The FBI investigating hacking of Covid research by “PRC-affiliated cyber actors”
fbi.gov
fbi.gov
1st: most people outside of government don't know how much they are expected/"required" to do to protect their work against foreign nation states. Except for heavily regulated sectors (government, military, heavy industry, banking, core telecom, and more recently elections) very few companies will actually get help from 3-letter-agencies to actively protect against foreign nation state attacks.
2nd: many people expect that the {NSA, Cyber Command, et al} are actively defending all US organizations. I don't see evidence of this (although if there was evidence, I probably wouldn't see it anyway).
3rd: In a national emergency (which the COVID response was declared), there are limits to the liabilities which would otherwise be enforceable in court. There are frequently/always legal escape clauses like force majeure and act of god which would likely alleviate liabilities due to fallout from acts of war or a severe pandemic, so it's not clear that those "nasty liabilities" could be enforced. There are currently 2 important cyberinsurance cases[1] which are winding their way through courts right now which may effectively decide if cyberinsurance is a viable product (depending on whether). Violations of HIPAA are possible, but similarly may not amount to much in terms of prosecution because of the pandemic.
In reality, it's damn near impossible to protect against a motivated+targeted nation state attack (especially with the resources of PRC). If the liabilities incentives require all projects (large and small) be able to withstand nation-state attacks, then all of the project resources go to cybersecurity and none into research -- your productivity is now zero.
It's important to remember that it's the FBI's job to do counter-intel. If a medical research group is defrauded by PRC spies and you blame the researchers for not being able to spot a non-trivial espionage attempt, you are just victim blaming. I work as a product developer in cybersecurity and I doubt I could identify most spy craft if it were to happen right in front of me.
[1] https://www.cpomagazine.com/cyber-security/aig-case-highligh...
If you keep your confidential research results on an unpatched server with weak passwords and exposed to the internet, what is the NSA supposed to do about that?
About the best thing they could do is to scan for and find the vulnerability before the attackers and notify you about it, which in general they don't. And it still wouldn't solve most of the problem because there would be objections if they did more than a cursory scan, which means they won't find most problems, but the attackers are under no such limitations.
> there are limits to the liabilities which would otherwise be enforceable in court
I don't think this is the kind of liability they're talking about. If your confidential research falls into the hands of economic spies, the problem isn't so much that someone is going to sue you as that your research and any relevant patents have now lost their economic value because a knockoff product will beat you to market.
> cyberinsurance
This is liable to be more of a grant hog than liability would. Not only do you have to pay the premiums -- which would be high unless researchers adopt good security practices, which having the insurance would give them the incentive to do the opposite of -- but you also then have the insurance company imposing some kind of bureaucratic best practices procedures that gives you even more compliance costs than you would get from having liability, because the insurance company has misaligned incentives with respect to the level of compliance burden to impose, since they don't pay any of it but get all the benefits.
The reality is, the researchers are the ones operating the systems their research is on. They're the ones who have to secure them. And they already largely have the right incentives to want to do that, but they also have a poor understanding of the necessity of it and the process for doing it.
What would help here are the things that would help in general. Fund vulnerability research in free software so that the software people are using (because it's what they can afford) is secure by default, and easy enough to use that people don't commonly make mistakes, and well-documented. Things like that. Make it easier to do the right thing so more people do.
This is very true, sadly. It ought not to be, but level of practical cyber abilities seems sorely lacking. I see lots of "governance" style cyber, but not a lot of "deep technical expertise being allowed to develop defences".
University research lab type environments deserve a special call-out though for being near-impossible to defend. Most of the time these are "defended" by pooled central IT staff without specific awareness of the significance of the systems or threats faced. University networks are also notoriously open, and even in lab environments, they're often connected directly to the internet or campus network (airgapped computers for internet access are less convenient and someone would have to pay for them, and nobody wants to). Let's not even go into the various shadow IT remote access systems in use, which circumvent the institution firewall to let them get work done from home in the evenings...
University lab environments are an incredibly tough target to secure. And the researchers will find ever more ingenious workarounds to security measures that they find getting in the way of their work.
> Except for heavily regulated sectors (government, military, heavy industry, banking, core telecom, and more recently elections) very few companies will actually get help from 3-letter-agencies to actively protect against foreign nation state attacks.
Even some of these sectors sorely lack ability in cyber, at least in some very developed and otherwise capable countries. There is still a very real barrier between 3 letter agencies, and the industries you mentioned that need this help. Information sharing is often too little too late, or not specific enough to be actioned.
That said, I do think cyber security needs to be a bigger priority in all sectors, but nobody wants to pay for it, and as long as there's no routine cost to business, I don't see that changing. Not while traditional "value for money" metrics are used to measure and compare options - it's very hard for those reviewing tenders or proposalsto see and differentiate between good security and some "military grade, unbreakable, quantum sprinkles" snake-oil security that has SQL injections everywhere.
A large part of cybersecurity is removing the low hanging fruit (eg. Gitlab's recent phishing test). The current stakes might probably target an unprecedented level of attention towards research facilities where people weren't concerned about all this stuff, and it's safe to assume aren't experts in the matter. So there's probably a lot that can be done to strengthen the security landscape, making life difficult to attackers, and generally consuming their attention and resources, resulting in a net positive. Even if each one would still succumb, maybe fewer will.
Chinese citizens are forced by law to spy when asked.
https://www.canada.ca/en/security-intelligence-service/corpo...
https://www.cnn.com/2020/01/28/politics/harvard-professor-ch...
Are you talking human counter-intelligence as well as IT security?
I get the point the parent comment was trying to make, but yeah, bad example.
1. Are you ok if some entity steals your research and publishes it under their name in a venue under their name before you publish it?
2. Are you okay if the entity stealing the research is not similarly liberal with their own research on the same subject?
the problem only exists because people want to 1) hold data hostage for money and power 2) only publish success.
Are you aware that there are protocols in medical research against this?
Publishing research in an ongoing basis will taint the results (placebo effects etc).
There are blackout periods etc. just to make sure that the analysis is valid and not tainted.
Also a lot of research has lag time. Experiments can take a lot of time.
There is also a hidden assumption China is hacking for the greater good.
I also wish they would explain how treatment options are jeopardized, even at a high level:
> The potential theft of this information jeopardizes the delivery of secure, effective, and efficient treatment options.
More importantly, while data theft is bad, data tampering could be much worse.
What happens to people's confidence, hope, and trust if a "remarkably effective" drug turns out to be a total dud or even dangerous because the underlying data was modified?
this presumes that the stolen information would be used 'to help as many people as possible'..
Also, 1st country with viable vaccine/treatment/etc will have a huge geopolitical bargaining chip & it will likely be used as such no matter the country of origin.
Ummm, I'm not sure how to break it to you, but USA is already laughingstock of world due to our comically misguided reaction to the "pandemic". Everyone expected Trump to screw up (and he hasn't disappointed), but there isn't any person or institution in USA that hasn't totally whiffed on this. CDC mandated tests that didn't work, news media remained unconvinced until late in the game and now jump from one conspiracy theory to another, in-person elections were held as late as April 7, some states required that diseased patients be forced into nursing homes for the elderly, effective masks are still somehow difficult to acquire, Congress has passed numerous "bailout" laws representing trillions of dollars yet has somehow not been able to arrange healthcare for every citizen as most comparable nations have had for decades, our deaths have passed 100k and seem certain to pass 200k as well, etc.
It's difficult not to see this "investigation" and especially this silly press release that purports to inform the public about it as just more of the same. Furious pretend activity with no view of long-term strategy or of benefit to anyone other than the bureaucrats who wrote the release.
Definitely, but thankfully, it is a positive sum game.
First thing, you won't keep your bargaining chip for long. If a country manages to find a vaccine, others will follow soon enough. Besides independent research and reverse engineering efforts, it is foolish to think that the US doesn't have spies and hackers targeting China.
So in order to use that "bargaining chip", the vaccine has to be at least as valuable as what you are asking for in exchange. So while it may cost a lot to the country that doesn't have the vaccine, if it took the deal, it means that the cost is less than not having a vaccine at all.
In the end it will be used to help as many people as possible, because it is the only thing a vaccine can do. Unless someone wants a full-on war that is. But if major powers really wanted the worst, there is a pile of nukes that is ready to make the whole pandemic look like a joke.
Like remember the indictment of 12 russians ( https://www.justice.gov/file/1080281/download )
The FBI linked a pool of bitcoins used to purchase a VPN service and other things to the Russians. Probably best to not use a crypto with a public ledger for criminal activity.
To your question: Imagine tracking these threat actors for years (or decades). You have observed different TTPs (Techniques, Tactics & Procedures) from different actors, you see them operating in different ways and with different teams, you can observe the time when they are active, by their targeting you can make an educated guess what they're after, you can correlate their activity with policy changes in their presumed home-countries and lastly you can repeat those observations over and over again since these threat actors are persistent and keep coming back since it's their job. If all these soft and passive observations already point to the same actor(s), and then you get some additional hard evidence on top (Opsec failures, HUMINT, SIGINT), you are eventually able to make a verdict with a high degree of confidence.
At the same time in this case I would be more surprised if the PRC , since their need for control, and since the stakes are extremely high, wasn't doing such things.
If I ever code a hacking tool I'll throw in some Korean comments for sure.
Instead, you get tribalist arguments over who believes which secret police.
Instead I found an article on Wikileaks claiming CIA executed false flag hacking operations: https://theintercept.com/2017/03/08/wikileaks-files-show-the...
The CIA is hardly the only organization to put misleading evidence in their attack path. Also, countries like China and Russia have healthy malware ecosystems so a Chinese-written malware can end up in the payload of a {North Korean, Russian, Iranian} cyber attack.
Personally, I'm starting to believe that the only way to have extremely high confidence in attributing an attack is to have surveillance of the person on the source keyboard when it happens or to have telecom evidence of people admitting what they did. Most of the actual attack is probably robotic at this point.
I'm sure the PRC has used password spraying before, the only detail mentioned. Tgatd about as easily forged as the IP address though.
This /may/ be the case. But the FBI wants me to come to this conclusion.
It seems a little fishy.
Although I am secretly grateful for this spam, as it cut down my time spent there from 3-4 hours a week to 3-4 hours a month, it's still disconcerting as they are highly organized and apparently take huge pleasure in bludgeoning seals and other harmless creatures. Heck, I am amazed that the boards were clean even after the US Elections, the shutdown of 8chon and other such events.
There are papers out there that have multiple ways of using language to identify specific authors, determine multiple authors, and even decode unknown language. That's my first shallow example and would be a pretty reliable indicator if you could get your hands on their code. With a budget of millions of dollar I'm sure they have dozens of ways that can be combined. It would make no sense to reveal every single method they use to defend against people on the internet. That also assumes they don't just have a mole who told them about it, which they also wouldn't reveal.
I have not said this. The evidence they have provided makes it equally likely that they've tracked these hacks (correctly or incorrectly) or that they've made the whole thing up. You can't rule out either action.
>There are papers out there that have multiple uses of using language to identify specific authors, determine multiple authors, and even decode known language. That's my first shallow example and would be a pretty reliable indicator if you could get your hands on their code
There have been multiple papers on these subjects, with a budget of millions of dollars I'm sure identifiers could be faked. Particularly with password spraying, the only method mentioned.
Firing inspector generals en masse [1], personally attacking specific FBI agents and their families [2], intervening in the criminal proceedings of friends and political allies [3], etc. is a pattern of behavior that undermines the rule of law in this country. It's a comprehensive strategy to weed out anyone who disagrees with you, hurts your feelings, dares second guess you, or, god forbid, didn't vote for you.
This pattern of comprehensive corruption is unique to this administration.
There are _literally_ dozens of links I could provide for each point since these behaviors happen constantly, but I just google'd and picked one each.
[1] https://www.washingtonpost.com/politics/as-trump-removes-fed...
[2] https://www.vanityfair.com/news/2020/02/donald-trump-nemesis...
[3] https://www.politico.com/news/2020/02/25/judge-rebukes-trump...
https://www.rasmussenreports.com/public_content/political_co...
>>>intervening in the criminal proceedings of your friends and political allies
http://www.allgov.com/news/controversies/obama-fires-inspect...
https://cei.org/blog/obama-fires-inspector-general-who-uncov...
>>>a comprehensive strategy to weed out anyone who disagrees with you
https://www.motherjones.com/politics/2012/06/obamas-whistleb... https://www.washingtontimes.com/news/2020/may/7/president-ob...
>>>pattern of comprehensive corruption is unique to this administration
If you think that this administration is UNIQUELY corrupt....you might be in an echo chamber. Here's a more humorous take on the Obama administration's screwups: https://www.youtube.com/watch?v=1T7F2mvZE1E
That, or have a short memory, since Trump and Obama both pale in comparison to VP Dick Cheney and the Iraq War (KBR? Halliburton? have people forgotten about them already?).
>https://www.rasmussenreports.com/public_content/political_co...
All I see is extreme editorializing of the regular push and pull of government ("horrific neglect", "bull[ing]", "stonewalling", etc). How many of them were fired because Obama didn't like what they were investigating? Trump's count is 5 in the last few weeks. I'm sure Obama fired at least that many if you're making a comparison, right?
>http://www.allgov.com/news/controversies/obama-fires-inspect... >https://cei.org/blog/obama-fires-inspector-general-who-uncov...
You don't take these blog posts seriously, do you? His connection to Obama was... what exactly? This is prototypical far right nuttery: oBaMaS FrIeNd dEeP StAtE BeZoS NyT AmAzOn hEr eMaIlS.
>http://www.allgov.com/news/controversies/obama-fires-inspect... >https://cei.org/blog/obama-fires-inspector-general-who-uncov...
I wonder if you actually read these, since they have basically nothing to do with what you quoted. Did you just google "Obama friends bad" and copy/paste the first few links or something?
>"Obamagate II: Secret of the Schmooze"
Not going to spend time watching some fringe conspiracy YouTube channel, sorry. More complete nuttiness.
>That, or have a short memory, since Trump and Obama both pale in comparison to VP Dick Cheney and the Iraq War (KBR? Halliburton? have people forgotten about them already?).
I'm disappointed that I got this far before seeing this. You should seriously consider that you may be in a short, narrow, and extremely loud echo chamber. These aren't the kinds of ideas that normal, well-read, well-informed people from all sides of the political spectrum hold.
Far-right websites like the Washington Post? http://voices.washingtonpost.com/federal-eye/2009/06/third_c...
>>>His connection to Obama was... what exactly?
Kevin Johnson was a public political supporter of Obama while mayor of Sacramento.[1] Walpin investigated Johnson for fraud. Obama fired Walpin. Which one of those three facts are you disputing?
>>>since they have basically nothing to do with what you quoted
The cei.org link should have been grouped with the Rasmussen Reports link as they are both related to the firing of IGs.
>>>Not going to spend time watching some fringe conspiracy YouTube channel
That video cites numerous articles from major journalistic outlets (BBC, NY Observer which itself cites the Washington Post) relevant to the discussion of corruption in the Obama administration, and runs through them at the cyclic rate. It's time-efficient content. It's also funny. But you can't debate any of the information provided, or any of the conclusions drawn, if you discount the presenter as "fringe conspiracy nuttiness".
>>>You should seriously consider that you may be in a short, narrow, and extremely loud echo chamber.
In this thread I've cited sources ranging from the right (Michelle Malkin, Heritage foundation), to the center (BBC, CBS News), to the left (Washington Post, Politifact). You haven't posted anything, haven't countered any of the facts, and have only criticized the sources with strawman accusations of "far right conspiracies". I would challenge you to be more aggressive about exposing yourself to information that challenges your positions and assumptions, and avoid the strawmen.
>>>These aren't the kinds of ideas that normal, well-read, well-informed people from all sides of the political spectrum hold.
Which idea are you arguing against, that Dick Cheney and associated companies were massively corrupt? [2] [3]
[1]https://abcnews.go.com/Politics/president-obama-introduced-c...
[2]https://www.politifact.com/factchecks/2010/jun/09/arianna-hu...
[3]https://www.cbsnews.com/news/halliburton-whistleblower-on-ex...
What do you mean by "so lightly"? It changed the entire meaning of the sentence.
Maybe because as opposed to Chinese and other oppressive governments, the western press actually makes the people informed. Sometimes.
It's propaganda that pushes an agenda. That agenda may even be correct, but an outside observer who can't verify any of the evidence can't tell.
That's not a very responsible statement.
In Germany it is (incident was 15.05) - NEMO (Freiburg) - bwUniCluster 2.0 and ForHLR II (Karlsruhe) - Hawk (Stuttgart) - Leibniz Supercomputing Center (Munich) - JURECA, JUWELS und JUDAC (FZ Jülich) - Taurus (Dresden)
Switzerland shutdown access to all of CSCS (16.05).
That's not my reading of the article you linked. A bad actor compromised the credentials of multiple researchers with access to various supercomputers (over some unknown or at least unspecified period of time). They then simultaneously accessed the compromised machines and installed cryptocurrency mining software on them.
This could easily be profit motivated (as it appears). It could also be (as you suggest) a hostile act disguised as the former, but I don't see what the motivation to do that would be?
Seems more likely that more people are using/accessing these services, and people's guards are down, which made it easier for intruders to get in.
1 - HPC centers in Europes are down.
2 - Those are useful resources to battle battle against COVID-19.
3 - HPC centers are down due to malware infections.
4 - FBI warned and Department of Homeland Security warns of possible cyberattacks targeting COVID-19 research.
1 - one of the two incidences reported (#EGI2020512) targeted academic data centers "for unknown purposes" (https://csirt.egi.eu/academic-data-centers-abused-for-crypto...) and not necessarily crypto currency mining.
2 - IP addresses associated with that second attack were all assigned to a Chinese University (Shanghai Jiaotong University), CSTNET and one Polish host known to be compromised by someone from China.
It's like trying to assign blame for a terrorist attack based on where the jacket dropped by a terrorist was made. Maybe it was made in their home country. Maybe it was imported. Or maybe they purposefully wore a jacket made in a different country and dropped it on the scene to confuse you.
"The attacks may have been perpetrated in order to mine cryptocurrency; investigations are ongoing."
I believe it's referred to as the "limited hangout" in spycraft jargon. You maintain the target's sense of security and ability to detect intrusion while you maintain the capability to reintrude at will.
Decades ago I spent a bunch of time around fnal.gov with a buddy who worked there, and they were debating the requirement of every computer, including desktops, having a static, public IPv4 address. Nobody wanted to be behind a firewall in the name of open, collaborative research.
Incidentally, if attackers were looking for sensitive research results from this, I think it would have to be targeted with detailed knowledge about what specific researchers were doing; after all, it's difficult enough for a typical researcher to keep track of their own stuff, and it mostly won't have look-at-me names.
Gavi/Gates/GSK and other big pharma companies might be claiming to help the world, but they're also seeking to get a return on their research funding. Even in academic circles, there isn't really a lot of information sharing.
History has shown us that any super power will go to war. The Romans, the British, the Americans. Maybe we’ve learned our lesson from history or maybe today things are different due to greater education, multiculturalism and just rapid communication. Either way we shouldn’t be pinning our hopes on “Jesus Christ”, as again I don’t know what that means. Would he come down and disarm everyone or something?
We avoid conflict by having rational open dialog, educating people and increasing transparency and accountability. The way to increase the probability of conflict is by having this tribalistic us vs them mentality. Everything they do is bad, they are evil and we are just.
The fact that you managed to understand that I decry the collapse of the Soviet Union when my post said the exact opposite, namely that I can't see how in China an event like that could take place -- and this was the foundation on which I based my affirmation of Russians having a soul -- tells me that your agenda stands firmly on the side of the CCP, in detriment of everybody else. Quite sad, really.
Something akin to an anti-Palantir.
Post it online with a hash, particularly in a way that will get archived by others?
Keep off-site backups?
Here's an idea for how this could work for an example given elsewhere in the thread about the risk of an attacker mislabelling the subjects so the outcomes are unclear or deliberately skewed.
For a binary double-blind placebo trial (one group gets the medication, another gets the placebo), compute the hmac of each subject identifier (name, some participant ID), keyed with a key known to the principal investigator. Everyone whose hash MSB is above 0x80 gets the treatment, and everyone whose hash is below 0x80 gets the placebo. If you need more experimental groups, adjust the thresholds as needed
Clearly this is very restrictive and limited (you might need to ensure a proper demographic and medical/age profile distribution of subjects between both groups), but there are likely ways to achieve this by creating multiple "groups" and doing this process within each demographic balanced group.
You'd get a reproducible outcome, as long as you can recover the patient names or participant ID numbers, and the PI or experimental lead takes careful note of the hmac key used.
Just a straw man idea for how at least the patient to group allocation could be done deterministically. If someone attacked this and muddled patients and groups around, it could be reproduced just from knowing who the subjects are, and the hmac key. Clearly this doesn't scale to results or beyond, but I imagine this is where digital signatures start to help. And with modern ed25519 signatures we aren't talking massive signatures either.
"One of Britain's most powerful academic supercomputers has fallen victim to a "security exploitation" of its login nodes, forcing the rewriting of all user passwords and SSH keys."
https://www.theregister.co.uk/2020/05/05/coronavirus_researc...
"Foreign state hackers are trying to brute-force their way into pharmaceutical and medical research agencies hunting for a COVID-19 vaccine, British and American infosec agencies are warning.
The National Cyber Security Centre (NCSC) and America’s Cybersecurity and Infrastructure Security Agency (CISA) cautioned of a “password spraying” campaign targeting healthcare and medical research organisations."
I have a hard time believing foreign state hackers are using "script kiddie" tactics. But that's just me.
Also, some/many countries have laws that disallow patents or patent infringement claims associated with medicine.
In fact, until the US became top dog in the post-war era, we pirated everything we could from England, especially industrial know-how so that we could promote our own development. It is only after we reached hegemonic status that we started enforcing these ludicrous agreements in order to preserve our own businesses' position.
This is another gross oversimplification at best, and I have yet to hear anyone who has spent significant amounts of time in either public or private sector R&D make such a claim. Real life, and product development in particular, is not so easily reduced to catchy political slogans.
You can make some arguments about things like iPhones but that device depended on a huge state funded or regulated infrastructure to be useful (e.g. cell towers, internet), and it was essentially a very polished cobbling together of different components (microchips, batteries) that were developed from many decades of state supported / regulated monopoly research.
Business is very good at taking something off the shelf and making money with it. It's very bad at sustained investment that might not be profitable more than a few years away.
I mean, it'd make sense if the government research spending aligned with public interest more closely than private investment did, the government is spending the public's money after all.
Also, you are mistaken in thinking that, by publishing a patent, the company is sharing knowledge. Quite the contrary, the contents of a patent gives only the minimum necessary to protect a crucial aspect of a business secret. Most patents are opaque and don't give any concrete business information that be used to successfully replicate what it is trying to conceal.
AWS can decipher decade old encryption standards for about $100k brute computational cost.
Nation states have access to 5-8 zeros of effort if it is valuable enough. Private entities have no chance against nation-state backed hacking efforts.
It’s one-sided or ‘asymmetric’, because western intelligence refuses to share commercial intelligence with western businesses (probably because there isn’t much of value to share... yet).
Only solution is political change.
I don't think COVID-19 research should be secretive, I think it should be a global effort, and I'm perfectly happy with the idea of any nation having open access to all COVID-19 research, vaccines, results, and (anonymized) data. There should NOT be a concept of intellectual property when there are people dying in droves from a disease. Please, China, Italy, Spain, everywhere, scoop up all the COVID-19 research you can find and act upon it to save lives. Copy ideas. Copy drugs. Re-do and verify tests. Immediately. Don't mind the courts. They suck, and are sitting in armchairs killing people by delaying the effort and enforcing intellectual "property".
If China succeeds in stealing the solution, that will harm mankind because it will reduce future incentive to stop these things quickly.
The government certainly doesn’t pull long hours.
Beyond the military. They do pull some late nights and cold field deployments in the DoD.
And beyond local police and fire. And state troopers. Law enforcement does go late and I’m pretty sure fire departments deploy all night. But of course those are not federal.
There is, obviously, the FBI. Those agents are mostly not up at night though. Now, CBP and TSA staff air and sea ports pretty late but that’s different.
The diplomatic corps also works pretty late hours if I remember my leaked cables correctly. But again, an exception. And they get to go to fancy parties.
Obviously people in Congressional staff offices, political advisers in the executive branch, and so forth. But those folk are essentially politicians.
FEMA. Pretty sure some of them stay up.
Other than our armed forces and supporting staff (good morning NSA NSOC), police and fire departments, federal law enforcement, State Department diplomatic staff, staff for elected officials, and FEMA, no one I can think of right now in government stays up late.
Intelligence community, forgot them, other than NSA and FBI. At least some of the 14 other members probably work late, I think? NGA, at least.
But no you’re right, why would we want government scientists like those at NASA, CDC and the EPA working as leading exemplars of COVID research. Surely they are lazy. And they show good work does not happen without a profit motive.
Maybe a slight headstart if they throw extra research money on it.
Humans are humans. The virus doesn't care for the politics, it will spread without regard to human-invented political borders, so the preventative measures shouldn't stop at political borders, either. That would be contradictory to the apolitical nature of the virus.
(In any case, if you shared something with them and it is actually useful, there's a good chance you're pretty close to the solution yourself, anyway.)
* Becoming the first to market, to try and salvage their reputation
* Using the vaccine as leverage toward the incoming sanctions for violating the Hong Kong treaty during UK handover, as well as the now-declared possible non-peaceful reunification of Taiwan
* monetary gain
* leverage against the US restricting/removing Chinese’s companies from the NASDAQ
I agree research should be open, but it’s hard to say to what degree, and how that might effect the economics of it. Whether we like it or not, capitalistic driven progress requires a reward, and one of the few reasons pharmaceutical companies will take the risk of finding a vaccine is the potential for increased reputation, and being first to market.
Without those incentives, it’s straightforward to not to take a massive monetary risk as others are all working on similar problems, thus the likelihood that your lab will be the first is slim.
Further, the crisis is a worldwide pandemic, but if the rate of natural immunity is as high as some predict, the efficacy of these vaccines may lead to less ‘sales’ than initially expected.
Oxford running out of people to test their vaccine on: https://news.cgtn.com/news/2020-05-25/COVID-19-disappearing-...
China report about Taiwan has “peaceful” removed: https://www.reuters.com/article/us-china-parliament-taiwan/c...
China breaking the handover treaty: https://www.theatlantic.com/international/archive/2020/05/ch...
Really? They just recently ban Australia trades because Australia inquire about Covid19 origins.
https://www.theguardian.com/world/2020/may/13/australia-chin...
I'm not a medical expert, but can someone in the know comment on this? Can I volunteer to get the Oxford vaccine in the US? Can I volunteer to fly to UK and get the vaccine immediately upon arrival?
Although I'm also strongly against deliberately infecting people, if there is a high chance there is no danger to take the vaccine, and a strong possible upside (i.e. possibly save lives in the next 2 weeks), I don't see why we it isn't okay to volunteer to take it today, even if it isn't a fully conclusive data point. Hell, if there are 5 candidate vaccines, and they are all non-dangerous, I'd love to take all of them just to protect my own life, even if that makes me not as useful of a useful data point. There's a nonzero chance the virus will kill me in 2 weeks, 4 weeks, 6 weeks, and I think it is only ethical to reduce that chance even if that means 5 shots (pun intended) in the dark.
Of course, I see people downvoting me and it seems HN doesn't welcome this type of discussion anymore.
Yes there’s a non-zero chance of death, but assuming you’re a part of the average population (assuming US or UK for example sake), then you’re more likely to die getting in a vehicle.
Personally I’m for vaccines, but I do not want to be the first 10k they try it on. I’m in good health, so I’ll wait months or longer if one where released in their hopeful expedited timeline. By nature of the pandemic, this is rushed, and the risk to reward ratio favors waiting a bit (for myself), given the low mortality rate for people with no preexisting conditions.
Further, I’m near a hot spot, so it’s highly likely I have the antibodies, given others in my household are less careful, and thus my exposure profile essentially equals the lowest common denominator.
China promised to give its covid-19 vaccine to WHO for free. If the accusation is true, it's basically Robinhood for poor countries.
You should champion China to be more transparent about the origins of the virus. Even if it did not originate in a lab, shining more light on its origins will help prevent future outbreaks.
China also actively prevented Taiwan from joining the WHO. This would have resulted in more free flow of information.
Curiously, I was a labelled a racist for making this statement.
> Please, China, Italy, Spain, everywhere, scoop up all the COVID-19 research you can find and act upon it to save lives. Copy
China does not do anything for free. Let us not pretend that China is angelic. Have you heard of debt diplomacy?
So we are excusing one of the most locked up countries in terms of information to hack into cutting edge research in a free society.
No matter how objective I am it is going to piss violate some unknown law of the land here. Being logically correct in these threads usually ends up being politically incorrect.
Thanks for all your hard work moderating.
What China does or doesn't do has no bearing on this.
Is it fair and ethical to ask country A to make free all research while being okay with country B hiding its own research on the same subject?
Let us not whitewash unethical behavior with broad strokes of "freely available to all as a matter of principle."
This isn't about countries. I think it is unethical to hide research when it could save lives. If country B is hiding research, that doesn't mean country A should hide it as a revenge, and that doesn't mean the residents of country B deserve to take the brunt of the actions of their government policies. The civilians of B and the civilians of A deserve the best of science equally.
The virus doesn't care about where country borders are drawn. Even in the above situation where country B is hiding their research, if country A shares their research with B, it helps country A themselves because country B's people may be inoculated much faster and immigrants from country B to A will not be carrying the virus anymore.
The objective function that should be optimized is getting the virus eradicated from the world ASAP. There's a good chance that only some fraction of the world needs to be inoculated with a vaccine before the virus is nearly eradicated, and that will only happen if the vaccine is shared across borders. A good start, for example, would be to inoculate everyone who wants to take a flight or train, inoculate all doctors, and inoculate all service industry personnel, regardless of which of the 200 countries they are a citizen of.
Why are you assuming the US is hiding research?
Are you aware that there are protocols in medical research against premature release of information as it will taint the results (placebo effects etc)?
There are blackout periods etc. just to make sure that the analysis is valid and not tainted.
Also a lot of research has lag time. Experiments can take a lot of time.
You are also assuming that China is hacking to release information for the greater good. You are discounting the following:
1) Hacking to corrupt results and data.
2) Hacking to patent possible cures first.
3) Getting to a cure first to use as leverage over countries. https://www.nytimes.com/2020/04/14/us/politics/coronavirus-c...
This is an interesting potential debate. In some sense we are sacrificing lives for scientific validity, because it is potentially possible that we could deploy early, ignore blackouts, and have probabilistically fewer deaths + tainted data. But the world is apparently wanting to choose probabilistically more deaths + clean data.
This is spurious logic.
How are you saying that tainted science + bad data will result in fewer deaths long term?
You may end up with probabilistically more deaths + tainted data.
Why is that not a possibility?
Secondly, patent where? If they do it to limit the use I doubt many nations would respect that patent.
With #3 you are just arguing for a form of debt slavery.
Thanks for conveniently ignoring #1.
FBI stance is we can hide stuff from you, and hack you, because we are the "good guys".
An American journalist toured the Soviet Union in the 1930s. Everyone he spoke to proudly bragged about the USSR and its accomplishments. But some things seemed off. He asked about the mass starvation, and his handler explained it was because the kulaks destroyed their food to spite the people. He questioned why newspapers would one day say one thing, and the next denounce the same as counterrevolutionary. His handler responded, there was no difference, he's just misunderstanding the context. Finally he asked about political opponents mysteriously disappearing when they stood against Stalin.
Exasperated, the handler shrieked, "And you are lynching negroes!"
TBH no matter how transparent China is you won't trust it until it turns out to be what you believe.
> actively prevented Taiwan from joining the WHO
Every WHO member can formally invite Taiwan and cast a vote, why didn't any five-eyes nation do that?
> does not do anything for free
I agree. It's simply ruthless geopolitics no matter how angelic a country pretends to be.
- "If you want to buy our vaccine, you need to buy Huawei equipment for all your communications systems" - we've already seen that in France with PPE
- What would that do for investment in vaccine research if you know China can drop in theirs at any time and address the entire market? Investments dries up, China pulls back, go back to 1.
What you're encountering might just be a selection effect since many of these press releases don't raise people's interests. Perhaps it's the people amplifying certain stories to drive their narrative than the FBI themselves?
Usually I list the interference they do in left wing movements where they spy and infiltrate spaces to disrupt and discredit vital activities aimed at e.g. preserving the environment. As a highlight, they tried to get MLK to kill himself. Much of this was documented by the revelations of COINTELPRO. That stuff was never punished, so why would they ever stop? It's good for the integrity of the state.
For a conservative example, the recent "Obamagate" disclosures show how the FBI was instrumental in creating the now totally discredited Russiagate conspiracy which raged in the media for two years as a ploy to disrupt the Trump administration by an insane xenophobic conspiracy that Trump was the manchurian candidate, going so far as to create speculation that he was some kind of soviet sleeper agent from the 1980s. He's of course a bad guy, but this stuff is off the wall.
Now the FBI is being brought under control by the current administration which is attempting to distract from it's total failure to respond to the pandemic and its actions which are widely acknowledged to have made it far worse that it should have been. The United States, the richest most powerful country in the world, has had one of the worst responses in the world. So the administration is attempting to clumsily pin the blame on a "foreign enemy" by saying it's attempting unfairly to do something about the pandemic. What an incredible world we live in.
EDIT: To conclude: Is withholding medical information in a pandemic for any reason ethical? What about for making money? Is stealing such information from such an actor unethical?