Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

61–70 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#61
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries.

The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of nuclear power. Making things safe and keeping them safe while also making things easy and cheap are often in conflict. Ultimately it was split into two different agencies: One tasked with regulation and one Tasked with research and promotion.

I believe both missions of the NSA are important. However I believe it should be split into two agencies each Enthusiastically pursuing a single mission to the best of their abilities.

Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc.

Is that necessarily the best form? Probably not but it’s way better than what we have now: every time the NSA suggests changes to “make something more secure “ there is a looming specter that they are lying and are actually trying to compromise things.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#62

It looks like cyber warfare, as well as espionage, is considered pretty much fair game in geopolitics nowadays. I wonder where the line is drawn that would make it an act of war. In any case, a direct attack from the Chinese government towards it's main trade partners (US, Germany and Japan among them) sounds crazy to me.

I don't think it's crazy at all. We (i.e. the US) use our SIGINT abilities to spy on allies all the time, or at least according to numerous books and leaks. With that said, I'm not sure that the US government considers China an ally.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#63
post #2

Will someone accuse Microsoft of publishing vulnerable software?

If someone robbed your apartment would it be convenient to accuse you of low-security procedures instead of condemning the bad actors

If you brought a security door, and the thieves just had to knock on it on the right frequency to open, yes, you would accuse the door seller of fraud.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#64

Earlier quoted context omitted.

Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt? As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the…

No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…

> China is a big country and the Chinese government does not control everything that is going on.

Yeah - just look at the sheer number of cyberattacks originating from mainland China targeting CCP and state owned enterprises!

> Yet it is different for Russia and China.

It's not, it's different only for mainland China.

There are no indications Russia monitors outgoing Internet traffic nearly as closely as CCP.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#65

It looks like cyber warfare, as well as espionage, is considered pretty much fair game in geopolitics nowadays. I wonder where the line is drawn that would make it an act of war. In any case, a direct attack from the Chinese government towards it's main trade partners (US, Germany and Japan among them) sounds crazy to me.

Why? China wants to build an empire and views the US as an enemy. They will use their military and intelligence forces to achieve that, just like any other country does to achieve their respective goals.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#66

Earlier quoted context omitted.

Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt? As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the…

No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…

You're being deliberately obtuse about this. The simplest explanation for cyberattacks against high-profile targets coming out of countries like China (or the US, for that matter) isn't "rando script-kiddies having a laugh ha ha!". It's that their government intelligence forces did it.

This kind of attempted misdirection is really common from people defending/spreading propaganda for the Chinese government. It's also similar to the excuses made when business partners with heavy government influence conduct scans and do other questionable things against US infrastructure. Apparently they think westerners are all too stupid or blind to understand what's happening. It's ridiculous.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#67
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

You are hugely overestimating the level of security of software like this. There's a constant stream of vulnerability discoveries, disclosures and fixes. Those vulnerabilities don't pop into existence the week someone publicly discloses them and informs the vendor, they've been waiting there for anyone to find them for years.

If MS wanted to replace a product like this with one that has a low probability of containing any remotely exploitable vulnerabilities, they'd have to go back to the drawing board, do a full rewrite witha completely different sw development process, take a lot of time or make some major functionality compromises (or probably both).

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#68
There is so much doubt in this comment section around the validity of the accusations.

We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#69
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of…

> Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc.

I like this idea. At the same time, I think the agency - or organization, if you prefer - should look something like the National Transportation Safety Board, where incidents are investigated, reported on, and recommendations are made in a way that improves user safety. Maybe the 'National Digital Safety Board'?

Post reply on HN