Chinese military personnel charged for hacking into Equifax
justice.gov
justice.gov
Their worry is that foreign countries will eventually retaliate by charging people who are involved in US government programs to hack those foreign countries.
Another worry is that indicting people might give away information information about your sources and methods.
[1] https://www.mcclatchydc.com/news/nation-world/national/natio...
It’s ridiculous how many people here seem to think China is somehow special as far as this sort of hacking goes.
Shadowbrokers leaks even make it easy to identify specific NSA operators, for example Michael A Pecoraro, Nathan S. Heidbreder, Gennadiy Sidelnikov and a Brian C Fong
Going after specific Chinese individuals means throwing these US operators under the bus.
Considering many of these soldiers are probably conscripts and might be killed or imprisoned if they don’t follow orders to hack us, I can see the case for treating them like normal soldiers and not like criminals.
On the other hand I guess charging individuals is a way for the government to ignore that ultimately China’s government is the one responsible for their military’s actions.
How are non "cyber" crimes handled? Is it normal to charge people for the murders, thefts, and other illegal activities intelligence officers perform?
I'm not going to make a moral judgement here, I'll just say that I'm not a fan of treating "cyber" as some magical realm where there are no norms.
On the contrary, I think we are pulling in too many assumptions into "cyber". Imagine this: if someone had left their door unlocked and someone came in and stole their lawn mower, you could say they deprived the owner of use of their lawn mower. However, imagine if equifax removed [authorize] in an http endpoint like /v2/person/:id allowing anyone to just GET /v2/person/1 .. 999999999 consecutively. Is this a criminal matter? I'd say no. I'd go further and say that this "cyber" fearmongering has gone too far and we should ABOLISH the CFAA. The EFF has still laid their hopes on reform but I for one think it is irredeemable and must be abolished with no replacement.
Intent has to matter a lot in these cases, though.
If a bill blows a mile away and somebody happens to find it with no knowledge of the crash, that's qualitatively different than witnessing the accident and then rushing to grab the money you watched spill out.
How about to copy?
I think that a better comparison would be with an armoured truck having left open its doors and spilling top secret documents all over the road.
If you want to print them though, I am pretty sure that it is legal as long as you include a clear disclaimer that they are fake.
These are very different things and regulated in different ways. This is some weird version of strawman.
This is different from information which is inherently not physical, so any copy of representation is a copy. The grey area of course is a lossy copy... redistributed low-res copies of art, etc.
Maybe I'm wrong about this, but I'm pretty damn sure if you use tor the right way they're not ever going to find you unless you give yourself away some other way.
Furthermore, perhaps I operate a crawler or an internet archiving service, and i dont even know i am collecting it.
The "place" metaphor was intended to help people who don't have an intuitive understanding of communication networks. Since POTS had existed for many decades, it's not clear that this metaphor was ever necessary. No one ever confused a phone number with a place. Now that most living people have had childhoods during which the internet existed, the metaphor is certainly not necessary now.
If host A on the internet responds to a simple unauthenticated GET from host B with PII, we really shouldn't be blaming host B. The "place" metaphor obscures that fact.
It depends, I'd say mostly on the public outcry. For "extralegal renditions" aka kidnapping by the CIA in Europe, some investigations were happening, some charges were brought, but I haven't heard anything about conclusions.
Cyberspace attacks even against allies have generally been considered part of diplomacy, e.g. the US breaking into Germany's telecommunication systems to spy on Merkel's SMS.
Since this isn't even a state <=> state issue, it's more like the NSA's decades long industrial espionage: business as usual.
In the former case a physical crime was committed where the suspect and criminal act were both in the geography where the crime is alleged. If not for diplomatic status there would be nothing unique about this case and criminal proceeding would move forward with the suspect in apprehension.
In the later the suspect has no relationship to the geography where the crime was committed. The suspect is not a resident or citizen and was not present or planning to visit the geography in question. Furthermore the suspect was likely acting on orders of a nation-state and so bears limited responsibility. There is no legal recourse to apprehend the suspect.
Well that's just wrong.
There's diplomatic immunity unless the visiting country explicitly waves it. It's not based on some hypothetical legal theory of whether she should have it or not. The visiting country either waves it, or doesn't.
In this case, the police requested a diplomatic waiver and were denied.
https://opil.ouplaw.com/view/10.1093/law/9780198703969.001.0...
Additionally, the husband was not on a diplomatic mission, was not a registered diplomat, and does not qualify for diplomatic immunity by the rules of the host country.
Neither does his wife.
The rules only matter with regard to who's allowed entry under what status. They're not subject to review after entering, except for expulsion.
I'm going to assume you're conflating the definitions of diplomat. The Vienna convention only sets a minimum standard. The things you're taking about might matter if it's the US and maybe Libya.
For friendly countries, there are agreements that extend the diplomatic privileges well beyond the core diplomatic party.
And once rules are agreed upon, they only apply to who is let into the country under what status. So entry can be denied, but once allowed in with a diplomatic or official passport, the host country can't change that status. All they can do is expel the person.
If the UK allowed entry under a diplomatic / official passport, that's all that matters.
Regardless, in a "possession is 9/10s if the law" sort of way, the only thing that matters in practice is if the visiting country waives immunity.
The victim's family recently accused the driver of working for the CIA, and if she was in fact a spy she absolutely doesn't have immunity. That's just an accusation, of course.
There's no other measure of quality that matters in a practical sense. If the host country wants to dispute that, their recourse is expulsion.
And CIA and other agencies certainly do act under the auspices of diplomatic protection. Barring any movie-like treasonous behavior, why wouldn't they? They're government officials working in an official capacity while abroad.
Besides, being ex-CIA doesn't disqualify spousal immunity. Even if the host country had a problem with that, the recourse is... expulsion.
This is such an American-centric view of the world. If you don't want to abide by the moral standards of another country, maybe... uh... don't go there?
Laws and courts are there for all. The fact that this lady killed a child, and chose to flee the country, says a lot about her character. All this would have probably been resolved with a generous compensation (by the US gov to the victim's family)(all except bringing the child back). She didn't do anything on purpose until she flipped the finger to UK justice and the victim's family and ran away like the rat she is (let's not forget that she killed a child). US gov on the other hand protects its citizens (even those who kill children and flee justice - great job USA)(she was in the UK, she would have a fair trial). It's a messed up sorry that only has pain, sorrow, and anger.
I'm not saying there shouldn't be any compensation or repercussions, but the possibility of 14 years for an accident is absurd. If it wasn't an accident or if she was in fact negligent, that's another story. And what precedent would the US gov be setting by turning over gov employees working abroad (or their families)?
Now that you know I basically have gone through this, maybe you should re-think your sentiment.
But isn't Anne Sacoolas walking free?
You haven't "basically gone through this", since person that killed your sister was held accountable for their actions.
Anne Sacoolas was not held accountable, that family has no closure unlike yours.
> If it wasn't an accident or if she was in fact negligent, that's another story
She is to be charged with "causing death by _dangerous_ driving", not an accident.
All that being said I'm sorry about your sister and I hope you're doing OK.
And that's ignoring the implications of it possibly being a state actor.
Good. If you get caught committing a crime you should be charged with it.
> Another worry is that indicting people might give away information information about your sources and methods.
Also good. US intelligence should not be holding back 0days.
Presumably you’re fine with trying all of the US soldiers who killed other soldiers in war with murder?
Shooting the enemy is not murder.
So any military personnel that kill someone while doing his job should be able to be charged for murder?
- the military personnel did not kill someone in order to defend themselves
- they kill civilians
- they kill other military personnel during peace time
Then yes, they should be charged with murder.
I see that you did some effort choosing the word "peace time" to be able to say "well we are at peace with China, thus this is fine to charge them", but at the end of the day, what is peace time? Does receiving the order to attack a target make it become a war? They got an order to attack the US company, this is not peace.
Incorrect, actually I did it because I am against events such as the murder of the Irani general. I personally do not think that hacking should be illegal so I do not think that the chinese agents should be charged in this instance.
> but at the end of the day, what is peace time?
Not having a formal declaration of war.
If it were really about providing secure services then we'd be holding companies responsible, and even encouraging hackers to clean up those systems by hacking them. But it isn't about security so instead we're criminalizing hackers and engage in security-theater.
https://theoutline.com/post/8610/united-states-russia-whatab...
Whataboutism, according to my understanding, would be saying that it's OK for China to hack because the US hacks. That's not what the top comment is about.
The top comment is about some in the US intelligence community saying that the US indicting named foreign hackers for hacking US targets might put US hackers in danger and might leak information about US intelligence capabilities.
1. Foreign nationals, working (?criminally) to exfiltrate information from US companies (or servers in the US) can now be subject to US laws directly?
Isn't this the same as what I saw with the Julian Assange case, where he facilitated his actions while in a foreign country?
It seems there's been a new international law that's been set up that draws a line for any international hacking? But the article doesn't read that way... There no international criminal courts mentioned...
If that's the case, should I start recording all the US ips that try to hack into my servers, and take legal steps to have them arrested and extradited to my country? (What a nightmare!)
2. The ability for doxxing of these individuals by the US despite taking significant steps to hide their tracks indicates a certain level of Pwn-ership of the internet as a whole by the US. How could individuals have been revealed? Is ipv6 enough to de anonymise to individuals machines or is the US able to 'packet watch' across the entire internet?
Edit: better wording of concerns
Of course. We live in the 21st century, it's possible to commit crimes in countries you've never visited from halfway across the world. If such people weren't subject to criminal law where they committed their crimes, IT-support scammers, ransomware crooks, and all kinds of other criminals would act with even more impunity than they already do.
Should China issue an Interpol warrant for CIA's John Doe that handles US spy assets in China? I am sure there's a Chinese law against it
>The nine-count indictment alleges that Wu Zhiyong (吴志勇), Wang Qian (王乾), Xu Ke(许可) and Liu Lei (刘磊) were members of the PLA’s 54th Research Institute, a component of the Chinese military.
How were they identified exactly? I'm always fascinated with these DOJ indictments of foreign state actors but I'm always left wondering how they managed to narrow it down to a small group of people. I'm guessing that "PLA’s 54th Research Institute" employs thousands of people so how does the FBI/DOJ identify the culprits so precisely? Is it through CIA/NSA spying and moles inside the PLA?
You don't see foreign governments identifying individual NSA employees when the NSA hacks into something... so how does the DOJ do it?
If they made it public, they could never do it again.
You don't see foreign governments identifying individual NSA employees when the NSA hacks into something...
I suspect that it does happen, but most people don't know about it because that requires knowing another language, and then regularly keeping up with the media of another country in that language.
The case will never go to court. The DOJ knows it so they don't have to have actual evidence.
The indicment is being publicised for political reasons.
The Chinese are a bogeyman comparable to the Russians. Being tough on them and have the other party being in bed with them is something that is surely useful in a coming election campaign.
As for the ability to trace back traffic sent through 30+ computers placed around the world including China; just think of what surveillance and logging that would entail. It is not really possible.
Then DOJ would have to reveal their sources, wouldn’t they?
Of course not, that would be idiotic, and horrible for morale. You don't give your own people up, regardless of whether or not they are innocent or guilty.
As such, this is a spherical cow thought experiment. To address it - it's quite likely that the sources would not be revealed in an open trial, due to the catch-all of national security. For a helping of double irony, the sources are likely the product of... Espionage (Digital or otherwise).
Also consider how US treats 'threats to national security' - Chelsea manning, indefinite detention in Guantanamo bay, etc.
This is also why the US is not even a signatory of the ICC. It, by principle, opposes the sheer notion of Americans facing international trials for war crimes, even in impartial, third party courts. There's no way in hell it would extradite its spies to face trials for computer crimes.
It's arguments for not participating in the ICC are that the trials would be political, and not impartial. That's a stick with two ends.
[0] https://www.law.com/nationallawjournal/2019/09/16/were-now-o...
https://nos.nl/nieuwsuur/artikel/2213767-dutch-intelligence-...
See my mysteriously flagged comment demonstrating exactly this https://news.ycombinator.com/item?id=22290767
Of course, we don’t know who TSB were. But it’s not like individual NSA hackers have gone unidentified.
Did the DOJ just indict a bunch of procurement people? ;-)
My guess is they counter-hacked the PLA’s 54th Research Institute to identify the culprits, then used parallel construction for the indictment.
IIRC, the public intelligence report on the Russian 2016 election influence campaign revealed that the US had counter-hacked some of the Russian groups involved, and used the information gained from that as evidence to attribute the overall campaign to the Russians.
[1] https://techbeacon.com/security/why-equifax-breach-should-ne...
There also hasn't been aggressive legislation about it until CCPA. Start adding minimum costs for a breach and things may change.
It's the executives job to keep software up-to-date? Not the engineers building the software or implementing open-source tools? I understand being buck-stops-here accountable for the hack, but how could they be charged for negligence? Was there a conscious decision by the execs to not update the software?
It's be hilarious/sad if the executives got punished for something like not updating software, because you know what the result would be? Companies would set up a system to protect execs and ensure the line-workers would be held accountable for hacks or breaches. That'd make our jobs super fun.
Ultimately, yes. They are in charge, they are accountable.
> because you know what the result would be? Companies would set up a system to protect execs and ensure the line-workers would be held accountable for hacks or breaches.
As if most big companies didn't already have these systems in place.
They’re very particular about this; particular meaning polygraphs and agents talking to your family members. I know because I almost took a job like this (and know a number of people who have) but the pay and location were crap.
How much do you think legislative aides are scrutinized? Political party staff who aren't on the government payroll?
The US has essentially on omnipotent traditional military force that can either engage or assure mutual destruction of any opponent on the earth. Nobody can compete successfully. But humans are crafty, and come up with ways to defeat irresistible force.
As we've seen predicted for 20+ years and demonstrated in the public space for 10, our nation's weakest link is that election system and political finance system, particularly for legislators. The checks and balances that are supposed to prevent egregious behavior are broken (see what happened to most US Attorneys since 2016, the impeachment circus, and 100 other things at the state/local level).
Building dossiers on Americans are a great, obvious way to wield this power and to target and enable espionage/influence activity. Recall that the federal agency that keeps records on background checks was breached a couple of years ago. So now you have a hostile nation state that knows everyone, and all of their background data, with security clearances. You can cross-walk that with Equifax information, health insurance breaches (Recall that Blue Cross was also breached), etc and do all sorts of interesting things.
How many times in the past two years have our boats crashed into one another? The F35 program is a complete failure. When we ran Hormuzi wargames, a rag-tag group that fought through guerilla warfare won until our Navy cried and made the other side "fight fair." In the past 80 years the only win we can claim is the Gulf War. This is seriously overstating our military capabilities.
My inclination is that China would be perfectly capable of doing so, but that they have more effective jobs programs than the States.
No the idea that either China or America would "win" a war with each other is naive at best
I'm not saying that, I'm that the entirety of the US military is incompetent and pumped too full of cash (despite its many failures) that's it's ridiculous to act like no one can compete.
> The US and allies
I know we like to take our satellite states for granted, but that day will come to an end and it seems likely that taking real action against China could be the catalyst.
The war in Iraq hasn't really gone well, has it?
The US won a war in Afghanistan and two in Iraq. Now, the occupations afterwards? Different story.
Wargames are designed to teach lessons. Example: https://time.com/5772665/uboat-wargames
That exercise happened in 2002, after the USS Cole bombing in 2000 ashore with a similar attack. How many warships were sunk by speedboats in the last 18 years?
Omnipotent and "assure mutual destruction" are contradictory if you think about it. MAD ( mutually assured destruction ) resulted from a lack of omnipotence. If one was omnipotent, one wouldn't require MAD.
> As we've seen predicted for 20+ years and demonstrated in the public space for 10...
Who is "we"?
E.g. APT17: https://intrusiontruth.wordpress.com/2019/07/25/encore-apt17...
https://krebsonsecurity.com/2014/03/who-built-the-id-theft-s...
Makes all the people talking about suing Equifax for subjecting them to identity theft look pretty silly.
>"The FBI has about a thousand investigations involving China's attempted theft of U.S.-based technology in all 56 of our field offices and spanning just about every industry and sector," Wray said.
>John Brown, FBI Assistant Director for the Counterintelligence Division, said the bureau has already made 19 arrests this fiscal year alone on charges of Chinese economic espionage.
>In comparison, the FBI made 24 arrests all last fiscal year, and only 15, five years earlier, in 2014.
https://www.zdnet.com/article/fbi-is-investigating-more-than...
The evidence for why is sealed unless there's a trial. There's never going to be a trial, because those guys aren't going to show up to their court date.
It's entirely possible that this has been fabricated for political purposes... It's not like the only people who could disprove the lie (the accused) have any interest in disproving it.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
It would be easy to know who to bribe if you know who works in government, and which one has debt. As part of security clearance check, if you have substantial debt you're not suppose to be able to get a clearance...but I'm sure there are some who get exempt.
From https://en.wikipedia.org/wiki/Office_of_Personnel_Management... I gather that only hearsay was provided to the public, no credible evidence.
https://en.wikipedia.org/wiki/Office_of_Personnel_Management...
If you have a list of federal employees + a list of people's credit histories you can do things like spot people who have security clearances but no credit history.
Jenna McLaughlin did a great piece on how breaches like this are making it almost impossible for intelligence agents to operate under traditional cover:
https://news.yahoo.com/shattered-inside-the-secret-battle-to...
The days of creating a SSN, issuing it a passport + an entry in OPM as a "cultural attaché" at some embassy are waning fast, if not gone already.
Maybe it was to guard against generating useful metadata that could be later breached? Very interesting.
Equifax didn't have good oversight of which systems were patched and instead relied on a single employee to remember to do it. One got forgotten. People broke in using an old exploit and then leveraged into Equifax's network.
Equifax's first problem was bad patch policy. Its second problem was lack of network isolation/intranet security/onion-ing. As soon as an edge server was compromised the attacker hit the jackpot and had everything.
The last problem was lack of audit/accountable into who/what was accessing sensitive data on the intranet. If they had that they still would have been compromised and lost data, but not every customer's record (which took a long time).
Frankly, this really does explain why they were treated with kids gloves after the incident. I was certain after insider trading came to light, the company will fight with US government to stay alive.
Boy was I an optimist.
If the US can identify the individual hackers, then they should be able to identify the physical location from which the military committed the acts of war and respond with the use of force as permitted by the UN Charter and international laws and norms. By responding with grand jury indictments the US sets a terrible and dangerous precedent and is telling foreign governments the US will not do anything in response to military based acts of cyber warfare.
Unsure why they would join a shooting war.
Perhaps aiding and abetting? But an act of war, no.
Why would you believe this? The last time they didn't like their government, they replaced it with the current government. Even the Ayatollah was pissed off that they mistakenly shot down a plane full of Iranians; they weren't about to curb the relatively limited public demonstrations that agreed with him on that topic.
Oh, let me guess... you learned of the average Iranian's great political discontent from the USA war media. "Wishful thinking disguised as reporting" leads to wishful thinking in place of analysis.
Russia won't, neither will most African nations.
There won't be a war anyhow.
Make life miserable for those directly involved and responsible. Next time, others will push back against an order to attack like this because consequences will be personal for them, not just another move in a war
You think Chinese soldiers will push back against orders from above because one time the US made the (supposed) perpetrators lifes miserable?
What do you think China will do? Just say "OK, on second thought you don't have to do that"?
I doubt any government wants someone working for them that invests the majority of their wealth in an adversarial country.
If this were a rogue state, or rogue actors, or non-state related activity like general corruption, as we see with Russian figures, it might make more sense to go after the individuals.
I don't think so. People usually follow orders until the bitter end, especially when the government wields as much power as China's.
The grand powers on the world stage are constantly posturing and taking actions to further their own power. The United States is no different. We, civilians don't know the majority of what is taking place.
A "hot" war between two powers would be of such a great cost in human life, you would want to avoid it at all costs. This means indicting with a grand jury instead of starting a war.
How about we start with securing our systems? Modernize identity and credit reporting, stop relying on social security numbers, etc.
But I, as a civilian am not qualified to answer that question. Nor do I want to answer that question.
This is not a perfect analogy, and I don't want you to think that geopolitics is a zero sum game. But, imagine two heavyweight boxers circling each other in a ring. They are bouncing on the balls of their feet. They are moving in what you would almost call a dance. Most of the "fight" is in their footwork, their positioning. When one does jab, the other blocks, or moves out of the way, or takes the hit. Sometimes they counter. Sometimes they punch. This fight goes on for a long, long time. It is not tit for tat. They both want to win.
What you are saying is "That boxer needs to jab back, because the other boxer jabbed at him."
I think it is best for the population on the other side to feel that as well which is why I prefer an electronic counter attack. We need deterrence. If China was to "jab", let them use other means of interaction that doesn't make us want to attack them physically. The more people who are affected financially by this, the more the call for a physical deterrence whether we agree with people's feelings or not.
The Response should be shifting the Liability back to the credit providers, not the consumers
The idea of "Identity Theft" should be a thing of the past, for you did not have your identity stolen, you still have your identity, no the bank was defrauded by giving money to someone they did not properly vet. 100% of the liability should be on them, not the person who they claim had their "identity stolen"
the Liability for financial Fraud in the US is 180 degrees from where it should be.
Launching missiles at China may make you feel good, but it does not solve the root cause of the problem
"Fixing" takes a long time that does not mean one should not deter attacks on the current system. How does one respond to a broken legacy software system that can be taken advantage of? You restrict the actions that can be performed on that system until it is replaced.
No the response from me, internally is, is how did they get in, how can I plug that hole, and how can I make my systems more robust.
Your response is making china (the hacker) pay, in order to "prevent" future attacks, that is simply naive IMO nor it is a viable solution.
^ this is the deter I am talking about.
APT is on a different level than what you are used to. Also my question was rhetorical. Didn't actually mean for you to answer it. For you or your company it is not a viable solution since you don't have the resources.
I was very careful to specify "respond with the use of force as permitted by the UN Charter and international laws and norms." In other words the UN Charter only permits a response in proportion to the offense. I do think an act of cyber warfare may legally allow us of "armed force" but it would likely have to be limited to targeting the installations where the attacks were coming from (but realistically it is a new and undeveloped area of law with respect to cyber warfare).
The problem in my opinion with failing to act is we signal that there will be no military response, and these acts of cyber warfare escalate to hacking power grids or other infrastructure than results in indirect lose of life. Then due to political pressure all out war becomes more realistic.
I believe it raised to a level above spying and intelligence gathering. It was a state sponsored military act of cyber warfare that infringed on the US' territorial sovereignty.
>The appropriate response would be more akin to hacking back into China's social credit scoring company and snooping around.
The purpose of a proportionate response to military acts under the UN Charter and the use of force and armed conflict is not so much "an eye for an eye" (i.e. you hack me, I hack you), but to put an end to the military operations infringing on your sovereignty ...for example, assuming you believe Iraq had WMDs and chemical weapons or response is not to create stock piles of our own chemical weapons.
The CCP routinely engages in this class of behavior of salami slicing. Tiny little cuts that unto themselves wouldn’t be cause for aggression.
This is the child poking another. Violence isn’t preferable but if one refuses to correct...
So does the US. If you treat this as an act of war, you automatically classify any cyber operation your operatives have executed as an act of war. Against Russians, against EU countries etc. I don't think anybody really wants that.
I am no hacking expert, but the fact that the internet is such an open place and knowledge sharing is so widespread, I would lean to the side that they have comparable hacking capabilities as America. I've yet to hear of a reason why they wouldn't other than the standard " 'Murica #1". And given a dictatorship presiding over a massive economy and a valid raison d'etre for such capabilities, there is no reason they cannot fund an equivalent of the NSA
By declaring such intrusions as an 'act of war' (or maybe something literally just a little less hard sounding) it's a signal to foreign powers of the seriousness of such activities.
There is no doubt that this is a really, really serious act that has to have serious consequences.
In this new 'information era' we have to establish new boundaries. Those boundaries will help establish clarity, validate responses, enable 3rd parties to take a judicial view instead of just a political one etc..
Edit: For the last 30 years, China has been on a fairly exponential path to increasing aggression, there's no reason at all to believe this will not continue to the extent they have the material ability (i.e. supporting economy) unless they are stopped, or it becomes too painful for them to continue. If there is little meaningful response to this action, it will grow 10x. Charging the military staff responsible is the wrong tactic as the state is responsible, not these actors (it may even be against the Geneva convention), but more importantly, the cost to the state is nothing. Throw a few officers under the bus for a massive attack? That is 'no consequence' to them, and maybe even not said charged officers. There won't be any lack of volunteers. There has to be a pretty comprehensive coordinated response, and definitely not just some artefact/negotiating point in a trade war. The response may include trade, but it shouldn't be part of a tit-for-tat in a trade deal.
I specifically said "respond with the use of force as permitted by the UN Charter and international laws and norms."
It seems clear the people responding talking about all out war and "end of human civilization" don't have much experience with the UN Charter, security council and international laws and norms for the use of force. Generally the legal terms of art I used.
The idea is a proportional response to deescalate future cyber warfare attacks...not end all of humanity.
Oh wait, the congress abdicated it's constitutional duty to be responsible for declaring war via the unconstitutional War Powers Act and AUMF's...
AUMFs are (often limited and/or conditional) declarations of war, from a Constitutional perspective, not an abdication of the power; the Supreme Court has consistently held that the Constitution doesn't require magic words when exercising the Constitutional power to declare war.
Look at the range of actions the AUMF's are applied to. The AUMF's, in effect, allow the executive to wage war pretty much anywhere on the planet for an indefinite amount of time.
In your view, is Congress honoring the spirit of their Constitutional duty?
Most declarations of war do not have temporal or geographic bounds. What was unusually expansive about the 9/11 AUMF (not AUMFs more generally, neither prior nor subsequent AUMFs have had this feature) is that it also delegates the decision of the actual primary opponent(s) to executive discretion, which, yes, is an abdication of Congressional responsibility. But that's the 9/11 AUMF, not AUMFs in general.
Know quite a few people with these qualifications, they are highly polarized human beings who seem to have trouble discussing politics.
Because apparently it must be said, I am not a "Nazi sympathizer". I would have preferred that the Nazis had never existed let alone dominated a large portion of Europe. Similarly, it would have been better had we not invaded Iraq and caused ISIS to exist.
But sure you can ignore the nuance.
I would venture to guess I have significantly more experience and knowledge with the UN Charter Article 2(4), the UN Security Council and the international laws on the use of armed force than you.
No one said anything about "go to war", the Use of armed force is not "going to war". The UN Charter permits the use of armed force in response to acts that infringe on the sovereignty of any nation by military action.
To bury ones head in the sand at this point in history to foreign military acts against a populace is inviting more invasive and damaging acts of cyber warfare. Do you honestly think China is going to say we got away with this we should deescalate?
???
> The UN Charter permits the use of armed force in response to acts that infringe on the sovereignty of any nation by military action.
Should France have nuked Fort Meade to stop the NSA from infringing on their sovereignty?
I don't understand this line of thinking, it's basically "if we do it, yeah, it's cool. If they do it, it's an act of war against our innocent republic", and you figure everybody will agree to that and not treat your cyber attacks similarly?
Consider the US Seal Team military operating in Pakistan where Bin Laden was killed. That was use of armed force, we infringed on Pakistani territorial sovereignty, conducted a military operation and even killed a couple people...I hope you understand that this example of using armed force is not the equivalent of "going to war."
China is not nearly as constrained by diplomatic inroads or other mechanisms at play (such as cultural considerations) that would vastly change the potential of any overt action against China causing an exponential series of increasing escalations that could end up as a major war.
I'm not excusing China and not saying the US or other western countries should lay down for China's increasingly agressive diplomatic and strategic actions, but rather that the utmost care should be taken in the response, just as the US is doing in the conflicts going on in the south China sea and increase in espionage cases.
As an Iraq combat vet who has spent quite a bit of time trying to understand these subjects, my general thought is that I really dislike so many armchair quarterbacks speculating and being so eager to throw away others lives, even if in the of potentialities such as your suggestion. War is one of the most horrible things humans can ever experience and any avoidance of it should be sought in almost all cases possible. It's also annoying how many of those armchair quarterbacks usually don't volunteer to serve themselves.
I fully understand that. The thing you are missing is that by ignoring act of cyber warfare from a foreign military and/or treating acts of war by a foreign military as a domestic criminal case, escalates the risk of causing acts of war much larger than if they were to be nipped in the bud now.
>As an Iraq combat vet who has spent quite a bit of time trying to understand these subjects, my general thought is that I really dislike so many armchair quarterbacks speculating and being so eager to throw away others lives
I trust you understand there are many uses of force that do not result in lost lives. The very nature of my argument is that the actions of China's military is an act of war and use of force...yet no lives were lost. As I said we should respond proportionately as authorized by the UN Charter and international law...I am not suggesting WW3, nukes or throwing away lives as has been suggested by countless people in this thread.
Just as much as I am admittedly "speculating" that treating cyber warfare by a foreign military will result in escalated attacks...it is also a speculation to suggest China will deescalate their cyber warfare against us.
So the question would fall to you is the US strategy of treating cyber warfare by a foreign military as crimes going to deescalate China's attacks here?
It's not a "war" because Pakistan isn't a match for the US. It's very much an act of war, though, Pakistan just chooses to ignore the offense because they can't really do anything about it. That's different with China or Russia. Please don't try landing a Seal team in Moscow to extract some hacker.
Orgs like Equifax should not exist. I did not consent to this kind of surveillance, I was forced into it because I needed a paycheck and a place to live. Now I'm paying for it because of the incompetence of others - if the U.S. government instead had this power it would become much more difficult to differentiate between incompetence and malice.
If the US government ran this, you would at least have a chance at congressional oversight. Equifax is largely unchecked in its present corporate state.
I’d argue for a people very dependent on credit, a financial credit score already approaches the burden of a social credit score.
Good Plan.
Personally I am impressed that the War Hawks were unable to persuade the Administration to start a Conventional War over this. Good for them for refusing such an action
https://en.wikipedia.org/wiki/United_States_intelligence_ope...
I honestly don't see how the US could spin anything positively on the world stage in that regard, they are by far the worst offender as far as spying is concerned. It's not even funny to compare. And there is documentation that tech/trade secrets from foreign companies aquired by e.g. CIA or NSA was given to US companies — industrial espionage isn't exactly new or surprising, but when conducted by Federal Agencies above any control, responsibility or accountability to the US public, let alone the UN or the world...
Your suggestion is disingenuous at best and, I'm sorry to say so, terribly blind to the reality of the world, wherein the US is certainly not an all around good guy. Especially these days, it's clearly a hostile power to most others. As seen from the EU, at least, I can't speak for other places/cultures. But I hear it's not that great in general.
I 10000% disagree they should ever have any accountability to the UN or any other international body
I also do not feel bad that they spied on Angela Merkel, I do care that they spied on US Citizens. Spying on Angela Merkel is constitutional and within their remit, Spying on US Citizens is Unconstitutional and not in their Remit
Well not exactly. One was a state sponsored military act of cyber warfare that indiscriminately targeted an entire populace and infrastructure (i.e. a military infringed on the sovereignty of an entire nation state). The other was a targeted intelligence operation.
>Your suggestion is disingenuous at best and, I'm sorry to say so, terribly blind to the reality of the world...
Being from Europe I would assume you would be very familiar with the dangers of failing to act when one military infringes on the sovereignty of another. Though I guess we will see either China will continue hacking and escalate their hacking or they won't...if I were a betting man I would happily take you up on such a bet that China will continue and escalate its military hacking against all nation states.
Should every CIA black and grey op... And any operation by the NSA be considered by the target country as an act of war, too?
If a government employee hacking some software system is an act of war, then the US has committed acts of war against China, Russia, Germany, France, the UK, etc, etc, etc.
Committing an act of war against four nuclear powers sounds pretty irrational to me... Maybe we should reign those two organizations in a bit, before they get everyone killed?
I'd be careful throwing around wishes like that. Are you sure the US doesn't do similar hacks? I'd much prefer people steal data than damage/penetrate critical infrastructure. (The latter is something that should be treated much more harshly, in my opinion)
It may not seem like a distinction to some, but I think there is a difference from hacking by an intelligence agency and directly by a military. Now if you disagree, that is fine, but also each hack would need to be looked at on the merits to determine what would be a proportionate response, if any.
Even more interesting is the question of how the named individuals were identified, which is not addressed in the indictment. The indictment also includes photos of three of the people indicted. This comes across as a shot across the bow to show China that the US govt can identify the individual people doing these things.
"Today, we hold PLA hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the Internet’s cloak of anonymity and find the hackers that nation repeatedly deploys against us."
However, the line:
> 34 servers located in nearly 20 countries
Doesn't describe tor. You don't use that many servers (nodes). And it's strength isn't based on number of hops. That's more old school hack a box and put in a chain.
Then what's the cloak? Is their ability that they can easy "go around" somehow any X number of connections right to the source?
a) They are charged with conspiring with each other to this, but simultaneously b) "fits a disturbing and unacceptable pattern of state-sponsored computer intrusions", and in the process they managed to commit c) "conspiracy to commit wire fraud"
None of those 3 things make any sense in the face of the others. How is doing this kind of things even legal?
I’m curious if there is concrete data breaking down whether recruiting for cyber security roles in the public sector is constrained by culture, compensation or something else.
I worked in the US federal gov't during college and was casually asked if I would consider coming on after college.
If I remember right, fresh college grad compscis would make about $50k / year.
The General Schedule caps out at a GS-15 with a yearly salary of $142k which is basically how much SV will pay a fresh grad.
It makes no financial sense for any CS grad to get a job in the federal government.
You can either maybe make $142k / yr in 20 - 30 years or $200k / yr in about 5 years.
I guess someone could work for a pittance for a few years then leverage an NSA position for absurdly higher pay at a government contractor doing the same thing.
How cool is that. They have been able to grab and correlate netflow from across 20 countries.
It's almost literally the job description of military personnel to conspire to cause mayhem abroad.
The USA engages in actual military campaigns in jurisdictions with whom it is not formally at war.
https://en.wikipedia.org/wiki/Declaration_of_war_by_the_Unit...
"The Equifax security chief noted that the company continues to fend off attempted cyberattacks every day, and expects hacks to escalate in the future. He said that given how dedicated the Chinese military hackers were, a breach could still have happened even if the vulnerability had been patched. "They're extraordinarily sophisticated," Farshchi said in an interview. "I would say that it's possible.""
https://www.cnet.com/news/justice-department-charges-chinese...
Good to see they are confident.
Similarly to the Russian military intelligence officers that were indicted in the Muller investigations?
2/ Create a score of potential recruit-ability based on people's credit history, target them once they enter a field they're interested in.
I like the idea better of making additional keypairs that have a chain of signatures back to your social security card so that you don't have to rely on it as much. It seems to me there's a lot of things that could be very workable as far as this is concern, but just to be clear I just like to use PGP as an analogy to a system that could work.
(This is the same logic many use for opposing backdooring encryption, since often it boils down to key escrow)
The model itself is fundamentally flawed and this hack won’t be the last or the worst.
Bothering with the international politics is a waste of valuable time and energy and will probably just hurt people.
What slander? If credit information is inaccurate, you can have it changed. If they don't do it in a timely fashion, you can sue. (I won several thousand dollars a few years back for a tax lien on my report that wasn't even mine.)
I'm no fan of credit bureaus at all, but "slander" is hyperbole and not even true (and it's an inaccurate word, when credit reports are written, thus the correct word would have been "libel" -- however, even accusing credit bureaus of libel is ridiculous.)
To further dispute the claim that these companies "slander" people, one must look at what the legal test is for defamation.
The company (or person) must have:
1. Published or otherwise broadcast an unprivileged, false statement of fact about the plaintiff
2. Caused material harm to the plaintiff by publishing or broadcasting said false statement of fact
3. Acted either negligently or with actual malice
Credit bureaus don't publish or broadcast. Material harm has to be proven. There must be quantifiable damages. Just shouting someone's potentially inaccurate credit information from the rooftops isn't necessarily causing damages -- it's possible, but those damages would have to be proven. It's not negligent if a file is inaccurate -- it's negligent if they were presented with a challenge of that inaccurate information and refused to correct it. However, admittedly, the bureaus do seem to act negligent rather frequently when it comes to information accuracy -- however, negligence alone doesn't make a defamation case -- the information must be publicly released (i.e. broadcast or published,) and cause material harm.
> and facilitating fraud en mass.
...and facilitating credit en mass... Without credit bureaus there would be a much more difficult credit market and it would be much more subject to discriminatory practices. A credit report can't be racist, but a local bank manager, making a credit decision based on "knowing you" is (and has been,) prone to discrimination and unfairness. The VP's golfing buddy needs a loan: "No problem, we got you!" While the immigrant business owner needs a loan -- a much more difficult proposition. America's economy is the largest in the world -- and contributing to that is the ready availability of credit.
To be clear, I'm not defending credit bureaus from their numerous misdeeds. But throwing words around like "slander" or "fraud" is a childish view on the importance of credit bureaus to the American credit system.
1. nobody has suggested it as an alternative; nobody wants to completely get rid of the system we have now. PKI requires electronics to create and verify signatures created with the keypairs.
2. Because financial institutions do not care and it's not their prerogative. The social security administration is not responsible for people's credit reports and as far as their concerned their is no problem.
3. People are afraid to try new things and new technology and it's up to the government to see that it's done correctly. Theoretically a problem could arise from somebody making a business out of "keeping track of your private key for you" which negates the purpose entirely.
4. People are lazy, and not everybody cares and doesn't necessarily speak to the benefit of people who don't care about their credit or their identity which is why I say it should be an option.
5. If cryptography fails, then the whole thing is pointless. But, I think most people will agree if cryptography fails we will have much bigger problems.
The solution I have in mind is similar to what I've seen with "paper bitcoin wallets" where you have two QR codes: a public and a private key. Imagine a social security card with two QR codes. When you create a bank account, or when you get a state id or something you can get another set of qr codes, that have a record of signatures provided by a state department's private key or that of a financial institution along with a signature provided by your social security card. With your new set you can safely put away your social security card. The idea being, signatures can represent business and billing agreements as well as establishing an identity chain similar to how PGP's web of trust works. Anyone can have your public key, you just have to keep your private keys safe. Even if somehow you stupidly manage to screw this up, it's not that hard to start over. People lose social security cards now and they have to be re-issued. They just have to come up with the system for it and start doing it.
https://docs.google.com/spreadsheets/d/1-YhLDDrFIPlVVXG3EkpA...
Recently there's been a lot of speculation that Shadow Brokers were in fact the "second source". That may or may not be true.
>I mean it's pretty obvious the Shadow Brokers were aligned with foreign policy interests of the Russian government
It's really not. Unless everything anti-US fits that mould, but then we'd have a plenty of other governments to suspect too.
With the OPM breach and the Equifax leak the Chinese have the personal details and biometrics of millions of Americans who work for the government in areas that handle sensitive information.
The Russians have already specifically identified US cyberwarfare individuals before. So, it can be done and has been done. With the information the Chinese already have it is very unlikely they could not do the same, but they'd gain very little from it. (The US doesn't gain much and should probably stop the practice also.)