Earlier quoted context omitted.
> Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc. I like this idea…
Or they should stop stealing tax payers money and dissolve these agencies. The one thing they are good at is digging deeper and deeper the debt account, for virtually no benefit, and surely nuisance and worries.
U.S. and key allies accuse China of Microsoft Exchange cyberattacks
141–150 of 267 posts
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#142Earlier quoted context omitted.
No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…
You're being deliberately obtuse about this. The simplest explanation for cyberattacks against high-profile targets coming out of countries like China (or the US, for that matter) isn't "rando script-kiddies having a laugh ha ha!". It's that their government intelligence forces did it. This kind of attempted misdirection is really common from people defending/spreading propaganda for the Chinese government. It's also…
Some had certain variables hardcoded, e.g. Administrator user's name and their exploits worked with higher success rate in anglosphere, but failed in localized environments. Others had more advanced exploits which queried parameters instead of assuming them - those where more successful around the globe.
Another nuance missing from popular press is that most groups in China (and Russia) are operating independently, but share tradecraft among them and occasionally engage with politicized missions (either working on explicit orders from government handlers or simply defending their beliefs hacktivist-style). This is what FireEye means by "affiliation with Chinese government", NOT "operates strictly on government orders".
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#143There is so much doubt in this comment section around the validity of the accusations. We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.
"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#144Earlier quoted context omitted.
Not commenting on OP, but you are talking about a single US regime. And Many countries did independently investigate, and refuse help.
Actually, the US worked to fabricate evidence in collaboration with the UK too. The UK had an expert produce the so called "dodgy dossier", that was used as Blair's justification to follow the US into their illegal war. The media called it out as obvious bullshit, then the guy that produced the report allegedly committed a timely suicide.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#145That's a pretty heavy diplomatic change. Especially the inclusion of NATO.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#146Earlier quoted context omitted.
No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…
Chinese citizens cannot even mention recent historical events on in private messages on the internet without approval from the government, and you're trying to tell us that some "kids with computers" were able to carry out a sophisticated years-long cyberattack? "Kids with computers" might be plausible in a free country, but not in China.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#147Earlier quoted context omitted.
Whether the Chinese government has control over these APTs, the crime originated on Chinese soil, and it's their responsibility to deal with these threats. What's so hard for you to understand?
I don't think this makes much sense. We don't even know if the APTs actually do operate on Chinese soil, much less that the Chinese government condones them. All we know is that they used Chinese IPs at some point and Chinese configured computers, and that they went after military targets. And we don't even know that these are the same APTs.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#148Earlier quoted context omitted.
and yet, we were able to accurately attribute the code released in that leak as being developed by NSA.
We know it was the NSA because of leaked NSA documents that admitted to the affiliation. Not from the tools themselves.
I had only previously heard [0] that similarities in the tools were discovered by Kaspersky, not that there were any leaked docs that pointed the finger back at NSA themselves. Are you maybe thinking of PRISM/Wikileaks?
[0] - https://arstechnica.com/information-technology/2015/02/how-o...
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#149Earlier quoted context omitted.
"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.
I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion? As an aside, I'm not sure what's more frustrating: Witnessing the Bush administration circa 2001-2004 be called out on these lies, by numerous entities, and still march inexorably toward armed conflict, or... having to witness these lies being u…
You realize that this wasn't the first time the US did this, so I feel we should question these claims as much as possible.
Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks
#150Earlier quoted context omitted.
"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.
I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion? As an aside, I'm not sure what's more frustrating: Witnessing the Bush administration circa 2001-2004 be called out on these lies, by numerous entities, and still march inexorably toward armed conflict, or... having to witness these lies being u…
>>> We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.
>> "Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.
> I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion?
I think the logic is once an organization or its leaders get something wrong, you should never, ever believe anything that organization ever says ever again. Even 20 years later after the leadership and staff has turned over a couple times.
Of course, that's totally unworkable idea when applied consistently, so it's only used, knowingly or unknowingly, to reenforce existing biases.