Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

31–40 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#31
post #20
post #9

Earlier quoted context omitted.

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

>A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. Actually most locks are susceptible to being picked (ie. a known exploit), so what you're describing is already the case, minus the lawsuits.

Locks being susceptible to lock picking actually turns into a feature when, for example, you're locked out or lose your keys: you just call a locksmith and they pick it for you.

There's no perfect security in the real world.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#32
post #9

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

Windows instead of doors would have worked just as well.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#33

Earlier quoted context omitted.

> continuing to use Insecure Brand locks wouldn't be advisable. Agreed. Microsoft should clarify how this happened and what measurements will take to prevent this incident from happening again. Still, the problem is with robbery and it should be condemned. Why changing the subject to Microsoft? I don't think whataboutism is the valid argument here.

It is not whataboutism. It is about 3 decades of seemingly intentional inability to deliver secure product on the mildly evil calculation that the subscriber will need 'security updates' and 'support'. There is a good argument to be made that Windows is a big target, but they should at least try not making it so easy.

> It is about 3 decades of seemingly intentional inability to deliver secure product.

This is a consumer choice. You don't trust Microsoft, you don't use its services. On the government level, you ask for regulations if the situation is escalated (if necessary). But dealing with global cyberattacks is not Microsoft problem and it's not connected to one company or one service. It's an international responsibility to act and establish a framework that prevents such attacks.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#34
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector.

It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies.

Digital security will never be trust unless these things are addressed in an open transparent way.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#36

The EU does not accuse the Chinese government of being behind the attacks. This is the EU press statement: https://www.consilium.europa.eu/en/press/press-releases/2021... China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory

So which key allies follow the US accusation? Is the title just wrong?

> The U.S., NATO, European Union, U.K., Australia, Canada, New Zealand and Japan

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#38
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

> You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies.

Are you under the impression that MS doesn't spend millions on security? They're currently spending roughly $1b/year. This isn't going to be fixed by "a few pen test"

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#39
post #25

Earlier quoted context omitted.

An indication that the EU does not believe the probably American intelligence assessment that these hackers operate on behalf of the Chinese government.

When the US was angry with Russia everything was suddenly Russians. Now they're being difficult at China, and suddenly China is the country doing everything wrong. That anyone still takes them seriously is to my mind an incredible miracle.

Not suggesting at all that the USA is some benign superpower, but Russia is run by a criminal gang and China by a despot and a corrupt communist party.

Note that I am a US citizen than expatriated after the second gulf war.

So I am not a fan if the US gvmt, but if you think for a second that the Chinese and Russian governments AREN'T doing the things they are accused you are naive.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#40

why impose sanctions on Russia and not China? The article implies that allies would not agree to sanctions which is fair enough, but the USA can still do something alone, no?

China will probably deny it regardless of what other countries say. Beyond that, attribution isn't made by IP addresses.
Post reply on HN