US Inadvertently Enabled Chinese Google Hackers
Phrogman writes "In this CNN article by Bruce Schneier, he states that the US Government inadvertently enabled Chinese hackers access to Google's Gmail. The article states 'Google made headlines when it went public with the fact that Chinese hackers had penetrated some of its services, such as Gmail, in a politically motivated attempt at intelligence gathering. The news here isn't that Chinese hackers engage in these activities or that their attempts are technically sophisticated — we knew that already — it's that the US government inadvertently aided the hackers.'"
Update: 02/22 20:26 GMT by S : As readers have noted, Schneier said not long after he wrote this article that he no longer thinks this is what happened.
Proud computer experts of China,
We were made aware of your recent exploits concerning Google and a number of other Western corporations. We know that you have the facility to go after bigger and better targets, so why not go after the U.S. government itself? Instead of hacking Gmail to read average citizens' e-mail, you could go after congress and deliver to us their damming communiques. We want to know all about their marital affairs, business dealings, money streams, and even their bowel movements. We want them to know that they are being watched using the very systems they voted to put into place. We cannot do the same, for our society is becoming repressive and average citizens are being tried as war-criminals if not tortured detained indefinitely without trial.
You can do it. We understand that your government tacitly condones your hacking actions against U.S. interests. Google is your friend. The United States government is your enemy. Google will publicly condemn China and cause it to lose business. The U.S. government will not release public statements out of fear of humiliation, so they will not affect Chinese business. Get into their computers, post their secrets on Wikileaks, and you will be our heroes. After exploitation, publicly supply the methods of exploitation to humiliate our government. Our government are out of touch with reality and are stinking drunk with power and the money earned with capitalistic corporate greed. You must become heroes of the people. Not just your people, but the people of the world.
http://livingwithanerd.com/wp-content/uploads/2010/02/TerroristsHateFreedom.gif
That is all.
Living With a Nerd
I don't see how doing what is required to not be put in prison, is "inadvertently aiding" anything.
I want my ad impressions back :P
Why would you use GMail to do anything private? You're already trusting Google and the NSA, and they are more likely to want to interfere in your business than China.
This is a month old, and Schneier has since backed off this assertion.
This is something that Schneier has insinuated but provides no proof or detail about this " US backdoor access" at all.
I'm calling bullshit on this one. Where is the evidence for his claims? Has anybody at Google confirmed such a system exists?
The original essay, linked to in TFP, is dated January 23rd; the update I quote from is from February 8th.
Carousel is a lie!
Arm the penguins and let Linus sort 'em out!
..should be: "Repeal CALEA."
As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
When it comes to data:
To PROTECT it,
Don't COLLECT it.
The chinese probably called up Googles secretary, and talked her into giving them their password (ChuckNorris).
Who would win this election: Andrew Weiner vs Andrew Weiner's weiner.
Every time I read something about China I can hear that freakin' bulldozer saying; "Building the Chinese empire" or "I build for China".
"The laws of science be a harsh mistress." --Bender
In order to comply with government search warrants on user data, Google created a backdoor access system into Gmail accounts. This feature is what the Chinese hackers exploited to gain access.
Put on your tinfoil hats people!
Not only is Google working WITH the government, they're doing a sloppy job of it!
...is the fact that 30-some other companies -- companies without any such lawful surveillance facilities -- were also compromised as part of this Chinese operation, and all accounts indicate it was via 0-day vulnerabilities in IE and JavaScript-enabled PDF documents, not via any mechanism to enable surveillance intercepts.
This was Schneier using the incident as a platform to grind a political axe (probably based on a bogus tip), from which he wisely backed off.
Presuppositions. Or unstated assumptions.
The largest prime factor of my UID is 263267.
Every article I have read that explains who committed the hacking, how, and why has been an opinion piece, and ends with "the opinions expressed in this commentary are solely those of X". I have no problem with this per se, but we should all take it with a grain of salt; Slashdot should preface it's headline with "Theory:" or "Opinion:".
I prefer my news to be my news, and my conspiracy theories to be my entertainment.
Why bother having a summary when it adds nothing to the headline?
Fuck systemd. Fuck Redhat. Fuck Soylent, too. Wait, scratch the last one.
That is exactly correct.
Unfortunately, too many people see this as a reason to prevent the wealthy from "gambling" (ie: investing). It's not the gambling/investing that is the problem.
Example: If General Motors can not pay it's bills, then it should file bankruptcy just like any other company in the world. The unions are the reason it got bailed out and they are the pinnacle of cronyism.
you are too prejudiced. Evidence? Click the link given in the summary. In the CNN article that comes up, go to the paragraph that starts with "And surveillance infrastructure can be ...". Hover your mouse over the link labeled with the word "helped". Your browser's status bar will tell you that it links to yet another article about China's surveillance. You won't open an article that supposedly talks about such an "obvious" thing. But only when you click that link, you will know that it doesn't exist. Apparently, the CNN propagandist is an expert who is aware that you won't click the link. But that is not the issue here. The fact that nobody complained about this, either in the CNN site or here on Slashdot, tells volumes about how prejudiced the public is and how badly the propagandists are exploiting it.
The largest prime factor of my UID is 263267.
The summary uses the phrase "we already knew". Who knew? and how did they know?
The largest prime factor of my UID is 263267.
How the news media portrays 'chinese hackers' as this hugely sophisticated bunch launching attacks, when in fact if you leave a door unlocked a fucking child can open it.
It's all a front to take your civil liberties anyways.
http://tech.slashdot.org/story/10/01/24/1518213/Surveillance-Backdoor-Enabled-Chinese-Gmail-Attack
the banking system bubbled and bursted a number of times in the 1800s-1920s, because it wasn't regulated. so the government came in and regulated it. it bubbled and bursted again in 2007 because the government was hard at work REMOVING regulations for a decade before that
and then idiots like you come along and go "look, the government is involved, so its all their fault"
the only thing at fault in the government is idiots in the government who think the solution is less government
you WANT heavy government regulation for a healthy functional economy. simple solid fact
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
All this mess for an "undisclosed vulnerability in Internet Explorer 6".
WTF! Still using it? Google employees or anyone else? You deserve it!
Yeah, right....
Did anyone else notice the banner in the article is completely shopped?
I'm sorry but Communism is IMHO a scourge and a threat and always will be!
Anybody remember "Die Yankee dog, running dogs of imperialism!", I do.
I killed da wabbit -Elmer Fudd
Armstrong and Aldrin safe on the moon... /.
haha I scooped
here is that the affront to our freedoms here enables the Chinese to squash those advocating Chinese freedom.
Slashdot never even pretended to be journalists and to check spelling, facts, etc. but it is now beyond a joke. Will EVERY story now come with a "this turned out to be bullshit" disclaimer ?
the retarded libertarian mantra is the market polices itself
bullshit
the truth is that some assholes notice natural imperfections in the market, and exploit them
furthermore, smaller players are not on the same footing as larger players. the free market fundamentalist delusion is that without government, everyone will coexist in equality. when the simple truth is, smaller fry are abused by larger fry UNLESS a strong regulatory policing governmental force keeps thing equal
but no, all these ayn rand naive philosophy students with dreamy ideas and no fucking real world common sense imagine themselves to be one of the big guys, and they clamor for their right for coexist with the big guys as equals. its some sort of mass delusion. when the simple truth is, they aren't big, they just have big heads, and they merely fight for the "rights" of entrenched economic class structures, rather any sort of equality. all of their libertarian mantra serves to keep the rich rich, the poor poor, and themselves ignorant. there is no equality in libertarianism. well, there is, in all of the propaganda, but no equality in the real world effects of the idiotic philosophy. libertarianism is the mirror image of communism, and is equally stupid
for the clean functioning of a healthy capitalist system YOU NEED A STRONG GOVERNMENTAL REGULATORY FORCE. iron clad rock of gibraltar fact
if that makes some assholes whine about having to deal with red tape, well, now you know what it means to have no red tape: the implosion of 2008. so live with the fucking red tape already and shut the fuck up because now you've learned your lesson the hard way, fucking morons
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
guess this means I enable muggers by walking down the street with a cell phone and mp3 player.
Be seeing you...