I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Cyber Sleuths Track Hacker to China’s Military
21–30 of 57 posts
Re: Cyber Sleuths Track Hacker to China’s Military
#22I wonder if China online newspapers have stories about tracking hackers to USA's military?
Re: Cyber Sleuths Track Hacker to China’s Military
#23I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.
Re: Cyber Sleuths Track Hacker to China’s Military
#24Earlier quoted context omitted.
Why do companies, security companies even, do something like this... " Below are the document checksums for Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf MD5: b12f118840d0aa0d5ab2fb9aa052ede3 SHA1: dbd710751a6c32ba91401fb5e5623f46b4d2475f SHA256: da6b105f1e58f860ce67b2ad2db7b15ff7b637cfb37f7d0680a20eb633bcc741" ... when you are then providing both the PDF, and the list of its supposed hashes, over an unencrypted…
> creating megabyte long PDFs with colliding MD5 hashes is not even a difficult challenge anymore. Source, please? Suppose the hashes and PDF were provided over HTTPS. How would it be easy to create another document that collided with all 3 hashes? Not trying to be facetious - just wondering.
If its not over HTTPS, it doesn't matter there are 3 hashes. I change the doc. I generate the 3 hashes for my changed doc. I can serve those new hash values.
Re: Cyber Sleuths Track Hacker to China’s Military
#25I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.
Re: Cyber Sleuths Track Hacker to China’s Military
#26Without having read the full PDF report [0], the summarized version [1] makes the allegations seem quite weak. It comes down, seemingly, to the fact that a PLA domain name appears in the malware. Maybe I'm missing something. [0] http://cdn2.hubspot.net/hubfs/454298/Project_CAMERASHY_Threa... [1] http://www.threatconnect.com/camerashy-resources/
It seems pretty likely there is some PLA connection, though not necessarily to this particular guy - no way of knowing that a buddy didn't steal his handle for use elsewhere (seriously, not sharing the same hacking handle and the same personal username should be Tradecraft 101)
Re: Cyber Sleuths Track Hacker to China’s Military
#27I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…
Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.
It wants users to get used to how Windows works, versus to other alternatives like Linux, Mac, etc.
Re: Cyber Sleuths Track Hacker to China’s Military
#28It's embarrassing to see the flailing of the US intelligence apparatus trying to take attention away from their own abuses of power.
Re: Cyber Sleuths Track Hacker to China’s Military
#29A huge amount of space is dedicated to tenuous ties between physical military activities and espionage on the assumption that all chinese agencies are coordinating with each other, that the Chinese are just better at conspiracy than any US operation. No actual intelligence officer would ever describe China in that way. It's a patchwork of poorly-connected operations all trying to put on a good show for the bosses, much the same as US intelligence agencies.
Certain key phrases suggest political motive. As example, the phrase "China’s ... military grade signals intelligence Unit" caught my ear. "Military grade" doesn't mean much in infosec. It does mean something to lifelong service members who labour under the assumption that military structures just do things better than civilian organizations. In some fields "military grade" is actually a bad thing, a reference to products built to conform to rarely-updated procurement standards. It's like still selling floppy disks because the computer on the stealth bombers haven't been updated in 20 years. The phrase appears right at the start of the takeaways section, right where most senior officials will probably start reading.
The drilling down upon a few people, to the point of tracking a man's movements and finding the bike he offered for sale, certainly plays into current US national security desires. Targeted killings based on poor intel is a big chip on the military shoulder these days. They aren't happy about it. So peppering a document with a few grains of seemingly accurate and specific intel about individuals is a good trick to win people over. The excessive reliance on google maps is just eyecandy. This gives the false impression of validity, a false suggestion that the rest of the report is based on equally detailed and reliable intel. if this were such intel, it wouldn't be released publicly.
the pdf: http://cdn2.hubspot.net/hubfs/454298/Project_CAMERASHY_Threa...