Man I got to tell you if you there are low standards almost everywhere. I've pulled off multiple (legal) gigs where you'd think "surely X has done Y to stop obvious negative conclusion Z" and no, they did not do Y. They did some dumb B or C and it was trivial to detect and get around and, at best, it took them a month to notice what you did and their new countermeasures aren't up to the challenge either.
This is why I've been so concerned about cybersecurity and cyberwarfare. I do not see gross competence here and most of the people I respect that write about this type of thing are sounding the alarm. Click Here to Kill Everybody or Matt Tait (@pwnallthethings on Twitter) ending an Infiltrate conference talk with a nuclear bomb as the final image.
>So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use.
Like leaving data of their secret assets available on Google searches, leading to hundreds of deaths? And firing the employee who warned then of the problem seven years before it was exploited?
You'd think at least some of these inept cyberspooks would have read Neal Stephenson's Cryptonomicon. Or Brian Krebs. Or Bruce Schneier.
Or even the news story of how their old boss(!) John Brennan had his AOL(!) email account(!) cracked(!) by a teenager(!) guessing his password(!). The teenager exfiltrated something sensitive, a job application I believe, and was prosecuted for it. Meantimes, the former Director of Central Intelligence gets to keep his reputation.
Glossing over 10 years of tens of thousands of people's work, things like Titan Rain (1, 2) led to a lot of thinking about monitoring your production environment with things like the istio sidecar system.
To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205
Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online.
Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe.
And when will these state actors with unlimited funding figure out that NOBODY can keep secrets forever, not even them?