Live data from Hacker News

Chinese hack U.S. Weather systems, satellite network

washingtonpost.com

41–50 of 71 posts

Re: Chinese hack U.S. Weather systems, satellite network

#41
post #14

I always appreciate how the US are able to pin every network compromise directly back to China. And not just China but the Chinese government in particular. Almost like VPNs, proxies, TOR, compromised machines, botnets, or similar do not exist in this arena and that a reverse DNS lookup will tell them 1337.mss.gov.cn. When the US talk about cybersecurity/"cyber wars" in general they're talking about something more ak…

Having hacked Google, Juniper, Symantic, Morgan Stanley and countless USGOV sites - why not hack NOAA? Its not as if there will be any USGOV response. No sanctions. No demarche of which I'm aware. No counter-attack that has been publicized by China. Turning the other check is not a valid strategy in a prolonged conflict.

Turning the other cheek is an OK strategy when the damages are not terribly high and the political and economic costs of any reaction would be worse than that of the attacks. In fact, improving defensive security and not responding to cyber-warfare except in cases that imminently endanger human lives or defense capabilities would probably be the sounder policy. That said, that's far from what the U.S. government is doing, the U.S. government engages in espionage and arguable cyber-warfare against nations it's not in conflict with (including China) with alarming regularity. The Snowden leaks give us an idea of how a fraction of those operations looked more than 6 years ago...

If it were me, I'd just issue a formal letter thanking the Chinese government and their people for spending their own taxpayer's money pen-testing U.S. infrastructure and ensuring security best practices are followed ;p (yes, I am being tongue-in-cheek, speaking of cheeks...)

Re: Chinese hack U.S. Weather systems, satellite network

#42
post #22
post #21

Earlier quoted context omitted.

That doesn't mean that it's actually Chinese users doing anything though. China has a lot of software piracy in their culture, where piracy is, malware and botnets are rife.

I find that debatable, they are still guilty to some extent because of their inaction to do anything (effective) against these botnets. whether 'action' would refer to users installing a decent anti-virus, or an ips blocking and isolating obviously infected hosts. Of course, this is a whole different level of culpability than if they were actually condoning large scale attacks on other countries infrastructure. The f…

http://en.wikipedia.org/wiki/Usage_share_of_operating_system...

17.18% of all desktop OS-es connected to the internet are Windows XP, the version for which Microsoft doesn't publish updates. Most of these computers are in China. Also "in 2009, approximately 80% of software sold in China was pirated."

The average weekly income of a Chinese worker is around 100 USD. He is not going to buy new software even if it costs the same as in the US. It typically costs even more.

Don't be surprised bots have easier targets there.

Re: Chinese hack U.S. Weather systems, satellite network

#43

I never will understand how this spying stuff always is allowed to happen. I know every government does is, but I find it unbelievably dishonest. What kind of relationship is that? I would intuitively see any spying as an act of war, especially if supposedly friendly countries do it.

Yeah, but what are they going to do about it. Sanctions that hurt you just as much? Retaliate in kind? War? I'm not sure its understood yet what the appropriate response should be, or what the bounds of the consequences are. A lot of people worry about Government sponsored hacking taking the gloves off, and fucking with commercial infrastructure directly and relentlessly. The amount of leaks and compromises we see today suggests this could be economically catastrophic.

Re: Chinese hack U.S. Weather systems, satellite network

#45
post #42
post #22

Earlier quoted context omitted.

I find that debatable, they are still guilty to some extent because of their inaction to do anything (effective) against these botnets. whether 'action' would refer to users installing a decent anti-virus, or an ips blocking and isolating obviously infected hosts. Of course, this is a whole different level of culpability than if they were actually condoning large scale attacks on other countries infrastructure. The f…

http://en.wikipedia.org/wiki/Usage_share_of_operating_system... 17.18% of all desktop OS-es connected to the internet are Windows XP, the version for which Microsoft doesn't publish updates. Most of these computers are in China. Also "in 2009, approximately 80% of software sold in China was pirated." The average weekly income of a Chinese worker is around 100 USD. He is not going to buy new software even if it costs…

Windows 7 is just as easy to pirate so the logic is not solid there.

Re: Chinese hack U.S. Weather systems, satellite network

#46

Earlier quoted context omitted.

Of course if you were an evil genius bent on destroying the US by sending a massive hurricane into the eastern seaboard, your first step would be to disable the ability to see it coming ... :-)

Nature. What better secret ally to start a war with?

Cows. No one suspects something so docile and they outweigh us as a species by about 50%. We bred them to be tasty, but they were the ones using us.

Re: Chinese hack U.S. Weather systems, satellite network

#47

I don't know who this Wolf guy is, but he's absolutely right: if we are in the government, and we have a breach, and we're working on it, we have an obligation to fess up. (Unless there's some kind of counter-intelligence operations underway) We can all sit back in our comfy chairs and debate whether it really is China or not, whether various networks are secure or not, or how much various agencies can store (and the…

I think you're right that an open attitude towards security breaches is essential for a healthy security ecosystem. However, in practice, fessing up in public during an investigation will rarely happen. Security incident responses are some of the most-hushed processes, even inside otherwise open organizations.

That's because you want to find and close the vulnerabilities before publicizing them. Otherwise, by publicizing, you invite attacks that will (a) multiply the noise you have to sift through to complete the investigation and (b) potentially create new incidents, at a time when you are already in a crisis (the current attack & investigation).

So most security departments will only talk about what happened after the fact, when it's all been tidied up again. But even then, the habit of secrecy has already been established. It's a constant struggle to bring openness to a process where secrecy is a short-term advantage. If you want an informative accounting of what happened, I think you need to add it to the incident response process.

For example (simplified for illustration)

1. Notice an intrusion

2. Capture information (logs, vulnerabilities used, etc)

3. Secure systems that have been compromised

4. Prevent future intrusions within the organization

Need to modify 4 (or add 5)

5. Publish to help other orgs also prevent intrusions.

But other orgs may hate you for that, because in the process of publishing, you have exposed their lax practices that (in hindsight) used to be your lax practices ...

Re: Chinese hack U.S. Weather systems, satellite network

#48
post #22
post #21

Earlier quoted context omitted.

That doesn't mean that it's actually Chinese users doing anything though. China has a lot of software piracy in their culture, where piracy is, malware and botnets are rife.

I find that debatable, they are still guilty to some extent because of their inaction to do anything (effective) against these botnets. whether 'action' would refer to users installing a decent anti-virus, or an ips blocking and isolating obviously infected hosts. Of course, this is a whole different level of culpability than if they were actually condoning large scale attacks on other countries infrastructure. The f…

Ever heard of PPStream or PPTV? Well, good news is that both software open some sort of transparent http proxy listening on 0.0.0.0, obviously it's for helping the p2p.

Hint: port 9415

Re: Chinese hack U.S. Weather systems, satellite network

#49
post #45
post #42

Earlier quoted context omitted.

http://en.wikipedia.org/wiki/Usage_share_of_operating_system... 17.18% of all desktop OS-es connected to the internet are Windows XP, the version for which Microsoft doesn't publish updates. Most of these computers are in China. Also "in 2009, approximately 80% of software sold in China was pirated." The average weekly income of a Chinese worker is around 100 USD. He is not going to buy new software even if it costs…

Windows 7 is just as easy to pirate so the logic is not solid there.

I find it very hard to believe myself, because when you can obtain for free, why not go for the latest, shiniest version? But the reality is, most of Chinese computers are still stuck with XP, whatever the reason is.

Re: Chinese hack U.S. Weather systems, satellite network

#50
post #33

I always appreciate how the US are able to pin every network compromise directly back to China. And not just China but the Chinese government in particular. Almost like VPNs, proxies, TOR, compromised machines, botnets, or similar do not exist in this arena and that a reverse DNS lookup will tell them 1337.mss.gov.cn. When the US talk about cybersecurity/"cyber wars" in general they're talking about something more ak…

These articles always make me wish I could see the Chinese equivalent. Are the newspapers in Beijing just full of stories about US "cyber attacks" on Chinese infrastructure?

No. There are plenty of articles in China about how an evil empire the US is, but mostly on how it misuses its military, financial and cultural power, how it instigates unrest in other countries, how its democracy is a fake one, etc. Seldom if any mentions US hacking.
Post reply on HN