U.S. Decides to Retaliate Against China’s Hacking
nytimes.com
nytimes.com
That also sounds like hacking into another country's systems.
The rational move is a massive investment in security technology including strong encryption and the kind of work that the NSA used to do in the 1990s of working to make Windows and Linux more secure for American businesses.
Any attempt by our intelligence services to back door computer systems, instead of working to make everyone more secure, is a grave disservice to the American taxpayer.
And that's what our leaders don't understand. If the NSA has access to backdoors in collusion with vendors, what stops China or Russia from exploiting the same backdoors ? absolutely nothing. If the NSA can hack phones because provider X or Z has setup a "secret" interface for that purpose, well it's going to be exploited by someone else, and foreign hackers will figure it out. How can the NSA be sure that PRISM and co themselves aren't compromised?
Attacking is easy, securing is hard.
So everyone is concentrating on the offensive abilities, because that's where the easy pickings are. And you can make flashy presentations about "how we f*cked them over". Flashy presentation about how you probably reduced the risk of a security breach by a few percentage points? Not so much.
Think of a fort. Forts had defined security controls in the old times. In a fort, you go through a security rotation of making sure the pot of boiling oil tips over on time. You practice your smoke signaling so that the appropriate people are notified in the event of a wall breach. You measure your walls and review their height periodically. You protect transports carrying crown jewels. But the only way to make sure all these worked effectively was to write down their processes down and practice them.
You need a systematic checklist to control your sensitive environment and protect your fort. In an agile environment, keeping all the processes in your head is painful. By prescribing to a series of security rotations (e.g. Code review process, Change control process, Log review process, Key Rotation process, Secure Delete process) you can provide accountability that reasonable steps were taken to build your fort and protect your crown jewels.
1. Boundary Control (e.g. Firewall, Router, Switch)
2. System Hardening (e.g. Chef, Puppet)
3. Data Storage (e.g. SAN, File Servers)
4. Data Encryption (e.g. VPN, TLS, SSH)
5. Malware Protection (e.g. App Isolation Containers)
6. Source Code Analysis (e.g. Unit Testing, Integration Testing, Code Coverage, Linting, Code Formatting, Brakeman)
7. Authorization/Authentication (e.g. LDAP)
8. Physical Access (e.g. Badges)
9. Log Monitoring (e.g. FIM, Logstash, Papertrail, Splunk)
10. Intrusion Prevention (e.g. Snort, Metasploit, Burp suite, Nmap, Nessus, Kismet)
11. Write current processes (e.g. Code review process, Change control process, Log review process, Key Rotation process, Secure Delete process)
Its writing down current processes (and following them) that's the missing piece to a holistic security program.
The other missing piece to a hardened environment is buy-in from the three primary stakeholders that hold up the fort: Sysadmins, Developers, and Security Officers.
Developers don't realize the importance of Source Code Analysis. Is your code even 80% covered? That's a big part of building up a good defense :).
The point being that it doesn't seem unreasonable to expect that a legion of military minds trained in deterrence as the primary response to threats from rational entities would think first to build the capability to retaliate and second the capability to defend.
I'm not really sure how far the comparison between physical military threat and cyber threat really carries, though.
And yet, the title is "U.S. Decides to Retaliate Against China’s Hacking" - this is quite sensationalistic.
You don't see other nations who engage in adversarial ways against the US broadcasting their intentions in public theatre.
If the US and obama administration really wanted to demonstrate power and deter china from cyber attacks, they wouldn't go chatting about all the things they're going to do. They would go do it and it would be heard of after the fact.
Has the concept of the element of surprise been forgotten?
"One of the conclusions we’ve reached is that we need to be a bit more public about our responses, and one reason is deterrence," said one senior administration official involved in the debate
This sentiment should probably be read as "so as not to appear impotent to the citizens at home" instead.This is meant as a last warning for China, and everyone else, that the US is going to begin aggressively attacking in response, instead of mostly just taking it. I don't think anybody is going to like what's going to come of it. Picture the US military, with its $600 billion budget, treating all global digital infrastructure as its new battlefield.
They would also have to disrupt the world reputation of China - not just its domestic one.
And be rest assured the US already does and attempts to do this.
No positive news of China gets upvoted in America though, because we are burned that they are winning the trade war.
You have to kind of salute Clapper for what he did, committing perjury and then keeping his job
sounds like a typical BigCo's PM argument when waiving security bugs.
“This is one of those cases where you have to ask, ‘Does
the size of the operation change the nature of it?’ ” one
senior intelligence official said. “Clearly, it does.”
But of course, that doesn't apply to NSA's bulk data collection, right?Apparently the meetings weren't really all _that_ classified.
Sadly, it has come to a point I don't know what to believe anymore. Whoever released the story has an agenda. Does the agenda in any way mirror factual reality? Beats me.
I'm a westerner. I support the west. My lively hood depends on it. So if they say we've always been at war with Eastasia I guess I don't know enough to say differently.
Looking around at bureaucratic politic filled government agencies and big companies I don't see real protective measure being taken any time soon. The leadership of those places has been filling up for years with ass covers and bullcrappers, and a turn around towards effectiveness isn't going to happen any time soon. So maybe send some drones or something. Oh wait... we can't do that, because those are all reserved for poor Muslims who can't really fight back at any scale. So I don't know. I guess puffing around and taking the lumps is about the only option for now.
I wouldn't count on China coming out on top at that point.
But more than likely it will stay just short of that and be like a fly that is just annoying enough not to walk inside for the flyswatter. Incidentally, what would China want with personal records of US government employees? Is it going to send them all spam or order stuff on Amazon using their bank accounts or something?
- Power grids
- bank accounts
- internet
- water/sewer control
- traffic control
like, it could be really, really bad.
Secondly, it is dangerous to suppress cyber attacks via negotiations, appeals and threats (as opposed to technological means) because then we'll be in the dark as to their capabilities and our exposures, and in the event of an actual war we'll be unprepared and they will cripple us easily.
Instead, we should do what companies such as Google and recently United Airlines have done: reward hackers who find vulnerabilities. Then disarm the opponent by fixing our vulnerabilities as quickly as possible.
China's growth has been trending down for a decade plus. The fundamentals of their economy continue to get worse by the year. Keeping that picture in mind, their stock market lifted off to insane heights, in a matter of months, for absolutely no good reason other than a flood of margin that was encouraged by the State.
China's stock market crashed because it went up drastically for reasons that were never going to be able to support the new levels (ie not due to growth or general improvement in economic fundamentals).
The US has also not been crashing their real estate market the past year. That too is a mess of their own making.
Someone tell me what use China has for "personal information" of Americans from the Office of Personnel Management.
Seriously. What do the records contain and what is it to China? Wouldn't China be more interested in the "personal information" of their own peons?
> But in a series of classified meetings, officials have struggled to choose among options that range from largely symbolic responses — for example, diplomatic protests or the ouster of known Chinese agents in the United States
So how classified were the meetings if you know what they talked about?
> In public, Mr. Obama has said almost nothing, and officials are under strict instructions to avoid naming China as the source of the attack.
.. But it's alright for the New York Times to declare to the world that China is being naughty?
> unless the United States finds a way to respond to the attacks, they are bound to escalate
Yeah, pretty soon the Chinese government will be hacking PayPal for Americans' credit card numbers! You know, for extra revenue and all.
> In the Sony attack, the theft of emails was secondary to the destruction of much of the company’s computer systems, part of an effort to intimidate the studio to keep it from releasing a comedy that portrayed the assassination of Kim Jong-un, the North Korean leader.
Why the hell would the Chinese government give a flying fuck about a comedy about Kim Kong-Un? Let alone to the extent of "destroying Sony's computer systems", whatever that's supposed to mean? How do you destroy computers by hacking them remotely?
> The Justice Department is exploring legal action against Chinese individuals and organizations believed responsible for the personnel office theft
So assuming these people were working for the Chinese government, the US would have to extradite/kidnap them from China to get them convicted. How's that for "escalation"?
If kidnapping isn't in the plans, why would they "explore" legal action, knowing it would be a waste of time? Why would they publicize their plans for legal action? Do they just want to make themselves look stupid?
In reality, this article is just Cold War 2.0 propaganda. Who knows if any hacking even happened? It makes no sense for China to hack Sony over a movie, so why wouldn't this be bullshit too?
Russia and China are Bad, mmm'kay?
> Seriously. What do the records contain and what is it to China? Wouldn't China be more interested in the "personal information" of their own peons?
From what I've read, these files can potentially contain very sensitive information. As part of the background check for some government positions, many dark secrets are unearthed and documented. Why? So that the government has a heads-up on how its employees may be compromised by foreign adversaries. So if the Chinese had such files on 20 million people, they would have a treasure trove of information to use as leverage against US citizens.
> Why the hell would the Chinese government give a flying fuck about a comedy about Kim Kong-Un?
They don't, and the article never implies that they did. "Admiral Rogers made clear in a public presentation to the meeting of the Aspen Security Forum last week that he had advised President Obama to strike back against North Korea for the earlier attack on Sony Pictures Entertainment. Since then, evidence that hackers associated with the Chinese government were responsible for the Office of Personnel Management theft has been gathered by personnel under Admiral Rogers’s command, officials said." The DPRK is associated with the Sony hack, and PRC with the OPM one.
> So assuming these people were working for the Chinese government, the US would have to extradite/kidnap them from China to get them convicted. How's that for "escalation"?
"Legal action" could be sanctions, warrants, etc. Why do you jump to kidnapping so suddenly? (Not that I would put it past this government...)
> In reality, this article is just Cold War 2.0 propaganda.
Of course, it's in the NYT!
NSA comes to mind...
We will look on in horror as the tools we built are used against us.