Slashdot Mirror


Retaliatory Cyber Attacks Are Only Way To Stop China, Says Former FBI Director (afr.com)

Targeted cyber attacks and a strong deterrence capability are the most effective way of preventing China and other countries continuing to steal Australian commercial secrets, according to a former director of the Federal Bureau of Investigation. From a report: Louis Freeh, who ran the FBI for almost eight years until 2001, said the threat of criminal charges or jail time would do little to prevent state-sponsored hackers from continuing to steal valuable intellectual property. "It's like trying to serve a subpoena on [Osama] Bin Laden -- it's not very effective," Mr Freeh said on the sidelines of a speech in Sydney on Monday night. His comments come as the federal government considers how best to respond to a surge in cyber attacks directed by China's peak security agency over the past year. An investigation by The Australian Financial Review and Nine News confirmed China's Ministry of State Security (MSS), was responsible for the recent wave of attacks on Australian companies. These formed part of what is known in cyber circles as "Operation Cloud Hopper", which was detected by Australia and its partners in the Five Eyes intelligence sharing alliance.

105 comments

  1. Stuxnet Them Where It Hurts: Their Pocket Book by Anonymous Coward · · Score: 0

    You Stuxnet their manufacturing SCADA systems you know the ones that are still run on pirated versions of Windows XP...

  2. Right... by Immerman · · Score: 1

    It's a good thing it's not possible for hackers to spoof their origin to make it look like it's their competitors doing the hacking.

    --
    --- Most topics have many sides worth arguing, allow me to take one opposite you.
    1. Re:Right... by Anonymous Coward · · Score: 0

      No such thing as intellectual property. And if it is copied then under the WTO there is redress under Chinese law. Simples. The real problem is dumb Australian/Other/ companies connecting to the web, never compartmentalizing sensitive stuff. Commercail op systems are just junk. What do you expect.

    2. Re:Right... by Anonymous Coward · · Score: 3, Interesting

      It's a good thing it's not possible for hackers to spoof their origin to make it look like it's their competitors doing the hacking.

      Are you trying to claim China DOESN'T have an organized, state-sponsored dedicated cyberwarfare unit?

      And that the intelligence and law envforcement agencies of the US, UK, Australia, Canada, and others can't track at least some of that unit's activities?

      If you can't credibly claim all that, you're just an ignorant blowhard trying to confuse things.

    3. Re:Right... by Immerman · · Score: 1

      Not at all.

      Are you trying to claim that it's not possible for Russian, Indian, American, etc. hackers to make it look like their attacks on Australia are coming from China? Or vice-versa?

      --
      --- Most topics have many sides worth arguing, allow me to take one opposite you.
    4. Re:Right... by Anonymous Coward · · Score: 1

      He is being sarcastic; it is pretty well known that CIA routinely use IP spoofing as it can be trivially done when you control the telcos.

    5. Re:Right... by jellomizer · · Score: 1

      However connecting to an other system requires 2 way communication. If the computer knows how to send back its response back to your system saying it had connected and that the packets didn't get lost or didn't collide. Then we can track it back. Most of the time spoofing is good enough, just because the effort on tacking back is higher then what the damage of the hacking is, and the value of finding the hacker.

      However if you piss of the right person or government with some real money to track you back. IP Address spoofing will be little help.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    6. Re:Right... by Anonymous Coward · · Score: 0

      botnets to the rescue!

    7. Re:Right... by Anonymous Coward · · Score: 0

      Not at all.

      Are you trying to claim that it's not possible for Russian, Indian, American, etc. hackers to make it look like their attacks on Australia are coming from China? Or vice-versa?

      Utterly fucking irrelevant. If Canadian, UK, US, Australian, New Zealand law enforcement and/or intelligence agencies track illicit cyberwarfare back to China, it doesn't matter in the least what other hackers can and can not do.

      You apparently didn't bother to take a class in basic logic, did you?

      So, are you able to back up your claim that China doesn't conduct illicit cyberwarfare, and that activity can't be tracked back to China?

      Because you are literally no different than that "It was aliens!" fellow idiot - you have no actual evidence for your claim, but you're gonna pound away at it anyway.

      I bet you will continue to pound on the "ILLOGICAL ignorant blowhard trying to confuse things" button...

    8. Re:Right... by Ogive17 · · Score: 1

      It's as likely as you being paid by the Chinese government.

      --
      "Action without philosophy is a lethal weapon; philosophy without action is worthless."
    9. Re:Right... by Archtech · · Score: 1

      No such thing as intellectual property.

      "If nature has made any one thing less susceptible than all others of exclusive property, it is the action of the thinking power called an idea, which an individual may exclusively possess as long as he keeps it to himself, but the moment it is divulged, it forces itself into the possession of everyone, and the receiver cannot dispossess himself of it. Its peculiar character, too, is that no one possesses the less, because every other possesses the whole of it. He who receives an idea from me, receives instruction himself without lessening mine; as he who lights his taper at mine, receives light without darkening me. That ideas should freely spread from one to another over the globe, for moral and mutual instruction of man, and improvement of his condition, seems to have been peculiarly and benevolently deisgned by nature, whom she made them, like fire, expansible over all space, without lessening their density at any point, and like the air in which we breath, move, and have our physical being, incapable of confinement or exclusive appropriation. Inventions then cannot, in nature, be a subject of property".

      - Thomas Jefferson (who invented lots of things, all of which he freely released for general public use without any request for payment).

      --
      I am sure that there are many other solipsists out there.
    10. Re:Right... by Anonymous Coward · · Score: 0

      It's a good thing it's not possible for hackers to spoof their origin to make it look like it's their competitors doing the hacking.

      A couple of years ago the NSA let it slip that they had the ability to leave digital fingerprints making it appear as though another nation had committed cyberattacks. The story went away within an hour of the first broadcast on CNN.

    11. Re:Right... by Anonymous Coward · · Score: 0

      If you think IPs are the only way to know the origin of an attack, with all due respect, you are an idiot, sir!

      Hints: work hours (hint2: for the manual part of the attacks), exploits used, strings in code, structure of the code, targets, ... And some machine learning both supervised or not.

    12. Re: Right... by phantomfive · · Score: 1

      A more natural way would be to hack into a computer in China then from there hack into the US. If you are hacking serious targets, go through multiple proxies. Never hack directly from your own computer.

      --
      "First they came for the slanderers and i said nothing."
  3. View on China Needs to Change by sycodon · · Score: 5, Insightful

    China is not really our friend in any sense.

    They steal intellectual property

    They use state subsidies and subpar working conditions to undercut our products

    Their, "students" are usually tools of the Government.

    While it is doubtful the US and China will ever engage in some kind of ground war, it is probably inevitable that some kind of air/sea conflict occurs. Given the tremendous economic entanglements, it will be a very bizarre conflict.

    --
    When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    1. Re:View on China Needs to Change by Virtucon · · Score: 4, Interesting

      You didn't mention the BGP attacks they've been conducting lately. They're a bad actor in terms of Internet trust and it's time to cut them off.

      --
      Harrison's Postulate - "For every action there is an equal and opposite criticism"
    2. Re:View on China Needs to Change by sycodon · · Score: 1

      Ya...I completely neglected to include the very thing the story is about.

      I have Turkey and Dressing on the brain.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    3. Re:View on China Needs to Change by BringsApples · · Score: 1

      Given the tremendous economic entanglements, it will be a very bizarre conflict.

      It's already a bizarre. Soon, China, Russia and the US will hold the world hostage: pay huge taxes on over-seas shipping, or WW3.

      --
      Politics; n. : A religion whereby man is god.
    4. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      American government is not anyone's friend; not even Americans.

    5. Re:View on China Needs to Change by Anonymous Coward · · Score: 1

      China is not really our friend in any sense.

      They steal intellectual property

      They use state subsidies and subpar working conditions to undercut our products

      Their, "students" are usually tools of the Government.

      While it is doubtful the US and China will ever engage in some kind of ground war, it is probably inevitable that some kind of air/sea conflict occurs. Given the tremendous economic entanglements, it will be a very bizarre conflict.

      This is a highly dangerous viewpoint. Like saying that war with Mexico and Canada are inevitable because we have serious unresolved border, trade and even national security disputes with them... War with China is not inevitable just because the US and China are two of the biggest most powerful nations on Earth. Nor is war inevitable with the EU or India just because they are so big and powerful. Even a limited war between major powers is extremely undesirable and could result in millions of deaths and decades of tensions between the survivors. And forget any chance of avoiding mass extinctions. All habitats will be on the economic table as all nations work towards war preparedness and economic self sufficiency.

      Yes, China has been acting in an adversarial manner (So has the US. ) and we can't just accept future cyber attacks without a real response and roll over like the Obama administration did... But if we are responding to attack from 5 years ago just because the public was kept in the dark by Obama then that is on us. China should be judged on what they are doing today, not 5 years ago.

      If the US can be a friend and "ally" for decades with a no-human rights totalitarian country like Saudi Arabia based on economic mutual interests alone with no other common values then we can at least avoid poor relations and conflict with any country, even China.

    6. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      I hear they also urinate in peoples' Cokes.

    7. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Another Alex Jones copy-paste job. Congrats you moron.

    8. Re:View on China Needs to Change by Alwin+Henseler · · Score: 1

      They steal intellectual property

      Put "steal" between quotation marks, please. IP is a legal construct that creates government-assisted artificial scarcity. A relatively recent concept, with non-existing or shaky scientific foundation. For that reason, ignoring IP is not by definition immoral. One can have different views on that:

      IP supporters base their p.o.v. on some unproven theory that IP has a net benefit to society. Even though it's obvious it is not serving its original purpose, IP law is largely written by a powerful lobby from rightsholders, and forced down the throat of other nations through hidden passages in trade agreements. Not to mention excesses like perpetual copyright terms, digital rights management, right-to-repair issues, or patent trolls - just to name a few. Or that copyright laws as they are, are supported by a minority of the population at best (see: lobbying).

      Whereas views in most of the world tend towards "copy at will, where it helps make a better product". In this case emphasis shifts from legalities to practicalities: win in the market by producing more efficient, innovating faster than the competition, or offer some added-value service. Personally I prefer this over the lawyers. But either way isn't by definition 'good' or 'bad', just a different philosophy.

      They use state subsidies and subpar working conditions to undercut our products (..) Their, "students" are usually tools of the Government.

      In other words: state power is used to put the nation's interest as a whole, above the interests of individuals. Again one may argue this is 'bad' as it involves curtailing or ignoring rights of those individuals. And sure there'll be some Communist Party members & friends that took more than their fair share. But does it benefit society as a whole? In the case of China: probably yes (or at least it has, for a number of decades).

      As for government: as long as China doesn't use military force to take from other nations what shouldn't be theirs, it's up to the Chinese people to deal with their own government. Note people != government, average Chinese person may have very different views / attitude than policies as enforced by government officials.

    9. Re:View on China Needs to Change by DNS-and-BIND · · Score: 2

      If this is the case then why did we build China into the behemoth it is today? China used to be a poor, backwards country until our elites decided to let it into the WTO. Afterwards our factories died and our working class fell into poverty as China became a force to be reckoned with.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    10. Re:View on China Needs to Change by Anonymous Coward · · Score: 2, Insightful

      "to undercut our products"

      have you been paying attention to how globalisation works?

      it wasn't China's fault that America outsourced their entire manufacturing base to them.

      it was the fault of greedy corporate CEO's who wanted to maximize profit for shareholder gains (loss of American jobs be damned), plus the mindless consumerist working folk who valued getting a good deal above all else (loss of American jobs be damned).

      so yes, it was all your own fault.

    11. Re:View on China Needs to Change by Archtech · · Score: 1

      China was the biggest and most powerful nation in the world for many centuries before the USA was created. Its rulers made the apparently unwise decision not to develop their firearms, bombs, rockets, etc. because such weapons could lead to dreadful slaughter and destruction.

      They did not expect foreigners from the other side of the world to do what they had chosen not to, allowing them to conquer China - at least some of the coastal regions and Beijing. That, followed by the US-encouraged Japanese invasion, reduced China to the level of a thrid world country for over a century.

      In the past 25 years China has begun resuming its rightful position as the world's leading industrial and commercial nation. With the Western nations still violent and ceceitful, China obviously has to arm itself to protect its wealth against further depredations.

      --
      I am sure that there are many other solipsists out there.
    12. Re:View on China Needs to Change by DNS-and-BIND · · Score: 2

      Uh, did you respond to the wrong comment? China wallowed in poverty for decades before our elites admitted them to the WTO. This was what crushed our working class and enabled China to become wealthy beyond its wildest dreams. Their descent into poverty was not caused by the Japanese (WTF?) nor encouraged by the Americans (double WTF - America was China's staunch ally against the Japanese, something largely forgotten today). This tragedy was caused by Marxism.

      --
      Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    13. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Much truth here; but, too limited in scope. All property--all of it--is a legal construct. Hence the expression "property is a crime": it only exists because of sovereignty, "force in the service of just laws," as Hobbes would have it. All property rights are a "relatively recent concept." Historically, and pre-historically, all property belongs to the state, or the King, or the boss, or whatever authority happens to be around. You may use things for a while, and think you "own" them, but city hall takes what it wants, and you have nothing to say, in the end, because "taxation" and "eminent domain." You can't even destroy or discard much of your own property now without following a series of regulations.

    14. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Lol at steal intellectual property. Show us some studies that state as a percentage point how much intellectual property was stolen by nefarious means, rather than just transfers of technology, or incompetent inability of many companies to not protect their IP when doing business in China.

    15. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Wouldn't be bizarre at all. USA won WWII and the cold war because of manufacturing capacity. Now China owns that title. USA needs to start manufacturing again as a patriotic movement, but pink cat hat wearing pinkos will fight anything patriotic because they will say it is jingoistic, misogybistic, transphobic, and GMO.

    16. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      China and the USA (or China and the rest of the world) do not agree on China's borders, and Chinese fighters and ships have made aggressive actions against USA fighters and ships. This is not the stuff of fantasy.

    17. Re:View on China Needs to Change by MikeMo · · Score: 2

      In the case of "our elites", it was Bill Clinton that signed the Most Favored Nation pact with China. It's that pact that gave them everything.

    18. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      They use state subsidies and subpar working conditions to undercut our products

      They're subsidizing our purchases? Hey, friend or not, you have to admit it has been very nice to be on the receiving end of this for the last couple decades. More cheap electronics, please. With enemies like China, America doesn't need friends.

    19. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Assuming from China or recent American public school, the history Archtech was taught is that China won WWII fending off all of the world using Mao's Great Wall. The USA was the aggressor, as it always is and has been.

    20. Re:View on China Needs to Change by burni2 · · Score: 1

      Actually I'm worried about China too, but don't your points are also valid for the "U.S.A."

      - I mean intellectual property (NSA / Enercon)
      - State subsidies vs. Custom Duties
      - students tools of the government (and if students go on and work for NSA and CIA and implement things like egoistic giraffe).

      Well, only those who are without sin should throw the first stone.

      Except critisizing the government will not land you in internment camps or prison in the U.S. that's the difference.

    21. Re:View on China Needs to Change by jbengt · · Score: 2

      No, Archtech did not respond to the wrong comment. They just went farther back in history than you were talking about in your comment.

    22. Re:View on China Needs to Change by eaglesrule · · Score: 1

      If this is the case then why did we build China into the behemoth it is today? China used to be a poor, backwards country until our elites decided to let it into the WTO. Afterwards our factories died and our working class fell into poverty as China became a force to be reckoned with.

      Que bono.

      We generally accept that we're ruled by rich sociopathic oligarchs, yet still wonder why foreign policy does not align with our stated ideals or interests.

      It's almost as if an organization ran by globalist bankers and lawyers would see both China and the U.S. as resources to exploit. You're asking for a reason, look for the most self-serving, short sighted, profit motive driven one you can imagine.

    23. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      Their students are not tools of the government. What an awful thing to say. The students have their own hopes and dreams of living a prosperous life, they are not agents. Having known roughly 20 of them while I was in grad school, many often want to immigrate permanently, but America's immigration system makes it nearly impossible to do so. These are incredibly smart people that we are turning away, and while the Chinese government would love to control them, and they do try to brainwash them, they are not often successful.

      The Chinese people, unlike their government, are not bad people. Do not lump them in with the communist party that rules them. A similar thing could be said about American government (versus its people).

    24. Re:View on China Needs to Change by Anonymous Coward · · Score: 0

      China was the biggest and most powerful nation in the world for many centuries before the USA was created. Its rulers made the apparently unwise decision not to develop their firearms, bombs, rockets, etc. because such weapons could lead to dreadful slaughter and destruction.

      They did not expect foreigners from the other side of the world to do what they had chosen not to, allowing them to conquer China - at least some of the coastal regions and Beijing. That, followed by the US-encouraged Japanese invasion, reduced China to the level of a thrid world country for over a century.

      So in other words, they're backwards and naive.

      In the past 25 years China has begun resuming its rightful position as the world's leading industrial and commercial nation. With the Western nations still violent and ceceitful, China obviously has to arm itself to protect its wealth against further depredations.

      Rightful position? Bullshit. You act as this is fait accompli, and it's anything but. Past performance does not predict future results.

      Manufacturing is already shifting to places like Vietnam and in some cases is coming back to the US due to increased robotization as it's cheaper to manufacture closer to the consumer, which compounds the fact that they grew a middle class and now the rug is being pulled out from under it. Fossil fuels are on the way out, but won't be for some time and we've got them dead to rights there for at least the next 30-40 years.

      In addition, they lack fresh water and with their population will have increasing difficulty feeding themselves, especially with global warming. Throw in a couple of wild cards like nuclear weapons for Japan, Korea, or Taiwan and we can keep them on edge. Certain nations with a clue are preventing foreign purchase of land with an eye towards the Chinese (New Zealand is the first).

      I work with many of their graduate students on a daily basis, and they're generally weak sauce, and in fact some have been caught trying to cheat their way to the top.

      Understand something now, you Chinese sycophant, we haven't taken off the gloves.. yet. When we decide to act, you'll be brought back into alignment.

      And national debt? If I owe you 10k and can't pay, I have a problem. If I owe you a trillion and can't pay, you have a problem. To whom are they going to sell the debt?

      On a side note, Bill Clinton, despite everything else, should have been charged with treason for technology transfer to China. (Thanks Loral, you motherfuckers.)

    25. Re: View on China Needs to Change by Anonymous Coward · · Score: 0

      You're so pathetic it hurts my eyes to read your splutterings.

    26. Re: View on China Needs to Change by ozduo · · Score: 1

      USA did NOT win WW2!,, It contributed to the defeat of the AXIS forces. If you were to simplify their defeat to one protagonist then the SOVIET UNION would have that honour.

      --
      I got to the chocolate box before you, that's why the hard ones have teeth marks.
    27. Re: View on China Needs to Change by Anonymous Coward · · Score: 0

      We really should be doing more on cyber warfare, because that is the only way more of our infrastructure will get defended better.

      At least that way if we don't all nuke each other, the AI fuckup yet to come won't kill all the communication, power and water systems on the same day.

  4. Better Idea by alvinrod · · Score: 4, Insightful

    Instead of starting some kind of cyber war, why not have our guys act as white hats and target Anerican firms and government organizations. Find breaches and alert the concerned parties so they can get filled in.

    It gives our guys practical experience and helps protect American citizens and businesses. It even affords a good job opportunity for the kind of mischievous minds that might otherwise cause some of that trouble.

    1. Re:Better Idea by pr0fessor · · Score: 2

      Using our talent to increase our security sounds a lot better than an ever escalating cyber feud, that will have more impact on our businesses, the people that work there, and the people that depend on services they provide than the governments that started the feud.

       

    2. Re:Better Idea by bill_mcgonigle · · Score: 1

      You're entirely right on the merits - because the U.S. is the most connected society, in terms of economic dependence on telecommunications, every vulnerability that the NSA hoards for attacks, is a potential breach on corporate and personal information.

      However, if you think the type of people, largely sociopaths, who run the government are likely to just back down from a war they can foment, or really care about individuals' safety, you're entirely misunderstanding the mindset of someone who would go to work for the NSA or FBI, instead of the private sector.

      The trouble comes down to the profitability of making these vulnerabilities go away with the private sector - perhaps a non-profit could manage to do this, or some other economic mechanism that doesn't rely on the good graces of the crazy people who are calling themselves "Cyber Warriors".

      Anybody who needs evidence of this can go talk to someone who has battled Eternal Blue or something else of that nature.

      --
      My God, it's Full of Source!
      OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
    3. Re:Better Idea by alvinrod · · Score: 1

      I don't think you could have anyone, but the government do this kind of work on the kind of scale that is necessary. First of all, it's almost all illegal without permission, so only the government could get away doing it to organizations that don't ask. It might be a bit more hairy even then doing it companies, but the government could at the very least attempt to hack or social engineer other parts of the government. The government meanwhile, is never going to let a non-profit or any private organization get away with trying to hack them and won't even allow them to try in most circumstances.

      There's also all kinds of difficult questions that need to be answered, or rather are really difficult to answer. For example, what responsibility does anyone doing this type of work have to report any crimes that they might uncover as a side effect of what they're doing? If they have to report anything, no one else is going to want any of this to happen and it will quickly be viewed (and actively used) as a tyrannical tool to suppress people the government doesn't like. I almost think you need to give it to some group that's independent enough within the government and probably doesn't care about small time tax cheats or other things like that.

      Even though there are some good intentions behind this idea, or at least better ones that starting a cyber war with China, we're still playing with fire.

    4. Re:Better Idea by AmiMoJo · · Score: 1

      Seems like China already has much better cyber defences (the Great Firewall) and that the US couldn't match them even if it wanted to, because the US government doesn't have that kind of contralized control and people would never stand for it.

      So on the face of it starting open cyberwar with China doesn't sound like a good idea. Securing US systems seems like a better strategy.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    5. Re:Better Idea by pr0fessor · · Score: 1

      That also doesn't mention that it would only serve to strain relations and create a continuing rivalry that would cost the people and businesses. Rivalries like that don't serve anything but resentment and elevated hostility.

    6. Re:Better Idea by Archtech · · Score: 1

      the US government doesn't have that kind of contralized control and people would never stand for it.

      Hahahahahahahahahahahahahahahahahaha!

      --
      I am sure that there are many other solipsists out there.
    7. Re:Better Idea by MikeMo · · Score: 1

      I think this is virtually impossible. How many 10's of thousands of private companies are there in the US that need better security? Like all of them? You have to get them all - many of the hacks are via contractors, not just the main IP holders.

    8. Re:Better Idea by Anonymous Coward · · Score: 0

      Instead of starting some kind of cyber war, why not...

      What's good for the goose is good for the gander!!!

    9. Re:Better Idea by Anonymous Coward · · Score: 0

      Why not? Here's why: All American firms and organizations worth mentioning have become international corporations with customers all over the world. This creates a conflict of interest, since it's virtually impossible to secure their US infrastructure and software without also making software and infrastructure elsewhere safer. The US wants to be able to hack into every other country and company abroad, and so your strategy would get in their way.

    10. Re:Better Idea by Voyager529 · · Score: 2

      the US government doesn't have that kind of contralized control and people would never stand for it.

      Hahahahahahahahahahahahahahahahahaha!

      I think what Amimojo was getting at was that there is no American analogue to the Great Firewall of China. Japanese internment camps or Bay of Pigs or Area 51 can be searched without consequence in America; Tienanmen Square in China...less so.

      Yes, the federal government has enough tentacles that there's a decent amount of centralized control in an abstract sense, but when Net Neutrality was on the table for response, Americans flooded the DC switchboard and told them where to shove it. Americans aren't going to vote in favor of a Great Firewall of America, and even if the response is, "well, the elites will implement one anyway", it's not completely outrageous, but the moment it goes into effect, the consequences will be very difficult to predict and may well backfire.

  5. And here is a different idea by gweihir · · Score: 2, Interesting

    Maybe have IT security that is not cheapest possible, but actually works? That would also have the advantage that China may actually be stopped. "Hacking back" is still the most stupid idea possible in this space. But especially for China, has this person forgotten that the Chinese have their whole country behind a big firewall?

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    1. Re: And here is a different idea by mermeid007 · · Score: 1

      This makes about as much sense as using a DOM object to cut the crusts of a peanut butter sandwich

    2. Re:And here is a different idea by pr0fessor · · Score: 4, Informative

      This goes right a long with governments that want to have back doors to fight terror and crime but somehow magically it's only going to work for them and the bad guys will never be able to use it against us.

      In the end we have aloud the uninitiated to set policies for something they don't understand and the resulting mess is going to be hard to clean up.

    3. Re:And here is a different idea by gweihir · · Score: 1

      Oh yes. Those that crave power, but are not even capable to ask experts on matters they do not understand, routinely make big, big messes. This is just one of them.

      The only thing that will work in the end is better security, no backdoors, no holding back zero-day exploits, no "lawful" access, etc. Anything else will be suicidal. Of course, those with power are deeply afraid of citizens being able to hide things and communicate secretly, so it will take a while. But there really is no alternative.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  6. data by Anonymous Coward · · Score: 0

    Right now, I'm patenting a google cam in every pigeons ass. They'll take away my surveillance over my dead body.

  7. Or, you know, fix it. by DarkRookie2 · · Score: 1

    How about the tech companies fixing their shit so this doesn't happen.

    --
    http://progressquest.com/spoltog.php?name=Son+Of+Son+Of+DarkRookie
  8. Consequences by Anonymous Coward · · Score: 1

    Starting a cyber war with China will provide a justification for previous Chinese actions.We should try and work out something with the Chinese. The interests of China and the US and for that matter the rest of the world will be better served by dialog. If there is cyber war we will still need in the end to work out an agreement. So first dialog then if that is a failure move on to stronger measures.

  9. It's more than that by MikeRT · · Score: 0

    China has been working to make Chinese immigrant communities, particularly in the US, a fifth column. Chinese migrants/immigrants have also been problematic all across parts of East Asia and Indonesia as well from other things I've read. Then there is the whole problem of China colonizing Africa with millions of "workers."

    First world liberals will continue to ignore the problem, and do things like say "but the King of Belgium was a real bastard in the Congo, so who are we to judge***" as the situation gets worse.

    *** Gotta love how liberalism functions as a Christian heresy where you have all of the guilt and shame, but unlike Christianity you have no path of repentance and are collectively responsible for the actions of ever asshole before you (Ez 18 explicitly condemns that for Jews and Christians).

    1. Re:It's more than that by Immerman · · Score: 2

      Yep, monsters. Not like America, which conducts their invasions honestly, with overwhelming military power against grossly outmatched opponents, who we falsely accuse of having "Weapons of Mass Destruction" and drag a bunch of other militaries into the fracas as well.

      Face it, all the global superpowers (and a lot of the minor ones) are all constantly throwing their weight around to try to take what they want from other countries - the big differences from a moral standpoint are mostly in how many people die in the process, and how much important infrastructure is destroyed.

      --
      --- Most topics have many sides worth arguing, allow me to take one opposite you.
  10. No kidding. by Anonymous Coward · · Score: 0

    Game Theory 101. They need to suffer enough pain that it's in their interest to go along with a phased drawdown to some mutually acceptable level of cyber-espionage.

  11. Attack what exactly? Defense is what we need! by Opportunist · · Score: 4, Insightful

    What do you want to attack? Want to steal back the trade secrets they got from us? How do you steal from someone who has nothing that you could possibly want? What kind of deterrent is it when you throw a nuke into a mostly void desert? It costs you a nuke and doesn't bother your enemy at all.

    Instead get your defense up to speed! The itsec situation in most companies is atrocious. And I'm not talking about irrelevant mom'n'pop shops, we're talking large and very juicy targets for international criminal actors. If anything, the FBI should start treating sloppy IT security as what it is: A criminal offense.

    But no, wait, we can't do that! Then our corporations would have to do something about their IT security! That could cut into their bottom line! No, let's instead wage a silly "cyber" war we can't win on taxpayer money. One silly, useless and unwinnable war that we get to foot the bill for more or less, who cares?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Attack what exactly? Defense is what we need! by burtosis · · Score: 1

      If the NSA and other agencies would give up thier secret list of vulnerablities to the vendors it would help quite a bit. Instead of increasing defense by patching and hardening against known issues we purposely leave ourselves open to anyone able to use these exploits to use against these same "enemies" for the same reasons which makes no sense when we have more to lose. It only makes sense when those keeping the secrets don't care about the nation/people as a whole and want to get these gains despite the costs they don't directly pay - and that's if everything goes according to plan. I don't know how many times these exploits were turned into cyber weapons, then promptly "lost" somehow and used by just the people we didn't want to get hurt by before then finally being disclosed well after its too late to prevent a ton of damage.

    2. Re:Attack what exactly? Defense is what we need! by Slayer · · Score: 1

      You can not defend 100% against dedicated attackers in IT space, just as you can't reasonably prevent all violent crime upfront. With violent crime, it is commonly accepted, that suspected offenders are prosecuted, and in many cases extradited to the country the alleged offense took place. If a country does not cooperate in such a prosecution, the country affected by the crime will at some respond with travel restrictions or with sanctions against individuals associated with the crime, c.f. Skripal assassination attempt.

      With cyber attacks this is not the case, even if a nation state actively protects the perpetrators, or even worse, actively encourages them. For China the reasoning is simple: cyber crime pays off, espionage boosts their economy, and right now it has no adverse consequences. Commonly accepted perception in the west is, that we can't do anything about cyber crime coming from Russia and China, that we are sitting ducks who simply have to put up with it. Mr. Freeh may not be the only one in DC to think differently, let's see how this plays out ... looking forward to some investigative news outlet suddenly having access to Putin's or Jinping's financial records :)

    3. Re:Attack what exactly? Defense is what we need! by Anonymous Coward · · Score: 0

      Attack what? Easy. Neuter the great firewall and keep doing it until they behave.

    4. Re:Attack what exactly? Defense is what we need! by gman003 · · Score: 1

      Cyberwar isn't just about corporate espionage. Hack their oil pipelines, see what happens when the valves open and shut at 60Hz. See what Beijing traffic looks like when every traffic light is red, or worse, every one is green. Disable the Great Firewall, or better yet, mess with it. Block the official government sites, redirect them to a troll site. Unblock sites they really, really want blocked. Screw with the censorship on their social media - get "June 4th Incident" trending. Hack Xi Jinping's emails, spread the juicy ones around.

    5. Re:Attack what exactly? Defense is what we need! by Anonymous Coward · · Score: 0

      We could send them Ivanka's emails.

    6. Re:Attack what exactly? Defense is what we need! by Opportunist · · Score: 1

      Ponder how interesting she is.

      Now ponder how interesting anything she writes can be.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  12. China acts like an asshole by Anonymous Coward · · Score: 0

    So the former FBI director thinks we should act like assholes.

    No, thank you.

    1. Use our talent to "attack" ourselves in order to fix our defenses.
    2. Reduce trade by 1% for 1 year (cumulative) for each cyber attack.
    (100 cyber attacks = 100% reduction in trade for 100 years; your move, China)

    1. Re:China acts like an asshole by Anonymous Coward · · Score: 0

      That's a great idea.
      Signed Japanese or Korean person looking for a Chinese hosting site for 'reasons"
      Actually I was but hurt American pretending to be one of the above.
      See how trivial it was.

  13. Re:Sounds like this former FBI director by BeauHD++(3492052) · · Score: 0

    Also, Might We Add, there is not enough emphasis on Russia and it's mighty hackers. We need to go ahead and get a Cyber Army going to be able to hack into Russia's voters and make them vote against Putin next cycle and make the country collapse.

    If Putin is out of the way that gets TRUMP out of the way so we can have great things like prosperity and Hillary leading the world back into the hot flames of Progress to be forged into something good.

  14. Re:Sounds like this former FBI director by BlackOverflow · · Score: 1

    The FBI has no chance because all of China is running APK's impenetrable hosts file. They are 100% protected from any attack the FBI could conceive of.

  15. White hat here - lol no. Cops breaking in doesn't by raymorris · · Score: 4, Interesting

    Finding vulnerabilities and warning the vulnerable companies is what I do for a living. What we do is in no way a substitute for deterrence.

    Instead of putting muggers in jail, why don't our good guys try mugging people and alert victims that they're vulnerable?

    Instead of killing bin Laden, why don't our good guys just ram planes into all the buildings and then we'll know which buildings are vulnerable?

    Having cops break into the people's houses won't make burglary stop.

    The main benefit of vulnerability assessment, what I do for a living, is that when we make Lockheed Martin a more difficult target, the attackers focus more on Northrop Grumman, because it's an easier target. That's an advantage to Lockheed.

    We will never come anywhere close to making our county impenetrable. If we magically did, which would require a police state, two days Microsoft would release a new version of some software and we'd all be vulnerable again. Every time somebody installs anything connected to a network, there are opportunities for it to be configured poorly, and that happens a million times a day. We will never be secure. We can only make YOU a harder target than your neighbor.

    "Instead of starting a cyber war" - LOL! We're *in" a cyber war. Pur adversaries spend billions of dollars every year attacking us, and we're losing. Ignoring it and pretending it's not happening won't make it go away. The way to make a country (or a person) stop attacking you is to make it hurt them to continue, to exact a high price. If someone is swinging a knife at me, knowing I'm vulnerable doesn't solve the problem. You stop their attack by shooting them. That's what solar the problem.

  16. GayPK by Anonymous Coward · · Score: 0

    GayPK's host file can chortle my balls.

  17. hack their supply chain by Anonymous Coward · · Score: 0

    what the usa should do is hack china's supply chain so their exports are crippled and their economy suffers - if foxconn can't export electronics, tool factories can't export cheap tools, trinket factories can't export christmas decorations, clothing factories can't export cheap, thin, shoddy clothing, and so on, china would be crippled economically and unable to survive very long - we could hit them hard in trade! no trade, no prosperity - their government could collapse in months, and the usa would be going strong because we don't have any direct dependencies on foreign countries

  18. So no plans to ... by CaptainDork · · Score: 1

    ... be the smartest kid on the block and provide hardened entry points.

    Sounds like an excuse to fight fire with fire and then the US declares open season.

    I do not know why China doesn't get a branded credit card from Facebook, Apple, Google and Microsoft each.

    That way they could get points while buying all that stuff right off the shelves of the big box data stores.

    --
    It little behooves the best of us to comment on the rest of us.
  19. Five Eye already attacked by hackingbear · · Score: 1

    The Five Eyes have already attacked China. Now, can the Five Eyes just tell us where the Weapons of Mass Destruction are in Iraq?

    1. Re:Five Eye already attacked by Anonymous Coward · · Score: 0

      Yum! Five Eyes makes some delicious burgers.

  20. Re:White hat here - lol no. Cops breaking in doesn by Archtech · · Score: 1

    [Our] adversaries spend billions of dollars every year attacking us

    Evidence? Citation? Or is that just a wild paranoid guess?

    The US government spends about $1 trillion every year on its armed forces, weapons, ammunition, the many secret police "agencies", and paying vast numbers of head-chopping, heart-eating terrorists to attack everyone the US government doesn't like.

    The USA is far and away the world's biggest spender on "defence" - which of course, in true Orwellian fashion, really means "aggression".

    Because everything in the world belongs to Americans, but some damned foreigners just refuse to accept that.

    --
    I am sure that there are many other solipsists out there.
  21. MADDoS by Anonymous Coward · · Score: 0

    Mutually Assured Distributed Denial of Service

  22. Yet again, a non technical person talking... by Anonymous Coward · · Score: 0

    about technical things.

    Attacking china will only shore up their defenses and give them better ideas on how to attack us.

    The ONLY way to stop China from attacking others is to stop hording zero days for the TLAs, and help companies secure their networks and also promote security first development. Unfortunately when all you have is a hammer then everything looks like a nail. The FBI has so many exploits that it always will look like the best way forward is to attack them and try and cripple their infrastructure. This is a horrible idea as it is based off the assumption that the Chinese are dumb and unable to react to the attacks. They will learn and adapt and then they will come back twice as strong using new evolutions of our own attacks against them.

    But hey, lets listen to a politician about how to secure computational resources instead of someone with real technical expertise.

  23. Re:White hat here - lol no. Cops breaking in doesn by Anonymous Coward · · Score: 0

    We write 0 days just for you assholes, because you think you know 'security'

  24. Honeypot of false info by hunter44102 · · Score: 2

    Why don't companies create millions of fake sites with false tech info and documents to make it impossible to figure out what they are stealing?

    1. Re:Honeypot of false info by aybiss · · Score: 1

      I thought that was what the advertising industry basically was.

      --
      It's OK Bender, there's no such thing as 2.
  25. Slashdot DEFENDING intelectual property?! by Anonymous Coward · · Score: 0

    When did Slashdot become home to people who are big on defending intellectual property??

    Remember when every one was happy when DeCSS came out because nobody was happy with they way movie studios were protecting their intellectual property?

  26. Sure they are by rsilvergun · · Score: 1

    you're thinking like a member of the working class. The Ruling Class is global now, and they get along just fine with China. Sure, there's the occasional bit of back and forth, but it's all in good fun.

    Now, as a member of the working class the Chinese government is about the worst thing ever. They massively drive down wages and standards of living across the globe. But good luck doing anything about that. It's hard to say no to a 50" TV for $200 bucks.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  27. Re:Sounds like this former FBI director by Anonymous Coward · · Score: 0

    You elected a stupid girl from New York to the US Congress. Not even the Russians could have managed that feat in a US election.

  28. Because... by jd · · Score: 2

    Fighting a hot cyberwar against an entire nation that can be turned into a supersized botnet (and which probably runs half the existing major botnets out there), when your own country has grotesquely incompetent IT managers, virtually no cybersecurity, a bunch of Federally-required backdoors into mission critical systems and a vast number of SCADA-based critical servers on the public Internet, is such a good idea.

    I mean, what could possibly go wrong?

    --
    It's a small world and it smells funny; I'd buy another if it wasn't for the money; Take back what I paid (SoM)
  29. How are things at Microsoft? Or is Adobe? by raymorris · · Score: 1

    > We write 0 days

    How are things at Microsoft these days? If you get bored there, Adobe is hiring zero-day creators.

  30. AGREED!!! by Anonymous Coward · · Score: 0

    "Retaliatory Cyber Attacks Are Only Way To Stop China, Says Former FBI Director"

    I for one, completely agree!!!

    Targeted companies should/must try to improve their computer security?
    Absolutely yes! But, isn't that already & always tried, as much as possible?
    & is there any computer hardware/software, anywhere in the world, that is hacker/malware-proof?
    Absolutely no!
    So, this theoretically cannot ever be a complete solution to the problem anyway!!!
    (As long as (absolutely) hacker/malware-proof computer hardware/software never invented!)

    Are any/all diplomatic/political ways tried & failed?
    IMHO, the answer is yes!

    Then, what option is really left to do, other than retaliation in kind?

    Already, if we look at how countries of the world take care any/all kinds of problems between each other,
    it is clear that, equal retaliation in kind, is always the final action (that works),
    whenever other diplomatic/political ways tried & failed!

  31. Re:White hat here - lol no. Cops breaking in doesn by Anonymous Coward · · Score: 0

    Finding vulnerabilities and warning the vulnerable companies is what I do for a living. What we do is in no way a substitute for deterrence.

    Deterrence is no substitute for nuking it from orbit, and that's basically the only thing that's going to slow down or stop China from attacking other countries. Attacking them in response leads to escalation.

    Instead of putting muggers in jail, why don't our good guys try mugging people and alert victims that they're vulnerable?

    As one of a hundred other bad analogies, you can't stop people being mugged. Nor can you really stop all cyber attacks. But large areas of cyber attacks can be 100% stopped. There is no good real world analogy to normal crime because logic circuits can provide actual limitations on the possible.

  32. IMPERSONATING ME AGAIN? apk by Anonymous Coward · · Score: 0

    gweihir KNOWS u IMPERSONATE me https://it.slashdot.org/commen... c6gunner proves it https://linux.slashdot.org/com... he forgot to SUBMIT as AC & using his registered 'lusrname' instead (because he tried to mock me both BEFORE & after I FAIRLY challenged him to show he's done better work - he had ZERO).

    & NO WAY I'd "cry" like you "ne'er-do-wells" on /. (TROLL /.ers, not all) OR post on hosts offtopic.

    YOU HELPED ME https://science.slashdot.org/c... (& you quit trying to make me look bad trying to "tell lies" on hosts as "ME" IN YOUR IMPERSONATIONS of me e.g. https://tech.slashdot.org/comm... as regards Intel speculative execution attack? Hosts PREVENT 'EM)

    APK

    P.S.=> I KNOW the 2nd to last link above's KILLING YOU - YOU ACTUALLY HELPED ME getting me to see if hosts stop more than portsmash (& Meltdown + Spectre too) & "lo & behold" - hosts WORK on 'em - U LOSE (& U STOPPED TRYING IT in your impersonations of me) .... apk

  33. Re:White hat here - lol no. Cops breaking in doesn by Anonymous Coward · · Score: 0

    Cool, you used yourself as the authority in the authority fallacy. We can see that it really is a fallacy because in no way the fact that you supposedly are a security worker helps make the argument stronger.

  34. That word doesn't mean what you think it does by raymorris · · Score: 1

    Look up argument from authority, also called an appeal to authority, or argumentum ad verecundiam before you use yhe term again.

    Michael Jordan endorsing tires is fallacious appeal to authority. Randomly movie star making statements about vaccines or politics is the same.

    Learning physics by reading Stephen Hawking is called *civilization*. The other option is inventing your own physics, which is mysticism.

  35. Channeling Paul Hogan by hackertourist · · Score: 1

    Nah, they're just kids playing. That's not a cyberattack, this (zhing!) is a cyberattack.

  36. How did net neutrality work out for you? by Anonymous Coward · · Score: 0

    How did net neutrality work out for you?