Vast Electronic Spying Operation Discovered
homesalad writes "Researchers in Toronto have discovered a huge international electronic spying operation that they are calling 'GhostNet.' So far it has infiltrated government and corporate offices in 103 countries, including the office of the Dalai Lama (who originally went to the researchers for help analyzing a suspected infiltration). The operation appears to be based in China, and the information gained has been used to interfere with the actions of the Dalai Lama and to thwart individuals seeking to help Tibetan exiles. The researchers found no evidence of infiltration of US government computers, although machines at the Indian embassy were compromised. Here is the researchers' summary; a full report, 'Tracking "GhostNet": Investigating a Cyber Espionage Network' will be issued this weekend." A separate academic group in the UK that helped with the research is issuing its own report, expected to be available on March 29. Here is the abstract. They seem to be putting more stress on the "social malware" nature of the attack and ways to mitigate such techniques.
the abstract mentions that the attack was done using malwares. Firstly, I expected Chinese hackers (read govt.) smarter than this.
The bulk of Chinese intel is heavily distributed. The world's largest families don't need to rely on 007 agents; they can aggregate huge quantities of data by getting observant volunteers from the chinese diaspora to send bits of info back home through regular channels, like aunt Ping or even uncle James. It's so distributed it doesn't look like spying, and it isn't really, in the traditional sense.
This has driven counterintelligence agencies in 'western' democracies and republics to distraction. There are hardly any spooks to catch, mainly just a giant global gossamer net of informers, and enormous compiling and analysis operations in China. The 'agents', who are barely agents if at all, have strong deniability and can always fall back on complaints of harassment due to ethnic targeting. (Google the issue, it's amusing.)
I think it's brilliant, even if wholly dependent on the chinese sense of family ties. A malware attack is a similar approach: it doesn't look like the work of spies, at first, and it's broadly distributed. So, it's plausible that it could be a chinese intel operation, just from the M.O.
Damn those pesky terrorists
Windows is much more prevalent and the low hanging fruit. I don't think Mac and Linux will be totally ignored, but the bulk of the effort will go where the bulk of the target are, and in a normal office environment that means Microsoft Windows, Office and Internet Explorer.
Learning HOW to think is more important than learning WHAT to think.
How do you think wealth is created? By magic? Hardly: it's by building and selling things to other countries, it's called trade.
This is categorically incorrect. You can create wealth without ever trading with another country on the entire planet. The idea that wealth only comes from a positive current account is a discredited idea that dates back to mercantilism.
You know how you really create wealth? By growing your GDP faster than your population, resulting in a growth in disposable income per capita. It doesn't matter if we're digging holes and filling them again, as long as at least one party in the economy finds this valuable to them.
Let's say I write a book and sell it to you for $10. Then let's say I pocket $2 of that as profit, then turn around and pay someone else $8 to print the book. That person turns around and pays someone else $6 for paper and ink. Etc., etc.
In exchange for your $10, you've made a whole series of people $2 richer, and you now own a book presumably worth $10 to you. That $10 just became $20 of national wealth, by the "magic" of economics. And no other countries were involved, no mining of gold or printing of money, just an input of domestic labor, capital, and resources to provide a product you value.
Economics is ultimately about everyone providing goods and services to everyone else. Money is just a mechanism for keeping score of who owes who what.