Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

101–110 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#101
post #60

Earlier quoted context omitted.

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

I don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software. But the "just hire a pentester and you'll never have any bugs" and "just follow some (ill-defined) 'best practices' and you'll never be hacked" attitudes are so prevalent.

If you are not outsourcing security, then you are not taking it seriously. It is the one thing where you need to give the job to the best person.

But, we’re more likely to outsource the one thing you don’t need to outsource, like app developers.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#102
post #75

Earlier quoted context omitted.

[flagged]

Oh please. If the U.S. was so concerned about human rights violations they would stop funding Israel. Sorry dang.

It's more complicated than that. Few decisions, particularly ones regarding foreign policy, are made on single factors.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#103
post #75

Earlier quoted context omitted.

[flagged]

Oh please. If the U.S. was so concerned about human rights violations they would stop funding Israel. Sorry dang.

It's also instituted a very oppressive social credit system and runs an enormous censorship apparatus that it will be increasingly able to turn outwards in the future.

Its really about their ability to destroy Western democracy - which is already happening.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#104
post #92

Earlier quoted context omitted.

"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

Not commenting on OP, but you are talking about a single US regime. And Many countries did independently investigate, and refuse help.

From late 2002 to 2003, it was very much the international consensus that Iraq might have active WMD programs. The Security Council never authorized a war, but they did issue a unanimous resolution declaring that Iraq was in violation of its disarmament obligations and offering "a final opportunity to comply".

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#105
post #92

Earlier quoted context omitted.

"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

Not commenting on OP, but you are talking about a single US regime. And Many countries did independently investigate, and refuse help.

Actually, the US worked to fabricate evidence in collaboration with the UK too. The UK had an expert produce the so called "dodgy dossier", that was used as Blair's justification to follow the US into their illegal war. The media called it out as obvious bullshit, then the guy that produced the report allegedly committed a timely suicide.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#106

Earlier quoted context omitted.

Which is quite different from saying it is being done by the Chinese government. Read the uk ditto for comparison.

Here is the uk version: https://www.gov.uk/government/news/uk-and-allies-hold-chines... UK and allies hold Chinese state responsible for a pervasive pattern of hacking UK joins likeminded partners to confirm Chinese state-backed actors were responsible for gaining access to computer networks via Microsoft Exchange servers.

Here's the DOJ indictment

https://www.justice.gov/opa/pr/four-chinese-nationals-workin...

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#107

There is so much doubt in this comment section around the validity of the accusations. We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

I was in France when the US started the Iraq war, now I live in China. Sorry if I doubt lol, it's just impossible to trust them now. And the attacks and humiliations I faced as a French (soft ones, ofc, in the US medias) really didn't help.

So no, having a lot of countries saying China bad poopoo together is not enough anymore for me.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#108

Earlier quoted context omitted.

> The solution is the same in both cases. Don't use vulnerable software. So, basically, don't use software. Actually, given the horrific state of modern software, I can get behind that.

You digress, but you're onto something here. I suspect I'm not the only one who cringes at bloated packages and sometimes rolls my own alternative.

They're not digressing. There is no such thing as not vulnerable software. Especially if the attacker is the government of one of the most powerful nations on Earth.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#109
post #84

Earlier quoted context omitted.

The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of…

> The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. I don't know... isn't that like saying a military general has 2 conflicting missions: offense and defense? We trust military leaders with both duties, even though they could theoretically sacr…

Genuinely curious about the downvotes on this. I know political stances often trump generally reasoned arguments on HN -- is it that this thread isn't _outright_ anti NSA?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#110
post #79

Earlier quoted context omitted.

Russia and Iran do cyberattacks all the time. We have good evidence of these attacks from many sources. Same with China. The idea that these attacks are just being made up or we don't have evidence who executed them is either willfully ignorant (a google search will provide plenty of evidence) or actively malicious.

> The idea that these attacks are just being made up or we don't have evidence who executed them is either willfully ignorant (a google search will provide plenty of evidence) or actively malicious. Tools to fake such attribution and evidence were literally part of the leaked NSA/Equation Group toolkit.

and yet, we were able to accurately attribute the code released in that leak as being developed by NSA.
Post reply on HN