8 ms·
"operation aurora fbi backdoor" https://www.google.com/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=operation%20aurora%20fbi%20backdoor https://www.go
by themeek 11y ago
"operation aurora fbi backdoor"
https://www.google.com/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=operation%20aurora%20fbi%20backdoor https://www.google.com/webhp?sourceid=chrome-instant&ion=1&e...
- meowface 11y agoHmm, I don't think you're totally right. >Former government officials with knowledge of the breach said attackers successfully accessed a database that flagged Gmail accounts marked for court-ordered wiretaps. To me it sounds like Gmail was compromised, and during the compromise, the attackers identified a database containing information that was of great intelligence value to them. This database does not appear to have been the vector that allowed the attackers to get in, nor was it a "backdoor". I suspect the attackers also had access to many, many other databases. It's certainly possible the primary intended goal of the breach was to access this information (for counter-intelligence purposes), but it's not how they actually got in, nor did it help them get in.
- themeek 11y agoContinue to read. You will find that this was the target of the operation. It was not the vector that allowed them to get in (not soley). It is usually the case that a successful breach gives very wide access, so I would suspect this as well. I think you'll find that on the whole I am right. That the system was there for US intelligence and the Chinese were there for counter-espionage and that the backdoor allowed the Chinese used the system to access email information that they would have had to compromise a different way to get - thus their getting access through a back door.
- meowface 11y agoThere are a lot of security analysts who say the target of the operation was indeed that database, and there's certainly a good chance of that, but still, it's definitely not the same as a backdoor.
- themeek 11y agoI'm afraid this is heading the direction of 'let's define a backdoor'. What remains true is that China targeted a system built for the FBI to get unencrypted access to GMail systems and customer data that did not require 'front door' access. Many people here would call a service run for the FBI without oversight or a lengthy and transparent approval process with the requirement for a warrant a backdoor. We don't have to call it that if you don't like - I think the terminology is not so important for the point. I will leave the semantic discussion to whether such a system constituted a 'front door' or a 'back door' to folks who enjoy such deliberations. Ultimately I hope that readers see how hacking of 'side systems' built for intelligence agencies to make full data requests have been used to gain access to the larger systems they connect - in the spirit of the original thread.
- magicalist 11y ago> Many people here would call a service run for the FBI without oversight or a lengthy and transparent approval process with the requirement for a warrant a backdoor Er, what? No one would call it a front or back door. If someone gets root access to my machine and uses that to get access to data on my machine, that data was not the entry point. The phrase "without oversight or a lengthy and transparent approval process with the requirement for a warrant" shows what a red herring this is.
- themeekforgotpw 11y agoRight, but if there is a system to access your machine without your usual creds and that system gets hacked, that's backdoor access. You can say - the system for US intelligence is like 'another account' or a 'second root' and is known to Google and so it is not a backdoor - but is that really within the spirit of the discussion? If you didn't understand that this was a separate system with separate access data, specifically for law enforcement requests, then that should clear it up. If not we can go over semantics a ton but I don't like those games (everyone loses [time]).
- csandreasen 11y agoI think the point you're trying to make is that this database of accounts under FBI surveillance is such a juicy target that it enticed China to go after Google. If the database didn't exist China wouldn't have had a reason to break in. You have a point, but I don't think it applies in this situation. Google was a valuable target for Chinese intelligence for a whole variety of reasons. Google itself suspected that the primary motivation was to gather information on Chinese activists that were using the service.[1] The fact that there was apparently a database of FBI targets is just added benefit for them, and there's no evidence that I've seen to indicate that they knew of the database to begin with. [1] http://www.independent.co.uk/news/media/china-google-cyberattack-part-of-spying-campaign-experts-1867429.html http://www.independent.co.uk/news/media/china-google-cyberat...
- themeek 11y agoNo, that's not quite the claim I'm making. I'm making a strictly stronger claim - backed by the brunt of articles - which is that China was purposefully performing a counter-espionage operation that involved Google because Google had (and has) a partnership with US intelligence. You being in the role and expertise that you are - excluding Operation Aurora for now because you seem to have a certain characterization of it - you know that China and the US hack each other for strategic purposes and that when China hacks the US it is not about dissidents. We can't predict an alternate history here whether China would have gone after Google for other reasons. What we do know is that China went after the intelligence system linked up to GMail and used it for counter-espionage purposes. One Google personal relations spokesperson did say they suspected China of using the system to collect information of terrorists and dissidents as well. Attributing motive of course changes the narrative. Making it sound like China wanted to hack Google for the sole purpose of getting to dissidents makes it sound all spooky and evil. The reporting that has China hacking Google to track down terrorists and dissidents usually 'forgets' to mention the counter-espionage link at all or that the database they accessed was for law enforcement or that they gained access to Google's systems exclusively through this system; so I tend to believe the reporting and sources that include more, rather than less, information. There's purpose behind casting doubt on the intentions of China and the context of the compromise: this is known as spin. Spin is important - for PR and for propaganda - but if you want people to have a real conversation you've got to do what you can to minimize it.