Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

171–180 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#171

Earlier quoted context omitted.

I always see this is trotted out as to say that Iraq did not possess WMDs, however technically it is wrong, as WMDs (chemical weapons in this case) were found after the invasion, (see https://en.wikipedia.org/wiki/Iraq_and_weapons_of_mass_destr... ). While there was no evidence of nuclear weapons or an active program I believe that a better quote should be used since the pretences that it is quoted for are technicall…

Of course, because WMD is a manufacturered phrase with tautological utility. A kitchen knife wielded in a sinister way is capable of mass destruction.

No, there's a pretty stable presumptive meaning of "weapons of mass destruction". It means radiological, biological and chemical.

There are always people trying to expand the definition, but it's usually from more left-leaning critical schools of thought that want to classify landmines, sanctions or guns as WMD.

But in official usage, it's been pretty stable at those three.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#172
post #127

The USA hasn't yet provided evidence of Huwei spying for Chinese government.

They don't need to it is a reasonable assumption that all Chinese companies are hand in glove with the Chinese military.

If there was never evidence to anything, then it's reasonable to assume?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#173

Earlier quoted context omitted.

It's not about the specific allegations, it's about the posture and priorities of the security state. A few years ago, we ran out of fear and urgency on the Islamic terror thing and now we need a new top dog bad guy.

So, in your view, is security simply not a problem? Is it all a giant lie to fund the security state? If not, where do you draw the line between real/legitimate security concerns vs. the fake ones?

That's clearly not their view. Blindly following liars into two wars has led to many avoidable casualties and has arguably made us less safe. The line between real & fake is the line between real & fake. We need to be on guard and insist on checking the intel before being led into another war.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#174

Earlier quoted context omitted.

Here is the uk version: https://www.gov.uk/government/news/uk-and-allies-hold-chines... UK and allies hold Chinese state responsible for a pervasive pattern of hacking UK joins likeminded partners to confirm Chinese state-backed actors were responsible for gaining access to computer networks via Microsoft Exchange servers.

Here's the DOJ indictment https://www.justice.gov/opa/pr/four-chinese-nationals-workin...

Thank you.

These are worth reading. Even though I am not sure how much of it would be able carry the burden of proof in a court.

Similarly to the Russian hacking cases, these will never see an independent court meaning the prosecutor can politicize and speculate without limits.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#175

Earlier quoted context omitted.

Of course, because WMD is a manufacturered phrase with tautological utility. A kitchen knife wielded in a sinister way is capable of mass destruction.

No, there's a pretty stable presumptive meaning of "weapons of mass destruction". It means radiological, biological and chemical. There are always people trying to expand the definition, but it's usually from more left-leaning critical schools of thought that want to classify landmines, sanctions or guns as WMD. But in official usage, it's been pretty stable at those three.

The utility is in the muddying. To use the broader term (WMD) instead of the specific (chemical weapons) is to imply the broader abuse. While the specific abuse is something the US turned a blind eye to a generation previously (chemcial weapons by Iraq against Iran)

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#176

Earlier quoted context omitted.

>>> There is so much doubt in this comment section around the validity of the accusations. >>> We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely. >> "Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Ch…

It's not a question of getting something wrong. The Bush administration carried out a massive disinformation campaign to convince the public that Saddam had WMD - something they knew they had no good evidence for. Large parts of the media and most senior politicians in both major parties (including the current President of the US) went along with this disinformation campaign. After that experience, I'll believe the U…

> After that experience, I'll believe the US government only when they make all their evidence public, and even then, I'll be exceedingly skeptical.

So who do you think carried out these attacks? Do you think that China does not carry out any offensive hacking? Do you think they do, but avoid the US for some reason?

IMHO, these allegations are plausible enough to believe without strong evidence to the contrary. Taking the experience with the Iraqi WMD allegations as your North Star (to the exclusion of all other factors) seems like a heuristic that will be wrong far more often than it's right, and more often wrong than alternative heuristics.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#177

Earlier quoted context omitted.

It's not about the specific allegations, it's about the posture and priorities of the security state. A few years ago, we ran out of fear and urgency on the Islamic terror thing and now we need a new top dog bad guy.

So, in your view, is security simply not a problem? Is it all a giant lie to fund the security state? If not, where do you draw the line between real/legitimate security concerns vs. the fake ones?

Constant attempts to hack each other between rivals and even allies are not a big deal.

I'm not saying this is fake, our people should be doing their job mitigating this stuff and hacking them in turn, but it being blown up into a Big Deal is part of the propaganda.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#178

It looks like cyber warfare, as well as espionage, is considered pretty much fair game in geopolitics nowadays. I wonder where the line is drawn that would make it an act of war. In any case, a direct attack from the Chinese government towards it's main trade partners (US, Germany and Japan among them) sounds crazy to me.

Was there ever a time when espionage and cyber warfare weren't fair game? To me the only difference seems to have been where a nation state did have the capability and where they didn't.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#179
post #60

Earlier quoted context omitted.

>> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independe…

I don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software. But the "just hire a pentester and you'll never have any bugs" and "just follow some (ill-defined) 'best practices' and you'll never be hacked" attitudes are so prevalent.

> I don't understand why HN has such a flippant attitude towards cybersecurity. You would think a forum full of developers would understand the complexity of software.

HN is also full of contrarians and people who like to feel superior than everyone else (and often express that through flippant dismissals).

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#180
post #39

Earlier quoted context omitted.

Not suggesting at all that the USA is some benign superpower, but Russia is run by a criminal gang and China by a despot and a corrupt communist party. Note that I am a US citizen than expatriated after the second gulf war. So I am not a fan if the US gvmt, but if you think for a second that the Chinese and Russian governments AREN'T doing the things they are accused you are naive.

just curious, have you visited china before? or seen first hand what's it actually like? you seem to have a very strong opinion, yet i'm not sure if they are based on reality or not.

This is a weird comment. Gp wasn't talking about day to day life or what cities look like or anything like that.

Going to China wouldn't teach you much about its government structure and governance. It's not like you can just walk in and observe party cells interacting with company leadership.

You don't need to go to China to know what the government structure is, what foreign policy it conducts and what kind of economic behavior is clearly not just condoned (small scale hacking, data harvesting) but encouraged (fishing other nations' territorial waters) or even demanded (foreign business ownership requirements, IP transfer requirements) by the party.

You don't need to go to China to hear reports from dissidents experiencing internment, forced labor and cultural genocide. Or to see all the broken international agreements and sovereign promises, eg the early destruction of a free Hong Kong. Or to see the territorial expansionism in salami slicing illegal maritime boundaries.

Or... most importantly, to understand that a despotic cartel that doesn't believe in individual human rights is a terrible form of human organization that has terrible externalities for the whole species and planet.

Post reply on HN