US has 'no strategy' for dealing with Russian cyber attack, says McCain

Trump administration blasted by former candidate

Senator John McCain has warned that the US "[doesn't] have a strategy" for dealing with cyberwarfare tactics that may be employed by Russian, Chinese or North Korean agents, The Guardian reports.

Speaking at the Republican party's annual retreat in Philadelphia, he reiterated the commonly-held belief among the US intelligence community that "the Russians were trying to influence the outcome of our election", and warned that America wasn't ready to respond to similar attacks on elections in Europe.

Many EU countries - France and Germany chief among them - are facing a groundswell of support for far-right parties in the upcoming elections, and there are fears that Russia may use offensive cyber capabilities to propel these parties to victory.

McCain was vocally critical about the state of US cyber security, saying "we don't have a policy and we don't have a strategy". "It is the one aspect of our confrontation where I believe our adversaries are ahead of us," he added.

Advertisement
Advertisement - Article continues below

"Much of the investment in the west has been on cyber defence and monitoring, rather than offence; whether at a government level or within the enterprise space," agreed Piers Wilson, Huntsman Security's head of product management.

He cautioned, however, that the ends does not always justify the means. "Whether the US or any other nation, if we claim to hold 'Western' values, we may find ourselves unwilling to take courses of action that others might find more acceptable," he said. "We shouldn't compromise those values just to reset a perceived asymmetry."

Despite McCain's scorn, signs would suggest infosec is front-of-mind for the Trump regime; the president's foreign policy makes specific mention of using "cyberwarfare" to fight terrorist groups.

However, there have also been recent indications that the personal security of Trump and his top aides may not be up to scratch. Eagle-eyed hackers recently spotted that Twitter accounts belonging to president Trump, vice president Mike Pence, the first lady and more were all vulnerable to security exploits due to a lack of basic protections including two-factor authentication and multi-stage verification.

By exploiting Twitter's password reset function, a hacker known as WauchulaGhost was able to ascertain the email addresses associated with these accounts, many of which were private accounts hosted by companies like Microsoft and Google.

Furthermore, TheNextWeb discovered that cabinet members and key advisors such as Steve Bannon, secretary of defense James Mattis and press secretary Sean Spicer were also vulnerable to the same tactics. Spicer also drew ridicule this week when he accidentally tweeted out an alphanumeric string that many suspected was his Twitter password.

Featured Resources

The IT Pro guide to Windows 10 migration

Everything you need to know for a successful transition

Download now

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Software-defined storage for dummies

Control storage costs, eliminate storage bottlenecks and solve storage management challenges

Download now

6 best practices for escaping ransomware

A complete guide to tackling ransomware attacks

Download now
Advertisement

Recommended

Visit/government-it-strategy/28305/ir35-news
Policy & legislation

Businesses urged to continue IR35 preparations despite Conservative review pledge

3 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/policy-legislation/34515/what-has-donald-trump-done-for-the-tech-industry-so-far
Policy & legislation

What has Donald Trump done for the tech industry so far?

27 Sep 2019
Visit/cyber-warfare/33958/are-we-in-the-midst-of-a-cyber-war
cyber warfare

Are we in the midst of a cyber war?

4 Jul 2019

Most Popular

Visit/security/identity-and-access-management-iam/354289/44-million-microsoft-customers-found-using
identity and access management (IAM)

44 million Microsoft customers found using compromised passwords

6 Dec 2019
Visit/cloud/microsoft-azure/354230/microsoft-not-amazon-is-going-to-win-the-cloud-wars
Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Visit/hardware/354237/five-signs-that-its-time-to-retire-it-kit
Sponsored

Five signs that it’s time to retire IT kit

29 Nov 2019
Visit/business/business-strategy/354195/where-modernisation-and-sustainability-meet-a-tale-of-two
Sponsored

Where modernisation and sustainability meet: A tale of two benefits

25 Nov 2019