Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

41–50 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#41
post #2

Will someone accuse Microsoft of publishing vulnerable software?

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

I get your metaphor but I don't think it meets the situation. If you were paying a security guard to watch your apartment and they instead went to guard some other place for additional money for 2 hours and then your apartment got robbed, well, that security guard is Microsoft in this example.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#42
post #9

Earlier quoted context omitted.

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

A better analogy would be, if you were a company selling doors - after a string of break-ins involving some group casually walking through your products like they weren't there, somebody would eventually start asking about your responsibility. (Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the dri…

Cyber Insurance is a huge growing sector in Toronto at least, and I worked on strategy for a "startup" in the space last summer.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#43
post #26

The EU does not accuse the Chinese government of being behind the attacks. This is the EU press statement: https://www.consilium.europa.eu/en/press/press-releases/2021... China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory

Apparently you haven't read it at all These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

Which is quite different from saying it is being done by the Chinese government.

Read the uk ditto for comparison.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#44
post #4

Earlier quoted context omitted.

The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.

So you think that a Linux mail server is unhackable for a state actor?

Lol. Love it. Don't use Microsoft, instead become an expert in cisco OS and Linux and don't spend ay time generating anything of economic value but instead spend all your time securing your infrastructure and doing pen tests.

(yes, if you are expert open source is easier top secure maybe, at least that was my experience 20+ years ago. Now I mostly pay companies like microsoft to host my stuff so I can do billable shit).

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#45
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

How do you know they're not doing exactly that? For every 1 vulnerability that gets disclosed, we have no clue how many potential vulnerabilities were caught by security testing or practices. The entire nature of security is that it's impossible to have literally 0 vulnerabilities.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#47

why impose sanctions on Russia and not China? The article implies that allies would not agree to sanctions which is fair enough, but the USA can still do something alone, no?

Useually they get some of the hackers tools / code and analyse that to discover the origin. They look for strings in a foreign language but mostly the grammer of the language is used as hackers will often write comments in a foreign language to try and make it difficult to originate.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#48

why impose sanctions on Russia and not China? The article implies that allies would not agree to sanctions which is fair enough, but the USA can still do something alone, no?

Didn't vault 7 revealed the NSA had tooling to make hacks look like Russian and Chinese hacks Umbrage and the marble framework. Wouldn't be surprised they will use these hacking threats to create a western great fire wall. Pompeo already talked about it with the Clean network Initiative.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#49
post #26

Earlier quoted context omitted.

Apparently you haven't read it at all These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

Which is quite different from saying it is being done by the Chinese government. Read the uk ditto for comparison.

Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt?

As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the same feeling of freedom, do they?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#50
post #26

Earlier quoted context omitted.

Apparently you haven't read it at all These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

Which is quite different from saying it is being done by the Chinese government. Read the uk ditto for comparison.

Here is the uk version:

https://www.gov.uk/government/news/uk-and-allies-hold-chines...

UK and allies hold Chinese state responsible for a pervasive pattern of hacking

UK joins likeminded partners to confirm Chinese state-backed actors were responsible for gaining access to computer networks via Microsoft Exchange servers.

Post reply on HN