Slashdot Mirror


JP Morgan Chase Breach: Shades of a Cyber Cold War?

TheRealHocusLocus writes: The New York Times is quoting "people briefed on the matter" who allege that the JP Morgan data thieves "are thought to be operating from Russia and appear to have at least loose connections with officials of the Russian government." The article suggests it could be retaliation for sanctions. Personally, I'm skeptical — I've seen the former Soviet Union evolve into an amazingly diverse culture that is well represented on the Internet. This culture has grown alongside our own and runs the gamut of characters: tirelessly brilliant open source software developers, lots of regular folk, and yes — even groups affiliated with organized crime syndicates. This is no surprise, and these exist in the U.S. too. Are we ready to go full-political on this computer security issue, worrying more about who did it than how to protect against it in the future? How do you Slashdotters feel about these growing "tensions," and what can we do to help bring some reason to the table? The article also notes that the same group responsible for the breach at JP Morgan Chase was responsible for attacks on 9 other financial institutions.

96 comments

  1. All is fair... by BringsApples · · Score: 1

    ...in love and war.

    --
    Politics; n. : A religion whereby man is god.
    1. Re:All is fair... by koan · · Score: 1

      All is vanity.

      --
      "If any question why we died, Tell them because our fathers lied."
    2. Re:All is fair... by BringsApples · · Score: 1

      "All is fair in love and war" can mean anything you want, but here, it would be wise to look at it to mean, "Inspire love rather than war".

      So many groups of people aren't satisfied with the current configuration of the financial institution that the US harbors, because it's a debt-based system whereby many many more are in debt than are not.

      --
      Politics; n. : A religion whereby man is god.
    3. Re:All is fair... by koan · · Score: 0

      I'm sure this will go over well... (sarcasm) if you read nothing else from the Bible, read Ecclesiastes.

      Or did you actually mean to reply to the OP?

      --
      "If any question why we died, Tell them because our fathers lied."
    4. Re:All is fair... by TheRealHocusLocus · · Score: 1

      Remember wise old Solomon
      Recall his history
      He was the wisest man on Earth
      And so he cursed the day of his birth
      He knew that all is vanity

      So not much fun was poor Solomon
      Now most of us would agree
      We are not much better off than he
      His brains it was that put him on the spot
      I thought that brains were good--- Guess not!

      ~Threepenny Opera

      --
      <blink>down the rabbit hole</blink>
  2. Betteridge's law of headlines by Anonymous Coward · · Score: 2, Insightful

    no

    1. Re: Betteridge's law of headlines by tysonedwards · · Score: 1, Insightful

      Don't be daft. Everyone has at least a loose association with a government official, and that's what's being asserted here. A friend of a friend was a Russian Government official, thereby the whole thing must be their fault! Couldn't possibly be that it was "because we could", or "because it looked like easy money", or "because they were acting in a criminal syndicate"... Nope, we need a new enemy and ISIS isn't scary enough and China owns too much of our debt, so Russia it is!

      --
      Thirty four characters live here.
    2. Re: Betteridge's law of headlines by Anonymous Coward · · Score: 0

      That's my point here. I didn't RTFA as per /. standards, but from the summary, it all seems like a conspiracy theory without anything as much as the slightest evidence. I don't know if TFA explains anything (again, I didn't read it), but the summary is there to be a, well, summary of what the article is about. The submitter is even "skeptical" about the whole issue. TL;DR: I'm not clicking this bait.

    3. Re: Betteridge's law of headlines by TheRealHocusLocus · · Score: 1

      The submitter is even "skeptical" about the whole issue.

      Hello. I'm more than skeptical, I find it alarming. It's Orwellian. Because I remember a time when the US and USSR were one provocation away from open conflict. And as we all knew at the time it would have been ugly and global. I remember when newspapers went out of their way not to even appear to be inviting or inciting conflict. The New York Times now considers itself to be an ankle-biting attack dog for the Obama Administration. They're proud of it. It would merely be pathetic if one could find humor in there somewhere.

      What if the attack had appeared to originate from IP address ranges in the UK? Would the Queen's photograph be on Drudge, and would the NY Times accuse Her Majesty's government of hooliganism, or would the reporting take on a whole other angle? Would Drudge dip into his stock photo bin and retrieve some generic 'hacker' illustration instead? They need to consider that, and ask themselves why the response would be different.

      People need to ask these questions. It is not enough to shrug off Yellow Journalism when it touches on things that really matter. There must be an appropriate response, even if it is some sort of dialogue taking place elsewhere, such as on the net. Otherwise we run the risk of being carried along (towards war, for example) with people who do NOT question these things.

      TL;DR: I'm not clicking this bait.

      Too bad no one showed up when you held that March For Apathy. Oh darn--- I was just one click short of earning a free bicycle from the New York Times affiliate program! Curses, foiled again.

      --
      <blink>down the rabbit hole</blink>
    4. Re: Betteridge's law of headlines by cavreader · · Score: 1

      About the idea of China owning much of the US debt. Over 80% of the national debt is owned by the US Federal Reserve. The remaining debt is parceled out in bonds and investment certificates to countries and regular people. China and a lot of other countries stash large sums of cash in US financial instruments. The US is recognized as one of the safest and stable places to invest their money. And in the unlikely event that the US and China were to start a war or do anything else that pisses off the US government their assets can be frozen with a signature.

    5. Re: Betteridge's law of headlines by Anonymous Coward · · Score: 0

      assuming you could even tell which ones they owned...

    6. Re: Betteridge's law of headlines by Anonymous Coward · · Score: 0

      And our asses can get nuked with the push of a button, or invaded by a million soldiers on a whisper...

      Your point?

    7. Re: Betteridge's law of headlines by cavreader · · Score: 1

      Other than the US embassy what property or bank accounts could China freeze to seriously harm the US? And for a million soldiers to get any where close to the US they would have to execute the "million man" swim to get there. One word: logistics. Geography has always given the US an advantage. There is not a single country on the planet who can project military power any where in the world on a moments notice except for the US. No other country has as many foreign military bases around the world as the US. Bases that are there because the foreign governments have welcomed them for various reasons. Bases that were built after WW2 to place trip wires to deter potential aggression against US allies. SK is the best example.However, the US has always vacated any base were the host asked them to. The Philippines are sort of regretting their decision as well as Iraq. And in the event that things get really out of hand a nuclear war would devastate all sides so there is really nothing to talk about in that dismal case. If missile defense technology continues to advance to the point of rendering ICBM's and cruise missiles useless we could see another non-nuclear WW3 in the future.

  3. Classic case of not owning the problem by Anonymous Coward · · Score: 1, Insightful

    Just as most other organizations that have been hacked and made public, I'm sure they (JP Morgan Chase and associated entities) would love to blame this on some "advanced", "state sponsored", or other threat they claim was unrealistic to defend against. They will claim they spend a lot of time and money, and they still got hacked. In reality, they simply use the "time and money" as as plausible deniability. They are making so much money off their "customers", they could care less about security. It's all about dodging responsibility when something happens.

  4. um by Charliemopps · · Score: 1

    I think someone doesn't know the definition of "Cold war"
    Given that this story is about an actual attack, that would lead me to believe this is a "hot" war.

    1. Re:um by Anonymous Coward · · Score: 0

      I think someone doesn't know the definition of "Cold war" Given that this story is about an actual attack, that would lead me to believe this is a "hot" war.

      I think that someone is you. There were "actual attacks" all through the actual Cold War. The difference between a hot war and a cold war is that during a hot war people do very little prevarication about who's responsible. For example, note that Ukrainian separatists openly boasted about blowing a plane out of the sky when they thought that it was a Ukrainian plane. They didn't start lying about it until they found out that it was a Dutch passenger plane. Cold war attacks are like that from the beginning. They didn't happen. If you can prove they did happen, we didn't do it. We don't know anything about it. If you can prove we did it, then it was a mistake. Also, this is not what I would describe as an actual attack. There were no boots on the ground. No weapons fire. No one died. Economic sabotage is exactly the kind of thing that happens during a cold war precisely because it is easily deniable. This could be a directed attack or it could just be some crooks looking to make money. Did Putin ask for this? Did some middle level member of the government suggest it to an old friend from the KGB days who is now in the Russian mob? Did a patriotic member of the Russian mob come up with the idea without help from any member of the government? Jack Ruby had mob ties. Was the Lee Harvey Oswald assassination a mob hit? If it was, did that mean that the Kennedy assassination was a mob hit? This is not exactly smoking gun evidence here. This is the kind of evidence that is processed at the beginning of an investigation to suggest avenues for further investigation.

    2. Re:um by Anonymous Coward · · Score: 0

      The Harvey Oswald thing smacks like a Russian-American co-project. Given that the guy was first a radar operator, then married a Russian girl, lived in Russia and then cam back to America.

    3. Re:um by TheRealHocusLocus · · Score: 1

      The difference between a hot war and a cold war is that during a hot war people do very little prevarication about who's responsible. For example, note that Ukrainian separatists openly boasted about blowing a plane out of the sky when they thought that it was a Ukrainian plane. They didn't start lying about it until they found out that it was a Dutch passenger plane. Cold war attacks are like that from the beginning. They didn't happen. If you can prove they did happen, we didn't do it. We don't know anything about it. If you can prove we did it, then it was a mistake. Also, this is not what I would describe as an actual attack. There were no boots on the ground. No weapons fire. No one died. Economic sabotage is exactly the kind of thing that happens during a cold war precisely because it is easily deniable.

      Well said. Spoken like an old school CIA analyst. To clarify for the three-letter gubmint haters out there, that is high praise.

      I see a Cold War as a sort of heavy mechanical 'flywheel' that begins to move because it is fed with an assortment of motive and sentiment. It may be started by some actual conflict such as competition for resource or political influence in contested regions, or difference of ideology and the merest suspicious of intent of conquest... it feeds also on distrust... but once it gets going it becomes an object used by both sides to acquire 'ways and means'. It is a funding machine, a hate machine. It supplies momentum and drop-in motives for anything one would wish to allege or ascribe to the 'enemy', even false flag operations. It can win or upset elections. But this is key: once all parties involved gain their footing, all parties involved find ways to make it useful to them. A Cold War is as lucrative as a successful corporation, as threatening as an invading army. It is a shadow-construct that spins off fear and loathing. The Cold War itself is easy to create and cheap to maintain. The true cost of weaponry is not what it costs to make--- it's the cost and effort put behind keeping people convinced that it is necessary. Cold Wars deliver this justification cheaply, for years. They can do this because they thrive on acquired personal prejudice and pride in one's own opinion, which can last a lifetime with little external input. It thrives on and depletes the same cultural energy people would otherwise spend reaching out in curiousity, seeking opportunities that promote cooperation and generally improve life.

      I could call it a vampire squid, but the term is taken. Suffice it to say, fuck Cold Wars.

      Cold Wars also promote false flag operations because they subvert healthy skepticism. Back in the "good old days ha ha", no terrorist organization would act without ensuring that they claim responsibility in a way that was incontrovertible. This took the form of a telephone or fax delivered to news media just before or at the moment the event occurred. You'd think anyone with a cause would want to ensure that the world knows who is responsible, and why, right?

      Something awful happened to the human race between 1970-1980, a real IQ drop. Terrorists stopped calling and claiming responsibility in ways that were verifiable. There was a time--- believe me--- when no self-respecting news organization would even publish a claim of responsibility that had been received after the event. Now not only do they publish any rumor they hear (especially if it pins the act on an evil empire)... what's worse, they are slobbering at the feet of "confidential government sources" and printing it word for word without analysis or even speculation.

      The Internet is the best antidote human kind has created to oppose their formation. Oh yeah, it can be used to spread and replicate crap with blinding speed and easily manipulated (I prefer to call them un-vested persons) can create a storm... but it also keeps tyhe lines of communication open for more productive or truthful messages once they arise. The New York Times does not even seem to know what it is doing, that's the saddest part. Perhaps all the adults have left the building.

      --
      <blink>down the rabbit hole</blink>
  5. Loose connections? by rduke15 · · Score: 1, Interesting

    appear to have at least loose connections with officials of the Russian government.

    I thought any important criminal gang in Russia had much more than "loose connections with the gorvernment.

    1. Re:Loose connections? by Anonymous Coward · · Score: 0

      In Soviet America all the important white collar criminal gangs have much more than "loose connections" with the gorvernment. Thank you, thank you. I will be here all week, the roast beef is excellent and try the salad bar your heart will thank you.

  6. Corporate Wars by JimSadler · · Score: 4, Interesting

    How long before we see corporations forming hacking groups off shore dedicated to destroying competition by breaching security and causing chaos? Causing chaos to a competitor is one way to steer profits towards a companies cash registers. Can't you see Burger King trying to wipe out McDonalds?

    1. Re:Corporate Wars by CaptainDork · · Score: 1

      I agree with you, but a question I'm more concerned about is, "How long before we see corporations tighten up their stuff?"

      Personally, I don't see that happening until some major lawsuits are filed.

      --
      It little behooves the best of us to comment on the rest of us.
    2. Re:Corporate Wars by koan · · Score: 1

      This has been going on as long as the Internet has existed, you are a bit slow on the uptake.

      --
      "If any question why we died, Tell them because our fathers lied."
    3. Re:Corporate Wars by sgt_doom · · Score: 1

      You're not particularly current, dood, it has been going on for quite some time now.

    4. Re:Corporate Wars by BringsApples · · Score: 1

      I like the way you think, because it's insightful. But in this case, who would be the competition to The Federal Reserve?

      --
      Politics; n. : A religion whereby man is god.
    5. Re:Corporate Wars by Anonymous Coward · · Score: 0

      Essentially, they CLAIM the Russian state is the opposing side to the Federal Reserve. But would that make sense and WHERE IS THE PROOF ? These folks lie when they fart, so we have to assume another shitload of LIES.

    6. Re:Corporate Wars by mlts · · Score: 2

      Here is the problem rearing up with two nasty heads:

      The first is that security has no ROI, and has a relatively trivial financial cost. A major breach happens, a company feeds a PR firm some cash, says they boosted security [1], they toss all affected a year's subscription to some monitoring service, and that is that. Come a lawsuit, there isn't much to sue because they can easily throw their hands up and say that the hackers would get through anything.

      Which brings up the second point. In the 1990s, a rogue Internet site could be pulled from the net. Now, doing that is tantamount to an act of war, similar to blockading a port with a naval force. So, no matter what, there is no shutting down blackhats. IP blocks can be worthless since it just takes a compromised computer to bypass them. So, eventually the bad guys will find a way in.

      Want an actual solution to the hacking problem? Banks need to create a separate network that uses dedicated physical links that is not connected to the Internet, and if it is, it is connected via application firewalls. Machines are keyed to only be able to connect with other boxes in a pre-arranged manner. If box "A" wants to connect to box "B", it needs to be registered beforehand, or the central switch fabric will deny it. Built into the fabric would be the ability for the central switching fabric to completely lock a box out at the L1 level, so a DoS is stopped.

      Yes, this sounds Draconian, and puts power into a central place... but this isn't the Internet we are looking at, but a private network between banks, banks and credit card processors, and other entities. With this in mind, the actual machine NICs could be made with tamper-resistant chipsets, public keys, and authorization can be done via a PKI system.

      Higher layers could be controlled by the individual institutions, so that even though L1/L2 traffic is handled by a central authority, application permissions can be controlled on a per machine basis with whitelists. That way, if the central authority is compromised, machines are still secured. Spoofing is protected, since public key fingerprints would be used as a part of a box's IP and stored on a HSM on the interface.

      This is nowhere near 100%, but what it means is that there is not just an open network for someone to go after a site. To access a bank, it would require a compromise of an extremely hardened CA and a L1 ISP (both the keys authorizing machines to communicate and the actual WAN switching fabric, which could be kept completely separate from each other.) If a breach happens, it can be fixed fairly rapidly, and a site failing to address it would be disconnected from the WAN.

      In general, not a 100% secure solution, but this gives three benefits. The network is separate, so for any mischief to occour, it require compromise of the core fabric. Then, individual hosts will have to be attacked, and with contract stipulations mandating a high level of security, this would be difficult. Finally, sites that are too lazy to keep current with security advisories would have their access pulled as part of being on this network.

      This is pretty much done with NIPRNet and SIPRNet, so why not a similar WAN mechanism for businesses and finance.

      [1]: The security "boost" could be another checkbox ticked off in a GPO object applied to the ass end of the company, so that passwords are needed to be changed every 60 days instead of every 90. Yep, a security boost.

    7. Re:Corporate Wars by Deadstick · · Score: 1

      And this would be a bad thing how?

    8. Re:Corporate Wars by CaptainDork · · Score: 1

      I'd mod you +1 if I could. Well said.

      --
      It little behooves the best of us to comment on the rest of us.
    9. Re:Corporate Wars by eric_harris_76 · · Score: 1

      That was sarcasm, I assume. (But thanks to Poe's Law, I don't put much confidence in that assumption.)

      We do all know that the movie "Demolition Man" was fiction, right?

      --
      There's no time like the present. Well, the past used to be.
  7. Worry less about motive - worry about apathy by QuasiSteve · · Score: 4, Interesting

    http://www.bloomberg.com/news/...

    tl;dr: People think it'll happen at other banks anyway, plus it costs money to change banks, thus they don't care enough and stick with Chase (JP Morgan).
    And, naturally, how does the stock market react to that? "The bankâ(TM)s shares climbed 2.5 percent to $60.30"

    Start making people care that a company they do business with has been hacked, maybe then people will actually bother to worry about motives.

    1. Re:Worry less about motive - worry about apathy by Anonymous Coward · · Score: 0

      I came to say this.

      The fact that they got in *AT ALL* is a problem. I dont care who did it.

      These banks have become computer nightmares. One bank in my area has merged about 5 times since I moved here about 15 years ago. They currently have 30k in servers. There is no way they can control that. They offer so many products they do not even know what they offer. They run the gamut from windows nt4 thru windows 2012 to various levels of bsd and linux. Of course there are holes. They have too many servers to know what has what patches.

      These banks getting hacked does not surprise me. It pisses me off actually.

      After trying to use an ATM outside of my bank and saw it was an XP shell I went inside to get my money. They were surprised 'why didnt I just use the ATM outside' 'because XP is insecure' 'Oh I dont know anything about that it should be fine though'.

    2. Re:Worry less about motive - worry about apathy by matthekc83 · · Score: 2

      I would like to be able to care less. We need to get the ssn to have a changable security pin attached to it. It looks like your information has been compromised sorry you will have to change your pin... darn.

    3. Re:Worry less about motive - worry about apathy by Anonymous Coward · · Score: 0

      Start making people care that a company they do business with has been hacked, maybe then people will actually bother to worry about motives.

      No, people should NOT care. The banks should care, and making the banks liable will motivate them to fix security, without having to change public opinion.

  8. Can We All Just Get Along? by MellowBob · · Score: 1

    No.

    1. Re:Can We All Just Get Along? by drpt · · Score: 0

      we don't use money here (do you hear the banjos?)

      --
      Proudly Butchering code for 20 years
  9. FUD. They don't even know. by Vokkyt · · Score: 4, Insightful

    From the article:

    "But much remains unanswered about the intrusion, including just who the hackers are, which other financial institutions were hit and why the hackers went down a path inside JPMorganâ(TM)s computer system that contained troves of customer information, but not financial data."

    They have no motive, no indication of who, or why they did what they did. I agree with posters saying that it's officials throwing out a red herring to get everyone worked up over Russia instead of poor security.

  10. Boot them from the Swift system for a few weeks by EmperorOfCanada · · Score: 1, Interesting

    If this turns out to be provably true then an easy solution would be to boot Russia from the swift system for a few weeks. That would basically mean that no international transactions could take place large or small. Or if they wanted to make it interesting they could restrict swift transactions to minor amounts so that the very richest would be impacted while the average Russian would feel a lesser impact.

    But large food importers and whatnot would be massively impacted.

    But before this can be done Europe needs to find an alternative to Russian Gas. But when Europe does then they won't tolerate Russian shenanigans for 1 second.

    The key is that any retaliation needs to hit those around Putin who can change their mind about his being in power. The average Russian on the street will choose Putin over the West nearly 100% of the time.

    1. Re:Boot them from the Swift system for a few weeks by Anonymous Coward · · Score: 0

      But before this can be done Europe needs to find an alternative to Russian Gas. But when Europe does then they won't tolerate Russian shenanigans for 1 second.

      Russia's military buildup of the last years strongly suggests that if Europe were to stop buying Russian gas, the current Russian leadership would sooner invade a number of Eastern European nations to force them to remain customers than give up their hold on power or allow the country to go bankrupt. Of course Russia would leave Germany alone, but the Baltics, Poland and Romania would be easy pickings, and Slovakia and Hungary would readily collaborate. NATO looks increasingly to be a paper tiger, and the US public is unlikely at this particular time to accept involvement in a major conflict on foreign soil that could swiftly escalate to nuclear war.

    2. Re:Boot them from the Swift system for a few weeks by koan · · Score: 1

      Or maybe we can goose step Dimon to jail, and burn JPMorgan to the ground financially.

      --
      "If any question why we died, Tell them because our fathers lied."
    3. Re:Boot them from the Swift system for a few weeks by hjf · · Score: 1

      Argentina has VAST reserves of gas and oil. They just don't have the money to exploit them.

    4. Re:Boot them from the Swift system for a few weeks by Bob_Who · · Score: 1

      Or maybe we can goose step Dimon to jail, and burn JPMorgan to the ground financially.

      Now that's the first pertinent response I've yet heard.

      Why should we trust anything JP Morgan says when they are proven liars and frauds and they are protected by policy. The fact is that bank robbery has been conveniently been redefined as identity theft, therefore JP Morgan has less at stake when they say this happened. One minute they're secure, the next, they're not but they can point to the perpetrators with certainty. Yeah right, I trust them, its the commie gangster's fault. Not one US Banker has taken the fall yet, but we're supposed to blame Russia for our fucked up security and banking laws. Eric Holder will no doubt be well paid for his epic failure. Its unbelievable how distracted and hypnotized Americans have become lately. Common sense has eluded us. If we won't toss Dimon in jail then lets just make him President or drop him from B-2. Its really getting absurd. Russia is not our enemy, our policy is the problem we need fix first and foremost. WAKE UP AMERICA!!

    5. Re:Boot them from the Swift system for a few weeks by Anonymous Coward · · Score: 0

      And why would Europe trust Argentinian gas when Argentina illegally nationalised parts of a Spanish oil company and is trying to constantly inflame tensions with Britain by making claims on islands which it has no legitimate claim to?

      Switching to Argentinian gas would be no better for Europe than Russian gas. Europe would be better off just doing away with nearly all fossil fuels with more wind, hydro, nuclear, and solar then just exploit the likes of Poland's shale reserves and North Sea Oil/Gas for what little oil and gas it does actually need.

      No point being dependent on any hostile foreign country if you don't need to be and definitely no point switching from one hostile country to another.

    6. Re:Boot them from the Swift system for a few weeks by hjf · · Score: 1

      Argentina paid to repsol MORE than its market value estimation.
      And what they did was not "illegal". If it was, they couldn't have done it.

  11. TL;DR: US just as corrupt as Russia! by Anonymous Coward · · Score: 0

    yeah, um, nope.

    Try again, typical US university professor.

  12. Re:FUD. They don't even know. by crunchy_one · · Score: 3, Insightful

    Spot on comment. TFA also fails to name the 10 financial firms that were allegedly attacked. The New York Times seems to be rapidly morphing into a US version of Russia Today. If there's any new cold war, it's clearly a propaganda war. And guess what? I don't give a flying fuck.

  13. FUD by mike.mondy · · Score: 1

    Posting to undo moderation mistake.

  14. shades of incompetence actually... by Karmashock · · Score: 4, Insightful

    Secure your fucking networks or get off the internet.

    --
    I've decided to stop wasting my time responding to AC trolls/sockpuppets... so if you want a response from me... login.
  15. Isn't JP Morgan Chase an enemy of the US public? by Anonymous Coward · · Score: 0

    Wouldn't "attacking" JP Morgan basically be doing the US a favor?

  16. Re:FUD. They don't even know. by Archtech · · Score: 3, Interesting

    Very much like the utterly unsubstantiated claims that Russia had something to do with the shooting down of MH17. John Kerry said that there was a mountain of evidence, but so far not a single shred of evidence has been published by the US government. The Russians released a good deal of hard evidence, including radar traces and the locations of known BUK units. Basically, MH17 was shot down either by cannon fire from one or more fighters, or by a BUK SAM. The only fighters in the air that day were Ukrainian government planes, and while the rebels may have captured a BUK unit, it had no radar. However the Ukrainian military units near Donetsk had at least three BUK units, complete with radar and trained crews - one of which was in exactly the right place to have shot down MH17, given where it came down.

    So the Western media were flooded with "stenographic" reports and opinion echoing US government statements (almost word for word) and without any skepticism or investigative journalism. Although there has still been no evidence produced to incriminate Russia or the Ukrainian rebels, virtually all Westerners have been so heavily and repeatedly brainwashed with the certainty that Russia was responsible that they think they "know" it.

    Perhaps the recently revealed large and widespread payments made by the CIA to American media (and others) in return for the printing of CIA-written propaganda helps to explain many of these odd situations. And media corporations are all the more disposed to go along with the scam because their circulations are shrinking and they laying off journalists and editors left, right and centre. It's a double win: money for nothing, and masses of copy that has been written elsewhere. The only losers are any remaining readers who are foolish enough to believe what they read in the newspapers and what they hear on radio and TV.

    --
    I am sure that there are many other solipsists out there.
  17. Hackers: "This is our world now." by matthekc83 · · Score: 1

    Hackers movie quote "This is our world now. The world of the electron and the switch" I think at some point nearly everthing will get "hacked"... we can cry about it or we can make things less fun. Hackers movie quote "There is no right and wrong. There's only fun and boring." We need treaties to ensure those commiting crimes can be prosecuted across borders with long boring sentences. Hackers movie quote "Kid, don't threaten me. There are worse things than death, and uh, I can do all of them." For the love of god why is our ssn a national identifier and the unchangable password to our finances!

  18. Wagging the dog? by ErikTheRed · · Score: 4, Insightful

    "People briefed on the matter" generally equals "deliberate leak, to move public opinion or at least test the waters."

    --

    Help save the critically endangered Blue Iguana
  19. Can't be serious.. by Anonymous Coward · · Score: 0

    China is a critical trade partner, so we tolerate a certain amount of this kind of thing from them. But Russia? We're already breaking the back of their economy with sanctions. Do they really want to get into it with us electronically? While I despise what the NSA has done to Americans, I would quite enjoy seeing them systematically dismantle every bit of Russia's modern infrastructure while the Russians make every futile attempt to stop them.

    The US sticks its nose where it doesn't belong mostly out of poorly considered good intentions. Russia's decided to go beat the Hell out of their smaller and weaker neighbors so they can feel better about themselves. They should really think twice about poking the US while they're doing that.

    1. Re:Can't be serious.. by koan · · Score: 2

      Then you're an idiot, that's reason for war.

      --
      "If any question why we died, Tell them because our fathers lied."
  20. Propaganda by koan · · Score: 2

    Sounds like one of many smears to come up prior to some sort of "intervention" in Russia or just the usual "he said she said" crap our (and other) government/s are famous for.

    --
    "If any question why we died, Tell them because our fathers lied."
  21. Russia not equal to USA by Anonymous Coward · · Score: 0

    When the leader of your country is connected to the mafia, declares himself leader and starts taking over other countries this is very much different from a country that has democratic elections and holds freedom as an ideal. I'm sure there are great people in Russia, but it is no united states.

    1. Re:Russia not equal to USA by Anonymous Coward · · Score: 2, Funny

      When the leader of your country is connected to the mafia, declares himself leader and starts taking over other countries this is very much different from a country that has democratic elections and holds freedom as an ideal. I'm sure there are great people in Russia, but it is no united states.

      Are you describing President Obama and the United States of Amerika (now KKK) or President Putin and Russia (formerly part of the CCCP)? Any pretence of freedom in USA has long been exposed an a fallacy. Dear Leader Barack Hussein Obama is merely jealous that Putin wrestles with Siberian tigers, swims in icy waters, and does not bow and scrap to the Master of the Plantation.

    2. Re:Russia not equal to USA by Anonymous Coward · · Score: 0

      Someone's been sniffing glue in his grandparents' nuclear bunker.

    3. Re:Russia not equal to USA by k6mfw · · Score: 0

      Goes to show what's happened with this country. it seems much of Obama's policies are extension of Bush. Both parties put highest priority on surveillance of the people and in meantime more and more people struggling financially with feeling both political parties and higher ups are more interested in themselves rather than what's good for the country. Then there's foreign policy debacles in Middle East. Perfect timing for Putin to expand his empire and ISIS to go on their rampage because now it's difficult for this country's leaders to rally up the people to assemble an effective response.

      --
      mfwright@batnet.com
    4. Re:Russia not equal to USA by wiredlogic · · Score: 2

      You shouldn't delude yourself into thinking that the US has free elections or in any resembles a true democracy or republic. Just look at how almost all states ban non-party affiliated voters from participating in primaries even though they use public resources to collect those votes.

      --
      I am becoming gerund, destroyer of verbs.
    5. Re:Russia not equal to USA by Anonymous Coward · · Score: 0

      Some of us in the US aren't drinking the coolaid. I realized things weren't right when Bush Sr. was in office.

  22. Re:FUD. They don't even know. by Anonymous Coward · · Score: 0

    What makes these things hard to analyze is the difference between state-sponsored and state-tolerated, a distinction lost to most journos. State-sponsored says you get a budget and tasking from a government. State-tolerated is like privateering: you're on your own, keep any profits you earn, make sure your attacks are consistent with government policy, if you come across anything the government might find interesting pass it along, and if you attack a site inside your own country the government will hunt you down and shoot you. State-tolerated attacks reap all the benefits of state-sponsored ones with none of the risks; no nasty "acts of war" or justification for kinetic response. Even if the victim tracks down the perps all the local government has to say is "oh, yeah, we were just about to raid that place," frame some dissident for the crime, and go back to business as usual. Win-win for everybody but the targets.

  23. Companies want Swiss cheese software by Anonymous Coward · · Score: 0

    They don't really want security - that's just secondary to features and schedule at most companies I have worked for. Not surprising though considering how many managers were the dumbest-coder yes-men that mostly get into the positions of authority and then just expect their retardnessness is the "right-way" to do things. More software developers I talk with (than not) just do manual testing of their code and are confused by what automated unit testing even is. It's pathetic. And forget about such qualities as ACID.

    "It's unnecessary". "It's not likely to really be a problem" . "It doesn't have to be perfect". "That's over-engineering". These are the kinds of excuses manager types use to justify the crappy software security/quality that is out there that I've heard.

    I need to find a new line of work - like becoming a cracker.

  24. Technology should be designed to be *secure* by Anonymous Coward · · Score: 5, Interesting

    And system administrators have to stop acting like implementing security is a bad idea, shouldn't happen, and won't work. You can argue that 'the business' always comes first no matter what. However that doesn't work if 'the business' puts security at risk. If your business is cloned by a foreign competitor your screwed, if your bank accounts drained your screwed, if you really think 'the business' always comes first your wrong. It highly depends on what the risks from being comprised are.

    I'm the CEO of a small technology company and I get that security is hard. Hell- I'm not even living up to my own high standards. However its hard to do that when *nobody* else is. Despite that I'm trying to put security first during our web site revamp (the most critical aspect of this company, if our security is hosed in a slow planned manor we'll never recover).

    One good example is the 'security' systems (two factor authentication) aren't even well thought out and are done such to be 'cheap' rather than effective. This will only stop the bottom feeders temporarily. It won't stop Russian organized crime from doing live intercepts via botnets to gain access to bank accounts and once the tools are sold to typical criminals the entire system is back in the hands of the criminals. I have nothing against the criminals, and considering that I'm the *primary victim* (100% of the shares, business owner here) when fraud happens I'm in a position where I should be more pissed than anyone (and it happens too often).

    But I'm not because the problem isn't the criminals. It's the lack of security and enablement by critical institutions (government and corporate). What I have a problem with is visa, master card, american express, the banks, and the government. They are not implementing the systems we actually need.

    1. True security, not halfway crap 'wireless WEP/WPA/WPA2', if your bank's site gets 'hacked' and a known vulnerability w patch exists at the time, then the bank should be shut down, assets seized, etc, none of this proprietary bull shit either. All defaults should be set to off or specifically added to a white list after approval only (on the client side, things like macros, etc).

    2. The systems should be built on hardware that there is source code for and audited. BIOS, firmware components, etc. Right now this doesn't even really exist unless we're talking about *a consumer router* or two. Some individual components may qualify as being pretty close to 100% free software friendly and source code available though.

    3. Calling a cell phone for authentication is NOT a security measure. It's merely a nuisance for the customer (particularly when the cookies make it such you can steal them and never actually have to authenticate via phone anyway). We need something closer to secure ID /w password (on the secure ID token itself). This would prevent the ability of a middle-man (or make it much more difficult) because the identification number revealed by the token to authenticate can only be used once and you can be confident that the person involved in accessing it did authorize it. Now it won't prevent some attacks where the system is compromised, but you can thwart unauthorized wire transfers by adding a screen that shows information to a wire transfer such that the user has to approve it on the device itself. This way the attacker could not simply show the user a different set of data than the one he authorized by entering the token number during authentication.

    1. Re:Technology should be designed to be *secure* by Anonymous Coward · · Score: 0

      I see you are one of these naive persons who has not yet grokked how capitalism works. I'll hint you: it is like a sausage factory - you dont want to know too much about it if you plan to eat sausage in the future.

      If you have ANY trade secret, store it on paper with some ancient typewriter. Lock it into a mechanical safe and conceal the safe under a heap of smelly rubbish. Have a second safe in a nice room to be stolen by the bad guys.

      And, DONT EVER THINK a networked device will be secure. Dont take my word, Google for Mr Binney (Ex NSA tech director) and listen what he has to say about it.

    2. Re:Technology should be designed to be *secure* by Anonymous Coward · · Score: 0

      I half-heartedly agree with your statements. A large part of the risk comes down to the transitory nature of the IT community at large. Temporary resources, off-shore resources, and employees with a common employment span of less than five years at any given company. Technology employees are largely under-compensated, have little or no growth opportunity within the company, and seldom have any shares in the company that would give them a sense of loyalty. Factor in short deadlines, and overzealous requirements for any project, and it is no wonder that they would rather take short-cuts and deliver on time and on budget than to implement security protocols that are safe and sane, and meet the needs of your business. That is a management issue, and you CEOs have to stop expecting miracles. I've seen projects bid requiring a certain number of resources, a defined budget, and estimated with a specific deadline only to come back with fewer resources, less budget, and a "compressed timeline". Is it any wonder that rather than disappoint you, they do what they have to in order to deliver on your timeline? Your statements above are still about the symptoms, they are not about the disease.

      The huge press by technology companies to bring in more H-1B visas so they can introduce even more temporary workers from off-shore is an indicator in and of itself that these companies have little care or concern for security. Until this changes, there will be no real movement in the security arena to prevent a determined insider from delivering all of your data outside your shop. In a lot of cases, it is still very easy for someone to change their identity and return with a new name the next time they want to get up to some nonsense.

      So, if I were someone who wanted to pull off one of these hacks, I would form a small team of people, call myself a contracting company, forge credentials if necessary, and focus my efforts on introducing these people into large companies. Once I got one infiltrated, I would use the rest of my team to support their efforts to compromise systems. I would provide them with innocuous looking software, scripts, code, etc., and while they are on contract, I would have them infiltrate this software wherever they could. When they leave the contract, then I would sit back and collect the fruits of their efforts quietly. In this case, even if it is discovered, there would be very little fanfare or media coverage because the last thing that anyone would want would be to embarrass the company and potentially lower the stock price. As to who did it, it would be rare for a company to be able to identify exactly which of the many people on a development team did a particular task, and over time, the logs would rotate out and nobody could possibly perform a forensic analysis on it anyway. Companies in certain fields are required to keep logs of privileged access for one year, but many things can be done without privilege, and seldom are any logs kept of routine activity, especially in a development environment. So, based on what your log retention standards are, and whether you bother to keep logs of routine activity, you would never be able to find out for certain who did anything on your systems.

      In the case of JPMorgan, based on the systems that were compromised, and the path that "didn't include any financial information", I am left wondering if this wasn't an internal attack. Too many large companies outsource their work, hiring temporary workers to perform even critical tasks. What this leaves them with is an exposure of their inner-most critical systems to people who have been lightly vetted, have no real loyalty to the company (or the business), and have very little oversight. They come in, set up their software (malware, virii, data exfiltration routes), leave, and sit back and collect their data over the course of months and years because nobody expects an internal system would be compromised. Most focus, even in your case, is on the external web servers. Very few networks moni

  25. Re:FUD. They don't even know. by xdor · · Score: 0

    Perhaps the recently revealed large and widespread payments made by the CIA to American media

    Citation please.

  26. TIL: by Anonymous Coward · · Score: 0

    A whole host of white people with slightly differing internet usage patterns constitutes "diversity." No wonder I so strongly disagree with it. I always thought it was community-destroying forced integration.

  27. China by Anonymous Coward · · Score: 0

    Agreed.

    Don't forget, few months ago it was all the rage that the Red Chinese were going to infiltrate every system in America. Remember? Telecommunication contracts were even canceled on grounds of "national security" because the "evil Chinese" have malware baked in silicon.

    Of course, that does not matter anymore. Now it's all about the Ruskies.

    Proof? Motive? Who cares! Russians flexed their muscle to keep strategically important areas under Russian influence. Imagine if Canada wanted to join Russian Federation tomorrow - surely, the friendly Americans would make sure that such a thing would not have happened, no matter the cost.

    It's pretty sad world politicians always seem to need some perpetual war. Soviet Union? Terrists? Libya? Iraq? Putin? There are always resources for bullshit like that, but actual positive stuff? That's boring. Who needs healthcare, science or environment. Cut that shit. Need a manufactured crises instead!

  28. Re:FUD. They don't even know. by Archtech · · Score: 1

    "Citation please".

    That's an easy game to play, isn't it? Tell you what: first, since it was mentioned first, YOU give ME a citation for some hard evidence substantiating the claim of Russian involvement in the J.P. Morgan affair.

    And if you want a citation for the CIA allegations, Google is your friend.

    --
    I am sure that there are many other solipsists out there.
  29. Did I read a story about this by Anonymous Coward · · Score: 0

    So now we are in "cyber war" with Russia. A few weeks ago it was China, is China our friend now ? I need a scorecard. This "cyber war" stuff is getting too much, if you fine companies 10000 real dollars per account compromised and the company must fully disclose to the public exactly what happened, you can bet these issues it will be fixed in no time.

  30. Re:FUD. They don't even know. by Archtech · · Score: 1

    Although I did go to the CIA Web site and searched for "propaganda media". This is what I saw next:

    Search is Temporarily Unavailable

    Search is temporarily unavailable. We apologize for the inconvenience. Please try again later.

    Posted: Aug 27, 2012 04:31 PM
    Last Updated: Aug 27, 2012 04:31 PM

    --
    I am sure that there are many other solipsists out there.
  31. Russian diversity by wonkey_monkey · · Score: 1

    I've seen the former Soviet Union evolve into an amazingly diverse culture that is well represented on the Internet. This culture has grown alongside our own and runs the gamut of characters: tirelessly brilliant open source software developers, lots of regular folk

    But no pooftahs.

    --
    systemd is Roko's Basilisk.
    1. Re:Russian diversity by mjwalshe · · Score: 1

      In Russia we have many types of criminals "simples yes" - as Lord Leveson sort of said perception is a bitch

  32. Blame Russia to distract the plebs by Anonymous Coward · · Score: 1

    Hurr durr, someone hacked us and exposed our incompetence. Let's blame Russia so the masses don't take it out on us.

  33. Attribution? by Lawrence_Bird · · Score: 1

    Fail, fail and more fail. The press, three letter agencies and especially the congress critters love to a) inflate the threat and b) give attribution when none is possible. This book is extensively researched and has footnotes out the ying-yang. Bottom line is attribution at a level where one can say "these guys did it" is rare and even saying "probably did it" is difficult. And beware that many of the players involved have multiple objectives and even relationships with each other (when convenient).

  34. Curious reframing within a reframing . . . by sgt_doom · · Score: 3, Insightful

    . . . after all, JPMorgan Chase (Chase) is the largest criminal organization in America today, and together with Goldman Sachs, they effectively run and control the US Department of the Treasury, while existing as the major forces of the Federal Reserve Bank. If the Russian mob was attacking the American mob, it is really about the mobs, now isn't it?

  35. Ah yes, The Times by fustakrakich · · Score: 2

    The war mongering Randolph Hearst of the new century, and the old one.

    --
    “He’s not deformed, he’s just drunk!”
  36. Boot them from the Swift system for a few weeks by Anonymous Coward · · Score: 0

    Hi,

    Gee weren't the Russians our best buddies during the recent Olympics?

    Why don't we secure our networks from the people who will exploit them (who will always exist), and work on understanding between people rather than trying to "retaliate" against countries? What exactly are we retaliating against anyway?

    War (cold, hot or political) is stupid.

  37. how dare they hack corporations by Anonymous Coward · · Score: 0

    that is s the nsa job and only against none merkins. Any one else committing such acts of war will be declared an act of war equivalent to using a wmd.. Or as Americans are so brave a tube of tooth paste.

  38. I'm rooting for the Russians by Mister+Liberty · · Score: 3, Insightful

    I hate banks. So should you.

    1. Re:I'm rooting for the Russians by Anonymous Coward · · Score: 0

      Too general.
      You can hate big banks if you like, but there are many small community-scale ones which didn't cause the problems and generally deserve our support, since we do actually need banks.
      And in any case, opinions about banks do not justify support for international organized crime, from Russia or any other source.

    2. Re:I'm rooting for the Russians by Billly+Gates · · Score: 0

      Well when your account has no money and your boss has to let you go due to no line of credit available to the finance department to pay your monthly salary I think your mind will change.

    3. Re:I'm rooting for the Russians by Anonymous Coward · · Score: 0

      And for how long is your boss going to use the line of credit instead of actually making money? Not to mention that you can only use the credit if you have assets which the bank can take from you if you cant return the credit (ah i forgot, your boss might just be sharing the benefits of infinit credit with a high-ranked bank employee and avoid the necessity to have ANY assets). And dont forget the mad percents they make you pay (while enjoying much-much cheaper money). Then you of course have to use a bank to even be in any kind of legal business. And soon the banks will probably charge money even for entering them. At least in my experience and in my country which is Russia.

      Well, the husband of my cousin who works in some bank's IT as a (mostly) senior programmer sincerely believes that the banks are a blessing and those who says they are a plague are just inept losers who cant make money. Since i believe i am an inept loser then he is right. oh well...

  39. BINGO by Anonymous Coward · · Score: 0

    They also had a big smear campaign running against Huawei. Now we know it was their own fucking with Cisco devices and their owmn bad conscience leading to that smear campagin.

    All we know is that both NSA and GCHQ are hacking into systems worldwide.

  40. Re:FUD. They don't even know. by khallow · · Score: 0

    while the rebels may have captured a BUK unit, it had no radar.

    Unless of course, the system actually had a radar contrary to your assertion. For example, they could have gotten a radar from their buddies in Russia and maybe a few trainers too. It's worth noting here that there weren't problems with airliners getting shot down by BUK SAMs until the rebels got a hold of one. Maybe they got framed, but maybe a poorly trained SAM crew killed 298 innocent people.

    Then there's the interference with the crash site by the rebel side. You'd think they'd be more forthcoming, if they hadn't destroyed the plane.

  41. Linus doesn't like black and white people by Anonymous Coward · · Score: 0

    Linus doesn't like black and white people.

  42. Re:FUD. They don't even know. by Anonymous Coward · · Score: 0

    Nonsense. If you are going to make hyperbolic and barely relevant comments about Ukraine in an article about J. P. Morgan, it is _your_ obligation to provide some evidence.

  43. some sound advice by Anonymous Coward · · Score: 0

    Never listen to JP Morgan Chase

  44. Proxy wars, same strategy, different territory. by Anonymous Coward · · Score: 0

    In the past it was only third world countries that got savaged in the proxy wars between super powers, now it has become virtual and the web is increasingly the battle ground. The difference now is that we all become the refugees as our digital spaces are compromised and our consumer products exploited to allow the actors to attack each other indirectly. Meanwhile companies are not held accountable for how weak the security in their systems and products are, nor are we able to cover the damage as virtual goods are hard to insure.

  45. Re:FUD. They don't even know. by znrt · · Score: 1

    which "rebel side"? you mean the fascist western backed coup d'état that overthrew a legitimate elected government and threw the country into civil war?

    and you guys still speak of "cold" wars? lol.

  46. NO proof by Anonymous Coward · · Score: 0

    just some reporter going on and on and on , heck i could change it and its space aliens that did ti...for all you know i did it using russian proxies
    of course i didnt and watch th ensa edit this part out so im screenshooting it

    cause your us govt is full a fucking assholes

  47. wow slashdot is a propaganda tool now? by Anonymous Coward · · Score: 0

    Ok... if any of you guys didn't happened to notice... Russia is being blamed for everything computer related... and also remember how a few years ago it was always china... this stuff is so easy to see through it's pitiful... pay attention people

  48. Russia has already restarted the cold war by Anonymous Coward · · Score: 0

    Russia has started the cold war all over again. Maybe Putin thinks they have a better chance this time. Western countries simply need to be willing to destroy the Russian economy with sanctions and to do so immediately. Putin thinks they are too weak to do this and it looks like he is right.

    Russia shot down a civilian airliner (or Russian backed terrorists which were still probably serving Russian military...) and got away with it. If the world stands by as Russia murders their people, why would they are on a bit of hacking?

  49. Cooperation by Sciath · · Score: 1

    Going after criminals (in foreign countries) requires the cooperation of that government. Russian government (like the U.S.) is corrupt enough to impede any legitimate investigations. Especially when government officials are benefitting from the criminal activities. In the case of Russia, there is little incentive for Putin to cooperate.

    --
    "Those who can make you believe absurdities can make you commit atrocities." - Voltaire
  50. Diversity of russians by bombman · · Score: 1

    I find it an odd chain of logic, that because the Russian netizens are a diverse bunch, then it excludes that
    a crime syndicate with ties to persons in the Russian government are involved in some specific incident of hacking.
    Both can easily be true at once.