Live data from Hacker News

Google Hack Attack Was Ultra Sophisticated, New Details Show

wired.com

71–80 of 116 posts

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#71
post #63

Earlier quoted context omitted.

I don't know a lot about security -- certainly not as much as some here (although I can follow along with their banter easily enough) But I know enough not to feel comfortable commenting on this in a public forum. (Not trying to pass a value judgment on you, just suggesting a reason you guys might not be getting an answer to your question.)

>But I know enough not to feel comfortable commenting on this in a public forum. why?

Because it's a lose-lose proposition. If I get it right, I'm helping some other schmuck break into people's systems. If I get it wrong then I'm the schmuck.

And yes, people will learn to break into systems without my help, and yes, openness is the best defense we have against these things. I've just decided I'm just not going to put anything out there that could possibly be used like that.

I tell you one of the reasons why: about twelve years ago, back in the Windows 3/95 days, I got a call from some stock brokers in New York. They wanted to know basically how to spy on their employees.

So I sketched out a system where software would take pictures of their desktops every few seconds -- this was a long time before such software ever existed. I also sketched out several ways you could keep the software from being detected.

I never knew if they wrote the system or what happened to my design, but it never sat well with me. I always wished I could have went back and not provided them with the information.

So now I don't do that anymore.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#72
I don't really get the part with Russian nested dolls.

Was it like this?:

For example, there is a code which is encrypted three times. And that crypt-code by itself is executable which decrypts itself into another executable, and so on.

If this is true - I'm really impressed.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#73

Earlier quoted context omitted.

This kind of attitude has to stop. "Glorified phishing" might not have pizazz, but it was DAMN effective in this case. Why go to the trouble of finding, coding, exploiting an increasingly difficult target when end users will do all the work for you? This is the kind of scenario that gives security people nightmares. It takes VERY sophisticated processes and technology to find covert backdoors on your network, and ver…

Effective or not, sending some bad links to a bunch of Google employees and hoping one of them clicks is not a 'VERY sophisticated process'. It's just a good example of how users will always be the weakest link in securing a network.

Opening up a page in a web browser ought to be a safe operation. Letting that page start a plugin, or running something it downloads, or flat out using IE for an unknown link, then I'd be more inclined to blame the user.

(This is why I use Foxit for PDF reading, I don't have a PDF plugin enabled in my browser, PDFs download to disk, and similarly QuickTime, RealPlayer, WMP etc. plugins are all disabled, with only Flash enabled but controlled via FlashBlock.)

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#74

Earlier quoted context omitted.

Perhaps is was custom encryption not previously seen? I would imagine that while using encryption doesn't imply massive resources, developing custom encryption does.

I don't know a lot about security -- certainly not as much as some here (although I can follow along with their banter easily enough) But I know enough not to feel comfortable commenting on this in a public forum. (Not trying to pass a value judgment on you, just suggesting a reason you guys might not be getting an answer to your question.)

Sheesh,

I'm pretty sure the bad guys aren't going to gain much by any vagues sketches of an approach that apparently requires a whole modern state to execute... The original is specific in points...

And there are zillions of reasons for people not to reply to my post. I know I'm not always that interesting...

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#75
post #53

I'm guessing they're leaving out the "sophisticated" details of the compromise. Using encryption to hide your malware from virus scanners and using some computer "social engineering" (ssl connection) is not very sophisticated. I don't understand why it needs to be sophisticated ? because it's google ? It's known that some of the largest viruses have spread to government comuputers (sobig).

Perhaps is was custom encryption not previously seen? I would imagine that while using encryption doesn't imply massive resources, developing custom encryption does.

Packing is already fairly effective. http://polypack.eecs.umich.edu/

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#76
The sophistication and determination of this attack actually makes Google's actions more plausible.

By walking in and trying to take what it viewed as Google's most valuable assets, the Chinese state signaled that Google would never win in China. The playing field wasn't just rigged by one or another forms of low-level favoritism. The state at a fairly high level had decided it was going to 'p0wn' all the competition. So at that point, it was pretty obvious Google had nothing to lose by leaving China and perhaps even more intellectual property to lose by staying.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#77
post #69

I wonder how much smart people / money / hardware / etc you need to start an attack that sophisticated.

Really not that much. Once you find a good exploit, the payload code is copy and paste for a lot of it. The payload issue is a solved problem with lots of available source code and knowledge out there for free.

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#78
post #63

Earlier quoted context omitted.

I don't know a lot about security -- certainly not as much as some here (although I can follow along with their banter easily enough) But I know enough not to feel comfortable commenting on this in a public forum. (Not trying to pass a value judgment on you, just suggesting a reason you guys might not be getting an answer to your question.)

>But I know enough not to feel comfortable commenting on this in a public forum. why?

No clue.

I'm guilty of reading the article

“The encryption was highly successful in obfuscating the attack and avoiding common detection methods,”

One of the malicious programs opened a remote backdoor to the computer, establishing an encrypted covert channel that masqueraded as an SSL connection to avoid detection

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#79
post #66
post #12

I find the fact that the targets were source code repos very interesting. If you are a super-smart black-hat villain who wants to plan a mass global attack, what better place to start than with Google and Adobe's source code?

> what better place to start than with Google and Adobe's source code? I wonder if Microsoft was targeted too.

What's the point, when the Chinese government already has all their source code?

Re: Google Hack Attack Was Ultra Sophisticated, New Details Show

#80
post #53

I'm guessing they're leaving out the "sophisticated" details of the compromise. Using encryption to hide your malware from virus scanners and using some computer "social engineering" (ssl connection) is not very sophisticated. I don't understand why it needs to be sophisticated ? because it's google ? It's known that some of the largest viruses have spread to government comuputers (sobig).

Perhaps is was custom encryption not previously seen? I would imagine that while using encryption doesn't imply massive resources, developing custom encryption does.

There's no requirement for it to be custom. It's encryption.
Post reply on HN