40 ms·
Chinese military personnel charged for hacking into Equifax
- apotatopot 7y agoand then everyone gives away daily info in tik tok like its no big deal, but the chinese govt has everything they need now lol.
- swiley 7y agoIt doesn’t matter at all who “hacked” it, these companies are committing slander against Americans and facilitating fraud en mass. The model itself is fundamentally flawed and this hack won’t be the last or the worst.
- duxup 7y agoI think it does matter who and we can in fact take issue with both who hacked it and the companies business methods.
- swiley 7y agoMeh, the “hack” is a symptom of a broken credit model. If you fix the fundamental problem then it makes it harder for bad actors to create problems like this (no matter what the intention is.) Bothering with the international politics is a waste of valuable time and energy and will probably just hurt people.
- duxup 7y agoThe information is out there credit model or not.
- briandear 7y ago> these companies are committing slander against Americans and facilitating fraud en mass What slander? If credit information is inaccurate, you can have it changed. If they don't do it in a timely fashion, you can sue. (I won several thousand dollars a few years back for a tax lien on my report that wasn't even mine.) I'm no fan of credit bureaus at all, but "slander" is hyperbole and not even true (and it's an inaccurate word, when credit reports are written, thus the correct word would have been "libel" -- however, even accusing credit bureaus of libel is ridiculous.) To further dispute the claim that these companies "slander" people, one must look at what the legal test is for defamation. The company (or person) must have: 1. Published or otherwise broadcast an unprivileged, false statement of fact about the plaintiff 2. Caused material harm to the plaintiff by publishing or broadcasting said false statement of fact 3. Acted either negligently or with actual malice Credit bureaus don't publish or broadcast. Material harm has to be proven. There must be quantifiable damages. Just shouting someone's potentially inaccurate credit information from the rooftops isn't necessarily causing damages -- it's possible, but those damages would have to be proven. It's not negligent if a file is inaccurate -- it's negligent if they were presented with a challenge of that inaccurate information and refused to correct it. However, admittedly, the bureaus do seem to act negligent rather frequently when it comes to information accuracy -- however, negligence alone doesn't make a defamation case -- the information must be publicly released (i.e. broadcast or published,) and cause material harm. > and facilitating fraud en mass. ...and facilitating credit en mass... Without credit bureaus there would be a much more difficult credit market and it would be much more subject to discriminatory practices. A credit report can't be racist, but a local bank manager, making a credit decision based on "knowing you" is (and has been,) prone to discrimination and unfairness. The VP's golfing buddy needs a loan: "No problem, we got you!" While the immigrant business owner needs a loan -- a much more difficult proposition. America's economy is the largest in the world -- and contributing to that is the ready availability of credit. To be clear, I'm not defending credit bureaus from their numerous misdeeds. But throwing words around like "slander" or "fraud" is a childish view on the importance of credit bureaus to the American credit system.
- jayess 7y agoThe indictment is linked at the bottom of the page and has interesting technical details. Even more interesting is the question of how the named individuals were identified, which is not addressed in the indictment. The indictment also includes photos of three of the people indicted. This comes across as a shot across the bow to show China that the US govt can identify the individual people doing these things.
- dx87 7y agoYep, they even say that in the link. "Today, we hold PLA hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the Internet’s cloak of anonymity and find the hackers that nation repeatedly deploys against us."
- ISL 7y agoIf this ever goes to trial, the defense-discovery of how it was done will be interesting.
- bitxbitxbitcoin 7y agoUnless they use parallel reconstructionism to keep their (probably Tor) deanonymizing skillset on the down low.
- ISL 7y agoIf the prosecutors were to do so knowingly, the prosecutors would be breaking their oath to the Constitution (and simultaneously obliterating their case/perhaps committing crimes of their own).
- LunaSea 7y agoLike that hasn't happened before with no consequences when investigative forces were handed a cool new toy.
- xivzgrev 7y agoHoly shit did not see that coming. Was sure it was some hackers out looking to sell info on dark web. Chinese government gives it a whole different motivation.
- dx87 7y agoYep, it could be used for finding extortion targets. Just find someone with bad credit who also works for some sort of sensitive program, and now you have leverage over them.
- swiley 7y agoI don’t know what you mean by “sensitive program” but anything the federal government considers critical disqualifies people like this (even if their credit goes bad after they’re hired.) They’re very particular about this; particular meaning polygraphs and agents talking to your family members. I know because I almost took a job like this (and know a number of people who have) but the pay and location were crap.
- Spooky23 7y agoThat happens if you work with DoD programs. How much do you think legislative aides are scrutinized? Political party staff who aren't on the government payroll?
- jvanderbot 7y agoThis is oversimplified. Anything ITAR or EAR or commercial proprietary related to tech would be prime to extract but would be worked by million(s) US persons with no further background screen beyond basic employability checks. US Gov secret and above requires lots of checks ... but the breadth of the human attack surface for commercial or ITAR technology combined with the Equifax data would in fact be an ace in the hole.
- kevin_thibedeau 7y agoDon't forget that China dumped the OPM database and can cross correlate individuals in important places with credit issues. Foolishly poking at them is the sort of inept strategic thinking this administration is so good at.
- kazinator 7y ago> The defendants are charged with three counts of conspiracy to commit computer fraud. It's almost literally the job description of military personnel to conspire to cause mayhem abroad.
- JoeAltmaier 7y ago...when at war. Otherwise its a serious breach. A military person who commits murder outside their mandate, is a criminal.
- loceng 7y agoI don't think China cares to follow international, or even their own stated, protocols very well - reminded of recently seeing a comment highlighting China's official values that includes freedom of speech, yet in the same stroke - the comment thread highlighting that China has the phrase "freedom of speech" ban from use in social media for people demanding "I want freedom of speech."
- FDSGSG 7y agoIs it a serious breach when both sides are doing this? We know very well that the US does this.
- JoeAltmaier 7y agoWhen discovered. Its like a spy being arrested - always an embarrassment, usually leveraged to get some concession.
- kazinator 7y agoThis is just mild espionage. The USA engages in actual military campaigns in jurisdictions with whom it is not formally at war. https://en.wikipedia.org/wiki/Declaration_of_war_by_the_United_States#Undeclared_wars https://en.wikipedia.org/wiki/Declaration_of_war_by_the_Unit...
- throwaway_tech 7y agoThe US needs to treat this as an act of war by a foreign military/government, not as a criminal act by people acting in an individual capacity. If the US can identify the individual hackers, then they should be able to identify the physical location from which the military committed the acts of war and respond with the use of force as permitted by the UN Charter and international laws and norms. By responding with grand jury indictments the US sets a terrible and dangerous precedent and is telling foreign governments the US will not do anything in response to military based acts of cyber warfare.
- anonexpat 7y agoThat starts World War 3.
- leberkleister 7y agoWho would you expect to join in on the side of the CCP?
- jvanderbot 7y agoRussia, Iran, NK, a number of countries we ignore in Africa.
- leberkleister 7y agoOther than NK, do the others have any material alliance with the CCP or is this based on their less-than-friendly stance with the US? Unsure why they would join a shooting war.
- jvanderbot 7y agoIts a somewhat educated guess if they would but I meant who answer who might. I personally anticipate an escalation of tensions along NATO / non-NATO lines and exploitation of destabilized regions. It's almost inevitable, classic Thucydides trap combined with NATO. https://foreignpolicy.com/2017/06/09/the-thucydides-trap/ https://foreignpolicy.com/2017/06/09/the-thucydides-trap/
- krak12 7y agoBusiness as usual with Chinese, hope you consider an proper act of aggression
- president 7y ago*Chinese government
- cfv 7y agoThis is nuts. a) They are charged with conspiring with each other to this, but simultaneously b) "fits a disturbing and unacceptable pattern of state-sponsored computer intrusions", and in the process they managed to commit c) "conspiracy to commit wire fraud" None of those 3 things make any sense in the face of the others. How is doing this kind of things even legal?
- nexuist 7y agoThe US has no jurisdiction to arrest Chinese soldiers on Chinese land. How could it be illegal? They would become prisoners of war in a war that doesn't legally exist.
- sschueller 7y agoWasn't Equifax the one that had admin/admin as password and leaked most of its data because of complete incompetence?
- Someone1234 7y agoMost security breaches are because of incompetence (typically management/oversight, rather than technical). Equifax didn't have good oversight of which systems were patched and instead relied on a single employee to remember to do it. One got forgotten. People broke in using an old exploit and then leveraged into Equifax's network. Equifax's first problem was bad patch policy. Its second problem was lack of network isolation/intranet security/onion-ing. As soon as an edge server was compromised the attacker hit the jackpot and had everything. The last problem was lack of audit/accountable into who/what was accessing sensitive data on the intranet. If they had that they still would have been compromised and lost data, but not every customer's record (which took a long time).
- uranium235 7y agoyes people are unreliable that's why we need a more resilient means to establish identity like PKI. Consider PGP for example, they could put QR codes on social security cards for all I care just fix the real problem for once.
- swarnie_ 7y agoI think they had an unpatched weblogic server/java web application that was internet facing.
- A4ET8a8uTh0 7y agoYep, but now they will be able to play victim card and wrap themselves in American flag. The PR value of this is amazing. Frankly, this really does explain why they were treated with kids gloves after the incident. I was certain after insider trading came to light, the company will fight with US government to stay alive. Boy was I an optimist.
- tvanantwerp 7y agoI think criminal charges against specific government hackers will probably become the norm, since no power is likely to stop hacking other powers yet no powers are too keen to start a war over it. If you're a government hacker, I wouldn't plan on taking any overseas vacations for the rest of your life.
- leptoniscool 7y agoI wonder what Snowden thinks?
- uranium235 7y agoHe probably thinks wow why is it that nobody ever considers that this problem would go away if we just came up with a better system for identity, such as how PGP works.
- dontbenebby 7y agoPlease feel free to illuminate for me how PGP would have prevented the Equifax breach, since I'm failing to connect the dots
- uranium235 7y agowell not using PGP specifically, but imagine having a social security card with two QR codes on it in addition to your social security number. one of the QR codes contains a private key and the other a public key. The financial institutions and credit reporting agencies can freely access your public key and it's safe to give away. You can make signatures with your private key when it's scanned at a bank or on a phone and the signatures can be verified to be correct by your publicly available public key. I like the idea better of making additional keypairs that have a chain of signatures back to your social security card so that you don't have to rely on it as much. It seems to me there's a lot of things that could be very workable as far as this is concern, but just to be clear I just like to use PGP as an analogy to a system that could work.
- dontbenebby 7y agoThat sounds like a very important key. I'm not discounting the technical merits of your proposal, but I'd worry it'd be very hard to secure the infrastructure used to create, update, and track those keys. (This is the same logic many use for opposing backdooring encryption, since often it boils down to key escrow)
- tempotemporary 7y ago> They routed traffic through approximately 34 servers located in nearly 20 countries to obfuscate their true location, used encrypted communication channels within Equifax’s network to blend in with normal network activity How cool is that. They have been able to grab and correlate netflow from across 20 countries.
- dclusin 7y agoIt looks like they’re using the common meaning of routing and are implying tunneling instead actual route hijacking. So finding which servers they’re tunneling to is thorough but doesn’t seem all that impressive.
- ed_balls 7y agoDid they want to get find then?
- FDSGSG 7y agoI don't think the implication here is 34 hops, but 34 different VPN exits that showed up in log data.
- KaoruAoiShiho 7y agoIf true this is a giant failure of Chinese intelligence. It just shows how far ahead the US is that they're able to charge specific people. The PLA needs to upgrade its capabilities if they don't want to stay an embarassment.
- FDSGSG 7y agoWe wouldn't know if China, Russia or whoever could identify specific US operators, only the US plays silly indictment games like this.
- president 7y agoWhy is indicting foreign nationals for hacking American citizens' data "silly"?
- siv- 7y agoIt doesn't achieve much, it increases the risk of revealing methods and sources. It also puts US cyber security personnel at greater risk, some of whom have spoken out against the practice.
- jessaustin 7y agoFor one thing, because there's no reason to suspect that any particular accusation in these indictments is true.
- alwayseasy 7y agoRussia did reveal at least one NSA TAO operative through their ShadowBrokers puppet account.
- FDSGSG 7y agoAt least 4. But it's really not at all obvious that Shadow Brokers was Russia. https://docs.google.com/spreadsheets/d/1-YhLDDrFIPlVVXG3EkpA7FcLSapt9JyzWEOnbeQWq9g/edit#gid=1562229435&range=A3 https://docs.google.com/spreadsheets/d/1-YhLDDrFIPlVVXG3EkpA...
- alephnan 7y agoI remember a opinion piece claiming hackers might have piercings, tattoos, neon colored hair, which doesn’t jive well with (U.S.) government agencies where people wear suits. I’m curious if there is concrete data breaking down whether recruiting for cyber security roles in the public sector is constrained by culture, compensation or something else.
- madamelic 7y agoBoth. I worked in the US federal gov't during college and was casually asked if I would consider coming on after college. If I remember right, fresh college grad compscis would make about $50k / year. The General Schedule caps out at a GS-15 with a yearly salary of $142k which is basically how much SV will pay a fresh grad. It makes no financial sense for any CS grad to get a job in the federal government. You can either maybe make $142k / yr in 20 - 30 years or $200k / yr in about 5 years.
- dsfyu404ed 7y agoNobody who runs the bay area rat race gets to be root on other countries computer systems and have an easy commute through semi-rural Georgia. There's definitely a group of people to whom the life that comes with a government job is attractive.
- madamelic 7y agoTotally, but the question becomes what caliber of scientist that is attracting. I guess someone could work for a pittance for a few years then leverage an NSA position for absurdly higher pay at a government contractor doing the same thing.
- dx87 7y agoAnecdotally, nobody I saw doing cybersecurity work for the government had to wear a suit, unless they had a performance review that day, or had to give a presentation to senior management. It was mostly jeans and t-shirts from what I saw, maybe a polo if they were a junior manager.
- chvid 7y agoIsn't this one of those cases that is never going to court? Similarly to the Russian military intelligence officers that were indicted in the Muller investigations?
- Jerry2 7y agoFrom the article: >The nine-count indictment alleges that Wu Zhiyong (吴志勇), Wang Qian (王乾), Xu Ke(许可) and Liu Lei (刘磊) were members of the PLA’s 54th Research Institute, a component of the Chinese military. How were they identified exactly? I'm always fascinated with these DOJ indictments of foreign state actors but I'm always left wondering how they managed to narrow it down to a small group of people. I'm guessing that "PLA’s 54th Research Institute" employs thousands of people so how does the FBI/DOJ identify the culprits so precisely? Is it through CIA/NSA spying and moles inside the PLA? You don't see foreign governments identifying individual NSA employees when the NSA hacks into something... so how does the DOJ do it?
- reaperducer 7y agoHow were they identified exactly? If they made it public, they could never do it again. You don't see foreign governments identifying individual NSA employees when the NSA hacks into something... I suspect that it does happen, but most people don't know about it because that requires knowing another language, and then regularly keeping up with the media of another country in that language.
- xxpor 7y agoI'm guessing part of the reason they're willing to ID them is because the DOJ knows this will never actually get to court where they'd have to explain how they found them.
- dx87 7y agoSeems likely. I wouldn't be suprised if it was done as a way to get them put on watchlists in all western countries without having to officially reveal any sources or methods.
- chvid 7y agoThey are guessing. The case will never go to court. The DOJ knows it so they don't have to have actual evidence. The indicment is being publicised for political reasons.
- tzs 7y agoThis kind of charging of specific foreign military or intelligence personnel for hacking US institutions is somewhat controversial in the US intelligence community [1]. Their worry is that foreign countries will eventually retaliate by charging people who are involved in US government programs to hack those foreign countries. Another worry is that indicting people might give away information information about your sources and methods. [1] https://www.mcclatchydc.com/news/nation-world/national/national-security/article205363554.html https://www.mcclatchydc.com/news/nation-world/national/natio...
- ryanlol 7y agoYeaaah, it’s not like the US doesn’t do this https://github.com/649/EQGRP-TrickOrTreat/tree/master/pitchimpair https://github.com/649/EQGRP-TrickOrTreat/tree/master/pitchi... It’s ridiculous how many people here seem to think China is somehow special as far as this sort of hacking goes. Shadowbrokers leaks even make it easy to identify specific NSA operators, for example Michael A Pecoraro, Nathan S. Heidbreder, Gennadiy Sidelnikov and a Brian C Fong Going after specific Chinese individuals means throwing these US operators under the bus.
- xxpor 7y agoPart of the calculation of taking these types of jobs should be the consideration that there's a strong chance you'll never be able to visit a foreign country ever again.
- skim_milk 7y agoIs anything really going to change? If you had a role in US intelligence you're already going to know you really shouldn't leave the western bloc.
- vsareto 7y agoI guess there was some question as to whether government hackers could be treated just as badly as proper spies. If you're a gov't hacker, you should probably assume the worst is waiting for you if you are good at your job and avoid summer Beijing trips.
- qiguai 7y agoWell when China takes over the US, and they implement their personal credit score here, they'll already have the profiles for the database!
- president 7y agoCan anyone comment on what kind of damage the Chinese might be able to do with this type of data on American citizens?
- alwayseasy 7y ago1/ Cross-reference their Equifax data with the OPM database they stole, and use it to identify American NOC operatives entering China (or their sphere of influence, or countries who's border system they've pwned) and place them under surveillance from the start. 2/ Create a score of potential recruit-ability based on people's credit history, target them once they enter a field they're interested in.
- cellard00r 7y agoEnter their horse in the presidential race and manipulate social media for people to vote for it.
- deleted 7y ago[deleted]
- papreclip 7y agoAmazed to see the US attribute anything to China instead of the usual transparent lie that North Korea was responsible
- sebastianconcpt 7y agoAccording to the indictment, the defendants exploited a vulnerability in the Apache Struts Web Framework software used by Equifax’s online dispute portal. They used this access to conduct reconnaissance of Equifax’s online dispute portal and to obtain login credentials that could be used to further navigate Equifax’s network. The defendants spent several weeks running queries to identify Equifax’s database structure and searching for sensitive, personally identifiable information within Equifax’s system. Once they accessed files of interest, the conspirators then stored the stolen information in temporary output files, compressed and divided the files, and ultimately were able to download and exfiltrate the data from Equifax’s network to computers outside the United States. In total, the attackers ran approximately 9,000 queries on Equifax’s system, obtaining names, birth dates and social security numbers for nearly half of all American citizens.
- uranium235 7y agowould just like to merely point out that we could use public key cryptography to solve the problem of identity theft.
- majos 7y agoI'm curious, if you think that this big problem has a simple solution, why do you think that the solution has not been widely adopted?
- mindslight 7y agoBecause user-first nym systems would solve the problem for consumers, not the surveillance stakeholders. Once again, if you're not the customer, you're the product.
- uranium235 7y agoI can only speculate but I've given a lot of thought to this problem and: 1. nobody has suggested it as an alternative; nobody wants to completely get rid of the system we have now. PKI requires electronics to create and verify signatures created with the keypairs. 2. Because financial institutions do not care and it's not their prerogative. The social security administration is not responsible for people's credit reports and as far as their concerned their is no problem. 3. People are afraid to try new things and new technology and it's up to the government to see that it's done correctly. Theoretically a problem could arise from somebody making a business out of "keeping track of your private key for you" which negates the purpose entirely. 4. People are lazy, and not everybody cares and doesn't necessarily speak to the benefit of people who don't care about their credit or their identity which is why I say it should be an option. 5. If cryptography fails, then the whole thing is pointless. But, I think most people will agree if cryptography fails we will have much bigger problems. The solution I have in mind is similar to what I've seen with "paper bitcoin wallets" where you have two QR codes: a public and a private key. Imagine a social security card with two QR codes. When you create a bank account, or when you get a state id or something you can get another set of qr codes, that have a record of signatures provided by a state department's private key or that of a financial institution along with a signature provided by your social security card. With your new set you can safely put away your social security card. The idea being, signatures can represent business and billing agreements as well as establishing an identity chain similar to how PGP's web of trust works. Anyone can have your public key, you just have to keep your private keys safe. Even if somehow you stupidly manage to screw this up, it's not that hard to start over. People lose social security cards now and they have to be re-issued. They just have to come up with the system for it and start doing it.
- interlocutor 7y agoI am still waiting for Equifax leaders to be charged for their negligence. They failed to keep their software up-to-date [1], while storing sensitive information about millions of US citizens. [1] https://techbeacon.com/security/why-equifax-breach-should-never-have-happened https://techbeacon.com/security/why-equifax-breach-should-ne...
- kortilla 7y agoWait until you find out nearly every company with sensitive documents has pieces of software that are out of date.
- noobermin 7y agoThat makes things worse but should absolve no one of responsibility.
- blaser-waffle 7y agoNot sure why the downvotes. Is painfully true. There also hasn't been aggressive legislation about it until CCPA. Start adding minimum costs for a breach and things may change.
- aguyfromnb 7y ago>I am still waiting for Equifax leaders to be charged for their negligence. It's the executives job to keep software up-to-date? Not the engineers building the software or implementing open-source tools? I understand being buck-stops-here accountable for the hack, but how could they be charged for negligence? Was there a conscious decision by the execs to not update the software? It's be hilarious/sad if the executives got punished for something like not updating software, because you know what the result would be? Companies would set up a system to protect execs and ensure the line-workers would be held accountable for hacks or breaches. That'd make our jobs super fun.
- outworlder 7y ago> It's the executives job to keep software up-to-date? Ultimately, yes. They are in charge, they are accountable. > because you know what the result would be? Companies would set up a system to protect execs and ensure the line-workers would be held accountable for hacks or breaches. As if most big companies didn't already have these systems in place.
- momirlan 7y agojust keep in mind that most of the comments against the charges are probably made by chinese trolls
- blunte 7y agoThe problem with being a political "hack" and repeatedly lying is that it creates doubt when you might be telling the truth. With William Barr's name on this, it is weaker.
- exabrial 7y agoI don't really consider this a "hack", I mean Equifax left the door wide open.
- sdinsn 7y agoStrange how many people on HN try to downplay hacking whenever China is involved...
- deleted 7y ago[deleted]
- favorited 7y agoWhether or not the word "hack" is a good description, it's still illegal to take things from someone who leaves their door wide open.
- TrackerFF 7y agoWell, if the bank left their vault door open, and you walked straight in taking something, it would still be considered theft - even though the door is open, you're not authorized to be there.
- avanti 7y agoCould be 4 colleagues just having some fun time.
- hatenberg 7y agoHacking. More like shooting fish in a barrel with what we know today
- pgrote 7y agoThe CISO of Equifax assured a reporter it was possible it still could have happened even when patched. "The Equifax security chief noted that the company continues to fend off attempted cyberattacks every day, and expects hacks to escalate in the future. He said that given how dedicated the Chinese military hackers were, a breach could still have happened even if the vulnerability had been patched. "They're extraordinarily sophisticated," Farshchi said in an interview. "I would say that it's possible."" https://www.cnet.com/news/justice-department-charges-chinese-nationals-over-equifax-hack/ https://www.cnet.com/news/justice-department-charges-chinese... Good to see they are confident.
- lowdose 7y agoIt's all about timing with public relation messages.
- fqye 7y agoJust curious. How much faith do Americans have in current DOJ’s credibility after the whole Trump impeachment show and Barr’s political driven handling of Muller report? To me I believe the current DOJ can make political allegations with very weak evidence or even with no evidence at all. I am sure China would say show us the evidence and we all know it’s not gonna happen.
- stjohnswarts 7y agoAnd nothing will happen because no one in the US government has the cajones to do anything about it.