Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

231–240 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#231

Earlier quoted context omitted.

That's not the problem. We shit on the US all day every day. There's also not a problem with this. The problem is that when we're talking about someone else it's being used as a defense. Honestly it doesn't even matter if the US is doing the same thing. If something is wrong it is wrong, no matter who does it. Responding to "China is hacking the US" with "But the US hacks China" doesn't accomplish anything except cre…

What would you like to have discussed and/or judged independently? I agree that a lot of the comments here are shitposting or making reactionary equivocations. Others though, are making valid points... which you may agree with, or not. IMO, for example, the most important part of this to pay attention to is NATO. Cybersecurity & China seem to be the new focus of the alliance. To me, this seems like the most potential…

Well look at the conversations in threads about the US hacking. They typically discuss the international implications of this, how to protect yourself, and what we can do about it. Yeah, there's people that bring up China and Russia, but they typically aren't the top comment or a majority of the comments. The top comment in this thread[0] is the beginning of a conversation I'd like to see but one that is already being pulled away from. It recognizes the danger of these actions (independent of the country issuing them). It is not excusing the hacking by stating that another country has done it, but rather condemning it all around.

[0] https://news.ycombinator.com/item?id=27883812

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#232

Earlier quoted context omitted.

What would you like to have discussed and/or judged independently? I agree that a lot of the comments here are shitposting or making reactionary equivocations. Others though, are making valid points... which you may agree with, or not. IMO, for example, the most important part of this to pay attention to is NATO. Cybersecurity & China seem to be the new focus of the alliance. To me, this seems like the most potential…

Well look at the conversations in threads about the US hacking. They typically discuss the international implications of this, how to protect yourself, and what we can do about it. Yeah, there's people that bring up China and Russia, but they typically aren't the top comment or a majority of the comments. The top comment in this thread[0] is the beginning of a conversation I'd like to see but one that is already bein…

Those aren't really equivalents.

This isn't just a thread about chinese hacking, it's a thread about a US-NATO statement in response to hacking.

Anyway, who cares about convicting one or the other. This is about consequences. The consequences of whatever direction NATO is taking now are meaningful.. much more meaningful than the hack.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#233
post #140

Earlier quoted context omitted.

Why is it deliberately obtuse to think that some of China's billion people could be independent black hat hackers? Are they incapable of being evil or greedy?

They're not incapable of either. Are they as motivated as the government? In general, no . Genocidal dictatorships are more motivated than random script kiddies and "evil" black hat hackers to go after high profile government and government-adjacent (infrastructure) targets.

As the other commenter pointed out, these weren't really high profile targets. Hell, security groups found evidence they were planning to mine crypto on some of the servers. You don't need to be purposefully ignorant to question if private hackers were involved.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#234
post #130

China has been accused of hacking and/or electronic spying by other states. Russia has been accused of hacking and/or electronic spying by other states. North Korea has been accused of hacking and/or electronic spying by other states. And yes, the US and quite a few European states -- and many other countries -- have also been accused of hacking and/or electronic spying by other states[a]. All these governments are p…

If a seemingly insignificant issue is enough to start a war, perhaps the problems run deeper than the tipping point trigger issue.

I have to disagree, in todays internet-connected world cyber attacks are not insignificant. It is not inconceivable for an large-scale attack to e.g. turn off an entire countries' electricity distribution, and that's more than most traditional weapons ever could do.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#235

Earlier quoted context omitted.

There is more than the most recent Iraq war. There is Vietnam (Gulf of Tonkin) and the Spanish-American War (USS Maine sabotage). Several others. It's not disingenous and it's not discrediting _any_ future allegation, but to appropriately raise the threshold before belief.

Everything you said would be true if today's accusations were a pretext for armed conflict, but I don't believe we've reached that level of escalation. Do you? Accordingly, I don't find comparison to prior wars helpful for discussion. Obviously opinions here may differ...

I do not expect that even if there was truth to the matter that war would be a direct consequence. I agree that citing historical false pretexts for war reduces the surface for debate of the validity of allegations of state-sponsored cybercrime. I should not have contributed in this manner. My apologies.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#236

Earlier quoted context omitted.

Is there any evidence the US has directed the intentional sabotage of critical energy providers and food providers in Russia or China in recent years? Russia appears to be waging an all-out cyber war against the US at this point. Putin admitted as much in the hour-long interview with NBC a month ago. He declared as openly as he possibly could have that the US would be targeted until it came to the negotiating table (…

https://en.m.wikipedia.org/wiki/Operation_Olympic_Games

Sibbling comment is correct that this is an attack on a military research project, not civilian infrastructure. Thus non-responsive to the original request.

Perhaps a better (but also possibly fictional) example is sabotage of the Soviet trans-Siberian gas pipeline in 1983. Certainly there appears to have been a US suggestion to surreptitiously provide the Soviet Union with compromised technology it was seeking in the West. But it's not clear whether compromised technology was provided, or whether the US caused the pipeline explosion.

Here is one (controversial) source: https://en.wikipedia.org/wiki/At_the_Abyss

I wasn't going to comment at all, since the US does a lot of - ahem - "disruption" throughout the world. However, I'm not aware that the US does a lot of civilian infrastructure attacks outside of active military theatres. If true: it's a notable/interesting fact.

But I'm also not sure that civilian infrastructure attacks are further beyond the pale than rendition, bombing, arms sales, embargoes, et cetera. I worry that we in the States are more sensitive to infrastructure attacks because (1) it's a weapon readily available to our national adversaries and (2) for the first time, we are the victims.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#238

Earlier quoted context omitted.

The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of…

> Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc. I like this idea…

> I like this idea. At the same time, I think the agency - or organization, if you prefer - should look something like the National Transportation Safety Board, where incidents are investigated, reported on, and recommendations are made in a way that improves user safety. Maybe the 'National Digital Safety Board'?

I like it too, but I also think it would be needed to be backed by some kind of regulatory agency that could issue the cybersecurity equivalent of an "Airworthiness Directive". Otherwise we'd be in a similar situation we have know: lots of information about vulnerabilities that are often not acted upon.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#239
post #21

> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…

The challenge the NSA has is it possesses 2 separate missions that are often in direct conflict: secure the communications of the United States, and to collect, eavesdrop, and compromise the communications of other countries. The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of…

For what it's worth, I think this is the NCSC in the UK.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#240

There is so much doubt in this comment section around the validity of the accusations. We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

Comment sections are not a reliable source of information.
Post reply on HN