Chinese hack U.S. Weather systems, satellite network
washingtonpost.com
washingtonpost.com
...
Due to the classified nature of the DMSP imagery and other data products, the DMSP downlink data is encrypted, and thus the direct readout system is not available to nonmilitary users.
That all comes from this cool-as-hell PDF† about how to build a GOES/POES ground receiving station. Anyways the most obvious target here is probably the DMSP products, rather than, say, a Bruckheimer-esque plot to disrupt NOAA satellite imagery during the height of the Atlantic hurricane season.
† http://noaasis.noaa.gov/NOAASIS/pubs/Users_Guide-Building_Re...
"We bred them to be tasty, but no one could foresee that it was us that would be devoured"
So no one in the Chinese government or citizens had noticed that they can't see across the street until the Americans mentioned it?
This one-party autocratic rule will one day make people insane.
They have no end of complaints about the government and are quite vocal about it- but huge divisions (to put it mildly) between provinces, as well as urban and rural people mean that the idea of letting "those people" have a say in how things are run is unthinkable.
Almost like VPNs, proxies, TOR, compromised machines, botnets, or similar do not exist in this arena and that a reverse DNS lookup will tell them 1337.mss.gov.cn.
When the US talk about cybersecurity/"cyber wars" in general they're talking about something more akin to a Hollywood movie than anything you see on the ground on either side of the "fight."
I'm extremely sceptical every time they claim Chinese responsibility. I am sceptical not because China wouldn't have the skills or motivation to do so (they do/would) but because they jump to these conclusions unrealistically quickly and if their adversary covered their tracks even modestly pointing fingers like that would be quite hard (e.g. send it through Russia).
If it were me, I'd just issue a formal letter thanking the Chinese government and their people for spending their own taxpayer's money pen-testing U.S. infrastructure and ensuring security best practices are followed ;p (yes, I am being tongue-in-cheek, speaking of cheeks...)
tail -n 50 /var/log/auth.log
Nov 12 15:33:28 VPS-3167 sshd[11950]: Connection closed by 122.225.97.110 [preauth] [SNIP]
Nov 12 20:12:51 VPS-3167 sshd[12016]: Connection closed by 61.174.50.164 [preauth] [SNIP]
Nov 12 20:40:44 VPS-3167 sshd[12031]: Connection closed by 122.225.97.72 [preauth]
The list goes on and on, and the ip's in the last fifty lines were all Chinese or Russian, still they could also have been hacked themselves.
Of course, this is a whole different level of culpability than if they were actually condoning large scale attacks on other countries infrastructure.
The fact remains that if I were to plot the amount of ip's that come knocking at my non-production server you'd see over 50% coming from china.
17.18% of all desktop OS-es connected to the internet are Windows XP, the version for which Microsoft doesn't publish updates. Most of these computers are in China. Also "in 2009, approximately 80% of software sold in China was pirated."
The average weekly income of a Chinese worker is around 100 USD. He is not going to buy new software even if it costs the same as in the US. It typically costs even more.
Don't be surprised bots have easier targets there.
Hint: port 9415
1) use a different port 2) use ip ban 3) use a firewall with range blocking -
Or do you have a good reason for allowing access from every ip on the internet?
EDIT: removed snark
So yes, probably.
I find it weird how in a world this connected, we still only get one POV.
The "one POV" thing is not about how interconnected the world is; it's about language barrier. An English site will always be dominated by people whose native language is English.
We can all sit back in our comfy chairs and debate whether it really is China or not, whether various networks are secure or not, or how much various agencies can store (and the dangers associated with them storing things). But we can only do that if we have recent and valid information about what's going on. Good public policy decisions depend on an informed electorate. This kind of situation is not the place to be covering up your mistakes.
That's because you want to find and close the vulnerabilities before publicizing them. Otherwise, by publicizing, you invite attacks that will (a) multiply the noise you have to sift through to complete the investigation and (b) potentially create new incidents, at a time when you are already in a crisis (the current attack & investigation).
So most security departments will only talk about what happened after the fact, when it's all been tidied up again. But even then, the habit of secrecy has already been established. It's a constant struggle to bring openness to a process where secrecy is a short-term advantage. If you want an informative accounting of what happened, I think you need to add it to the incident response process.
For example (simplified for illustration)
1. Notice an intrusion
2. Capture information (logs, vulnerabilities used, etc)
3. Secure systems that have been compromised
4. Prevent future intrusions within the organization
Need to modify 4 (or add 5)
5. Publish to help other orgs also prevent intrusions.
But other orgs may hate you for that, because in the process of publishing, you have exposed their lax practices that (in hindsight) used to be your lax practices ...
I wonder if a serious problem with the world is due to secrets that allow some to have power over others. For example, a company with a patent on a drug that costs $80K has power over those who will die without it. If you can't afford it, have you seriously harmed the company if you violate the patent to manufacture it in a 3rd world country for people who could never pay for the drug. When is human life more important that a company's right to a patent (or information)?
The chinese have a serious problem in the form of several hundred million people who need to be moved out of poverty. To help them get there they seem to be mining a precious resource: information in 1st world countries. Is this different (or worse) than 1st world countries mining precious resources in the 3rd world?
What is the net result? China will use this information to make itself wealthy enough to buy more of our goods? China will acquire the ability to make our goods cheaper than we can make them and force us to work harder?
I'm not saying "stealing" is "right" but it seems to be an important way all 1st world countries became richer. The notion of "right" is suspect given that history is written by the winner.
http://en.starafrica.com/news/mozambique-chinese-firms-clinc...
http://www.ide.go.jp/English/Data/Africa_file/Manualreport/c...
My experience five years ago was that regular African people were not too keen on the Chinese mining companies that had set up shop. But perhaps there was not enough competition to mine more locally.
Edit: Also, if they just wanted weather data, they should've signed up for http://pressurenet.io ;)
http://www.history.com/news/the-weather-forecast-that-saved-...
Eisenhower rolled the dice and the weather did indeed hold up long enough for the invasion to occur. His opponent, Gen. Rommel, felt the weather was going to be so bad there was no way the invasion could commence so he was actually away from Normandy on D-Day to see his family.
knowing how much your opponent knows about the weather is also pretty important.
...and so is knowing where they want to know about the weather.
NOAA is a branch of the US Department of Commerce - it's likely that is a relatively interesting target. And the NWS probably has data feeds that are based on non-publicly available information: maybe they've got some military satellite feeds out there. Who knows.
But in reality I'd bet this was just a "cast many lines, see what we catch" operation. And most people probably discounted the risks of Chinese attacks against the weather service. I'd further bet that there are plenty of lesser-known government organizations out there that are being actively exploited right now.
Slides 12-25 in particular.
If only there were laws in place that protected companies from things like this...
There are no US data breach laws, only state data breach laws, and they vary significantly from state to state, also in what constitutes "data", "breach", and "disclosure".
So it's not just a matter of breaking the law or not. There are lots of situations where specific companies can not disclose publicly that they've been breached and not run afoul of the law.
A good read - http://www.ncsl.org/research/telecommunications-and-informat...
Is it just me, or is this apparently the reaction every time a US government or military system gets hacked by China?
"Yep, we got hacked again. But we're just going to do our best to minimize the damage and pretend it never happened. No meaningful action will be taken against the perpetrators."