Live data from Hacker News

China hacked a Navy contractor and secured sensitive data on submarine warfare

washingtonpost.com

41–46 of 46 posts

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#41

Earlier quoted context omitted.

> So it's pretty obvious by now that we are actively at war with China and Russia on the cyber front. We are actively fighting a cyber war with every country. The nations who we spy on the most are our allies. And the nations who spy on us the most are our allies. I know it's counterintuitive but it's international politics, geopolitics and intelligence 101. For example, israel, Britain, Canada, germany, japan, south…

Citations needed. I know some intelligence people. This isn't what they tell me. They tell me that western governments are obsessed with following the law and limiting what their cyber operations touch. It's born out by what I understand from non-classified sources. For example, I read through the source code of Stuxnet when it first came out. There was a ton of guards put in to limit the potential damage it made. Th…

Just because the microcosm that your contacts happen to see within our compartmentalized and super secret intelligence agencies happens to (supposedly, through two levels of rumor) be on the up and up, doesn't make that a rule for these organizations.

In fact, most everything published besides your testimony suggests the opposite.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#42
post #3

> The data stolen was of a highly sensitive nature despite being housed on the contractor’s unclassified network. Former government contractor here: Dumbasses need to keep their sensitive data air gapped and inside a SCIF. If you need to network stuff, there are ways for contractors to implement NSA-approved "type 1" crypto with the appropriate personnel and infrastructure. Also, I think whoever improperly classified…

The article states clearly that this was Controlled Unclassified Information. Massive volumes of industrial data fit this description. It does call for special protections, which are outlined in NIST SP 800-171. Nowhere in this document does it imply that CUI data should be kept in a SCIF.

From the article, Cmdr. Bill Speaks, a Navy spokesman, said, “There are measures in place that require companies to notify the government when a ‘cyber incident’ has occurred that has actual or potential adverse effects on their networks that contain controlled unclassified information.”

This does not indicate the data was or was not classified. Now, at the beginning of the article, "The data stolen was of a highly sensitive nature despite being housed on the contractor’s unclassified network. The officials said the material, when aggregated, could be considered classified, a fact that raises concerns about the Navy’s ability to oversee contractors tasked with developing ­cutting-edge weapons."

The article suggest the data, in aggregated form, could be viewed as classified. I am quite sure not all the details have been made public nor will they be for some time. I am sure it will take many years for that true nature of the breach to enter public domain. Submarines are the US primary means of nuclear deterrence and any breach to limit that deterrence might be considered harmful.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#43

Earlier quoted context omitted.

There's stupid and then there's "stupid" putting my tinfoil hat on here: maybe they were allowed to steal the data. I mean really? Oh WOOOPS we stored 613 GB of classified data on an unsecured network in the EXACT place hackers would look... aww that sucks, welp we'll try to do better next time. I call BS, this level of incompetence smells more like treason disguised as stupidity.

A true believer would say the point was to suggest intentionally bad technology (e.g. screen doors!), to retard progress in Chinese submarine design...

Good point, there's always free cheese in a mouse trap.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#44
post #33

Earlier quoted context omitted.

So it's not like you're going to take the F-35 and move it over to another contractor. More likely, you'll just cancel it and start gain. The other aspect is that it's not really the contractor's fault if the exploit was done with a zero-day.

Wow I really disagree with that. 0-days are a fact of life. If billions of dollars aren't enough to set up a secure supply chain and air gaps, what would be?

You conflate the way the world is with the world you wish it would be.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#45

Earlier quoted context omitted.

Citations needed. I know some intelligence people. This isn't what they tell me. They tell me that western governments are obsessed with following the law and limiting what their cyber operations touch. It's born out by what I understand from non-classified sources. For example, I read through the source code of Stuxnet when it first came out. There was a ton of guards put in to limit the potential damage it made. Th…

Just because the microcosm that your contacts happen to see within our compartmentalized and super secret intelligence agencies happens to (supposedly, through two levels of rumor) be on the up and up, doesn't make that a rule for these organizations. In fact, most everything published besides your testimony suggests the opposite.

Just saw this.

I'm happy to change my view when I encounter new evidence, but I see absolutely no evidence that the Canadians (or anyone else outside of Russia / China) have hacked the shit out of the entire USA.

Re: China hacked a Navy contractor and secured sensitive data on submarine warfare

#46
post #44

Earlier quoted context omitted.

Wow I really disagree with that. 0-days are a fact of life. If billions of dollars aren't enough to set up a secure supply chain and air gaps, what would be?

You conflate the way the world is with the world you wish it would be.

No, I wish we didn't spend trillions of dollars on killing machines for no reason. It's pretty difficult to confuse that world with this one.

Your magical phrase "zero-day" doesn't "win this argument" for you... You're imagining some Stuxnet-level pyramid of remote BIOS and NIC firmware hacks when we all know this was just a poorly configured firewall. That's why "TOP SECRET" exists, CYA.

Post reply on HN