rdist

June 12, 2008

China hax0rs US

Filed under: Crypto,Hacking,Misc,Security — Nate Lawson @ 9:12 am

Like any mainstream article on security, this recent AP article sensationalizes China’s response to multiple accusations of state-sponsored hacking. First, the money quote:

“Is there any evidence? … Do we have such advanced technology? Even I don’t believe it.”
— Foreign Ministry spokesman Qin Gang

Is this supposed to play into some pompous Western belief that China is a backwater and thus incapable of hacking computers? Does anyone believe it takes advanced technology to break into PCs?

Next we have the meaningless numbers. The Pentagon claims its network is scanned or attacked 300 million times a day. For this to be true, that would be an average of 3400 times per second. If we consider every packet to be a scan, that is about 200 KB/second. However, the entire port scan should be considered a single attempt. Of course, bigger numbers sound more scary and justify a higher budget. Perhaps each TCP option in the header of each packet could be considered a separate attempt since they could be attacking both timestamp and window scaling implementations!

The more interesting allegations are that China copied the contents of a laptop of the visiting U.S. Commerce Secretary and hacked into the office computers of two House representatives. The laptop incident is more interesting since it seems easier to prove. Did they confiscate the laptop and take it to another room? Did the file access times change or was it powered off? I assume he continued using the laptop during the trip and thus it would be harder to tell. Was he using disk encryption? Why not?

The allegations regarding the two House members are much less provable. The FBI investigated their computers and said they’d been accessed by people in China. How did they first decide they should call the FBI? Porn popups? Without more evidence showing a clear intent, this is more likely a malware incident. It is surprisingly convenient that their allegations appear alongside House Intelligence committee meetings on hacking.

3 Comments

  1. The same can be claim for Chinese visitors to US…

    Comment by hi — June 17, 2008 @ 9:21 pm

  2. Please provide a citation for a Chinese diplomat claiming his laptop was taken and information was used from it to access his network. I’m not saying it didn’t happen, just that I haven’t heard of it.

    Comment by Nate Lawson — June 18, 2008 @ 2:47 pm

  3. I couldn’t find one in 2 minutes, and gave up. Maybe the Chinese are not so sensitive as the Americans, regarding this. Anyway, such things are totally deniable.

    Comment by hi — June 19, 2008 @ 8:51 pm


RSS feed for comments on this post.

Blog at WordPress.com.