Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

171–180 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#171
post #154

Earlier quoted context omitted.

Again, all you've done is repeat the same explanation for the Great Firewall and censorship of news as soon as it starts to appear to be capable of "fomenting dissent". It's worth noting that many in China do not share your view, and we have the weibo messages to prove it. While there is certainly a good bit of animosity aimed at the US (both well-sourced and born of invented stories), it's ridiculous to claim that e…

the complete lack of agency you seem to believe the people that actually live in Egypt, Tunisia, Libya, Syria, etc had in deciding to revolt in the first place. http://www.guardian.co.uk/world/2012/oct/21/barack-obama-ara... Egypt's revolution provided the first hurdle. Obama was criticised for backing stability as the drama of Tahrir Square unfolded. But on 1 February came his call for Mubarak to step down "now". As…

While I totally understand and don't debate that the US has supported many of the revolutions in the Middle East, there is a fundamental difference between supporting and creating said movements.

As far as I can tell, the US has been a follower, not a leader, in these movements. Sure, activists have been trained in the US. That's been the case for decades though, and it took organization and significant change and economic pressure — not brought about by the US — in the region to create an the conditions for change.

Re: Chinese Hackers Infiltrate New York Times Computers

#172
post #66
post #59

Earlier quoted context omitted.

You may believe reinstalling the OS is enough I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. I can accept however that the Times may well have been running 10 year old PCs, with manual IT management processes, and outdated security software, and that replace…

> verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. Can you back up that claim with reference to a system that does that? EVERY single management system I can think of trusts the system to report its status. You can't trust a compromised system to report its status. Assume you have 5,00…

Good point, as in theory both the BIOS and the BIOS flash update routine could be replaced/virtualized... confirming a successful update even though the update was ignored.

Re: Chinese Hackers Infiltrate New York Times Computers

#173
post #154

Earlier quoted context omitted.

Again, all you've done is repeat the same explanation for the Great Firewall and censorship of news as soon as it starts to appear to be capable of "fomenting dissent". It's worth noting that many in China do not share your view, and we have the weibo messages to prove it. While there is certainly a good bit of animosity aimed at the US (both well-sourced and born of invented stories), it's ridiculous to claim that e…

the complete lack of agency you seem to believe the people that actually live in Egypt, Tunisia, Libya, Syria, etc had in deciding to revolt in the first place. http://www.guardian.co.uk/world/2012/oct/21/barack-obama-ara... Egypt's revolution provided the first hurdle. Obama was criticised for backing stability as the drama of Tahrir Square unfolded. But on 1 February came his call for Mubarak to step down "now". As…

I think this comes close to accusing an umbrella seller of conspiring with the weather because she happens to push umbrellas when it rains and switches to selling lemonade when it's hot. I think the NYT and Salon both have readerhips and understand them and try to ride waves of interest.

I think there are coincidences and occasionally there could be coercion (don't publish on account of national security) but I do not see it as "an organ of the gov't". It's self interest. In other words it's not comparable to XinHua News, as you're implying.

W/re ME revolutions. All those examples were in places where the outcome was nearly inevitable (needed some logistical/moral support) and the US/EU didn't want to appear to be on the 'wrong side' of history. Witness CN and RU. Specially RU tends to pour arms into those conflicts to upset the West, to some extent --I don't fully understand their intent but they are unsuccessful in much but delaying the inevitable.

Re: Chinese Hackers Infiltrate New York Times Computers

#174
post #155
post #124

Earlier quoted context omitted.

I think you're overstating your case. I would say the "228 incident" [1] would counter your assertion that rallying cries (political causes) are anathema or that people don't care about authoritarianism as they might seek over ways to overcome the difficulties presented by such (following your waves in the ocean). I think the healthy political involvement (even antagonistic approach) to politics in, practically Chine…

The political ecology of Taiwan when 228 incident occurred is largely different than the current (smoggy and turbid) one in Mainland China. And in the late 1980s, KMT regime lost its vitality(, but still holds some kinda moral integrity, )as the older generation who fled from the Mainland to Taiwan around late 1940s died out or retired, allowing a transformation of the political session there. However, in Mainland Ch…

One of my implied points was that democracy is not 'foreign' and uninteresting to the Chinese, as implied by the OP. Prior to Mao's consolidating power, there were lots of CN intellectuals who were very excited about the prospects for CN and democracy. Song, Jiaoren was one such enthusiast of democracy who was assassinated prior to assuming CN Premiership[1]

It reminded me somewhat of the Japanese justification for protecting domestic ski manufacturers from EU mfgs: "Japanese snow is different".

[1]http://www.economist.com/news/christmas/21568587-shot-killed...

Re: Chinese Hackers Infiltrate New York Times Computers

#175

Earlier quoted context omitted.

What? Why? I happily wish for the day that the Great Firewall gets shut off, but in my book, the Chinese Government has been fantastically successful. The sheer number of people brought out of poverty in the last few decades is mind-boggling. In 1981, 85%[1] of China's population (that's 850 million people[3]) lived on I'm confident that we'll eventually see reform in China. It'll take a few decades. People are still…

It might be worth taking a quick glance at those articles again to make sure you're making a meaningful comparison. The US poverty figures you quote are for an income of $23k/yr, or ~$11/hr. In that chart you quote for China, you notice that even the 71% mark only gets you up to $5/ day (so $0.60/hr).

Correct. The number of people living in the US under the UN definition of poverty is ~0

Re: Chinese Hackers Infiltrate New York Times Computers

#176
post #146

Earlier quoted context omitted.

Read the top comment that started this whole conversation. It's foundational to the whole thread. There is no thread without that claim.

If you read my comments above, you can see that I did indeed read the top comment. All that is provided is the assertion that all (american?) organizations questioning the Chinese government are apparently seen as arms of the United States's campaign against China, which explains why the Chinese government would make this move. What I was asking for any specific evidence that would preclude the much more obvious expl…

@magicalist: I agree with you (i.e., that in this case the obvious explanation is operative, and furthermore that the Chinese government is capable of discriminating between the actions of the US government and those of the NYT) but there's no sense arguing the point.

To me, this back-and-forth is reminiscent of "lefter-than-thou" debates I have witnessed before, and they all end up right where they started.

One caveat: it's quite possible that there are US government sponsored probes of Chinese sites, that we are not aware of, and that may be quite extensive and outrageous (to the Chinese government). So this skirmish with the NYT may be part of that larger cold war. This is not the same as saying (as the original comment did) that the Chinese government sees the NYT as a proxy of the US government.

Re: Chinese Hackers Infiltrate New York Times Computers

#177

It will be interesting if we see the first use of national firewalls used to keep a nation-state boxed in from the outside. I'm not sure what the 21st century equivalent of a blockade or siege is, but that would come close.

In a manner of speaking, isn't that what the Great Chinese Firewall is?

Re: Chinese Hackers Infiltrate New York Times Computers

#178
post #74

Earlier quoted context omitted.

How likely do you think a Chinese spring would be? It's unfortunate that we don't get more foreign perspective on HN and Reddit - I hope you comment more.

What? Why? I happily wish for the day that the Great Firewall gets shut off, but in my book, the Chinese Government has been fantastically successful. The sheer number of people brought out of poverty in the last few decades is mind-boggling. In 1981, 85%[1] of China's population (that's 850 million people[3]) lived on I'm confident that we'll eventually see reform in China. It'll take a few decades. People are still…

I didn't ask the question rhetorically. I agree with you, but it's nice to get different perspectives as well.

Re: Chinese Hackers Infiltrate New York Times Computers

#179

Jeez, NYT. 2FA much?

Most valuable point in this otherwise very interesting discussion.

MFA neutralizes most hacker threats. Organizations like the NYT that are sensitive should implement them. I know we do for banking, per industry standards (FFIEC). Fraudsters aren't about to defeat RSA tokens or multiple channels of authentication in the near future, as far as I know. It's just too logistically difficult and an order of magnitude harder to then compromise the MFA servers (via MITM or otherwise), etc. If implemented correctly, they make access to individual personal data significantly more distributed and difficult to breach.

Is MFA for e-mail each time extremely annoying? Probably. But logging into a system with just a username and password for a new ip address should not be the standard for authentication. This has got to be the solution eventually, and one which will essentially de-emphasize nation states or any large organizations from surveilling lists of accounts.

Re: Chinese Hackers Infiltrate New York Times Computers

#180
post #159

All this focus on the sophistication of the Chinese hackers irritates me slightly. Reading between the lines, it seems the NYT would likely have weathered this "sophisticated" attack a lot better if they had observed a few simple security best practices: - Salt your password hashes (rendering rainbow tables inert) - Train your staff NOT to open attachments from unknown sources (especially if you've just written an in…

> Salt your password hashes As brown9-2 mentions in his reply, it was a Windows Domain Controller > Train your staff NOT to open attachments from unknown sources Spear phishing attacks are more sophisticated than that. They aren't sending .EXE files. The two most common attachments are RTF[0] and PDF[1], or a link in the email body to a website that will attempt a drive-by download. These emails are composed in a way…

Re: Windows Domain Controllers - I wasn't aware they didn't have the ability to salt hashes (I last used domain controllers and active directory back in the Win2K days). I could be facetious and say "move to open ldap, samba 4, zarafa and an open stack" but I realise that isn't being very helpful :)

Re: spear phishing attacks

All it takes is a bit of training and common sense to significantly reduce the effectiveness of this vector. Examples:

1). Remove Flash and, if possible, Java from all the desktop PCs and work laptops. [0]

2). Use a non-Adobe product for reading PDFs

3). Standardise on one browser (e.g. Chrome), force all users to use it and have someone in IT be responsible for tracking all security announcements from the manufacturer.

4). Ban browser addons

5). Train staff to hover over any link in an email and verify where it's going to before clicking it (and to be especially vigilant if the url purports to be from a well known website i.e. amazon, twitter etc)

6). Ban staff from clicking on any link rendered by an url shortening service.

7). Ban staff from opening any attachment from a new/unrecognised email source (regardless of file format).

8). Re-work your provisioning, network architecture and file storage setup so that it becomes quick and painless to regularly (even randomly) format user's machines and install a clean image.

9). If feasible, configure all user's email programs to render emails in plain text and encourage staff to avoid checking their private accounts on work provided machines (especially high profile users).

10). Ban users from connecting non-work appliances to the network. Use MAC filtering if you have to enforce this.

Re: firewalling

That's why I said block everything going out and only white list a very limited number of _processes_ not ports. Do it via the native software firewall or something like TinyWall.

[0] If a user really needs either of these, they can apply for special dispensation and IT can (after making sure the user is security trained) give them a locked down virtualbox instance they can launch from the desktop. If possible this could also be scripted so that it gets deleted every day or week and re-provisioned from a "gold" vm image.

Some attacks would still make it through despite the above but that's life. At the very least it raises the bar needed for a successful attack, making vanity hacks (like in the case of the latest one on the NYT) less common.

Post reply on HN