Earlier quoted context omitted.
Very good points! >> it does not see a line between NGOs, the NYT/WSJ, and the US government. Aren't we all doing the same mistake when we refer to them? All we know is that the attacks came from China, so we safely assume it came from the Government? Why is it that each time something comes from China (a country with approximately 5 time more people than the US - source Wikipedia) we blame their government and treat…
I've been there. I spent 6 months last year. What you might not understand is that the Chinese government has its hands in every corporation, organization, competitor, etc. You might have false assumptions coming from the US system, where corporations and government are separate entities. They even sue one another at times. In China, large corporations are overseen by the government. The government funds them, decide…
Chinese Hackers Infiltrate New York Times Computers
111–120 of 183 posts
Re: Chinese Hackers Infiltrate New York Times Computers
#112Earlier quoted context omitted.
You are also categorically incorrect. The Chinese central government most certainly cares about Arabs, as they share a disputed border with several majority Muslim countries, including Pakistan and Afghanistan. Moreover they have repressed domestic minority populations who are predominantly Muslim. The extent to which there are Islamic unification or nationalist movements (which are often tied in with movements in th…
I'm confused... What's the relationship between Arabs and Pakistan/Afghanistan? There's a difference between being Arab and being Muslim. The greatest Muslim countries are not Arab (Indonesia, Turkey, Iran, Pakistan). "Islamic unification" is by definition the opposite of "nationalist movements", and is very unlikely to happen. I can guarantee that Saudis, Pakistanis, Morrocans and Turks have way too little in common…
And yeah, you're right, Arabian culture is distinct from other parts of the Muslim world, but neither are they totally disentangled either. Both the green revolution in Iran and the Egyptian revolution against Hosni Mubarak had well defined religious components for example.
Re: Chinese Hackers Infiltrate New York Times Computers
#113I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…
They are neither incompetent nor ignorant. They can tell who's who. When they want Industrial info, they know where and how to get it. When they want advanced tech, they know how to get it. When they want to retaliate "cybernetically" they know how to do it.
I would say, as others have pointed out, that this is in retaliation to the pieces about graft and wealth building by CN officials counter to the spirit of the revolution because it could cause internal PLA dissent/strife -and to see if they could obtain info about sourc(e)s of that info.
>"and in general even the NYT does tend to side with the USG against China or Arab regimes"
This is like comparing people's comments about the weather and saying "see, they are aligned, they agree on aspects about the weather". I think it's more that their views coincide rather than the implied "pseudo-state-organ-piece" view. They (CN) are not naive.
I'd predict that if you began hosting Fa Lun Gong sympathetic views and began getting traction that you (your site) would become a target -not because you'd be assoc with the gov't, or even think you were related to the gov't, but because FLG is something they consider counter to their interest. You could be based in North Korea, but if you published things they found counter-productive, they'd look into investigationg your nature, I suspect.
Re: Chinese Hackers Infiltrate New York Times Computers
#114Earlier quoted context omitted.
Arab spring has kind of taught us that things aren't as simple as: "Break status quo and things get better". I don't think that anyone needed to be taught that. I doubt that we will be able to judge whether the Arab Spring was a success for another ten or twenty years- the immediate aftermath of revolution is always deeply messy. Not to mention that 'better' is entirely subjective anyway, of course. There are plenty…
That was my point. If it takes 20 years to see a 'benefit' is it that bad now, that they should go through that kind of mess?
Re: Chinese Hackers Infiltrate New York Times Computers
#115Earlier quoted context omitted.
http://www.nytimes.com/2012/12/06/world/africa/weapons-sent-... But in the months before, the Obama administration clearly was worried about the consequences of its hidden hand in helping arm Libyan militants, concerns that have not previously been reported. The weapons and money from Qatar strengthened militant groups in Libya, allowing them to become a destabilizing force since the fall of the Qaddafi government. h…
> As for the phrase "conspiracy theory", the implication of that phrase is that conspiracies don't exist. Exactly this. Or that all theories are not worth our time, since they are just that, "just a theory" (implying there is no proof?), like creationists (of which, America is filled with) like to say.
congratulations on the beautiful ad hominem
Re: Chinese Hackers Infiltrate New York Times Computers
#116If you want to give credit to a report detailing how much money your political leaders have piled up for themselves, hacking the media outfit that published it is a great way to confirm the story.
It just doesn't seem rational to expend that kind of resource for such petty motives, especially if they have any idea how western media works, which I believe they do.
Re: Chinese Hackers Infiltrate New York Times Computers
#117Earlier quoted context omitted.
You aren't assuming, you are looking on all machines for IOC's (specifically machines that have been compromised before), and hopefully making use of all that fancy network security monitoring technology you paid entirely too much money for. And you're monitoring outbound connections to any of the places which are known to be "bad neighborhoods", as well as any other suspicious traffic. In the gmail example you used,…
I was trying to figure out how you think you know all of this when I clicked on your profile. Then the thought suddenly hit me that publicly disclosing details about how we think they work, and what we actually look for in cleaning up, might not be the best thing to do on a forum that is world accessible. Also if you're right, I'm depressed that they don't in practice use ideas that have been publicly known for decad…
And I share your sadness that we're still dealing with these types of attacks, when we could make things so much more difficult for attackers by just implementing the things we've learned in the past thirty years.
I feel a little torn, though, because I also worry about what unintended consequences would arise if we actually replaced all of our infrastructure with things like hardware roots of trust, and trusted network connect implementations (which are systems which really provide very little value unless everything on your network uses them). Whether that's just moving the ball ten yards forward, when we still struggle to engineer large systems in a secure manner.
If that depresses you, I worry how you'd react when most organizations balk even at the prospect of a mass password reset. How many try to argue why can't they just reset the ones that you "know" are compromised? Or how long it takes to get said password reset signed-off and put into the change management process.
For what it's worth, I work a lot now with TPM's, and even the places that have actually gone through the trouble of rolling out bios measurements and signed firmware, are still getting breached.
Re: Chinese Hackers Infiltrate New York Times Computers
#118Re: Chinese Hackers Infiltrate New York Times Computers
#119Earlier quoted context omitted.
> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions Wait, what? Do you have any evidence to support that?
Yes, please read the article I linked: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... Title: US Groups Helped Nurture Arab Uprisings Here is another. http://www.nytimes.com/2012/12/06/world/africa/weapons-sent-... The Obama administration secretly gave its blessing to arms shipments to Libyan rebels from Qatar last year, but American officials later grew alarmed as evidence grew that Qatar was turnin…
Re: Chinese Hackers Infiltrate New York Times Computers
#120Judge for yourself.
They operate from a bare apartment on a Chinese island.
They are intelligent 20-somethings who seem harmless.
But they are hard-core hackers who claim to have gained
access to the world's most sensitive sites, including
the Pentagon.
In fact, they say they are sometimes paid secretly by the
Chinese government -- a claim the Beijing government
denies.
"No Web site is one hundred percent safe. There are Web
sites with high-level security, but there is always a
weakness," says Xiao Chen, the leader of this group.
"Xiao Chen" is his online name. Along with his two
colleagues, he does not want to reveal his true identity.
The three belong to what some Western experts say is a
civilian cyber militia in China, launching attacks on
government and private Web sites around the world.
If there is a profile of a cyber hacker, these three are
straight from central casting -- young and thin, with skin
pale from spending too many long nights in front of a
computer.
One hacker says he is a former computer operator in the
People's Liberation Army; another is a marketing graduate;
and Xiao Chen says he is a self-taught programmer.
"First, you must know about the Web site you want to
attack. You must know what program it is written with,"
says Xiao Chen. "There is a saying, 'Know about both
yourself and the enemy, and you will be invincible.'"
CNN decided to withhold the address of these hackers' Web
site, but Xiao Chen says it has been operating for more
than three years, with 10,000 registered users. The site
offers tools, articles, news and flash tutorials about
hacking.
Private computer experts in the United States from
iDefense Security Intelligence, which provides
cybersecurity advice to governments and Fortune 500
companies, say the group's site "appears to be an
important site in the broader Chinese hacking community."
Arranging a meeting with the hackers took weeks of on-
again, off-again e-mail exchanges. When they finally
agreed, CNN was told to meet them on the island of
Zhoushan, just south of Shanghai and a major port for
China's navy.
The apartment has cement floors and almost no furniture.
What they do have are three of the latest computers. They
are cautious when it comes to naming the Web sites they
have hacked.
On camera, Xiao Chen denies knowing anyone who has
targetted U.S. government Web sites. But off-camera, in
conversations over three days, he claims two of his
colleagues -- not the ones with him in the room -- hacked
into the Pentagon and downloaded information, although he
wouldn't specify what was gleaned. CNN has no way to
confirm if his claim is true.
"They would not publicize this," he says of someone who
hacks the U.S. Defense Department. "It is very sensitive."
This week, the Pentagon said computer networks in the
United States, Germany, Britain and France were hit last
year by what they call "multiple intrusions," many of them
originating from China.
At a congressional hearing in Washington last week,
administration officials testified that the government's
cyber initiative has fallen far short of what is required.
Most alarming, the officials said, there has never been a
full damage assessment of federal agency networks.
"We are here today because we must do more," said Robert
Jamison, a top official in the U.S. Department of Homeland
Security. "Defending the federal system in its current
configuration is a significant challenge."
U.S. officials have been cautious not to directly accuse
the Chinese military or its government of hacking into its
network.
But David Sedney, the deputy assistant secretary of
defense for East Asia, says, "The way these intrusions are
conducted are certainly consistent with what you would
need if you were going to actually carry out cyber
warfare."
Beijing hit back at that, denying such an allegation and
calling on the United States to provide proof. "If they
have any evidence, I hope they would provide it. Then, we
can cooperate on this issue," Qin Gang, a spokesman for
the Chinese Foreign Ministry, said during a regular press
briefing this week.
But again off-camera, Xiao Chen says after the alleged
Pentagon attack, his colleagues were paid by the Chinese
government. CNN has no way to independently confirm if
that is true.
His allegations brought strenuous denials from Beijing. "I
am telling you honestly, the Chinese government does not
do such a thing," Qin said.
But if Xiao Chen is telling the truth, it appears his
colleagues launched a freelance attack -- not initiated by
Beijing, but paid for after the fact. "These hacker groups
in my opinion are not agents of the Chinese state," says
James Mulvenon from the Center for Intelligence Research
and Analysis, which works with the U.S. intelligence
community.
"They are sort of useful idiots for the Beijing regime."
He adds, "These young hackers are tolerated by the regime
provided that they do not conduct attacks inside of
China."
One of the biggest problems experts say is trying to prove
where a cyber attack originates from, and that they say
allows hackers like Xiao Chen to operate in a virtual
world of deniability.
And across China, there could be thousands just like him,
all trying to prove themselves against some of the most
secure Web sites in the world.
Source(s):