8 ms·
Chinese Hackers Breach U.S. Navy Contractors
- tivert 8y agoPaywall workaround: http://archive.is/KMi5Y http://archive.is/KMi5Y
- syspec 8y ago> The victims have included large contractors as well as small ones, some of which are seen as lacking the resources to invest in securing their networks. That does not compute. If they want to become a defense contractor, it stands to reason not spending resources on securing their network (and educating their employees against phishing attacks) is a non-starter.
- kasey_junk 8y agoWhy? You can be a “defense contractor” as a one person show out of your garage. The requirements for selling a toilet to the navy were written at a time when these issues didn’t exist. That the biggest bureaucracy on earth doesn’t respond well to new threats seems ecpected not odd.
- rhodysurf 8y agoExactly. Legit anyone can bid on these contracts and the DOD is finally starting to crack down on “Confidential Unclassified Information” and the contractors that handle that data. It’s wild how many small companies have no security infrastructure
- paulie_a 8y agoAre you serious? It should be pragmatic and taken seriously, but it isn't. As for phishing attacks, try it three times in a row and, if I recall correctly you get results of 50 percent success.
- metacritic12 8y agoIs this a surprise? I imagine many powerful countries' cyberespionage groups are going after the other side.
- golem14 8y agoA slightly different headline would be "Navy has lousy security practices especially regarding contractors" I'm pretty sure the CIA and NSA do their utmost to spy as much as they can on the Chinese and Russian Navy.
- everdrive 8y agoExcellent job moralizing, comrade.
- vkou 8y agoWhat exactly is immoral about spying on a foreign nation state? We do it to them, they do it to us, what exactly is the issue? Is there some no-spying gentleman's agreement that's being violated, here?
- code_duck 8y agoThe notable news is not that they’re trying to do it. The news is that they are succeeding, and what’s worth noting is that our defenses are so weak.
- psychedictic 8y ago@snowden sold us out to china when he fled in 2013, by revealing details about our spying operation on them. apparently they bolstered their defenses after this, due to this information, meanwhile stepping up offensive attacks against the United States
- rhegart 8y agoAccording to the NYTimes they also killed over a 100 CIA assets in China. So we went in the dark for a while as the whole batch was compromised. We didn’t retaliate either. The Snowden thing wasn’t the cause of that but I bet the Snowden thing compromised other assets.
- 8y ago
- curt15 8y agoDo procurement contracts have clauses that discount the purchase price when proprietary information is lost to reflect the diminished value of the product?
- fermienrico 8y agoThis is an excellent question. I can imagine the difficulty of such clause would be to quantify the value that was diminished due to a breach in financial terms. Most likely the case is that the government has a vested interest in keeping tight security over their program - from engineering to manufacturing and small suppliers rely on security engagement from the gov. Big suppliers such as General Dynamics and Northrop Grumman, I am sure security breaches are taken very seriously and it would impact future supplier selection process and bidding.
- dx87 8y agoI wouldn't be suprised. I've done some unclassified govt contracting and it wasn't uncommon for them to include clauses in software purchase contracts that they had to be re-imbursed a certain amount of money any time a security vulnerability was discovered in the purchased software. The reasoning was that they had to spend money identifying, reporting, and updating systems, so the vendor had to pay for wasted resources.
- drblast 8y agoNot surprising at all. What's surprising is that it's taken this long to appear in the news. While in the shipyards for maintenance I would stand watch and was responsible for letting people on/off a large ship. Most were contractors. The only requirement was that they had a contractor badge. How did we tell this was a valid badge? Good question. You'd think there would be some sort of master list of people with badges we could check and verify. Not quite. Every contractor had their own style of badge and we had no way of knowing if any particular badge was real or not. Want a "valid" badge? Buy a badge printer. You're in. We had people we didn't even know just show up to install systems on board that nobody was able to verify were supposed to be there or not. It was a little better with the classified systems, but you can imagine that any verification of contractor IT systems was non-existent.
- WrtCdEvrydy 8y agoI can't believe it, but I also can believe it - Me, ever since doing CyberSec 2 years ago.
- azinman2 8y agoAt what point will the gov actually do something meaningful here? I know security is hard, but so is putting a man on the moon. This is insane the amount of hacks without consequences.
- killjoywashere 8y agoA non-trivial bit of the problem is the highly fashionable attitude of refusing to do work that helps the Department of Defense. The fact that skilled labor is a limited resource for both nations, which means refusing to help is at least similar to aiding foreign powers, which are statistically dictatorships of one kind or another, seems to not factor into the set of moral ethoses that such folks espouse. Remember, it's not just China. It's North Korea, Russia, Iran, Isreal; any country facing significant military threats is interested in US weapons technology. You live in a constitutional democracy on a planet where the mean, median, and mode country is a dictatorship? And don't want to defend that government? Really?
- thenanyu 8y agoI would happily do this work if it was accessible and lucrative. I think plenty of SV nerds would. I don't doubt that there is a significant contingent that are politically opposed like you describe, but I don't think the compensation can match what is being offered these days for talent.
- RhodesianHunter 8y agoExactly what I was going to say. I have no moral issues with (most) code related DOD work, but it just doesn't pay comparably.
- ryanmarsh 8y agoIt is accessible and quite lucrative. My biggest customer was the US Navy. We did great things.
- icanhazcoins 8y agoAdditionally, I find it intellectually lazy to believe that assisting the military is morally wrong. What I think people (and in particular Americans) fail to consider is that if you really do feel that the political system is so corrupted that the will of the people has been subverted, what that actually morally requires you to do is to overthrow it. You cannot say "Oh well I didn't vote for the guy who started the war so I guess I'm ok". You are responsible for everything that happens and is happening, and if you really believe that the system is so badly broken that we are involved in illegitimate wars then you need to take responsibility for that and stop it. Stop paying your taxes, organize your community against it. Be willing to sacrifice to make it happen. By not doing this, you are disregarding the sacrifice that so many people make in support of the system (members of the military, administrators, etc). It's reprehensible to disregard the sacrifices of others so callously yet be willing to sacrifice nothing yourself.
- resters 8y agoHackers breaching US Navy contractors tells us one important thing: That the US Navy is not doing adequate due diligence on the firms it allow to be contractors. This story is part of the campaign to present China as an unethical, capable adversary and threat. In reality, China wants to trade peacefully with the US and the aggression is nearly 100% on the US side and is meant to garner all the benefits of threat-oriented chest pounding for US politicians. The #1 rule of being a citizen should be "don't let them tell you who to fear or who to hate". Sadly, the NYT, Bloomberg, and the WSJ are all telling us to hate and fear China, when it's obvious that the US has domestic political motives in mind. In the US, leaders need an enemy or the conversation might turn to things like "why do we have poisonous drinking water?" or "Why has there been a trend of downward mobility?" or "Why didn't anyone get punished for Snowden's revelations or for the lies that led to the Iraq war?"
- deleted 8y ago[deleted]
- mindslight 8y ago> In reality, China wants to trade peacefully with the US and the aggression is nearly 100% on the US side You don't need to make this claim to support the rest of your point. I agree with the gist of your comment but think this point makes it easier to attack the overall message. Personally, I think China is trading with the goal of jump starting their economy, and then seeing where they end up. China's incentives aren't to act within our paradigm of free trade, but to attempt to operate on it. If free trade is truly a Schelling point, then we'll remain there. Otherwise at the end of the day, holding currency or title to imaginary property won't matter, but where the factories are located will. But that isn't really relevant to the larger point that all this finger pointing at China (or Russia, depending on the month) is just basic scapegoating to cover the asses of negligent contractors and corrupt government.
- resters 8y ago> You don't need to make this claim to support the rest of your point. True
- deleted 8y ago