Live data from Hacker News

China hacked a Navy contractor and secured sensitive data on submarine warfare

washingtonpost.com

31–40 of 46 posts

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#31
post #4

Why doesn't the US do something about that? China almost seems overt about stealing secrets like that.

What if they let themselves be hacked, for fake/misleading data to be stolen?

It's good not to let yourself be hacked. It's better to let your enemies think you can be hacked.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#32
I blame the classifiers in this one. The data should have been classified from the start.

The key words in the article were:

> The officials said the material, when aggregated, could be considered classified

So, the problem is that the material was probably designated as FOUO, but should have been classified as secret.

The difference is that FOUO is okay to be left on desks and the like, but confidential and above needs a safe, and document control.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#33
post #3

> The data stolen was of a highly sensitive nature despite being housed on the contractor’s unclassified network. Former government contractor here: Dumbasses need to keep their sensitive data air gapped and inside a SCIF. If you need to network stuff, there are ways for contractors to implement NSA-approved "type 1" crypto with the appropriate personnel and infrastructure. Also, I think whoever improperly classified…

Are there penalties written into contracts to address failures like this? ISTR when China got loads of F-35 data, Lockheed was "punished" by getting to spend another year and hundreds of millions more dollars "fixing" the plane.

So it's not like you're going to take the F-35 and move it over to another contractor. More likely, you'll just cancel it and start gain.

The other aspect is that it's not really the contractor's fault if the exploit was done with a zero-day.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#35
post #17

The US nuclear triad currently rests dangerously on the US Ohio-class submarines. If the Chinese military develops technology that can eliminate these subs in a surprise attack, they would potentially have the ability to take over the world. Step 1. Target the 1950s era US ICBM fleet in their static bunkers. This only requires making the POTUS hesitate for ~7 minutes to "use or lose" them. Step 2. Destroy the few doz…

Everything you say is true, but extremely misleading. China's nuclear posture uses what's called the "minimum means of reprisal", which means they have an extremely small nuclear force that is incapable of completing the scenario you outline. Let me just quote the abstract from Jeffery Lewis's phd dissertation on the topic: Among the 5 states authorized under the NPT to possess nuclear weapons, China has the most res…

Nothing has changed in 14 years with China's nuclear arsenal?

Based on what evidence?

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#36
post #35

Earlier quoted context omitted.

Everything you say is true, but extremely misleading. China's nuclear posture uses what's called the "minimum means of reprisal", which means they have an extremely small nuclear force that is incapable of completing the scenario you outline. Let me just quote the abstract from Jeffery Lewis's phd dissertation on the topic: Among the 5 states authorized under the NPT to possess nuclear weapons, China has the most res…

Nothing has changed in 14 years with China's nuclear arsenal? Based on what evidence?

There have been no substantive changes, but of course there have been minor changes. If you're actually interested in learning more, there's a lot of open source information available. Lewis's blog http://armscontrolwonk.com is a great starting point, but covers a much greater scope.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#37

Earlier quoted context omitted.

There's stupid and then there's "stupid" putting my tinfoil hat on here: maybe they were allowed to steal the data. I mean really? Oh WOOOPS we stored 613 GB of classified data on an unsecured network in the EXACT place hackers would look... aww that sucks, welp we'll try to do better next time. I call BS, this level of incompetence smells more like treason disguised as stupidity.

A true believer would say the point was to suggest intentionally bad technology (e.g. screen doors!), to retard progress in Chinese submarine design...

Forcing China to waste their spook manpower sifting through half a TB of crap data would also be quite funny.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#38
post #33

Earlier quoted context omitted.

Are there penalties written into contracts to address failures like this? ISTR when China got loads of F-35 data, Lockheed was "punished" by getting to spend another year and hundreds of millions more dollars "fixing" the plane.

So it's not like you're going to take the F-35 and move it over to another contractor. More likely, you'll just cancel it and start gain. The other aspect is that it's not really the contractor's fault if the exploit was done with a zero-day.

Wow I really disagree with that. 0-days are a fact of life. If billions of dollars aren't enough to set up a secure supply chain and air gaps, what would be?

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#39

Earlier quoted context omitted.

> So it's pretty obvious by now that we are actively at war with China and Russia on the cyber front. We are actively fighting a cyber war with every country. The nations who we spy on the most are our allies. And the nations who spy on us the most are our allies. I know it's counterintuitive but it's international politics, geopolitics and intelligence 101. For example, israel, Britain, Canada, germany, japan, south…

Citations needed. I know some intelligence people. This isn't what they tell me. They tell me that western governments are obsessed with following the law and limiting what their cyber operations touch. It's born out by what I understand from non-classified sources. For example, I read through the source code of Stuxnet when it first came out. There was a ton of guards put in to limit the potential damage it made. Th…

If Stuxnet being limited to interfering with its intended target is your example of how Western intelligence is over concerned with limits to their operations’ scope, I think you hold our services to a very low standard, both ethically and practically. Would it have been responsible, or in the nation’s best interests, to allow Stuxnet to play with any industrial equipment it found itself on? And further, would such a blatant infection have half a chance of hitting its actual objectives?

You also seem to assume that, however badly the Russians have us over a barrel through infected infrastructure, that we haven’t gotten into their stuff just as badly, or worse. All the regulations that U.S. spooks complain about aren’t a problem once you’re on foreign soil working on foreign targets. Cyberwarfare favors the attacker, just because we’re very vulnerable isn’t a reason to believe we don’t have the upper hand.

(And as noted, the U.S.’s budget for this stuff is way greater than our opponents’. If we’re not decisively on top something is seriously wrong.)

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#40
post #17

The US nuclear triad currently rests dangerously on the US Ohio-class submarines. If the Chinese military develops technology that can eliminate these subs in a surprise attack, they would potentially have the ability to take over the world. Step 1. Target the 1950s era US ICBM fleet in their static bunkers. This only requires making the POTUS hesitate for ~7 minutes to "use or lose" them. Step 2. Destroy the few doz…

> Hopefully the US military will be able to upgrade the nuclear triad in time to maintain MAD and eliminate this potential threat.

I consider MAD to be a greater threat. We are talking about extinguishing all human life.

Some reference material:

https://www.goodreads.com/book/show/16884.The_Making_of_the_...

https://www.goodreads.com/book/show/6452798-command-and-cont...

Just recently published: https://www.goodreads.com/book/show/25663779-the-doomsday-ma...

> But I think the best solution would be for the entire G7 to develop independent MAD systems so there's never any doubt that it remains in effect.

Comprehensive MAD would be a wonderful thing, if you had utter certainty that the chance for accidental launch was zero. If the chance is nonzero, you've put a time limit on civilization. How long? A hundred years? Three hundred?

You refer derisively to "1950s-era" technology. And you have a point. I'm agreeing with that point, and using it to make the case for a real chance of accidental nuclear war based on flawed or worn-out technology.

The third book in the list above goes into stark detail about the other danger - that of nuclear war based on flawed human decision-making.

Post reply on HN