Looks like free enterprise has introduced a tax on people who fail to secure their systems against untargeted attacks and fail to make backups. One also wonders what's the point of all NSA's "SIGINT" efforts if they can't or won't use it to catch such usually foreign actors, so maybe they also introduced an argument against mass surveillance.
I suggest that the cybersecurity tool-set favors offense these days.
Chris Inglis, recently retired NSA Deputy Director, remarked that
if we were to score cyber the way we score soccer, the tally would
be 462-456 twenty minutes into the game, i.e., all offense. I will
take his comment as confirming at the highest level not only the
dual use nature of cybersecurity but also confirming that offense
is where the innovations that only States can afford is going on.
This is a serious problem, not only from the problems intelligence angies with many powers and poor oversight; ignoring defense is going to bite a lot of people in bad ways. We are already seeing the beginnings of this with the escalating impact computer-based attacks are having on their victims.I also recommend considering Jacob Appelbaum's response to this question[2] from the audience - from someone currently working for the NSA. The summary is that we need people doing NSA-style work, but on the defense side, and we need it now. If the NSA isn't doing that, then maybe people that want to actually protect their country should find somewhere else to work that is actually working on defense.