Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

81–90 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#81
From the article:

"After surreptitiously tracking the intruders to study their movements and help erect better defenses to block them, The Times and computer security experts have expelled the attackers and kept them from breaking back in.

"The timing of the attacks coincided with the reporting for a Times investigation, published online on Oct. 25, that found that the relatives of Wen Jiabao, China’s prime minister, had accumulated a fortune worth several billion dollars through business dealings."

As a student of the language, history, culture, current politics, and future prospects of China since 1975, I had better comment on how significant this is. The effort by operatives based in China (that much is indisputable from the computer forensics involved in this case) is deeply hostile to the press freedom that is a fundamental difference between China and the United States. Under usual principles of international law, China has the responsibility to keep actors on its territory from launching harmful attacks on the territory of another country, unless it is interested in declaring war. Prior restraint of news media is routine in China, and accounts for a great deal of the public ignorance in China that keeps the current dictatorial regime in power, but it is not at all a friendly act toward the United States. The United States government has everything to gain and essentially nothing to lose by every other government on the planet being exposed to more press coverage of national leaders and their possibly corrupt activities. In this regard, the current regime in China and any government of the United States under the Constitution have inherently differing interests.

The national interest of the common people of China, on the other hand, would be best served by freeing the news media there from the prior restraint and censorship that now exist there. If everyday people in China knew better what is really going on in the country, and what their leaders are doing, China could make greater progress in overcoming persistent poverty and enjoy more peaceful relations with countries all around the globe. Right now, the masses in China are not given the choice of knowing what's going on through uncensored mass media, nor are they given the choice of free and fair elections for choosing national leaders.

My best hope is that this effort to scare off the New York Times from honest reporting about China will fail as efforts by the Church of Scientology to frighten away investigative journalists are also increasingly failing.

http://tonyortega.org/2013/01/29/more-signs-of-scientologys-...

A lot of journalists would like nothing better than to write even more tough stories about what is really going in China, based on unfettered reporting with Chinese-speaking sources in the country. One journalist from China I met long ago in a place far away commented well in advance of the Internet age that if the Communist Party of China ceased censoring mass media that its rule would be gone "in a week." The time will come when the Party can't shut down all the channels of information flowing into China and within China, and then the Party will have to face elections or face a revolution.

AFTER EDIT: The first reply asked a fair question, which is whether or not there is a basis for thinking that the Communist Party of China losing power in China would be a good thing. My answer is yes. I lived in Taiwan both under the KMT dictatorship and under its current democratic regime (which now again has the KMT as the ruling party, after an election). I have also been to Hong Kong. Chinese people can adapt well enough to democracy. In general, all around the world, freedom and democracy have their defects, but they are generally better for the people who live with them than the alternative. Precisely because Taiwan is available for an example, I think a transition to democracy in China could be especially smooth. It is regrettable that although there are Muslim democracies, the first attempts at specifically Arab democracies so far are nascent and struggling. The democratic transition in Arab countries will be harder in the short term for lack of culturally similar examples, but I think that too will be a long term benefit to the common people of the Arab lands.

AFTER ONE MORE EDIT: Anyway, it shouldn't be the censorship and armed force of the Party that restricts the people's right to choose their national leaders.

Re: Chinese Hackers Infiltrate New York Times Computers

#82
post #32
post #22

"It then replaced every compromised computer and set up new defenses in hopes of keeping hackers out." I hope that's just poor reporting, or does the Times' IT department really have that poor an understanding of how computers work? No wonder they got pwned. And I'm not buying the "we gave them free reign for four months on purpose" line. It makes no sense.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times. Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places. While it should potentially be possible to reflash eve…

Uh, reprovision the VMs, reinstall your packages, QA everything and be back up and running in a couple hours. At least that's what they could do if they had a competent SE team running things.

Re: Chinese Hackers Infiltrate New York Times Computers

#83
post #76

Earlier quoted context omitted.

All of those things are technically true, but don't match up with the M.O. of the perpetrators in question (they're not actually using any super-fancy BIOS rootkits). Also, the remediation process is exactly that, a process. It involves a pre-planned, direct remediation effort at a specific time, after which, egress traffic is monitored to look for any other outbound connections that pop up that were missed in the fi…

> but don't match up with the M.O. of the perpetrators in question Oh, the hubris. This statement may be true (and probably is), but the perpetrators might also be running a BIOS rootkit at the same time - unless you actually pull the bios chip out and read it in another machine, you cannot tell. If you haven't already, read Ken Thompson's "Reflections on Trusting Trust", and mentally replace every occurrence of "C c…

I don't disagree with anything you've written, but remediation from these attacks almost never involves replacing any of the hardware (with the possible exception of when a laptop belongs to an executive, and it becomes easier to just set them up with a new one and swap it out).

Re: Chinese Hackers Infiltrate New York Times Computers

#84
post #78
post #55

Earlier quoted context omitted.

> This is why the Chinese government feels that it is under attack by the United States, and it does not see a line between NGOs, the NYT/WSJ, and the US government, Ironically, you are assuming the same thing about China.

Because that's actually how it IS in China. China is a giant corrupt honeycomb. There are blurred lines between corporation/government. Corporations are often a face for government interests. It's totally corrupt, and everybody knows that the face of an organization is not the actual motives behind the organization. A single Chinese clan will control multiple branches of government and multiple corporations. They all…

And the only people who can do this are the government and corporations? Surely not all traffic leaving China is accounted for by the government.

Re: Chinese Hackers Infiltrate New York Times Computers

#85
post #67
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions Wait, what? Do you have any evidence to support that?

Yes, please read the article I linked:

http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante...

  Title: US Groups Helped Nurture Arab Uprisings
Here is another.

http://www.nytimes.com/2012/12/06/world/africa/weapons-sent-...

  The Obama administration secretly gave its blessing to arms 
  shipments to Libyan rebels from Qatar last year, but 
  American officials later grew alarmed as evidence grew that 
  Qatar was turning some of the weapons over to Islamic 
  militants, according to United States officials and foreign 
  diplomats.

  But in the months before, the Obama administration clearly 
  was worried about the consequences of its hidden hand in 
  helping arm Libyan militants, concerns that have not 
  previously been reported. The weapons and money from Qatar    
  strengthened militant groups in Libya, allowing them to 
  become a destabilizing force since the fall of the Qaddafi 
  government.

Re: Chinese Hackers Infiltrate New York Times Computers

#86

From the article: "After surreptitiously tracking the intruders to study their movements and help erect better defenses to block them, The Times and computer security experts have expelled the attackers and kept them from breaking back in. "The timing of the attacks coincided with the reporting for a Times investigation, published online on Oct. 25, that found that the relatives of Wen Jiabao, China’s prime minister,…

> One journalist from China I met long ago in a place far away commented well in advance of the Internet age that if the Communist Party of China ceased censoring mass media that its rule would be gone "in a week."

Is that a good thing?

Would it's replacement be better?

Arab spring has kind of taught us that things aren't as simple as: "Break status quo and things get better".

Re: Chinese Hackers Infiltrate New York Times Computers

#87
post #56

I like how the whole article is rambling about Chinese hacks yet no strong & clear evidence suggests it's from China, except perhaps from a Chinese IP address. You know what, Chinese computers are also likely to be hacked easily.

I agree that the Times can't prove absolutely that the Chinese government was behind the attack. But they do provide a few strong pieces of evidence: (1) the university computers used in this attack were the same machines used in past attacks that were linked to China's military; (2) the attacks coincided directly with policy issues affecting Chinese officials. The article also had a relatively even-handed tone. It d…

the two evidence from NYT made a meme in Chinese Interwebs:

蓝翔 hacked Google.

Re: Chinese Hackers Infiltrate New York Times Computers

#88
post #71

Earlier quoted context omitted.

The MO is that they are a state attacker, not a one trick pony. Until proven otherwise, you should assume that in addition to what you know they did, they did everything you can think of that is within their known capabilities. Super fancy BIOS rootkits are not outside their known capabilities. Also monitoring egress traffic is easier said than done. For example you could have a special gmail account that you connect…

Sorry, I should have stated that better. I'm not talking about, "best practice for an advanced attack from an unknown perpetrator". I absolutely agree with you in general. I'm saying that, this particular attacker, is a known, identifiable actor. They have names, they have huge reams of files in manilla envelopes. If you are privy, you get to know their actual names, see photos of them. They have a very specific meth…

Your reply has a lot of very specific information about the attack, attacker, and state of the compromise that I find rather dubious and cannot find in the article. Do you have a source that you would care to share?

Furthermore in this case we've been told that the attacker managed to achieve a rather thorough compromise of the network. And managed to persist through multiple attempts to remove them. Even if the attack proceeded by the rules that you describe, it would be foolhardy to assume that they were not subjected to the advanced campaign.

Re: Chinese Hackers Infiltrate New York Times Computers

#89
post #2

"Security experts found evidence that the hackers stole the corporate passwords for every Times employee and used those to gain access to the personal computers of 53 employees" Does this mean the NYTimes is storing passwords in plaintext?

they probably found the place where windows stores the passwords. All 8 character passwords under the unsalted scheme (NTLM) used by Microsoft can be cracked within minutes via use of rainbow tables. Even easier if LANMAN passwords are enabled.

Re: Chinese Hackers Infiltrate New York Times Computers

#90
post #32

Earlier quoted context omitted.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times. Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places. While it should potentially be possible to reflash eve…

Uh, reprovision the VMs, reinstall your packages, QA everything and be back up and running in a couple hours. At least that's what they could do if they had a competent SE team running things.

If you believe that, than you are not part of a competent team, and do not understand enough to evaluate anyone's competence. See, e.g. http://en.wikipedia.org/wiki/Blue_Pill_%28software%29 - despite the (justified) criticism listed there, the principle holds.

According to the Wikipedia article, tptacek / matasano says he can detect it, and if tptacek says, I'll take his word for it. (And yes, timing attacks are inherently hard to fake, though -- since this is a targeted attack, there could be a blue pill version that targets a specific matasano detector version. Continues ad absurdum)

Regardless - the advice given by parent is useless against a BIOS or deepest-level hypervisor rootkit.

A note to all armchair security people: Security is not just another engineering field like (say) networking, UI or databases: It is pervasive and very different:

Engineering is the practice of making sure that whatever is in the spec, works.

Security is the practice of making sure that anything outside the spec, doesn't work (unless it is desirable for some reason, in which case it should be added to the spec).

Post reply on HN