Live data from Hacker News

China spied on Dutch Cyber Intelligence through FortiGate backdoors

defensie.nl

21–29 of 29 posts

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#21
post #4

Earlier quoted context omitted.

> it's even easier to believe commonplace unintended software defects Note the fact that this was actively exploited by the Chinese. That sort of reduces the chance of this being an accident, especially since they've done this before.

Why would Chinese intelligence (or any intelligence agency) care if the vulnerability is an accident or intentional? I imagine they prefer the former, because it reveals less about their techniques, methods, etc.

Also, a proven intentional security vulnerability in Fortinet products would be bigger news, for multiple reasons, and make a lot of urgent work and disruption for a lot of people.

Occasionally, a proven intentional vulnerability will happen, so we want to be careful not to cry wolf other times.

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#22
post #3

The full report is here: https://www.ncsc.nl/binaries/ncsc/documenten/publicaties/202...

As someone not super familiar with security research, this work and the associated report must have cost millions of euro in experienced engineering man-hours to write, right? You can't just put a team of interns on this sort of stuff (of course, not defending is not an option, well, an extremely dangerous one)

AIVD / NSCC don't have money to waste compared to larger countries they're relatively small (but pretty effective).

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#23
post #2

Firefox Translations of it says it was known vulnerability: > The malware found installed a ‘backdoor’ by using a known vulnerability in FortiGate devices. The publication of the MIVD therefore does not describe any new vulnerability in all FortiGate devices. I could believe factory backdoors in Fortinet products, including bugdoors, but it's even easier to believe commonplace unintended software defects. Edit: This…

> including bugdoors Is a bugdoor a factory backdoor implemented via an intentional bug? Is the idea to give plausible deniability if the backdoor gets found?

Yes, I heard this concept alleged publicly ~25 years ago. I've only heard the "bugdoor" term within the last few years.

The first time I heard the idea, someone was claiming publicly that a manager/lead at a tech vendor had been approached by a government, and asked to insert a backdoor that would look accidental, and without the larger organization aware. That might've been apocryphal, but the idea was plausible.

The idea is maybe received a bit differently today, when there's a ton more people doing work, by a ton of developers who haven't had correctness and security prioritized. Even some of the key bits of tech infrastructure, by some the largest tech companies, seem to think weekly security updates, for multiple CVEs each, isn't insane. "Uh, you want us to make a security vulnerability, and make it look like it was because we were negligent? If you can wait a week, I can give you a dozen all-natural ones."

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#26
I'm not entirely sure why driving a tank across a border is materially different to "driving code" across a digital border.

Personally I'm less concerned about the tank. It's obvious and easy to risk assess. I don't get why countries don't have any significant, and honestly out sized, response to hacking and spying.

The damage that is/can be done is outrageous.

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#27

I'm not entirely sure why driving a tank across a border is materially different to "driving code" across a digital border. Personally I'm less concerned about the tank. It's obvious and easy to risk assess. I don't get why countries don't have any significant, and honestly out sized, response to hacking and spying. The damage that is/can be done is outrageous.

> I'm not entirely sure why driving a tank across a border is materially different to "driving code" across a digital border.

Cyberattacks are much more analogous to traditional episonage than acts of war. States don't regard episonage as acts of war because it's something engaged in by all sides and which literally happens all the time, unlike tanks rolling across the border.

Politicians of course like to pretend otherwise ... I was reminded of this, shall we say, breath-taking question I saw Rep. Haley Stevens asking recently on cspan :)

https://www.c-span.org/video/?c5105488/user-clip-do-departme...

> So we shouldn't consider cyberattacks warfare? I mean, what are they doing over there? Do they have a department that is just focused on cyberattacks? 'Coz this is, sort of, in some respects, hard to wrap our heads around, right? I mean, we don't …

Re: China spied on Dutch Cyber Intelligence through FortiGate backdoors

#29
post #3

The full report is here: https://www.ncsc.nl/binaries/ncsc/documenten/publicaties/202...

Strange, it's not available anymore. Thankfully it's archived: https://web.archive.org/web/20240206154347/https://www.ncsc....

Odd, I can still download it from the original link.
Post reply on HN