Live data from Hacker News

Chinese Hackers Breach U.S. Navy Contractors

wsj.com

11–20 of 65 posts

Re: Chinese Hackers Breach U.S. Navy Contractors

#11
post #5

A slightly different headline would be "Navy has lousy security practices especially regarding contractors" I'm pretty sure the CIA and NSA do their utmost to spy as much as they can on the Chinese and Russian Navy.

@snowden sold us out to china when he fled in 2013, by revealing details about our spying operation on them. apparently they bolstered their defenses after this, due to this information, meanwhile stepping up offensive attacks against the United States

According to the NYTimes they also killed over a 100 CIA assets in China. So we went in the dark for a while as the whole batch was compromised. We didn’t retaliate either. The Snowden thing wasn’t the cause of that but I bet the Snowden thing compromised other assets.

Re: Chinese Hackers Breach U.S. Navy Contractors

#12
post #5

A slightly different headline would be "Navy has lousy security practices especially regarding contractors" I'm pretty sure the CIA and NSA do their utmost to spy as much as they can on the Chinese and Russian Navy.

Excellent job moralizing, comrade.

What exactly is immoral about spying on a foreign nation state?

We do it to them, they do it to us, what exactly is the issue? Is there some no-spying gentleman's agreement that's being violated, here?

Re: Chinese Hackers Breach U.S. Navy Contractors

#13
Not surprising at all. What's surprising is that it's taken this long to appear in the news.

While in the shipyards for maintenance I would stand watch and was responsible for letting people on/off a large ship. Most were contractors. The only requirement was that they had a contractor badge. How did we tell this was a valid badge? Good question. You'd think there would be some sort of master list of people with badges we could check and verify.

Not quite. Every contractor had their own style of badge and we had no way of knowing if any particular badge was real or not. Want a "valid" badge? Buy a badge printer. You're in.

We had people we didn't even know just show up to install systems on board that nobody was able to verify were supposed to be there or not. It was a little better with the classified systems, but you can imagine that any verification of contractor IT systems was non-existent.

Re: Chinese Hackers Breach U.S. Navy Contractors

#14
post #3

> The victims have included large contractors as well as small ones, some of which are seen as lacking the resources to invest in securing their networks. That does not compute. If they want to become a defense contractor, it stands to reason not spending resources on securing their network (and educating their employees against phishing attacks) is a non-starter.

Are you serious? It should be pragmatic and taken seriously, but it isn't. As for phishing attacks, try it three times in a row and, if I recall correctly you get results of 50 percent success.

Re: Chinese Hackers Breach U.S. Navy Contractors

#15
post #11

Earlier quoted context omitted.

@snowden sold us out to china when he fled in 2013, by revealing details about our spying operation on them. apparently they bolstered their defenses after this, due to this information, meanwhile stepping up offensive attacks against the United States

According to the NYTimes they also killed over a 100 CIA assets in China. So we went in the dark for a while as the whole batch was compromised. We didn’t retaliate either. The Snowden thing wasn’t the cause of that but I bet the Snowden thing compromised other assets.

It's interesting how much people still talk about metadata collection (protected behind the requirement of itemized FISA court approval) because "big mean US is evil" while ignoring events like this.

Re: Chinese Hackers Breach U.S. Navy Contractors

#16
post #15
post #11

Earlier quoted context omitted.

According to the NYTimes they also killed over a 100 CIA assets in China. So we went in the dark for a while as the whole batch was compromised. We didn’t retaliate either. The Snowden thing wasn’t the cause of that but I bet the Snowden thing compromised other assets.

It's interesting how much people still talk about metadata collection (protected behind the requirement of itemized FISA court approval) because "big mean US is evil" while ignoring events like this.

Events like what? That people committing capital crimes for money are being caught, and convicted of... Said capital crimes?

If you don't want to do the time, don't do the crime. You don't just stumble into being an informant for a foreign power.

Re: Chinese Hackers Breach U.S. Navy Contractors

#17
post #16
post #15

Earlier quoted context omitted.

It's interesting how much people still talk about metadata collection (protected behind the requirement of itemized FISA court approval) because "big mean US is evil" while ignoring events like this.

Events like what? That people committing capital crimes for money are being caught, and convicted of... Said capital crimes? If you don't want to do the time, don't do the crime. You don't just stumble into being an informant for a foreign power.

> Events like what?

Killing dozens of people in secret without a proper trial.

And the fact that it isn't an uncommon occurrence.

Re: Chinese Hackers Breach U.S. Navy Contractors

#18
post #17
post #16

Earlier quoted context omitted.

Events like what? That people committing capital crimes for money are being caught, and convicted of... Said capital crimes? If you don't want to do the time, don't do the crime. You don't just stumble into being an informant for a foreign power.

> Events like what? Killing dozens of people in secret without a proper trial. And the fact that it isn't an uncommon occurrence.

>Killing dozens of people in secret without a proper trial.

To be fair, they also executed some of them in public ;)

https://www.nytimes.com/2017/05/20/world/asia/china-cia-spie...

>From the final weeks of 2010 through the end of 2012, according to former American officials, the Chinese killed at least a dozen of the C.I.A.’s sources. According to three of the officials, one was shot in front of his colleagues in the courtyard of a government building — a message to others who might have been working for the C.I.A.

Re: Chinese Hackers Breach U.S. Navy Contractors

#19
post #7

Do procurement contracts have clauses that discount the purchase price when proprietary information is lost to reflect the diminished value of the product?

I wouldn't be suprised. I've done some unclassified govt contracting and it wasn't uncommon for them to include clauses in software purchase contracts that they had to be re-imbursed a certain amount of money any time a security vulnerability was discovered in the purchased software. The reasoning was that they had to spend money identifying, reporting, and updating systems, so the vendor had to pay for wasted resources.

Re: Chinese Hackers Breach U.S. Navy Contractors

#20
post #5

A slightly different headline would be "Navy has lousy security practices especially regarding contractors" I'm pretty sure the CIA and NSA do their utmost to spy as much as they can on the Chinese and Russian Navy.

@snowden sold us out to china when he fled in 2013, by revealing details about our spying operation on them. apparently they bolstered their defenses after this, due to this information, meanwhile stepping up offensive attacks against the United States

It seems like that is more appropriately attributed to USG's persecution of whistleblowers. I'd bet that Snowden would rather have not fled the US, but he did not have that option.

You can't build on a broken foundation - exposing domestic anticonstitutional corruption is more important than the fallout to foreign policy.

Post reply on HN