Manufacturing is and that can be relocated.
APT10 is a state sponsored hacking group.
The US government accused them of working for China[2]. Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up.
[1] https://www.crowdstrike.com/blog/two-birds-one-stone-panda/
[2] https://www.justice.gov/opa/press-release/file/1121706/downl...
All I'm seeing is the Uber receipt, which even they say they can't verify.
>It's not 100% proof, but what are the alternatives, and what chances do they have?
The alternative is that they are black hat hackers, which is very likely.
>Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up.
The default position should be skepticism, and any evidence should be made public before a "hard line" is taken on China.
There's other stuff there. For example Gao was recruiting for Laoying Baichen Instruments which shares an address with CNITSEC (which is run by MSS). CNITSEC has in the past been confirmed to work with APT3.
>The alternative is that they are black hat hackers, which is very likely.
Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government. For example APT3 and APT1. Also the APT10 stuff appears to have happened during Chinese working hours, which is indicative of government work[1].
[1] https://intrusiontruth.wordpress.com/2018/08/09/was-apt10-th...
They can't verify that was Gao, that the poster represented that company, or show that they occupied the office building with the other company.
>Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government
Any hack reported by the western media immediately gets linked to the government, no matter how thin the evidence is. Chinese people can be smart and motivated by greed too, and they have a ton of people.
If you personally think China is behind this based on the released evidence, that's fine. Using it as justification for attacks on the Chinese requires more proof to even be considered.
The October hack of Facebook[1] didn't seem to be blamed on any government by the media. It seems to me like a fairly sophisticated attack that could have been done by a government.
And the western media blames some hacks on the US government and its allies as well[2][3].
> Chinese people can be smart and motivated by greed too
How do they plan to make money by hacking NASA and the US military's shipbuilder? They're not installing ransomware asking for bitcoin payment. If they want to hack for money, I would think they would target credit cards, or banks, or better yet: cryptocurrency exchanges. Or maybe popular websites whose databases they can use for credential stuffing. One way to make money by hacking NASA is to be paid by the Chinese government.
[1] https://www.nytimes.com/2018/10/12/technology/facebook-hack-...
[2] https://www.reuters.com/article/us-usa-cyber-yandex-exclusiv...
[3] https://www.nytimes.com/2010/09/30/world/middleeast/30worm.h...
Sorry, I should have said "any hack originating in China." Poor wording on my part.
>How do they plan to make money by hacking NASA and the US military's shipbuilder?
Their methods were to gain access to a machine, and then try to use that access to jump to client servers. There's nothing saying NASA or government contactor's were specifically targeted, but seem like excellent jump targets if an opportunity arose.
For example, researchers at Malwarebytes [1] say:
> "While this supports the thesis of APT10 being a government threat group, we caution defenders against associating any one piece of malware exclusively with one group. Countries maintain multiple threat groups, all of whom are fully capable of collaborating and sharing TTPs."
> "Variants of PlugX and Poison Ivy were developed and deployed by Chinese state-sponsored actors. They have since been sold and resold to individual threat actors across multiple nations. At time of writing, it is inappropriate to attribute an attack to Chinese threat actors based on PlugX or Poison Ivy deployment alone."
Likewise, the report put out by PwC and BAE [2] label APT10 only as a "China-based actor". They cite things like attacks occurring during Chinese timezones and CCP-interest aligned hacking as evidence. This is all great circumstantial evidence and while compelling, it is far from conclusive. The report does not mention the Chinese Ministry of State Security even once.
We can say how likely or unlikely something is, but the likelihood of something in the context of circumstantial evidence should not be taken as a full-on indictment. The most one could say conclusively is that it is likely to be state sponsored.
[1] https://blog.malwarebytes.com/cybercrime/2019/01/advanced-pe...
[2] https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report...
This is not a valid reasoning.
If your reply is going to be about British textile machinery or some one-off accusation from the last century, please focus on the scale of the accusations against the CCP, as well as consensus global norms of the current era.
As long as we're talking about unsubstantiated claims (and yes, that is all they are at the moment unsubstantiated), I would hazard a guess that the U.S is by far the largest, most capable and most pervasive wager of cyber warfare and espionage of them all -which incidentally is probably the reason why they are so paranoid. One would have to be supremely naive to think otherwise.
Many tools used by these alleged Chinese state hackers were likely generously donated by the NSA themselves during their own cyber operations [1].
The consensus global norms of the current era is that everybody is hacking everybody at massive scale in order to further their own strategic interests -the same as it has always been. The only thing worthy of attention is the fact that these attacks are only being publicly disclosed now, coincidentally in the middle of a trade war, when the U.S administration is grasping for support from the American public against China.
[1] https://www.nytimes.com/2019/05/06/us/politics/china-hacking...
I'm talking about concerted IP / business secrets theft which is then funneled to domestic companies. I call these companies "state-controlled" because they are ultimately susceptible to the authoritarian central government's will.
I can't think of anywhere else in the world where this is not only routine, but coordinated at massive scale. Can you inform me what I'm missing?
Edit: I disagree with your last point too. There's been plenty of reporting on Chinese IP theft dating back years, it's only increased in prominence. Trump is waging the trade war partially because of the history of hacking. It was a point of contention throughout Obama's admin too, but Trump is handling it his way. (Obama's answer was TPP, but deployed too late)
> I can't think of anywhere else in the world where this is not only routine, but coordinated at massive scale. Can you inform me what I'm missing?
Why would you need me to inform you about something that I’ve never claimed? My claim is that nobody’s hands are clean when it comes to cyber warfare, not that China has never before engaged in the type of espionage you describe.
> Edit: I disagree with your last point too. There's been plenty of reporting on Chinese IP theft dating back years, it's only increased in prominence. Trump is waging the trade war partially because of the history of hacking. It was a point of contention throughout Obama's admin too, but Trump is handling it his way. (Obama's answer was TPP, but deployed too late)
I’ve addressed the industrial espionage point above. As far as the trade war: Trump is waging his trade war because of the trade imbalance between the U.S and China as he has repeated ad nauseam since day one. There was a particular point in time (probably around the time of the as-of-yet unsubstantiated and unretracted Bloomberg Supermicro story) where the hacking narrative was retroactively shoehorned in as a reason. I stand by my opinion that the timing of this report, along with the other recent mountains of anti-China mainstream media stories and social media posts, is highly suspect.
If the companies are susceptible to the government's will, then attacks against the government would also be attacks on the companies. Defense and recovery against geopolitical espionage diverts resources away from those companies. Why is the drain on profit industrial espionage causes a problem while a drain on resources is acceptable?
There is no consensus on 'norms' for cyber-espionage and every country is operating the the gray-areas. There is no red-line that defines what an act of war is. It wasn't long ago that the NSA was listening to Angela Merkel's phone calls; this is far more aggressive than industrial espionage, in my book.
Every nation does industrial espionage - in the "national interest"
No, we don't buy that anymore.
If "To be fair, isn't this functionally equivalent to the NSA attacks on Huawei and Chinese aircraft manufacturers over the past decade" is indeed a logically valid comparison, is that not a perfectly valid rebuttal to ~scare mongering accusations of "state sponsored attacks" from China? It doesn't nullify it, but it puts it in accurate perspective, no? And should not accuracy be an important part of such conversations?
Pretty low-effort stuff, tbh. It's up there with "fake news!" as a credible rebuttal.
Constructively pointing out hypocracy is to also call for B to be held to account. Whataboutism isn't constructive; it's obstructive.
In many cases, it's even worse. Whataboutism is often used to argue that the hypocracy of B negates the complaints of third party C against A. Nobody is claiming HP or the journalists have tried to hack the Chinese government, or that HP or the journalists support the NSA's misdeads.
Whataboutism impedes progress and should be called out when encoutered.
When you bring up something quite related to the presented problem, that's not whataboutism.
In my experience, it's almost always used in the latter (incorrect) sense.
That is the essential problem of whataboutist arguments
"Report on forced organ harvesting in China"
https://news.ycombinator.com/item?id=20249489
We're in a situation where we are confronted by our own fundamental values and what they mean to us and what we're willing to do about it.