Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

21–30 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#21
This story, and the recent RubyGems debacle should be teaching all of us one thing -- assume you can and will be hacked. Do you understand the implications (what data you are going to lose? what credibility?) Do you have a plan to deal with it?

Ruby Gems was lucky in that their hack was noisy. The chinese government, as illustrated above, won't play so nice.

This is why monitoring and incident response matter.

Remember the subtle backdoor that almost slipped into the Linux kernel in 2003[1]? That could be Ruby Gems right now. Hopefully, they are taking the proper steps to investigate exactly what the hackers did.

[1] http://kerneltrap.org/node/1584

Re: Chinese Hackers Infiltrate New York Times Computers

#22
"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out."

I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Re: Chinese Hackers Infiltrate New York Times Computers

#23

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

About Symantec's technology, it is worth noting that antivirus scans are based on identifying malware in one place, then being able to recognize that malware everywhere. This does not particularly help you recognize malware that was custom made to only be installed in one location. Particularly not when the people who were making that malware themselves have access to your anti-virus scans prior to deployment and can verify on their own computers that you do not detect them.

Therefore there is no surprise that Symantec failed to provide any meaningful protection during this attack. They know this. But they hardly want to admit it in front of all of their customers.

Re: Chinese Hackers Infiltrate New York Times Computers

#24
post #3
post #2

"Security experts found evidence that the hackers stole the corporate passwords for every Times employee and used those to gain access to the personal computers of 53 employees" Does this mean the NYTimes is storing passwords in plaintext?

I think if they have the ability to steal the passwords, even if they weren't plain text, they didn't do the proper precautions of encrypting with a salt. So either way, they failed.

A domain controller is a Microsoft server, not custom built software.

Re: Chinese Hackers Infiltrate New York Times Computers

#25

This story, and the recent RubyGems debacle should be teaching all of us one thing -- assume you can and will be hacked. Do you understand the implications (what data you are going to lose? what credibility?) Do you have a plan to deal with it? Ruby Gems was lucky in that their hack was noisy. The chinese government, as illustrated above, won't play so nice. This is why monitoring and incident response matter. Rememb…

China appears to be engaging in highly sophisticated attacks of the like that major companies need to be aware.

The RubyGems fiasco is the result of remarkably incompetent decisions by everyone in the chain of control.

The lessons are completely different. In the first, it's that you have to expect that you will be compromised if a determined and capable attacker targets you.

In the second, it's that you will be compromised if you use software written by people and maintained by a community that seemingly lacks any remote resemblance of engineering competence.

Re: Chinese Hackers Infiltrate New York Times Computers

#26
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Maybe they actually meant every compromised computer OS (i.e. hard disk)?

Re: Chinese Hackers Infiltrate New York Times Computers

#28
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

>> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions and prominent neocons (like Fukuyama in that WSJ article) were/are calling for similar actions in China. This is why the Chinese government feels that it is under attack by the United States

The Chinese don't give a rat's hoot about the Arabs. They attack American computer systems for obvious reasons, obvious to most of us.

Re: Chinese Hackers Infiltrate New York Times Computers

#29

Earlier quoted context omitted.

Symantec (or any software company) isn't going to comment to a reporter about why it's product didn't perform adequately, regardless of whether it's related to that reporters parent organization. If a reporter asked Oracle for a comment every time Tumblr went down because of something related to MySQL (I have no idea if Tumblr actually runs MySQL, that's just a hypothetical), the best they'd hear is "We don't comment…

Surely the Times could waive whatever privacy rights they have? Your example would be more on target if Oracle told Tumblr that they couldn't comment. What I'm getting at is, "We don't want to comment on our product ." is a lot closer to the truth, they're just trying to weasel out of saying that.

Edit: It took me so long to write that that you edited your comment before I finished. ;) I think we're in agreement.

It's not really about privacy (which was why when I saw the quote in the article, I giggled, and thought "That reporter's being funny"), it's about the fact that Symantec isn't even in a position to have a comment about it.

If they were super on the ball and forthcoming, they might comment "We make software which is designed to protect users from the overwhelming majority of malware and viruses. There does not exist any solution which can completely guarantee safety from infection, but we have detected and stopped billions of threats."

Don't get me wrong, the AV industry (actually much of the security industry) should be embarrassed by how fundamentally primitive things are; it's a bunch of horseshit.

But they have absolutely nothing to gain by commenting about it, it would be walking into a hornet's nest. So they get to deflect it by saying they won't comment on a customer issue.

Re: Chinese Hackers Infiltrate New York Times Computers

#30
post #28
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

>> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions and prominent neocons (like Fukuyama in that WSJ article) were/are calling for similar actions in China. This is why the Chinese government feels that it is under attack by the United States The Chinese don't give a rat's hoot about the Arabs. They attack American compute…

jebblue, I believe the point of the paragraph you highlighted is that China feels it's under attack by the United States, not that it cares about the Arabs.
Post reply on HN