5 ms·
They did a few days ago: https://blogs.microsoft.com/on-the-issues/2021/10/24/new-activity-from-russian-actor-nobelium/ https://blogs.microsoft.com/on-the-issue
by Keyframe 5y ago
They did a few days ago: https://blogs.microsoft.com/on-the-issues/2021/10/24/new-activity-from-russian-actor-nobelium/ https://blogs.microsoft.com/on-the-issues/2021/10/24/new-act...
- criddell 5y agoRussia. Saved you a click.
- emkoemko 5y agomore likely its NSA/CIA... i mean how can anyone even know, look at NSA/CIA program "Marble" its designed to do this make their hacks look like Russians are doing it etc.
- skjhhhhhhhnnn 5y ago>which the U.S. government and others have identified as being part of Russia Microsoft is not making their own determination of who the state actor is and is just letting the three letter agencies' finger pointing fly with no evidence. There is however significant evidence indicating a country other than Russia in the FBI's Solarwinds report that contradicts the headlines if you read the body of the report.
- Ansil849 5y ago> There is however significant evidence indicating a country other than Russia Such as?
- emkoemko 5y agoCIA? look at Vault 7 "Marble" program.... and you really think hackers don't do what the CIA does? could be anyone basically... China etc etc and are probably doing the same crap as the CIA with their "Marble" program attributing the hacks to another state.
- mrRandomGuy 5y agoLess than 1 hour old account created to say that there's significant evidence that Russia isn't behind this without saying what evidence....
- rvnx 5y agoWell it's not really right to censor his answer. The narrative US = good, Russia = bad is true but only if you are in the US. In Russia you see the complete opposite. Both US and Russian intelligence have lied in the past, it's part of their job. For example, the intelligence agencies don't have the right to spy or attack their own population (as far as I know), but there is nothing that forbids them to ask an ally to do it and put the blame on someone else. Russia denies doing it, and both US and Russia have interest into collecting this data, so starting from there, it's important to keep an open mind that the interactions between countries are not black & white.
- 369548684892826 5y agoWeird because Russia isn't really a nation-state.
- kube-system 5y agoIt has somehow become common for people to use "nation-state" almost interchangeably with "state" without fully considering the connotations it implies. Regardless, there's not a clearly agreed upon threshold of how much national identity must be shared to qualify as a nation-state, nor was Microsoft intending to make any sort of commentary on national identity.
- whatshisface 5y ago>there's not a clearly agreed upon threshold of how much national identity must be shared to qualify as a nation-state The best place to draw the line is Texas. More national identity than Texas and you're a nation-state, less and you're a state. The nationality of Texas is undefined in this scheme, which is just as they would have it. P.S. people call extremely well-funded cybersecurity adversaries "nation-state adversaries" because those three words start with the letters NSA. It's a joke about US national security being the greatest threat to US private security.
- dragonwriter 5y ago> The best place to draw the line is Texas. More national identity than Texas and you're a nation-state, less and you're a state. When used in the politico-social sense that invokes national identity, nation-state still takes as a minimum requirement the functional sense of Westphalian sovereignty, which Texas lacks. Texas would probably be considered a nation-state in both senses if it was a nation-state in the functional sense; but as a subordinate unit of a Westphalian sovereignty it is not a nation-state in the functional sense, much less the narrower social sense.
- tptacek 5y agoThe "nation-" at the beginning of the term also doesn't add any context that is useful to understanding the story. People should just try not to use that term unless they're making some kind of sociological point. It's "state-level adversary", or something similar.
- deleted 5y ago[deleted]
- shireboy 5y agoI don't really like the way attribution for these sorts of things happens. Conspiracy theories aside, we do have a history of questionable attribution (Gulf of Tonkin, Iraq WMD to name two). So a rational mind is right to be skeptical and ask for evidence before accepting a narrative whole cloth. Instead, we are rarely given any evidence at all. In the article cited, we're just supposed to trust that Microsoft knows it's Russian government and can prove it. When we _are_ given some explanation, it's usually pretty weak: IP addresses are from XYZ country, metadata in a word doc is ABC language, etc. Add to that you have criminal elements that may or may not be controlled by their government. ...and then when you do question, you're downvoted, accused of being a shill, etc. I understand this sort of thing can rarely be proven 100%, and there is a need to protect intelligence sources and methods, but given that we should stop speaking and behaving as though things are 100% certain. Personally I'd like to see articles present more evidence and/or summarize into a percentage. "We rate the likelihood this is XYZ branch of Russian government at 60% due to the following factors: ...."
- JumpCrisscross 5y ago> you have criminal elements that may or may not be controlled by their government We can debate whether the Kremlin controls Russia's criminal elements. What is apparent is it's unwilling to pursue them. So much so that they practically live in the open.
- jcrawfordor 5y agoI think the major problem for organizations like MSTIC is that the vast majority of information they have access to came from other companies under strict confidentiality agreements. This is the norm in information security, most intelligence sharing goes through large vendor security centers or ISACs. In order to encourage/facilitate that sharing, these organizations require all of their members to agree to non-disclosure regimes (the "traffic light protocol" classification scheme is common in ISACs). It creates a bureaucratic situation where a company might have a great deal of data points to base an attribution on, but is prevented from disclosing 95% of them... not necessarily out of concern about source protection, but simply by contract with the data source(s). There's a long-running controversy within the industry about whether or not this situation is productive. The confidentiality agreements make corporations more willing to disclose data due to reduced risk of reputational damage and liability. But it also tends to make research and open communication more difficult and vague. The federal government has been through basically the exact same controversy over the last two decades regarding intelligence sharing, and to further complicate things it's common for there to be government elements (e.g. DHS) involved in these circles that mean there are also confidentiality agreements between government agencies and private industry that enforce many of the same rules. At its core, this comes out of a fundamental tension of liability and the law: is it better to do research that will produce damning material in lawsuit discovery, or to avoid doing the research and remain ignorant to the problem? Various industries have various half-solutions to this problem (e.g. Patient Safety Organizations in healthcare that are exempt from discovery), but the dominant one in information security reflects the roots of the industry in the intelligence community: anonymity of sources and confidentiality of information.