9 ms·
China airs documentary proving military university is hacking U.S. targets
- p_h 15y agoIt's depressing that this is so out in the open, and it seems like there's nothing America can do to defend itself.
- lhnn 15y agoCarpet nuke.
- a3camero 15y agoSeems like good news to me: amateurs! I haven't seen a video of US government hackers in action.
- 3pt14159 15y agoYou don't think we hack them? We're far more proficient than they are, the only difference is that Chinese systems are more difficult for your average script kiddie to hack due to the language barrier.
- orangecat 15y agoWe're far more proficient than they are I wouldn't be sure of that. Check out the country distribution of Google's Code Jam participants: http://www.go-hero.net/jam/11/regions http://www.go-hero.net/jam/11/regions
- BasDirks 15y agoAnd more importantly, the distribution in subsequent rounds. Especially the Polish and Russians are beast, but China is up there too. (Ex-)communist countries are on top. I don't mean to imply anything with that, because I have no clue, just sayin'.
- bgurupra 15y agoInterestingly India has so many people in qualifiers but none in the finals, now I don't know what that says about India!
- rpearl 15y agoBecause the ability to code algorithms quickly is the same as the ability to break into systems.
- sukuriant 15y agoThe same type of mind is likely to be good at both, yes. [I would expect]
- ajross 15y agoSeems to me like it correlates with economy more than anything else. The best American (and to a lesser extent western european) programmers are making six figure salaries working on world class products and/or getting funding for their own startups. The best Russian and Chinese programmers are doing ... Google Code Jam.
- roc 15y ago> "it seems like there's nothing America can do to defend itself." We could consider a legal requirement to disclose security breaches. If every firm that failed its customers had to admit it to the market, I would think financial pressure would move us toward more effective security fairly quickly.
- 127001brewer 15y agoStates have already been passing such laws for security breaches that contain personal identifiable information since 2002: http://en.wikipedia.org/wiki/Security_breach_notification_laws http://en.wikipedia.org/wiki/Security_breach_notification_la... It has to be considered that effective security has significant costs financially and non-financially. (An example of a non-financial cost is a overly difficult registration process for a web application that requires long, complex passwords with multiple security questions and answers.)
- roc 15y agoI was thinking more about the systems for major banks, defense contractors, industry suppliers, etc. And effective security wasn't meant to imply the best thing you can think of. It would be a huge step forward if more people simply did the things we all know we should be doing: e.g. policies of accounts not having more access than necessary, network security not 100% focused on the firewall, etc.
- 127001brewer 15y agoIt would be a huge step forward if more people simply did the things we all know we should be doing... That's what I mean by "effective security". Although security breaches at banks should fall under such laws (especially since they have personal identifiable information), I do not believe defense contractors, energy concerns, industrial suppliers, etc, should even acknowledge such breaches simply because of national security.
- roc 15y ago
- ja30278 15y agoThe logical counter-response would be to encourage the sort of unrest present in the "Jasmine Revolution". This would present China with the same sort of dilemma...they might suspect (or even know) that we were stirring up trouble, but would probably be reluctant to go to war over it.
- anamax 15y ago> The logical counter-response would be to encourage the sort of unrest present in the "Jasmine Revolution". The US has a lousy history wrt helping such folk. We tend to abandon them. We did it in both Iraq (during Saddam) and Iran (a couple of years ago).
- ja30278 15y agoWho said anything about helping them? I was responding to a comment that suggested we had no useful counter-strategy to hacking, since it's difficult to respond to a cyber attack via conventional means. They know this, which is why it's relatively safe for them to engage in targeted hacking of US targets. China is vulnerable to social unrest, and stirring up that social unrest puts them in a similarly difficult position...it's not something that they'd likely be willing to go to war over, but causes them great inconvenience. Developing/distributing vpn or other software that would bypass the great firewall would be useful here.
- anamax 15y ago> Who said anything about helping them? I was responding to the person who wrote "The logical counter-response would be to encourage the sort of unrest present in the "Jasmine Revolution". If the suggested encouragment doesn't help, what's the point? Note that some of our "help" has consisted of "we'll help if you accomplish {goal}" promises that we've broken. What kind of "encouragment" and "stirring up" are you proposing that doesn't include help?
- est 15y agoThe funny part is, that youtube video in TFA, in the first several minutes it's been keep blaming US being the first and lead in cyber offence/defence warfare.
- msie 15y agoseems like there's nothing America can do to defend itself Well that's ridiculous. Just install McAfee. Disconnect yourself from the network. ;-) Seriously, computer security is a big business. Money is being made. Something is being secured out there. Edit: Please read the other comments and calm yourself down.
- Gustomaximus 15y agoI don't see how this proves state collusion in hacking rather than just some individual working on their on behalf? While we all know this is likely, I don't get the "proving" claim. Did I miss something in the story?
- est 15y agoYes, because the title of the software says "Denial of Service Network Attacking Tool, By Chinese P.L.A. Electronic Engineering Institute, Version 1.0" Btw the Institute website is http://www.eei.edu.cn/ http://www.eei.edu.cn/
- lukejduncan 15y agoGiven that hacking is considered an act of war... where does this lead? http://online.wsj.com/article/SB10001424052702304563104576355623135782718.html http://online.wsj.com/article/SB1000142405270230456310457635...
- hugh3 15y agoAt the point where hacking isn't really considered an act of war. Obviously neither side actually does consider it an act of war, or else they wouldn't dare. If "hacking is considered an act of war" were ever a bluff, then it has been thoroughly called long ago. Anyone enthused about going to war against China about this? Anyone? Anyone? Nope. I guess it's not going to happen then. And of course I think we can only assume that the US is hacking 'em back. It's like spying. It's officially against "the rules", and everybody acts shocked, shocked when they catch foreign spies within their country, but everybody is constantly doing it to everybody and everybody knows it.
- tptacek 15y ago"Hacking" is like "terrorism"; it's not an end state. It's "spying" when it's done for "spying". It's an "act of war" when it's done to shut down the power grid.
- Alex3917 15y agoNowhere. It's already generally understand by the U.S. government/military that anything on any computer connected to the Internet is public. Unless they decide to crash our power grid or meltdown some of our nuclear reactors then no one is going to do anything, unless it becomes politically convenient for propaganda purposes at some point in the future.
- rdtsc 15y agoSo I am guessing US would accept and forgive a retaliatory attack by Iran, since US "declared an act of war" on them and attacked first?
- insraq 15y agoNote that this news comes from The Epoch Times, which belongs Falun Gong, an anti-PRC organization. The Chinese government (CCP) declared Falun Gong illegal on 1997. The two parties have been "attacking" each others ever since. Falun Gong once interfered TV satellites in China. And Chinese government has banned all websites related to Falun Gong (using Great Firewall, of course). All the sites in the screenshot are related to Falun Gong. That's why they are on the "target list". This is not evidence that China is hacking U.S. agencies. I am not saying that China has never done that - I mean even if China is doing that, they will do it secretly and will never disclose it on a propaganda TV program. I personally think this news is misleading by not disclosing all the information.
- SoftwareMaven 15y agoThe targets are related to Falun Gong (which is explicitly mentioned in the article). More importantly, the source of the attacks is a hacked machine at the University of Alabama. Sure, all of the politics about China and Falun Gong are not mentioned, but they really aren't completely relevant to the fact that China is using American computers for their hacking.
- anigbrowl 15y agoAre you sure about that? How do you know they're not just spoofing the address?
- mcantelon 15y agoGiven that Falun Gong is led by a fellow who has claimed he can levitate and control people's actions with his mind, I would want some third-party collaboration of their "evidence". Pretty easy to cook up screenshots and such.
- alnayyir 15y agoThe word you want is corroboration unless you mean for a third-party to help Falun Gong in their fight against the PRC. To corroborate: to make more certain; confirm. Example: He corroborated my account of the accident.
- ansy 15y agoComputer hacking as a new battlefield is inevitable if not already a reality. Much like how at one time in the US there was no Air Force and airplanes were part of the Army, right now there is no Cyber Force and hackers are part of the Air Force. If computers really are a new theater of war, there probably needs to be a new branch of the military to recruit, train, and deploy new kinds of hacker-soldiers. The hacking operations of the Chinese right now are like American high-altitude spy planes and satellites flying with impunity over the China and the Soviet Union during the Cold War. The longer the US delays to enter the cyber arms race the more it risks conceding dominance for the foreseeable future. I could actually see a lot of positive economic synergy if the United States were to establish a Cyber Force to recruit and train computer security specialists. EDIT: I recognize the US does have a Cyber Command. It's in the Air Force. The point is it's under-funded, understaffed, and under-publicized. Recruitment is pretty much limited to a handful of people already in the Air Force with computer backgrounds. There are no commercials on TV or recruitment offices to tell people to join the hacker corps like there are for the other military branches. Mixing geeks with paratroopers isn't effective. The US needs a new branch that can make its own rules, recruitment standards, and awards to be truly effective in a different kind of war.
- wgx 15y ago>there probably needs to be a new branch of the military to recruit, train, and deploy new kinds of hacker-soldiers. Agree, but I'd suggest it likely that this branch is already well-established and operational, if hidden from the public eye.
- hugh3 15y agoI imagine this is a very large portion of NSA operations. There's no need for "cyber command" to really be part of the military. There's no need to put hackers through boot camp, or make 'em wear uniforms, or salute... it would bring down the average quality of the hackers and the average quality of the military. Far better to fold it under the roof of the intelligence agencies.
- 15y ago
- DanielBMarkham 15y agoI think sometime in the last year or two this issue has transformed into something that you could argue one way or another to something that's obvious: the Chinese are actively and purposefully trying to break into computers around the world. This is a policy of their government. Motives are still unclear. Everyone seems to agree on punishing dissidents and suppressing political groups they don't like. Most folks (I think) think it's pretty obvious they're trying to steal U.S. (and foreign) military secrets. Industrial secrets also look high on the list. Perhaps it's all of the above. And more. My money says they're out to steal anything they can. Now that the discussion is beginning to yield conclusions -- most people agree that this exists and is a problem -- the interesting thing is what to do about it. Maybe I'm wrong, but I don't see a lot happening in the next couple of years. But pressure will increase domestically in democracies to provide some kind of relief from this. Would a new administration in the U.S. be more confrontational? Would we start a more public counter hacking effort? Does this just heat up more and more as both sides escalate without dealing with the underlying problem? Or does one side or another try to get some resolution? If the politicians continue to dodge it, does it at some point just blow up? This is going to be a fascinating story to watch play out over the next decade or so.
- SoftwareMaven 15y agoUntil we can get our budget under control, nothing will happen. You can't tell the guy paying the electric bill to 'F off' if you still want to have heat in the winter. The most important reasons for us to get our finances and oil use under control are all national security related. I don't understand how the neocon camp doesn't understand that.
- rapind 15y agoIf you constitue a significant amount of the electric guy's revenue, and he already has a massive amount invested in you, then actually yes, you might very well be able to tell him to temporarily F off and still get heat in the winter so long as he thinks you'll become profitable again one day. That being said, I do agree it's a good idea to get your finances under control.
- 15y ago
- zurn 15y agoSo what in the video "proves" it's a live situation? Probably half the countries in the world have some giddy geeks in bunkers demoing their their own LOIC clones.
- ximeng 15y agoThe geek.com article adds little if nothing to the original, available at: http://www.theepochtimes.com/n2/china-news/slip-up-in-chinese-military-tv-show-reveals-more-than-intended-60619.html http://www.theepochtimes.com/n2/china-news/slip-up-in-chines... The above also has links to the original video in Chinese.
- ximeng 15y agoLater in the video that this article talks about there is a picture of a "US hacker", running "hack.bat" in a Windows 2000 command prompt. hack.bat copies "ph0rce.jpg" out. There is an IP address visible which looks like 209.134.176.39, that resolves to a subdomain of iss.net, an IBM security site. Not really sure what to make of the combination of the bizarre "hacking" and the real IP addresses. Some more translated bits and pieces from 03:46 in the video, when it starts talking about US capabilities: * US first to introduce the concept of network warfare, also first to put into practical use * In 2002 the US army established the world's first hacker unit, and in 2006 officially made this unit a core part of the airforce capabilities, with a general leading it and an operational remit consisting of 541 locations * The unit has 3000 to 5000 experts in network warfare, and 80000 soldiers. The training of the unit started officially in 2007. * Army, navy, and air force all have computer response squadrons to maintain network security. * The US is the pacesetter in computer technology, so its economy relies on this technology more than other countries, meaning it pays particular attention to network security. * Other countries such as South Korea, Japan, India, UK also have network warfare units
- dramaticus3 15y agoBased on the assumption that the network the computer is attached to is the same network as iss.net is attached to. I could make you a video where I attack every IP address on the net if you like.
- buss 15y agoI think it's important, when viewing anything put out by the chinese government, to take the information with a huge dose of skepticism. This shows a simple GUI with a list of Falun Gong targets and an "Attack" button. There's no reason to believe this is an actual tool, or to believe that the Chinese government _accidentally_ allowed this to be filmed and published. This is almost certainly a propaganda effort, intended to show the Chinese people that the government is ready and willing to attack the technological infrastructure of its enemies. There are very few Falun Gong sympathizers inside China, and the majority of the population would view this video snippet with pride.
- 127001brewer 15y agoFor anyone interested, CNBC recently produced a "special" called "Code Wars: America's Cyber Threat"[1], which talks about cyber attacks against American interests. In my opinion, the show was technically weak and seemed more concerned pushing fear-uncertainty-doubt than factual information (on actual cyber attacks against American interests). For example, the show referenced the "Northeast Blackout of 2003" as an example of the potential damage hacking an energy utility could do ... except, as the show quickly (and a little more quietly) pointed out, the event was caused by mechanical failure. Overall, cyber attacks are a concern, but not necessarily more so than other threats and certainly not as great as some would like you to believe. 1. http://www.cnbc.com/id/42210831/ http://www.cnbc.com/id/42210831/ Edited for clarity.
- ww520 15y agoThe Reddit thread yesterday has some detail and discussion. http://www.reddit.com/r/worldnews/comments/jqnpa/oops_china_accidentally_broadcasts_evidence_of/ http://www.reddit.com/r/worldnews/comments/jqnpa/oops_china_...
- click170 15y agoLink is inaccessible from safari on iPhone. Most frustrating.
- gaoshan 15y agoThe screenshot does not show any IP addresses at all. The drop down does say something about Falun Gong and the buttons do say what the article claims (about "Attack" and what not) but aside from that, the rest is just hearsay. So we have a screenshot of a window that could be created by anyone, reported by the Epoch Times (a Falun Gong media outlet). That fails the smell test. As much as I don't like the Chinese government's position with regards to what it views as dissident organizations, the evidence is not there and this sort of article runs the risk of being a "must be true because I don't like 'em" sort of thing.
- utunga 15y agoand now we get to see how the people's liberation army responds to an 'internet scandal' in the west.. my guess? ignore it completely ';-)
- TeMPOraL 15y agoAnother thing - does this tool looks like anything that can be used for hacking? Even Hollywood does a better job at showing 'hacking scenes'... For me, that's +1 on my fake-news detector.
- applicative 15y agoWhy not think this was made by some Chinese dissident at Alabama/Birmingham? Not that it's likely, but its absurdly credulous to link it.