Critical entities targeted in suspected Chinese cyber spying
apnews.com
apnews.com
It is unclear why the M.T.A. was a target of the campaign, but investigators have several theories. One focuses on China’s push to dominate the multibillion-dollar market for rail cars — an effort that could benefit from knowing more about the inner workings of a transit system that awards lucrative contracts.
However, the article also said it's possible "hackers mistakenly entered the M.T.A.’s system and discovered it was of little interest, which cybersecurity experts say is not unusual."
https://www.nytimes.com/2021/06/02/nyregion/mta-cyber-attack...
The actors have different playbooks. America's is "get in as quietly and as targeted as possible, and make the damage look like random equipment failing." Which makes sense. If they wanted to do value targeting at a wide scale they'd use a nuke or what have you. The mobility the domain of cyber gives them is deniability and operational security, not capability since they can basically bomb anywhere on the planet in under an hour. The dragnet stuff is done via MITM attacks or with friendlies like telcom and tech companies.
With the DPRK it's completely different. They don't have multiple points of access on the global internet. They don't have the worlds best military jets or satellites. Sure they have a few nukes, but they can be intercepted, so getting access to critical infrastructure is something they would value in the first minutes of a war with America.
But I agree with your overall premiss. In cyber you can't get a completely accurate idea of how backdoored your systems are. There is more observability here than people give credit for, because we hack the hackers to figure out their access levels then monitor the intruded on systems, but ultimately it's unknowable just what percentage of our systems are compromised and even if we could somehow know the degree of compromization, it wouldn't matter because a previously unused, wormable 0day could infect whole classes of systems we thought were secure.
Also, I think China does have multiple points of access to the internet, and is catching up with the world’s best jets and satellites (but not entirely caught up).
But I've been following the DPRK for a while, and their cyber strategy is more obvious.
I think people underestimate European countries. Their less hostile, so people conclude that they lack capability, but they have 0days and cyberwarfare capabilities.
We lengthen IP protections, but todays world technology is moving faster than ever so you'd think it makes sense to reduce them. Originally patents were 14 years. Shorter patent length would encourage companies to focus further on innovation and logically you'd think things like industrial espionage would be somewhat reduced, at least at consumer levels, as the window/incentive to steal reduces based on the lower need. Plus this would make things fairer to companies that dont steal IP vs those that do.
If you can keep something secret, you don’t need or want a patent (which creates a public record). There’s no patent for the Coca-Cola recipe. And this is also a situation where espionage is useful.
I think that's a really simplistic view of human motivations and a reflection of how China is viewed in the West onto how any "reasonable" Chinese hacker must also view China. When in fact, how this hacker might view about the situation could range anywhere from feeling that the government was justified in their actions from a realpolitik point of view to an acceptance that it's just one of those complicated problems in Chinese society that can't be solved overnight, like systemic racism or economic inequality in the US. I doubt Americans live every minute of their lives thinking of all the minor tragedies that occur in their country at any given moment, and is motivated by them to overthrow the American system. Rather, it's more of a shrug and carry on while trying to do a little better within the system they have.
If for us the solution is to have the crime rate of the USA, the inefficiencies of Europe, or the slow death of Japan, it's hard for them not to prefer the glorious albeit maybe artificial paradise promised by their rulers.
But realistically at most it would plant seeds of doubt like all the CIA craziness we've seen posted to HN of late. There's some pretty disturbing stuff with respect to that such that it made me appreciate some more of the anti government sentiments about the evil government and dirty affairs we've created in other countries.
Even then, people use a variety of VPNs to access sites not otherwise accessible.
As to your second point, people of all countries are easily blinded by their own nationalistic rethoric. I mean how many in the US had access to the same information as Snowden and said nothing? People acting in these circles are vetted for their patriotism and checks are in place to make sure they don't deviate.
People who are into these secret clubs -whether they are government agencies, hacking groups, terrorists, etc- tend to not want to lose their privileges, because it gives them power an insight- and also because they know the consequences to themselves -and possibly on their families- of violating their masters' trust.
It takes real courage to give that up and the outcome is probably often pretty bleak.