Sources: US plans attacks on Russian networks and new sanctions, in retaliation for SolarWinds hack; Biden curbed Cyber Command's offensive leeway in Jan. 20 EO
The proliferation of cyberattacks by rivals is presenting a challenge to the Biden administration as it seeks to deter intrusions on government and corporate systems.
Related coverage shows the proposed sanctions becoming a broader action against Russian election interference and SolarWinds, including blacklisting six technology companies supporting Russian intelligence. It marks a departure from the prior tolerance of cyber espionage described in the subsequent coverage.
First-order effects
The Biden administration shifts its response to SolarWinds from deterrent rhetoric to a combined package of planned network operations and sanctions targeting Russia.
Cyber Command faces tighter White House control over offensive action at the same time it is being positioned as part of the retaliation.
Second-order effects
Russian intelligence-linked technology suppliers become an immediate pressure point as sanctions turn cyber retaliation into a commercial constraint, not solely a state-to-state technical contest.
US cyber policy must coordinate military-network activity with sanctions policy, making presidential authorization a more consequential part of operational timing.
Third-order effects
If this approach persists, US responses to major intrusions will treat cyber espionage as conduct that can trigger both covert network operations and public economic penalties, rather than as tolerated intelligence collection.
The balance between Cyber Command's operational latitude and White House oversight becomes a central determinant of how quickly the US can respond to state-backed intrusions.
The trend: State cyber deterrence is moving toward integrated retaliation that combines offensive access, sanctions, and tighter civilian control of military cyber operations.
The White House is pushing back on NYT's use of the term “cyberstrikes” to describe what's planned against Russia: “That was the New York Times' characterization, not ours. We don't know what the article is specifically referring to,” an administration official told me.
Biden's drone strike memo also contained a paragraph requiring Cyber Command to get NSC approval for “major cyberoperations that risk escalating conflict,” per NYT. Covert “actions across Russian networks” expected in next few weeks to respond to SW. https://www.nytimes.com/... h…
NYT story originally described the covert actions as “cyberstrikes,” but then, in a development that no one could have seen coming, the White House said “I don't know her” to that. https://twitter.com/...
Self-defeating: “Officials” tell NYT that “over the next three weeks” the USG will engage in “a series of covert counterstrikes on Russian networks.” USG is only country that regularly signals and boasts about its “secret” offensive cyber ops. https://www.nytimes.com/...
This is a crazy huge hack. The numbers I've heard dwarf what's reported here & by my brother from another mother (@briankrebs). Why, though? Is this a flex in the early days of the Biden admin to test their resolve? Is it an out of control cybercrime gang? Contractors gone wild? …
Two huge pieces of news in this: -U.S. is planning counterstrikes against Russian networks -Biden is reining in the broad authorities Trump gave Cyber Command. Will have to come to White House/NSC for any major ops now. https://www.nytimes.com/...
The first major move by the Biden administration to respond to a proliferation of cyberattacks by rivals is expected over the next three weeks, officials said, with a series of covert counterstrikes on Russian networks. https://www.nytimes.com/...
Biden administration is planning retaliatory cyber strike against Russia, and potentially China. “That would put them in the position of engaging in a potentially escalating conflict with two countries that are also its biggest nuclear-armed adversaries.” https://www.nytimes.com/…
“...move is expected over the next three weeks, officials said, with a series of covert counterstrikes on Russian networks that are intended to be evident to President Vladimir V. Putin and his intelligence services and military but not to the wider world” https://www.nytimes.com…
Thanks to decades of underfunding basic research on building secure systems, we are now in the idiotic position of threatening retaliatory cyberattacks against two nations. https://www.nytimes.com/...
Maybe I am missing something here but how would this be substantively different than the system put in place under Trump's NSPM 13, which is still on the books? It was always a misconception that Cyber Command ever had total freedom to launch attacks under the last admin. https:/…
Incidentally, Russia never owned up solar winds hack. So, advertising beforehand is rather bizarre. Wonder if papers should carry speculative pieces quoting undisclosed sources. After fact, maybe. But beforehand, meh. https://twitter.com/...
Two key questions: 1) The proposed retaliation hacks, we are told in the article, will reinforce what is in bounds and what is out. But what is that line, exactly? What norm that we adhere to did this campaign cross? Or does it not matter if we cross it ourselves? 1/2 https://twi…
The beauty of telegraphing cyberattacks is that it serves the dual purpose of satisfying the public's demand for retribution and will inevitably result in Russians (and allies) limiting the use of their networks in the coming weeks. If I had to guess, this is not about cyber. htt…
@Techmeme Guess this will make Dr. James Lewis happy. He was advocating for a more aggressive cyberspace posture in a US Cyber Command legal webinar last week.
Use of covert action for norms enforcement is pretty much always a mistake (as I wrote in longer form back in 2016) https://www.lawfareblog.com/ ... https://twitter.com/...
war is truly terrible, join me to pray for the mothers of the Russian servicemen that will soon be lost inside their text editors, unable to rely on their paintakingly memorized keyboard shortcuts https://twitter.com/...
Chinese state hackers compromised 30,000 American email accounts. Now, the White House is figuring out how to respond. “The White House is looking at convening an emergency group of government agencies to address the issue” https://www.washingtonpost.com/ ...
NEW: Biden administration moving to address a global compromise by Chinese and other hackers of Microsoft email servers. It's looking at standing up an emergency group to address the issue, officials say. https://www.washingtonpost.com/ ...
Now THIS is a Biden appointment to get excited about at last - Tim Wu - A Leading Critic of Big Tech Is Expected to Join the White House https://www.nytimes.com/...