An inside look at NSA tactics, techniques and procedures from China's lens
inversecos.com
inversecos.com
I or anyone outside obviously cannot verify the technical details. However, the above statement struck as particularly uninformed. As any engineer in East Asia can tell you, there is nothing especially collaborative about tech in Confucian culture; if anything, the engineers in that region admire the free speech and discussion traditionally prized in the Western culture. Calling Chinese political framework, especially in the context of national security, conducive to open public discussion was quite ironic to see.
Edit: the punchline is this. If a friend who is always secretive and deceptive about his personal life is suddenly openly discussing his life, what does that say about the details he just disclosed and/or the situation he is currently in?
source: I regularly work with engineers from that culture and studied relevant geopolitics.
IIRC, Bunnie (Huang) mentioned how freely data flows in Shenzhen for hardware hacking, versus pulling teeth trying to get data sheets for components from western component makers.
> source: I regularly work with engineers from that culture and studied relevant geopolitics.
(Winces)
That's different though. Shenzhen is where electronics factories are; they get the datasheets from western companies, but because said western companies can't really enforce their IP over there, the locals get to ignore it and use the datasheets however it's convenient for them.
The provenance of the component is also really important. If it’s a ghost shift at a contract manufacturer producing the parts, they might have skimped on some part of the process (like packaging so that another subcontractor responsible for that step isn’t alerted) and the datasheet might be significantly inaccurate. I don’t know if these manufacturers ever bother to characterize their ghost shift parts enough to release their own datasheet but I assume it happens with especially popular parts. If the contract manufacturer loses the contract but keeps the ghost shift, they might be significantly out of date in revisions so you’d have to be careful to use only the datasheet they provide and not the one your engineers download from the first Google result (good luck!). In short, it’s complicated.
The most infamous example is probably the FTDI serial to usb chips that have been counterfeited for many years with varying quality, both by ghost shifts and manufacturers who reverse engineered the design to some degree.
That’s like pointing to torrent sites as proof that US media companies are open to sharing their content.
Most of the hardware details being shared in shenhzen are stolen from western firms that have no way to enforce their IP.
It’s why you can get your iPhone storage upgraded for pennies on the dollar.
??? How is this related to anything IP? To get your iPhone storage upgraded, you just need to blow off the old NAND Flash and "solder" new ones. Their pinouts are in public standards and every storage vendor in this world uses the same one.
And they did this for pennies because, of course, contrary to what Apple wants people to believe, flash storage does not cost much and even with the cost of all the dirty work it's still not much.
Or do you mean that they are violating Apple's IP rights by modifying their own devices? That's just... bullshit.
that's the problem
in 1990-2010, >80% chinese influencers are liberals
after 2010, it went down to <30%
after 2020, <10%
and most important, there's a very higher proportion of software engineers are liberals, which is easy to understand since we are followers of western
but things are changing now, when you talk with a young chinese developer now, there's a good chance that he/she is a commie
there's a simple way to validate this, if a chinese developer willing to discuss abt politics with you and 'admire the free speech and discussion traditionally prized in the Western culture', he/she is a liberal,
if he/she avoids talking abt politics with you, it's not because he/she fears to talk abt this, it's because he/she is too polite to share different opinions as yours
Simple but effective. A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA, as long as they are flexible enough to allow off-hours and overtime pay and remember to respect the US federal holidays.
> Two zero-days were used to breach any company with SunOS-exposed systems in neighbouring countries to China
SunOS? Wonder if it's because it's genuinely used still quite a bit or they simply had zero-days for it since many of those are old and unpatched?
If I were in charge of things I'd like to think that this sort of thing would be the first step I'd take to cover my tracks, but I still hear cyber security firms using it in their attributions.
It also may not be worth it. Generally APT's want to stay under the radar while they are executing. But after the goals have been reached, most of the time it doesn't matter much if they get attributed. We have yet to see real consequences against any APT's. So paying your employees more to work night shifts, likely doesn't stack up against the consequences of attribution.
EDIT: Huh, I guess sometimes it is like the movies: > One of the frameworks used by TAO that was forensically uncovered during the incident named “NOPEN” requires human operation. As such, a lot of the attack required hands-on-keyboard and data analysis of the incident timeline showed 98% of all the attacks occurred during 9am – 16pm EST (US working hours).
You wouldn't spend hundreds of thousands of dollars on large scale attacks with lots of (temporary) infrastructure and planning to then yolo it at the last minute and hope that everything goes well and you have the results back when you come back on Monday.
(My perspective on this comes from doing security assessments and pentests 10+ years ago. Take that for what it's worth.)
I think of it a little bit like robotic vs. human space missions.
A robot can gather a ton of data without human intervention. It can perform repeated mindless activities. A certain amount of contingency against unforeseen issues can be engineered-in. Beyond the point of expected anomalies, though, the robot is going to fail (and perhaps expose your operation).
When it comes to reacting to rapidly changing mission conditions nothing beats a human in the loop. It's really hard to plan for all the peculiarities of any given environment. Intuition and experience play an immense role. Most of all, though, you may only get one shot before you're detected and stopped.
Do we have any probe into the state-sponsored APT world? I wouldn't be surprised if there isn't any, but would like to know.
It seems like such a lapse in tradecraft that, absent other indicators, I would just assume it's a crude false flag attempt.
It's not like China will sue them, and not like both sides can easily say that it is just reciprocal.
*> A good non-NSA agency should also learn from this to be able to effectively false-flag as NSA*
For what it's worth, this is already a TTP used domestically, as well as by our adversaries (and allies, eg GCHQ and 8200).Similarly, 0day ABNF to identify probable NSA front companies:
[optional-firstname] <surname> [optional-adjective] <"systems">
the traffic redirection is interesting in that i would be curious if they rate limited it or used on device selectors in their implant to redirect traffic. the trade off between memory caching packets to sort on selectors vs.stealthy throughput would have been a fun design meeting.
hunting these kinds of actors would be supremely fun. the main thing that protects them is few outside massive bureaucracies really care enough or find it economical, as the rewards are more in finding new zero day and not hunting state level threat actors. the exceptions who do (p0, citizenlab etc) are attached to massive orgs and dont really led themselves to privateering. amazing write up anyway.
- the focus on switches and routers is very pro (did you mean the defenders or the attackers?)
- What kind of knowledge is a starting point to hunt these players? I assume very good Linux system admin skills that can protect the whole system well enough to maybe only allow some obscure entries, and then have enough RE/Red team knowledge to know how to focus on these entries. Does it make sense?
- How do those APTs operate? I'd imagine there are at least 3 groups of people, group 1 = people who make tools, do analysis, RE and such -- they are the support guys; group 2 = people who directly execute the operations -- they don't need very in-depth knowledge but need to a whole range of knowledge to know where to look at and how to best use the tools; group 3 = blue team who protects the whole facility. And of course there are managers, admins, etc.
I'm guessing this is so when they do data exfiltration (and hosted MITM) it's not sending a ton of data to a single server, but spreads them out.
> SECONDDATE: This tool was allegedly used by TAO (NSA) to hack into the office intranet of the University. Attribution of SECONDDATE was discovered through collaboration with other industry partners. They found thousands of network devices running this spyware – where the communications went back to NSA servers located in Germany, Japan, South Korea and Taiwan. This tool was used to redirect user traffic to the FOXACID platform.
> SECONDDATE – Backdoor installed on network edge devices such as gateways and border routers to filter, and hijack mass amounts of data in a MiTM. This was placed on the border routers of the University to hijack traffic to redirect to NSA’s FOXACID platform.
Throughout my longish life, these things have not changed.
~All federal politicians support/expand it and then obfuscate their part.
News orgs don't/won't cover it (most of the time). The reason is every possible reason. Stated differently: Reluctance is a forgone conclusion; every editor/journalist has their own why.
There is an excess of voters who compulsively give Gov the benefit of the doubt. At least where Gov favors it's interests over ours. (modern version: Where Gov acts in good faith and places our interest first, wound-up voters endlessly crap all over that [because agendas].)
I've quite literally seen people ask "why don't we attack them back?"
> * One of the frameworks used by TAO that was forensically uncovered during the incident named “NOPEN” requires human operation. As such, a lot of the attack required hands-on-keyboard and data analysis of the incident timeline showed 98% of all the attacks occurred during 9am – 4pm EST (US working hours).
> * There were zero cyber-attacks on Saturdays and Sundays with all attacks centralised between Mon-Fri.
> * No attacks occurred during Memorial Day and Independence Day holidays which were unique American holidays.
> * No attacks occurred during Christmas.
It's surprising the NSA would be this sloppy and obvious, or maybe they don't care about attribution in this situation, or maybe someone else did it. But I've read attribution of Chinese attackers using work hours and thought the attackers were sloppy and obvious.
> A key observation from the Chinese case notes was the extensive use of big data analysis, particularly in tracking “hands-on keyboard” activity. This approach enabled Qihoo 360 to identify patterns, such as the alleged absence of activity on Memorial Day, and precisely documenting the operational hours of the attackers, allowing 360 to isolate activity to Monday-Friday, EST working hours.
If the blogger's claim of experience is true, they must know about the things I've read. I wonder what they are thinking of.
I think the English language aspect is much more interesting and difficult/impossible to prevent.
I assume it's a jungle out there, so teams need to protect themselves 24/7/365 and I'm surprised to find no activities in holidays.
This is probably a dumb question but doesn't that require an SSL cert? Obviously the NSA can get someone to issue a cert for a domain they don't own but wouldn't that be visible?
Couldn't you have every user device log the SSL certs it sees to detect this attack? What about CT?
What is Shadow Broker, does anyone know?
Nyet
Come on guys, if Satoshi can cover his timezones tracks, so can you.
Someone doing extensive research on Weixin might ordinarily realize that it's called "Wechat" in English.
Wechat is also the mainland version. It's always been Wechat, and in particular it was Wechat years before they kicked me off of the mainland Chinese version† for registering an American phone number. The reality is exactly what I already told you: the app's name is 微信 in Chinese and Wechat in English. This is why coverage of Wechat's extensive market penetration in China always calls it "Wechat".
Don't believe everything you read in the results of the stupidest web search you know how to run. If you try facts, you might like them!
† By the way, "version" is really stretching things. There is no difference in the app. They don't keep your data within China, you go into a different advertising segment, and by default you connect to a different in-app sticker shop.
Always love the use of a dagger though, I don't see them too often online!
There are tons of difference. Wexin has more adware/spyware, no CallKit on iOS, local payments.
There's even a chat firewall between wexin and wechat.
...is there a reason you believe this? It is not true in any sense.
I'll also note that, if you believe the claims in your comment, you'll have a tough time explaining how my installation from the Google Play Store includes local payments.
So the app functions differently depending on who (or an inferred "where") you are and you as the user have different terms - how would you describe that? Could "version" suffice?
0. https://weixin.qq.com/cgi-bin/readtemplate?lang=en_US&t=weix...