U.S. and key allies accuse China of Microsoft Exchange cyberattacks
axios.com
axios.com
> Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector.
Finally they seem to be starting to take the defence of citizens and private industry seriously - in a far more public forum. Instead of just hearing the odd story of this happening through back channels.
From the linked press release:
https://www.whitehouse.gov/briefing-room/statements-releases...
It is amazing that NSA had to notify Microsoft. You would thing a company with that much money like MS, they would have drop several millions on a few pen test, and independent security audit companies.
Digital security will never be trust unless these things are addressed in an open transparent way.
Are you under the impression that MS doesn't spend millions on security? They're currently spending roughly $1b/year. This isn't going to be fixed by "a few pen test"
But the "just hire a pentester and you'll never have any bugs" and "just follow some (ill-defined) 'best practices' and you'll never be hacked" attitudes are so prevalent.
But, we’re more likely to outsource the one thing you don’t need to outsource, like app developers.
HN is also full of contrarians and people who like to feel superior than everyone else (and often express that through flippant dismissals).
If MS wanted to replace a product like this with one that has a low probability of containing any remotely exploitable vulnerabilities, they'd have to go back to the drawing board, do a full rewrite witha completely different sw development process, take a lot of time or make some major functionality compromises (or probably both).
The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of nuclear power. Making things safe and keeping them safe while also making things easy and cheap are often in conflict. Ultimately it was split into two different agencies: One tasked with regulation and one Tasked with research and promotion.
I believe both missions of the NSA are important. However I believe it should be split into two agencies each Enthusiastically pursuing a single mission to the best of their abilities.
Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc.
Is that necessarily the best form? Probably not but it’s way better than what we have now: every time the NSA suggests changes to “make something more secure “ there is a looming specter that they are lying and are actually trying to compromise things.
I like this idea. At the same time, I think the agency - or organization, if you prefer - should look something like the National Transportation Safety Board, where incidents are investigated, reported on, and recommendations are made in a way that improves user safety. Maybe the 'National Digital Safety Board'?
I like it too, but I also think it would be needed to be backed by some kind of regulatory agency that could issue the cybersecurity equivalent of an "Airworthiness Directive". Otherwise we'd be in a similar situation we have know: lots of information about vulnerabilities that are often not acted upon.
I don't know... isn't that like saying a military general has 2 conflicting missions: offense and defense? We trust military leaders with both duties, even though they could theoretically sacrifice everything to achieve victory.
> I believe both missions of the NSA are important. However I believe it should be split into two agencies each Enthusiastically pursuing a single mission to the best of their abilities.
If you split the NSA in two, wouldn't you just have two agencies working against each other? And it would essentially give the offensive agency full permission to hoard security flaws to the detriment of the nation it serves.
I think a better solution is to clearly establish the relative priorities of each mission. IMO, the NSA should always prioritize the security of the USA's (and it's allies') technological infrastructure over attacking its enemies'.
At least with cryptography, I'm not sure how practical that is. I'm not cryptographer, but my impression is that offense and defense both deeply inform each other in that space.
Right now adversaries are just playing treasure hunt because of this.
We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.
Tools to fake such attribution and evidence were literally part of the leaked NSA/Equation Group toolkit.
I had only previously heard [0] that similarities in the tools were discovered by Kaspersky, not that there were any leaked docs that pointed the finger back at NSA themselves. Are you maybe thinking of PRISM/Wikileaks?
[0] - https://arstechnica.com/information-technology/2015/02/how-o...
And there are most likely a lot of cases where:
1) "...we got more than that," and...
2) ...data from "IPs and tools that are easily faked" is the only information that could be released publicly without compromising sources and methods.
It's a hopeless wish to want to be able to independently assess (as an amateur!) intelligence findings in all cases. If trusting the official assessments isn't acceptable (cross-checked with general knowledge of the situation), about the only reasonable alternative position is to remain agnostic.
And Many countries did independently investigate, and refuse help.
The UK, Spain, Italy and a few other EU countries took part in the illegal invasion of Iraq.
It was not illegal
> Iraq had weapons of mass destruction (chemical)
Even the US government admitted after the war that it could find no evidence of an Iraqi WMD program. All the US found were a few misplaced ancient, rusting artillery shells from the 1980s. These things were unusable, and were more of a danger to the people handling them than anything else. This is not the WMD stockpile the US claimed Saddam had. Nobody would ever have accepted to go to war on the basis of, "We think there are still a few misplaced, unusable artillery shells with degraded chemical agents in Iraq."
The vast majority of the most recent wars have not been UNSC authorized. UN involvement is not necessary for a war to occur nor do they prevent wars or proxy wars between countries on the UNSC. The "modern international system" is an ideal. The US was attacked.
>ancient, rusting artillery shells (from the 1980s)
20-30 years old isnt ancient, they were serviceable, and they had chemical weapons in the quantity for the potential of wmds. That is only what they found, and I imagine there were more not found.
>Nobody would ever have accepted to go to war
There was reasonable evidence they had more that the allied force didn't find. The international community is more to blame for the conditions after involvement than the instigators 10+ years on. A neighbor is beating up another neighbor and both are blaming it on someone else.
Unless those wars are fought in imminent self-defense, then they're illegal. The invasion of Iraq was an especially egregious violation of international law for two reasons:
1. The US knew that the UN Security Council would reject a resolution authorizing war, so it decided in the end not to ask.
2. The war had catastrophic consequences for Iraq. It's not every day a country of 20+ million people is invaded and its government overthrown. Hundreds of thousands of people died as a result.
A third factor making this war particularly egregious is the deliberate campaign of disinformation that was carried out in order to justify it.
> The US was attacked.
Not by Iraq.
> 20-30 years old isnt ancient, they were serviceable, and they had chemical weapons in the quantity for the potential of wmds.
This is how the NY Times described the small number of chemical artillery shells found scattered across Iraq:
> Filthy, rusty or corroded, a large fraction of them could not be readily identified as chemical weapons at all. Some were empty, though many of them still contained potent mustard agent or residual sarin. Most could not have been used as designed, and when they ruptured dispersed the chemical agents over a limited area, according to those who collected the majority of them.
These were the misplaced remnants of the chemical weapons program that Iraq dismantled in the 1990s.
> There was reasonable evidence they had more that the allied force didn't find.
The US occupied Iraq for nearly a decade. It's simply not credible to claim that there was any sort of sizeable stockpile that the US did not find.
>> The US was attacked.
>Not by Iraq.
Saddam gave material assistance to suicide bombers and network. It would suggest had they not gotten rid of him some of the perpetrators would have tried again. The resulting catastrophe was the result of neighbors meddling in their affairs and an internal domestic power struggle.
>These were the misplaced remnants of the chemical weapons program that Iraq dismantled in the 1990s.
if it was dismantled it wouldn't exist.
>It's simply not credible to claim that there was any sort of sizeable stockpile that the US did not find.
it probably wasnt in Iraq anymore.
Edit: I can't reply to the child but here are some salient quotes from the wiki...
"I will wait until the end of the week before judging – many dark actors playing games. Thanks for your support." - Dr Kelly
"it was subsequently established that neither the knife nor the blister packs showed Kelly's fingerprints on their surfaces"
"The former leader of the Conservative Party, Michael Howard, and the former Liberal Democrat MP, Norman Baker, both think Kelly was murdered.[173] In 2007 Baker published The Strange Death of David Kelly in which he argued that Kelly did not commit suicide."
I do see your point, mind, but I don't think such damning circumstantial evidence is "shit"; by that logic, MI6 could never be responsible for anything, unless of course they signed a confession.
It was about timing too - it was a critical point for Blair and Bush getting the war they so desired. Keeping in mind there was already huge opposition to the war, proper 1st hand evidence being revealed at that point could well have resulted in Blair having to stand down, and potentially even the British not joining the war. Which of course the US services would not have liked.
This regime has remained in power ever since Bush's 8 year reign of terror. In fact, they were in power even before George W. Bush's administration. The name of the president may change, but the people running the US war machine remain the same.
As an aside, I'm not sure what's more frustrating:
Witnessing the Bush administration circa 2001-2004 be called out on these lies, by numerous entities, and still march inexorably toward armed conflict, or...
having to witness these lies being used to disingenuously discredit any future allegations made by the US.
You realize that this wasn't the first time the US did this, so I feel we should question these claims as much as possible.
>>> We have a number of countries putting forward the knowledge they have mutually agreed upon. What is shared is known to a high degree of certainty. Any details that are questionable would not have been shared prematurely.
>> "Simply stated, there is no doubt that Saddam Hussein now has weapons of mass destruction." — Dick Cheney, before the US and coalition of the willing invaded Iraq.
> I'd ask that we be more thoughtful on this and evaluate separate allegations on their own merits. Why do you think invoking Cheney's statement is relevant to this discussion?
I think the logic is once an organization or its leaders get something wrong, you should never, ever believe anything that organization ever says ever again. Even 20 years later after the leadership and staff has turned over a couple times.
Of course, that's totally unworkable idea when applied consistently, so it's only used, knowingly or unknowingly, to reenforce existing biases.
After that experience, I'll believe the US government only when they make all their evidence public, and even then, I'll be exceedingly skeptical.
So who do you think carried out these attacks? Do you think that China does not carry out any offensive hacking? Do you think they do, but avoid the US for some reason?
IMHO, these allegations are plausible enough to believe without strong evidence to the contrary. Taking the experience with the Iraqi WMD allegations as your North Star (to the exclusion of all other factors) seems like a heuristic that will be wrong far more often than it's right, and more often wrong than alternative heuristics.
If they claim to have evidence but don't provide it, I assume they don't have evidence, or that the evidence is weaker than they are claiming. If they do provide evidence, I consider the possibility that it has been tampered with, that its provenance is dubious, or that contrary evidence has been concealed.
We're talking about professional liars here. Not everything they say is wrong, but everything they say is suspect.
It's not disingenous and it's not discrediting _any_ future allegation, but to appropriately raise the threshold before belief.
Accordingly, I don't find comparison to prior wars helpful for discussion. Obviously opinions here may differ...
A few years ago, we ran out of fear and urgency on the Islamic terror thing and now we need a new top dog bad guy.
If not, where do you draw the line between real/legitimate security concerns vs. the fake ones?
I'm not saying this is fake, our people should be doing their job mitigating this stuff and hacking them in turn, but it being blown up into a Big Deal is part of the propaganda.
What problem did US solve by invading Iraq?
It's a sad position to take, but we have definitely been misled/lied to by gov't officials.
Why is this particular incident any more legit/not-fake than the totally legit/not-fake WMD evidence?
What, besides credibility of the institutions making the allegations, are these allegations' "own merits"?
Agreed that a reflexive "they lie!" position isn't useful, but... trust doesn't seem like a reasonable default either. In the same vein, it would be naive to trust the Chinese NBS to report unflattering economic statistics honestly. Why? Because of past/recent dishonesty.
Whether it's true or not, I don't think the purpose of this announcement is to inform us. It's part of power games with China, laying public groundwork for updating the NATO mission, new departments/funding/laws/etc... That's not a general paranoia. I get this impression from the NATO statement itself.
from P4:
China’s growing influence and international policies can present challenges that we need to address together as an Alliance. We will engage China with a view to defending the security interests of the Alliance. We are increasingly confronted by cyber, hybrid, and other asymmetric threats, including disinformation campaigns, and by the malicious use of ever-more sophisticated emerging and disruptive technologies. Rapid advances in the space domain are affecting our security. The proliferation of weapons of mass destruction and the erosion of the arms control architecture also undermine our collective security.
Promising to engage China, followed by nonspecific cyber, WMD & space threats.
Here is where I might be paranoid, cynical or whatnot. Is defense against cyberattacks the actual goal, or is cyberwarfare just another long term raison d'etre?
Because China hacking is fairly widespread and so this is not just about a single institution, it's about many.
There's broad consensus here, it's not just 'Dick Cheney & Co.', it's many governments, many agencies, many businesses, academic institutions and the spying/hacking takes a variety of forms.
Yes, this an 'escalation' of sorts, because making it 'NATO' makes it both firmly an issue of national security for not just the US, but for many 'important' actors.
If anything, I think there's not enough action here.
It's definitely worthwhile to keep a very close eye on misinformation and propaganda ... but I think so far we're on the right path.
Okay. What about NATO and "other allies" then?
There are always people trying to expand the definition, but it's usually from more left-leaning critical schools of thought that want to classify landmines, sanctions or guns as WMD.
But in official usage, it's been pretty stable at those three.
A knife is not generally a weapons.
Saddam 100% had WMD's and was capable of making more.
But he didn't have an active program, stockpiles were small and there wasn't really a huge risk of him selling to 'terrorists' etc..
The misrepresentation was really one of magnitude and capabilities and especially how the information is presented.
"He Has WMD's" is very true and legitimate (different than 'he has a knife'), but obviously the misrepresented context makes it a giant lie.
To this end, I suggest that the US would do better in their public communications if they revealed some Twitterable/TikTokable visuals and graphics which highlighted the nature of some of the incursions, so as to more strongly make their case i.e. it's easier to believe 'something material' than accusations.
1) When that was stated there was serious pushback not just from US reporters but also other countries/allies.
2) It's pretty reasonable to believe that it is far easier to obtain hacking tools and knowledge as compared to weapons of mass destruction. You can't just download the knowledge and tools for nuclear weapons through the internet.
I get the cynicism and I agree that we should be doubtful and not trust our leaders at face value. But that doesn't mean that we should throw all evidence to the wind. It just demonstrates that we need to be more thoughtful in our analysis.
Not to me, not to you. You're just believing them. My kid believes in Father Xmas "to a high degree of certainty."
See also Dick Cheney
They could just give us the evidence.
So no, having a lot of countries saying China bad poopoo together is not enough anymore for me.
https://www.justice.gov/opa/pr/four-chinese-nationals-workin...
Exchange being hacked has 0 relevance to HN commenters, their knowledge, or their influence. Absolutely nobody cares about the technical specifics, or technical effects of this. This is an exec level political issue, and is more related to the recent trade wars than infosec.
There is a frankly stupid amount of bipartisan US consensus on confronting China. MENA is being put to simmer. A form of “rapprochement” with Russia is underway, and the EU & NATO are barking when told.
The comparisons to the Iraq war are apt in the sense there’s essentially nothing anyone outside those circles can do about this.
Bonus points for the fact there’s 0 chance of this going kinetic anytime soon, so no blood, guts, and (non climate) refugees to affect PR going forward.
For example, the NYTimes just published a piece about a "Rogue" section of the Commerce Department that used racial profiling targeting Chinese Americans:
https://www.nytimes.com/2021/07/16/us/politics/commerce-depa...
I recall an incident long ago where it was back and forth - you don't know, we know, you don't have proof, we have proof, share proof - it's all bs.. then the frustrated investigators released a trail of this addy, this pic, which was also used for this and that..
what came of it?
not a damn thing changed other than teaching the other side what they needed to not do to not get caught in the same way.
If we are not going to put a missile into a building to stop office building 123456 - because of their theft, then keep the proof under wraps.
a public statement like this does nothing but make it reasonable for us to continue similar theft - meh. no proof needed for that.
MyFitnessPal, Strava, etc are threats to national security and they’re US based, but you think that Tiktok isn’t because someone you don’t like said it is? That’s playground logic.
Yeah, it's pretty much a bomb waiting to be used. It might not have been used yet, but that's no reason to claim it's harmless and sleep next to it.
Though, Facebook and Twitter are not much better, and only somewhat less exploitable by the same adversary (there's capitalism for you).
If you are not American, though, the TikTok drama has been one of the more darkly amusing spectacles.
Wait, it wasn't? I'm not sure why this is a controversial opinion. Social media has often been linked to information leakage. Geo tagging of photos was part of the proof that was used to show that Russia invaded Crimea. Similarly US soldiers have had their locations revealed when posting on Facebook/Twitter/Instagram. In fact if you're over seas and talking to your partner back home they generally have another soldier listening to the conversation. Given all this why is it surprising that a large social media platform that focuses on videos (which reveal more info), grabs a lot of data, and is connected to the US's largest geopolitical adversary is considered a threat?
Sorry but a bunch of politicians agreeing isn't evidence. I have a higher standard.
> attack crippled thousands of computers around the world
Attack vs. espionage are treated differently.
Espionage is done with the intention is to steal information. Espionage is relatively normal between states. Condemn, file charges, then do the same back a them.
Attack is when the intention is to cause harm or coerce. Ransomware, intentionally disrupting or destroying systems. Attacks from foreign government or entities acting behalf of an government are essentially acts of war.
The West is condemning together "mixing" where Chinese government sanctioned groups are doing attacks for financial gain on the side. China should spy responsibly and stop attacks.
That's a pretty heavy diplomatic change. Especially the inclusion of NATO.
This is the EU press statement:
https://www.consilium.europa.eu/en/press/press-releases/2021...
China: Declaration by the High Representative on behalf of the European Union urging Chinese authorities to take action against malicious cyber activities undertaken from its territory
Note that I am a US citizen than expatriated after the second gulf war.
So I am not a fan if the US gvmt, but if you think for a second that the Chinese and Russian governments AREN'T doing the things they are accused you are naive.
Going to China wouldn't teach you much about its government structure and governance. It's not like you can just walk in and observe party cells interacting with company leadership.
You don't need to go to China to know what the government structure is, what foreign policy it conducts and what kind of economic behavior is clearly not just condoned (small scale hacking, data harvesting) but encouraged (fishing other nations' territorial waters) or even demanded (foreign business ownership requirements, IP transfer requirements) by the party.
You don't need to go to China to hear reports from dissidents experiencing internment, forced labor and cultural genocide. Or to see all the broken international agreements and sovereign promises, eg the early destruction of a free Hong Kong. Or to see the territorial expansionism in salami slicing illegal maritime boundaries.
Or... most importantly, to understand that a despotic cartel that doesn't believe in individual human rights is a terrible form of human organization that has terrible externalities for the whole species and planet.
What governments know based on intelligence and what they say publicly are not the same thing. If the EU thinks that making a direct public accusation would be antagonistic and would not serve their interests then they won't make one. That does not mean that they don't know what's going on, don't protect themselves, or even don't retaliate.
This is effectively a PR campaign. What is its purpose? Is it a coincidence that it comes at the same time as this Pegasus/NSO story blows up?
These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.Read the uk ditto for comparison.
As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the same feeling of freedom, do they?
China is a big country and the Chinese government does not control everything that is going on.
Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented.
Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or Bangladeshi government for that.
Yet it is different for Russia and China.
This kind of attempted misdirection is really common from people defending/spreading propaganda for the Chinese government. It's also similar to the excuses made when business partners with heavy government influence conduct scans and do other questionable things against US infrastructure. Apparently they think westerners are all too stupid or blind to understand what's happening. It's ridiculous.
Some had certain variables hardcoded, e.g. Administrator user's name and their exploits worked with higher success rate in anglosphere, but failed in localized environments. Others had more advanced exploits which queried parameters instead of assuming them - those where more successful around the globe.
Another nuance missing from popular press is that most groups in China (and Russia) are operating independently, but share tradecraft among them and occasionally engage with politicized missions (either working on explicit orders from government handlers or simply defending their beliefs hacktivist-style). This is what FireEye means by "affiliation with Chinese government", NOT "operates strictly on government orders".
[1] https://www.fireeye.com/blog/threat-research/2019/03/apt40-e...
All we know is that they used Chinese IPs at some point and Chinese configured computers, and that they went after military targets.
And we don't even know that these are the same APTs.
Honestly even without the government imposing so much control on corporations I believe it is fair to say that the acts can't be done without cooperation on some level of the government. If there's an elite group of hackers in your country attacking a country and generating ill will then a hands off approach is condoning the action. The only way to condemn the action is to work with said country to apprehend said hackers. But headlines aren't "US and China work together to apprehend rogue elite hacking group."
https://www.gov.uk/government/news/uk-and-allies-hold-chines...
UK and allies hold Chinese state responsible for a pervasive pattern of hacking
UK joins likeminded partners to confirm Chinese state-backed actors were responsible for gaining access to computer networks via Microsoft Exchange servers.
https://www.justice.gov/opa/pr/four-chinese-nationals-workin...
These are worth reading. Even though I am not sure how much of it would be able carry the burden of proof in a court.
Similarly to the Russian hacking cases, these will never see an independent court meaning the prosecutor can politicize and speculate without limits.
> Which is quite different from saying it is being done by the Chinese government.
Who in China would be more likely to organize an espionage campaign? Espionage is a game played by governments.
Your objection is like, after detecting a nuclear missile launch from the continental US, doubting that the US government was responsible.
There is also a "slight" difference in the difficulty of moving a nuke and a vurnerability across borders to launch it.
It's simply hard to know where data is coming from on the internet.
Is it meaningfully different? Let's suppose that they aren't nationally funded. If there's a large group of elite hackers in your country generating international ill will is it not also your responsibility to shut them down? To work with the government of the country that these rogue hackers are attacking to find them? Not doing so is akin endorsing the behavior.
And it can't be anything else honestly. They are spy organizations, which are intentionally created to be difficult to track back to the funding government. We've seen the US do this for decades and have plenty of declassified documents to support this. It would be surprising if Russia, China, Germany, Australia, Israel, or anyone else didn't also operate in a similar fashion. If the method is effective then it is effective. The fact that a group resides in another country does not have any bearing on the effectiveness of the method.
That said, this is Germany. All those Chinese factories are built with Germany equipment. They are leading the 'softer language' position.
But the EU and NATO are not the same thing, so Germany can have it's cake and eat it too on this one.
"If jobs in Germany depend on how we deal with controversial topics, then we shouldn't add to indignation, but rather carefully consider all positions and actions,"
Germany is the 'big country' using the most careful language.
[1] https://www.dw.com/en/germanys-reluctance-to-speak-out-again...
The US has denounced, accused, etc Russia on cyber attacks
It is now calling out and accusing China of cyber attacks.
My guess - ZERO concrete action.
Meanwhile, China says relatively little and focuses on actual power - trade ties, threats etc.
Russia has been accused of hacking and/or electronic spying by other states.
North Korea has been accused of hacking and/or electronic spying by other states.
And yes, the US and quite a few European states -- and many other countries -- have also been accused of hacking and/or electronic spying by other states[a].
All these governments are playing with explosives: The right spark at the wrong place at the wrong time can start a fire.
Seemingly "minor" incidents have triggered wars in the past.[b]
--
[a] Including via highly-targeted malware such as https://en.wikipedia.org/wiki/Stuxnet
[b] For example, https://en.wikipedia.org/wiki/Pig_War_(1859) , https://en.wikipedia.org/wiki/Marco_Polo_Bridge_Incident , https://en.wikipedia.org/wiki/Football_War , https://en.wikipedia.org/wiki/Assassination_of_Archduke_Fran... -- to name a few off the top of my head.
Russia appears to be waging an all-out cyber war against the US at this point. Putin admitted as much in the hour-long interview with NBC a month ago. He declared as openly as he possibly could have that the US would be targeted until it came to the negotiating table (they want sanctions etc. removed in exchange for stopping the attacks). So far the US appears to have been exceptionally reserved in its response, given it's a clear declaration of war by Russia to be intentionally targeting critical US infrastructure with attacks.
Perhaps a better (but also possibly fictional) example is sabotage of the Soviet trans-Siberian gas pipeline in 1983. Certainly there appears to have been a US suggestion to surreptitiously provide the Soviet Union with compromised technology it was seeking in the West. But it's not clear whether compromised technology was provided, or whether the US caused the pipeline explosion.
Here is one (controversial) source: https://en.wikipedia.org/wiki/At_the_Abyss
I wasn't going to comment at all, since the US does a lot of - ahem - "disruption" throughout the world. However, I'm not aware that the US does a lot of civilian infrastructure attacks outside of active military theatres. If true: it's a notable/interesting fact.
But I'm also not sure that civilian infrastructure attacks are further beyond the pale than rendition, bombing, arms sales, embargoes, et cetera. I worry that we in the States are more sensitive to infrastructure attacks because (1) it's a weapon readily available to our national adversaries and (2) for the first time, we are the victims.
Chickens coming home to roost....
Entire comment section: b-b-but the US.
China probably is "hacking us." US/NATO credibility is suspect.
I'm tired of this argument because it just serves the propagandists. It eliminates a real conversation happening because we can't even start one because we don't even agree on a basic premise of that things can be judged independently. Comparisons can be great, but independent judgement/criticism is also necessary.
I agree that a lot of the comments here are shitposting or making reactionary equivocations. Others though, are making valid points... which you may agree with, or not.
IMO, for example, the most important part of this to pay attention to is NATO. Cybersecurity & China seem to be the new focus of the alliance. To me, this seems like the most potentially impactful aspect.. and probably a key reason why this announcement was made in the way that it was made. IE, I think that what NATO do in the coming few years will make the history books, rather than Chinese cyberattacks. I may be wrong, but this isn't a disingenuous equivocation. It's just my judgement on this, at this point.
This isn't just a thread about chinese hacking, it's a thread about a US-NATO statement in response to hacking.
Anyway, who cares about convicting one or the other. This is about consequences. The consequences of whatever direction NATO is taking now are meaningful.. much more meaningful than the hack.
Watch this: https://www.youtube.com/watch?v=ZrsOM8ww8ug
Second, this isn't something China-specific. The US Federal government also has enormous power to compel companies to cooperate in surveillance. Just recall when the US government ordered Lavabit to turn over its SSL keys, so that the government could intercept Snowden's emails.
In some cases, yes.
For instance, I'm sure China wouldn't build its nuclear deterrent around some hypothetical US-made COTS "Nuclear Weapon Control System," even if there was zero evidence that system was compromised. Absence of evidence is not evidence of absence. Ditto with Huawei.
IMHO, if its decision-making wasn't so addled by wishful thinking and capitalism, the US would use far less Chinese technology for this reason.
China have:
* crushed protest at home and moved deeper into dictatorship
* shat all over the 1 country 2 systems agreement and strangled what little democracy there was in HK
* started a mini ground war with their nuclear armed neighbour India
* launched multiple pandemics, the latest costing the world trillions in lost output and millions of deaths
* started a Genocide internally
And were not willing to do anything are we? No so much as a sanction or an embargo except for Australia, who've been left to twist in the wind.
So now China hacked some shit? Great. What are we gonna do? Nothing because no one wants to pay interest on their borrowing or 3p more for pointless plastic shit they don't need from amazon.
/Rant.
My wife just got a new Windows laptop and the amount of dark patterns they use to push people towards the Windows cloud is insane. I haven't used Windows in years, but it's glaringly clear that the entire modern Windows OS is designed around recurring monetization of users. Nowadays, Windows machines are essentially one big trojan horse waiting to either be hacked or tapped into by 3-letter agencies.
I feel bad for the admins who are stuck with these systems.
(yes, if you are expert open source is easier top secure maybe, at least that was my experience 20+ years ago. Now I mostly pay companies like microsoft to host my stuff so I can do billable shit).
https://en.wikipedia.org/wiki/Nirvana_fallacy
https://www.cvedetails.com/product/194/Microsoft-Exchange-Se...
Is there any widely used software that doesn't have any vulnerabilities?
So, basically, don't use software. Actually, given the horrific state of modern software, I can get behind that.
I'm all for re-using code when rebuilding the wheel would be a hassle but it has to be balanced with proper code review before it should be included. Developers are much too quick to include outside code with the assumption that other people have already done the necessary reviews and this is where a lot of devs are getting bit.
Agreed. Microsoft should clarify how this happened and what measurements will take to prevent this incident from happening again. Still, the problem is with robbery and it should be condemned. Why changing the subject to Microsoft? I don't think whataboutism is the valid argument here.
There is a good argument to be made that Windows is a big target, but they should at least try not making it so easy.
This is a consumer choice. You don't trust Microsoft, you don't use its services. On the government level, you ask for regulations if the situation is escalated (if necessary). But dealing with global cyberattacks is not Microsoft problem and it's not connected to one company or one service. It's an international responsibility to act and establish a framework that prevents such attacks.
But we speaking freaking NATO here !!!!! Do you attach string to hand granade and hand other side to your adversary ? And then argue that someone pulled it ??
Microsoft Windows and Microsoft Exchange is SYNONYM to "security HOLE" ! So tell me - why customer NATO _choose_ to use this ?
The current situation ( and the resulting clamoring ) is absolutely a direct result of people who create this software. Trying to shift the blame onto nonexistent framework is at best laughable and at worst very deceptive. It absolves MS and its engineers from guilt associated with it.
To put it another way, if those engineers were bridge engineers, we would now be witnessing multiple collapses with swathes of engineers arguing that it is not their fault as 'there is an international responsibility to act and establish a framework' that prevents bridges from falling apart.
I am sorry. I do not buy this defense. As an architect, you should know better.
(Maybe "cyber insurance" needs to be a thing in the SMB world? As much as I feel it's currently mostly nonsense, maybe it's serviceable. In the physical world, it seems the driving force behind buying security measures is not the (unlikely) possibility of being a victim of a break-in, but the (more likely) possibility of not getting insurance to cover it.)
Is the US in a state of war with China? Do we need medieval tactics to deal with cyber security? Why insisting on blaming the victim.
Actually most locks are susceptible to being picked (ie. a known exploit), so what you're describing is already the case, minus the lawsuits.
There's no perfect security in the real world.
How confident are you that you could write an email server that could withstand extended attacks from nation states?
How would that work for something like a Boeing 737 max?
Yes, I am confident I could process text over the network without (42) remote code execution vulns.
https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
>Microsoft revealed that these vulnerabilities had existed for around 10 years
https://en.wikipedia.org/wiki/Microsoft_Exchange_Server#Vuln...
If they had any integrity they'd say: "I guess you got us back, huh!".
Entertaining to watch nonetheless.
It could be anyone.
In Stuxnet for example, the alleged perpetrators hinted that they were behind it.
Will the same countries and allies now condemn known, disclosed and proven cyberattacks sourced from other countries (with known state involvement and complicity) on activists and journalists that lead to imprisonment and death?
And Microsoft has a very long history of vulnerabilities and hiding it. And then they will refuse to patch known vulnerabilities in lower versioned software trying to force large customers to do unwanted version upgrades and to adopt the more expensive SaaS offerings.
They are now trying to force all customers off of the already paid for and cheaper on-prem Microsoft Exchange which is still the dominant software in the directory services market and trying to get all corporates onto Azure AD.