Earlier quoted context omitted.
> to not share as much information as possible with as many researchers as possible in order to help as many as people as possible. this presumes that the stolen information would be used 'to help as many people as possible'.. Also, 1st country with viable vaccine/treatment/etc will have a huge geopolitical bargaining chip & it will likely be used as such no matter the country of origin.
...huge geopolitical bargaining chip... Ummm, I'm not sure how to break it to you, but USA is already laughingstock of world due to our comically misguided reaction to the "pandemic". Everyone expected Trump to screw up (and he hasn't disappointed), but there isn't any person or institution in USA that hasn't totally whiffed on this. CDC mandated tests that didn't work, news media remained unconvinced until late in t…
The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
161–170 of 262 posts
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#162Some of the comments here discuss how an attacker could tamper with data. What are some good ways for a scientist to ensure the integrity of their data in this case? Post it online with a hash, particularly in a way that will get archived by others? Keep off-site backups?
Here's an idea for how this could work for an example given elsewhere in the thread about the risk of an attacker mislabelling the subjects so the outcomes are unclear or deliberately skewed.
For a binary double-blind placebo trial (one group gets the medication, another gets the placebo), compute the hmac of each subject identifier (name, some participant ID), keyed with a key known to the principal investigator. Everyone whose hash MSB is above 0x80 gets the treatment, and everyone whose hash is below 0x80 gets the placebo. If you need more experimental groups, adjust the thresholds as needed
Clearly this is very restrictive and limited (you might need to ensure a proper demographic and medical/age profile distribution of subjects between both groups), but there are likely ways to achieve this by creating multiple "groups" and doing this process within each demographic balanced group.
You'd get a reproducible outcome, as long as you can recover the patient names or participant ID numbers, and the PI or experimental lead takes careful note of the hmac key used.
Just a straw man idea for how at least the patient to group allocation could be done deterministically. If someone attacked this and muddled patients and groups around, it could be reproduced just from knowing who the subjects are, and the hmac key. Clearly this doesn't scale to results or beyond, but I imagine this is where digital signatures start to help. And with modern ed25519 signatures we aren't talking massive signatures either.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#163Earlier quoted context omitted.
I mean, I'm not trying to say "china always good, USA always bad", either. I'm just trying to add some perspective. If I were to take that on as some sort of debate challenge, I'd point out the mass incarceration and the fact that we still have a bigger chunk of people in jail despite being so much freer. Of course, that's a bit of a rhetorical gambit. As far as the characterization of china, it depends. Han Chinese…
> Han Chinese don't go to prison just for criticizing the government, they just lose opportunities. This is verifiably false. Han vine Chinese book store owners in Hong Kong were kidnapped to mainland China, incarcerated and forced to sign confessions. Their ‘crime’ was selling books critical of the CCP.
HK was more of a hot situation, you had protestors waving UK flags and talking about independence. I'm not justifying anything, but that's exactly the 'credible threat' vs 'talking shit' distinction I was talking anout.
In the cases you're referencing, are they still locked up? I'll check out a link if you've got one.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#164If you’re doing research of any significance in today’s world and don’t have an active security program looking for harmful actions by foreign intelligence your organization opens itself up for all sorts of nasty liabilities. You don’t even have to have an electronic intrusion. The PRC’s government also pays people off as the case of this former Cleveland Clinic researcher shows: https://www.cleveland.com/crime/2020/…
I'm not sure I agree that it's the responsibility of the people doing research to protect against foreign nation state attacks (whether cyber or legacy intelligence). 1st: most people outside of government don't know how much they are expected/"required" to do to protect their work against foreign nation states. Except for heavily regulated sectors (government, military, heavy industry, banking, core telecom, and mor…
This is very true, sadly. It ought not to be, but level of practical cyber abilities seems sorely lacking. I see lots of "governance" style cyber, but not a lot of "deep technical expertise being allowed to develop defences".
University research lab type environments deserve a special call-out though for being near-impossible to defend. Most of the time these are "defended" by pooled central IT staff without specific awareness of the significance of the systems or threats faced. University networks are also notoriously open, and even in lab environments, they're often connected directly to the internet or campus network (airgapped computers for internet access are less convenient and someone would have to pay for them, and nobody wants to). Let's not even go into the various shadow IT remote access systems in use, which circumvent the institution firewall to let them get work done from home in the evenings...
University lab environments are an incredibly tough target to secure. And the researchers will find ever more ingenious workarounds to security measures that they find getting in the way of their work.
> Except for heavily regulated sectors (government, military, heavy industry, banking, core telecom, and more recently elections) very few companies will actually get help from 3-letter-agencies to actively protect against foreign nation state attacks.
Even some of these sectors sorely lack ability in cyber, at least in some very developed and otherwise capable countries. There is still a very real barrier between 3 letter agencies, and the industries you mentioned that need this help. Information sharing is often too little too late, or not specific enough to be actioned.
That said, I do think cyber security needs to be a bigger priority in all sectors, but nobody wants to pay for it, and as long as there's no routine cost to business, I don't see that changing. Not while traditional "value for money" metrics are used to measure and compare options - it's very hard for those reviewing tenders or proposalsto see and differentiate between good security and some "military grade, unbreakable, quantum sprinkles" snake-oil security that has SQL injections everywhere.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#165Given today's anti-free-thinker HN climate I'm probably going to get downvoted to oblivion for saying this, but I feel I need to say it. I don't think COVID-19 research should be secretive, I think it should be a global effort, and I'm perfectly happy with the idea of any nation having open access to all COVID-19 research, vaccines, results, and (anonymized) data. There should NOT be a concept of intellectual propert…
> Given today's anti-free-thinker HN climate You should champion China to be more transparent about the origins of the virus. Even if it did not originate in a lab, shining more light on its origins will help prevent future outbreaks. China also actively prevented Taiwan from joining the WHO. This would have resulted in more free flow of information. Curiously, I was a labelled a racist for making this statement. > P…
What China does or doesn't do has no bearing on this.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#166Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#167Earlier quoted context omitted.
While the admin is currently pushing a very negative image against China, I do not believe the FBI would do that so lightly.
Why would the FBI be hesitant about faking/sensationalizing this? It's nearly impossible to prove, China's unlikely to make an issue out of it, and even if the lie got exposed what punishment would they face?
There are papers out there that have multiple ways of using language to identify specific authors, determine multiple authors, and even decode unknown language. That's my first shallow example and would be a pretty reliable indicator if you could get your hands on their code. With a budget of millions of dollar I'm sure they have dozens of ways that can be combined. It would make no sense to reveal every single method they use to defend against people on the internet. That also assumes they don't just have a mole who told them about it, which they also wouldn't reveal.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#168Earlier quoted context omitted.
The problem is that this administration has shown time and again that they're willing to corrupt American institutions (like the FBI) when it suits them.
"this administration"? As if it's a new problem?
Firing inspector generals en masse [1], personally attacking specific FBI agents and their families [2], intervening in the criminal proceedings of friends and political allies [3], etc. is a pattern of behavior that undermines the rule of law in this country. It's a comprehensive strategy to weed out anyone who disagrees with you, hurts your feelings, dares second guess you, or, god forbid, didn't vote for you.
This pattern of comprehensive corruption is unique to this administration.
There are _literally_ dozens of links I could provide for each point since these behaviors happen constantly, but I just google'd and picked one each.
[1] https://www.washingtonpost.com/politics/as-trump-removes-fed...
[2] https://www.vanityfair.com/news/2020/02/donald-trump-nemesis...
[3] https://www.politico.com/news/2020/02/25/judge-rebukes-trump...
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#169Earlier quoted context omitted.
Imagine a state actor hitting the contract research organization in charge of the last phase of a clinical trial for a blood pressure medication and changing data. Due to the nature of double blind trials, catching these modifications can become really hard to catch and could lead to a lot of human suffering.
If they target a CRO the sponsor still has the original data from the trial sites. I can say that at least for the company (one of the 10 largest pharmaceutical companies) I work for this would almost be impossible to not be caught.
I get the point the parent comment was trying to make, but yeah, bad example.
Re: The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
#170Earlier quoted context omitted.
The power grid I don't know, but gaz pipeline apparently they did. See for instance https://en.m.wikipedia.org/wiki/At_the_Abyss
Yeah and we also dropped potato beetles via parachutes over crops across Warsaw Pact countries https://en.wikipedia.org/wiki/War_against_the_potato_beetle
"Communist propaganda of the time claimed that the insect was being dropped from parachutes and balloons"