Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

91–100 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#91
post #77
post #62

Earlier quoted context omitted.

> It's not obvious that they are wrong in that assessment. Any entity with the reach of the United States is naturally going to have connections with all kinds of actors. While the idea of Americans/Zionists/Illuminati/Nibiru pulling the strings behind every major event is no doubt very exciting for conspiracy theorists (eg. I'm getting 2.28 million google hits for ["dalai lama * a cia agent"]), and simpler (ignoring…

http://www.nytimes.com/2012/12/06/world/africa/weapons-sent-... But in the months before, the Obama administration clearly was worried about the consequences of its hidden hand in helping arm Libyan militants, concerns that have not previously been reported. The weapons and money from Qatar strengthened militant groups in Libya, allowing them to become a destabilizing force since the fall of the Qaddafi government. h…

> As for the phrase "conspiracy theory", the implication of that phrase is that conspiracies don't exist.

Exactly this. Or that all theories are not worth our time, since they are just that, "just a theory" (implying there is no proof?), like creationists (of which, America is filled with) like to say.

Re: Chinese Hackers Infiltrate New York Times Computers

#92

Earlier quoted context omitted.

I don't think the RubyGems people were incompetent. The software serves its core purpose quite well (as a library delivery mechanism) and is quite reliable. But clearly they weren't thinking about security in decision, and what would happen if the repos were compromised. Let's be honest here - no software is 100% secure. As developers and consumers, the idea that we all review all of the tools in our toolchain for se…

> I don't think the RubyGems people were incompetent. They sat on a publicly disclosed vulnerability in the YAML parser for a week. The YAML parser itself was ridiculously designed to (essentially) eval() YAML. Those were the two active decisions of incompetence. On top of this, they built a massively central system that is widely trusted with no means of code verification whatsoever. There is no telling what people…

> On top of this, they built a massively central system that is widely trusted with no means of code verification whatsoever.

https://github.com/rubygems/rubygems/blob/master/History.txt

0.8.11 / 2005-07-13: Added Paul Duncan's gem signing patch.

They've had a mechanism for code signing for 8 years. Yes, they could require signing of all gems on the site, but the ability has been there for a long time.

Re: Chinese Hackers Infiltrate New York Times Computers

#93
post #86

From the article: "After surreptitiously tracking the intruders to study their movements and help erect better defenses to block them, The Times and computer security experts have expelled the attackers and kept them from breaking back in. "The timing of the attacks coincided with the reporting for a Times investigation, published online on Oct. 25, that found that the relatives of Wen Jiabao, China’s prime minister,…

> One journalist from China I met long ago in a place far away commented well in advance of the Internet age that if the Communist Party of China ceased censoring mass media that its rule would be gone "in a week." Is that a good thing? Would it's replacement be better? Arab spring has kind of taught us that things aren't as simple as: "Break status quo and things get better".

Arab spring has kind of taught us that things aren't as simple as: "Break status quo and things get better".

I don't think that anyone needed to be taught that. I doubt that we will be able to judge whether the Arab Spring was a success for another ten or twenty years- the immediate aftermath of revolution is always deeply messy.

Not to mention that 'better' is entirely subjective anyway, of course. There are plenty of older Russians that miss the Soviet days, believe it or not.

Re: Chinese Hackers Infiltrate New York Times Computers

#94
post #65
post #56

I like how the whole article is rambling about Chinese hacks yet no strong & clear evidence suggests it's from China, except perhaps from a Chinese IP address. You know what, Chinese computers are also likely to be hacked easily.

I've found that's the case with any hack... for all we know it could be a competing newspaper routing through China. But nationalism/xenophobia trumps reason.

What Chinese newspaper competes with the New York Times, in any meaningful sense? Given that media inside China is heavily censored, and Chinese newspapers publish in a language the vast majority of the US cannot read?

Re: Chinese Hackers Infiltrate New York Times Computers

#95
The executive editor of the Times says “Computer security experts found no evidence that sensitive e-mails or files from the reporting of our articles about the Wen family were accessed, downloaded or copied"... but referring to their forensics they say that the attackers "search[ed] for and grab[bed] Mr. Barboza’s and Mr. Yardley’s e-mails and documents from a Times e-mail server" after cracking their password hashes.

So which is it? Did they download gigs and gigs of mail, but not the ones they were looking for? Or is "found no evidence" doublespeak for "we're pretty sure they got what they were looking for, but the logs had already rolled over on that system, so we have no evidence that they did". Based on the rough timeline presented, this was after they were known, so it may have been their honey-pot server, but the tone of the article suggests that they were not honey-potting them and simply monitoring their progress as they slowly stomped their way through their live network. This begs the question... if they were really monitoring the attackers for months, including watching them grab Barboza and Yardley's e-mails, what are we to make of the PR statement that no relevant or sensitive e-mails were obtained?

Re: Chinese Hackers Infiltrate New York Times Computers

#97
post #88

Earlier quoted context omitted.

Sorry, I should have stated that better. I'm not talking about, "best practice for an advanced attack from an unknown perpetrator". I absolutely agree with you in general. I'm saying that, this particular attacker, is a known, identifiable actor. They have names, they have huge reams of files in manilla envelopes. If you are privy, you get to know their actual names, see photos of them. They have a very specific meth…

Your reply has a lot of very specific information about the attack, attacker, and state of the compromise that I find rather dubious and cannot find in the article. Do you have a source that you would care to share? Furthermore in this case we've been told that the attacker managed to achieve a rather thorough compromise of the network. And managed to persist through multiple attempts to remove them. Even if the atta…

You aren't assuming, you are looking on all machines for IOC's (specifically machines that have been compromised before), and hopefully making use of all that fancy network security monitoring technology you paid entirely too much money for.

And you're monitoring outbound connections to any of the places which are known to be "bad neighborhoods", as well as any other suspicious traffic.

In the gmail example you used, it would indeed be difficult to see that on the network. If that was sent out by some BIOS rootkit it would indeed be very difficult to detect.

I have no idea why we don't see more of that stuff (I suppose you could argue that we wouldn't recognize it even if we did), but that's not been the level of attack associated with these actors.

I suppose the main reason they don't do that is because they don't need to. They will just keep sending malicious emails over and over again until they get someone to click on one.

Or, if the company does a good job with protecting email, they'll compromise another company that partners with the target company (which is what ensnares a lot of small companies today, who are partners with larger defense contractors) and exploit a trust relationship there.

It might just be that the five guys they have who can write BIOS rootkits are all busy being used on projects that have more strategic importance. The shortage of good programmers isn't just a problem in the west.

Re: Chinese Hackers Infiltrate New York Times Computers

#98
post #86

From the article: "After surreptitiously tracking the intruders to study their movements and help erect better defenses to block them, The Times and computer security experts have expelled the attackers and kept them from breaking back in. "The timing of the attacks coincided with the reporting for a Times investigation, published online on Oct. 25, that found that the relatives of Wen Jiabao, China’s prime minister,…

> One journalist from China I met long ago in a place far away commented well in advance of the Internet age that if the Communist Party of China ceased censoring mass media that its rule would be gone "in a week." Is that a good thing? Would it's replacement be better? Arab spring has kind of taught us that things aren't as simple as: "Break status quo and things get better".

As one American once put it, "The boisterous sea of liberty is never without a wave."

In the United States, over 200 years in, it is still very much so the American experiment. Its success dependent on all sorts of radical notions about human nature.

Turbulence in brand new democracies is not evidence of failure. It is to be expected. Democracy is hard.

Re: Chinese Hackers Infiltrate New York Times Computers

#99
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

The CPC simply wanted the names of whoever was leaking their corruption to the foreign press to 'fix the leak' by rounding these people up for unpleasant interrogation.

lol western orchestrated arab spring in China. I don't think so.

Hey China, you guy's stop buying our debt, floating our consumer economy with a giant pool of near slave labor we can exploit, and stop giving us billions for our resources or we will promote a rebellion so all your nuclear weapons can wind up in the hands of breakaway republics that might be hostile like nuclear Uyghurstan

Re: Chinese Hackers Infiltrate New York Times Computers

#100
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

Very good points! >> it does not see a line between NGOs, the NYT/WSJ, and the US government. Aren't we all doing the same mistake when we refer to them? All we know is that the attacks came from China, so we safely assume it came from the Government? Why is it that each time something comes from China (a country with approximately 5 time more people than the US - source Wikipedia) we blame their government and treat…

> Aren't we all doing the same mistake when we refer to them? All we know is that the attacks came from China, so we safely assume it came from the Government?

I think the reason they see all of our institutions as one head of the same beast is that in China things really do work that way.

Of course, as parent points out, it's not completely false to see the United States that way, although our institutions collaborate in a more anarchic and haphazard fashion than the Chinese leadership may realize.

Post reply on HN