Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

31–40 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#31
post #28

Earlier quoted context omitted.

>> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions and prominent neocons (like Fukuyama in that WSJ article) were/are calling for similar actions in China. This is why the Chinese government feels that it is under attack by the United States The Chinese don't give a rat's hoot about the Arabs. They attack American compute…

jebblue, I believe the point of the paragraph you highlighted is that China feels it's under attack by the United States, not that it cares about the Arabs.

Maybe I should have highlighted the whole drivel of a comment ... my point ... remains what I wrote. America trying to teach Arabs about the virtues of Democracy is +not+ why China attacks American computer systems.

Re: Chinese Hackers Infiltrate New York Times Computers

#32
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times.

Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places.

While it should potentially be possible to reflash everything, it is practically cheaper to replace the computers. Do YOU know how to reflash your bios with a trusted version, your GPU firmware, etc?

I don't mean "I know how to look it up on Google, and I'm sure I can do it if needed". This thing is hard to automate and do at scale even if you do know how to do it, especially if not all your computer models are uniform. Depending on how old and varied the hardware is, it is very likely that the economical solution, (assuming you suspect an attacker capable of these feats), is to replace all the computers.

[Though, all the hardware they replaced it with has been, most likely, built and QAd in China. Why would you trust _that_? The rabbit hole goes very deep. Practically too deep for anyone without a billion dollar R&D budget these days]

Re: Chinese Hackers Infiltrate New York Times Computers

#33
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

There's a sort of interesting journalistic gamble at work there. If you're confident that your backup systems are untouchable and you're able to track exactly what is going on, you could gather evidence for a truly ground-breaking story. Unfortunately like usual there's no iron-clad evidence that the Chinese government is behind the hacking, so it's not the story it could have been.

Re: Chinese Hackers Infiltrate New York Times Computers

#34
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Maybe they actually meant every compromised computer OS (i.e. hard disk)?

Maybe they mean OS and BIOS?

Re: Chinese Hackers Infiltrate New York Times Computers

#35
post #31

Earlier quoted context omitted.

jebblue, I believe the point of the paragraph you highlighted is that China feels it's under attack by the United States, not that it cares about the Arabs.

Maybe I should have highlighted the whole drivel of a comment ... my point ... remains what I wrote. America trying to teach Arabs about the virtues of Democracy is +not+ why China attacks American computer systems.

No one said what you're disagreeing with. Try reading the comment again.

Re: Chinese Hackers Infiltrate New York Times Computers

#36

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

When newspapers are making the news, they often write about it in the third person, as if they were writing about any other newspaper. Symantec would not give the NYT a quote on the record about this. It doesn't mean Symantec wouldn't give the NYT details off-the-record. The comment in the article was a response to a question from a reporter, not the Times' security chief. For instance a few weeks ago the Washington…

[deleted]

Re: Chinese Hackers Infiltrate New York Times Computers

#37
post #16

Strange that they would hack NYT when NYT's source for the WenJiaobao article seemed to be public financial records and info from wikileaks (state department cables). What is the strategic gain from hacking NYT? Identify potential other sources (within china) perhaps?

Any decent reporter is going to try to track down additional sources if possible. Conversely Chinese dissidents who want to get word out to the world are much more likely to talk to reporters for the NY Times than to the Chinese government. Therefore this becomes a possible way to identify dissidents.

Even their public outing is good for them. The fact that this story is out there will make it less likely that Chinese dissidents will dare talk to NY Times reporters. Which means that dissidents will have a harder time getting their stories out to the world.

There are other benefits to the Chinese as well. For instance the rich data that the Times has about various US organizations could help them identify people who could become useful informants.

Re: Chinese Hackers Infiltrate New York Times Computers

#38

This story, and the recent RubyGems debacle should be teaching all of us one thing -- assume you can and will be hacked. Do you understand the implications (what data you are going to lose? what credibility?) Do you have a plan to deal with it? Ruby Gems was lucky in that their hack was noisy. The chinese government, as illustrated above, won't play so nice. This is why monitoring and incident response matter. Rememb…

China appears to be engaging in highly sophisticated attacks of the like that major companies need to be aware. The RubyGems fiasco is the result of remarkably incompetent decisions by everyone in the chain of control. The lessons are completely different. In the first, it's that you have to expect that you will be compromised if a determined and capable attacker targets you. In the second, it's that you will be comp…

I don't think the RubyGems people were incompetent. The software serves its core purpose quite well (as a library delivery mechanism) and is quite reliable. But clearly they weren't thinking about security in decision, and what would happen if the repos were compromised.

Let's be honest here - no software is 100% secure. As developers and consumers, the idea that we all review all of the tools in our toolchain for security soundness is absurd. It's like saying that everyone using C made poor decisions because of security flaws in popular libraries (even security ones, like openssl) and therefore all of the C community has no engineering competence.

The fact is, China already has their eyes on GitHub and it's not beyond the planning capability to place backdoors in popular software to suit their future ends.

No matter who the attacker may be, you have to be prepared for the situation where your computers and data are compromised, period.

Re: Chinese Hackers Infiltrate New York Times Computers

#39
post #16

Strange that they would hack NYT when NYT's source for the WenJiaobao article seemed to be public financial records and info from wikileaks (state department cables). What is the strategic gain from hacking NYT? Identify potential other sources (within china) perhaps?

It's not necessarily that the state as a whole found strategic value in this. Could just be one general hoping to impress the Politburo.

TBH, it could be anyone in the chain with sufficient authority to trigger it and hoping to impress someone who can reward him in a tangible manner.

And the sad thing, it is not limited to bureaucracies or government organisations. I have seen bugs that are not fixed, patches that are rejected because it allows someone somewhere to behave heroically in an attempt to impress someone.

When I first experienced this, it was a very real WTF moment from the School of Dilbert Mismanagement.

Re: Chinese Hackers Infiltrate New York Times Computers

#40
post #16

Strange that they would hack NYT when NYT's source for the WenJiaobao article seemed to be public financial records and info from wikileaks (state department cables). What is the strategic gain from hacking NYT? Identify potential other sources (within china) perhaps?

That's not how journalism really works.

More often than not, the journalist or their editor get tips from people in the know (who are trusted NOT to disclose that information to you). Only then does a journalist start combing public records to have a verifiable (and non incriminating) source -- there's just too much to look at without some initial hints.

Perhaps they are looking for information about the tipsters.

Post reply on HN