Details Emerge On the 2006 Hacking of Congress
The National Journal just published an article with details about the hacking of Congress in 2006, possibly by agents in China, though the attack's origin is uncertain. The article notes the difficult work of the House Information Systems Security Office, which must set security policies and then try to enforce them on a population of the equivalent of C-level executives. The few members who have called attention to the issue of Congressional cyber-security have been advised to shut up about it, by whom the reporter did not discover. "Armed with this information about how the virus worked, the security officers scanned the House network again. This time, they found more machines that seemed to match the profile — they, too, were infected. Investigators found at least one infected computer in a member's district office, indicating that the virus had traveled through the House network and may have breached machines far away from Washington. Eventually, the security office determined that eight members' offices were affected; in most of the offices, the virus had invaded only one machine, but in some offices, it hit multiple computers. It also struck seven committee offices, including Commerce; Transportation and Infrastructure; Homeland Security; and Ways and Means; plus the Commission on China, which monitors human rights and laws in China."
Only a paranoid totalitarian state would waste time penetrating Congress. There's not much there that isn't accessible via the news. Anyone who had half a brain would target the Executive branch, where there is data that is not publically accessible.
Silly commies.
HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
All I know is "Made in China" = poor quality.
I now shop at second hand stores to buy better quality than what I can find at the retail stores. Seriously sad.
If someone had told congressmen that buying mass-quantities of Viagra (and Vimax!) from canadian pharmacies was a bad idea, they may not have been exposed to so many security threats...
But what's a horny old-guy to do...
Politics will sooner or later make fools of everybody... - Dick Armey
Any proof about the Chinese origin?
Why not the Italian Mafia, the Muslim Jihad or whatever else?
Sounds more like FUD than real investigation!
Maybe Computers will never be as intelligent as Humans.
For sure they won't ever become so stupid. [VR-1988]
Its simple folks - there is no such thing complete security. Its a negotiation. If you want a sterile network, then neuter it. Congress can be completely free of network attacks if they disconnect from the Internet, and reality....which defeats the purpose. Short of that I think its a fair assumption that information is a virus. We need to understand that on line is like a public restroom in a football stadium. Relative privacy is available, but don't write any important phone numbers on the wall.
Congress overseas ALL of what is going on. That is THEIR job. If the old white house, Pelosi and Reid are dumb enough to use Window boxes, then a lot of information has most likely been sent to China. They will be aware of operations throughout the world (though not necessarily who is in them). Pelosi will have access to very UNIQUE information about NK, Russia, and China that will have been fed to her from CIA, NSA, and NRO. By having access to that info, somebody in CHina or Russia could narrow suspects down. In fact, China has been at this for over a decade. My guess is that they have BEEN narrowing the trap for a long time (or have them).
It is a disaster to America and most likely to the west to have this information get out. Sadly, NSA has been usurp by DHS who is LOADED with total idiots.
I prefer the "u" in honour as it seems to be missing these days.
The number 1 spy in America IS Chinese. They are VERY active. Nearly all of the spies that we have caught over the last 20 years, have been Chinese that are working in DOD or intel jobs who then send back data to mainland. The same is true in Canada, Australia, EU, and I suspect, Russia. Any place that has more advanced military secrets is being actively infiltrated.
Worse, we are not just sending our goods over there and having them come back loaded with virus, we continue to do so even KNOWING this. You may not have liked the tone of the parent, but it was still accurate.
I prefer the "u" in honour as it seems to be missing these days.
All that info can't be kept on random pcs. Depending on the classification, it could even not be allowed to be seen on anything but physically at the computer containing the info. Also, why would her running windows automatically make her computer compromised? Is that an automatic assumption? Oh and by her looks she's probably a Mac User ;p
"...possibly by agents in China, though the attack's origin is uncertain."
Why mention that it was possibly by agents in China when, immediately afterwards, you admit their origin is unknown? They could be agents from Russia. Or Iran. Or Canada. If you don't know, that means they could be from anywhere. Sure, it's fun to paint China as the badguy and gawd knows it's en vogue right now but, if it's unknown who was behind the attack, leave it at that.
Get Jack, They have the CIP Device!
LOTS of information gets out. Far too much. The names of many projects are known all over. What is not known is all objectives, who all is involved (typically, the top person who is running it is known), and all the results. But far too often, congress members are given and sometimes leaked information that does make it on their system. They pass it in emails to each other, etc.
Yes, Windows is the surest sign of an easy compromise. Even this virus was designed for Windows. Nearly all the virus on goods coming from China are for Windows. It will remain that way as long as Windows is easy to crack and dominant. The fact that a number of EU countries, Russia, and China are switching their govs to Linux (and some mac) should have generated LOADS of virus for these systems IF it were easy. Do you see them? NOPE. Get past your silly prejudice and bias and look at the facts. Virus are written for easy targets that yield information.
I prefer the "u" in honour as it seems to be missing these days.
We've had to deal with a number of government agencies where I work. It's not surprising they get hacked. The Defense Security Service, for instance, tried to force us to "get a .com address if you want to interact with our online tools, because .edu addresses are insecure". After laughing to their face it took three weeks to convince them they had no clue what they were talking about. They also asked me to contact them any time we saw "anomalous" traffic on our network. I offered to forward them a copy of the 90% of our packets that are anomalous, but they weren't amused. As another example, the State Department is basing export restriction management on broken Active X that requires users to be Administrators to use. :/ The list goes on.
I was going to go check something on their site, and discovered that it's now running a self signed cert. *sigh* Check out the mission of DSS, and the irony is... scary: http://en.wikipedia.org/wiki/Defense_Security_Service
DSS is tasked with facilitating personnel security investigations, supervising industrial security, and performing security education and awareness training.
Doomed I tell you, doomed.
Imagine the potential for disaster if our elected officials were tech savvy enough to actual use technologies such as "e-mail" and the "world wide web" and that "http" thing!
"You have liberated me from thought."
Only a paranoid totalitarian state would waste time penetrating Congress
So you're saying the US hacked itself?
Hacktivism,
only a bitch would post that a hacker con, got hacked
Congress overseas ALL
I really think we need to cut back on this outsourcing craze. I am not convinced foreign politicians are any more efficient than their American counterparts.
Oh, "oversees"? nevermind.
-
... where X is the closest to rival the power of the US. In the old days, it was always the Russians. Nowadays, it is the Chinese. Now it could very well be the Chinese, but if it was then they did a sloppy job. Infiltrating a computer network using a virus is probably the worst idea in terms of being low profile. Perhaps a passive network sniffer, a backdoor, some MAC-layer attack or just plain old social engineering or spies are much lower profile. By the tone of the original article, I call FUD.
I definitely think it is the greatest chinese spy toy at work here.... the Furby. They are so cute and cuddly (Who would ever suspect cute and cuddly???)... just try to bring one onto a plane as carry on one day :)
"The public security services in China can turn your telephone on and activate its microphone when you think it's off."
Now if only they can emit a tone outside of human hearing and record the echoes to be centrally processed in one massive computer displaying real time video of anyone anywhere in astounding detail.
Actually, I think this is probably too much power for anybody to have. Let's blow it up.
we have always been at war with Eastasia.
Bin Laden is not the enemy we are looking for (*).
* - see http://www.whitehouse.gov/news/releases/2002/03/20020313-8.html
You need to reread the Constitution. Congress does not oversea everything, and that is not their job. They are responsible for legislating (creating laws & regulations, including defining budgets). That's it. The Constitution is quite clear that the role of the Executive branch is to execute those laws (and spend only the money allocated by Congress).
Together, both branches settle their differences in the Judicial branch (i.e. the courts).
This is the beauty of the US Constitution - the founders know that governments are corrupt, and designed a government that would be difficult to completely corrupt (unlike a dictatorship, which while it could be clean, is easy to completely corrupt).
Congress overseas ALL of what is going on.
Sending Congress overseas could SAVE AMERICA.
Rich And Stupid is not so bad as Working For Rich And Stupid.
Wouldn't it be simpler, but not as much fun ( and no challenge at all ), to just buy whatever information you wanted from the lobbyists ?
When people first start taking seriously the spread of organized computer crime, by national and by private groups, it usually appears the Chinese are the root of all evil. Taking into account that China manufactures the overwhelming majority of computer systems and components only deepens this suspicion.
Only with deeper experience do we start to appreciate that China is an easy target and that it's in a lot of other people's interest to reinforce views of China as the world's cyberboogeyman. The Chinese do their share of espionage and they do sleazy things to their citizenry's traffic. But on both fronts they've taken their cues and lessons from the US, which has always had the most active and extensive national criminal espionage operations of any nation. Since the early days of the Cold War, the US has viewed technology as weaponry and has used new exports of technology as platforms for "intelligence" gathering. Even in the cancerous secrecy society Cold Warriors have created and lately expanded, its a matter of public record that the US is the leader in this field of belly-walking endeavor.
On the private side, the chief rival of the US in criminality is not China but tis old playmate from the last century, the USSR remnants. They're trying to rebuild their national sleaze capability, but the collapse has left a ton of ace engineers and programmers with lots of time to think of ways to screw around with networks. They've led the way in using the famously insecure networks of China as gateways to launch quasi-anonymized attacks. Now essentially everyone reroutes their traffic before sniffing, attacking, controlling, etc. It's a favored trick of all sorts of people up to no good to route through China, because no one believes a word the government there says on the subject. Really, the only people with any credibility on these questions of origin are independent researchers - and I don't count any Federal contractors in that group.
This is the beauty of the US Constitution - the founders know that governments are corrupt, and designed a government that would be difficult to completely corrupt (unlike a dictatorship, which while it could be clean, is easy to completely corrupt).
And yet, our elected officials have found many ways to massively -- if not completely -- corrupt the government.
If you want money from Congress, then you will go to their committees and answer questions. ALL of the departments do this today, even DOJ. OTH, if you can operate without a budget, then what are you doing in the gov in the first place?
What did china have to do with anything? There was nothing pointing to them. But hey guilty until proven innocent right? Why not point at non-spy civilian hackers? Congress is a fun target. Or how about one of the hundreds of other countries? What about Israel? Pointing fingers with no proof like this is embarassing /.
This is where I should've made my point regarding foreign IT contracts rather than the open source topic above. At any rate, we've been awarding government IT infrastructure contracts to foreign companies over the last decade. That this might be a problem shouldn't come as a surprise to anyone and should be regarded as criminal neglect by those who've let it happen. As for HBI's assertion that the executive branch is where the goods are, I want to point out that the Chinese and other foreign governments lobby our representatives as much as any industry. They have a huge incentive to gain leverage over them in order to influence US trade and foreign policy. I can't imagine that a US company operating in a similar capacity overseas wouldn't find itself under the uncomfortable scrutiny and manipulation of our intelligence services.
Homeland security was amongst one of the departments within the government to have been compromised...
Are you kidding....of all people to not get caught by the virus or trojan or even hacking, I would think they were the ones to not get hit (along with the NSA).
The geniuses that work in those places would be the first to say
"HEY YOU SHOULD NOT DO THAT....OPEN THE EMAIL ATTACHMENT I MEAN."
If you have too much secrecy it make embezzlement far too easy, and then the criminal can still scream that they are a wronged patriot because the evidence is hard to get to. No matter what you think about selling US weapons to Iran to get funds to supply central american terrorists, we still have a couple of guys (North and Poindexter) stealing from the state for home airconditioning, cars etc.
It's very likely that such a dumb scheme could never have happened with more oversight which is why it was so secret and they got away with petty crime for so long. Keep it in the military or whatever but the oversight is required to stop the damage that occurs when utterly stupid things get beyond control.
It's 100%. The computer virus is now an MS Windows only problem - there are other exploits on other platforms but for whatever reasons all computer virusus out on the net and on media are now only MS Windows compatible.
I misunderstood the exclusion act and just looked it up. Hard to believe that we did that or that I just supported something as racists as that. I have NO desire to exclude ppl based on races, ancestory, etc from America. My interest is in keeping those that want to spy on us away from sensitive areas. China IS spying by sending ppl here to be citizens but are actually spies. We are quietly catching these ppl and sending them back to China. And it does not make the press. Basically, I think that we need to limit the spread of sensitive information more than we do. A great deal of damage has been done over the last 20 years.
I prefer the "u" in honour as it seems to be missing these days.