# Russians hack many US government systems

**URL:** <https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 14, 2020, 1:46pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023 "2020-12-14T13:46:37Z")\
**Posts on this page:** 20\
**Page:** 3

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 4:51pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/41 "2020-12-20T16:51:54Z")

</div>

> [@Riemann](#):
>
> So however many smart people had been devoted to cybersecurity over the past few years, none of them could conceivably have spotted any potential problem here or done anything about it?

No one spotted it until it had been in the wild for several months.

> [@Riemann](#):
>
> By your reasoning, presumably you’d advocate that we may as well just shut down the entire cybersecurity division and save the money - because going forward why would you expect it to be any different? There’s nothing anyone could possibly do to improve the situation.
> 
> Your position is utterly ridiculous.

Whew, lucky that isn’t my position. It’d put me out of a job if it was.

My actual position: The only way to have avoided this would be to have better security practices at Solarwinds controlling their update servers, or for their product not to have been so popular at large organizations.

If you’ve got a way that Trump could have fixed that, then you’ve got an argument with me. If not, please stop coming up with alternate positions you’d rather argue with and attributing them to me. I mean, hell, is Trump responsible for all the times a piece of _commercial_ software is exploited while he’s in office? Because that’s what happened here. That’s a pretty damn ridiculous position, and I don’t see how your position differs from that.

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [December 20, 2020, 5:08pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/42 "2020-12-20T17:08:01Z")

</div>

> [@scabpicker](#):
>
> Whew, lucky that isn’t my position.

We can read what you wrote, and you’ve written it again:

> [@scabpicker](#):
>
> If you’ve got a way that Trump could have fixed that, then you’ve got an argument with me.

Your stated position is that there was no conceivable way for _anyone_ in government service to have fixed or improved this situation over the past few years, whatever resources were dedicated to it?

Your position and the burden of proof that you seek to place on me make absolutely no sense. You are claiming that the well documented fact that Trump was removing resources and smart people from cybersecurity is irrelevant.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 20, 2020, 5:25pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/43 "2020-12-20T17:25:26Z")

</div>

> [@scabpicker](#):
>
> My actual position: The only way to have avoided this would be to have better security practices at Solarwinds controlling their update servers, or for their product not to have been so popular at large organizations.

A trojan carried by the SolarWinds updates was used to place _other_ malware on client systems.

With more security personnel checking critical systems for malware, they could have found out what was happening sooner.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 7:30pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/44 "2020-12-20T19:30:20Z")

</div>

> [@Riemann](#):
>
> Your stated position is that there was no conceivable way for _anyone_ in government service to have fixed or improved this situation over the past few years, whatever resources were dedicated to it?

I’m certainly of the position that those budget cuts had nothing to do with fixing Solarwinds’ practices. You’ve provided no mechanism how they might have.

> [@GreenWyvern](#):
>
> A trojan carried by the SolarWinds updates was used to place _other_ malware on client systems.
> 
> With more security personnel checking critical systems for malware, they could have found out what was happening sooner.

That’s still not preventing or avoiding this hack, it’s just reacting sooner.

---

<div class="post-metadata">

**Author:** ![Riemann](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/riemann/32/3133_2.png) [@Riemann](https://boards.straightdope.com/u/Riemann)\
**Post date:** [December 20, 2020, 7:42pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/45 "2020-12-20T19:42:28Z")

</div>

> [@scabpicker](#):
>
> You’ve provided no mechanism how they might have.

I’ve cited clear evidence that Trump has systematically been taking financial resources and smart people away from cybersecurity for years. I don’t think you’re disputing that.

What more do you think I have any burden to prove here? I’m not a technical expert in cybersecurity, in that I bow to your superior knowledge. But the burden is on you to support your preposterously implausible hypothesis that _however_ many smart people and whatever resources might have been dedicated to this over the last several years, _nothing_ could possibly have stopped or ameliorated this hack. So it was perfectly fine that Trump took money and people away from cybersecurity to build a wall instead.

And further, to explain _why_ you claim that I’m parodying your opinion when I point out that a natural consequence of your view is that there’s no point funding cybersecurity in the future either. If you think it could not possibly have achieved anything in the past, why do you think it could achieve anything in the future?

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 20, 2020, 7:49pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/46 "2020-12-20T19:49:00Z")

</div>

> [@Riemann](#):
>
> But the burden is on you to support your preposterously implausible hypothesis that _however_ many smart people and whatever resources might have been dedicated to this over the last several years, _nothing_ could possibly have stopped it or ameliorated it.

Nope, the burden is on you to prove that those budget changes would have prevented the hack. I’ve never said no amount of resources would have fixed it, but unless those resources were applied to fixing Solarwinds’ practices or replacing its use, this was almost inevitable.

> [@Riemann](#):
>
> So it was perfectly fine that Trump took money and people away from cybersecurity to build a wall instead.

I’ve never said anything of the sort. The moving of this money was stupid in the extreme, but it would not have prevented this.

---

<div class="post-metadata">

**Author:** ![asahi](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asahi/32/8693_2.png) [@asahi](https://boards.straightdope.com/u/asahi)\
**Post date:** [December 20, 2020, 7:51pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/47 "2020-12-20T19:51:00Z")

</div>

Hacking of some type? Yes, of course.

But we’re talking about a matter of degree, and we’re also talking about the timing. It’s arguably a more provocative type of hacking than the garden variety intrusions that governments of all stripe engage in. But even if we disagree on this point, what’s less debatable is that the response from Trump was predictable, and it a) encouraged the hacking before it happened; and b) will likely encourage more hacking in the future until a US administration establishes its own rules of engagement.

The US needs to show that it is capable of retaliating in kind. Right now, it’s not showing that at all. It’s showing the opposite, and what’s also not clear is…who is defending US interests from within the Trump administration. Mike Pompeo has come closest to saying that this is an act of hostility, but that’s it.

I think it is very likely that there is some degree of coordination within the Kremlin and within the White House. The behavior of the administration is just too damn bizzaro to believe otherwise.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [December 20, 2020, 7:54pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/48 "2020-12-20T19:54:42Z")

</div>

We did in fact find out about this hack, right? So finding out about it is something that’s possible. And I think it’s safe to say that we found out about it as a result of someone doing something. And whoever that someone was, and whatever it was that they did, it would have been at least theoretically possible for someone to have done it sooner. And Trump gutted the someones who were supposed to be trying to do just that.

But to get more specific than that: The government was using SolarWinds for secure purposes. When the government uses a piece of software for secure purposes, they should first be checking to see if the software is secure. They shouldn’t just take the company’s word on it. And that independent security checking is one of the things that’s supposed to be done by the agencies Trump gutted.

Could they have missed spotting this even if they’d been adequately funded and otherwise supported? Sure, maybe. Or maybe not. We don’t know, because we live in the world where they weren’t adequately supported.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 21, 2020, 3:45am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/49 "2020-12-21T03:45:10Z")

</div>

> [@asahi](#):
>
> But we’re talking about a matter of degree, and we’re also talking about the timing. It’s arguably a more provocative type of hacking than the garden variety intrusions that governments of all stripe engage in. But even if we disagree on this point, what’s less debatable is that the response from Trump was predictable, and it a) encouraged the hacking before it happened; and b) will likely encourage more hacking in the future until a US administration establishes its own rules of engagement.

Yes, I would agree this is a very severe hack. However, it was going to happen no matter who the president was once Solarwinds’ update server was compromised. Trump’s idiocy doesn’t enter into when this was executed. They got the opportunity, and worked as hard as was prudent until the hack got shut down.

Rules of engagement? This is the internet, baby. You can moan and cry, or you can issue sanctions, but I don’t think that any rules of engagement are going to save you. In the case of Solarwinds, it appears that there were indications of lax security there before this happened, and industry/institutional inertia may have contributed to their not being discarded. If you started instituting audits of the security practices of the companies as suggested by **Chronos** in the post following yours, you might be able to successfully combat some and possibly most of these kind of supply chain attacks. But that’s not done in most software employed by the government these days, and it would have a side effect of slowing the technologies available to the government, and increase its cost (which would have its own security costs and time based vulnerabilities).

> [@asahi](#):
>
> The US needs to show that it is capable of retaliating in kind.

Ehh, I think we’ve already shown we can stockpile zero day hacks. I don’t think the results have been positive, so far. If we were to devote resources to anything besides the massive cleanup that’s needed now, I’d say it should be to finding and notifying software producers of their holes in both their product and production.

> [@Chronos](#):
>
> We did in fact find out about this hack, right? So finding out about it is something that’s possible. And I think it’s safe to say that we found out about it as a result of someone doing something.

Yeah, you make it sound simple. As far as I know we fond out about this hack by FireEye having its red team tools stolen. They found out about the Solarwinds hack because they wanted to know how those tools ended up in the wild, and worked backward from there. They didn’t notice the malicious actors before their tools were stolen. If an actual security firm isn’t going to notice it except in retrospect, I can’t see how their customers are going to be able to fix the same problem by throwing cash at it.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 21, 2020, 4:27am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/50 "2020-12-21T04:27:18Z")

</div>

Yes, sure! Hackers gonna hack, whatcha gonna do?

No point in trying, even. Might as well just defund cybersecurity completely and hand everything over to the Russians. Building a wall is the best security.

😀  

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 21, 2020, 4:35am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/51 "2020-12-21T04:35:47Z")

</div>

> [@GreenWyvern](#):
>
> Yes, sure! Hackers gonna hack, whatcha gonna do?
> 
> No point in trying, even. Might as well just defund cybersecurity completely and hand everything over to the Russians. Building a wall is the best security.
> 
> 😀

This is a complete misrepresentation of my position, but thanks.

🤡

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 21, 2020, 7:48am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/52 "2020-12-21T07:48:39Z")

</div>

You seem to be contradicting yourself.

- First you say that defunding cybersecurity couldn’t possibly have had any effect.
- Then you say that if more money is spent, it could in fact combat attacks like this.  
&nbsp;

> [@scabpicker](#):
>
> I’m certainly of the position that those budget cuts had nothing to do with fixing Solarwinds’ practices. You’ve provided no mechanism how they might have.

&nbsp;  
Then you yourself suggest the mechanism how they might have:

> [@scabpicker](#):
>
> If you started instituting audits of the security practices of the companies as suggested by **Chronos** in the post following yours, you might be able to successfully combat some and possibly most of these kind of supply chain attacks.

> [@scabpicker](#):
>
> If we were to devote resources to anything besides the massive cleanup that’s needed now, I’d say it should be to finding and notifying software producers of their holes in both their product and production.

So you say that “instituting audits of the security practices of the companies” would work, and that resources devoted to “finding and notifying software producers of their holes” is a good idea.

But funding those audits and resources is apparently not a good idea, and couldn’t have made any difference? 🤨

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [December 21, 2020, 8:05am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/53 "2020-12-21T08:05:55Z")

</div>

> [@GreenWyvern](#):
>
> But funding those audits and resources is apparently not a good idea, and couldn’t have made any difference? 🤨

There’s an interesting philosophical discussion about what is and isn’t “science”. For example, one idea was that science consists of falsifiable assertions, where “falsifiable” is a subset of “testable”.

“Couldn’t have made a difference” is an example of an assertion that can’t be tested, and is not falsifiable. It’s just a polemic.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 21, 2020, 8:29am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/54 "2020-12-21T08:29:52Z")

</div>

> [@Melbourne](#):
>
> There’s an interesting philosophical discussion about what is and isn’t “science”.

We’re not discussing the philosophy of science, but politics and current events.

Trump deliberately defunded cybersecurity in the face of several years of increasing Russian cyber attacks. That was obviously a bad decision in itself.

When that was followed by a massive and successful Russian cyber attack, we certainly have a right to wonder if that attack could have been mitigated by not defunding cybersecurity.

---

<div class="post-metadata">

**Author:** ![asahi](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asahi/32/8693_2.png) [@asahi](https://boards.straightdope.com/u/asahi)\
**Post date:** [December 21, 2020, 1:43pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/55 "2020-12-21T13:43:35Z")

</div>

I mean, right? 😆

---

<div class="post-metadata">

**Author:** ![asahi](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asahi/32/8693_2.png) [@asahi](https://boards.straightdope.com/u/asahi)\
**Post date:** [December 21, 2020, 1:50pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/56 "2020-12-21T13:50:37Z")

</div>

> [@scabpicker](#):
>
> Ehh, I think we’ve already shown we can stockpile zero day hacks. I don’t think the results have been positive, so far. If we were to devote resources to anything besides the massive cleanup that’s needed now, I’d say it should be to finding and notifying software producers of their holes in both their product and production.

We can walk and chew gum at the same time.

Look, I absolutely agree that hacking is hacking, and spying is spying. It’s like cheating in football. Every team’s gonna try to gain an edge, but there’s a difference between getting an edge and stealing a team’s playbook.

Moreover, if we don’t respond and if nothing else hold another state sponsor of intrusions responsible, the message that is sent may well be the opposite of the policy, and that is dangerous for all parties involved. If state A communicates to state B that there’s no formal response for a level 1 or 2 provocation, then state B will assume that it’s okay to escalate to level 3 or 4 provocation, when in fact, state A marks the threshold for a massive response at level 2. The problem is that, right now, there are not clear rules of engagement. “It’s the internet baby” is not the answer we’re looking for. It’s extremely dangerous not to have clear rules of engagement.

---

<div class="post-metadata">

**Author:** ![scabpicker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scabpicker/32/8268_2.png) [@scabpicker](https://boards.straightdope.com/u/scabpicker)\
**Post date:** [December 21, 2020, 1:55pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/57 "2020-12-21T13:55:04Z")

</div>

> [@GreenWyvern](#):
>
> You seem to be contradicting yourself.
> 
> - First you say that defunding cybersecurity couldn’t possibly have had any effect.
> - Then you say that if more money is spent, it could in fact combat attacks like this.

This is your misinterpretation of what I’ve said. I’ve consistently said that unless this budget was being applied to Solarwinds’ activities, it wasn’t gong to prevent this hack. This is true, if you’d tripled our cybersecurity budget, it was unlikely to fix the practices at a private company that isn’t under that budget. Fact is, the government doesn’t audit most of the private companies it buys software from, and I don’t know of any part of that budget that would have been applied to doing so.

For the third time: THAT BUDGET COULD BE USED FOR THE CLEANUP, BUT IT WOULD NOT HAVE PREVENTED THE HACK EVEN IF IT HAD NOT BEEN DIVERTED. It shouldn’t have been diverted, but that’s for a million other very good reasons not related to this hack.

Quite honestly, if you try to pin this hack on Trump, you’re only showing your own ignorance of how the situation worked out. I’ve tried to make this clear. This apparently makes you sad enough that you’re willing to try to paint anyone who disagrees with on it you as Trump supporter, and I’ve been accused of supporting the wall without any supporting evidence in this thread twice for my trouble.

So, if you could try to understand what I’m saying instead of trying to run the whole thing as some sort of partisan gotchya, I’d appreciate it. If the fucker shows up in the crosswalk, I’m not hitting the brakes, and defending him doesn’t make me happy – but it’s true this was going to happen no matter who led the country.

---

<div class="post-metadata">

**Author:** ![GreenWyvern](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/greenwyvern/32/2834_2.png) [@GreenWyvern](https://boards.straightdope.com/u/GreenWyvern)\
**Post date:** [December 21, 2020, 2:59pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/58 "2020-12-21T14:59:32Z")

</div>

> [@scabpicker](#):
>
> This is your misinterpretation of what I’ve said. I’ve consistently said that unless this budget was being applied to Solarwinds’ activities, it wasn’t gong to prevent this hack. This is true, if you’d tripled our cybersecurity budget, it was unlikely to fix the practices at a private company that isn’t under that budget.

Where exactly do you get this opinion from?

_ **Both government and the private sector have been calling for a close partnership for years, but nothing was done about it, because there was no funding for it.** _

Note the dates on these articles:

2016:

> **[Cybercom Commander: Public-Private Partnerships Needed for Cybersecurity](https://www.defense.gov/News/News-Stories/Article/Article/1006807/cybercom-commander-public-private-partnerships-needed-for-cybersecurity/)**
>
> Given growing threats to everyone from cyberspace, collaboration between private companies and federal agencies is critical, the commander of U.S. Cyber Command said during the Wall Street Journal CEO

> The public-private cybersecurity partnership between private companies and U.S. Cyber Command and other federal agencies has been uneven so far despite some fledgling success, but **collaboration is critical given growing threats to everyone from cyberspace, the commander of U.S. Cyber Command said here yesterday**.

2017:

> **[Expert Tells House Committee: "Healthcare Cybersecurity is Worse Than Reported"](https://www.businesswire.com/news/home/20170405006088/en/Expert-Tells-House-Committee-Healthcare-Cybersecurity-is-Worse-Than-Reported)**
>
> Expert Tells House Committee:

> Among the areas of opportunity he recommended to enhance greater partnership and collaboration are:
> 
> 1. HHS appointment of a **Healthcare Sector Cybersecurity Liaison to the private sector.**

2016:

> **[Public-private cyber threat intelligence sharing necessary in electricity...](https://www.csoonline.com/article/554709/public-private-cyber-threat-intelligence-sharing-necessary-in-electricity-industry.html)**
>
> Cybersecurity professionals are hungry for a strategic advantage to battle new denial of service attacks and unauthorized access to systems. The electricity industry has started to focus its efforts on combating the issue head-on through timely cyber...

> As a result, **the electricity sector is demanding more access from regulators and federal partners to actionable intelligence and threat streams.** With this added intelligence, utilities can better pinpoint threats to specific systems and focus efforts on system recovery and restoration.

2017:

> **[Improving the Public-Private Cybersecurity Partnership | The Regulatory Review](https://www.theregreview.org/2017/09/04/daniel-public-private-cybersecurity/)**
>
> State-sponsored cyber attacks may require revamping how the government helps companies fight back.

> **that same type of coordinated response across the public and private sectors is exactly what “we need to defend our country against major cyber-attacks.** ” But former Secretary Pritzker also recognized that achieving this unified partnership between government and business may require “fundamentally changing” the way businesses work with federal agencies to counter cyber threats.

_ **Again nothing was done about this, because there was no funding for it.** _

---

<div class="post-metadata">

**Author:** ![wguy123](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wguy123/32/3161_2.png) [@wguy123](https://boards.straightdope.com/u/wguy123)\
**Post date:** [December 21, 2020, 4:41pm UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/59 "2020-12-21T16:41:40Z")

</div>

I wonder if the roll-out of the Cybersecurity Maturity Model Certification (CMMC) would’ve helped with this sort of problem? DoD will be the first to roll out CMMC but I’m guessing it will spread to other agencies. And if you were curious, SolarWInds can help you prepare for CMMC:

> **[Cybersecurity Maturity Model Certification (CMMC)](https://www.solarwinds.com/federal-government/solution/cybersecurity-maturity-model-certification)**
>
> How can your IT team prepare for the new Cybersecurity Maturity Model Certification (CMMC)? That’s exactly the question the SolarWinds team can help you answer.

🤣

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [December 22, 2020, 12:15am UTC](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023/60 "2020-12-22T00:15:09Z")

</div>

> [@GreenWyvern](#):
>
> When that was followed by a massive and successful Russian cyber attack, we certainly have a right to wonder if that attack could have been mitigated by not defunding cybersecurity.

And we certainly have the right to say – nah, not so much.

[Previous page](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023.md?page=2)

[Next page](https://boards.straightdope.com/t/russians-hack-many-us-government-systems/928023.md?page=4)
