Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

51–60 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#51
post #23

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

About Symantec's technology, it is worth noting that antivirus scans are based on identifying malware in one place, then being able to recognize that malware everywhere. This does not particularly help you recognize malware that was custom made to only be installed in one location. Particularly not when the people who were making that malware themselves have access to your anti-virus scans prior to deployment and can…

But see, the thing is, that's not what it says on the box. http://us.norton.com/antivirus/

"It's okay to blink, because we never do – SONAR technology and live 24x7 Threat Monitoring watch over your PC for any suspicious behavior to quickly identify threats."

"Protection from the future, available today – our exclusive reputation and behavior antivirus technology are so advanced that they can stop online threats that bad guys haven't even created yet."

Re: Chinese Hackers Infiltrate New York Times Computers

#52
post #43

Earlier quoted context omitted.

Maybe they mean OS and BIOS?

And network card firmware. And graphics card firmware. And in some cases, also ILO firmware, DVD drive firmware, and maybe a few other pieces. If you trust your IT supplier, and the equipment is a two years old, it's probably more economical to replace everything than try to fix it. But why would you trust your IT supplier - who sources all their stuff from China in the first place?

All of those things are technically true, but don't match up with the M.O. of the perpetrators in question (they're not actually using any super-fancy BIOS rootkits).

Also, the remediation process is exactly that, a process. It involves a pre-planned, direct remediation effort at a specific time, after which, egress traffic is monitored to look for any other outbound connections that pop up that were missed in the first "sweep." Passwords are all changed.

You "rinse, lather, repeat" that process until you stop seeing the communications. It can take several times before you sound an "all-clear".

Re: Chinese Hackers Infiltrate New York Times Computers

#53
post #28

Earlier quoted context omitted.

>> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions and prominent neocons (like Fukuyama in that WSJ article) were/are calling for similar actions in China. This is why the Chinese government feels that it is under attack by the United States The Chinese don't give a rat's hoot about the Arabs. They attack American compute…

You are also categorically incorrect. The Chinese central government most certainly cares about Arabs, as they share a disputed border with several majority Muslim countries, including Pakistan and Afghanistan. Moreover they have repressed domestic minority populations who are predominantly Muslim. The extent to which there are Islamic unification or nationalist movements (which are often tied in with movements in th…

I'm confused... What's the relationship between Arabs and Pakistan/Afghanistan?

There's a difference between being Arab and being Muslim. The greatest Muslim countries are not Arab (Indonesia, Turkey, Iran, Pakistan).

"Islamic unification" is by definition the opposite of "nationalist movements", and is very unlikely to happen. I can guarantee that Saudis, Pakistanis, Morrocans and Turks have way too little in common to even consider unification.

Source: I'm a non-Muslim from the Middle East.

Re: Chinese Hackers Infiltrate New York Times Computers

#55
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

> This is why the Chinese government feels that it is under attack by the United States, and it does not see a line between NGOs, the NYT/WSJ, and the US government,

Ironically, you are assuming the same thing about China.

Re: Chinese Hackers Infiltrate New York Times Computers

#57
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

As a Chinese, I would say the Chinese government is worried about 'Arab Spring', but that's not why they attacked NYT this time. The 'Great firewall' was built to prevent any uprising similar to 'Arab spring' from being started.

Re: Chinese Hackers Infiltrate New York Times Computers

#59
post #32
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times. Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places. While it should potentially be possible to reflash eve…

You may believe reinstalling the OS is enough

I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure.

I can accept however that the Times may well have been running 10 year old PCs, with manual IT management processes, and outdated security software, and that replacement may have been overdue and economically more viable.

Post reply on HN