Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Which is quite different from saying it is being done by the Chinese government.

Read the uk ditto for comparison.



>> These activities can be linked to the hacker groups known as Advanced Persistent Threat 40 and Advanced Persistent Threat 31 and have been conducted from the territory of China for the purpose of intellectual property theft and espionage.

> Which is quite different from saying it is being done by the Chinese government.

Who in China would be more likely to organize an espionage campaign? Espionage is a game played by governments.

Your objection is like, after detecting a nuclear missile launch from the continental US, doubting that the US government was responsible.


There is a "slight" difference between getting/finding a nuke and a vurnerability.

There is also a "slight" difference in the difficulty of moving a nuke and a vurnerability across borders to launch it.

It's simply hard to know where data is coming from on the internet.


Here is the uk version:

https://www.gov.uk/government/news/uk-and-allies-hold-chines...

UK and allies hold Chinese state responsible for a pervasive pattern of hacking

UK joins likeminded partners to confirm Chinese state-backed actors were responsible for gaining access to computer networks via Microsoft Exchange servers.



Thank you.

These are worth reading. Even though I am not sure how much of it would be able carry the burden of proof in a court.

Similarly to the Russian hacking cases, these will never see an independent court meaning the prosecutor can politicize and speculate without limits.


They are not getting sent to the FISA court, that court only issues warrants. They are charged with conspiracy to commit economic espionage and conspiracy to commit computer fraud and are likely going to a federal district court.


This case will never go to court.


> Which is quite different from saying it is being done by the Chinese government.

Is it meaningfully different? Let's suppose that they aren't nationally funded. If there's a large group of elite hackers in your country generating international ill will is it not also your responsibility to shut them down? To work with the government of the country that these rogue hackers are attacking to find them? Not doing so is akin endorsing the behavior.

And it can't be anything else honestly. They are spy organizations, which are intentionally created to be difficult to track back to the funding government. We've seen the US do this for decades and have plenty of declassified documents to support this. It would be surprising if Russia, China, Germany, Australia, Israel, or anyone else didn't also operate in a similar fashion. If the method is effective then it is effective. The fact that a group resides in another country does not have any bearing on the effectiveness of the method.


Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt?

As opposed to many western countries where the companies might be patriotic, but they have minimal fear of taking on the government in general in the courts if they feel they are in the right. Perhaps Chinese companies have the same feeling of freedom, do they?


> Due to the level of control the Chinese government imposes on all the corporations within it, is it fair to say that such acts can't be done without the cooperation on some level of the govt?

Honestly even without the government imposing so much control on corporations I believe it is fair to say that the acts can't be done without cooperation on some level of the government. If there's an elite group of hackers in your country attacking a country and generating ill will then a hands off approach is condoning the action. The only way to condemn the action is to work with said country to apprehend said hackers. But headlines aren't "US and China work together to apprehend rogue elite hacking group."


No. It is not.

China is a big country and the Chinese government does not control everything that is going on.

Most hacking is done by kids with computers and uses trivial exploits: easy to guess passwords or security holes that are left unpatched for years after they are documented.

Fairly regularly I get a phone call from a guy with a strong accent claiming to be from Microsoft support. No one blames the Indian or Bangladeshi government for that.

Yet it is different for Russia and China.



You're being deliberately obtuse about this. The simplest explanation for cyberattacks against high-profile targets coming out of countries like China (or the US, for that matter) isn't "rando script-kiddies having a laugh ha ha!". It's that their government intelligence forces did it.

This kind of attempted misdirection is really common from people defending/spreading propaganda for the Chinese government. It's also similar to the excuses made when business partners with heavy government influence conduct scans and do other questionable things against US infrastructure. Apparently they think westerners are all too stupid or blind to understand what's happening. It's ridiculous.


What you're missing is that these attacks weren't targeted. They scanned internet and processed pretty much all accessible Exchange servers in the same manner. There were a few crews operating in parallel by the way which had access to same exploit chain but different exploits.

Some had certain variables hardcoded, e.g. Administrator user's name and their exploits worked with higher success rate in anglosphere, but failed in localized environments. Others had more advanced exploits which queried parameters instead of assuming them - those where more successful around the globe.

Another nuance missing from popular press is that most groups in China (and Russia) are operating independently, but share tradecraft among them and occasionally engage with politicized missions (either working on explicit orders from government handlers or simply defending their beliefs hacktivist-style). This is what FireEye means by "affiliation with Chinese government", NOT "operates strictly on government orders".


Why is it deliberately obtuse to think that some of China's billion people could be independent black hat hackers? Are they incapable of being evil or greedy?


They're not incapable of either. Are they as motivated as the government? In general, no. Genocidal dictatorships are more motivated than random script kiddies and "evil" black hat hackers to go after high profile government and government-adjacent (infrastructure) targets.


As the other commenter pointed out, these weren't really high profile targets. Hell, security groups found evidence they were planning to mine crypto on some of the servers. You don't need to be purposefully ignorant to question if private hackers were involved.


Whether the Chinese government has control over these APTs, the crime originated on Chinese soil, and it's their responsibility to deal with these threats. What's so hard for you to understand?


I don't think this makes much sense. We don't even know if the APTs actually do operate on Chinese soil, much less that the Chinese government condones them.

All we know is that they used Chinese IPs at some point and Chinese configured computers, and that they went after military targets.

And we don't even know that these are the same APTs.



Chinese citizens cannot even mention recent historical events on in private messages on the internet without approval from the government, and you're trying to tell us that some "kids with computers" were able to carry out a sophisticated years-long cyberattack? "Kids with computers" might be plausible in a free country, but not in China.


You obviously haven't met Chinese infosec researchers, have no knowledge about Chinese underground and are simply speaking from your biases.


It's a huge difference diplomatically to state specifically 'The Chinese Government' vs. 'Groups within China'.

That said, this is Germany. All those Chinese factories are built with Germany equipment. They are leading the 'softer language' position.

But the EU and NATO are not the same thing, so Germany can have it's cake and eat it too on this one.


Edit: here is the situation on Germany's stance on China [1] from a German news source.

"If jobs in Germany depend on how we deal with controversial topics, then we shouldn't add to indignation, but rather carefully consider all positions and actions,"

Germany is the 'big country' using the most careful language.

[1] https://www.dw.com/en/germanys-reluctance-to-speak-out-again...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: