetrated “every major national-security database that they can within the Pentagon and US defense companies.”  But this could be just ordinary pre-battle preparation.  Every general is going to investigate his enemy so as to understand as clearly as possible that enemy’s force disposition and the strengths and vulnerabilities of that enemy’s systems so as to efficiently neutralize those systems at the battle’s start.

To support these efforts, the PLA “Third Department” (among others),

which handles telecommunications, can call on 12 operation bureaus to carry out cyberattacks, and three research institutes for technical support with some 13,000 staff upon request.

The PRC isn’t alone in this sort of effort.  Russia and Iran are two others who maintain major efforts in offensive cyberspace.

A necessary, but not sole, prelude to defending against a first strike is understanding the nature and depth of what’s happening in a particular incident.  Siobhan Gorman and Siobhan Hughes address this in part, citing Army General Keith Alexander, Commander, US Cyber Command

When does a nuisance become a real problem and when are you prepared to step in for that?  That’s the work that I think the administration is going through right now and highlighting that.

But this is the question concerning a physical problem, too—when does any incursion stop being an error, or stop being minor, and start being an act of war?  And what do we do about it, and when?  Do we simply defend against the incident?  To we take offensive measures to encourage the attacker to not do that anymore, do we take more extensive measures to defeat outright the attacker and compel his acquiescence?  When?  In accordance with what criteria?

And that’s part of where a first strike starts to come into play.  A cyber attack as a first strike in all likelihood won’t occur.  A first strike, though, will include a decisive cyber attack.  We’ve seen rehearsals of the cyber component:

  • the “PLO virus,” a logic bomb designed to infect and destroy files on computers [a very early virus, its “rehearsal” aspect is in the lessons learned in managing and delivering such malware]
  • 2010’s stuxnet, which damaged or destroyed hardware—high-speed centrifuges, in one case, by causing them to run too fast and burn themselves out
  • 2012’s cyberassaults on the websites of many US banks
  • 2012’s more destructive attack on a Saudi oil company that destroyed 30,000 computers
  • the implantation of malware on computing equipment prior to sale and delivery to the target nation.  For instance, I bought a laptop from an otherwise reputable major computer company; it was delivered to me directly from the factory in Shanghai—with a Trojan carefully installed.

Given the penetration of American systems by the Chinese, it’s not beyond the pale that either a) this kind of malware has infected the computing systems managing any target nation’s infrastructure—water, electricity, communications, et al.—and the target nation’s defense systems, including, but not necessarily limited to, sensor suites and communications, or b) this kind of malware is ready to be emplaced in the weeks prior to the intended first strike.

How would a first strike work, then?  With the malware in place, sufficient of it could be triggered to shut down a nation’s electrical grid, its water handling and delivery systems, and its financial infrastructure.  With responders deployed to deal with this—and so widely dispersed—communications then could be crippled, isolating those responders, and isolating that nation’s population from each other and from their government.  Far fetched?

Russia tested a limited cyber attack against Estonia in 2007.  Moreover, as Gorman and Hughes note the temptation offered by our own continued vulnerability:

US intelligence officials told a Senate hearing that the nation is vulnerable to cyberespionage, cybercrime, and outright destruction of computer networks, both from sophisticated, government-sponsored assault as well as criminal hacker groups and cyberterrorists.

“It’s hard to overemphasize its significance,” Director of National Intelligence James Clapper said, addressing members of the Senate Intelligence Committee. “These capabilities put all sectors of our country at risk—from government and private networks to critical infrastructures.”

Then, with cyber’s civil battlefield preparation in place and domestic upset rising, additional malware could be triggered to attack defense sensory and communications systems (among others), greatly disrupting, if not crippling them.  This phase of the cyber preparation could functionally blind physical military units and cut off their communications with adjacent units and higher command echelons.  In this environment, many of those units might not even know they’re next coming under physical attack until they start being destroyed.

This isn’t even a new strategy; it just uses modern facilities.  Karl Marx and Friedrich Engels wrote about this a century and a half ago, as noted by Sigmund Neumann and Mark von Hagen in Makers of Modern Strategy:

They were fully aware that military campaigns could be lost before the first shot, that they would in fact be decided beforehand on the preliminary battlefronts of economic and psychological warfare….  To [Marx and Engels] war was fought with different means in different fields.

Modern economies expand the opportunities to be gained from a first strike.  Most modern economies don’t have an industrial capacity.  Modern industry either assembles components that have been manufactured in other countries or it consists of component manufacture which are then shipped to those assembling economies.

A Cyber first strike would be no worse than a Pearl Harbor?  On the contrary, a properly executed first strike, as a classical combined arms assault that would include cyber warfare, could prevent us utterly from responding in any way at all, whether in cyberspace or in meat space.  There may not be any opportunity to work our way through our response decision criteria.

In a modern war (now exacerbated by those modern national economies), there will be no time to recover, to build up our forces, to bring our industrial capacity to a wartime footing and production rate.  We’ll fight this war with the army we have and with nothing at all, including replacement equipment and soldiers, else.

We could be left prostrate, begging for mercy.  If we could get our radios and telephones to work well enough to beg.

None of this is to suggest that a first strike is imminent.  But responding after the fact will be no response at all.  If we’re not better prepared, though, after the fact is what will be left to us.

Update:  Here’s a realtime example of a cyber attack rehearsal.

Computer networks at major South Korean banks and top TV broadcasters crashed simultaneously Wednesday, paralyzing bank machines across the country and prompting speculation of a cyberattack by North Korea.

Screens went blank at 2 p.m., the state-run Korea Information Security Agency said, and more than six hours later some systems were still down.

YGTBSM

And these guys are serious.

Recall that Cyprus is as bankrupt as Greece.  In order to bail out Cyprus (we’ve been over the legitimacy of bailouts elsewhere), the European Central Bank, European Commission, and the IMF have demanded a one-time tax on deposits: 9.9% on deposits over €100,000 ($131,000) and 6.75% on smaller deposits.

Nothing underhanded about any of this, either.  Uh, uh.  Because depositors, including many of the 3,500 British soldiers stationed in Cyprus, are complicit in the incompetence of the banks’ management.  Yeah.  That’s it.  We’ll go with that.

Finance Minister Michalis Serris already has taken steps to block depositors from taking their money out ahead of the tax:

We have taken immediate measures so that electronic transfers cannot take effect before banks reopen on Tuesday [today is a holiday in Cyprus.]

Chump change was recovered by depositors over the weekend via Cyprus’ cash machines, but the machines’ money stocks were limited and not replenished as they ran out.  Willy Sutton couldn’t have done it better.

A planned weekend vote by the Cypriot Parliament to pass this thing, however, was been postponed until today amid…concerns…that the Parliament may have more integrity than Serris and block the “agreement” with the ECB, the EC, and the IMF.

This is supposed to raise €5.8 billion ($7.6 billion).  Think about this, though.  Are the interest rates or investment rates of return that the Cypriot banks are paying on those deposits more or less than those taxes?  You get three guesses, and the first two don’t count.  For how long will those depositors leave their remaining money in those banks?  Again, three guesses, and the first two don’t count.

This is what happens when the wrong folks are left in charge of OPM.

Update: Cyprus’ legislative vote has been delayed until Tuesday afternoon.

Update again: Today (Tuesday) the Greek Parliament rejected any “tax” on private deposits by a vote of 36 “No,” 19 abstentions, and 0 “Aye.”