Live data from Hacker News

Chinese Hackers Infiltrate New York Times Computers

nytimes.com

61–70 of 183 posts

Re: Chinese Hackers Infiltrate New York Times Computers

#61
post #23

Earlier quoted context omitted.

About Symantec's technology, it is worth noting that antivirus scans are based on identifying malware in one place, then being able to recognize that malware everywhere. This does not particularly help you recognize malware that was custom made to only be installed in one location. Particularly not when the people who were making that malware themselves have access to your anti-virus scans prior to deployment and can…

But see, the thing is, that's not what it says on the box. http://us.norton.com/antivirus/ "It's okay to blink, because we never do – SONAR technology and live 24x7 Threat Monitoring watch over your PC for any suspicious behavior to quickly identify threats." "Protection from the future, available today – our exclusive reputation and behavior antivirus technology are so advanced that they can stop online threats that…

Yes. And if you engage in suspicious behavior like connecting to a botnet and then spewing spam, SONAR likely figures out that something is wrong.

But remote command and control through a covert channel can be done in ways that do not look particularly suspicious. And a sophisticated attacker should be assumed to know what behaviors SONAR is looking for.

Re: Chinese Hackers Infiltrate New York Times Computers

#62
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

> It's not obvious that they are wrong in that assessment.

Any entity with the reach of the United States is naturally going to have connections with all kinds of actors. While the idea of Americans/Zionists/Illuminati/Nibiru pulling the strings behind every major event is no doubt very exciting for conspiracy theorists (eg. I'm getting 2.28 million google hits for ["dalai lama * a cia agent"]), and simpler (ignoring the agency of the citizens of those countries), that doesn't mean sane people should believe extraordinary claims without extraordinary evidence. It's not in anyone's interest to topple the PRC, even if it were possible, which it is not.

Re: Chinese Hackers Infiltrate New York Times Computers

#63
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

It's more important to understand that there's not one monolithic "Chinese perspective" at any level.

Re: Chinese Hackers Infiltrate New York Times Computers

#64
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

Very good points! >> it does not see a line between NGOs, the NYT/WSJ, and the US government. Aren't we all doing the same mistake when we refer to them? All we know is that the attacks came from China, so we safely assume it came from the Government? Why is it that each time something comes from China (a country with approximately 5 time more people than the US - source Wikipedia) we blame their government and treat…

The giant honeycomb is (supposedly) tucked away inside the Great Firewall.

Re: Chinese Hackers Infiltrate New York Times Computers

#65
post #56

I like how the whole article is rambling about Chinese hacks yet no strong & clear evidence suggests it's from China, except perhaps from a Chinese IP address. You know what, Chinese computers are also likely to be hacked easily.

I've found that's the case with any hack... for all we know it could be a competing newspaper routing through China.

But nationalism/xenophobia trumps reason.

Re: Chinese Hackers Infiltrate New York Times Computers

#66
post #59
post #32

Earlier quoted context omitted.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times. Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places. While it should potentially be possible to reflash eve…

You may believe reinstalling the OS is enough I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. I can accept however that the Times may well have been running 10 year old PCs, with manual IT management processes, and outdated security software, and that replace…

> verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure.

Can you back up that claim with reference to a system that does that?

EVERY single management system I can think of trusts the system to report its status. You can't trust a compromised system to report its status.

Assume you have 5,000 desktop computers. How do you set them up so you can verify bios and firmware signatures without forcing a good bios reflash in the first place? (An action that does require soldering or jumper setting on modern motherboards!)

> I can accept however that the Times may well have been running 10 year old PCs

If you're running your business properly, 3-4 years is the oldest any PC should ever get. If you know a business running 10 year old PCs, tell them to get a new accountant. Today's $300 ATOM netbook (with your 10 year old screen and keyboard) will have positive ROI compared to maintaining a 10 year old machine (The best 2002 Pentium 4 is comparable to a modern ATOM, but needs 5-10 times as much power). You'll be saving money just with energy/cooling costs.

Re: Chinese Hackers Infiltrate New York Times Computers

#67
post #19

I think it's important to understand the Chinese perspective on this issue, if only to see why they do these things. Start with this: http://www.nytimes.com/2011/04/15/world/15aid.html?pagewante... U.S. Groups Helped Nurture Arab Uprisings Even as the United States poured billions of dollars into foreign military programs and anti-terrorism campaigns, a small core of American government-financed organizations were pr…

> Whether or not you believe the Arab Spring actually resulted in good outcomes, the salient fact is that US funded groups started the revolutions

Wait, what? Do you have any evidence to support that?

Re: Chinese Hackers Infiltrate New York Times Computers

#68

There's a couple surreal quotes in here. Like asking the Chinese Ministry of Defense to comment. "A Symantec spokesman said that, as a matter of policy, the company does not comment on its customers." Uh huh. Even when it's the customer doing the asking? Way to hide behind the policy.

If the CIO asks, then Symantec will probably comment, under condition that it doesn't get reprinted.

If a reporter is fishing for a quote, they won't get anything special.

Re: Chinese Hackers Infiltrate New York Times Computers

#69
post #59
post #32

Earlier quoted context omitted.

Someone has poor understanding of how computers work, but it isn't necessarily the NY Times. Once a computer is compromised, you can't trust anything about it. You may believe reinstalling the OS is enough, but it is possible that some remote control tool is still lurking in a main BIOS reflashed while compromised, or in the GPU firmware, or tens of other places. While it should potentially be possible to reflash eve…

You may believe reinstalling the OS is enough I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure. I can accept however that the Times may well have been running 10 year old PCs, with manual IT management processes, and outdated security software, and that replace…

> I made no such claim, but verifying bios and firmware signatures (and indeed detecting changes when they happen), and reinstalling them at scale is not a major challenge with a well managed IT infrastructure.

It is? How do you do it?

Post reply on HN