Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

51–60 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#51

Earlier quoted context omitted.

It is not whataboutism. It is about 3 decades of seemingly intentional inability to deliver secure product on the mildly evil calculation that the subscriber will need 'security updates' and 'support'. There is a good argument to be made that Windows is a big target, but they should at least try not making it so easy.

> It is about 3 decades of seemingly intentional inability to deliver secure product. This is a consumer choice. You don't trust Microsoft, you don't use its services. On the government level, you ask for regulations if the situation is escalated (if necessary). But dealing with global cyberattacks is not Microsoft problem and it's not connected to one company or one service. It's an international responsibility to a…

Look, you could be right in... usual case.

But we speaking freaking NATO here !!!!! Do you attach string to hand granade and hand other side to your adversary ? And then argue that someone pulled it ??

Microsoft Windows and Microsoft Exchange is SYNONYM to "security HOLE" ! So tell me - why customer NATO _choose_ to use this ?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#52
post #38

Earlier quoted context omitted.

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

> You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies. Are you under the impression that MS doesn't spend millions on security? They're currently spending roughly $1b/year. This isn't going to be fixed by "a few pen test"

If they are spending a billion, these flaws show that obviously isn't enough.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#53

Earlier quoted context omitted.

It is not whataboutism. It is about 3 decades of seemingly intentional inability to deliver secure product on the mildly evil calculation that the subscriber will need 'security updates' and 'support'. There is a good argument to be made that Windows is a big target, but they should at least try not making it so easy.

> It is about 3 decades of seemingly intentional inability to deliver secure product. This is a consumer choice. You don't trust Microsoft, you don't use its services. On the government level, you ask for regulations if the situation is escalated (if necessary). But dealing with global cyberattacks is not Microsoft problem and it's not connected to one company or one service. It's an international responsibility to a…

Just the other day I was listening to a radio show ( further right than shown in mainstream ), where a user was clamoring for a proper locked down version of Windows where nothing can go wrong.

The current situation ( and the resulting clamoring ) is absolutely a direct result of people who create this software. Trying to shift the blame onto nonexistent framework is at best laughable and at worst very deceptive. It absolves MS and its engineers from guilt associated with it.

To put it another way, if those engineers were bridge engineers, we would now be witnessing multiple collapses with swathes of engineers arguing that it is not their fault as 'there is an international responsibility to act and establish a framework' that prevents bridges from falling apart.

I am sorry. I do not buy this defense. As an architect, you should know better.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#54
It looks like cyber warfare, as well as espionage, is considered pretty much fair game in geopolitics nowadays. I wonder where the line is drawn that would make it an act of war. In any case, a direct attack from the Chinese government towards it's main trade partners (US, Germany and Japan among them) sounds crazy to me.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#55
The amount of hot air on this topic is incredible.

The US has denounced, accused, etc Russia on cyber attacks

It is now calling out and accusing China of cyber attacks.

My guess - ZERO concrete action.

Meanwhile, China says relatively little and focuses on actual power - trade ties, threats etc.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#56

Earlier quoted context omitted.

Which is quite different from saying it is being done by the Chinese government. Read the uk ditto for comparison.

Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt? As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the…

No. It is not.

China is a big country and the Chinese government does not control everything that is going on.

Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented.

Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or Bangladeshi government for that.

Yet it is different for Russia and China.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#57

Earlier quoted context omitted.

> The solution is the same in both cases. Don't use vulnerable software. So, basically, don't use software. Actually, given the horrific state of modern software, I can get behind that.

You digress, but you're onto something here. I suspect I'm not the only one who cringes at bloated packages and sometimes rolls my own alternative.

This is sadly true. We need to return back to the Unix Philosophy of do one thing and do it well. None of these multi-purpose tools that have terrible feature creep and try to take over everything cough systemd cough. In all seriousness though, a lot of software that should be simple and easy to audit ends up having all these dependencies that are ether no longer maintained or doesn't get the necessary code reviews and it isn't until stuff like this happens that it actually comes to light.

I'm all for re-using code when rebuilding the wheel would be a hassle but it has to be balanced with proper code review before it should be included. Developers are much too quick to include outside code with the assumption that other people have already done the necessary reviews and this is where a lot of devs are getting bit.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#59
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

It's not possible to find all the bugs and they only get noticed when they fail to find one. No one recognizes all the bugs that they continually find and fix.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#60
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

I don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software.

But the "just hire a pentester and you'll never have any bugs" and "just follow some (ill-defined) 'best practices' and you'll never be hacked" attitudes are so prevalent.

Post reply on HN