Earlier quoted context omitted.
If you brought a security door, and the thieves just had to knock on it on the right frequency to open, yes, you would accuse the door seller of fraud.
Locks get picked literally all the time, and nobody sues lock makers. Perfect security does not exist.
U.S. and key allies accuse China of Microsoft Exchange cyberattacks
81–90 of 267 posts
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#82Is this damage control to distract from Israeli companies NSO and Candiru being caught running malware for despots to target journalists and activists? The timing surely is peculiar.
This is maybe the fifth time this year I've seen Israel used as an immediate deflection subject in China-related cybersecurity news posts; is that a trend anyone else has picked up on? just me?
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#83Earlier quoted context omitted.
Locks get picked literally all the time, and nobody sues lock makers. Perfect security does not exist.
Security can never be perfect. However negligence, bloat and poor design decisions are still a thing. The ideas are not mutually exclusive.
How confident are you that you could write an email server that could withstand extended attacks from nation states?
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#84> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…
The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of…
I don't know... isn't that like saying a military general has 2 conflicting missions: offense and defense? We trust military leaders with both duties, even though they could theoretically sacrifice everything to achieve victory.
> I believe both missions of the NSA are important. However I believe it should be split into two agencies each Enthusiastically pursuing a single mission to the best of their abilities.
If you split the NSA in two, wouldn't you just have two agencies working against each other? And it would essentially give the offensive agency full permission to hoard security flaws to the detriment of the nation it serves.
I think a better solution is to clearly establish the relative priorities of each mission. IMO, the NSA should always prioritize the security of the USA's (and it's allies') technological infrastructure over attacking its enemies'.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#85If they had any integrity they'd say: "I guess you got us back, huh!".
Entertaining to watch nonetheless.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#86Earlier quoted context omitted.
The solution is the same in both cases. Don't use vulnerable software. The problem starts with the same actor in both cases, Microsoft. I feel bad for the admins who are stuck with these systems.
So you think that a Linux mail server is unhackable for a state actor?
https://en.wikipedia.org/wiki/Nirvana_fallacy
https://www.cvedetails.com/product/194/Microsoft-Exchange-Se...
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#87Earlier quoted context omitted.
Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt? As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the…
No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#88Earlier quoted context omitted.
China is just the bogeyman of the hour. If it were more politically convenient to blame Russia or Iran you'd suddenly find the same evidence pointing a different way.
[flagged]
Sorry dang.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#89Earlier quoted context omitted.
Security can never be perfect. However negligence, bloat and poor design decisions are still a thing. The ideas are not mutually exclusive.
And you can confidently claim that Microsoft was negligent here? You have in depth knowledge of their architecture decisions? How confident are you that you could write an email server that could withstand extended attacks from nation states?
How would that work for something like a Boeing 737 max?
Yes, I am confident I could process text over the network without (42) remote code execution vulns.
https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
>Microsoft revealed that these vulnerabilities had existed for around 10 years
https://en.wikipedia.org/wiki/Microsoft_Exchange_Server#Vuln...
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#90Earlier quoted context omitted.
China is just the bogeyman of the hour. If it were more politically convenient to blame Russia or Iran you'd suddenly find the same evidence pointing a different way.
Russia and Iran do cyberattacks all the time. We have good evidence of these attacks from many sources. Same with China. The idea that these attacks are just being made up or we don't have evidence who executed them is either willfully ignorant (a google search will provide plenty of evidence) or actively malicious.
Tools to fake such attribution and evidence were literally part of the leaked NSA/Equation Group toolkit.