Earlier quoted context omitted.
Easy to read western propaganda and jump to conclusions without viewing the whole picture. Of course the US hack the Chinese govt. Just because china don't publish accounts of attacks does not mean attacks are not occurring. We already know Google are quite jaded towards China given their failure to succeed in the china market. Thus I take anything they comment about China with a grain of salt, given they clearly hav…
50 cent army much?
Google uncovers major account-hijacking campaign targeting senior US officials
61–70 of 89 posts
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#62Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…
I'd expect the US to be doing the exact same thing to China. I'd be surprised if they weren't.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#63Earlier quoted context omitted.
How about adding in another factor of authentication and make the passphrase a hash of data from a biometric scan (e.g. retina scan)?
Is it secret? If so, how do you change it if it gets disclosed? If not, how hard is it to make a fake eyeball? How do you know the user's actually being authenticated and it's not just a replay of a previously captured image? Do you require a trusted hardware scanner now? If so, how do you deploy it to all your users? How do you keep the attacker from taking it apart and reverse engineering it? But most of all, how d…
[Also: If a user enters , how do we know for sure that they aren't entering under duress? We'd better just scrap this whole authentication thing altogether.]
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#64Earlier quoted context omitted.
Is it secret? If so, how do you change it if it gets disclosed? If not, how hard is it to make a fake eyeball? How do you know the user's actually being authenticated and it's not just a replay of a previously captured image? Do you require a trusted hardware scanner now? If so, how do you deploy it to all your users? How do you keep the attacker from taking it apart and reverse engineering it? But most of all, how d…
Awesome. I'm so glad that you have shown me the light. I now realize that we are perfectly and 100% secure right this very moment and that the security system of using the same password everywhere (e.g. password = 'password') is working out so well for people! [Also: If a user enters , how do we know for sure that they aren't entering under duress? We'd better just scrap this whole authentication thing altogether.]
Lol. :-)
If a user enters , how do we know for sure that they aren't entering under duress?
Haven't you heard of the three factors of authentication?
Something they steal, something they chop off, and something they beat out of you...
We'd better just scrap this whole authentication thing altogether.
You can't. It's a fundamental activity, as old as the the first cell membrane (this is me, this is not me). Multicellular organisms have immune systems (which are often fooled). Babies (sometimes switched at birth) recognize their mother's voices right when they're born. Ever visit another city and people there can just tell right away you're from out-of-town?
The irony is that millions of years of evolution has given us humans so much built-in natural hardware for authentication that we're now doomed to underestimate the inherent complexity and subtlety of the problem.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#65http://contagiodump.blogspot.com/2011/02/targeted-attacks-ag...
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#66Re: Google uncovers major account-hijacking campaign targeting senior US officials
#67Earlier quoted context omitted.
Easy to read western propaganda and jump to conclusions without viewing the whole picture. Of course the US hack the Chinese govt. Just because china don't publish accounts of attacks does not mean attacks are not occurring. We already know Google are quite jaded towards China given their failure to succeed in the china market. Thus I take anything they comment about China with a grain of salt, given they clearly hav…
> An attack originating in Jinan does not necessarily mean chinese govt either. In that case, we should expect to see a vigorous Chinese investigation into this illegal activity that originated from China, right? Just like there was a comprehensive Chinese response to the well-documented cyber attacks on several American tech companies that originated from China in Dec 2009?
Tell you what, Chinese police never deal with "Internet Theft" or "online intrusion" unless a large amount money is envolved.
And why do they even bother to investigate Gmail which is constantly in-accessable in China?
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#68Is it possible for the government to establish a separate secure network? A North American network for government communication and infrastructure control use which was entirely separated from the internet would be very useful.
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#69Does it bother anyone that China continues to hack us? It is very possible that this was a government-backed attack, which wouldn't be the first against Google by the Chinese government. The biggest problem is that these don't seem to be sophisticated attacks. They didn't find a backdoor or install some malicious piece of code...they simply "hacked people" with phishing scams. I think a great place for the US govt (a…
The reason we only see the unsophisticated attacks might well be that the ones that are carried out professionally are never caught. If I was China and intent on this kind of cybercrime I wouldn't put all my eggs in one basket, but would try different avenues to get to my target. Resources don't seem to be a problem since it's apparently government backed. I would see this as the top of the iceberg, and expect there…
Like hacking SecureID? The previous attack Google discussed? The fact that just about anyone on port 22 sees half or more of their port-knocking from China? Shawn Carpenter's Titan Rain? (oh, wait, EMC now owns RSA and NetWitness ...)
Re: Google uncovers major account-hijacking campaign targeting senior US officials
#70"Review the security features offered by the Chrome browser. If you don’t already use Chrome, consider switching your browser to Chrome." Nice subtle suggestion.