Earlier quoted context omitted.
I don't find the money inexplicable at all. Building multi-billion dollar data centers increases wealth for billionaires but paying overtime would benefit a middle-class pleb.
Well how convenient those plebs are down-sized right now.
An inside look at NSA tactics, techniques and procedures from China's lens
51–60 of 76 posts
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#52> Chinese cyber organizations openly acknowledge and publicize their partnerships. This openness was particularly interesting to observe and may be influenced by cultural factors, such as the Confucian emphasis on shared knowledge and a political framework that encourages collective efforts. I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninform…
> As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture IIRC, Bunnie (Huang) mentioned how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. > source: I regularly work with engineers from that culture and studied relevant geopolitics. (Winces)
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#53Earlier quoted context omitted.
The same strategy is used to attribute attacks against US based targets by Russian, N.Korean and Iranian and other state or state sponsored actors. Time of day, holidays, etc. are (in tandem with other evidence) considered to be surprisingly reliable. If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using…
The type of work the people working at an APT do, is mainly office work, while it still is very much "hands-on-keyboard" work (so you cannot set an action to automatically occur when nobody is checking the results in the middle of the night). You might want to try shuffling this up when you are in charge, but your (usually highly skilled and expensive) employees probably don't want to be working weird shifts all the…
Do we have any probe into the state-sponsored APT world? I wouldn't be surprised if there isn't any, but would like to know.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#54Earlier quoted context omitted.
Wechat is the internationalized version; Weixin is for mainland China. https://duckduckgo.com/?q=weixin+vs+wechat
I guess if ChatGPT told you to glue the cheese onto your pizza, you'd eat it that way. Wechat is also the mainland version. It's always been Wechat, and in particular it was Wechat years before they kicked me off of the mainland Chinese version† for registering an American phone number. The reality is exactly what I already told you: the app's name is 微信 in Chinese and Wechat in English. This is why coverage of Wecha…
There are tons of difference. Wexin has more adware/spyware, no CallKit on iOS, local payments.
There's even a chat firewall between wexin and wechat.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#55glad to see the same basic tradecraft from 90s hacking, only very refined and industrialized. it's a durable skill. the focus on switches and routers is very pro, as they are the most opaque infra with the fewest forensic capabilities. iot is less reliable as RE'ing cheap devices and firmware for IoCs is accessible, where almost nobody outside the IC did core gear (word to phenolit from back in the day tho). the traf…
- the focus on switches and routers is very pro (did you mean the defenders or the attackers?)
- What kind of knowledge is a starting point to hunt these players? I assume very good Linux system admin skills that can protect the whole system well enough to maybe only allow some obscure entries, and then have enough RE/Red team knowledge to know how to focus on these entries. Does it make sense?
- How do those APTs operate? I'd imagine there are at least 3 groups of people, group 1 = people who make tools, do analysis, RE and such -- they are the support guys; group 2 = people who directly execute the operations -- they don't need very in-depth knowledge but need to a whole range of knowledge to know where to look at and how to best use the tools; group 3 = blue team who protects the whole facility. And of course there are managers, admins, etc.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#56Earlier quoted context omitted.
> how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. That's different though. Shenzhen is where electronics factories are; they get the datasheets from western companies, but because said western companies can't really enforce their IP over there, the locals get to ignore it and use the datasheets however it's convenient…
One other question is: how accurate are the data sheets in Shenzhen as opposed to in the US? I can't speak to China, but in the US if you publish a spec for a component and then don't deliver within that spec, you will get sued, and you will lose.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#57What is Shadow Broker, does anyone know?
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#58Earlier quoted context omitted.
I guess if ChatGPT told you to glue the cheese onto your pizza, you'd eat it that way. Wechat is also the mainland version. It's always been Wechat, and in particular it was Wechat years before they kicked me off of the mainland Chinese version† for registering an American phone number. The reality is exactly what I already told you: the app's name is 微信 in Chinese and Wechat in English. This is why coverage of Wecha…
> There is no difference in the app There are tons of difference. Wexin has more adware/spyware, no CallKit on iOS, local payments. There's even a chat firewall between wexin and wechat.
...is there a reason you believe this? It is not true in any sense.
I'll also note that, if you believe the claims in your comment, you'll have a tough time explaining how my installation from the Google Play Store includes local payments.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#59> * One of the frameworks used by TAO that was forensically uncovered during the incident named “NOPEN” requires human operation. As such, a lot of the attack required hands-on-keyboard and data analysis of the incident timeline showed 98% of all the attacks occurred during 9am – 4pm EST (US working hours).
> * There were zero cyber-attacks on Saturdays and Sundays with all attacks centralised between Mon-Fri.
> * No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays.
> * No attacks occurred during Christmas.
It's surprising the NSA would be this sloppy and obvious, or maybe they don't care about attribution in this situation, or maybe someone else did it. But I've read attribution of Chinese attackers using work hours and thought the attackers were sloppy and obvious.
> A key observation from the Chinese case notes was the extensive use of big data analysis, particularly in tracking “hands-on keyboard” activity. This approach enabled Qihoo 360 to identify patterns, such as the alleged absence of activity on Memorial Day, and precisely documenting the operational hours of the attackers, allowing 360 to isolate activity to Monday-Friday, EST working hours.
If the blogger's claim of experience is true, they must know about the things I've read. I wonder what they are thinking of.
Re: An inside look at NSA tactics, techniques and procedures from China's lens
#60Earlier quoted context omitted.
> how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers. That's different though. Shenzhen is where electronics factories are; they get the datasheets from western companies, but because said western companies can't really enforce their IP over there, the locals get to ignore it and use the datasheets however it's convenient…
One other question is: how accurate are the data sheets in Shenzhen as opposed to in the US? I can't speak to China, but in the US if you publish a spec for a component and then don't deliver within that spec, you will get sued, and you will lose.
The provenance of the component is also really important. If it’s a ghost shift at a contract manufacturer producing the parts, they might have skimped on some part of the process (like packaging so that another subcontractor responsible for that step isn’t alerted) and the datasheet might be significantly inaccurate. I don’t know if these manufacturers ever bother to characterize their ghost shift parts enough to release their own datasheet but I assume it happens with especially popular parts. If the contract manufacturer loses the contract but keeps the ghost shift, they might be significantly out of date in revisions so you’d have to be careful to use only the datasheet they provide and not the one your engineers download from the first Google result (good luck!). In short, it’s complicated.
The most infamous example is probably the FTDI serial to usb chips that have been counterfeited for many years with varying quality, both by ghost shifts and manufacturers who reverse engineered the design to some degree.