Today’s New York Times has a remarkable story identifying the Shanghai office building that is the source of hundreds of hacking attacks on US computer networks. And Mandiant has released an even more detailed report on the Chinese hackers responsible for the attacks.
Author Archive | Stewart Baker
Attribution: the PLA’s University of Hacking
Bloomberg Businessweek has a remarkable story about the identification of another Chinese hacker. It’s a long, tangled, and fascinating tale of good sleuthing by several researchers, but the trail ends with Zhang Changhe, a digital entrepreneur and teacher — at a People’s Liberation Army school that is suspected of training PLA hackers. In the denouement, […]
A soft counterattack on private counterhacks
Herb Lin of the National Research Council has launched the first, soft counterattack on those who think victims of cyberespionage should have greater leeway to respond directly to intrusions. Herb always strives for some balance in his work, but it’s clear that he’s a skeptic, concluding “It is not clear that the use of offensive […]
Every rung goes higher, higher
Once again, Ellen Nakashima of the Washington Post has broken a cybersecurity story: A new intelligence assessment has concluded that the United States is the target of a massive, sustained cyber-espionage campaign that is threatening the country’s economic competitiveness, according to individuals familiar with the report. The National Intelligence Estimate identifies China as the country […]
They really don’t know clouds at all
Every new computing technology seems to bring with it a privacy flap. Cloud computing is going through that phase right now, at least outside the United States. Canadian and European elites fear that putting data in the cloud will somehow let the US government paw through it at will, a fear that usually centers on […]
Introducing a nicer Baker
Well, that was quick. At the age of 6, my grandson, Asa Baker-Rouse, has already accumulated more Internet clout than I’ve been able to assemble in a career. What’s more he did it with pure sweetness. (Perhaps that’s where I went wrong.) A Middlebury student named Bianca Giaever turned one of Asa’s stories into a […]
A dubious proposal for amending the Computer Fraud and Abuse Act
I’ve just looked at the new proposal for revising the Computer Fraud and Abuse Act (CFAA) offered by Orin Kerr, Jennifer Granick and the EFF. Essentially, they would set a higher threshold for deciding when a hacker has accessed a computer “without authorization,” by requiring that the defendant circumvent a technological barrier that “effectively controls” access. On first […]
Anonymous Attacks Again
Anonymous claims to have struck a blow in Aaron Swartz’s memory. It has hacked the website of the US Sentencing Commission and posted a long manifesto and a group of files named after Supreme Court Justices. The manifesto suggests that the files contain embarrassing secrets and declares that the secrets will be revealed in installments […]
Iran Attacks US Banks; Privacy Groups Attack … NSA?
The denial of service attacks now afflicting American banks are widely attributed to Iran. They’ve grown so serious that US banks have asked the National Security Agency for help. That has provoked the usual response from privacy advocates. Faced with a serious threat to the security of our online banking accounts, they are happy to […]
An Internet of Things … That Hate Us
Turns out that hackers can use Cisco phones to monitor our communications, says Sal Stolfo of Columbia University, and Cisco evidently has taken its own sweet time to fix the problem. And the FAA’s fancy new NextGen traffic control system will allow hackers with $1000 worth of equipment to send fake GPS signals to commercial planes, […]
Computer Security: When Seconds Count, the FBI is Years Behind
Ellen Nakashima of the Washington Post has another ground-breaking article on novel approaches to network defense. I’ve blogged before about honey tokens, deceptive files that leave hackers with false data while flagging the intrusion to defenders. Nakashima’s article suggests that their use is growing, as other defensive techniques prove ineffective: Brown Printing Co.,…began planting fake […]
Prosecuting Cyberspies — And Their Customers — The Shape of a New Deterrence Strategy
The Justice Department’s National Security Division may be getting on the cyberspace attribution/retribution bandwagon — and in the process, reshaping US strategy for deterring cyberespionage. First, NSD is creating a new liaison position in US Attorney offices across the country — the National Security Cybersecurity Specialist, or NSCS (rhymes with “discus meniscus” for you knee […]
DHS Dresses Up A Turf Fight as a Privacy Issue While Ignoring the Lessons of 9/11
The Wall Street Journal thinks it’s found another scandal in government. It has, but the scandal isn’t about privacy. It’s about how the government is slowly unlearning the lessons of 9/11. DHS has passenger lists for flights in and out of the US. It uses those lists to watch for terrorists. The National Counter Terrorism Center also […]
Tracing Cyberspies
I’ve thought for a while that attribution of hacker attacks was improving rapidly. Now we have confirmation from a Ken Dilanian scoop in the LA Times. Dilanian reports that “the U.S. intelligence community is nearing completion of its first detailed review of cyber-spying against American targets from abroad, including an attempt to calculate U.S. financial […]
Why Cybersecurity Matters
For those who think I’m a little paranoid on the subject of cybersecurity, I suggest this story – a nightmare made in China for a small US businessman. Brian Milburn’s parental control software was pirated and used in a China’s infamous Green Dam software. “Green Dam Girl” Logo When he sued, hackers tied to the […]