6 ms·
So they're state sponsored attacks and then they deny any and all culpability? Europe needs to join the hard line on China.
by AimForTheBushes 7y ago
So they're state sponsored attacks and then they deny any and all culpability? Europe needs to join the hard line on China.
- echevil 7y agoSo where's the proof that they are state sponsored? I failed to find that from the article?
- AimForTheBushes 7y ago> Computer systems owned by a subsidiary of Huntington Ingalls were connecting to a foreign server controlled by APT10. APT10 is a state sponsored hacking group.
- boomboomsubban 7y agoHow are you making that claim? The only evidence I can find is an Uber receipt showing someone allegedly connected to APT10 visiting a MSS building.
- Thorrez 7y agoWhich claim are you doubting? Are you doubting that APT10 hacked Huntington Ingalls, or are you doubting that APT10 is state sponsored?
- boomboomsubban 7y agoThe latter.
- Thorrez 7y agoThere's a fair amount of evidence that APT10 is sponsored by China here[1]. It's not 100% proof, but what are the alternatives, and what chances do they have? The alternative possibilities seem slim to me. The US government accused them of working for China[2]. Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up. [1] https://www.crowdstrike.com/blog/two-birds-one-stone-panda/ https://www.crowdstrike.com/blog/two-birds-one-stone-panda/ [2] https://www.justice.gov/opa/press-release/file/1121706/download https://www.justice.gov/opa/press-release/file/1121706/downl...
- boomboomsubban 7y ago>There's a fair amount of evidence that APT10 is sponsored by China here All I'm seeing is the Uber receipt, which even they say they can't verify. >It's not 100% proof, but what are the alternatives, and what chances do they have? The alternative is that they are black hat hackers, which is very likely. >Of course not everything the US government says is true, but it seems likely to me this is true and they have some non-public evidence to back it up. The default position should be skepticism, and any evidence should be made public before a "hard line" is taken on China.
- Thorrez 7y ago>All I'm seeing is the Uber receipt, which even they say they can't verify. There's other stuff there. For example Gao was recruiting for Laoying Baichen Instruments which shares an address with CNITSEC (which is run by MSS). CNITSEC has in the past been confirmed to work with APT3. >The alternative is that they are black hat hackers, which is very likely. Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government. For example APT3 and APT1. Also the APT10 stuff appears to have happened during Chinese working hours, which is indicative of government work[1]. [1] https://intrusiontruth.wordpress.com/2018/08/09/was-apt10-the-work-of-individuals-a-company-or-the-state/ https://intrusiontruth.wordpress.com/2018/08/09/was-apt10-th...
- boomboomsubban 7y ago>There's other stuff there. For example Gao was recruiting for Laoying Baichen Instruments which shares an address with CNITSEC They can't verify that was Gao, that the poster represented that company, or show that they occupied the office building with the other company. >Are there a lot of advanced Chinese black hat hackers that don't work with the Chinese government? Because it seems like there are a lot of advanced Chinese hackers that work for the government Any hack reported by the western media immediately gets linked to the government, no matter how thin the evidence is. Chinese people can be smart and motivated by greed too, and they have a ton of people. If you personally think China is behind this based on the released evidence, that's fine. Using it as justification for attacks on the Chinese requires more proof to even be considered.
- tepidandroid 7y agoLikely both. I'm no expert in this domain, but from my perspective, due to the nature of cyber warfare, it's all but impossible to have any kind of concrete evidence or smoking gun. Cyber security firms are deliberately very careful in levelling specific accusations with the lack of concrete evidence. For example, researchers at Malwarebytes [1] say: > "While this supports the thesis of APT10 being a government threat group, we caution defenders against associating any one piece of malware exclusively with one group. Countries maintain multiple threat groups, all of whom are fully capable of collaborating and sharing TTPs." > "Variants of PlugX and Poison Ivy were developed and deployed by Chinese state-sponsored actors. They have since been sold and resold to individual threat actors across multiple nations. At time of writing, it is inappropriate to attribute an attack to Chinese threat actors based on PlugX or Poison Ivy deployment alone." Likewise, the report put out by PwC and BAE [2] label APT10 only as a "China-based actor". They cite things like attacks occurring during Chinese timezones and CCP-interest aligned hacking as evidence. This is all great circumstantial evidence and while compelling, it is far from conclusive. The report does not mention the Chinese Ministry of State Security even once. We can say how likely or unlikely something is, but the likelihood of something in the context of circumstantial evidence should not be taken as a full-on indictment. The most one could say conclusively is that it is likely to be state sponsored. [1] https://blog.malwarebytes.com/cybercrime/2019/01/advanced-persistent-threat-files-apt10/ https://blog.malwarebytes.com/cybercrime/2019/01/advanced-pe... [2] https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report-final-v4.pdf https://www.pwc.co.uk/cyber-security/pdf/cloud-hopper-report...
- djanogo 7y agoThey stole data for years and didn't try to blackmail the companies for money. What other possibilities do you deduce?
- sniperjzp 7y agoIf it is not A, then it must be B, loll, not to mention we don't even know if it is A. This is not a valid reasoning.
- ETHisso2017 7y agoTo be fair, isn't this functionally equivalent to the NSA attacks on Huawei and Chinese aircraft manufacturers over the past decade?
- Bizarro 7y agoTo be fair, isn't this.... No, we don't buy that anymore.
- ETHisso2017 7y agoWhy not?
- hguant 7y agoNot sure about the parent comment's stance, but for me, simply because it's "whataboutism" and all it does is distract from the issue at hand.
- mistermann 7y agoCan anyone explain the popularity and persuasiveness of "whataboutism"? If "To be fair, isn't this functionally equivalent to the NSA attacks on Huawei and Chinese aircraft manufacturers over the past decade" is indeed a logically valid comparison, is that not a perfectly valid rebuttal to ~scare mongering accusations of "state sponsored attacks" from China? It doesn't nullify it, but it puts it in accurate perspective, no? And should not accuracy be an important part of such conversations?
- ToddBonzalez 7y agoAn accusation of "whataboutism" is an easy put-down if somebody disagrees with your comment, but doesn't have any counter-argument... Pretty low-effort stuff, tbh. It's up there with "fake news!" as a credible rebuttal.
- SuoDuanDao 7y ago
- gorio 7y agoWhat hardline though? One can't on the one hand sell manufacturing, technology, companies and even infrastructure to China and on the other claim to be uncompromising. I wouldn't mind an actual uncompromising stance on for example labour conditions and investments. But that certainly isn't the case now. Ericsson probably employs less people in Sweden than Chinese companies do at this point.
- NicoJuicy 7y agoTechnology from China isn't the case yet. Manufacturing is and that can be relocated.
- tepidandroid 7y agoYour fundamental assumption is that all nation states do not engage is such cyber activities.
- elefanten 7y agoYes, nearly-indiscriminate colossal-scale industrial espionage being funneled to state-controlled companies is NOT a cyber activity in which most nation states engage. If your reply is going to be about British textile machinery or some one-off accusation from the last century, please focus on the scale of the accusations against the CCP, as well as consensus global norms of the current era.
- tepidandroid 7y agoMy assertion is that all advanced nation states engage in cyber warfare against one another, sometimes for the purpose of industrial espionage, sometimes for the purpose of achieving geopolitical goals (regime change, influencing elections, etc). As long as we're talking about unsubstantiated claims (and yes, that is all they are at the moment unsubstantiated), I would hazard a guess that the U.S is by far the largest, most capable and most pervasive wager of cyber warfare and espionage of them all -which incidentally is probably the reason why they are so paranoid. One would have to be supremely naive to think otherwise. Many tools used by these alleged Chinese state hackers were likely generously donated by the NSA themselves during their own cyber operations [1]. The consensus global norms of the current era is that everybody is hacking everybody at massive scale in order to further their own strategic interests -the same as it has always been. The only thing worthy of attention is the fact that these attacks are only being publicly disclosed now, coincidentally in the middle of a trade war, when the U.S administration is grasping for support from the American public against China. [1] https://www.nytimes.com/2019/05/06/us/politics/china-hacking-cyber.html https://www.nytimes.com/2019/05/06/us/politics/china-hacking...
- elefanten 7y agoThere's important nuance here that has a large impact. I'm not talking about geopolitical espionage, which I'd agree goes in all directions. I'm talking about concerted IP / business secrets theft which is then funneled to domestic companies. I call these companies "state-controlled" because they are ultimately susceptible to the authoritarian central government's will. I can't think of anywhere else in the world where this is not only routine, but coordinated at massive scale. Can you inform me what I'm missing? Edit: I disagree with your last point too. There's been plenty of reporting on Chinese IP theft dating back years, it's only increased in prominence. Trump is waging the trade war partially because of the history of hacking. It was a point of contention throughout Obama's admin too, but Trump is handling it his way. (Obama's answer was TPP, but deployed too late)
- carapace 7y agoThere are even more compelling reasons to adopt a hard line with the CCP: "Report on forced organ harvesting in China" https://news.ycombinator.com/item?id=20249489 https://news.ycombinator.com/item?id=20249489 We're in a situation where we are confronted by our own fundamental values and what they mean to us and what we're willing to do about it.
- deleted 7y ago[deleted]