17 ms·
As China Hacked, U.S. Businesses Turned a Blind Eye
- systematical 7y agoJust disgusting
- dang 7y agoMaybe so, but please don't post unsubstantive comments here.
- aristophenes 7y agoThe government sponsored professional hacking team that was mentioned in the article was the focus of the infamous APT1 report by Mandiant (now FireEye), with investigations from 2006 and later: https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf https://www.fireeye.com/content/dam/fireeye-www/services/pdf... There have been many APT groups named and tracked since then, not just in China.
- tgragnato 7y agoOh, memento. Those events fit the climate described in the article. > Intrusion Truth's controversial approach of anonymously unmasking government-backed hackers and exposing a foreign intelligence agency is something new and seen as a method to put pressure on Chinese companies cooperating with state-sponsored hacking efforts. https://www.zerohedge.com/news/2018-10-04/intrusion-truth-mysterious-group-doxing-chinas-hacking-army https://www.zerohedge.com/news/2018-10-04/intrusion-truth-my... - https://motherboard.vice.com/en_us/article/wjka84/intrusion-truth-group-doxing-hackers-chinese-intelligence https://motherboard.vice.com/en_us/article/wjka84/intrusion-... - https://twitter.com/intrusion_truth https://twitter.com/intrusion_truth - https://intrusiontruth.wordpress.com https://intrusiontruth.wordpress.com
- dmix 7y agoAlso even naming the group APT which was a corporate buzzword at the time (for advanced persistent threat aka anything above script kiddies and aimless bots).
- applecrazy 7y agoAPT still kinda is a buzzword. It appears in my Cisco cybersecurity courses all the time.
- Spooky23 7y agoAPT is anything that happens to you.
- sonnyblarney 7y ago"When I pressed them on why they were not taking stronger action against China, their response was, 'We have a multifaceted relationship with China.' " And this is it: don't want to upset the promise future sales. And this is how 'dividing and conquering' works. One side speaks with 'one voice', the other with 'thousands of little voices' - and it's game.
- creato 7y agoAnd the one company highlighted in the article as speaking out is on the verge of being broken up by Western governments. The western world is being played like a fiddle. Negotiating power is everything, and western democracies and their private and corporate citizens have absolutely none compared to autocratic regimes.
- njepa 7y agoThe whole idea behind the western world at the moment is to have as little in common as possible. No government, no taxes and especially no regulation is the dream. So why would the average citizen care?
- math_and_stuff 7y agoThat one company has also completely reversed its stance over the last year and now openly defends censoring human rights and complying with the CCP's surveillance demands. Google has no reason to hold its head high.
- vatueil 7y agoWhy is Google singled out for reprobation when, as the article points out, they've spoken out more than other companies? Sure, no one is spotless, but as it stands it's Microsoft that runs a censored search engine (Bing in China) and Apple that handed over its Chinese users iCloud encryption keys. To be fair, you could say Apple and Microsoft had their reasons for doing so (as people including the Chinese themselves have argued). But why all the focus on Google then? Is the idea of a Chinese search engine (which has since been cancelled) worse than actually running a censored search engine such as Bing China? It's gotten to the point where people commonly think Google is cozier with Chinese authorities than other companies, when if anything it's the opposite. That seems perverse.
- hnaccy 7y agoGame, set, match.
- jcims 7y agoSubstitute ‘business’ with ‘women’ and ‘hacked’ with ‘sexually assaulted’ and this writer would likely have to find a new line of work. No real attempt at looking at this from the position of individual businesses or understanding what they stand to lose by going public with news of a compromise. No critique of the obviously ineffective approach by policymakers to address this issue. This just reeks of shifting blame to the victim, sorry.
- thro_a_way 7y agoWe're in the #metoo era now, so maybe these businesses should now all come out together too.
- thro_a_way 7y agoI don't understand what investigating and complaining against china will accomplish. If the US govt knew where the hacker offices were, why didn't they just bomb them? China only knows the game of strength. It's about time the world taught them the rules by use of strength.
- jessaustin 7y agoWow I'm so surprised that Crowdstrike is quoted in an article stoking jingoist xenophobia. I'm not saying these firms didn't get hacked or aren't still getting hacked. I'm saying, fix your shit so you don't get hacked instead of trying to foment WWIII. If your firm and its IP are so legible to a foreign team, you can be certain that's also legible to competitors a lot closer to home. Actually, it seems the executive teams at these firms agree with me, since none of them consented to quotation in TFA.
- azinman2 7y agoOr... you could say it’s nearly impossible to protect against dedicated nation states, particularly against all major US businesses. If Google can get hacked, then what hope does a vacuum cleaner maker have?
- jessaustin 7y agoThat's a good question. Where is the vacuum manufactured? Many have lots of parts manufactured in China. If they're not pretty sophisticated about this outsourcing, they're giving away the store before any hacking even starts. Maybe there are some vacuums manufactured in USA that have BOM with only generic components from China. That's a good start, but if they just have every technical document dumped in sharepoint then there could still be problems. If you're actually talking about vacuum cleaner marketers rather than manufacturers, I don't know what to tell you. Disintermediation is. I have more sympathy for middlemen than any consumer has, but that's not much.
- pertymcpert 7y agoNot really the point the GP was making. Doesn't matter where you manufacture, that's only one attack vector.
- jessaustin 7y agoThis is a defeatist attitude, not to mention a bit incoherent. One moment we're meant to despise them because they can't independently invent or manufacture anything. The next moment we're supposed to fear them because they are gods of hacking from which no commercial secret may be hidden or protected. Which is it? Actually, there are various techniques by which IP may be protected. It is work, though. Fix your shit.
- CharlesColeman 7y ago> Hickton opened an investigation and quickly set his sights on a special unit of the Chinese military — a secretive group known as Unit 61398. Investigators were able to watch as the unit's officers, sitting in an office building in Shanghai, broke into the computer systems of American companies at night, stopped for an hour break at China's lunchtime and then continued in the Chinese afternoon. > ... > But when Hickton went to the companies, eager for them to become plaintiffs, he ran into a problem. None of the companies wanted any part of it. Hickton says they had too much money on the line in China. There really ought to be a law that mandates that 1) companies disclose any and all hacking incidents/data breaches they become aware of and 2) co-operate with the government in the investigation of those breaches. Though I'm a little confused why they would need the "the companies to become plaintiffs." Wouldn't hacking be a criminal matter that's would be directly prosecuted by the government? Did they want to go against the hackers both criminally and civilly?
- atomical 7y agoSeems like a dangerous precedent. Someone could move to China and hack US companies and get away with it.
- pm90 7y ago> Wouldn't hacking be a criminal matter that's would be directly prosecuted by the government? Did they want to go against the hackers both criminally and civilly? The Justice System in the US is ultimately centered around the Jury. To prove criminality, you need to convince the Jury that a crime was committed. And they are much more likely to empathize and agree with the prosecutors if they have a large number of American companies agreeing with the prosecutors that the Chinese entities stole from them.
- subcosmos 7y agoWhy is it that intelligence agencies are still conducting their activities during their countries working hours? You'd figure it would be easier to find nocturnal neckbeards anyways.
- 7y ago
- adinobro 7y agoHow is this any different to the NSA and Chinese companies? We already know the NSA did this to Huawei for multiple years.
- wpasc 7y agoOne could make the case that Chinese businesses and governments have a tighter relationship where the fruits of such hacking could be used to benefit businesses. While the NSA/other US gov agencies may be hacking chinese companies, I have yet to see any indication that it is done for the purposes of IP theft and/or anything is being shared with US businesses.
- hansjorg 7y agohttps://www.bbc.com/news/world-europe-32542140 https://www.bbc.com/news/world-europe-32542140
- Mindless2112 7y ago"[Checking] whether European companies were breaking trade embargos" is not the same as government-assisted industrial espionage.
- hansjorg 7y agoThe EU claims information obtained by the US government was fed to amongst others Boeing and McDonnel Douglas.
- lampenrad 7y agohttps://en.wikipedia.org/wiki/ECHELON#Examples_of_industrial_espionage https://en.wikipedia.org/wiki/ECHELON#Examples_of_industrial... In 1999, Enercon, a German company and leading manufacturer of wind energy equipment, developed a breakthrough generator for wind turbines. After applying for a US patent, it had learned that Kenetech, an American rival, had submitted an almost identical patent application shortly before. By the statement of a former NSA employee, it was later discovered that the NSA had secretly intercepted and monitored Enercon's data communications and conference calls and passed information regarding the new generator to Kenetech.[69] As German intelligence services are forbidden from engaging in industrial or economic espionage, German companies are frequently complaining that this leaves them defenceless against industrial espionage from the United States. According to Wolfgang Hoffmann, a former manager at Bayer, German intelligence services are aware which companies are being targeted by US intelligence agencies, but refuse to inform the companies involved.[70]
- aj7 7y agoHere’s a little reminiscence. In 2000, I was working for a fiberoptic startup in Silicon Valley. We were trying to develop a “polarization-maintaining fiberoptic coupler.” We didn’t know shit what we were doing. So the lead engineer, a young native Chinese PhD, simply called a guy he knew at another startup. Put two and two together.
- DSingularity 7y ago?? Put what together? I don’t get it..
- subcosmos 7y agoThey were just making ends meet. Fiber ends
- yipbub 7y agoSo the guy at the other start knew how to do what you guys didn't? That makes this relevant to cyber-espionage how?
- radicaldreamer 7y agoKind of a weird example because: 1) that's not hacking 2) all that proves is that his professional network of friends/ex-colleague/former collaborators was stronger than the rest of the company's?
- rrggrr 7y agoUSGOV and all but the largest businesses don't mesh. The solution to the spying threat is extending tort liability and statutory damages to negligence when there are compromises. Not different than product safety, liability will make quick work of the problem.
- dmix 7y agoThank you, I’ve been saying this forever. The solution to widespread hacking isn’t to make it easier for one side to find the other guys malware (quicker) while compromising your data privacy, in exchange for help from gov. Which is basically the only NSA “defence” being offered to businesses via “information sharing” programs.
- eeeeeeeeeeeee 7y agoAgreed. There is just zero reason to care about it and that lack of care only diminishes as more and more companies are compromised so it becomes normal and consumers really have no choice to take their business elsewhere. The only way this will change is if there are financial and/or criminal penalties for gross neglect of private data. I think healthcare (HIPAA) is another good example, although the financial penalties need to be higher given some of the compromises and relatively small fines.
- nostrademons 7y agoWho's the plaintiff in your suggestion? The article is not about companies leaking Americans' private data to China (though I'm sure that happens too), it's about them turning a blind eye when their own company confidential technology and product designs are stolen by China. For tort liability to be a factor here, the company would have to initiate a lawsuit against itself, which would never happen. The type of industrial espionage described in the article is actually a form of temporal arbitrage - it's present shareholders stealing from future shareholders and then hoping to unload the shares before the consequences of their decisions are reaped. In order to get access to the lucrative Chinese market now (and goose this quarter's earnings), they put up with Chinese industrial espionage that results in reduced competitiveness 10 years down the road. In 10 years, they probably won't be working at the company, nor will they hold many shares, and so the consequences don't affect them personally. This is a big problem in general (not just with industrial espionage - short-termism also affects labor practices, financial health, social fabric, environmental pollution, and global warming), but it's hard to see how any legal solution would fix it. Future shareholders are generally not entitled to sue until they actually become shareholders, at which point everybody says "Well, you should've known how fucked up the company was when you bought the shares". Similarly, unborn children don't get a vote on societal policies that may destroy the earth or society they live in before they're born. Usually the best alternative is just to deal with the problem with band-aids in the future, once it becomes widely recognized as a problem.
- MegaDeKay 7y agoAn interesting coincidence that I listened to the "Aurora" episode on Darknet Diaries [0] on my way home today. It was all about the hack in to Google and Adobe back in 2009 and what has happened since then. The link below is both to the podcast and the text of the episode if you'd rather read it. I highly recommend the Darknet Diaries podcast if you haven't heard of it. It bills itself as "True stories from the dark side of the Internet" and I find it absolutely gripping. And the episode about a pen tester that breaks into the wrong bank (!) in Beirut is hilarious. [1] [0] https://darknetdiaries.com/episode/19/ https://darknetdiaries.com/episode/19/ [1] https://darknetdiaries.com/episode/6/ https://darknetdiaries.com/episode/6/
- anonymous_fun 7y agoI saw Mr. Hickton speak a few nights ago. It was really an interesting talk about some of the challenges for the future: https://www.youtube.com/watch?v=8Zktw-m5hTI https://www.youtube.com/watch?v=8Zktw-m5hTI
- AnthonyWnC 7y agoIt's something from npr.org; may as well be quoting form the Onion.
- watertom 7y agoForget about the hacking. U.S. business walked into China and handed over all of their technology and Intellectual Property, just to have it used against them by the Chinese government. China has only resorted to hacking lately in order to get more technology and IP.
- solotronics 7y agoThey figured out if you just pay the decision makers some money they will sell everyone out. See congress for examples.
- hueving 7y agoYour comment is so flippant it's useless. Can you explain how China has bribed our politicians?
- occupodd 7y agoAmerican politicians work for money, they don't work for the benefit of their people so China just paid them off.
- kuzehanka 7y agoHow can you not be aware of the blatant bribery going on across the globe? https://www.abc.net.au/news/2019-02-08/chinese-billionaire-huang-xiangmo-wants-political-donations-back/10794726 https://www.abc.net.au/news/2019-02-08/chinese-billionaire-h... https://www.afr.com/news/world/asia/chinese-aid-funded-1-million-bribe-to-former-png-leader-somare-20180603-h10we3 https://www.afr.com/news/world/asia/chinese-aid-funded-1-mil... https://www.abc.net.au/news/2018-05-22/chau-chak-wing-un-bribe-scandal/9788926 https://www.abc.net.au/news/2018-05-22/chau-chak-wing-un-bri...
- luckylion 7y agoNo. They figured if you present the decision makers with a way to massively increase their profits, they would happily trade long term advantages for short term gains.
- 7y ago
- lyrachord 7y agoThe logic of all kinds of evil, such as bitch and liar, is that I can but you cannot. --L.Chord Usuck MUST be one of these kinds.
- _cs2017_ 7y ago> unfair business practices originating from China are costing the American economy more than $57 billion a year, White House officials believe And yet the companies who supposedly lose that money don't care. It reminds me a little of the $200-250B "lost" to piracy by the movie and music industry (http://freakonomics.com/2012/01/12/how-much-do-music-and-movie-piracy-really-hurt-the-u-s-economy/ http://freakonomics.com/2012/01/12/how-much-do-music-and-mov...). To be more precise it reminds me of how everyone likes to create large impressive numbers that prove their point or support their agenda.
- deleted 7y ago[deleted]
- _cs2017_ 7y agoHere's the similarity. I do think US companies suffer from hacking, just like the music and video industry suffer losses from piracy. I think, however, that the numbers reported are exaggerated beyond belief. Piracy losses are exaggerated because if you take away free music and movies, most pirates will not pay anyway anywhere close to the amounts they are said to "steal" from the copyright owners. Hacking losses are exaggerated because the supposed trade secrets are often just a PR gimmick. I've seen all too often how corporate lawyers and executives claim their special unique tech is worth billions, when in fact it's worth very little if anything. As to whether US companies can do something: sure they can; the whole point of the article is that they care a lot less than one would expect.
- nicodjimenez 7y agoHey my bad for obnoxious comments on my part, it's true that people overvalue IP sometimes in the West. Part of the reason for the reason for China's entrepreneurial success is the fact people borrow ideas from others to move faster.
- deleted 7y ago[deleted]
- paulcarroty 7y ago“Honey or condensed milk with your bread?” he was so excited that he said, “Both,” and then, so as not to seem greedy, he added, “but don’t bother about the bread, please.” (c) Winnie the Pooh
- aheneghana 7y agoChina hacked. Because it seems they are better at their job than their counterparts in the U.S. - saw first hand their capability. Small cubicles, 3 sq yd, 30 in a row, all with different language skills, ( any language ), Computer science graduates from the No 1 University in China. Pay is a fraction of what a compatible grad is being paid in the U.S. No competition. High pay won't make the leverage.
- novaRom 7y agoI remember iRobot was quite popular few years ago here in Europe, today everybody buys much cheaper Chinese devices. Same about smartphones: Apple/Samsung->Huawei. Same about Quadrocopters. It looks like it's just a matter of time until CPUs, GPUs, FPGAs, E-vehicles will be designed/produced by Chinese companies.
- freeflight 7y agoIt's super weird how everybody considered Trump odd for his hate for China, yet these days so many people just repeat the, usually completely baseless, anti-China FUD. Whether it's Huawei supposedly spying on everybody or the Chinese government putting implants on Super Micro boards, nothing is too absurd to be spread by, out of all parties, Five eyes themselves. Does China hack? Of course, so does the US, it even steals IP from allies. But I seriously doubt the damages for that go into the $57 billion, that's just a piracy-damages like inflated number. In reality, a whole lot of interesting innovation, particularly on the hardware level, has already been happening in China for years already. They gonna out-make the US maker movement, on a massive scale [0]. [0] https://youtu.be/SGJ5cZnoodY https://youtu.be/SGJ5cZnoodY
- whenchamenia 7y agoThere is plenty of truth to much of the china situation, not just FUD. While the Potus has bounced between 'i love china' and 'we need to do something about these people', the rampant IP theft negatively affects nearly everyone on HN.
- freeflight 7y ago> There is plenty of truth to much of the china situation, not just FUD. Yet FUD is all we get and people eat it up like the best thing ever. Even here on HN barely anybody questioned the Super Micro narrative, even tho that Bloomberg story was super sketchy from the very beginning by not disclosing who did that audit, just like their inability to produce a sample of the chip. Trump also never "bounced" on China, China is pretty much the only thing he doesn't bounce on, it's been his one constant since the election [0] and just because he throws an "I love China" in there, does not reflect or change any of his policy decisions. This is much more "I love my enemies because they are so stupid" posturing [1] than an declaration of actual sympathies. [0] https://www.youtube.com/watch?v=RDrfE9I8_hs https://www.youtube.com/watch?v=RDrfE9I8_hs [1] https://abcnews.go.com/Politics/10-times-trump-attacked-china-trade-relations-us/story?id=46572567 https://abcnews.go.com/Politics/10-times-trump-attacked-chin...
- chillacy 7y ago
- novaRom 7y agoLook, you can really protect your intellectual property in Europe and in USA, but you cannot do that in the rest of the world. It means your innovations will be copied and much cheaper products will be created. You can protect your own internal national market, but you cannot compete on all the remaining world markets. So what to do? End of intellectual property? Back to trade secrets? Even this will probably not help in long term.
- netsa 7y agoI think the root cause is because of China has no human-rights.