Black Duck Eggs and Other Secrets of Chinese Hacks
Roberto123 writes "Network World offers some insights into the way China infiltrates US organizations, physically and via computer, to steal information. Security expert Ira Winkler says there are far more serious threats out there than the 'laughable' uproar over China's hack of Google."
My wife has no problems buying black eggs of any kind in asia stores in Germany. Oh, and black eggs can be mailed long distance, it's fermented and thereby preserved food.
And you really can't conclude from the menu of a chinese restaurant what's going or not going on behind the scenes. I call bullshit on this one. No corporate espionage ring would need to use a "safe house" or "safe restaurant" for that matter to drop off secret information or to secretly meet. It's the information age, dummies!
--- Eat my sig.
And furthermore:
Huh? I can see infiltrating them with spies ... but infiltrating them with people who you will then try to recruit to be a spy?
Isn't that a bit ... stupid?
That seems to be all the evidence needed.
From TFA:
"I can't get black duck eggs in San Francisco, let alone this little piece of crap town in the middle of nowhere." Stan's conclusion was that the Chinese restaurant was a front for a Chinese espionage operation targeting the Fortune 5 business.
Sounds like this security consultant is pretty quick to assume that we need more security. I wonder why.
And it's not just that one restaurant. Check out this menu, something definitely smells fishy about it to me. No doubt it's a north korean spy base.
Why even risk the possibility that one of them will NOT take the offer?
Cut out the middleman and simply send them spies to be hired. Spies who have ALREADY agreed to be spies for you.
Hate to blow you out of the water but the US government does leak private details of foreign companies collected by it's national security agencies. A good example was the US government being caught red handed leaking secret wheat price bids from Canadian companies to local US suppliers collected by the NSA. So if the US is happy to stab a trading partner like Canada in the back what do you think they are doing to none aligned entities like China!
So, you'd say this "security egghead" is a bit of a quack?
(ducks)
Oh, yeah, it's not easy to pad these out to 120 characters.
I find his statement that he can't get black duck eggs in San Francisco, which has one of the largest Chinese populations outside of Asia, hard to believe. I can get black duck eggs here in San Diego, which is a bit of a cultural backwater compared to the Bay Area.
This ain't rocket surgery.
I can get black duck eggs here in San Diego
As if San Diego wasn't home to the largest base of the US Navy! Coincidence? I think not! My rates for security consultation are quite reasonable, I assure you.
Definitely fishy about that menu... IT'S TOO EXPENSIVE FOR A CHINESE RESTAURANT! For $10, (in ANY English-speaking country's currency) that fried rice better be some top-of-the-line rice with corn-fed organic egg cooked to golden perfection!
Seriously though, this article is interesting in 2 ways. 1st, "black duck eggs" may be a delicacy, but it's not that rare nor it is expensive. The only way that it's not in the SF area would be that it doesn't comply with the food safety code, like a lot of Chinese food. (Just because white folks can't stomach our food doesn't mean it's poisonous.)
2nd, I actually talked to a guy who enrolled in a Chinese university for their "spy" recruit. He was there for a year before getting an offer to come study overseas. Sometimes we still wonder if he's still working for their government... Anyway, he was saying how all the guys were really plain-looking, and the girls are hot as hell, and very seductive at that too. SO, what you should be looking out for at your work place are: plain-looking Chinese dudes and hot Chinese girls!
I'm not sure if the author of the article is actually a moron who can't shop and also a complete racist, or smart enough to realize his article would have no readers without putting in a culturally ignorant title, but I'd like to know where the hell he has been shopping in SF.
First of all, you can get black duck eggs damn near everywhere. I can get them in Fremont, Sunnyvale, or Cupertino, California at a variety of locations (Lions, 99Ranch, etc.), and I'm PRETTY sure you'd be able to find it in one of the biggest Chinatowns this country has to offer.
Hell I live in Madison, Wisconsin now and I'm 10 minutes (walking distance) away from a run down Chinese grocery outlet the size of a 7-11 that sells black duck eggs, and two out of the three crappy fast-food only takeout restaurants here serve porridge with black duck eggs.
To use decades old "cultural insight" that black duck eggs are a "Chinese Delicacy" without realizing that within the last two decades foods and goods Chinese people have only heard about in stories have become commonplace items not only in China, but also internationally as exports, is just pathetic.
But I guess there really was no other way to emphasize the ridiculously commonplace adage--that the human link is the weakest in security--without resorting to making ridiculous and dated cultural assumptions.
It's alright that he's not too good with cultures and people I guess. I mean, he's Russian after all, they're only good at math and physics.
The author didn't state it elegantly, but he still made the point -- Chinese industrial espionage is very real, is here now, and it is state-sponsored. China views hacking not only as a fast-track to becoming an industrial superpower, but they view it as a method of becoming a military superpower, too. A good part of China's military buildup involves locating and training talented young people, as well as hiring the already established hacker-underground folk for military purposes. They figure (probably correctly) that they are nowhere near capable of competing with the US military on a technological front, but if they can shut down our command, control, communications, computers, intelligence, surveillance, and reconnaissance (C4ISR) networks (not coincidentally, this is also why they developed the satellite-killing missile), then they have essentially shut us down, especially for any military response to an attack on Taiwan.
Here are just a few examples of the many, many already known about cases of Chinese espionage.
- The infamous Cox Report (regarding the PRC stealing our most advanced nuclear weapon designs)
- The well-known Google attacks
- A Boeing engineer was sentenced to 15 years for espionage, selling rocket technology to the PRC
- The FBI caught an American with very high security clearance and a Taiwanese-American selling classified information about weapon-sales to Taiwan to the PRC.
- The British MI5 released a report detailing all kinds of Chinese espionage. For example, high-profile UK businessmen have been approached by PRC spies with lavish gifts which include USB flash drives infected with trojans to steal information, and in 2008, an aide to Gordon Brown had his Blackberry stolen after a sexy Chinese woman approached him in Beijing -- a classic, almost too classic to be true, Soviet-style tactic. Other diplomats, too, have been sexually blackmailed by the PRC to divulge information.
- Here is a research paper by Northrop Grumman regarding China's cyber-warfare abilities, 88 pages filled with the stuff. Turn to page 67 for a "Timeline of Significant Chinese Related Cyber Events 1999-Present," let alone the details of the rest of the paper which shows the large effort by the PRC to improve their cyber-warfare and espionage abilities.
Here are some more excerpts:
MI5 Report
The MI5 report described how China’s computer hacking campaign had attacked British defense, energy, communications and manufacturing companies, as well as public relations companies and international law firms. The document explicitly warned British executives dealing with China against so-called honey trap methods in which it said the Chinese tried to cultivate personal relationships, “often using lavish hospitality and flattery,” either within China or abroad.
“Chinese intelligence services have also been known to exploit vulnerabilities such as sexual relationships and illegal activities to pressurize individuals to cooperate with them,” it warned. “Hotel rooms in major Chinese cities such as Beijing and Shanghai which have been frequented by foreigners are likely to be bugged. Hotel rooms have been searched while the occupants are out of the room.”
Potential Chinese spy. Potential illegal immigrant. They all look the same to us here in Arizona.
The article basically lays out this argument:
I read the article, expecting at least some cursory information about system cracking techniques that have been detected. Instead, there's just this vapid paranoia that Chinese people may be up to something. It smacks of racism.
The same company had financial help building and running a motel nearby in Fremont where some of their customers stayed, but it also many other business people meeting with various companies. The motel was bugged, I was told by a close Chinese-American friend in the semi company. The semi firm got the customer private conversations and I think phone conversations.
In another case, an Israeli telecom chip company was designing software that is used in many datacom systems through which a LOT of US packets flow. I heard that there were backdoors in the hardware/software systems they sold to major communications operators. Some of us non-Israelis knew that Mossad ran some of the people in the company, but what could we do about it? The company got financial backing from Israeli intelligence but it would have been hard to prove since it was run through the Cayman Islands.
A lot of designs and technology have been pirated by Chinese, Taiwanese, and other governments. It's somewhat common knowledge here. And there are some very worrisome backdoors, for example the known sly replications of chips used in routers but with additional logic for remote access. The US military is well aware of this and there have been published stories about it. Just because the black egg story has credibility issues doesn't mean others aren't more solid.