Live data from Hacker News

PRC Targeting of Commercial Telecommunications Infrastructure

fbi.gov

121–130 of 157 posts

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#121
post #35

I was working with MISP[0], an open-source threat intelligence sharing platform, and came across a really interesting dataset from the Australian Strategic Policy Institute on China's technology research institutions[1]. I liked the data so much I built a quick cross-filter visualization on top of it to help explore it[2]. The data offers a fairly comprehensive and interesting perspective on China's research prioriti…

Two things and one question: 1) While being a fantastic resource to get a first impression of what's out there, the Defense Universities Tracker has not been updated since about 2019. So it is starting to be outdated and anyone using it should be well aware of it. It seems that an update is in an early stage. 2) In order to assess the actual risks, the sources that are provided at each institution's page are crucial.…

I’ve updated my link to include the site and wish I had searched more thoroughly as it would have saved me hours; This visualization was more of a personal thing after I stumbled upon it while working within MISP and the raw data(so that's what I initially attributed it to), and just wanted to see it visualized outside of MISP, it's really good analysis.

I've also added the references to the individual institution at the unitracker site as well.

To answer your question, the visualization is just a simple cross-filter. I guess the differences are the categorized and topic-based breakdowns/filtering, filtering by description and it includes a map. I did consider adding a network graph, but my focus isn't really visualization.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#122
post #89

Earlier quoted context omitted.

They are very clear about who is a valid target though. I think you’ll quickly find that those attacking domestic targets rapidly disappear.

Kinda works both ways. In many western countries you still go to jail for refusing to give private encryption keys

Or they convict you for money laundry because you developed a crypto phone they can't crack and don't have any legal means to destroy you. ( Dutch example, and yes - the guy payed taxes everything, they made him hang because of a single client of a client his client his client being involved with shady things. ) State-Spite, Repression and such is rising globally. The rule of law is gone.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#123
post #100

Earlier quoted context omitted.

> To be fair, the parent's claim that China is "ahead" in infosec also feels like fearmongering. The one thing that's true for China is that their government has far fewer qualms about hacking Western infrastructure to get dirt on dissidents, steal IP, and so on. But that's a matter of ethics and law, not tech. I've heard China also has many more personnel working in this space.

Ive also heard that China has many more people living in it than the US. Ive also heard that Chinese higher education system is state funded

> Ive also heard that China has many more people living in it than the US. Ive also heard that Chinese higher education system is state funded

So? It kinds sounds like you're making an excuse, but excuses don't do anything to address the capability difference caused by the larger number of personnel.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#124
post #45

Earlier quoted context omitted.

> we are falling far behind in many areas, including cyber security In terms of quantity and quality of talent, I don't think the western world would fall behind China, especially with their strict control of information. Most people there will have difficulty independently learning about cybersecurity. The difference is that most talent is captured by the private sector with higher compensation or bounties. Meanwhil…

> China can very easily compel anyone they need into the government I have worked with people in Chinese tech companies and in Chinese tech ministries, and I don't think this statement is true, any more than in the US. In the US, there are talented techies who work for FAANG, startups, Palantir, NSA, etc etc. Similarly in China.

Compel is a euphemism for a "friendly" visit to your wife & children or elderly parents. The western equivalent is to lawyer someone to death. Don't be naive.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#125
post #103

Earlier quoted context omitted.

The FBI is not the same as a news agency however. So that point is null.

Both depend on whether you believe in the government actually. When we say "Chinese state media", we're really talking about a media controlled by the government, especially for those political topics

This would be true even with private actors, at the end of the day it's whoever has concrete evidence of something taking place.

If the FBI is going to make the broad statement that China is hacking the USA, it'll have to back that statement up by evidence presented in court against individuals the FBI has investigated for hacking into US companies/government orgs.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#126

Earlier quoted context omitted.

Is this a whataboutism?

Friends don't treat friends like this.

They do, they just care less when it's friends doing it. 5-eyes did the same with the entire European parliament. The incident response & reporting ( clean up crew ) was done by a firm who got sold to a British intelligence daughter not much afterwards. You can't make this shit up. Another famous example would be from the previous cold war era. Dutch telephony routers had Hebrew manuals so they required personnel from Israel for "maintenance". They wiretapped the whole country.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#127
post #108

Earlier quoted context omitted.

check AI, green energy, EV, mobile computing, cloud computing, quantum stuff, robots etc. it is pretty much China vs US now when it comes to quality. how many people would seriously believe that EU or Japan can possibly compete with China on its own in terms of quality for those above mentioned sectors. just looking at those low quality & high pollution Japanese & European cars.

Interesting also is the type of names that appear in so many western academic journals. What I mean to say is that even in Western journals "Alice" and "Bob" is quite rare

when "alice" and "bob" can become a lawyer to talk their clients into paying some stupid amount, why bother studying STEM.

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#129

Whenever I see these news & FBI releases about Chinese state-sponsored hackers breaching systems in America, I wonder whether the same thing happens over there: American malware and hacker groups attacking & laying landmines in China's internet infrastructure, although the Chinese may not publicize these exploits because their system opts to maintain an air of invincibility.

[deleted]

Re: PRC Targeting of Commercial Telecommunications Infrastructure

#130

Earlier quoted context omitted.

> especially with their strict control of information. Most people there will have difficulty independently learning about cybersecurity. I'm puzzled by this assertion. I know quite a few self-taught infosec folks who grew up there. China is not North Korea. The government, by and large, doesn't monitor what you're doing day-to-day, unless you're a political activist or some other "undesirable". The Great Firewall do…

> The one thing that's true for China is that their government has far fewer qualms about hacking Western infrastructure to get dirt on dissidents, steal IP, and so on. But that's a matter of ethics and law, not tech. As opposed to the DoD, which strictly fights for freedom, liberty, and democracy?

> As opposed to the DoD, which strictly fights for freedom, liberty, and democracy?

Yes, the whataboutism is unwarranted here. The US government is no angel, but is far more constrained in this regard. The bar to become "the enemy of the state" is much higher - for example, your comment won't get you in trouble here. The US government also wouldn't, say, hack Spotify and snoop on their business plans to prop up a competing US startup - something that is commonplace with the Chinese intelligence apparatus.

Post reply on HN