The West’s failed fight against China’s ‘Cloud Hopper’ hackers
reuters.com
reuters.com
I don't know if the fact HP got hacked repeatedly is stronger evidence in favour of the competence of the attacker or of the incompetence of HP.
“The security of HPE customer data is always our top priority”
The story then tells otherwise - they kept relevant information from affected customers and even thwarted their own investigation team to keep customers in the dark.Clearly public image and short-term financial results were the real priorities.
Also a lot of questions are dodged with the "we have found no evidence in any of our extensive investigations that..." answer that provides full deniability. That only makes it plausible that much more happened here.
With airgapped servers, the question is, how do you install updates? There's almost always a way; IT needs it. With those updates, you can get an attack, if the machine supplying the update has been compromised.
For example, even if the update comes via a DVD, some machine wrote the DVD. If you can corrupt that machine, you can corrupt the DVD. Now you have a way to (eventually) get hostile code on the airgapped server.
I could care less what was used in the attack detailed by the article. I was replying to a specific comment, not the article.
SPECTRE, Meltdown, Rowhammer are just a few risks amongst thousands. Most importantly they at least have runtime signatures that could be detected.
There are weaker areas for directed attacks against an organisation (e.g. spear-fishing).
When attacked by highly skilled, highly motivated, highly resourced and foreign opponents, an org may find they are better relying upon an external team for securing your VMs. I would expect Google Cloud to be far better than the majority of fortune 500 companies at securing hypervisors and VMs.
b) You're not running untrusted, random stranger code on your Fortune 500 VM's. I can't signup for an account on Ford's VM's and start ripping through memory like I can with a public cloud.
But definitely running in public shared cloud exposes you to certain kinds of attack vectors that are not present in an on-prem deployment.
But it also protects you from certain types of attack vectors that your on-prem may not.
For example, you can be a co-incidental victim of a mass hack of public cloud. But it would be difficult to target your specific machines in the cloud (assuming your application surface is secure) but it might be easier when you are on-prem (easy to locate, isolate and infiltrate etc).
We had a set of sites on a special hardened security wise anti=hack anti ddos platform... and when that cloud got hacked they got all of our stuff and everyone else's and put it all on the dark net I believe. This was apparently because one of their customers was a semi-high profile target..
We found out a couple days later when the credit card on file started being used around the world, and that card had only ever been used at 2 places. We were not notified by the company.
We did read about it in a story a couple days later that named our hosting company in a sidenote when noting the one client that was hacked / defaced / exposed whatever.
Sadly in this case we would of been better off with non-cloud, non-extra-secure hosting.
As others have said, if it's connected it's vulnerable, I agree. There are different risks for different hosting situations.
Not saying it couldn't happen, it just seems unlikely.
sigh...
If the service that you're running is not made by idiots that will store your password with anything weaker than PBKDF2 then a strong (unique) password is still a good bet.
Human factors are an issue and I believe lack of enforcement and prosecution is another issue.
A rested, focused, well-trained human is almost bug-free. No one is rested, focused or well-trained 100% of the time.
For instance, someone gets a malicious email, and clicks on a link which downloads a bit of code the exploits a bug in the software to install something, perhaps a key logger or screen reader.
What on earth does hardware keys do to eliminate that?
Seriously, I can’t make the connection (and if I understood I’d probably roll that out across my firm tomorrow!).
Malware downloads is a separate issue from phishing schemes.
I’m reminded of back when Kevin Mitnick said it wasn’t that he was a great hacker, but that he was good as social engineering. What made him good was that he took the easiest way in, which is kind of what my point is. I don’t care if you block the hardest hack - I care about blocking the easiest.
(FWIW, I am a huge fan of 2FA, I just don’t understand how it stops phishing.)
The way U2F prevents phishing is by binding auth requests to the requesting origin and generating unique key pairs for each origin, so it doesn't matter if the user is convinced and manually activates the key, the phishing site gains nothing it can use on a different origin—even in real time.
My entire argument was "with U2F, this is the easiest hack, and it is very hard."
What do you think the easier alternative was?
One definition is tricking users into giving valuable information (such as passwords, 2FA codes, bank account details, credit card numbers, social security numbers, etc). Malware doesn't meet this definition of phishing.
Link to their somewhat vague white papers on the matter:
Google stopped allowing Windows to be used within the organisation in 2010 as a response.
I think any other organisation that continued to use Windows values features more than they value security (and I believe that is still the case: you can't secure Windows, Office or Microsoft browsers against state level actors).
It's annoying.
Seriously, right!
https://microsoftazuresponsorships.com https://getlicensingready.com/ https://sysinternals.com (fairly popular and well-known!) https://www.microsoftpartnercommunity.com/ https://azureedge.net
etc
This is so true. When you have app.<appname>.tld, <appname>app.tld, app.<appname>app.tld, cdn.<appname>.tld, cdn.<appname>app.tld, <appname>cdn.tld, <company>.tld, <appname>.<company>.tld, <company>corp.tld, etc, it's difficult for even tech-savvy users to spot fake domains, especially since there can be multiple TLDs used with seemingly no consistency. Then someone comes along and registers <cornpany>.tld, <company>.othertld, or <compаny>.tld (the "а" is a cyrillic "a")...
Even if you try to integrate Oauth so you can tell users "only enter your username/password on auth.<company>.tld", it's not always consistent. Google will require your email before redirecting, some services require an email and a password (whether it's correct or not) before redirecting, others have special company-specific subdomains, and I've seen a couple where you have to click on an SSO link on the login page and type in your company's domain. Then you get services where you type in your username/password into their site and it authenticates through AD or another backend mechanism which never goes through your Oauth flow (my college had O365 setup like this), bypassing 2FA and defeating the "only auth.<company>.tld is trusted" message.
The best solution I've seen for all of this is an internal TLD, but that requires a VPN to access from offsite, you have to maintain your own CA and DNS (which a much greater impact when it goes down), some services will not allow Oauth redirects to them, and it only works for internally hosted applications.
APT10 is a state sponsored hacking group.
The US government accused them of working for China[2]. Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up.
[1] https://www.crowdstrike.com/blog/two-birds-one-stone-panda/
[2] https://www.justice.gov/opa/press-release/file/1121706/downl...
All I'm seeing is the Uber receipt, which even they say they can't verify.
>It's not 100% proof, but what are the alternatives, and what chances do they have?
The alternative is that they are black hat hackers, which is very likely.
>Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up.
The default position should be skepticism, and any evidence should be made public before a "hard line" is taken on China.
There's other stuff there. For example Gao was recruiting for Laoying Baichen Instruments which shares an address with CNITSEC (which is run by MSS). CNITSEC has in the past been confirmed to work with APT3.
>The alternative is that they are black hat hackers, which is very likely.
Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government. For example APT3 and APT1. Also the APT10 stuff appears to have happened during Chinese working hours, which is indicative of government work[1].
[1] https://intrusiontruth.wordpress.com/2018/08/09/was-apt10-th...
They can't verify that was Gao, that the poster represented that company, or show that they occupied the office building with the other company.
>Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government
Any hack reported by the western media immediately gets linked to the government, no matter how thin the evidence is. Chinese people can be smart and motivated by greed too, and they have a ton of people.
If you personally think China is behind this based on the released evidence, that's fine. Using it as justification for attacks on the Chinese requires more proof to even be considered.
The October hack of Facebook[1] didn't seem to be blamed on any government by the media. It seems to me like a fairly sophisticated attack that could have been done by a government.
And the western media blames some hacks on the US government and its allies as well[2][3].
> Chinese people can be smart and motivated by greed too
How do they plan to make money by hacking NASA and the US military's shipbuilder? They're not installing ransomware asking for bitcoin payment. If they want to hack for money, I would think they would target credit cards, or banks, or better yet: cryptocurrency exchanges. Or maybe popular websites whose databases they can use for credential stuffing. One way to make money by hacking NASA is to be paid by the Chinese government.
[1] https://www.nytimes.com/2018/10/12/technology/facebook-hack-...
[2] https://www.reuters.com/article/us-usa-cyber-yandex-exclusiv...
[3] https://www.nytimes.com/2010/09/30/world/middleeast/30worm.h...
Sorry, I should have said "any hack originating in China." Poor wording on my part.
>How do they plan to make money by hacking NASA and the US military's shipbuilder?
Their methods were to gain access to a machine, and then try to use that access to jump to client servers. There's nothing saying NASA or government contactor's were specifically targeted, but seem like excellent jump targets if an opportunity arose.
For example, researchers at Malwarebytes [1] say:
> "While this supports the thesis of APT10 being a government threat group, we caution defenders against associating any one piece of malware exclusively with one group. Countries maintain multiple threat groups, all of whom are fully capable of collaborating and sharing TTPs."
> "Variants of PlugX and Poison Ivy were developed and deployed by Chinese state-sponsored actors. They have since been sold and resold to individual threat actors across multiple nations. At time of writing, it is inappropriate to attribute an attack to Chinese threat actors based on PlugX or Poison Ivy deployment alone."
Likewise, the report put out by PwC and BAE [2] label APT10 only as a "China-based actor". They cite things like attacks occurring during Chinese timezones and CCP-interest aligned hacking as evidence. This is all great circumstantial evidence and while compelling, it is far from conclusive. The report does not mention the Chinese Ministry of State Security even once.
We can say how likely or unlikely something is, but the likelihood of something in the context of circumstantial evidence should not be taken as a full-on indictment. The most one could say conclusively is that it is likely to be state sponsored.
[1] https://blog.malwarebytes.com/cybercrime/2019/01/advanced-pe...
[2] https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report...
This is not a valid reasoning.
No, we don't buy that anymore.
If "To be fair, isn't this functionally equivalent to the NSA attacks on Huawei and Chinese aircraft manufacturers over the past decade" is indeed a logically valid comparison, is that not a perfectly valid rebuttal to ~scare mongering accusations of "state sponsored attacks" from China? It doesn't nullify it, but it puts it in accurate perspective, no? And should not accuracy be an important part of such conversations?
Pretty low-effort stuff, tbh. It's up there with "fake news!" as a credible rebuttal.
Constructively pointing out hypocracy is to also call for B to be held to account. Whataboutism isn't constructive; it's obstructive.
In many cases, it's even worse. Whataboutism is often used to argue that the hypocracy of B negates the complaints of third party C against A. Nobody is claiming HP or the journalists have tried to hack the Chinese government, or that HP or the journalists support the NSA's misdeads.
Whataboutism impedes progress and should be called out when encoutered.
When you bring up something quite related to the presented problem, that's not whataboutism.
In my experience, it's almost always used in the latter (incorrect) sense.
That is the essential problem of whataboutist arguments
Manufacturing is and that can be relocated.
If your reply is going to be about British textile machinery or some one-off accusation from the last century, please focus on the scale of the accusations against the CCP, as well as consensus global norms of the current era.
As long as we're talking about unsubstantiated claims (and yes, that is all they are at the moment unsubstantiated), I would hazard a guess that the U.S is by far the largest, most capable and most pervasive wager of cyber warfare and espionage of them all -which incidentally is probably the reason why they are so paranoid. One would have to be supremely naive to think otherwise.
Many tools used by these alleged Chinese state hackers were likely generously donated by the NSA themselves during their own cyber operations [1].
The consensus global norms of the current era is that everybody is hacking everybody at massive scale in order to further their own strategic interests -the same as it has always been. The only thing worthy of attention is the fact that these attacks are only being publicly disclosed now, coincidentally in the middle of a trade war, when the U.S administration is grasping for support from the American public against China.
[1] https://www.nytimes.com/2019/05/06/us/politics/china-hacking...
I'm talking about concerted IP / business secrets theft which is then funneled to domestic companies. I call these companies "state-controlled" because they are ultimately susceptible to the authoritarian central government's will.
I can't think of anywhere else in the world where this is not only routine, but coordinated at massive scale. Can you inform me what I'm missing?
Edit: I disagree with your last point too. There's been plenty of reporting on Chinese IP theft dating back years, it's only increased in prominence. Trump is waging the trade war partially because of the history of hacking. It was a point of contention throughout Obama's admin too, but Trump is handling it his way. (Obama's answer was TPP, but deployed too late)
> I can't think of anywhere else in the world where this is not only routine, but coordinated at massive scale. Can you inform me what I'm missing?
Why would you need me to inform you about something that I’ve never claimed? My claim is that nobody’s hands are clean when it comes to cyber warfare, not that China has never before engaged in the type of espionage you describe.
> Edit: I disagree with your last point too. There's been plenty of reporting on Chinese IP theft dating back years, it's only increased in prominence. Trump is waging the trade war partially because of the history of hacking. It was a point of contention throughout Obama's admin too, but Trump is handling it his way. (Obama's answer was TPP, but deployed too late)
I’ve addressed the industrial espionage point above. As far as the trade war: Trump is waging his trade war because of the trade imbalance between the U.S and China as he has repeated ad nauseam since day one. There was a particular point in time (probably around the time of the as-of-yet unsubstantiated and unretracted Bloomberg Supermicro story) where the hacking narrative was retroactively shoehorned in as a reason. I stand by my opinion that the timing of this report, along with the other recent mountains of anti-China mainstream media stories and social media posts, is highly suspect.
If the companies are susceptible to the government's will, then attacks against the government would also be attacks on the companies. Defense and recovery against geopolitical espionage diverts resources away from those companies. Why is the drain on profit industrial espionage causes a problem while a drain on resources is acceptable?
There is no consensus on 'norms' for cyber-espionage and every country is operating the the gray-areas. There is no red-line that defines what an act of war is. It wasn't long ago that the NSA was listening to Angela Merkel's phone calls; this is far more aggressive than industrial espionage, in my book.
Every nation does industrial espionage - in the "national interest"
"Report on forced organ harvesting in China"
https://news.ycombinator.com/item?id=20249489
We're in a situation where we are confronted by our own fundamental values and what they mean to us and what we're willing to do about it.