Live data from Hacker News

U.S. and key allies accuse China of Microsoft Exchange cyberattacks

axios.com

141–150 of 267 posts

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#141

Earlier quoted context omitted.

> Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc. I like this idea…

Or they should stop stealing tax payers money and dissolve these agencies. The one thing they are good at is digging deeper and deeper the debt account, for virtually no benefit, and surely nuisance and worries.

Are you saying that the market, such as it is, is doing a good enough job of managing software vulnerabilities and their consequent breaches?

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#142
post #66

Earlier quoted context omitted.

No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…

You're being deliberately obtuse about this. The simplest explanation for cyberattacks against high-profile targets coming out of countries like China (or the US, for that matter) isn't "rando script-kiddies having a laugh ha ha!". It's that their government intelligence forces did it. This kind of attempted misdirection is really common from people defending/spreading propaganda for the Chinese government. It's also…

What you're missing is that these attacks weren't targeted. They scanned internet and processed pretty much all accessible Exchange servers in the same manner. There were a few crews operating in parallel by the way which had access to same exploit chain but different exploits.

Some had certain variables hardcoded, e.g. Administrator user's name and their exploits worked with higher success rate in anglosphere, but failed in localized environments. Others had more advanced exploits which queried parameters instead of assuming them - those where more successful around the globe.

Another nuance missing from popular press is that most groups in China (and Russia) are operating independently, but share tradecraft among them and occasionally engage with politicized missions (either working on explicit orders from government handlers or simply defending their beliefs hacktivist-style). This is what FireEye means by "affiliation with Chinese government", NOT "operates strictly on government orders".

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#143
post #92

There is so much doubt in this comment section around the validity of the accusations. We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

This is meaningless. You're saying that since we have gotten it wrong in the past it must be wrong this time? That's not how it works. Show me your superior intelligence that contradicts this.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#144

Earlier quoted context omitted.

Not commenting on OP, but you are talking about a single US regime. And Many countries did independently investigate, and refuse help.

Actually, the US worked to fabricate evidence in collaboration with the UK too. The UK had an expert produce the so called "dodgy dossier", that was used as Blair's justification to follow the US into their illegal war. The media called it out as obvious bullshit, then the guy that produced the report allegedly committed a timely suicide.

Source please.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#145
I don't think Chinese cyber spying is really news to anyone. What's different about this now is that the U.S., a few others and notably, NATO are specifically calling out China for it.

That's a pretty heavy diplomatic change. Especially the inclusion of NATO.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#146
post #126

Earlier quoted context omitted.

No. It is not. China is a big country and the Chinese government does not control everything that is going on. Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented. Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or…

Chinese citizens cannot even mention recent historical events on in private messages on the internet without approval from the government, and you're trying to tell us that some "kids with computers" were able to carry out a sophisticated years-long cyberattack? "Kids with computers" might be plausible in a free country, but not in China.

You obviously haven't met Chinese infosec researchers, have no knowledge about Chinese underground and are simply speaking from your biases.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#147
post #87

Earlier quoted context omitted.

Whether the Chinese government has control over these APTs, the crime originated on Chinese soil, and it's their responsibility to deal with these threats. What's so hard for you to understand?

I don't think this makes much sense. We don't even know if the APTs actually do operate on Chinese soil, much less that the Chinese government condones them. All we know is that they used Chinese IPs at some point and Chinese configured computers, and that they went after military targets. And we don't even know that these are the same APTs.

Yes we do.

https://www.justice.gov/opa/pr/four-chinese-nationals-workin...

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#148

Earlier quoted context omitted.

and yet, we were able to accurately attribute the code released in that leak as being developed by NSA.

We know it was the NSA because of leaked NSA documents that admitted to the affiliation. Not from the tools themselves.

Interesting; could you share your source on that?

I had only previously heard [0] that similarities in the tools were discovered by Kaspersky, not that there were any leaked docs that pointed the finger back at NSA themselves. Are you maybe thinking of PRISM/Wikileaks?

[0] - https://arstechnica.com/information-technology/2015/02/how-o...

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#149
post #92

Earlier quoted context omitted.

"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion? As an aside, I'm not sure what's more frustrating: Witnessing the Bush administration circa 2001-2004 be called out on these lies, by numerous entities, and still march inexorably toward armed conflict, or... having to witness these lies being u…

I think the Iraqi war was more frustrating than those two put together.

You realize that this wasn't the first time the US did this, so I feel we should question these claims as much as possible.

Re: U.S. and key allies accuse China of Microsoft Exchange cyberattacks

#150
post #92

Earlier quoted context omitted.

"Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion? As an aside, I'm not sure what's more frustrating: Witnessing the Bush administration circa 2001-2004 be called out on these lies, by numerous entities, and still march inexorably toward armed conflict, or... having to witness these lies being u…

>>> There is so much doubt in this comment section around the validity of the accusations.

>>> We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.

>> "Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.

> I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion?

I think the logic is once an organization or its leaders get something wrong, you should never, ever believe anything that organization ever says ever again. Even 20 years later after the leadership and staff has turned over a couple times.

Of course, that's totally unworkable idea when applied consistently, so it's only used, knowingly or unknowingly, to reenforce existing biases.

Post reply on HN