Live data from Hacker News

Airbus hit by series of cyber attacks on suppliers

france24.com

151–160 of 209 posts

Re: Airbus hit by series of cyber attacks on suppliers

#151

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

> The funny thing in all this is that passengers inherently trust the FAA

Not anymore.

Re: Airbus hit by series of cyber attacks on suppliers

#152

So, it used to be that saying anything remotely skeptical about Bitcoin was the way to get downvoted on HN. Nowadays, it seems that saying anything negative about China is how. Although, in the field of aeronautics, it is not like China is the only "state sponsor" to engage in espionage, or that this is anything new for any of the major powers.

HN / Reddit votes are very easy to manipulate with State-backed funding. Best to ignore the "consensus" on online boards and make one's own decision based on available evidence.

Please don't post insinuations about astroturfing without evidence. It poisons the well, and the overwhelming majority of such comments are based on imagination only.

https://news.ycombinator.com/newsguidelines.html

https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

Re: Airbus hit by series of cyber attacks on suppliers

#153
post #145

> "Globally recognized standards, such as ISO 27001, 27701 and 9001, can definitely ensure a baseline of security, privacy and quality assurance amid suppliers. One should, however, bear in mind that they are no silver bullet and some additional monitoring of suppliers handling critical business data is a requisite.” This is misleading. ISO standards dictate that a company should have certain processes in place. Like…

Do companies with ISO certifications ever get reviewed after-the-fact? Or do you just have to check the right checkboxes during an initial review process?

Almost every certification is a recurring income generator for the certificating parties. Some are annual, others bi-annual or even longer periods between certifications but none that I am aware of are 'forever'.

Re: Airbus hit by series of cyber attacks on suppliers

#154

So, it used to be that saying anything remotely skeptical about Bitcoin was the way to get downvoted on HN. Nowadays, it seems that saying anything negative about China is how. Although, in the field of aeronautics, it is not like China is the only "state sponsor" to engage in espionage, or that this is anything new for any of the major powers.

It's not remotely close to true that negative comments about China are "the way to get downvoted on HN". On the contrary, HN's demographic, while quite international, is almost all Western, and for better or worse it follows geopolitical trends and the leads set by government and media.

When we have to ask commenters not to take HN threads into nationalistic flamewar, it's usually because of generic nationalistic rhetoric against China. This happens often enough that we routinely get accused of being pro-Chinese. We're not, of course. We're against nationalistic flamewar, regardless of who is flaming or being flamed, because it's against HN's rules and destructive of the spirit of this site.

https://news.ycombinator.com/newsguidelines.html

Re: Airbus hit by series of cyber attacks on suppliers

#155
post #14
post #7

Out of curiosity: why is China not mentioned in the article's title, when the first sentence states a "Chinese state-sponsored hacking operation"?

It took my vouch to un-dead your comment, useful because I couldn't reply to it otherwise. I'm morbidly fascinated as to how the top two comments on this submission were marked dead in the first place, but considering it took a vouch to automatically bring it back to life, there's a hint of a Flag brigade on this thread. To answer your comment: because the title of the submission "Airbus Suppliers Hit in State-Sponso…

Please don't post insinuations of astroturfing or similar manipulation ("Flag brigade") without evidence. If you're concerned about abuse, please follow the site guidelines and email hn@ycombinator.com so we can look into it.

https://news.ycombinator.com/newsguidelines.html

Re: Airbus hit by series of cyber attacks on suppliers

#156

Earlier quoted context omitted.

What if the other guy is also innovating? What about what they plan to do next? Let's be honest here. Everyone has an incentive to gain insight into what everyone else is doing. Everyone is spying on everyone else.

So do you think DEC was spying on Intel during the Alpha days? Whatever they could’ve learned wouldn’t be worth the effort.

[deleted]

Re: Airbus hit by series of cyber attacks on suppliers

#157

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

Russia has expertise building airliners. Wonder why manufacturers never took to producing there for cheap labor? My guess is China leveraged their market potential to entice cos to take some of their mfg to China.

Re: Airbus hit by series of cyber attacks on suppliers

#158
post #157

Other comments here incorrectly pointing out that Boeing and Airbus don't manufacture in China - they do. And why wouldn't they, it's obviously much cheaper to manufacture there given material and labor costs. Obviously they don't manufacture highly sensitive military aircraft in China, but commercial aircraft, sure why not. What they don't do is the design, testing, and certification in China. This is the real IP -…

Russia has expertise building airliners. Wonder why manufacturers never took to producing there for cheap labor? My guess is China leveraged their market potential to entice cos to take some of their mfg to China.

Russian industry was taken over by the mafia. That is much less tenable than the situation with China.

Re: Airbus hit by series of cyber attacks on suppliers

#159

Earlier quoted context omitted.

I know the Chinese government has made a concerted effort to steal IP. Still I also find the descriptions of Chinese culture, and Asian culture in general, that demean it as imitative and incapable of creative thought not as rational descriptions of the world, but instead bizarre holdovers of old racist ideologies repackaged in more palatable contemporary business-lingo.

What other Asian countries in the present day are frequently accused of stealing IP? I don't get how you're arriving at it being a broadly Asian thing, when it's quite specifically a Chinese phenomenon. Conflating China to mean "all Asians" is pretty racist in and of itself.

There are broad stereotypes about Asians and conformity that are at play in the parent comments assumptions about what China’s weaknesses are

Re: Airbus hit by series of cyber attacks on suppliers

#160
post #76

How does one know that a particular attack is "state-sponsored" or originates from a particular country? Exactly what does it mean to be "state-sponsored"? And who provides this analysis?

Without talking about the controversial technical indicators of a state sponsored attack, you can figure it out based on the motive, complexity of the attack, and who is being targeted.

Criminal attacks have a profit related motive, which can be distilled down into "if we spend $X dollars trying to hack Y, we can probably get a payoff of $Z"

If an attack is extremely expensive and has very little potential payoff, you can be pretty sure it's not being done by a criminal organization.

You may wonder "how do you prove it's not being done by not-profit motivated hacktivists?". Hacktivist groups usually have limited resources (that doesn't mean they're not dangerous!). If scale of the attack/payload suggests a team of 10-30 skilled professionals working full time for a year or so, it's probably not a hacktivist group. Hacktivist groups also tend to proudly announce responsibility whenever they pull off successful attacks.

Post reply on HN