Live data from Hacker News

Cyber Sleuths Track Hacker to China’s Military

wsj.com

21–30 of 57 posts

Re: Cyber Sleuths Track Hacker to China’s Military

#21
post #9

I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…

Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.

Re: Cyber Sleuths Track Hacker to China’s Military

#23
post #9

I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…

Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.

Yes, so perhaps as a result, China will be more favorable to MSFT and FB.

Re: Cyber Sleuths Track Hacker to China’s Military

#24
post #16

Earlier quoted context omitted.

Why do companies, security companies even, do something like this... " Below are the document checksums for Project_CAMERASHY_ThreatConnect_Copyright_2015.pdf MD5: b12f118840d0aa0d5ab2fb9aa052ede3 SHA1: dbd710751a6c32ba91401fb5e5623f46b4d2475f SHA256: da6b105f1e58f860ce67b2ad2db7b15ff7b637cfb37f7d0680a20eb633bcc741" ... when you are then providing both the PDF, and the list of its supposed hashes, over an unencrypted…

> creating megabyte long PDFs with colliding MD5 hashes is not even a difficult challenge anymore. Source, please? Suppose the hashes and PDF were provided over HTTPS. How would it be easy to create another document that collided with all 3 hashes? Not trying to be facetious - just wondering.

ahhh. Was mixing pre-image attacks with collision attacks in MD5. so ignore that.

If its not over HTTPS, it doesn't matter there are 3 hashes. I change the doc. I generate the 3 hashes for my changed doc. I can serve those new hash values.

Re: Cyber Sleuths Track Hacker to China’s Military

#25
post #9

I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…

Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.

MSFT and FB want to maintain and increase access to the 1.35 Billion people of China. Not ironic at all, those companies need to be in China even if treated poorly.

Re: Cyber Sleuths Track Hacker to China’s Military

#26
post #5

Without having read the full PDF report [0], the summarized version [1] makes the allegations seem quite weak. It comes down, seemingly, to the fact that a PLA domain name appears in the malware. Maybe I'm missing something. [0] http://cdn2.hubspot.net/hubfs/454298/Project_CAMERASHY_Threa... [1] http://www.threatconnect.com/camerashy-resources/

Looks like PLA domain shares name with probable PLA employee social media handle. And the social media accounts were deleted immediately after the WSJ called the guy.

It seems pretty likely there is some PLA connection, though not necessarily to this particular guy - no way of knowing that a buddy didn't steal his handle for use elsewhere (seriously, not sharing the same hacking handle and the same personal username should be Tradecraft 101)

Re: Cyber Sleuths Track Hacker to China’s Military

#27
post #9

I think it is very important to understand that the timing of this report is likely no coincidence. With Xi set to have discussions today with Obama, this is effectively a slap across the face to Xi right before an important visit that he can't back out of, and effectively puts china on a lower footing by showing them to be lying directly to the US about their intentions. Edit: this isn't to say publication/announcem…

Ironical MSFT and FB are fawning over Xi's visit giving him the royal tours. China treats these two companies very poorly. Nearly all MSFT software in China is pirated. China bans FB partly for censorship and partly to protect internal social networking products.

MS technically has ability to shut off and cripple any pirated Windows over the wire if it wants to. But in this case, it has chosen not to for a lot of Asian countries. The reason? Market share.

It wants users to get used to how Windows works, versus to other alternatives like Linux, Mac, etc.

Re: Cyber Sleuths Track Hacker to China’s Military

#29
Having read many of these reports over the years, this one seems more manifesto than security report. It is full of carefully controlled language meant to appease a very specific audience: politicians and members of various agencies.

A huge amount of space is dedicated to tenuous ties between physical military activities and espionage on the assumption that all chinese agencies are coordinating with each other, that the Chinese are just better at conspiracy than any US operation. No actual intelligence officer would ever describe China in that way. It's a patchwork of poorly-connected operations all trying to put on a good show for the bosses, much the same as US intelligence agencies.

Certain key phrases suggest political motive. As example, the phrase "China’s ... military grade signals intelligence Unit" caught my ear. "Military grade" doesn't mean much in infosec. It does mean something to lifelong service members who labour under the assumption that military structures just do things better than civilian organizations. In some fields "military grade" is actually a bad thing, a reference to products built to conform to rarely-updated procurement standards. It's like still selling floppy disks because the computer on the stealth bombers haven't been updated in 20 years. The phrase appears right at the start of the takeaways section, right where most senior officials will probably start reading.

The drilling down upon a few people, to the point of tracking a man's movements and finding the bike he offered for sale, certainly plays into current US national security desires. Targeted killings based on poor intel is a big chip on the military shoulder these days. They aren't happy about it. So peppering a document with a few grains of seemingly accurate and specific intel about individuals is a good trick to win people over. The excessive reliance on google maps is just eyecandy. This gives the false impression of validity, a false suggestion that the rest of the report is based on equally detailed and reliable intel. if this were such intel, it wouldn't be released publicly.

the pdf: http://cdn2.hubspot.net/hubfs/454298/Project_CAMERASHY_Threa...

Post reply on HN