Live data from Hacker News

PRC Targeting of Commercial Telecommunications Infrastructure

fbi.gov

51–60 of 157 posts

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#51

Earlier quoted context omitted.

It's legal speak for "They are looking at who we have wiretaps on", which any country would be interested in, just to see which of their assets are being watched, for counter-counter-espionage purposes.

That is incorrect. While you're idea probably is interesting to them, they are indeed leveraging the infrastructure to "live off the land" doing their own collect. They are very much doing their own targeting.

How would their own targeting relate to "copying of certain information that was subject to U.S. law enforcement requests pursuant to court orders"? AFAIK, telecoms enforcement requests subject to court orders in the US mean one thing, and one thing only: lawful interception of communication.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#52
post #8

Earlier quoted context omitted.

China has the Great Firewall segregating most international access from the country's network. Additionally, China (moreso than most) has a motivation to onshore as much of their software and hardware manufacturing to bolster their own industry. It's possible that isolated attacks could pop off now and again, but hacking to-and-from China is strictly state controlled.

Their censorship infrastructure isn't security. If anything, it's another thing to hack.

It does have some defensive benefit. Getting legitimate connectivity to work reliably across the Chinese border, is a big pain. Due to this, Chinese commercial internet infrastructure has very few dependencies on international services.

Western infrastructure by comparison is very vulnerable to distribution of connectivity, attacks on deep sea cables can cause a lot of damage.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#53
post #11

Earlier quoted context omitted.

Does this mean that they were able to (ab)use LI infra? https://en.wikipedia.org/wiki/Lawful_interception

Yes. What no one here bothers to even mention is that APTs have been doing this very thing since the 2004 Athens Affair. It didn't feed into the sanctimony so it isn't mentioned.

I was just reading about the Greece incident linked on the wiki page. Absolutely staggering stuff - none of which I heard of before!

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#54
post #45
post #35

I was working with MISP[0], an open-source threat intelligence sharing platform, and came across a really interesting dataset from the Australian Strategic Policy Institute on China's technology research institutions[1]. I liked the data so much I built a quick cross-filter visualization on top of it to help explore it[2]. The data offers a fairly comprehensive and interesting perspective on China's research prioriti…

> we are falling far behind in many areas, including cyber security In terms of quantity and quality of talent, I don't think the western world would fall behind China, especially with their strict control of information. Most people there will have difficulty independently learning about cybersecurity. The difference is that most talent is captured by the private sector with higher compensation or bounties. Meanwhil…

Every ordinary Chinese needs to self-learn some cybersecurity to do daily things, like to watch YouTube, or to send messages to others without worrying being censored

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#56
post #37

Earlier quoted context omitted.

You've probably conflated the saying "going through the backdoor" with the noun backdoor, which is an understandable mistake to make. Conflating the two is even easier when the backdoor is morally questionable i.e. When someone purposefully installs a wooden backdoor on a bankvault and says it's so that we don't need to go through the whole rigmarole of opening the main vault-door. Yes it allows them to do their job…

A backdoor bypasses legitimate access mechanisms. Whether it is a backdoor or not depends fully on whether you believe lawful intercept is a legitimate access mechanism. And I think the law is on the side of it being not a backdoor.

We've had multiple bills proposed by multiple countries for government mandated backdoors. Multiple articles refer to how these bills would create backdoors, multiple computer security experts say the bills would create backdoors in the software. Under your definition of the word they'd all be using the word incorrectly because logically no bill could create a legal backdoor by definition.

It's seems there's a semantic schism on "the point in software where security is weak enough (either purposefully or unkowingly) for 3rd party access by a 3rd party" and "the point in software where security is purposefully weakened for 3rd party access by the legal requirement of a 3rd party" there's definitely a distinction but I generally conflate the two, perhaps incorrectly, under the word backdoor.

If you've got another more appropos word for this purposeful and legal weakining of security for non primary user/provider access I'd love to know it because sadly I feel I'd use it fairly often in the coming years.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#57

Whenever I see these news & FBI releases about Chinese state-sponsored hackers breaching systems in America, I wonder whether the same thing happens over there: American malware and hacker groups attacking & laying landmines in China's internet infrastructure, although the Chinese may not publicize these exploits because their system opts to maintain an air of invincibility.

Yes, the US famously has breached foreign infrastructure. In Confessions of an Economic Hitman[0], Josh Perkins discusses how he knows on good authority the US could shutdown the Japanese electrical grid with relative ease if needed, which an ally. Imagine what they do to perceived enemies. [0]: https://www.goodreads.com/book/show/2159.Confessions_of_an_E... This book was on of my favorite books to site in extemporan…

Confessions is best read as historical fiction. It's brilliantly written. But the author has never been able to substantiate much [1].

[1] https://en.wikipedia.org/wiki/Confessions_of_an_Economic_Hit...

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#58
post #45
post #35

I was working with MISP[0], an open-source threat intelligence sharing platform, and came across a really interesting dataset from the Australian Strategic Policy Institute on China's technology research institutions[1]. I liked the data so much I built a quick cross-filter visualization on top of it to help explore it[2]. The data offers a fairly comprehensive and interesting perspective on China's research prioriti…

> we are falling far behind in many areas, including cyber security In terms of quantity and quality of talent, I don't think the western world would fall behind China, especially with their strict control of information. Most people there will have difficulty independently learning about cybersecurity. The difference is that most talent is captured by the private sector with higher compensation or bounties. Meanwhil…

> especially with their strict control of information.

You have gross misunderstanding of how this strict control works. It isn't like novels or North Korea where some govt agency is creating/curating the info.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#59
post #39

Whenever I see these news & FBI releases about Chinese state-sponsored hackers breaching systems in America, I wonder whether the same thing happens over there: American malware and hacker groups attacking & laying landmines in China's internet infrastructure, although the Chinese may not publicize these exploits because their system opts to maintain an air of invincibility.

At least you have CIA openly recruit spies on Twitter: https://x.com/CIA/status/1841468925378171381 I think only CIA and mossad have the confidence to do it this way.

That's wild.

What's the situation like on the ground? I've read that the CCP sentences spies to death and that they catch a lot of them.

Post reply on HN