Live data from Hacker News

The M.T.A. Is Breached by Hackers as Cyberattacks Surge

nytimes.com

71–75 of 75 posts

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#71

Earlier quoted context omitted.

> and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity. Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." >Of course, their saying "just take my word for it" doesn't mean you should trust them or their findings, but it doesn't mean you should necessarily distrust them just…

>Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." Yes, a decent chunk of it comes down to that general idea, but in practice you're dealing with a ton of permutations of that idea. You don't want the adversary to know the specific data types or values you were pivoting off of and correlating against. So it's not about the general methodology but the speci…

>I don't think that's how that works. You just have no evidence or reason to believe their statement is true. That's different from assuming their statement is false. "

I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice.

As for the rest, all of the evidence they provided was pretty unsubstantiated in my opinion, but I had combined "an uber receipt they can't verify saying an alleged hacker went to an MSS building" and "a supposed recruiting message gave the same address as CNITSEC." I had not read the details in several years, that was my mistake. That was the grand total of the evidence provided though, and the indictment does not provide anymore.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#72

Earlier quoted context omitted.

>Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." Yes, a decent chunk of it comes down to that general idea, but in practice you're dealing with a ton of permutations of that idea. You don't want the adversary to know the specific data types or values you were pivoting off of and correlating against. So it's not about the general methodology but the speci…

>I don't think that's how that works. You just have no evidence or reason to believe their statement is true. That's different from assuming their statement is false. " I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice. As for the rest, all of the evidence they provided was pretty…

>I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice.

Yes, you shouldn't assume it's false. People should simultaneously assume I'm not guilty of any accusation until conclusive evidence is produced, and also not prima facie assume any such claim is false. Purely as a standalone statement, you can't assume it's either true or false. You shouldn't assume it to be true, but that doesn't mean you should assume it to be false.

To use an extreme example, let's say someone you know tells you they were assaulted by some individual, and at that moment you have no other information besides that. Should your immediate reaction be to assume the statement is false?

This is why one should simultaneously give both accusers and accused the benefit of the doubt. You should simultaneously grant victims the presumption of not lying and grant the alleged perpetrators the presumption of non-guilt. A victim makes an accusation, and the accused says they didn't do it, and you have no other information besides that. Do you simultaneously assume both statements from both people are false? No. You assume both are indeterminate at the present time, given you have no other information.

The burden of proof is always on the accuser, but there's still a difference between "not assuming something to be true" and "assuming something to be false". This is also why courts never find someone innocent; they just find you to be guilty or not guilty. Not guilty means the prosecutor/plaintiff failed to conclusively demonstrate guilt. Innocence would be a positive claim rather than a mere failure to accept a claim.

There's an exception if a claim is particularly extraordinary. If you have an extremely low prior, it's fine to assume the claim is false. "This person talking about security stuff online is a Chinese hacker" is a big claim, but not an extraordinary claim like "telekinesis is real".

Also, in this case with the MTA, it's not (yet) criminal justice. It's some private firms saying they believe they have evidence that indicates the perpetrators are likely affiliated with the Chinese government. If they were standing trial instead of just having some company making some claims about them, of course the standard of evidence would be much, much higher.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#73

Earlier quoted context omitted.

>I don't think that's how that works. You just have no evidence or reason to believe their statement is true. That's different from assuming their statement is false. " I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice. As for the rest, all of the evidence they provided was pretty…

>I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice. Yes, you shouldn't assume it's false. People should simultaneously assume I'm not guilty of any accusation until conclusive evidence is produced, and also not prima facie assume any such claim is false. Purely as a standalone sta…

>Should your immediate reaction be to assume the statement is false?

No, they have provided evidence, their statement they were assaulted by x. Whether that evidence is reliable is a different matter. Not making your mind up but proceeding as if they are telling the truth is a logical action.

A comparable event would be a stranger coming to you, saying person y was assaulted, and there is evidence x was responsible. You have no way of knowing how strong the evidence is, or if it even exists. And their motive for telling you this is unclear. The burden is on them to provide some kind of evidence before that statement should even be considered undetermined.

In this case, I don't doubt the ransomware attack happened, and I assume they have some idea of who is responsible as ransomware requires communication with the hackers. The claim that they have links to the Chinese government is extraordinary enough that evidence is required.

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#74
"The hackers did not gain access to systems that control train cars and rider safety was not at risk, transit officials said, adding that the intrusion appeared to have done little, if any, damage."

Isn't this because the systems that control train cars & rider safety on the MTA are all manual/electromechanical, with some dating back to the LaGuardia administration? Hard to hack those without being local to the tracks, and handy with a soldering gun....

Re: The M.T.A. Is Breached by Hackers as Cyberattacks Surge

#75

Earlier quoted context omitted.

>I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice. Yes, you shouldn't assume it's false. People should simultaneously assume I'm not guilty of any accusation until conclusive evidence is produced, and also not prima facie assume any such claim is false. Purely as a standalone sta…

>Should your immediate reaction be to assume the statement is false? No, they have provided evidence, their statement they were assaulted by x. Whether that evidence is reliable is a different matter. Not making your mind up but proceeding as if they are telling the truth is a logical action. A comparable event would be a stranger coming to you, saying person y was assaulted, and there is evidence x was responsible.…

>The claim that they have links to the Chinese government is extraordinary enough that evidence is required.

I agree. I just think this is a language debate. "Assuming [X] is false" is just different from "not assuming [X]" / "not assuming [X] is true" / "not believing [X]". It's fine to not believe it without evidence (I wouldn't, either), but to assume it's false is to make a positive statement rather than a rejection of another positive statement.

Post reply on HN