Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

181–190 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#181
post #26

Earlier quoted context omitted.

Apparently you haven't read it at all These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

Which is quite different from saying it is being done by the Chinese government. Read the uk ditto for comparison.

>> These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

> Which is quite different from saying it is being done by the Chinese government.

Who in China would be more likely to organize an espionage campaign? Espionage is a game played by governments.

Your objection is like, after detecting a nuclear missile launch from the continental US, doubting that the US government was responsible.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#183

Earlier quoted context omitted.

They don't need to it is a reasonable assumption that all Chinese companies are hand in glove with the Chinese military.

If there was never evidence to anything, then it's reasonable to assume?

The CCP/PLA can force any company operating within China to do its bidding. This is Chinese law. And this is common knowledge.

Watch this: https://www.youtube.com/watch?v=ZrsOM8ww8ug

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#184
post #128

There is so much doubt in this comment section around the validity of the accusations. We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

I would be happy to believe them if they released more technical details. Otherwise, just sounds like a typical "best-guess" based on geopolitical considerations. For example, the NYTimes just published a piece about a "Rogue" section of the Commerce Department that used racial profiling targeting Chinese Americans: https://www.nytimes.com/2021/07/16/us/politics/commerce-depa...

I don't think they should share more tech details.

I recall an incident long ago where it was back and forth - you don't know, we know, you don't have proof, we have proof, share proof - it's all bs.. then the frustrated investigators released a trail of this addy, this pic, which was also used for this and that..

what came of it?

not a damn thing changed other than teaching the other side what they needed to not do to not get caught in the same way.

If we are not going to put a missile into a building to stop office building 123456 - because of their theft, then keep the proof under wraps.

a public statement like this does nothing but make it reasonable for us to continue similar theft - meh. no proof needed for that.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#185

Earlier quoted context omitted.

Here's the DOJ indictment https://www.justice.gov/opa/pr/four-chinese-nationals-workin...

Thank you. These are worth reading. Even though I am not sure how much of it would be able carry the burden of proof in a court. Similarly to the Russian hacking cases, these will never see an independent court meaning the prosecutor can politicize and speculate without limits.

They are not getting sent to the FISA court, that court only issues warrants. They are charged with conspiracy to commit economic espionage and conspiracy to commit computer fraud and are likely going to a federal district court.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#186

Earlier quoted context omitted.

They don't need to it is a reasonable assumption that all Chinese companies are hand in glove with the Chinese military.

If there was never evidence to anything, then it's reasonable to assume?

> If there was never evidence to anything, then it's reasonable to assume?

In some cases, yes.

For instance, I'm sure China wouldn't build its nuclear deterrent around some hypothetical US-made COTS "Nuclear Weapon Control System," even if there was zero evidence that system was compromised. Absence of evidence is not evidence of absence. Ditto with Huawei.

IMHO, if its decision-making wasn't so addled by wishful thinking and capitalism, the US would use far less Chinese technology for this reason.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#187
post #130

China has been accused of hacking and/or electronic spying by other states. Russia has been accused of hacking and/or electronic spying by other states. North Korea has been accused of hacking and/or electronic spying by other states. And yes, the US and quite a few European states -- and many other countries -- have also been accused of hacking and/or electronic spying by other states[a]. All these governments are p…

Interesting to see the USA complaining about the cyberwarfare activities of other countries. As if it didn't have an entire government agency and even military branches dedicated to nothing but this.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#188

Is this damage control to distract from Israeli companies NSO and Candiru being caught running malware for despots to target journalists and activists? The timing surely is peculiar.

I completely fail to see why this post was flagged. This is a legitimate question that every thinking person needs to be asking themselves right now.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#189
post #135
post #132

Earlier quoted context omitted.

Not to say I don’t believe that China is actively attacking networks and services (if they don’t then they’re lagging behind and it’s embarassing), but I can understand the skepticism of grand claims when the latest was that tiktok was impacting national security.

If you don’t believe Tiktok is a national security threat you are hopelessly naive. MyFitnessPal, Strava, etc are threats to national security and they’re US based, but you think that Tiktok isn’t because someone you don’t like said it is? That’s playground logic.

Given the goals of the US, anything that weakens US hegemony can be regarded as a national security threat. Naturally, any internationally successful social media technology not under the control of US corporations counts.

If you are not American, though, the TikTok drama has been one of the more darkly amusing spectacles.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#190

Earlier quoted context omitted.

I doubt you'll find a credible source - the security services are afterall very good at what they do. It's all circumstantial, but at the time you'd have been hard-pressed to find a single citizen who believed Kelly very conveniently killed himself at just the right time to prevent further damage to the government and their web of lies with the US.

That's shit though. That can be said of anything. Moon landings were faked but the CIA is very good at what they do.

There is a bit of a difference - we have an abundance of evidence disproving the fake moon landing stories. OTOH, there were no witnesses of Kelly's death, and the timing was so very convenient - frankly, it's naive to think our security services wouldn't do this, especially with what was at stake. Keep in mind the the US and UK were fabricating evidence as justification for an illegal war. One that they knew would claim many, many casualties, and for which they must have known would end up destabilising the whole region and growing fundamentalists and terrorists (this was certainly obvious to many at the time).

I do see your point, mind, but I don't think such damning circumstantial evidence is "shit"; by that logic, MI6 could never be responsible for anything, unless of course they signed a confession.

Post reply on HN