Live data from Hacker News

An inside look at NSA tactics, techniques and procedures from China's lens

inversecos.com

41–50 of 76 posts

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#41

Earlier quoted context omitted.

Wechat is the internationalized version; Weixin is for mainland China. https://duckduckgo.com/?q=weixin+vs+wechat

I guess if ChatGPT told you to glue the cheese onto your pizza, you'd eat it that way. Wechat is also the mainland version. It's always been Wechat, and in particular it was Wechat years before they kicked me off of the mainland Chinese version† for registering an American phone number. The reality is exactly what I already told you: the app's name is 微信 in Chinese and Wechat in English. This is why coverage of Wecha…

That would have been great to include with your initial comment instead of seemingly picking at nits and then making inflammatory comments.

Always love the use of a dagger though, I don't see them too often online!

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#43

Earlier quoted context omitted.

I have a hard time imagining these APT attacks are manual at the keyboard typing. That seems like an invention for entertainment whereas I'd expect reality to be "run script & establish an ongoing backdoor" or "run script & perform attack". You might need on-call to flag if anything has gone wrong, but I'd have a hard time imagining the entire team is involved for that so the cost of paying extra for an on-call is qu…

On-Call for mission of this size sounds fairly unlikely, doesn't it? You wouldn't spend hundreds of thousands of dollars on large scale attacks with lots of (temporary) infrastructure and planning to then yolo it at the last minute and hope that everything goes well and you have the results back when you come back on Monday.

[deleted]

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#44

Given how US is attacking their enemies and at times their allies, 24/7 it is amazing how little we ever hear about it.

Everyone is always attacking everyone else at all times, its not just the US.

Well, yes, but we hear quite a bit about China or Russia or North Korea or wherever attacking us.

I've quite literally seen people ask "why don't we attack them back?"

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#45

Given how US is attacking their enemies and at times their allies, 24/7 it is amazing how little we ever hear about it.

Everyone is always attacking everyone else at all times, its not just the US.

Never trust the law of averages. I don't want to say that the US is exceptional, but assuming it's like every other country give-or-take is a horrifically bad assumption.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#46
post #24

> Chinese cyber organizations openly acknowledge and publicize their partnerships. This openness was particularly interesting to observe and may be influenced by cultural factors, such as the Confucian emphasis on shared knowledge and a political framework that encourages collective efforts. I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninform…

> As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture

IIRC, Bunnie (Huang) mentioned how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers.

> source: I regularly work with engineers from that culture and studied relevant geopolitics.

(Winces)

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#47
post #24

> Chinese cyber organizations openly acknowledge and publicize their partnerships. This openness was particularly interesting to observe and may be influenced by cultural factors, such as the Confucian emphasis on shared knowledge and a political framework that encourages collective efforts. I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninform…

> As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture IIRC, Bunnie (Huang) mentioned how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. > source: I regularly work with engineers from that culture and studied relevant geopolitics. (Winces)

> how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers.

That's different though. Shenzhen is where electronics factories are; they get the datasheets from western companies, but because said western companies can't really enforce their IP over there, the locals get to ignore it and use the datasheets however it's convenient for them.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#48

I originally came here to comment how crazy it seems that DoD employees at NSA cannot be bothered to cover their tracks by working nonstandard hours/holidays (obviously Mil & Intel folks do this, they even get deployed!). But the thought occurred to me that attribution to NSA was likely a desired outcome here (“We can hack you too”) and there are probably many people at NSA working nonstandard hours/days to prevent a…

It sounds exciting and all but it’s basically a boring government office job, the employees mostly have families, expect regular work hours, etc.

Re: An inside look at NSA tactics, techniques and procedures from China's lens

#49

Earlier quoted context omitted.

> As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture IIRC, Bunnie (Huang) mentioned how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. > source: I regularly work with engineers from that culture and studied relevant geopolitics. (Winces)

> how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. That's different though. Shenzhen is where electronics factories are; they get the datasheets from western companies, but because said western companies can't really enforce their IP over there, the locals get to ignore it and use the datasheets however it's convenient…

One other question is: how accurate are the data sheets in Shenzhen as opposed to in the US? I can't speak to China, but in the US if you publish a spec for a component and then don't deliver within that spec, you will get sued, and you will lose.
Post reply on HN