Another Rude Question

This one relates to Congressman Eric Swalwell’s (D, CA) apparent compromise by the reputed People’s Republic of China spy Fang Fang (Christine Fang).

It seems that Fang hooked up with Swalwell early on, when he was a local politician, and she helped him rise into Congress: fundraising, staff selections, and the like. My question doesn’t relate, directly, to this particular tale.

There is a stock investing technique that centers on gorilla investing. This is a technique that attempts to identify a bunch of companies that are likely to be highly successful while those companies are in their early stages of development. The gorilla investor then pumps money into the stocks of each of those early-identified companies. As some of the companies grow in the market place, and many of them flame out, the gorilla investor bails on the flameouts and adds the money withdrawn from their stocks into to remaining putative gorillas. The process is repeated until only a few gorillas remain, and are true gorillas.

My question is this: are the relevant intelligence and investigative authorities looking into whether the PRC’s intelligence community has been and/or is still engaging in gorilla politician compromise, even actively aiding those most…promising? If so, are those early ones being identified and their histories vetted, with responses for those who still fail vetting?

Couple Rude Questions

These arise from the SolarWinds hack attack that some experts claim doesn’t rise to an act of war (but that I think might do so*).

Why wasn’t it spotted sooner? This applies to SolarWind as much as it does the IT MFWICs and their staffs at the various government agency and private business recipients. Who inspected SolarWind’s “updates,” how were they tested both before SolarWind disseminated them, and how were they tested before the receiving entities implemented them? Were the recipients actually, with straight faces, allowing a remote entity to enter their systems and install software that was uninspected/untested by those recipients?

What’s being done about the hack now—both defensively and offensively?

On what basis would we be able to believe all of the proximately done SolarWind hackware has been rooted out?

What other software is broadly used in government and automatically updated from outside? What inspecting and testing is being done on that software?

What inspection/testing is being conducted on all the private economy cloud software extant?

More serious, though, are these questions:

Was this hack, which embedded spyware, among other things, all of it? Or was this hack intended to be found as a distraction from detecting other, more hidden, more nefarious software—software that could be triggered later to conduct sabotage of critical systems, insert misleading or outright false data into critical databases and imaging systems, cut off communications between critical government and military leadership entities and between those and their field-operational systems at critical moments of a more overt attack?

Was this hack conducted by Russia? Or perhaps by Iran, while framing Russia, the butcher of Chechnya? Or perhaps by northern Korea, while disguising its own culpability by framing Russia? Or by the People’s Republic of China, which still regards Russia as a foe and now recognizes Russia’s political and military impotence vis-à-vis the CCP and the PLA, and so harming two enemies with one exploit?

*Shameless plug

A Training Opportunity

Ramstein AB, Germany, location of USAFE headquarters, got an emergency alarm over the weekend of an in-progress missile attack on the base. The alarm turned out to be false.

There are a couple of ways such a false alarm might be triggered. One is that the alarm was part of an exercise and the exercise label simply dropped or missed. Another is that, as part of a Russian exercise, by happenstance in also progress, missiles were launched at exercise targets inside Russia during that exercise’s final phase, and detection systems acted on the fact and a short time later (but after the alarm had been sent) recognized the launches for what they were and canceled the alarm.

In any event, as “a Pentagon official” said,

It’s important that we find out what happened, for a lot of reasons. We don’t want people getting needlessly alarmed, and we don’t want them to be complacent in the face of a genuine alert.

“Ramstein officials” also noted

Today, the Ramstein Air Base Command Post was notified via an alert notification system of a real-world missile launch in the European theater.  The Command Post followed proper procedure and provided timely and accurate notifications to personnel in the Kaiserslautern Military Community.

And in response to the alarm, those officials said,

Those who heard the warning took it seriously.

Which raises another important aspect of the false alarm: the real-world operational training opportunity the alarm presented to the base and the surrounding Kaiserslautern Military Community. Finding out what happened regarding the transmittal of a false alarm should include a detailed, critical post mortem on the base and community response to the fact of the alarm. That post mortem also should include an assessment of why less than everyone heard the alarm.

Student Loans

A letter writer in last Thursday’s Wall Street Journal Letters section had a thought.

There are some degrees that are worth borrowing money for, but many aren’t. Parents and students, do your homework.

Indeed. Lenders need to do their due diligence homework much more diligently, too. Two ways to incentivize (to coin a term) the lenders: get Government out of the business of making student loans and out of the business of guaranteeing others’ loans to students.

The other way is to require the school being borrowed for to attend to be the primary lender—ideally, the sole lender.

Legal in LA

Los Angeles County District Attorney George Gascón has decided to pick and choose the laws he’ll work to enforce and the crimes he’ll explicitly excuse. Here’s the Directive Gascon issued to the County Prosecutors. This is the opening of his Section I, Declination of Policy Directive [emphasis in the original]:

The misdemeanor charges specified below shall be declined or dismissed before arraignment and without conditions unless “exceptions” or “factors for consideration” exist.
These charges do not constitute an exhaustive list

Here are the high points of Gascón’s non-exhaustive list:

  • Trespass
  • Disturbing The Peace
  • Driving Without A Valid License
  • Driving On A Suspended License
  • Criminal Threats
  • Resisting Arrest

Here’s what Angelenos are going to face/have to do as a result of Gascón’s legal negligence:

  • deal with trespassers their way rather than wasting precious minutes calling the cops.
  • auto insurance claims are going to skyrocket, and then so will premiums, from letting anyone, under any circumstance or skill, drive and endanger everyone else, pedestrian and motorist.
  • police will be at increased risk—at least those remaining before he abolishes them—from resisters.

This. Is. California.

 

H/t Bill Melugan, investigative correspondent for FOX 11 Los Angeles.