Chinese Spies Got the NSA’s Hacking Tools, and Used Them for Attacks
nytimes.com
nytimes.com
Source: https://www.cia.gov/library/center-for-the-study-of-intellig...
Not more than a mile later I passed an intersection with license plate readers for every lane in every direction. I seriously doubt there are strict controls on the police who have access to this data. But the article somehow suggested I should be worried about they spying China is doing.
https://www.symantec.com/blogs/threat-intelligence/buckeye-w...
Either way, as you say, it does seem like this probably happens frequently. It's the nature of the thing.
The article says "The losses have touched off a debate within the intelligence community over whether the United States should continue to develop some of the world’s most high-tech, stealthy cyberweapons if it is unable to keep them under lock and key."
But we know: of course you can't keep valuable software 'under lock and key', that's not how software works (at least not if it's intended to run on non-secure networks).
So that to me raises the question: Wouldn't it better for our national security if our well-funded military infosec aparatus were focused much more disproporationately on defense, instead of creating, perserving, and escalating available attacks? If the NSA knows about a 0day, how about they get it patched (so it can't be used against American and allied civilian networks, as it was in this story), instead of trying to keep it exploitable? I'd feel a lot safer if my tax dollars were used that way.
Out of curiosity, I wonder who directed the NSA to attack Chinese computers?
Edit: That was confusing. Basically, we don't know when exactly before Aug2016 the tools were leaked, so it could have been someone else probing the Chinese server.
Was this attack from China? Was it from the US making it look like China to justify US economic and diplomatic retaliation? Was it from Germany looking to embarrass the US with a false-false-flag attack making it look like the US made a false-flag attack on China after the US spied on Merkel's phone conversations?
We could go down rabbit holes forever. Who can be completely trusted to speak openly, knowledgeably, and honestly on specific instances of attacks? Every last individual and organization in that world is neck-deep in their own agendas.
What do you think is NSA's mission?
Here's what I have.
I’m talking about whether external control is required for software updates to occur. As with Windows, where Microsoft can replace software on your machine at any time. On Ubuntu, canonical can add backdoored software to their repositories but they can’t forcibly install software on your machine AFAIK. Maybe I just misunderstood the comment I was responding to.
e.g. law inforcement gets a tool "BreakEveryonesSecurity.exe/app" that can talk to any device they find. For that to work all devices have to be pre-compromised. Another work for pre-compromised is "insecure".
You trust your OS updates because your machine trusts the certificate it is presented with. Your machine trusts that certificate because it is signed by an authority which is in your machine's local list of trusted authorities.
If people mess up that list of trusted certificate authorities, it can easily compromise the system. Remember this?
https://en.wikipedia.org/wiki/Superfish#Lenovo_security_inci...
Now imagine if, instead of having an identifiable certificate authority which accidentally allowed third parties to intercept and modify your encrypted traffic, that were an undetectable feature of the encryption algorithm.
If that were the case, no matter how much you trusted the entity that understands the nature of the backdoor, you would not trust your OS.
An iOS device cannot install an update without an unlock, and any updates it does push are signed by an apple key, and does not make software with compromised security.
Apple then designs the system so that someone hacking Apple doesn't give them the ability to hack iOS devices. The way apple achieves this is to make the phones require a user unlock to update the device or to connect to another machine.
The only way to make magic software work would be for apple to deliberately compromise the device security. The moment they did that, that would mean there was a tool that would only need to be leaked once to compromise all apple devices. The solution is to not design a broken security model.
I assume the high end android devices are similar, but given android phones are still being shipped without a Secure Enclave I can imagine there are some trivially compromised devices.
So then let's get to how the update itself works.
The device gets a user unlock to occur (iirc if you have automatic updates enabled this means that your device has to have been unlocked in the last 24 hours?[1]). The device pulls an update from an apple server, verifies both the server it pulls from, and the bundle itself. No one else can publish or mitm the update. There's no magic software that can just be passed around - you would need to compromise apple itself, and compromise it to the point that you can get the updates signed by their production signing keys without anyone noticing.
If you're really unsure how all this works feel free to read their documentation: https://www.apple.com/business/site/docs/iOS_Security_Guide....
[1] I re-read the white paper's update mechanism and it sounds like it always requires an unlock before updating. So it's not a hysteresis. So automatic update is gated on an unlock before bed and asking permission to perform the update.
That's not quite applicable to this story though which seems to be just observing network traffic.
---
According to the blog post, "Buckeye", a group allegedly working on behalf of the Chinese state, also used an "exploit of a previously unknown Windows zero-day vulnerability. This zero day was reported by Symantec to Microsoft in September 2018 and patched in March 2019."
So Symantec reported a zero-day -- which was being actively exploited in the wild by a state-based actor -- to Microsoft and Microsoft STILL didn't release a patch for it until six months later?
[0]: https://www.symantec.com/blogs/threat-intelligence/buckeye-w...
I don't understand the US's relationship with China. The above seems to possibly suggest some mild cold war scenario?
Rivalry between a rising power and an existing superpower is inevitable. How it gets resolved though is not certain.
China is on track to overtake the US economically in a decade or two (if you consider PPP adjusted GDP they've already surpassed us). That have implications in other areas too -- strategic, diplomatic, cultural, etc. How will the US respond to this? Will we simply let it happen or will we stop it and perhaps violently? What will it mean for our agendas in different areas since China and the US don't share the same goals in many areas. What's especially frightening to me is that Xi seems to advocate a view that China's rise is a return to a historical greatness and that China is destined to dominate -- similar in some sense to the old "manifest destiny" idea of the US. Xi's idea is now enshrined into the Chinese constitution along side Mao's ideas. My view is on this rather bleak but I think the US needs allies more than ever. Ironically I think two equally matched powers are more likely to come to a peaceful coexistence than if one side perceives the other to be weaker. Maybe a new cold (or cool-ish) war isn't so bad compared to a hot war.
the UK was economically beneath the US a full 3 decades before the US actually decided they wanted to be the world leading superpower. almost two years in a world war, and after a massive attack by the japanese empire did the US finally took the reigns.
the reason for this is that the top global superpower needs to have an extensive network of diplomacy and military, things that come with huge costs domestically. when you’re top dog, everyone looks at you for guidance and rules.
The event that solidified US as the superpower was actually the Suez crisis, where the UK and French had to begrudgingly agree to American demands, making it clear who was the top dog.
I think a more realistic assessment is that there is a high degree of uncertainty in the relative balance of power between two nations, made worse by nationalism, ethnocentrism, and the tendency of charismatic leaders to believe their own hype. Peaceful, commerce-based regimes - the ones most likely to become economic superpowers - tend to be risk averse when it comes to pushing geopolitical boundaries, because war destroys the economic development that led to them becoming superpowers. Militaristic or fundamentalist regimes tend to be risk-embracing, because you don't come to power as a militaristic regime unless the populace believes they can win (a belief which is often distorted in fundamentalist or fascist regimes).
WW2 proved that the U.S. was light years ahead of Japan's industrial capacity. This was known to Japanese military officers who had visited the U.S, but the ruling cabal in Japan discounted their assessment as impossible. Similarly, Cold War propaganda (in both the U.S. and Russia) painted them both as roughly equal superpowers, but we learned after the Iron Curtain fell that the Soviet Union was never really an economic threat to the U.S. The U.S. may have passed the UK as an industrial superpower in WW1, but in the eyes of much of the world they were still an unknown quantity, enough that Japan directed simultaneous attacks on Hong Kong, Singapore, and Malaya at the same time as Pearl Harbor and the Philippines.
There is one thing that does give a lot of hope to me personally: the close economic relationship between the US and China has created a tight bond between the countries even if they are unwilling to admit it openly.
Its not inconceivable for world powers to co-exist in peace. There will be a lot more frontiers in the future that can be competed on without wanting to destroy one another.
Ironic then that it is called the Thucydides trap then, since the ideological lines between Athens and Sparta were very stark indeed.
https://www.google.com/amp/s/www.newsweek.com/2014/05/16/isr...
South China Sea: Chinese admiral wants to 'sink two US aircraft carriers'- https://www.news.com.au/technology/innovation/military/sink-...
Trump says tariffs on $200 billion of Chinese goods will increase to 25%. Additional tariffs on $350 billion goods as well - https://www.cnbc.com/2019/05/05/trump-says-tariffs-on-200-bi...
US accuses China of using 'concentration camps' against Muslim minority - https://www.theguardian.com/world/2019/may/04/us-accuses-chi...
AI has way too much hype behind it. Deep learning is not the best solution for most business data problems.
Cyber Security can be anything form a SOC analyst who looks at system logs and monitoring systems to a cryptographer.
For the most part Cyber Security is as varied as IT itself.
AI on the other hand would require a very specific set of skills and theoretical knowledge and a very good grasp of mathematics the latter is where most people fail even if they know the maths without being a mathematician at heart and being able to use it essentially as a language you likely won’t get too far even with all of the abstractions deep learning frameworks provide.
This isn’t just because of the mathematical nature of deep learning but also because the applications themselves are also mathematically complex e.g. computer vision.
This is basically the equivalent of asking what should you do website development or signal processing as a developer these aren’t exactly on the same level.
Does that open up the NSA to a lawsuit from those U.S. companies that were attacked by the same tools the NSA created and used against targets in China?
It seems like there ought to be some liability for any organization that gives this kind of technology to another organization who is likely to misuse it, even if "give" in this instance means "use it against them".
The Shadow Brokers released source code and the USA still doesn't know how it was leaked. There's no source code in an "interception".
Now, if the economy turns really sour, then like Indonesia in the 90's they may discover that the populace gets restless very quickly. But, for now, I think the Chinese middle class is not in the mood to make big trouble.
The West is used to seeing the decrepit aspect of the Chinese and associates that with its characteristic societal structure. But this nation also has an aspect of splendor. This renewed splendor appears to bother some in the West. In fact, any sort of renewal of Asia not under the control of the West is "alarming" to the West.
Don't worry. Asians don't hold grudges .. ;)
Somehow I'm not convinced.
Hong Kong is NOT China.
> Hong Kong is NOT China. It actually is, while HK enjoys a high degree of autonomy, it is still a "special administrative regions" of China and has been since 1997 when the 99 year lease expired.
But I meant in the context of this discussion. China's intelligence agencies consider Hong Kong to be home turf just like the Puerto Rico is home soil for the NSA.