Director Of National Intelligence Admits That There's Little Risk Of A 'Cyber Pearl Harbor'

from the so-why-are-we-rushing? dept

We’ve been pointing out for years that all the talk about “cyberattacks” and “cybersecurity” appear to be FUD, mostly designed to scare up money for “defense” contractors looking for a new digital angle. And yet, we keep seeing fear-mongering report after fear mongering report insisting that we’re facing imminent threats of such a dire nature that multiple people keep referring to this ridiculous concept of the “cyber Pearl Harbor” which is going to happen any day now if we don’t pass vaguely worded bills that will surely ramp up huge contracts. And yet, every time we’d hear these cinematic scare stories, we’d point out that no one has yet died from a “cyber attack” and ask: where was the actual evidence of real harm? Yes, we’ve seen hack attacks that are disruptive or really about espionage. But that “big threat” coming down to get us all? There’s been nothing to support it.

And perhaps that’s because it doesn’t exist. Amazingly, the Director of National Intelligence, James Clapper, actually admitted in a Senate hearing that there’s little risk of any “cyber Pearl Harbor” in the foreseeable future:

“We judge that there is a remote chance of a major cyber attack against U.S. critical infrastructure systems during the next two years that would result in long-term, wide-scale disruption of services, such as a regional power outage,” Clapper said in his statement to the committee. “The level of technical expertise and operational sophistication required for such an attack — including the ability to create physical damage or overcome mitigation factors like manual overrides — will be out of reach for most actors during this time frame. Advanced cyber actors — such as Russia and China — are unlikely to launch such a devastating attack against the United States outside of a military conflict or crisis that they believe threatens their vital interests.”

He later admitted that some others — who weren’t as knowledgeable — might be able to sneak in some attacks here or there, but that the impact would likely be minimal:

“These less advanced but highly motivated actors could access some poorly protected US networks that control core functions, such as power generation, during the next two years, although their ability to leverage that access to cause high-impact, systemic disruptions will probably be limited. At the same time, there is a risk that unsophisticated attacks would have significant outcomes due to unexpected system configurations and mistakes, or that vulnerability at one node might spill over and contaminate other parts of a networked system,” he said.

Of course, at the very same hearing, the NSA’s General Keith Alexander kept up the propaganda about threats. Alexander has been among those who have been spreading FUD about the “threats” — including ridiculous claims about Anonymous shutting down the power grid — so sticking to that line is hardly much of a surprise. This time around he focused on an increasing rate of attacks on Wall Street banks.

He also pulled out the old “the Chinese are stealing our business secrets!” claim. That always sounds good for Congress, but it is unclear how much real impact it has had.

But the Cyber Command chief stressed that the U.S. needs to clamp down on this intellectual property theft, warning it will ultimately “hurt our nation significantly.”

“For the nation as a whole, this is our future. This intellectual property, from an economic perspective, represents future wealth and we’re losing that,” Alexander said.

It doesn’t appear he has any real basis for saying that. There are all sorts of ways to compete and to innovate, and falling back on relying intellectual property laws may be the least useful and least efficient manner for doing so.

It would be nice if we could stop all the blatant fear mongering and focus on any actual problems, such as highlighting what important information isn’t being shared today, since we keep getting told that it’s our lack of information sharing that will lead to a cyber pearl harbor. Now that we know the threat isn’t imminent, can we sit back and look at the actual evidence, understand what the real problem is, and see if there’s a way to solve it that doesn’t involve giving up everyone’s privacy rights?

Filed Under: , , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Director Of National Intelligence Admits That There's Little Risk Of A 'Cyber Pearl Harbor'”

Subscribe: RSS Leave a comment

This time around he focused on an increasing rate of attacks on Wall Street banks.

Well, they flat out screwed up everyone, crashed the entire economy and used taxpayers money from the bail outs to pay themselves fat bonuses. If I could I’d do as much damage as I could to such morons.

There are all sorts of ways to compete and to innovate, and falling back on relying intellectual property laws may be the least useful and least efficient manner for doing so.

Offering quality products is a good start. The quality of Chinese stuff is usually very poor.

I read all these ‘cybersecurity’ scare stories as a single thing: “We, in the US, are utterly incompetent and cannot secure our vital systems thus we need to scare ourselves silly and run around screaming like loons while doing nothing that will actually address any real security breach”



There you go again Ninja, finding any way possible to bash the US.

They aren’t saying they can’t secure the systems. They are saying give us more money to give to corporations and pass more laws that take away the rights and privacy of our citizens.

It’s not about incompetence,if anything, it’s about greed and control.


Re: Re:

I’d say it’s a bit of both but if you are competent you don’t link vital infra-structure with the internet. Iran got delayed by stuxnet because they were incompetent enough to allow an infected pen drive to run in a ‘vital’ system. If you have a system that is THAT important external access to it must be very controlled.

I know it’s about greed and control but the image they pass is that of incompetence.

Minimum Waged Shillsays:

“we’d point out that no one has yet died from a “cyber attack””

It’s possible for someone to die from a cyber attack. If someone does a DDOS attack the right way all that traffic may overload the computer systems of the target routers and computers causing them to overheat and start a fire and fires are dangerous and could kill people. So laws must be passed to prevent this OK. Don’t you get it Mike. This is dangerous stuff here

Minimum Waged Shillsays:

Re: Re:

but if all the servers are forced to shut off all at once that’s even worse because when they turn back on all at once it can create huge power surges all at once and that can cause problems with the electrical wiring and cause fires and even very dangerous transformer explosions. Especially if that transformer gets hacked through the cyberwarbots. So regulations are needed.

Chris Brandsays:

Just doing his job

Of course “the Cyber Command chief” is focussed all the time on this stuff – he presumably sees little else. So to him, it no doubt is a huge problem that needs solving. Also, of course, his entire budget is presumably predicated on there being an actual cyber-threat.
It’s just like the Air Force Chief will tell you how desperately important it is that we defend our skies. It would be extremely surprising to see someone in this kind of position say “actually, it’s probably better to spend money elsewhere”.


SEC and DOJ have pretty much refused to hold big banks and Wall Street responsible for the damage they have done the economy and the average citizen. Politicians evidently don’t get people are pissed over this two tier justice system. Some are apparently doing things about it with hacking and exposing money trails and insider info.

When you have a cabinet level justice officer claiming that big banks are too big to be held responsible for their misdeeds it raises eyebrows. Lets not even talk about all the wrong claims for foreclosure on innocents that weren’t behind in their loans…if they had one. No one is making these banks pay up for their mistakes or for the third parties doing their bidding.

There’s lots of ill will out there on Main Street that no one seems to get a rats ass about in Washington. I wonder why there are so many doing things that the powers that be don’t like?

I couldn’t hack my way out of a wet paper bag. But I do see civil unrest building by the lack of action in Washington to deal with the real criminals and hold them accountable.


Re: "lack of action in Washington to deal with the real criminals"

Well, AC, I agreed with you right up to that point.

Problem is that there’s NO longer ANY separation between the political and corporate realms. It’s even worse than politicians being paid off: nowadays people move freely between political or appointed offices and corporate or media positions. It’s total fascism, just short of openly announced on front page of the New York Times. Difficult to believe anyone hasn’t noticed it, so I suppose that you just hold on to a faint hope it’s not so bad as looks.

Re: Re: "lack of action in Washington to deal with the real criminals"

Problem is that there’s NO longer ANY separation between the political and corporate realms. It’s even worse than politicians being paid off: nowadays people move freely between political or appointed offices and corporate or media positions.

I agree. My sense is that private industry will get exactly what it wants from the government in terms of security.

It will get defense contracts.
It will call on the government to clean up security whenever private industry wants help.
It will protest government surveillance whenever it wants to collect its own data on citizens, and then it will turn around and sell it to the government

As I read about all the back and forth on security and privacy I don’t see much difference between what government does and what private industry does and I think private industry calls the shots because it can buy the government it needs. The rest of the debate is just a sideshow.

Re: Re: "lack of action in Washington to deal with the real criminals"

POWER-CURVE SOCIETY: The Future of Innovation, Opportunity and Social Equity in the Emerging Networked Economy | The Aspen Institute: “The industries that are most resistant to any change in the status quo, said [Michael Fertik, Founder and Chief Executive Officer of] are Internet-based media incumbents such as Google and Facebook, which argue that new requirements to protect privacy will destroy innovation. Shane Green of Personal said that when he talks to people at large Internet companies that gather lots of personal data, he is ‘amazed’ at their resistance to disclosing how they capture data, what they do with it and how much money they make from it. ‘They sound just like Ma Bell from way back,’ said Fertik. ‘They have absolutely no interest in talking about privacy. Why won?t [these companies] open up and talk about how they capture data and what they do with it? Because they?re controlling things in a way that benefit them and not everyone else.’?



So our computers are at risk??

So, we arnt sending out IP to other nations so they can Build them Cheap, and send them back ‘for sale’ to US??

Hmm, sounds weird..

Do we send letters and NDA agreements to those companies in OTHER countries, AND ASK them not to share our DATA on products we WANT them to make??
Then ‘as the company’ why not just copy and send it to a Alternate, to make the product themselves…CHEAPER.

HOw many APPLE clones are there in China and the middle east..>? TONS. Why arent they HERE?? we have ANTI-COMPETITION LAWS/CONTRACTS..

Leave a Reply to Anonymous Cancel reply

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Older Stuff
13:40 It's Great That Winnie The Pooh Is In The Public Domain; But He Should Have Been Free In 1982 (Or Earlier) (35)
12:06 Norton 360 Now Comes With Crypto Mining Capabilities And Sketchy Removal Process (28)
10:45 Chinese Government Dragnet Now Folding In American Social Media Platforms To Silence Dissent (14)
10:40 Daily Deal: The 2022 Ultimate Cybersecurity Analyst Preparation Bundle (0)
09:29 A Fight Between Facebook And The British Medical Journal Highlights The Difficulty Of Moderating 'Medical Misinformation' (9)
06:29 Court Ruling Paves The Way For Better, More Reliable Wi-Fi (4)
20:12 Eighth Circuit (Again) Says There's Nothing Wrong With Detaining Innocent Minors At Gunpoint (15)
15:48 China's Regulatory War On Its Gaming Industry Racks Up 14k Casualties (10)
13:31 Chinese Government Fines Local Car Dealerships For Surveilling While Not Being The Government (5)
12:08 Eric Clapton Pretends To Regret The Decision To Sue Random German Woman Who Listed A Bootleg Of One Of His CDs On Ebay (29)
10:44 ICE Is So Toxic That The DHS's Investigative Wing Is Asking To Be Completely Separated From It (29)
10:39 Daily Deal: The 2022 Complete Raspberry Pi And Arduino Developer Bundle (0)
09:31 Google Blocked An Article About Police From The Intercept... Because The Title Included A Phrase That Was Also A Movie Title (24)
06:22 Wireless Carriers Balk At FAA Demand For 5G Deployment Delays Amid Shaky Safety Concerns (16)
19:53 Tenth Circuit Denies Qualified Immunity To Social Worker Who Fabricated A Mother's Confession Of Child Abuse (35)
15:39 Sci-Hub's Creator Thinks Academic Publishers, Not Her Site, Are The Real Threat To Science, And Says: 'Any Law Against Knowledge Is Fundamentally Unjust' (34)
13:32 Federal Court Tells Proud Boys Defendants That Raiding The Capitol Building Isn't Covered By The First Amendment (25)
12:14 US Courts Realizing They Have A Judge Alan Albright Sized Problem In Waco (17)
10:44 Boston Police Department Used Forfeiture Funds To Hide Purchase Of Surveillance Tech From City Reps (16)
10:39 Daily Deal: The Ultimate Microsoft Excel Training Bundle (0)
09:20 NY Senator Proposes Ridiculously Unconstitutional Social Media Law That Is The Mirror Opposite Of Equally Unconstitutional Laws In Florida & Texas (25)
06:12 Telecom Monopolies Are Exploiting Crappy U.S. Broadband Maps To Block Community Broadband Grant Requests (7)
12:00 Funniest/Most Insightful Comments Of 2021 At Techdirt (17)
10:00 Gaming Like It's 1926: Join The Fourth Annual Public Domain Game Jam (6)
09:00 New Year's Message: The Arc Of The Moral Universe Is A Twisty Path (33)
19:39 DHS, ICE Begin Body Camera Pilot Program With Surprisingly Good Policies In Place (7)
15:29 Remembering Techdirt Contributors Sherwin And Elliot (1)
13:32 DC Metro PD's Powerful Review Panel Keeps Giving Bad Cops Their Jobs Back (6)
12:11 Missouri Governor Still Expects Journalists To Be Prosecuted For Showing How His Admin Leaked Teacher Social Security Numbers (39)
10:48 Oversight Board Overturning Instagram Takedown Of Ayahuasca Post Demonstrates The Impossibility Of Content Moderation (10)
More arrow
This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it