Slashdot Mirror


Evidence Weakens That China Did the Recent Cyberattacks

click2005 notes an article in The Register calling into question the one piece of hard evidence that has been put forward to pin the Google cyberattacks on China. It was claimed that a CRC algorithm found in the Aurora attack code was particular to Chinese-language developers. Now evidence emerges that this algorithm has been widely known for years and used in English-language books and websites. Wired has a post introducing the Pentagon's recently initiated effort to identify the "digital DNA" of hackers and/or their tools; this program is part of a wide-ranging effort by the US government to find useful means of deterring cyberattacks. This latter NY Times article notes that Google may have found the best deterrence so far — the threat to withdraw its services from the Chinese market.

1 of 197 comments (clear)

  1. Re:The Chinese code matches _exactly_ by the_povinator · · Score: 5, Informative
    To add to this: the analysis on the original "research blog" was also more specific than the register article. He said:

    By decompiling the algorithm and searching the Internet for source code with similar constants, operations and a 16-value CRC table size, I was able to locate one instance of source code that fully matched the structural code implementation in Hydraq and also produced the same output when given the same input

    The Register people seem to have accepted similarity in code, without going to the trouble of checking the outputs.

    --
    The .sig is dead, and I believe I had a hand in killing it.