HNHacker News
TopNewBestAskShowJobs

opt-skept

16 karma · joined December 13, 2023

submissionscomments
opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Sorry in advance for the verbosity, but I really feel like we're crossing paths.

The US doesn't want to start a war with China. The US wants to prevent China's rise. It wants to do this as cheaply and as efficiently as possible, and if it could do it by a cheap cyberop/magic-wand/whathaveyou it would. However it has coarse tools to affect this and no easy, cheap answers. And its willing to do it expensive ways (war) if need be.

It therefore has an array of economic, diplomatic, military, and intelligence tracks attempting to prevent China's rise and raise its costs in a myriad of ways. These all create instability and risk war.

The US is, in its attempt to prevent the rise of China, and China in its attempt to continue to grow in power, in a Thucydides Trap - where conflict between them grows. China - in its role is attempting to grow does so by attempting to minimize the amount of tension and risk of conflict with the United States. Because strategically, that's its win condition. It grows.

The US on the other hand, is attempting to increase as much tension and conflict as it can with China, in order to problematize its rise. This may lead to a war (the "trap" in Thucydides Trap), but it is not inevitable.

The examples are plentiful (and as you've discovered I'm verbose) so probe and we can get into that.

I'll just repeat one example from earlier. Before the US was attempting to prevent China's rise, it's policy with regard to Taiwan was to prevent Taiwan from declaring independence and prevent mainland from attempting to annex. This was to create stability and maintain the status quo. It did this by being ambigious about what it would do in such a scenario. This was the policy for ~50 years and it was successful at stabilizing the region.

Once the US's policy became preventing China's rise, it's policy toward Taiwan has been to claim that it will defend Taiwan. The reason for this policy is to encourage Taiwan to declare independence, and to make China worry about this possibility, and encouraging it to attempt to act before it becomes too late. The US is succeeding in this policy of destabilizing the region.

This amounts to agitating for a war. That is not the same thing as wanting to start a war (e.g. "for wars own sake").

I wonder what you agree with, disagree with about this.

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Today I learned "gish galloping". No, I am a wordy person and I apologize for that. I think you'll find it isn't an excessive amount of arguments, but an excessive amount of detail to a very straightforward argument. At least that is my hope.

> Basically, you think that the US is forging alliances in the Indo-Pacific because really it wants an excuse to go to war with China and crush it. In reality, the US is using its military, specifically it’s deterrence capability as a bargaining chip in alliances with countries who are fed up with China.

Yes in broad strokes. I'm trying to not add nuance now.

However I would disagree with the "countries that are fed up with China" - that's a very American narrative but based on polls and looking from the region, these countries are mostly looking for whoever will give them the best bargain and play both sides.

> Yes, it wants to counter China’s rise

Right, I'm glad we agree on that.

> but it’s doing that through diplomacy.

I don't see this as very possible in any case. What country could convince through diplomacy another country to e.g. stop growing its economy? Are there any such examples?

Do you have any examples of diplomatic missions or examples you think show the US as having done this?

Anyhow, I'm glad we started out with my doing mental gymnastics, but now we agree that the US wants to prevent China's rise and that China is trying to avoid military conflict with the US. None of this is super crazy / convoluted.

Regards for sticking with my verboseness.

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Okay, so for (b) we agree that China does not want to agitate a war with the US; that it would like to avoid it.

For (a) you do not have an area of critique where you believe any chain of logic presented earlier in the thread in unsound. Instead for (a) you have an alternative theory that you would advance.

The reason I thought you had some critique of soundness in (a) is that you had commented earlier you thought there was wild mental gymnastics, which would imply that you thought there was some unsound/crazy/wild leaps of thought.

This I think leaves us to discuss (a). Your proposed alternative theory agrees on the premise that the US would be the one choosing to engage military with China - that China would not choose to attack the United States. The key difference in your theory is that the United States "begrudgingly" would be obligated to engage militarily with China such as due to a legal commitment. This is opposed to the characterization that I advanced, which is that the United States is "leaning into" reasons to engage militarily with China.

I can explain why I do not think that the US would "begrudgingly feel obligated" and instead is "leaning into reasons". This is quite simple (I will spare spilled ink).

The US established in 2009 that China was its primary rival (in 2009 the Obama Administration announces the "Pivot to Asia", which Wikipedia describes as "represented a significant shift in the foreign policy of the United States ... invest heavily and build relationships in [Asia] ... to counter [China's] rise as a rival superpower"). https://en.wikipedia.org/wiki/East_Asian_foreign_policy_of_t...

Since that time the reasons for a potential US conflict with China have kept changing. Once it was because of "unfair trade practices". It became for a while "Uighurs". "Tibet". "Defense of India". "South China Sea". "Taiwan". The constant over time is the explicitly and carefully articulated reason given by the US government itself that it needs to counter China as a rising superpower. The areas of conflict have been, are, and will continue to be, subject to change.

The US had almost certainly has no legal obligation to intervene on part of its "allies" (the Philippines only unless you have other legal allies in mind?) nor does it have any obligation to intervene for Taiwan. From a legal perspective again the Mutual Defense Treaty with the Philippines (who I assume you refer to by "allies") was effectively dead (with US bases, soldiers, exiting the region by early 1990s). It was only in 2021 (!) long long after the US identified the need to confront China that the US renewed this treaty (after the Philippines suggest it be scrapped). Neither the Philippine's specious claims to the Spratly Islands the a BRP Sierra Madre scenario would obligate a US intervention.

I would add that the US even insisted on intervening on behalf of the Philippines even when the Philippines itself rejected the United States and called for it to not engage in the area. This is how desperate the US has been to try to engineer something here. (The new Philippine administration has been easier for the US to work with).

Indeed the United States has been accelerating its efforts to grow treaties, obligations, and military basing in China's near abroad. From the Compacts of Free Association to the Nuclear "AUKUS" to the Quad, to its quite scandalous attempt at the Trans Pacific Partnership, the US's foreign policy has attempted to constrain the growth of China and attempted to engineer plausible scenarios in which it might escalate tensions with China into a victory.

China's interest in the South China Sea? To prevent an existential economic blow severing its ability to trade, a la the blockade that occurred during the Anglo-Chinese War. (Interestingly, and an aside only, Taiwan agrees with the Republic of China on Qing and earlier Chinese historical rights to the area).

Regarding such a confrontation? What would a war scenario look like? It would involve much more than the defense of the Sierra Madre or the defense of the Taiwan strait. The US military's footprint and conflict plan escalation from where-ever a conflict may arise to a blockade and strikes into China, even if it is not operationally called for (to defend a littoral, or whatever).

The US and Taiwan? The US's policy since the inception of relations with the island (despite being legally obligated to recognize Taiwan as part of the Republic of China) has been "strategic ambiguity" - to be purposefully vague about whether it will come to the defense of the island in order to discourage the status quo from changing.

The US, only after identifying its grand strategic need to prevent the rise of its superpower rival, has changed this policy, explicitly stating the US will defend Taiwan (again, no legal obligation) to encourage it to declare independence (again - despite US legal recognition).

US President Trump - China hawk of China hawks - first action as president was to call the leadership in Taiwan, a protocol breaking and intentionally provocative move intended to signal the US's intention to rock the boat and agitate for conflict with China.

I submit to you the "Pivot to Asia". The US first identified the need to confront a rising China as a rising superpower competitor more than a decade ago, and has since found various potential plausible means by which a conflict might occur and the US might escalate to situation in which China's potential is diminished.

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
The Belfare Center for Science and International Affairs has a nice report (https://www.belfercenter.org/thucydides-trap/case-file) indicating this is a good predictor for conflict (and lists examples that you can use).

Although, I'll definitely agree with you that all points in history are unique. Thucydides Trap shouldn't be understood as predicting the future using the past (that's absurd by definition). That would be a reductio ad absurdum, but it isn't what foreign policy scholars are actually arguing here.

Instead, it's a description of set of incentives that shape the relationship. What the individuals in power choose to do with those pressures/incentives on the relationship is absolutely a different question. The point the "foreign policy elite" in the United States are making is that it has strong incentives to agitate for a fight with China, before it becomes an competitor (as opposed to a "near peer competitor" or "pacing challenge" - the current language).

I suppose its worth clarifying. Do you deny that there are such structural elements of the Sino-American relationship? Or is your argument wrt Thucydides Trap that it isn't deterministic? Or something else?

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
While I disagree with this on its own merit, its important to point out this does not address the question/topic.

Asked above was: (a) What steps of reasoning do you think are unsound? (b) What reasons do you believe that China has to agitate a conflict with the US?

You answered (c) here is how China could avoid a conflict with the US

I'm sure you have questions about why this is disagreeable. But could we first resolve the open questions (a) and (b)?

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Thank you for the thoughtful response and for sharing your opinion.

About the standard you propose. It's interesting, but there might be some issues with it. I am writing this not to change your opinion but to expand on the idea with you.

> Single-party != democracy

The concept of parties being associated with democracy is somewhat new or "hyper-local" I think. In the West we often trace democracy to ancient Athens, crediting them with inventing democracy (although I'm sure historians would debate). From Wikipedia: a party system in ancient Athens did not exist, but voting for representation did (https://en.wikipedia.org/wiki/Athenian_democracy#:~:text=Tho....). This immediately disassociates the idea of democracy with the idea of parties. Parties are one way to organize coalitions of shared interest. Whereas democracy is a way for citizens to register their interests so that a government may address those interests.

As you suggested there are a wide range of different ways to organize democracy (parliament vs congress, representative vs direct, ...). There is in fact a Wikipedia article on different types of democracy: https://en.wikipedia.org/wiki/Types_of_democracy . An interesting thing I learned reading this is most of 1700s Britain was a one-party (Whig) system and by this standard would not have been considered by your proposed standard.

> If there is no democracy, then there can be no "president."

Again here's something I found on Wikipedia. The history and meaning of the word president means "presides over" rather than it meaning anything in particular in association with democracy. Its first recorded uses were in Aramaic and in the Bible. Today's common usage today means "head of state, usually of a republic", but has no common meaning associated with democracy as a form of government.

https://en.wikipedia.org/wiki/President_(government_title)#:....

> If you need a neutral term for that, maybe demote to a "leader."

I would just like to offer that if president means "presides over" and leader means "leads", someone else could have a similar objection you have to the use of "president" to the proposal to use "leader" - i.e. that we should not use it for persons who lead governments we don't consider to be "true democracies" because it shows some kind of respect or legitimacy.

> If a "leader" has murdered all of his opponents, then we should go with something actively derogatory. Not only should no respect be given, but the title should be extremely negative.

I suppose the idea here is that using a title that describes their role "quarterback Bob", "person who presides over, president, El-Sisi" gives some respect for their having that role, and we shouldn't give them that respect even if its technically accurate to describe them as the role they have. And if we think they've done something heinous we should give them a title that is heinous to disrespect them. "Smelly Bob", "Dipshit El-Sisi".

Here I think its fine for politicians, whose role is swaying public opinion and rousing people, to show disrespect or to not show respect. But I worry about setting standards for journalists because restricting them from accurately describing the roles of persons could undermine their job of communicating context and information, and it suggests that a journalist's role is to disrespect or respect persons, rather than focusing on being as accurate and informative as possible. I worry about the quality of information available in the US (where I live), and so I would worry this could further deteriorate what I perceive to be vulnerable.

In fact, I'll go further and say that I don't like it when journalists/editors go about trying to tell me what to think about a topic. I prefer that they law out a clear, accurate, precise and reproducible set of facts, observations and analysis - from which I can draw my own conclusions. Said another way, I like facts changing people's minds, rather than opinions changing people's minds, at least whenever we can afford it.

In terms of how often such a proposal could actually be used? I think there'd be some subjectivity in this, a "no true scotsman" type argument that would come up if the proposal were taken serious and made a standard (https://en.wikipedia.org/wiki/No_true_Scotsman)

For example, take Vladimir Putin. One could try to argue that he's murdered all of his opponents. On the other hand this man was part of 5 presidential elections. In 2000 he faced 10 opponents. In 2004 he faced 5 opponents. In 2012 he faced 4 opponents. In 2018 he faced 7 opponents. In 2024 he faced 3 opponents. If one researches these opponents they were serious contenders for election (for a multi-party system).

The point is that I think some persons, using your proposal, would wish to apply it to an adversary of the United States, because disrespecting an adversary is a popular thing to do. Others would choose not to, instead making a judgement call that 29 serious non-murdered opponents qualifies him as president or leader.

And if we get to that case, were baseline is actually a judgement call instead of an objective editorial policy, I think the standard becomes more of a signal of a journalist's opinion or the outlet's editor than it is communicating to the audience some consistent message. And we're a little bit back in the boat we are already in (without a real baseline established).

Therefore overall I think the proposal might be benefitted by a rethink, as there are multiple ways in which it might not achieve the objectives it may be inspired by?

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
I'm a bit confused about the question and how this relates to the topic.

I don't know how many journalists are lurking non-front page HN stories, so you'll probably get a non-journalist answer to the question (if anyone ventures, I'll try).

I think you may be trying to ask a question about structuralist/realist theories of international relations, vs constructivist theories of international relations. Basically "sure there's some structuralist arguments, re: Thucydides, that the US should be expected to agitate for conflict, but what about democracy vs non-democracy - can't that better or equally explain sources of conflict?"

If that's what you mean you could look at the many places in the world where authoritarianism is recognized, accepted, even partnered with the United States (Egypt, Saudi Arabia, UAE, Qatar, Pakistan, Uzbekistan, Bahrain, ...). In these cases you'll find the US partners with these allies, emboldens and arms them, due to shared structural/realist interests.

As far as the naming of people's titles around the world. I very often read glib/vitriolic denigrations of the specific people you've mentioned in US press. These articles tend to be intended more for domestic catharsis/rallying than it is to be accurate/analytical, although sometimes the articles are very good and I assume the editors make those changes based on guidelines/policy.

To learn more about governments around the world I would point to the CIA World Fact Book, which uses a taxonomic approach to classifying various systems. The CIA considers Russia to be a "semi-presidential federation" and indeed Putin is elected and extremely popular. (https://www.cia.gov/the-world-factbook/countries/russia/#gov...). The CIA considers China to be a "communist party-led state" and indeed Jinping is the factually elected president of the single communist party. (https://www.cia.gov/the-world-factbook/countries/china/#gove...).

Learning more about other leaders in these countries - their parliaments, their ministries, their election processes, their legislation drafting processes, etc - can help to abate some of the instincts to assume that political systems, because they aren't understood, are hostage/authoritarian situations. A good exercise is to learn at least ten other important officials from a given country and their roles for leading that country. I think trying this exercise yourself could help you answer your question above.

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Could you add some more information about what steps of reasoning you find unsound, or what reasons you believe China would have to agitate for a conflict?

The "Thucydides Trap" and its application to Sino-American conflict is not something that I've made up or is a personal opinion. I've merely captured what US defense and security analyst perspective here for those wanting more context on the article. Namely China wants to avoid conflict because it is the weaker power, and the US wants to create conflict now while China is a weaker power, to prevent China from becoming a stronger competitor in the future.

There are certainly some US security analysts who argue against the "Thucydides Trap" being the right framework to analyze Sino-American relations. However most of those criticisms are just pointing out that conflict isn't inevitable - that there's nuance. For example the US might become distracted with other priorities (domestic political issues, for example), and never initiate a conflict. Or perhaps China will see a slow down in the growth of its own power, and the US will no longer perceive it as a threat (much the same happened with Japan in the 90's, when Japan was considered a top security threat).

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
> Just to be clear, what are we talking about here exactly?

An ostensible war would be to set back China's growth and its trajectory of growth. The US has little interest in governing such a large country.

opt-skept··on FBI says Chinese hackers preparing to attack US infrastructure
Note, this isn't going to be a surprise attack. China is developing access to hold the infrastructure at risk as a retaliation/deterrent for an American attack on China.

It is highly likely that the US has achieved similar levels of penetration into Chinese critical infrastructure for its own use in conflict contingency.

The actual deterrent effect of this is unlikely to, on its own, prevent the US from agitating a war on or within China. War is not inevitable, just structurally likely, due to the so called "Thucydides Trap." China's rise in economic and military power in an of itself critically endangers US security interests of being uncontested dominant power.

opt-skept··on [dead]
Is it "largely" for filtering search results that civilians will have easy access to, in line with IDF narratives and perspectives (?)
opt-skept··on French company ramps up production to meet demand for its military drone radar
This has a range of 400+km (100kmph = 4 hours to respond).

It's purpose to maintain an accurate picture of the sky, tracking many objects at the same time at different altitudes. The radar itself is just part of the picture - its data is integrated with command and control, where decisions are made about the picture coming in, and the data is blended with other sources to get a more accurate picture (not sure if bird or drone? check the video feed data, or a number of other sources).

The unit itself looks at the behavior of the object (speed, acceleration, routes, elevation, radar profile) to determine the likely class of the object (birds don't fly like drones nor do they have the same radar profile).

As far as mitigating threats, command and control again makes those decisions. It depends on the context of the fight and the resources available. In the hypothetical situation you think a kamikaze drone is headed your direction, the radars are mobile - one option is to simply move. You may know (or have a good guess) as to the specific threat - how it is controlled. You might take out drone communications with EW. You might misguide a precision munition by spoofing GLOSNAS/GPS so that it drifts and misses its target. If it is flying at a low elevation, you might be able to take it out with heavy machine gun fire. You might decide to let it strike, due to cost-benefit ratio.

It really gets down to specifics: What's the air asset? What the threat? What's the mission? What's the battle context? What are the resources?

Regarding a drone having zero command & control due to AI - most of the "AI" in drones is simple straight line flying for a couple hundred meters (so called "terminal flight guidance"). This is because enemy electronic warfare cover may jam communications channels for the drone as it approaches closer to a target. As cool as it sounds to have fully autonomous drones making complex decisions, piloting around obstacles in all weather conditions in 3D space, tracking moving targets, etc - this isn't the threat from drones right now.

opt-skept··on How Johnny can persuade LLMs to jailbreak them
In my opinion we're protecting from LLM generated content all wrong.

A modest proposal:

(a) Put LLMs in the defensive role, give them the social media posts (for example) and let them determine whether to show the content

(b) Give the sliders/parameters to the user. If they don't want to see content that encourages harm to children (or whatever), have them turn on that slider/toggle

(c) Have the major platforms allow plugins to the content filtration controlled by the client side, so that users can subscribe to "Trusted Entities" to filter what they want. That can be a government, NGO, or a FOSS project, or whatever

(d) Have the major platforms open up _default_ parameterization and plugins to governments

This achieves the following:

(a) It encourages LLM technology rather than neutering it

(b) It gives the users the ability to control what they see online and not. It extends on existing parental control systems, so that parents can control what their children see until they become old enough to manage this themselves

(c) It gives persons the ability to outsource their filtration, either as a service or otherwise, to those they trust, however it gives them the ability to change this over time as their preferences change

(d) It gives governments the ability to set up their desired policies in a way that is reflected by the platforms at the same time it drives transparency about what these policies are because they are user facing

The biggest benefit is that its practical.

Objections that "in this proposal a person can get content that I/government doesn't want them to have" don't hold, because the same is true of all alternative proposals.

It's a proposal that works even when someone creates a "non-compliant" LLM that doesn't censor prompt output. Such systems already exist and will always exist, and already defeat the current strategy - which is "make existing LLMs less capable".

opt-skept··on Cybersecurity Isn't Special
I disagree. I think inspecting the output from Qualys (and other tools, including SAST) are substantially and manifestly different from inspecting Kubernetes logs.

I would worry the argument about "highly skilled SREs" could become a "true Scotsman" argument. If a business has any persons who are skilled enough and plentiful enough to process all of the security output and take action on them, let it be so.

My experience is that in practice, there are not the resources to process all of the output that the tools generate. Do you have experience to the contrary where this has been done at a company scale or is your argument a theoretical one that you believe stands to reason?

opt-skept··on Cybersecurity Isn't Special
Eh... maybe.

I think "configuring SAST" goes back to what you had previously said about "tool monkeys". Now there's thousands of potential issues. Many are false positives. Who is going to tune that SAST for accuracy rate? What about vulnerabilities that are framework specific? Will the SAST even allow for this? Who is responsible for triaging all of these alerts? Are they capable of correctly addressing them?

If you just set up SAST and walk away, you end up with more noise than you do signal. And you created the need for security professionals to process the results.

I think the article had better suggestions for scalable security, for example #3 Build standardized patterns and #7 Provide isolation patterns. Better to systematically prevent SQLi with a platform/library than try to detect all variations of SQLi with SAST!

WAF? It's something I would put in front of a product I have confidence in as a defense-in-depth. But would I rely on it as the sole security investment? Absolutely not. The reason is not all vulnerabilities are web-based, and many do not have differentially detectable payloads (missing authz on an API isn't going to get caught by WAF).

Why Red Team? Because the leading way businesses get compromises is with phishing attacks.

A security team needs to ensure application security, network security AND operation security. A SAST or WAF aren't going to do that. Neither with Qualys, etc.

opt-skept··on Cybersecurity Isn't Special
As part of the industry, I can tell you I've personally found dozens (hundreds?) of vulnerabilities per year for the more than decade running of my career. The same is true of my collegues.

I have met "cybersecurity teams" who are "tool monkeys" in the way you suggest. Usually these individuals are part of an extended compliance team. They are trying to check compliance boxes by having some level of automated scanning, because their parent organization/team can't/won't staff professionals capable of this or capable of scaling it or focusing attention on where it matters.

I don't want to oust you for where you work or your role within those companies - but really surprised to hear that there's no inhouse pentesting and no in house red teaming. I haven't worked at a company yet (on my fourth) that matches the experience you described.

opt-skept··on Cybersecurity Isn't Special
I'm on two sides about this article.

The first side is that ultimately the argument that the author debunks is a strawman argument, and the counter-arguments are equally sophomoric.

The second side is that I agree with the author on (some) of the recommendations and I think its great that the author made recommendations, instead of just pointing out perceived problems.

Cybersecurity isn't special. At least not any more special than any other subfield is in its own way. But the rest of the article doesn't follow from this axiomatic position. In fact, it's irrelevant to the meat of the article (the recommendations), and comes across to me as griping.

I think the article misses some of the realities of the business environment.

Why do (some) security teams (sometimes) try to put in roadblocks to software releases? Usually it is because the the release is going to have a business impact for which: (a) the business has not acknowledged (b) no person is accountable for (c) there are no plans for.

Why do security teams feel they must dictate outcomes rather than recommend? Usually because their leaders (running up the the Board or Executives) are holding the security team accountable for outcomes they have only indirect control over. Another common reason is that the incentive structures of various organizations push for development groups to release as quickly as possible, feature release estimates rarely include security work estimates, and teams/managers feel pressure to release anyway to avoid delaying due to missed work estimation at the project start.

Usually, these kinds of issues represent the failings of other structural aspects of the business.

Ideally security teams wouldn't be needed at all, the same as SREs and many other kinds of roles. Ostensibly developers would be so capable, so knowledgeable, so well rounded, so careful, that they would plan for, mitigate and manage all operational risks on their own.

There's depths to explore on this topic. I'm excited for the article author that they are just starting to get introduced to it. I hope they continue to explore this as they develop more seniority and experience, and share in more detailed public posts as they go along.