Foreign Hackers Attack Canadian Government
An anonymous reader writes " According to the CBC: 'An unprecedented cyberattack on the Canadian government from China has given foreign hackers access to highly classified federal information, and forced at least two key departments off the internet, CBC News has learned. The attack, first detected in early January, left Canadian counter-espionage agents scrambling to determine how much sensitive government information may have been stolen and by whom.' It should be noted that the Auditor-General warned of this months ago and was ignored by everyone as she usually is. It should also be noted that public sentiment towards China is getting very, very testy."
Great way to get yourself banned from the playground.
This can't happen overnight... it already owns too many balls, not to mention the playground and some referees... better get used to how the game is played nowadays.
Questions raise, answers kill. Raise questions to stay alive.
All the news of China's hacking attempts, compounded with the links many of those have to government, begs the question: "How far is too far?" When will the US (or the international community) hold China accountable and force them to stop these actions? The way I see it, what they are doing is worse than firing shells over a border. This could easily be a buildup for a larger attack, yet no one has done anything substantial yet.
"Going to war without the French is like going deer hunting without your accordion." ~General Norman Schwarzkopf
What did the steal? Their recipe for maple syrup?
This attack could have been EASILY avoided using 1 simple system: PGP digital signing. Give every government address a PGP key and set up a government public key repository. Any company doing work with the government has no excuse for not being able to do the same.
You then set up the email servers to block any email with attachments that isn't signed by a trusted key.
PGP signing (and even encryption in most cases) is so pathetically easy to set up, the fact that governments don't MANDATE it for internal use (and even external use for anything other than simple civilian inquiries) is absolutely unforgivable.
Canada's largest export partner is the US, the second is Europe(all). All of Asia combined ranks 3rd, but we still export more materials to Japan and India than China. Unless you're counting either coal, or nickle. Really if you eliminate Canadian resources? The world goes for a shit spin, mighty fast because ~30-35% of the market just went poof.
Really though? If China pulls shit and we take our ball and go home, not much will happen in Canada. We have other markets(south america, and russia--along with various others not mentioned) which we can continue to supply goods to. It will hurt china more, than it will hurt us.
Om, nomnomnom...
Well the first part is by and far true. We don't make enemies, hell we're the first ones the world runs to when they want mediators. Probably that whole, slow to anger, stubborn, type of thing. However, unlike in the US where shit hit the fan several times, over several things. And Americans went WTF, HOLY SHIT, CHINA...what the hell are you doing?
Canadians went...eh...okay. Dead? Nope. Carry on, government to do a better job. People as a whole here don't get angry quickly, over anything. And it takes a lot to push the general public over the edge on something. Either it has to have dire ramifications and is so fucked up for everyone(UBB is a fine example), or a lot of people have to die because of government stupidity(air india). People are getting pissed off at China here, it's taken a lot of really hard work to get people here angry. And that's saying something.
Om, nomnomnom...
> This attack could have been EASILY avoided
> using 1 simple system: PGP digital signing.
The Canadian government is in the process of rolling out a digital signature system... unfortunately, it's Entrust rather than an open solution like PGP, and it looks like it's going to be cumbersome enough that it won't get used in situations it's not absolutely necessary for.
Because it's not based on open standards it can't be used for external communications which makes it rather infeasible to block all unencrypted attachments. Which would be a bad idea, anyways, given the small fraction of "protected" information on unclassified networks (i.e. ones which communicate with the outside world).
Log in or piss off.
Which part of the country do you live in? In general it seems you're correct. However it's worth mentioning that out here in the frozen prairies much of the current economic strength, especially in Saskatchewan, has been coming from potash. You can't hear a discussion about potash and not hear China mentioned at least once, China is a huge buyer of the potash produced here. The price of potash has gone up significantly in recent years and they rely on it. Having China refuse to buy potash might not hurt people out in the east, but in the prairies we certainly would be impacted by it.
Well, it's a language barrier thing. Canadian for "fuck off" is "would you please consider leaving at your convenience?" :)
Well, it's a language barrier thing. Canadian for "fuck off" is "would you please consider leaving at your convenience?" :)
As a Canadian, this comment offends me. Sorry about that.
They say a little knowledge is a dangerous thing, but it's not one half so bad as a lot of ignorance. - Terry Pratchett
As one Canadian to another would you please consider leaving at your convenience?