Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

41–50 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#41

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

Easy to read western propaganda and jump to conclusions without viewing the whole picture.

Of course the US hack the Chinese govt. Just because china don't publish accounts of attacks does not mean attacks are not occurring.

We already know Google are quite jaded towards China given their failure to succeed in the china market. Thus I take anything they comment about China with a grain of salt, given they clearly have an agenda.

An attack originating in Jinan does not necessarily mean chinese govt either. Given China's opaqueness on cyber issues, anyone wanting to hack anyone else could use china as a place to do it.

Though I agree, governments should invest in educating people on phishing scams.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#42
post #28

Earlier quoted context omitted.

How about 2-factor authentication, as discussed in the article?

SMS is not global and is quite expensive to get started with. Only the major players like Google can roll out worldwide SMS authentication. Email is out of the question because it often takes several minutes to receive an email (due to POP-fetching intervals etc)

Google supports HOTP-based codes that can be generated by a mobile application or even a local bookmarklet. They also support printed one-time codes.

Here's the open source project for the mobile app and PAM module: http://code.google.com/p/google-authenticator/

(Disclaimer: I worked on this.)

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#43
post #28

Earlier quoted context omitted.

How about 2-factor authentication, as discussed in the article?

SMS is not global and is quite expensive to get started with. Only the major players like Google can roll out worldwide SMS authentication. Email is out of the question because it often takes several minutes to receive an email (due to POP-fetching intervals etc)

You don't need to have data access to use Google's two-factor authentication.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#44
post #16

Earlier quoted context omitted.

Except those crypto-card thingies (not the implantable ones) were duplicated as a result of the recent RSA breakin, which is how Lockheed was attacked.

Yeah, I really don't understand how that happened.

The working theory is that RSA retained information on the crypto "seeds" used to initialize the hardware tokens at the factory. When this database was hacked the attackers obtained a copy of this seed material. This was enough to duplicate the code sequence displayed on the key, though possibly in conjunction with a phishing or social engineering attack to obtain the target user's serial number (or a few current codes).

That's the theory anyway. Not everyone agrees that it's the Chinese-attacking-US-defense-contractors story again.

What everyone does agree on though is that RSA is withholding critical information about the severity of the compromise, or maybe even being a little disingenuous about it.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#45
post #41

Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…

Easy to read western propaganda and jump to conclusions without viewing the whole picture. Of course the US hack the Chinese govt. Just because china don't publish accounts of attacks does not mean attacks are not occurring. We already know Google are quite jaded towards China given their failure to succeed in the china market. Thus I take anything they comment about China with a grain of salt, given they clearly hav…

50 cent army much?

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#46
post #37
post #29

Earlier quoted context omitted.

Wrong. A law from 1986 that is being heavily abused ala Patriot Act, allows government to read your email and any other stored data online that is more than 180 days old without any judicial review (aka warrant). This is fact, not speculation. To be fair it's not just gmail but yahoo, etc.

Are you referring to the law nicked named the Clinton computer law? Read it again, any viewing of data on a computer requires notifying accused 180 days after the data view, no exceptions. As I understand it, the Patriot act replaces that requirement.

The ironically named 1986 Electronic Communications Privacy Act

http://www.nytimes.com/2011/01/10/technology/10privacy.html

the government does not notify people that they are searching their online information or prove probable cause, and if the government violates the law in obtaining information, defendants are generally unable to exclude that evidence

http://www.wired.com/threatlevel/2010/03/google-microsoft-ec...

http://www.wired.com/threatlevel/2011/05/cloud-content-warra...

Since the "Patriot" Act was renewed without discussion or change, there is little hope IMHO that the 1986 law will be changed (except maybe make it worse).

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#47
post #40

Earlier quoted context omitted.

do you know where he dismissed it? the article at http://www.schneier.com/essay-306.html is still up, with no disclaimer or obvious link to a correction.

A week or two later on his blog: http://www.schneier.com/blog/archives/2010/02/more_details_o... "The rumor that China used a system Google put in place to enable lawful intercepts, which I used as a news hook for this essay, has not been confirmed. At this point, I doubt that it's true."

thanks. i didn't know that. given how famous the other essay is, he should really update it...

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#48
post #24
post #18

Earlier quoted context omitted.

I agree that public key authentication is an improvement over passwords. Now show me a system that my mother-in-law can use (passphrases are out, she can't remember them).

How about adding in another factor of authentication and make the passphrase a hash of data from a biometric scan (e.g. retina scan)?

Is it secret? If so, how do you change it if it gets disclosed? If not, how hard is it to make a fake eyeball?

How do you know the user's actually being authenticated and it's not just a replay of a previously captured image? Do you require a trusted hardware scanner now? If so, how do you deploy it to all your users? How do you keep the attacker from taking it apart and reverse engineering it?

But most of all, how do you know the user is actually intending to authenticate the thing that is being authenticated? E.g. the user is wants to open door A so they put their eyeball up to the scanner, but the bad guy has installed a skimmer (like on ATMs) which replays the users retina and lets him into door B.

Biometrics usually raise more questions than answers IMHO.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#49
post #41

Earlier quoted context omitted.

Easy to read western propaganda and jump to conclusions without viewing the whole picture. Of course the US hack the Chinese govt. Just because china don't publish accounts of attacks does not mean attacks are not occurring. We already know Google are quite jaded towards China given their failure to succeed in the china market. Thus I take anything they comment about China with a grain of salt, given they clearly hav…

50 cent army much?

Looks like it. 1 comment (the grandparent), account created 69 days ago, shilling for the Chinese government.

For those who don't get the reference, here's an article that explains it: http://www.guardian.co.uk/media/2008/sep/22/chinathemedia.ma...

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#50
post #30

Earlier quoted context omitted.

Yeah, it bothers someone: http://www.bbc.co.uk/news/world-us-canada-13614125 Just today it is widely reported the Pentagon is setting a new policy that cyber attacks can be considered acts of war which lets the Pentagon retaliate with conventional weapons. Hack my email, get an ICBM.

I saw this a few days ago. I believe that if another country hacked the US and took top secret data, it could potentially cause as much damage as a conventional weapon. So, using conventional weapons in retaliation for cyber-attacks doesn't seem that far fetched. We are definitely in an interesting time with regards to technology and policy. Both exciting and scary.

I would not be surprised if the United States got a specialized "Cyber Force" branch of the military sooner rather than later to go along with Army, Navy, and Air. There are apparently already papers about it like this one from 2008:

PDF: http://www.albanylawjournal.org/articles/solce_0609.pdf

Abstract: https://litigation-essentials.lexisnexis.com/webcd/app?actio...

Granted, that niche is somewhat filled by the NSA, but it is not a branch of the military per se. And increasingly cyberspace will be as important or more so than land, sea, and air.

The problem is any formal "Cyber Force" announcement will kick off the 21st Century arms race. But forming a Cyber Force in secret will severely limit effectiveness. I think we're about at the tipping point when the United States sees a hacker battalion here and there as not enough. It needs strong hacker branch.

Post reply on HN