China Cyberspies Outwit U.S. Stealing Military Secrets
bloomberg.com
bloomberg.com
Just once, I'd love to read an article that talks in specifics, like how they got in (e.g. via exploit XYZ), how they spread (e.g. via hole in network policy XYZ), and what was done about it.
Also, if this super-top-secret information is so vital to the US's national security then why was it in the hands of a private company? I might be misunderstanding something here, but it seems less like information vital to national security and more like information vital to that company's future success (i.e. industrial espionage).
I cannot help but wonder if someone at this company (e.g. former CIA director) made a few phone calls and turned an industrial espionage incident into a national security incident in order to cover their arses.
I really wish people would stop posting them.
National security is a profit machine.
The real secrets are secure, but no guarantees on the Kernel's Chicken recipe.
Now that is a fast food restaurant I'd like to visit.
Here's a quote from the article, citing a 'princeling':
" "China no longer has a paramount leader who can hammer down authority at crucial junctures. "Gangs" of patronage and bribery are congealing together, he said, adding that "Corruption is the glue that keeps the whole system together, after the age of idealism." "
And another:
" A third princeling, whose father once ran China's security apparatus, blames Jiang for sabotaging the last leadership transition in 2002 by refusing to relinquish control of the military. He said Jiang promoted dozens of generals who are, as he put it, either "henchmen" or "morons." The result is that nobody is really in control, he said. "
[1] http://www.foreignpolicy.com/articles/2012/04/16/rotting_fro...
Note: You don't have to sign up for foreignpolicy.com to read the article. Just disable JS or stop the page from loading before the popup shows up.
What kind of bizarre world are you imagining where governments are meant to or do act "professionally". The international diplomatic community is indeed a noxious swamp where immoral and illegal activities get ignored and hushed up all the time. However it's also an environment where governments release stories to their populations through newspapers. Like China provoking that fight with Japan over islands and pretty much every story in the Daily Mail in the UK (or is it the Sun?).
The activities described in this article are shameful and it is one of the tragedies of this age that large organisations whether governments or corporations literally have no shame or morals. And more importantly nor do we have a way of requiring them to act rationally, reasonably or morally.
1. The Talon project (the robot pictured) is not, in fact, super secret. I worked with the Talon platform, and while my projects were "confidential", it wasn't some super secret thing. Would the government rather not have the Chinese have that IP? Of course. Is it at a security disaster? Hardly. That's not to say that they didn't have other, much more secretive, projects that were also compromised; it's just that the stuff being reported in this article isn't, like, nuclear launch codes.
2. IT security there (and, as I understand it, at similar government contractors) really was laughable. Total cowboy land. Assuming it hasn't revolutionized its security and culture, this attack didn't need to be some amazing exploit; it may have been a phishing attack or something similarly straightforward. So while the article lacks details, I'm not sure there's anything interesting to find here about the merits of the attack.
FWIW.
Good job that no one is using computer or the internet to launch attacks on research and production facilities in foreign countries.....stuxnet.......oh.
This might be new to some, but it it turns out countries spy and thieve off each other. But all we seem to see is lots of articles about the evil red commie Chinese, who we all happily do business with, including allowing to own our debt, hack the US. Strange that.
China's holdings are actually not a big deal. If pressed to do so, the Fed could print a trillion dollars tomorrow and buy it all back (with some obvious consequences, but non-the-less).
"The breakout of foreign-held debt shows that China was the largest holder, at $1.161 trillion (as of October 2012, most recent data). Japan came in second, at $1.134 trillion."
http://useconomy.about.com/od/monetarypolicy/f/Who-Owns-US-N...
There's a massive number of sources, but here you go:
http://finance.townhall.com/columnists/politicalcalculations...
people really, truly, honesty believe the last 200 years of US and European ascent didn't happen, as if the world sprang forth fully formed in 1997. the vast majority of people haven't spent 5 minutes really thinking about how this stuff works.
a lot of this double-standard is inextricably tied to racism also.
Did the US steal all the oil in Titusville (which instigated a massive economic boom) from Britain? How about all the chemistry work and exploration work that the US did to make oil useful and plentiful? Standard Oil had one of the most advanced R&D labs on the planet. I guess all the advanced technology out of Xerox PARC and Bell Labs was stolen from... Madagascar?
Who did Tesla steal his inventions from while he was in America? How about George Westinghouse? Edison invented a few things that you might have heard of.
We could be here all night.
While avoiding hyperbole of the parent comment let's not imagine that any country is immune from industrial espionage and industrial corruption. (The UK which has relatively little political corruption has some astounding examples of industrial corruption.)
The parent claimed the US primarily stole technology to fuel its way to economic power. The facts do not support that.
P.S.: BTW, the knowledge on which transistor relies did NOT occurred in USA, and networks similar to USA's ARPANET were developed in other countries in the same period, so the fact that Internet has an USA origin is purely incidental ...something that may be true for a lot of other things.
what you are doing is comparing the height of the US as it was hitting its stride (cellphones, cpus, internet) with the very beginnings of an industrial revolution in china. the US also had a beginning industrial revolution, and it stole much of that technology from the UK/Europe.
read that again: you are comparing the HEIGHT of a country (20th century US) to the BEGINNINGS of another. what you should be doing is comparing the BEGINNINGS of the US to the BEGINNINGS of china 2.0
then of course there's:
http://en.wikipedia.org/wiki/List_of_Chinese_inventions
but nobody really gives a shit about this stuff anymore because it's so old. what have you done for me lately, right?
yes, the US achieved prominence through all those inventions, but not before there were sweatshops, theft of English intellectual property, mass exportation of cheaply made goods, etc.
and maybe now china is ascending again, and in the next 50 years, you will see the equivalent of transistor, cell phone, CPUs, etc.
but then again that's probably just WAY too far-fetched for you to believe.
I think it's stupid to cast this as the super whiz kid Chinese hackers and the poor SOB admins looking at the logs. There usually isn't even a proper budget for admins to be looking at logs.
The Chinese tweaked the plans so when they tried building the thing nothing would fit.
I love the smell of irony in the morning.
Yes, one was a moron. And the other was a moron for employing that moron :)
I think maybe the fault lies not with the Chinese superhackers, but with your definition of "closely guarded."
Buying a second pc for every person is pocket change.
I'm thinking that if these secrets are not more valuable than the lifestyle and convenience of military consultants, then they're not actually all that live-or-die, are they? Instead, they're used as fodder for alarmism.
I'd find it very hard pressed to find a place where you can work remotely. (Especially with all the useless crap IT pushes usually)
Or make it easier, you can work remotely only by remote desktop access (like Google does internally).
(Yes, you can capture a video of the data, but it's one thing to see a picture of a cad drawing, another one to have the file)
* Joe's working from home, but logged in? Disconnect!
* Joe's transfered 80GB today when he normally does 2GB? Disconnect!
* Joe's connecting from a VPN server in Croatia? Disconnect!But a more interesting question is to look at what information is presented and what is missing. How much is new, how much is old. Then on policy stories like this one I sometimes pop over to the senate web site and look at what's coming up on the senate calendar [1] and oh look, on May 7th they are having a hearing to talk about
Hearings to examine the Department of the Air Force in
review of the Defense Authorization Request for fiscal
year 2014 and the Future Years Defense Program.
Hmm, who is in charge of Cyber Command? Why it's the Air Force! Who would have guessed.(yes I can be that cynical)
[1] http://www.senate.gov/pagelayout/committees/b_three_sections...
You can usually tell what hearings are coming up just by looking at what ads are currently plastered in and around metro stations
Is that really the case, though? Their own verbiage makes it sound different.
"Who is assigned to USSTRATCOM? The men and women of USSTRATCOM come from all four services —Army, Navy, Marines, Air Force— and include Guard and Reserve members, Department of Defense civilians and contractors. Thus, the command is a unified command. This concept allows USSTRATCOM to adapt to the changing international political and military landscape with all military branches providing key input and recommendations."[1]
and
"Organization USCYBERCOM is a sub-unified command subordinate to U. S. Strategic Command (USSTRATCOM). Service Elements include Army Cyber Command (ARCYBER); 24 AF/ Air Force Cyber Command (AFCYBER); Fleet Cyber Command (FLTCYBERCOM); and Marine Forces Cyber Command (MARFORCYBER)"[2]
Cyber Command seems to be headquartered at an army base, Fort Meade.
[1]http://www.stratcom.mil/faq/#faq2 [2]http://www.stratcom.mil/factsheets/Cyber_Command/
Just like during the cold war, there were legitimate threats from the Soviets, but it also became a self-perpetuating thing.
The irony is this time we're borrowing money to defend ourselves from the Chinese from...the Chinese. So at some point a marginal dollar spent on defense actually reduces our security!
But I think infosec is one of the more efficient means of spending defense dollars; tens or hundreds of billions of dollars of other stuff I'd cut first.
For those who don't see the connection, CISPA is intended to allow the government to help with exactly this type of situation.
Whenever Chinese military needs money, spread news outlets about horrifying US threats