U.S. Commerce Department Hacked Again
evil agent writes "The Bureau of Industry and Security (BIS), a branch of the Commerce Department, has sustained several successful attacks. Chinese hackers were able to gain access to its computers and install rootkits and other malware." From the article: "This is the second major attack originating in China that's been acknowledged by the federal government since July. Then, the State Department said that Chinese attackers had broken into its systems overseas and in Washington. And last year, Britain's National Infrastructure Security Co-ordination Center (NISCC) claimed that Chinese hackers had attacked more than 300 government agencies and private companies in the U.K."
They say they can't clean the systems. Bullshit, they just want to blow more of OUR tax dollars on new toys.
Also, what's the OS? No mention of that in TFA. Why are they using an OS that allows this sort of thing to happen. Shall we take a guess as to the OS?
If they were serious about security they WOULD put a stop to this crap.
It's easy to batten down the hatches.
What the fuck? Aren't they even behind a firewall?
Wouldn't a simple firewall "mitigate" that "vulnerability"?
Its not about whether the chinese or japanese did it. Its about whether the commerce dept knows enough to protect itself or not.
Wincopy
By that "logic", a house with a 10' hole next to the open front door is "less" "secure" than the same house with the front door closed and locked.
No, it is not.
Which is what I said that you had previously taken exception to.
And for others it is an acceptable risk. What is it with you and the pedantic generalizations?
Again with the pedantic generalization. Do you have ANY evidence that these workstations are not used to access legitimate web-based resources?
You even get your pedantic generalizations wrong.
Back in the old days, when computers weren't networked, we still had a virus problem that was spread from computer to computer via floppy disks. Having 2 computers available means "sneaker-net" would be easy. Not to mention that it depends upon ALWAYS getting the cables correct.
Why not just put those extra $$DOLLARS$$ into locking down the desktops, setting up the firewall and monitoring the traffic?
It's not like we don't have all those technologies TODAY. Look up "snort" and SELinux for starters.
If you really want to fight back, then the best thing to do is actually let them think they're getting in. Leave a few insecure holes here and there and plant some misinformation. If you're clever enough, then you can even use that misinformation to gain an advantage against them.
Well ok I should be more clear, I've banned the blocks allocated to an ISP which I'm told is the Chinese state ISP. The reason is that I get no legit traffic, tons and tons of hack attempts, and they just ignore abuse e-mails, including those translated to Chinese.
That's the real answer to this problem. If particular ISPs refuse to behave, just start banning them. I mean sure, all ISPs will have people who act bad, but if you contact them and get no response and if the bad/good ratio is vastly (or completely) slanted to bad just ban them. Eventually they'll have access to little enough of the Internet that they'll really have no choice but to reform, or it won't matter because for all intents and purposes they won't be a part anyhow.
It's really not asking too much for ISPs to respond to abuse complaints. I remember one time I found my net connection off. Called the ISP, apparently I had a computer spewing worm traffic. Questioned my roommates and the system was located (unpatched Win 2000 will do that). Got it cleaned, they let me back on. That's how it should work. You get an e-mail saying there's abuse, you check you logs, if there is you shut off access. We have to do it at work from time to time. Usually an infected laptop but sometimes someone being malicious.
For ISPs/companies that won't, fuck it, ban them.
In the US, globalist free trade advocates would rather trade with people that are attacking us, than take the necessary steps to sanction them and defend our country from them.
They start throwing out off topic words like "protectionism" and "nativism", which when you ask them what it all means, alarmingly resembles "concern for national security" and "patriotism".
Ah, patriotism, that evil word. The notion that, just as caring for your family is more important than caring for someone else's, so is taking care of your country first.
Globalism. Another word for "screw national sovereignty, screw your own citizens, let's transfer all our wealth elsewhere". See: the national deficit and the national debt.
--- Grow a pair, liberals... stop letting the Republicans bully you!
For the past several years china has been using their surplus cash to buy up resources around the planet, long term heavy deals in you-name-it, oil, natgas, various minerals and metals, etc. Manufacturing takes labor and energy and raw resources combined with an infrastructure that can combine those three things into manufactured goods then you need a shipping industry to move stuff in and out. You might be able to shift just the labor part in theory easily, but without the actual factory built and without the raw stock to feed it, it just sits there. To use an IT term, china has the whole stack. while everyplace else has been concerned with next quarter's profits, they have been working towards the next generation's profits. And they used a ton of free western resources and investments to accomploish this.
They got to be seriously laughing about it over there, how naieve and shortsighted the west has been to purposely kill off wealth producing for some relatively short term gains. That's what we have been primarily exporting to them, the ability to keep producing wealth.
Former DOC CIO Tom Pyke is now at Energy. DOC has repeatly flunked security reviews by the DOC Inspector General (IG), known as C&A's. Story is Pkye had a crappy relationship with the DOC IG.
West is clearly cleaning house. West has a huge challenge... DOC bureaus like NOAA, BIS, PTO, Census and so forth have little in common and little reason to work together on anything or respect authority from DOC HQ.
BIS systems contain all sort of useful information regarding applications for US businesses wanting to do business overseas, including technology reviews for export controls.
Of course the fucking Chinese are interested in Commerce. This is only one small piece of an over all plan to steal US technology and business secrets. Read some Bill Gertz.
This should scare the crap of the west. By something like 2020, China will have an estimated surplus of 20 million men over women. What do you do with an extra 20 million men who can't make babies after you've slowly, over the course of 30 years raped the west of it's technology advantage and destroyed it's industrial base? Bet even lame Slashdot liberals can guess!