A method that wouldn't show up on any firewall in the world is simply to delay or drop certain SYN packets. Even if you only intended to transmit a bit at a time through this, any unauthenticated host on the internet could use this without raising any suspicion or even printing log lines in most environments. As soon are you're making an assumption that you're trying to prevent what's inside from getting out things become substantially closer to impossible than anybody would like.
Navy ships don't upload via Dropbox.
I think Bloomberg (and all related) web servers displaying the article are compromised and they're leaving out critical facts the point the finger elsewhere.
I would have thought one single unexpected packet in these high security environments would raise significant alarm bells and any anomaly would be found very quickly.
If you’re running an IDS on a big 100 Gb datacenter network, you’re literally processing millions of events. Very few places would notice such a thing unless they were investigating something related, and the ones with the capability are going to be for static workloads as getting anything done will be slow and painful.
This sort of monitoring doesn't happen in the real world.
Now this does not make it impossible, just very complex. In a more "controlled" environment such as a naval ship, i could see this actually working better, especially if the system is supposed to talk to very few external systems.
Security engineering is about tolerable failure modes. - Dan Geer (2014)
Except on extremely controlled networks, this would be very hard to detect. It gets even worse when you consider that the Chinese had/have a distributed network of compromised machines. Imagine using a Google edge server as a dead drop...