Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

11–20 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#12
post #3
post #2

"Security experts found evidence that the hackers stole the corporate passwords for every Times employee and used those to gain access to the personal computers of 53 employees" Does this mean the NYTimes is storing passwords in plaintext?

I think if they have the ability to steal the passwords, even if they weren't plain text, they didn't do the proper precautions of encrypting with a salt. So either way, they failed.

The "Let's Set Up a Domain Controller" wizard doesn't ask how much salt you'd like to add to your passwords.

Re: Chinese Hackers Infiltrate New York Times Computers

#13

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

Symantec (or any software company) isn't going to comment to a reporter about why it's product didn't perform adequately, regardless of whether it's related to that reporters parent organization.

If a reporter asked Oracle for a comment every time Tumblr went down because of something related to MySQL (I have no idea if Tumblr actually runs MySQL, that's just a hypothetical), the best they'd hear is "We don't comment about specific customer information."

Re: Chinese Hackers Infiltrate New York Times Computers

#14
didn't expect much out of this story because it has felt for a long time that hackers targeting politically sensitive media orgs, govt and private sector out of China is the norm. Too common, widespread (however it's being organized) and they are too many for us to keep tabs on/hope to stop. All we can do is be vigilant in security practices and keeping on top of latest measures.

Re: Chinese Hackers Infiltrate New York Times Computers

#16
Strange that they would hack NYT when NYT's source for the WenJiaobao article seemed to be public financial records and info from wikileaks (state department cables).

What is the strategic gain from hacking NYT? Identify potential other sources (within china) perhaps?

Re: Chinese Hackers Infiltrate New York Times Computers

#17

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

When newspapers are making the news, they often write about it in the third person, as if they were writing about any other newspaper. Symantec would not give the NYT a quote on the record about this. It doesn't mean Symantec wouldn't give the NYT details off-the-record. The comment in the article was a response to a question from a reporter, not the Times' security chief.

For instance a few weeks ago the Washington Post broke a story about how the Washington Post was considering a pay wall.

Re: Chinese Hackers Infiltrate New York Times Computers

#18

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

Symantec (or any software company) isn't going to comment to a reporter about why it's product didn't perform adequately, regardless of whether it's related to that reporters parent organization. If a reporter asked Oracle for a comment every time Tumblr went down because of something related to MySQL (I have no idea if Tumblr actually runs MySQL, that's just a hypothetical), the best they'd hear is "We don't comment…

Surely the Times could waive whatever privacy rights they have? Your example would be more on target if Oracle told Tumblr that they couldn't comment.

What I'm getting at is, "We don't want to comment on our product." is a lot closer to the truth, they're just trying to weasel out of saying that.

Re: Chinese Hackers Infiltrate New York Times Computers

#19
I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this:

http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante...

  U.S. Groups Helped Nurture Arab Uprisings

  Even as the United States poured billions of dollars into 
  foreign military programs and anti-terrorism campaigns, a 
  small core of American government-financed organizations 
  were promoting democracy in authoritarian Arab states. ...

  The United States’ democracy-building campaigns played a 
  bigger role in fomenting protests than was previously 
  known, with key leaders of the movements having been 
  trained by the Americans in campaigning, organizing through 
  new media tools and monitoring elections. ...

  Today the work of these groups is among the reasons that 
  governments in turmoil claim that Western meddling was 
  behind the uprisings, with some officials noting that 
  leaders like Ms. Qadhi were trained and financed by the 
  United States. Diplomatic cables report how American 
  officials frequently assured skeptical governments that the 
  training was aimed at reform, not promoting revolutions.
and then this:

http://online.wsj.com/article/SB1000142405274870356040457618...

  Is China Next?

  Over the course of three short months, popular uprisings 
  have toppled regimes in Tunisia and Egypt, sparked a civil 
  war in Libya and created unrest in other parts of the 
  Middle East. They also have raised a question in many 
  people's minds: Are all authoritarian regimes now 
  threatened by this new democratic wave? In particular, is 
  China, a rising superpower, vulnerable to these forces?
Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions and prominent neocons (like Fukuyama in that WSJ article) were/are calling for similar actions in China.

This is why the Chinese government feels that it is under attack by the United States, and it does not see a line between NGOs, the NYT/WSJ, and the US government, which they believe are working in concert to discredit their leaders and foment violent revolution in the name of democracy, as they did in the Middle East. Is this paranoid? Well, it's now hard to gainsay the USG/NGO connection given those articles, and in general even the NYT does tend to side with the USG against China or Arab regimes (most famously with Judith Miller).

From this worldview, China thinks of this as a conflict between one of their intelligence agencies and one of ours. It's not obvious that they are wrong in that assessment.

Re: Chinese Hackers Infiltrate New York Times Computers

#20
post #16

Strange that they would hack NYT when NYT's source for the WenJiaobao article seemed to be public financial records and info from wikileaks (state department cables). What is the strategic gain from hacking NYT? Identify potential other sources (within china) perhaps?

It's not necessarily that the state as a whole found strategic value in this. Could just be one general hoping to impress the Politburo.
Post reply on HN