Live data from Hacker News

U.S. government probes VPN hack within federal agencies, races to find clues

reuters.com

51–60 of 61 posts

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#51
post #47
post #45

Do people know that Fortinet is pretty much a de-facto Chinese company?

Any links on that? Only notable incident was when they apparently sold intentionally mislabeled Chinese-made equipment to U.S. government end users. https://en.wikipedia.org/wiki/Fortinet#cite_note-37

I think they are referring to the fact how Fortinet was founded by two Chinese born brothers.

Tho Ken Xie is also a Stanford graduate and has had US citizenship for decades.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#52

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

The Crypto AG revelations --- a Swiss-based firm selling Telex encoding equipment revealed to be a CIA front --- strongly suggest to me that the principle (though not only) strength of the US intelligence agencies has been based on backdoors. As software-based encryption became more prevalent, they sought to either discourage effective crypto, or impose mandatory back-doors.

The downside of having generally-known weaknesses seems to have been largely deprecated.

Rather than "security by obscurity", the operational status has been "insecurity by obscurity". Unknown to users, systems are largely wholly insecure, and it's only ignorance that gives the illusion that they are secure.

I wrote on this recently: https://joindiaspora.com/posts/b596219086b1013991d8002590d8e...

In practice, the "everyone anywhere can attack any online system" status of the Internet, and the porosity of most LANs and even nominally airgapped / detached systems (see the Stuxnet attack on Iran's centrifuge systems) means that virtually all systems are vulnerable.

I suspect that the debate is quite live within government, particularly as the US itself is repeatedly the victim of such attacks.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#53
post #37

Earlier quoted context omitted.

Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…

I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use. If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else. If the government started requiring all/mos…

Doesn't SELinux provide some of that?

Tightly enclose all running software with a beyond-root, kernel-level authority/sandbox, so even vulnerabilities only we know can't harm us if they're discovered?

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#54
post #47

Earlier quoted context omitted.

Any links on that? Only notable incident was when they apparently sold intentionally mislabeled Chinese-made equipment to U.S. government end users. https://en.wikipedia.org/wiki/Fortinet#cite_note-37

I think they are referring to the fact how Fortinet was founded by two Chinese born brothers. Tho Ken Xie is also a Stanford graduate and has had US citizenship for decades.

Not only that, but them having the bulk of their staff in China.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#55

Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.

It probably already happened.

In the defensive world, success is abstract, failure is concrete and there are always going to be bugs, accidents, lapses, etc. in the offensive world, you demonstrate success by providing actual intel, you can demonstrate value. I’ve worked on security products for most of my career, there is a point in the lifecycle before your product is just a requirement where customers will ask “how do I know I need this? Or it’s working?” It can be more challenging to answer that than if your product failed and they got popped, at least you can help and provide information if they got popped.

I know who I think would climb the ranks. Long term strategy wise, if they split it up and aggressively worked with industry to patch holes and fix things, encouraging best practices, it would probably save the nation trillions but we would have to use other techniques to get some of our intel.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#56
post #54

Earlier quoted context omitted.

I think they are referring to the fact how Fortinet was founded by two Chinese born brothers. Tho Ken Xie is also a Stanford graduate and has had US citizenship for decades.

Not only that, but them having the bulk of their staff in China.

> not only that

By this logic does it not mean that Google is a Russian/Soviet company? Sergey Brin was born and spent some years in Russia, also Google has staff in Russia(and China in this regard)

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#57
post #56
post #54

Earlier quoted context omitted.

Not only that, but them having the bulk of their staff in China.

> not only that By this logic does it not mean that Google is a Russian/Soviet company? Sergey Brin was born and spent some years in Russia, also Google has staff in Russia(and China in this regard)

He was born there, but he did not remain as a citizen of that country, and not been going back, and forth in line of business.

A situation is different from where a double citizen operates a sales office of a company from his home country

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#58
post #35

Earlier quoted context omitted.

By intra-government you mean like US vs China? (or any other competitors? We could say Israel and Germany) I think this has always existed though the information age has swung the balance to there being more importance for average citizens to have encrypted data in a more general sense and not just finance.

"Intra" here means inside the same government (you're thinking of "inter"). The hypothesis is that there will be parts of the US government (like perhaps the FBI) that will advocate for government-controlled backdoors into all encryption, while other parts (like perhaps the NSA) will argue for the strongest, backdoor-free encryption possible. I think it's an interesting hypothesis, but one weakness is that the govern…

...until the higher ups learn that, yet again, China or Russia or Iran or somebody got their hands on a lot of sensitive data, and they start pressuring the NSA to get a handle on this. I don't know if it's happening yet, but if it hasn't it will.

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#59
post #57
post #56

Earlier quoted context omitted.

> not only that By this logic does it not mean that Google is a Russian/Soviet company? Sergey Brin was born and spent some years in Russia, also Google has staff in Russia(and China in this regard)

He was born there, but he did not remain as a citizen of that country, and not been going back, and forth in line of business. A situation is different from where a double citizen operates a sales office of a company from his home country

So that we are on a same page, you are stating that any company is de-factor to be considered belonging to country X if: 1) Founder has a double citizenship 2) Has some of the staff in a foreign country 3) Has a sales office in their home country

Is above what you are trying to say?

Re: U.S. government probes VPN hack within federal agencies, races to find clues

#60
post #59
post #57

Earlier quoted context omitted.

He was born there, but he did not remain as a citizen of that country, and not been going back, and forth in line of business. A situation is different from where a double citizen operates a sales office of a company from his home country

So that we are on a same page, you are stating that any company is de-factor to be considered belonging to country X if: 1) Founder has a double citizenship 2) Has some of the staff in a foreign country 3) Has a sales office in their home country Is above what you are trying to say?

In this case, the sales office is their main office, and the Chinese "subsidiary" is where the main body of the company really is.
Post reply on HN