Google redirect: https://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web...
Still paywalled for me, even following that link.
Cyber Sleuths Track Hacker to China’s Military
11–20 of 57 posts
Re: Cyber Sleuths Track Hacker to China’s Military
#12Perhaps the government makes it worth the hackers' while to hack the USG instead of it. Just sad that so many intelligent people would rather be powerful/wealthy than free (not that the USG is a shining example of that sentiment).
Re: Cyber Sleuths Track Hacker to China’s Military
#13I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Re: Cyber Sleuths Track Hacker to China’s Military
#14If you get the paywall, I'd advise downloading the actual report from ThreatConnect it's far more detailed: http://www.threatconnect.com/camerashy/
MD5: b12f118840d0aa0d5ab2fb9aa052ede3 SHA1: dbd710751a6c32ba91401fb5e5623f46b4d2475f SHA256: da6b105f1e58f860ce67b2ad2db7b15ff7b637cfb37f7d0680a20eb633bcc741"
... when you are then providing both the PDF, and the list of its supposed hashes, over an unencrypted connection! It renders it meaningless. I can't trust those hashes or that document. And creating megabyte long PDFs with colliding MD5 hashes is not even a difficult challenge anymore.
The irony here is this page is say "hey open this document, it's safe, trust us" when the document is all about APT attack methods, which often involve compromising people's computers by opening untrustworthy documents! I doubt that's what's happening here, but still kind of silly when you think about it.
Please, all the companies out there. Stop adding a list of hashes to appear more legitimate when you clearly don't know what you are doing.
Re: Cyber Sleuths Track Hacker to China’s Military
#15I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
What the last some years have done, however, is to make me rather distrusting of both sides.
I may be in the minority. But a democracy is in significant trouble when its own population no longer trusts and believes it, in the large. The leadership either turns increasingly autocratic, or it loses its power.
The t-word wins again. The lies told ostensibly because t-word, are proving to be far worse than the original risk of t-word.
And instead of effective oversight to harden our own systems, we have blindness, lack of accountability, and scapegoating.
It's not just the data collection that makes me distrust the Feds. It's its gross mis-management, abuse, and the insistence that I can't know what is going on.
So, pump out your stories about the Chinese. Many of you politicians sold us down the river, in that regard, years ago.
Re: Cyber Sleuths Track Hacker to China’s Military
#16If you get the paywall, I'd advise downloading the actual report from ThreatConnect it's far more detailed: http://www.threatconnect.com/camerashy/
Why do companies, security companies even, do something like this... " Below are the document checksums for Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf MD5: b12f118840d0aa0d5ab2fb9aa052ede3 SHA1: dbd710751a6c32ba91401fb5e5623f46b4d2475f SHA256: da6b105f1e58f860ce67b2ad2db7b15ff7b637cfb37f7d0680a20eb633bcc741" ... when you are then providing both the PDF, and the list of its supposed hashes, over an unencrypted…
Source, please? Suppose the hashes and PDF were provided over HTTPS. How would it be easy to create another document that collided with all 3 hashes?
Not trying to be facetious - just wondering.
Re: Cyber Sleuths Track Hacker to China’s Military
#17I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Mr Xi is in town, what else related to Xi can give us more eyeballs now that all things Xi/China are in the news, what do we have? Oh, yes, of course, spying!
Re: Cyber Sleuths Track Hacker to China’s Military
#18If you get the paywall, I'd advise downloading the actual report from ThreatConnect it's far more detailed: http://www.threatconnect.com/camerashy/
Why do companies, security companies even, do something like this... " Below are the document checksums for Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf MD5: b12f118840d0aa0d5ab2fb9aa052ede3 SHA1: dbd710751a6c32ba91401fb5e5623f46b4d2475f SHA256: da6b105f1e58f860ce67b2ad2db7b15ff7b637cfb37f7d0680a20eb633bcc741" ... when you are then providing both the PDF, and the list of its supposed hashes, over an unencrypted…
Also - There is no known method to (within the lifetime of this universe) create a different document with the same MD5 and SHA1 and SHA256. Adding the MD5 doesn't weaken things, and might improve them.
Re: Cyber Sleuths Track Hacker to China’s Military
#19Re: Cyber Sleuths Track Hacker to China’s Military
#20I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
I have no doubt there is significant espionage going on. What the last some years have done, however, is to make me rather distrusting of both sides. I may be in the minority. But a democracy is in significant trouble when its own population no longer trusts and believes it, in the large. The leadership either turns increasingly autocratic, or it loses its power. The t-word wins again. The lies told ostensibly becaus…
Actually, democracy is safest when the people distrust it.
The real problem is that we have far too many people who are either completely trusting or totally inert.