NSA Chief: China Behind RSA Attacks
informationweek.com
informationweek.com
If they were really concerned about espionage and eavesdropping, the first thing they would do is make sure that the phone lines to the White House were run by domestic companies and not a company with links to Israeli intelligence.
I think the real news is that China isn't publicly denying these incidents anymore. Though, it seems like nothing has really changed.
--------
I worked for a company that was acquired by Lockheed. I ran IT and had already spent a few years 100% rebuilding the infrastructure of the company when I joined.
As we were assimilated I worked with IS&S and their security teams closely to ensure our security measures were up to snuff with Lockheed's requirements (we built the RFID tracking system the military used for shipping pretty much everything) In our security meetings, we were briefed on activities that were happening, what we needed to do and why.
China was constantly attacking Lockheed and all other defense contractors.
They were pretty sophisticated in how they did it; targetted spear phishing was one of their successes:
Chinese spies would attend defense contractor events - meet and seek out lockheed and other employees. Get their business cards and spoof mail from one employee to the other, referring to events that occured at the convention to get people to click on shit that would be a trojan. These trojans were rather sophisticated in that they would operate very very slowly to trickle pieces of information out. Sometimes they were very specific pieces of information.
I don't recall exactly how this was found out, but someones machine was being checked out - and in the process the trojan was found. When the chinese were alerted to the fact that the trojan had been found, they turned whatever their bot-net was up to 11 and attempted to just mass send out as much data as they could.
(All of lockheed only has (I think) 3 connections to the internet)
They cut it off and had to get rid of these trojans.
Another time, a supplier (I think it was in Taiwan, I cant recall exactly) a supplier was hacked and its machines would install stuff on any USB sticks used.
Lockheed machines were not allowed to connect to non-lockheed networks, via Wifi or any other means. So they would use USB sticks to transfer stuff.
The chinese went after the suppliers machines as a vector to get connected with the lockheed machines. I have mentioned this stuff here on HN before, and in light of China's 50-100 year vision for where they want to be, we are basically fucked. The chinese have been securing access to all major natural resources in Africa, as well as being the manufacturing hub for EVERYTHING - while the US government is squabbling over petty short term profit efforts and securing a diminishing resource (oil).
This is not to say the US is some slouch in the cyber security space; Stuxnet and Doqu are clearly US/Israel cyber attacks that are amazing. But anyone would be a fool to not be very wary of where the online digital war is headed.
I take it at face value, though.
If you ever have time, trace back all the "China hacking" reports, they all came from non-tech sources, just authoritive accusing. Blame China is obviously the most safe and easy assumption, because Chinese people rarely care or hear foreign voices anyway.
But do you happened to know that Chinese Internet was one of the largest malware & botnet victims in the world? If you subscribe full-disclosure you can see lots of mass security issues happening in China everyday.
No, it isn't. The Chinese themselves are documenting the attacks. They made a documentary about it. It was a story here on HN. It's not exactly a secret.
http://news.ycombinator.com/item?id=2916613
Yes, it's documented, but it's DoS Falun Gong servers, the same stuff like Anons with LOIC. But stealing IP from company for political or commercial motives? You need much more than DoS.
Second, if you do not think that MASSIVE governmental cyberspying is taking place between pretty much everyone, then you are fooling yourself.
We have already seen the most amazing display of US/Israel cyber capability with Stuxnet.
THey have been even actively ASSASSINATING nuclear engineers in Iran for fucks sake!
Just because I have been aware of China's attacks on Lockheed since 2007, and likely the first time this type of thought entered your head in ~2012 doesn't make this some propaganda campaign.
OF COURSE china is under attack from the US, Israel, France, the UK.
I am not sure if you are aware of it - but a resource war is looming in the not too distant future.
While China has secured MASSIVE natural resources and made themselves the center of all consumer/industrial manufacturing (aside from heavy industry in Germany) - the US/Israel faction has spent trillions on advanced weaponry and securing fuel resources.
So that war that is coming will be a war of attrition: US/Israel with secured fuel for N years, China with massive natural and human resources.
Right now the chess game of getting everything in place is what is underway.
1. Hacking between nations happens
2. China has massive resources
While I agree a war is looming, but simply accuse China without decent evidence is just like "USA Imperialism" hatred in China without any rational reasons.
And just for the record, China relies heavily on resource import, too. And the documentary shows exactly how poor Chinese government hacking is.
Yes, china relies heavily on resource import - this is why they have been actively securing all the natural resources of Africa.
There was an amazing article written in 2008 called "China storms Africa" or something that went into detail about this.
EDIT HERE IT IS - READ THIS: http://www.fastcompany.com/magazine/126/special-report-china...
It talked about China having a 50-100 year plan to secure resources.
When have you seen the US think further than 4 years in advance.
They don't.
The US is dead. A husk - a farce and a country who has seriously lost its way.
Instead, we rely on the threat of our oil based military to scare countries into submission. We are incapable of long term thinking.
Contrary to what samstave said, Chinese APT aren't particularly sophisticated. They do leave a lot of footprints behind, although for obvious reasons that data is generally not made public.
Is it possible for island nations with no natural resources to be wealthy? Are you familiar with the historical and economic criticisms of Mercantilism? Are you aware that world proven oil reserves are at an all time high, and that the primary source of US oil and energy imports is Canada? http://en.wikipedia.org/wiki/Mercantilism
Unfortunately - even if this is correct, and opinions do vary - this does not counter the fact that oil is a diminishing resource. Furthermore, the quality of current reserves, in terms of oil grade and ease of extraction, is increasingly poor.
While certain metals are rare to Earth, they are overly abundant on asteroids which robots have already visited. Severe shortages would create a corresponding incentive to invest capital in extraterrestrial resource extraction, which would lead to much greater long term abundance.
However, I will say this: I really do think it's in a company's best interests to dabble in the blackhat security markets a bit as a bystander. You can watch the development of some VERY interesting 0days, botnets, and other such goodies from an in depth perspective. That way, you can protect your mission-critical assets from the latest and greatest vulnerability before it trickles through to vulnerability notifier services.
[I should add something about the degree of separation of govt and corps being a factor.]
If you want a declassified historical account, look back at the US IC programs to furnish sabotaged/backdoored electronics during the later years of the Cold War.
I am assuming IC == integrated circuit? Was that program targeting the USSR govt or private industry, such as may have existed? Was the backdoor designed to steal state secrets or economic secrets?
But your link is a little undersourced? And I'm really having a hard time with the part about Motorola. "The 1995 Motorola letter is proof positive that Bill Clinton is directly responsible for the present-day U.S. intelligence disaster." Giving Motorola an encryption export waiver (which is something crypto geeks had been fighting for for years) is proof that Clinton turned the NSA into a cash cow?
Really, I am interested in the topic, but your link is more of a hit piece than anything.
[The link noibl posted is exactly the interview I was thinking of wrt Boeing and Airbus.]
NewsMax. I'd sooner watch Fox News or read the gaggle of NYT's neocon pundits.
“The U.S. government is involved in espionage against other governments,” he says flatly. “There’s a big difference, however, between the kind of cyberespionage the United States government does and China. The U.S. government doesn’t hack its way into Airbus and give Airbus the secrets to Boeing [many believe that Chinese hackers gave Boeing secrets to Airbus]. We don’t hack our way into a Chinese computer company like Huawei and provide the secrets of Huawei technology to their American competitor Cisco. [He believes Microsoft, too, was a victim of a Chinese cyber con game.] We don’t do that.”
“What do we do then?”
“We hack our way into foreign governments and collect the information off their networks. The same kind of information a CIA agent in the old days would try to buy from a spy.”
“So you’re talking about diplomatic stuff?”
“Diplomatic, military stuff but not commercial competitor stuff.”
-- http://www.smithsonianmag.com/history-archaeology/Richard-Cl...
(Note: He's talking about the US government, not about any other US-based entities.)
I remember in the early 90s it was revealed that the French Intelligence had bugged Business-Class seats in Air France, and were passing commercial secrets to French companies: http://www.chron.com/CDA/archives/archive.mpl/1992_1089133/i...
i doubt they said anything to that effect.
My bet, if I could see the talk somewhere, is that he referred to the attacker as something generic (not "china") and then on another point talked about China's trouble with intellectual property as when they sell counterfeited cisco gear or use code from one US company manufacturing there on a huwaei product, etc.
and the journalist just cut, mixed, and published the bomb about china being the attackers.
of course the article may only have the worst quote choices and that's exactly what he said.