6 ms·
Australian Government and businesses hit by state-based cyber attack, PM says
- harikb 6y agoIs it possible it is being made as “breaking news” as support for any other narrative? Just saw on BBC breaking news > Regrettably, this activity is not new. Frequency has been increasing.”
- loktarogar 6y agoI'd wait til 5:30pm. It's possible they might be using this to cover another last-minute-friday announcement.
- deleted 6y ago[deleted]
- holografix 6y agoI guess sentencing an Australian citizen to death wasn’t enough retaliation.
- aaron695 6y agoI think this is Australia's response to that. There is nothing new in the announcement, it's a many months old incident in a decade long Chinese cyber breaches. It's announced today in what seems like a weak volley back in the reshuffle of trade with China post C19.
- saltedonion 6y agoLet me take a total shot in the dark. The country responsible starts with a C and ends with a A.
- sk0g 6y agoBut Canada is just cold Australia, why would they want to hurt us?! They scream cyber attack every time any of their services see a small uptick in usage, like the social services website Centrelink did, when the lockdown/ job losses started. I'm going to assume it's incompetence on their side, for now. EDIT: 95,000 users is all it took, apparently: https://www.itnews.com.au/news/minister-backflips-on-mygov-ddos-attack-claim-539704 https://www.itnews.com.au/news/minister-backflips-on-mygov-d... Some further information here: https://www.cyber.gov.au/threats/advisory-2020-008-copy-paste-compromises-tactics-techniques-and-procedures-used-target-multiple-australian-networks https://www.cyber.gov.au/threats/advisory-2020-008-copy-past...
- deleted 6y ago[deleted]
- google234123 6y agoOr... China is actually up-happy about people pointing out it's use of disinformation and economic coercion amidst COVID-19.
- sk0g 6y agoLooking into it more, ACSC has posted a serious advisory [0], so it might be real this time. It's not a good look when the government screams cyber attack willy nilly though, because people get jaded, and think it's rather their own incompetence, again. [0] https://www.cyber.gov.au/threats/advisory-2020-008-copy-paste-compromises-tactics-techniques-and-procedures-used-target-multiple-australian-networks https://www.cyber.gov.au/threats/advisory-2020-008-copy-past...
- google234123 6y agoThat maybe true but joking that Canada may be behind this when China is well known for this type of behavior is disingenuous.
- 6y ago
- metta2uall 6y agoAnyone taking responsibility for inadequate defences?
- thelittleone 6y agoAdequate by what measure? Best practices? Regulatory compliance? Are there ever adequate defenses in cybersecurity?
- ShorsHammer 6y agoFrom the Australian Signals Directorate advisory: > The title ‘Copy-paste compromises’ is derived from the actor’s heavy use of proof-of-concept exploit code, web shells and other tools copied almost identically from open source. Surely adequate can fit into defending against common open source toolkits?
- thelittleone 6y agoA quote from the PM "“We know it is a sophisticated, state-based cyber actor because of the scale and nature of the targeting and the tradecraft used". I didn't see open source toolkit mentioned in the article.
- torified 6y agoHmm, a "sophisticated state actor" or a copy-paste script kiddy? Which one was it? Copy-paste and open source was enough to get into the Australian Parliament, apparently our pollies simply can't resist the allure of larger penises and wealthy Nigerians in trouble. Or maybe, just maybe, there is just the slightest possibility that this is all just a manufactured distraction from other issues... These are the nincompoops who passed a law to backdoor everyone's encryption and nuke their own country's IT industry from orbit with a law that nobody wanted. What a surprise that they can't keep their own data secure.
- fowl2 6y ago> Hmm, a "sophisticated state actor" or a copy-paste script kiddy? Which one was it? There's no contradiction between those two things.
- ferros 6y agoWhat is the motivation behind this announcement? Considering that it is a generic ‘we are under attack’. The Prime Minister doesn’t usually hold press conferences like this unless there is a good reason.
- ShorsHammer 6y agoYou would hope the ACSC has been working furiously behind the scenes before anything got announced. There's nothing sophisticated whatsoever about these attacks, it's quite strange to make a vague political announcement where everyone jumps to their own conclusions.
- denkmoon 6y agoI think people jumping to conclusions is by design. In the context of the trade spat that is going on between Aus and China, "We're not saying it's China, but it's China"
- gonzo41 6y agoAustralian unemployment is essentially at 11% and youth unemployment is >25%. Both are going to trend higher this next quarter. I think it's a distraction from the poor handling of the recession. It's been pretty standard tack to ring the national security bell when ever there is a speed wobble from the government. This will grab the news for the day so they can end the parliamentary week without the weekend news being about everyone lack of a job. I can't really see any 4d chess moves from the Australian Government here.
- bigiain 6y ago> I can't really see any 4d chess moves from the Australian Government here. Or ever, at least from any of the parties we have contending for power right now... But "how good is coal?" :sigh: (I assume you're the Gonzo who's sharpening up a nice knife for this weekend? ;-) )
- mr_toad 6y ago> What is the motivation behind this announcement? Justifying spending millions of dollars on more bureaucracy .
- koheripbal 6y agoNorth Korea raising its head from the sand now that Kim recovered from his mystery illness.
- technion 6y agoThere's more details in the NCSC write up: https://www.cyber.gov.au/threats/advisory-2020-008-copy-paste-compromises-tactics-techniques-and-procedures-used-target-multiple-australian-networks https://www.cyber.gov.au/threats/advisory-2020-008-copy-past...
- fernly 6y agoThank you! But I don't see anything in there that isn't normal attempted cybercrime. What Steve Gibson dubbed "Internet Background Radiation", the continual poking for vulnerabilities.
- ShorsHammer 6y agoThe mitigations are hilarious too: - Update - Use 2fa
- giantDinosaur 6y agoThe same government which pushes for encryption nullification. What will we update to, eventually, backdoored encryption standards?
- torified 6y agoNot just "pushes", they have already passed a law where they can secretly force sysadmins to create backdoors for them under threat of 15 years jail, with no legal representation. No warrant necessary, just the approval of a retired judge. And no reporting. You can't make this shit up. Stasi commandant Dutton has also recently introduced a bill to interrogate 14 year olds with no legal representation as well. Bloody scary what's happening here.
- 8ytecoder 6y agoI don’t understand what’s going on in Australia. Why are there so many draconian spying and privacy invasion laws there? When I think of countries affected by terrorism, Australia isn’t the one that comes to my mind. So, what’s the justification behind all of this?
- timothy-quinn 6y agoThe Aus Government has a good guide called the "Essential Eight" for reducing risk. It's a good starting point for businesses, and is pretty much universal advice, not just applicable to government departments: https://www.cyber.gov.au/publications/essential-eight-explained https://www.cyber.gov.au/publications/essential-eight-explai... My take on the E8: https://blog.congruentlabs.co/essential-eight-essentially/ https://blog.congruentlabs.co/essential-eight-essentially/
- atlgator 6y agoSeriously, which one of you is doing this?
- MMM13SFH 6y agoWestern governments need to close the chinks in their armour
- deleted 6y ago[deleted]
- hnick 6y agoI wonder if we'll ever see letters of marque for cyber offense. It feels a bit like it's already the de facto situation in some countries because they just don't investigate.
- r721 6y ago>Government sources say China is behind the attack and Mr Morrison refused to shut down speculation that the nation was the “sophisticated state-based actor” behind the attack. Refusing to name the foreign entity, the Prime Minister stressed investigations were continuing by the Defence Signals Directorate and law enforcement agencies. https://www.news.com.au/technology/online/security/cyber-attack-in-australia-china-the-chief-suspect-behind-attack/news-story/44d60fdd551cfd890a0d4c14be5b15a7 https://www.news.com.au/technology/online/security/cyber-att... >9News political editor Chris Uhlmann said China was behind the attack. https://www.9news.com.au/national/cyber-attack-australia-scott-morrison-government-private-sector-breach-of-security/e621ae47-f810-4fa7-9c11-3caa3b09f4dc https://www.9news.com.au/national/cyber-attack-australia-sco...
- deleted 6y ago[deleted]
- suizi 6y agoAren't they the ones who passed an anti-encryption law? Gee, imagine thinking they care about security, they never seemed to care about it before with all the breaches and attacks which hit on a regular basis.