Earlier quoted context omitted.
> and obviously the people trying to catch them don't want to reveal the techniques they use to track and attribute their alleged activity. Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." >Of course, their saying "just take my word for it" doesn't mean you should trust them or their findings, but it doesn't mean you should necessarily distrust them just…
>Most of these methods are already public knowledge, usually advanced versions of "don't reuse email addresses." Yes, a decent chunk of it comes down to that general idea, but in practice you're dealing with a ton of permutations of that idea. You don't want the adversary to know the specific data types or values you were pivoting off of and correlating against. So it's not about the general methodology but the speci…
I have no evidence to believe the statement "meowface is a Chinese hacker" is true, but I shouldn't assume it is false? Accusations need evidence. This isn't science, it's criminal justice.
As for the rest, all of the evidence they provided was pretty unsubstantiated in my opinion, but I had combined "an uber receipt they can't verify saying an alleged hacker went to an MSS building" and "a supposed recruiting message gave the same address as CNITSEC." I had not read the details in several years, that was my mistake. That was the grand total of the evidence provided though, and the indictment does not provide anymore.