Showing posts with label cyberspy. Show all posts
Showing posts with label cyberspy. Show all posts

Wednesday, February 6, 2013

Hack Attack: Good News, Bad news, Security, and Freedom

First, the good news. This could have been a lot worse:
"Sophisticated cyber-attack hits Energy Department, China possible suspect"
FoxNews.com (February 4, 2013)

"The Energy Department has been hit by a major cyber-attack, which resulted in the personal information of several hundred employees being compromised and could have been aimed at obtaining other sensitive information, The Washington Free Beacon reports.

"FBI agents are investigating the attacks, which happened two weeks ago, at the Washington-based headquarters. Fourteen computer servers and 20 workstations reportedly were penetrated during the attack....
It looks like the Energy Department's hack attack is about as serious matter as what happened to Sony Playstation back in 2011. (Apathetic Lemming of the North (April 26, 2011) Individuals were affected, and the organization had a public relations headache: but that's as far as the trouble went.

Apparently hackers got information about Energy Department employees. That could be serious for the individuals involved, if folks who steal identities for fun and profit get it. Identity theft is a real problem, and a bit off-topic for this blog.

Politics, Editorial Views, and Motive

I'm not familiar with the Washington Free Beacon, but understand that it's editorial stance is "conservative." That might explain why the service was interested in posting this article: but doesn't mean that the hack attack didn't happen.

Another Employer's Personnel Files Hacked: So What?

The Energy Department handles information that's a tad more important than usernames and passwords for online games. They're interested in solar energy, wind farms, nuclear weapons, and other energy-related tech. (More at energy.gov)

I don't share the reflexive revulsion toward nuclear weapons, and unquestioning enthusiasm over solar power, expressed by some of my contemporaries. On the other hand, on the whole I'd rather have some technical details of America's nuclear weapons stay where it's supposed to be.

Back to that article:
"...While no classified information was compromised, the Free Beacon reports there are indications the hackers could have been seeking access to such data. Chinese hackers may be suspects, as the department is a known target of Beijing -- according to the Free Beacon, the sophistication of the attack indicates the involvement of a foreign government.

"The department includes the National Nuclear Security Administration, which maintains nuclear weapons.

" 'It's a continuing story of negligence,' former Energy Department security official Ed McCallum told the Free Beacon, explaining that the department continues to have security problems despite controlling some of the most 'sophisticated military and intelligence technology the country owns.'..."
(FoxNews.com)
Mr. McCallum might simply be an irate ex-employee, out to make trouble for his former boss, he may be an irate ex-employee who's legitimately concerned about a clueless former boss, or maybe there's another explanation for what he said.

Old-School Skills, Information Age Issues

I think it's quite possible that whoever's making decisions at the Energy Department is well-meaning Washington bureaucrat: who is very good at managing paperwork; diligent in pursuing greater intradepartmental communication; and clueless about the Internet. Folks in top leadership positions tend to be a bit on the old side, and less than familiar with information technology:
Clueless management is funny - in the comics.

Dilbert.com

In the real world, having a boss who doesn't understand why keeping a network safe from hackers could be a big problem.

Being 'Protected'

I think it would be nice if everybody could share information about anything, and do so without being concerned about anyone's safety. I also think it would be nice if everybody would be nice: but that's not the way the world is.

Reality being what it is, there is a need for secrets: and weapons, and that's almost another topic. Folks who decided to kill several thousand people on September 11, 2001, were not nice. What's happened since strongly indicates that outfits like Al Qaeda and the Taliban are still determined to behave badly.

Sadly, they're not the only ones who threaten the safety of the rest of us.

China isn't the same country it was a half-century back: but its leadership still seems to be unwilling to accept folks whose ideas don't follow the 'party line.' China isn't alone, of course. It's easy to see disagreement as a threat.


I'm concerned about threats from outside America. I'm also concerned about Americans who want to 'protect' us from ideas they don't like. And that is another topic. (March 9, 2008)

Related posts:

Saturday, June 11, 2011

IMF Hacked, Again - or - 'This isn't Cyberwar: It Just Acts Like Cyberwar'?!

I really hope that the key people who may have clicked the wrong link, or opened the wrong attachment, are a trifle less clueless than Dilbert's manager:



Still, there have been a lot of hack attacks so far this year.

Big ones:
  • Sony
  • Lockheed Martin
  • Oak Ridge
  • L-3 Communications
  • Grumman
    (see June 1, 2011)
Now we hear that the IMF's network has been compromised.

Again.

I hope I don't seem overly-concerned: but it's hard for me to shake the impression that all is not well with corporate and government information networks. Sure: Hacking Sony's Playstation database isn't quite like the International Monitory Fund network leaking. I include Sony's cyber-security woes in that list, because ideally a company as savvy as Sony shouldn't have let that happen.

Something, I think, has gone wrong with too many major commercial and government networks this year.

So, do I think it's time to run in circles and scream like a demented cat? No: That does not appear to be a reasonable approach.

On the other hand, I very sincerely hope that the White House cyber security coordinator has some response in mind. Besides calling cyber war a "turbo metaphor:" one that doesn't quite fit the sort of espionage we've been seeing. I think he's got a point, by the way, about staying calm:Here's what got me started with this post:
"IMF hit by 'very major' cyber security attack"
US & Canada, BBC News (June 11, 2011)

"The International Monetary Fund (IMF) says it has been targeted by a sophisticated cyber attack.

"Officials at the fund gave few details but said the attack earlier this year had been 'a very major breach' of its systems, the New York Times reports.

"Cyber security officials said the hack was designed to install software to create a 'digital insider presence'.

"The IMF, which holds sensitive economic data about many countries, said its operations were fully functional.

"The cyber attack took place over several months, and happened before former IMF chief Dominique Strauss-Kahn was arrested over sexual assault charges...."

"...A cyber security expert told Reuters the infiltration had been a targeted attack, which installed software designed to give a nation state a 'digital insider presence' at the IMF.

" 'The code was developed and released for this purpose,' said Tom Kellerman, who has worked for the Fund...."

'Epidemic' Sounds Dramatic

I think there are a whole lot of hack attacks happening - major ones - this year. I also am a little cautious when someone uses emotive terms like "epidemic."

Still, these anonymous "experts" may be right.
"Targeted cyber attacks an 'epidemic'"
Maggie Shiels, Technology, BBC News (June 2, 2011)

"The targeted attack used by hackers to compromise e-mail accounts of top US officials is reaching 'epidemic' proportions, say security experts.

"The scam, known as spear phishing, was used in a bid to get passwords of Gmail accounts so they could be monitored.

"Via a small number of customised messages it tries to trick people into visiting a web page that looks genuine so users type in login names.

"Such attacks are often aimed at top officials or chief executives.

"Such attacks are not new, say security professionals, but they are becoming more commonplace.

" 'What is happening more and more is the targeting of a couple of high value individuals with the one goal of acquiring valuable information and valuable data,' said Dan Kaminsky, chief scientist at security firm DKH...."

'This isn't War - It Just Acts Like War?!'

Or, famous last words?
"Cyber war threat exaggerated claims security expert"
Maggie Shiels, Technology, BBC News (February 16, 2011)

"The threat of cyber warfare is greatly exaggerated, according to a leading security expert.

"Bruce Schneier claims that emotive rhetoric around the term does not match the reality.

"He warned that using sensational phrases such as 'cyber armageddon' only inflames the situation.

"Mr Schneier, who is chief security officer for BT, is due to address the RSA security conference in San Francisco this week

"Speaking ahead of the event, he told BBC News that there was a power struggle going on, involving a 'battle of metaphors'.

"He suggested that the notion of a cyber war was based on several high-profile incidents from recent years.

"They include blackouts in Brazil in 1998, attacks by China on Google in 2009 and the Stuxnet virus that attacked Iran's nuclear facilities.

"He also pointed to the fallout from Wikileaks and the hacking of Republican vice-presidential candidate Sarah Palin's e-mail.

" 'What we are seeing is not cyber war but an increasing use of war-like tactics and that is what is confusing us...'..."

"...His point of view was backed by Howard Schmidt, cyber security co-ordinator for the White House.

" 'We really need to define this word because words do matter,' said Mr Schmidt.

" 'Cyber war is a turbo metaphor that does not address the issues we are looking at like cyber espionage, cyber crime, identity theft, credit card fraud...."
Okay: no turbo metaphors.

The IMF has been hacked. Again.

American defense contractors have been hacked. Several Times. This year. And the year isn't half-over yet.

Still, it could be worse.

Hey, the North American power grid is still working: right?

So, hey: how bad can it get? (June 1, 2011)

Like I said: Famous last words?

Related posts:
In the news:

Sunday, May 29, 2011

Lockheed Martin, Oak Ridge, Spear Phishing, and Common Sense

I mentioned the latest hack attempt in an American network yesterday. (May 28, 2011) Today, a Reuters article gave a bit more detail and background.1
"Lockheed Martin Corp., the U.S. government's top information technology provider, said on Saturday it had thwarted 'a significant and tenacious attack' on its information systems network a week ago but was still working to restore employee access.

"No customer, program or employee personal data was compromised thanks to 'almost immediate' protective action taken after the attack was detected May 21, Jennifer Whitlow, a company spokeswoman, said in an emailed statement.

"She said the company, the world's biggest aerospace company and the Pentagon's No. 1 supplier by sales, was working around the clock to restore employee access to the targeted network while maintaining the highest security level....
(Reuters)
So far, so good - although I wonder just how confident the IT folks at Lockheed are, that "No customer, program or employee personal data was compromised."

Maybe this is cynical: but I remember when a Qantas desk jockey insisted that there had been "no explosion" on one of their flights. That didn't explain the hole in their A380 airliners, or debris in Indonesia. (Apathetic Lemming of the North (November 4, 2010))

Bad News, Denial, and the Real World

Some bureaucrats and managers seem to deny that a problem exists as a sort of knee-jerk reaction to bad news. That may work with hirelings who can be fired if they don't agree: or with equally-clueless organizational deadweight the (delusional?) boss reports to. I don't think it's effective when dealing with the real world, though. And that's another topic.

Whodunit - Good Question

Where the attack came from is still unknown, apparently. My guess is that folks at the Department of Homeland Security and the Pentagon are trying to find out, though. Lockheed's system had data about weapons that are in use, and under development: not the sort of think I'd want outfits like Al Qaeda to have. Or none-too-friendly national governments, for that matter.

Reuters says Lockheed isn't alone - the May 21 situation was the latest in a string of attacks on American military contractors. Reuters also said that contractors aren't the only targets. The article says there have been hack attacks on "...defense contractors, security companies and U.S. government labs, including the U.S. Energy Department's Oak Ridge National Laboratory, since the start of this year." That's according to Anup Ghosh, who has been a senior scientist at the Pentagon's Defense Advanced Research Projects Agency, and now runs Invincea, a software security company. Interestingly, Reuters has edited that detail out of the story, as I'm finishing this post. (For now WUOB still has that detail in their copy of the article. (1:47 p.m. Central, May 29, 2011))

So, why doesn't the government 'do something?'

America, Law, and Limited Government

Back to that Reuters article:
"...U.S. officials may investigate a cyber breach at a company's request. DHS, the lead agency for securing federal civilian networks, can deploy a team to analyze infected systems, develop mitigation strategies, advise on efforts to restore service and make recommendations for improving overall network security....
(Reuters)
A key phrase there is "...may...at a company's request." America is a nation of law - and some of those laws control what government agencies can and can't do. We're not the only country to work that way: but I think we do a pretty good job of maintaining a balance between a government that's meddlesome, and one that's ineffectual.

Which doesn't mean that I approve of intrusive and occasionally silly federal regulations - and that's a topic that's outside the scope of this blog.

Finally I'm acutely aware that America isn't perfect. And that's yet one more topic. (July 3, 2008)

How These Attacks Work

This really should be obvious: but it's a bad to click that link and give personal information. Even if the email seems to come from your bank/credit card company/whatever. I'll get back to that.
"...These attacks typically were carried out through so-called 'spear-phish' inducements to click on a certain link to web sites or through emailed attachments carrying malicious code.

"Once so compromised, a computer can surreptitiously download other code that can log a victim's key strokes, giving an attacker a path to potentially wide network access....

"...The person with direct knowledge told Reuters on Friday that an intrusion at Lockheed was related to a recent breach of 'SecurID' token authentication technology from EMC Corp's EMC.N RSA security division...."
(Reuters)
I put a link to some common-sense advice about spear phishing under "Background," below.

Besides making the point that most financial institutions don't ask you for your Social Security Number in an email - and that you shouldn't use the phone number that the probably-bogus email provides - there's the same advice I've heard for decades: If it sounds too good to be true, it probably is.

And that, again, is another topic.

Related post:
In the news:
Background:
1 Excerpt from Reuters article:
"...The Department of Homeland Security, or DHS, said that it and the Defense Department had offered to help curb the risk from the incident....

"...Several top cybersecurity experts with extensive government dealings said they were in the dark about the origin of the attack....

"...Cyber intruders were reported in 2009 to have broken into computers holding data on Lockheed's projected $380 billion-plus F-35 fighter program, the Pentagon's costliest arms purchase.

"A series of once-secret U.S. diplomatic cables released by the WikiLeaks website suggests that China has jumped ahead of the United States when it comes to cyber espionage...."
(Reuters)

Saturday, May 28, 2011

Lockheed Martin Corp, SecureIDs, EMC, and All That


Update: (May 29, 2011)
The good news is that Lockheed seems to be doing something about the possibility that their networks have been hacked.

The bad news is that dealing with the issue is expensive. Also, that folks may be at risk as a result of stolen data.

From yesterday's news:
"Hackers may have infiltrated the networks of top US weapons manufacturer Lockheed Martin Corp., The Wall Street Journal reported Friday, citing a person with knowledge of the attacks.

"The security disruptions prompted the company to step up measures to protect its data. It wasn't immediately clear if any sensitive information was stolen or compromised...."

"...Lockheed sent 90,000 replacement SecureIDs to employees, which is being paid for by RSA, this person said. Employees were also told to reset all of their passwords used throughout the entire company as a precaution.

"EMC in March disclosed that it had been hit by a sophisticated cyber attack on its SecurID products, which are widely used by corporate clients...."
(The Wall Street Journal, via FoxNews.com)
On the 'misery loves company' principle, Lockheed isn't alone. Folks using some Sony products and services recently had an unpleasant experience - which doesn't have much to do with the war on terror, most likely, but shows how today's information technology can be a risk, as well as a boon.

As for the Lockheed Martin security issue: I have no idea who may have been behind it. We could be looking at anything from industrial espionage to international terrorists. Or some kid with an Internet connection and too much time to kill.

Related posts:In the news:

Friday, November 26, 2010

Stuxnet: Inhuman Secret Agent

Public Radio International calls Stuxnet a real threat. They could be right about that. Telegraph.co.uk calls it a virus.

Iran's government says that the nuclear weapons program they don't have - wasn't affected by Stuxnet. That's - unlikely.

Bombs? That's So 20th-Century

I've written about Iran's nuclear program before. While it's remotely possible that one of the world's leading producer of petroleum desperately needs nuclear power plants - which in turn require weapons-grade uranium - I think it's more likely that Iran's ayatollahs wanted nuclear bombs.

I think can see their point, in a way. Quite a few folks outside Iran don't act the way the ayatollahs want them to. Nuclear weapons might seem quite effective - either as an upgrade to their means for converting the unbeliever, or to incinerate folks who wouldn't cooperate.

That's not to say that I approve of the lot that's running Iran. "Understanding" isn't "approval."

I think it's very likely that's what Iran's nuclear program is intended to produce nuclear weapons. I also think that aging religious fanatics with nukes present a very serious threat to anyone within range of their missiles: which includes quite a lot of the Middle East, Russia, and a disturbing fraction of Europe.

If Iran Wanted Nukes, Wouldn't They Have Them By Now?

One of the problems with the notion that Iran wanted nuclear weapons was the way that predictions kept being wrong.

It was like Iran's nuclear program was slowing down.

In some circles, this would 'obviously' mean that the vast right-wing conspiracy, or some other mysterious force, had made up the whole 'Iranian nukes' idea. After all, if Iran wanted nukes, they'd have them by now - and since they don't have them, they didn't want them.

Looks like there was a 'conspiracy' involved. Sort of.

Also, apparently, a very, very sophisticated worm: a sort of Information Age secret agent.

Stuxnet: One Very Smart Worm

Stuxnet is, in a way, scary. I hope that whoever designed it has figured out a way of disabling the thing. I'll get back to that.

According to an article I read today, Stuxnet is a very, very sophisticated set of code: a worm that's designed to damage, but not destroy, particular machinery in Iran's nuclear program. Also not affect other systems it infects - and cover its tracks so effectively that Iranian counter-intelligence apparently assumed that people working on the project were damaging the equipment.

Some of those people were killed - others simply disappeared.

Moralizing While Cities Get Nuked?

I am not comfotable with the idea of (presumably) innocent people being killed by Iranian security, when the culprit is malicious code. Or, rather, whoever made Stuxnet.

On the other hand, I am not comfortable with the idea of people in Tel Aviv, Beirut, Stavropol, or some other city, getting vaporized because folks who could have stopped the Iranian nuclear program - didn't.

I know, by the way: A lot of the folks in the cities I mentioned are Muslims. I've gotten the impression that quite a few Muslims die because some other Muslim decided they're not doing Islam the 'right' way.

Stuxnet: No Skynet

Smart as Stuxnet is, I'm about as certain as I can be about anything that it won't wind up taking over the world, like The Terminator's Skynet.

On the other hand, like I said, I really hope that whoever designed Stuxnet has a way of disabling it - or that one of the many commercial anti-malware firms works out a method.

It looks like it was designed very carefully to perform one function - and only one function. On a particular computer system, in a particular place.

Still, anybody can make a mistake.

As to 'is it moral to use a worm like Stuxnet' to keep religious crazies from having nukes? If someone hadn't developed Stuxnet, the world's best and brightest might be discussion how if they'd just had a chance to talk with the ayatollahs, some city would still be on the map.

I'm inclined to think that "alive" is better than "dead," all other things being equal.

Here's a rather long set of excerpts from that article I mentioned:
"....--The worm also knew that the complex control system that ran the centrifuges was built by Siemans, the German manufacturer, and -- remarkably -- how that system worked as well and how to mask its activities from it.

"--Masking itself from the plant's security and other systems, the worm then ordered the centrifuges to rotate extremely fast, and then to slow down precipitously. This damaged the converter, the centrifuges and the bearings, and it corrupted the uranium in the tubes. It also left Iranian nuclear engineers wondering what was wrong, as computer checks showed no malfunctions in the operating system.

"Estimates are that this went on for more than a year, leaving the Iranian program in chaos. And as it did, the worm grew and adapted throughout the system. As new worms entered the system, they would meet and adapt and become increasingly sophisticated....

"...This went on until June of last year, when a Belarusan company working on the Iranian power plant in Beshehr discovered it in one of its machines. It quickly put out a notice on a Web network monitored by computer security experts around the world. Ordinarily these experts would immediately begin tracing the worm and dissecting it, looking for clues about its origin and other details.

"But that didn’t happen, because within minutes all the alert sites came under attack and were inoperative for 24 hours.

" 'I had to use e-mail to send notices but I couldn't reach everyone. Whoever made the worm had a full day to eliminate all traces of the worm that might lead us them,' Eric Byers, a computer security expert who has examined the Stuxnet. 'No hacker could have done that.'

"Experts, including inspectors from the International Atomic Energy Agency, say that, despite Iran's claims to the contrary, the worm was successful in its goal: causing confusion among Iran’s nuclear engineers and disabling their nuclear program.

"Because of the secrecy surrounding the Iranian program, no one can be certain of the full extent of the damage. But sources inside Iran and elsewhere say that the Iranian centrifuge program has been operating far below its capacity and that the uranium enrichment program had 'stagnated' during the time the worm penetrated the underground facility. Only 4,000 of the 9,000 centrifuges Iran was known to have were put into use. Some suspect that is because of the critical need to replace ones that were damaged.

"And the limited number of those in use dwindled to an estimated 3,700 as problems engulfed their operation. IAEA inspectors say the sabotage better explains the slowness of the program, which they had earlier attributed to poor equipment manufacturing and management problems. As Iranians struggled with the setbacks, they began searching for signs of sabotage. From inside Iran there have been unconfirmed reports that the head of the plant was fired shortly after the worm wended its way into the system and began creating technical problems, and that some scientists who were suspected of espionage disappeared or were executed. And counter intelligence agents began monitoring all communications between scientists at the site, creating a climate of fear and paranoia....

"...Speculation on the worm's origin initially focused on hackers or even companies trying to disrupt competitors. But as engineers tore apart the virus they learned not only the depth of the code, its complex targeting mechanism, (despite infecting more than 100,000 computers it has only done damage at Natanz,) the enormous amount of work that went into it—Microsoft estimated that it consumed 10,000 man days of labor-- and about what the worm knew, the clues narrowed the number of players that have the capabilities to create it to a handful.

" 'This is what nation-states build, if their only other option would be to go to war,' Joseph Wouk, an Israeli security expert wrote.

"Byers is more certain. 'It is a military weapon,' he said.

"And much of what the worm 'knew' could only have come from a consortium of Western intelligence agencies, experts who have examined the code now believe.

"Originally, all eyes turned toward Israel's intelligence agencies. Engineers examining the worm found 'clues' that hinted at Israel's involvement. In one case they found the word 'Myrtus' embedded in the code and argued that it was a reference to Esther, the biblical figure who saved the ancient Jewish state from the Persians. But computer experts say 'Myrtus' is more likely a common reference to 'My RTUS,' or remote terminal units.

"Langer argues that no single Western intelligence agency had the skills to pull this off alone. The most likely answer, he says, is that a consortium of intelligence agencies worked together to build the cyber bomb...."
(FOXNews)
Langer's picks are
  • The United States
    • Which has the technical skills needed
  • Germany
    • With access to Sieman's product design
  • Russia
    • Familar with
      • Iran's nuclear plant
      • Sieman's systems
He could be right about all that.

Then, there's this - I suppose you could call it a literary reference.
"There is one clue that was left in the code that may tell us all we need to know.

"Embedded in different section of the code is another common computer language reference, but this one is misspelled. Instead of saying 'DEADFOOT,' a term stolen from pilots meaning a failed engine, this one reads 'DEADFOO7.'

"Yes, OO7 has returned -- as a computer worm.

"Stuxnet. Shaken, not stirred."
(FOXNews)
Related posts:In the news:

Monday, February 22, 2010

China. Hackers. Cyberattack. Again.

Another variation on a theme, in the news:
"U.S. Pinpoints Coder Behind Google Attack"
Reuters, via Threat Level, Wired (February 22, 2010)

"U.S. government analysts believe a Chinese man with government links wrote the key part of a spyware program used in hacker attacks on Google last year, the Financial Times reported on Monday.

"The man, a security consultant in his 30s, posted sections of the program to a hacking forum where he described it as something he was 'working on,' the paper said, quoting an unidentified researcher working for the U.S. government.

"The spyware creator works as a freelancer and did not launch the attack, but Chinese officials had 'special access' to his programing, the report said.

" 'If he wants to do the research he's good at, he has to toe the line now and again,' the paper quoted the unnamed U.S. government researcher saying...."

"...The allegations over the spyware are the latest episode in a dispute that has pitted Google and the United States against China, with its wall of Internet controls and legions of hackers.

"In January, the giant internet search engine company, Google, threatened to pull back from China and shut its Google.cn Chinese-language portal over complaints of censorship and sophisticated hacking from within China.

"Washington has backed those criticisms and urged Beijing to investigate hacking complaints thoroughly and transparently. Beijing has said it opposes hacking.

"The Financial Times report also quoted unnamed sources backing a New York Times report that analysts had traced the online attacks to two Chinese educational institutions, the prestigious Shanghai Jiaotong University and the Lanxiang vocational school...."
On the 'up' side, it seems to me that China's unwillingness to play well with others is getting into the news a little more often now, than a few years ago. ("White House Computers Hacked, Probably by China: News That's Not Fit to Print? (November 9, 2008))

Other related posts:And click "China" in this blog's label cloud.

Friday, February 19, 2010

Cyber Attacks Came From China - Again

I'm not all that nostalgic about "the good old days." My memory's too good. The bad guys didn't always wear black hats in westerns, by the way: that's a campus legend. On the other hand, someone with an eastern European accent in a movie was very likely a spy and/or criminal. And a nasty one.

No, I don't miss "the good old days."

I'd like to embrace the fuzzy feelings of peace and love and brotherhood (oops - siblinghood?) for all: without borders, without animosities, without thinking. My memory's too good for that, too.

Not that I'm a "regular American," who grudgingly admits that some of those foreigners make good cars, but doesn't like any of 'those people over there.' I'm a Catholic, which gives me a particular point of view on tolerance and related topics. (A Catholic Citizen in America, August 3, 2009, , for starters)

"Don't be so open-minded that your brain falls out" is good advice, I think. Yellow journalism, headlines screaming "Remember the Maine!" and movies where anybody from eastern Europe was suspect were not good ideas.

Neither is a "tolerance" which involves studiously ignoring or misinterpreting facts.

Cyberattacks, China, and Getting a Grip

I think that The New York Times is a pretty good home-town newspaper for the upper crust of New York City. (October 21, 2008) I also think that the editors - some of them, anyway - try to be professional journalists. And, occasionally succeed.

If this article had been on the front page, or in with international news, I'd have a higher opinion of the Times:
"A series of online attacks on Google and dozens of other American corporations have been traced to computers at two educational institutions in China, including one with close ties to the Chinese military, say people involved in the investigation.

"They also said the attacks, aimed at stealing trade secrets and computer codes and capturing e-mail of Chinese human rights activists, may have begun as early as April, months earlier than previously believed. Google announced on Jan. 12 that it and other companies had been subjected to sophisticated attacks that probably came from China.

"Computer security experts, including investigators from the National Security Agency, have been working since then to pinpoint the source of the attacks. Until recently, the trail had led only to servers in Taiwan.

"If supported by further investigation, the findings raise as many questions as they answer, including the possibility that some of the attacks came from China but not necessarily from the Chinese government, or even from Chinese sources.

"Tracing the attacks further back, to an elite Chinese university and a vocational school, is a breakthrough in a difficult task. Evidence acquired by a United States military contractor that faced the same attacks as Google has even led investigators to suspect a link to a specific computer science class, taught by a Ukrainian professor at the vocational school...."
(The New York Times)
Kudos to the Times, for pointing out that evidence points to specific schools in China. And that this does not necessarily mean that the Chinese government is responsible for the attacks.

But: a security threat like this, in the Technology section? I'm all for suspended judgment and waiting until facts support a conclusion: but I'd also appreciate a bit less of what can be seen as bending-over-backwards polite reticence about acknowledging that China doesn't always play nice.

I don't think that the Chinese government is behind the many cyberattacks that came from computers in China. I certainly don't think that the Chinese government isn't behind the attacks. I don't know.

Sure, it looks like The People's Republic of China has been repeatedly trying to hack into private sector and government computer networks around the world - and in America. But that's suspicion, not knowledge.

Well-founded suspicion, in my opinion: but suspicion nonetheless.

I think I could be less suspicious, though, if traditional American news services didn't seem to be tiptoeing around the idea that the last large worker's paradise on the planet might not be behaving well.

Related posts:And click "China" in this blog's label cloud. In the news:

Tuesday, April 21, 2009

Pentagon Computers Hacked - Joint Strike Fighter Project Data This Time

The article is dated April 21, 2009 - and it's not the sort of thing I like to read at around 1 in the morning.

"Computer spies have broken into the Pentagon's $300 billion Joint Strike Fighter project -- the Defense Department's costliest weapons program ever -- according to current and former government officials familiar with the attacks.

"Similar incidents have also breached the Air Force's air-traffic-control system in recent months, these people say. In the case of the fighter-jet program, the intruders were able to copy and siphon off several terabytes of data related to design and electronics systems....

"The latest intrusions provide new evidence that a battle is heating up between the U.S. and potential adversaries over the data networks that tie the world together. The revelations follow a recent Wall Street Journal report that computers used to control the U.S. electrical-distribution system, as well as other infrastructure, have also been infiltrated by spies abroad.

"Attacks like these -- or U.S. awareness of them -- appear to have escalated in the past six months, said one former official briefed on the matter. 'There's never been anything like it,' this person said, adding that other military and civilian agencies as well as private companies are affected. 'It's everything that keeps this country going.'..." (WSJ)

On the other hand, I'm rather glad that Americans can read this sort of not-entirely-complimentary news about their country. Which is another topic.

Several terabytes of weapons system data in the hands of a potential enemy isn't a good thing, no matter how much value is put on "transparency." Worse, I think, is the possibility that North America's power grid could be shut down.

We've had blackouts before, notably in 1965, 1977, and 2003. To everyone except conspiracy theorists, those were accidents: and involved a fraction of the power grid. I don't think it's at all impossible that a coordinated, willful, effort to compromise the grid would be more effective than a single breaker near Niagara tripping at the wrong time.

"Cold War Mentality" and the Real World

Much of the article is old news.

America's military, taking their mandate to protect the country seriously, has noted that China is been steadily improving its online warfare capability. And, that a number of recent attacks point at China.

China's government says 'did not!'

As The Wall Street Journal put it:

"...The Chinese Embassy said in a statement that China 'opposes and forbids all forms of cyber crimes.' It called the Pentagon's report 'a product of the Cold War mentality' and said the allegations of cyber espionage are 'intentionally fabricated to fan up China threat sensations.' ..." (WSJ)

That's probably the line that Americans who like to appear sophisticated and/or open minded will take. Again, nothing new.

There's a War on, People

Despite the White House officially removing "war on terror" from America's authorized lexicon, there are sill quite a few organizations which want to kill Americans and change this country: violently.

That may not be a "war," officially, but it's going to feel like one no matter how nicely its described.

The Chinese connection with these cyberattacks doesn't surprise me at all. China is certainly not an Islamic country: but as I've written quite often, not all terrorists are Muslims. And China's leaders could easily see Al Qaeda, the Taliban, and similar groups as useful allies.

I think there's reason to believe that China's leadership wants to extend its influence beyond the borders of China and Tibet - or Xizang province, as China calls the country, now that it's been "liberated" and made part of China.

I do not agree with the official Chinese position, that the American military's assessment of the Chinese threat is "Cold War mentality." I have more respect for China's leaders than that. I see China as a large country which has not yet succeeded in decimating its own population: a country with significant technical capabilities, a potentially strong economy, significant natural resources, and an understandable desire for a place of prominence in the world.

I have no problem with China becoming a major economic power, provided that the Chinese markets are comparatively open.

However, there's good reason to suppose that China may be trying to assert itself the old-fashioned way: through raw power, intimidation, and sabotage. This, I have a problem with.

Related posts: In the news:

Sunday, March 29, 2009

Cyberspy Network Hacked 103 Countries' Systems

Here's the deal: Canadian researchers with the Information Warfare Monitor (IWM) started out seeing if there was anything to claims that the Chinese government had been using computers to spy with Tibetans living in exile.

Chinese Cyberspying: Big Time

I can see why China's government would want to keep track of Tibetans who escaped "Xizang Province." People like that could be an embarrassment. Tibet's got other names, too: but since I use American English - and so do you - I'll use a name you're likely to recognize.

So far, IWM has found 103 countries whose computers have been hacked by a small, selective, network that just happens to be mostly in China.

As The Canada Press put it:

" 'What we found is not so much unprecedented in scope and sophistication,' said Nart Villeneuve, a senior IWM analyst.

" 'But the relatively small size of the network and concentration of high-value targets is significant. It does not fit the profile for a typical cyber crime network.'

"Principal investigators Ron Deibert and Rafal Rohozinski said: 'This report serves as a wake-up call.'..."

Wake-Up Call - Not to be Alarmist, but This Sounds Serious

I've been reading about hacked government sites for some time. It's not exactly being hushed up, but news services haven't seemed overly eager to put the story up front, either.

Can't say that I blame them, considering the sort of comments I've gotten when I used the 'wrong' word for Xizang Province, and suggested that China's invasion and occupation of Tibet - and policies in general - fell somewhat short of the idea.

This time around, though, there doesn't seem to be so much polite reticence.

Good thing, too. The way I see it, breaking into another nation's files isn't nice: even it it's a virtual break-in.

Related posts: In the news:

Friday, October 10, 2008

World Bank Group Network Hacked; Chinese IPs Used: Just What We Need

Oh, dear. This is not good.

About 4,500 people working for the World Bank Group apparently hadn't changed their passwords when an emailed memo was written to remind a dozen or so key people, back in July of this year. Which is not good, since WBG had been under attack since Summer of 2007.

Last April, spy software dug deep into servers in World Bank Group's treasury unit, that's supposed to be unusually secure. For almost a month's time, in June and July, hackers had full access to the rest of WBG's network.

To World Bank Group's credit, a memo was sent around via email, back in July.1

On the other hand, nobody, except the hackers, seems to know just what data accessed and (presumably) copied. Considering the sort of data that the World Bank Group has, letting somebody from the outside read it is very bad news.

It gets more interesting.

Of the six major attacks so far, two are from the same set of IP addresses. In China. Could be a coincidence, but China's been overly-inquisitive about other people's data before.

I'm not happy to hear this. I'd say that one thing the world doesn't need right now is an unknown amount of very sensitive data, in all likelihood concerning almost 200 countries. The possibility that the Chinese government is involved doesn't make me any calmer. China doesn't exactly have a stellar record on human rights, and - melodramatic as this sounds - I'm concerned about why China needs a secret submarine base.

World Bank Group: A Little Background

Basically, it's an anti-poverty agency with a multi-billion-dollar budget, with representatives from 185 countries on its The World Bank, which "is a vital source of financial and technical assistance to developing countries around the world...," has a fairly rich About Us section. One of the resource links there is to a 12-page brochure, World Bank Group / Working for a World Free of Poverty, that describes the organization and its five units:
  • International Bank for Reconstruction and Development
  • International Development Association
  • International Finance Corporation
  • Multilateral Investment Guarantee Agency
  • International Centre for the Settlement of Investment Disputes
Previous post, discussing China and cybersecurity: In the news: (I'd never heard of darkreading.com before: it seems that the domain is registered by Tucows Inc.: which of course I'm quite familiar with.)
1 The email reads, in part, "We have new evidence that the Passwords that have been compromised may have accessed data. ... Please bear with us during this unprecedented crisis."

Tuesday, March 18, 2008

The War on Terror? This May be The War For Freedom

The War on Terror is a fairly common name for the efforts of America and other nations to keep Islamic enthusiasts from killing their citizens. A few things I read over the weekend made me consider using a new name for the 21st century's first major conflict.

Another Front in the War on Terror?

China has been exporting pre-infected consumer electronics to America. Last week's news included "Electronic gadgets latest sources of computer viruses" CNN (March 13, 2008), about an interesting new wrinkle in cybersercurity: electronic gizmos with viruses already loaded at the factory. All you have to do is plug them into your computer, and you've got a potpourri of malware. Gadgets affected include iPods, digital picture frames, and navigation systems: "some of today's hottest gadgets are landing on store shelves with some unwanted extras from the factory: pre-installed viruses that steal passwords, open doors for hackers and make computers spew spam."

The little v-bombs, for the most part, come from Chinese factories. Since the malware seems to be loaded at the end of the production process - ironically, in a quality-control check - this may not be intentional hacking: just the sort of sloppy work that brought us lead-tainted toys, and sent poison dumplings to Japan. ("'Just When You Thought it was Safe to Plug in Your iPod...' " Apathetic Lemming on the North (March 17, 2008), "China: Toxic Toys and Dubious Dumplings Aren't Signs of Terrorism" (January 30, 2008))

Factory-infected consumer electronics isn't the only concern that Americans should have when it comes to the Middle Kingdom. China's government says that the United States should stop thinking that they're trying to hack into American military computers. ("China denies U.S. computer hacking agenda" CNN (March 4, 2008))

I can understand why China's leaders want America to look the other way. They seem to be paying hackers to get information out of American military networks. ("Cyber Tensions Flare Amongst U.S., Chinese Military" (March 12, 2008))

For most of the Cold War, cameras, spy planes and wiretaps were the high tech intelligence tools. These days, it's hacking on the Internet. Attacks on American territory in cyberspace aren't anything new:
  • 2007:
    • Homeland Security networks shut down, sensitive data compromised
      Attack traced to the Chinese People's Liberation Army
    • Unclassified Pentagon email system used by the offices of Defense Secretary Robert Gates accessed,
      taken offline and fixed
  • 2006: Naval War College computer network attacked and temporarily crippled
Quite a few cyberattacks have Chinese fingerprints on them, and Chinese computer enthusiasts say that they're occasionally subsidized by the Chinese government to hack into American networks.

China's motives are clear enough. These days, it's easier to have someone in Beijing break through firewalls and encryption to get weapons blueprints and battle plans, than it is to arrange for an agent to go snooping around with a flashlight and lock picks.

All of which has nothing to do with Islamic extremists blowing up markets and beheading people they don't approve of. Apparently.

The War for Freedom?

My educated guess is that China and Russia are already involved in the global conflict that's been called the War on Terror.

Last year, I wrote about WWII's odd couple, Germany and Japan. ("Iran and Russia and Germany and Japan" (October 19, 2007) ) Germany's leadership was dedicated to the premise that the "Aryan Race" was superior to all others. Japan's very non-Aryan leadership undoubtedly did not share this view.

That didn't keep them from cooperating, a lesson that seems to be lost on people who insist that Iran couldn't possibly be supporting Al Qaeda because Iran is Shiite, and Al Qaeda's Sunni. Differences in philosophy don't make alliances impossible.

Last year, I suggested that Russia could be repeating the same mistake that it made in WWII, forming an alliance with Germany. Russia and its empire were called the Soviet Union then, and this time Russia seems to be leaning toward Iran: but the principle of forming an alliance with an up-and-coming tyranny is the same.

Now, I think that China may have gotten involved.

I don't suppose it's politically correct to say this, but it's not hard to see Russia and China as nations interested in gaining (or re-gaining) an empire. With a goal like that, either of them might make strange alliances, or at least take advantage of America's, and others', trouble with terrorists.

If Russia and China become more, and openly, involved in this global conflict, it won't be quite "the War on Terror" any more. I suggest calling it the War for Freedom. Whatever their ideological differences Al Qaeda and the Taliban, Russia, and China have, they are united in this: None can tolerate the free expression of ideas, open communication of facts, or people deciding how to spend their own money and live their own lives.

That's "freedom." This is a war with terrorists and tyrants on one side, trying to limit freedom, America and some other nations are defending freedom.

Under the circumstances, "War for Freedom" isn't such a far-fetched name for it.

A related post: "Deterrence in Cyberspace: This Just Might Work" (March 18, 2008)

Unique, innovative candles


Visit us online:
Spiral Light CandleFind a Retailer
Spiral Light Candle Store

Blogroll

Note! Although I believe that these websites and blogs are useful resources for understanding the War on Terror, I do not necessarily agree with their opinions. 1 1 Given a recent misunderstanding of the phrase "useful resources," a clarification: I do not limit my reading to resources which support my views, or even to those which appear to be accurate. Reading opinions contrary to what I believed has been very useful at times: sometimes verifying my previous assumptions, sometimes encouraging me to change them.

Even resources which, in my opinion, are simply inaccurate are sometimes useful: these can give valuable insights into why some people or groups believe what they do.

In short, It is my opinion that some of the resources in this blogroll are neither accurate, nor unbiased. I do, however, believe that they are useful in understanding the War on Terror, the many versions of Islam, terrorism, and related topics.