Showing posts with label Cyberwar. Show all posts
Showing posts with label Cyberwar. Show all posts

Friday, October 2, 2015

Xi in the White House: was the menu tasty?

As Prime Minister Narendra Modi returns to India after a highly successful trip to the United States (and Ireland), it is interesting to look at another high-profile visit, President Xi Jinping’s.
While Mr. Modi and US President Barrack Obama discussed several multilateral issues of common interest, including long term strategic issues such as China’s new assertiveness, the issue of climate change was central to the Obama-Modi talks.
While major powers, in particular China, have already pledged their CBDRs (Common but Differentiated Responsibilities), India is expected to announce its CBDRs in early October.
However, Xi Jinping’s US visit was important for several other reasons.
For the Chinese President, it was the first State Visit with a 21-gun salute on the White House lawn, an elaborate reception and a succulent ‘Sino-American’ menu for the State Dinner to which 240 selected guests from the US Industry and even Hollywood, were invited.
Before the visit, Reuters had mentioned ‘5 big challenges’ and their possible outcomes for the Sino-US relations.
First was ‘cybersecurity’ which has been the source of tension between the 2 superpowers.
Then was ‘climate change’: China is the world’s largest emitter of carbon dioxide and last year, it had pledged “to work towards a new global climate change agreement” to be agreed during the Paris’ UN Climate Change Conference in December.
Economy was a third issue on the agenda. Reuters says: “China’s faltering economy and perceived slow progress on market reforms are major concerns for global investors worried about its openness to foreign competition. The nation drastically devalued its currency in August, sending waves through global markets.” A bilateral investment treaty between Beijing and Washington is still far away.
More tricky was the tensions in the South China Sea. Beijing has recently developed a number of artificial islands and military infrastructure in the South China Sea causing “considerable concern from neighbouring countries and putting pressure on the US to address the conflict” said Reuters.
And of course, the Human Rights issue. Here Beijing is not ready to discuss anything, often citing the poor human rights’ records of the United States, where a Black has many more chances to be killed by a policeman than a White. Xi just agreed that human rights and democracy were important pursuits, “but that reforms would proceed in time with China’s timetable.”
Even for Washington, it was certainly not the most urgent issue to tackle, though it is useful for ‘public consumption’.
Incidentally, the Dalai Lama was in the US at the same time as Xi, but due to health problems, part of his program had to be cancelled; in any case no ‘official’ meetings had been planned.
The South China Morning Post (SCMP) spoke of ‘goldilocks problems’ faced by China: “When President Xi Jinping visits the United States, the mainland public is bound to receive wall-to-wall positive coverage of what Beijing has pledged will be a successful trip. But underneath the pomp and pageantry, Xi may find himself facing an American audience that is increasingly ambivalent towards China.”
The Hong Kong newspaper cites “a host of security and economic issues is a shifting balance between the two countries as China's clout continues to grow.”
An analyst commented “For nearly 30 years, a sense of opportunity for business and trade, …but now you have fear, anger and worry".
Let us look at the issue of cybersecurity.
Xi Jinping and Obama pledged to curb commercial cyberespionage.
The two governments announced that they would soon launch biannual ministerial-level talks. Xi stated that ‘lot of consensus’ had been reached with Obama, who asserted that both countries would refrain from state-sponsored cyber-theft of intellectual property.
It is easier said than done. Will the NSA stops peeping into Chinese servers? Will China rein in its hordes of hackers? And what is ‘commercial cyberespionage’? Will military espionage be allowed? Where is the limit between the two? Obama even admitted: "The question now is: Are words followed by actions?"
Though both leaders highlighted some areas in which the US and China could work together, they also acknowledged that many differences remain.
The Chinese media argued that Obama reiterated that the US would not interfere in Hong Kong and did not support ‘independence’ for Taiwan, Tibet or Xinjiang. Is it possible?
More important was the issue of the South China Sea. Xi reiterated China had the right to uphold its territorial sovereignty and that Beijing did ‘not intend to pursue militarisation’ of the artificial islands.
What means ‘militarisation’?
In the midst of the visit, the SCMP reported that according to Chinese military sources: “China might press on with land reclamation in the strategically important South China Sea despite US President Barack Obama’s warning.”
Xi ‘confirmed’ that the islands were Chinese territory from ‘ancient times’ and Beijing had the right to uphold its maritime rights.
A source close to the Chinese military told the SCMP that Beijing would carry out reclamation …when necessary “China needs those artificial islands and airstrips in the South China Sea, because [the area] is a supply base for its navy and air force in the Asia-Pacific.”
‘Peaceful’ supply?
Reclamation is bound to continue and though it is more and more worrisome for the neighbours, the US can’t do much about it.
These thorny issues were discussed during a private ‘informal’ dinner. For almost three hours, the two leaders, with a couple of aides, talked about the burning issues straining bilateral ties. Analysts say that it was an opportunity for the two leaders to ‘know each other’.
As Xi was leaving the dinner venue (at Blair House (sic), a guest residence nearby the White House), the American President waved at his guest and said ‘ni hao’ (‘hi’ in Chinese).
Will it be enough to sort out all the difficult issues? Probably not.
At the same time, Xi tried to project China as a ‘responsible’ stake-holder.
Xi pledged billions to battle climate change; in the joint statement, Beijing said that it will “make available 20 billion yuan (3 billion US $ billion) through a bilateral fund to help developing countries combat climate change”.
A few days later, Xi announced at the UN that China will take the lead to set up a permanent peacekeeping police squad, building a peacekeeping standby force of 8,000 troops, and again pledging one billion dollars.
But at the same time, Hong Kong newspaper Ta Kung Pao reported that China may have recently conducted a successful test of the fastest hypersonic aircraft in the world.
It quoted the website of the Aviation Industry Corporation of China (AVIC), which mentioned an initial test flight on an unspecified high-altitude, super-fast aircraft with a ‘unique flying style’. The report was deleted shortly after. Analysts however believe that Beijing is developing a new hypersonic aircraft that can travel at five times the speed of sound.
Though commentators say that for Xi, the opportunity to make personal connections with America's business and political leaders was important, it does not mean that China will be changing its ‘core’ positions.
Just before he left for the States, a report titled "The US-China Military Scorecard: Forces, Geography, and the Evolving Balance of Power, 1996-2017" had been released by the RAND Corporation, a US-based think tank. It argued: “Admitting that the People's Liberation Army still trails the US Navy considerably in terms of technology and skill, the gap has narrowed gradually between 1996 and 2017.”
Xi knows that, but China will not relent till it reaches the ‘level’ of the United States, which is Beijing’s ultimate objective.
A lot of tensions in perspective!
Narendra Modi’s visit was on a more peaceful and economic note.

Thursday, June 14, 2012

About state-sponsored attackers

I must say that it is quite unpleasant when you open your GMail box in the morning (or in the evening) to get this banner: "Warning: We believe state-sponsored attackers may be attempting to compromise your account or computer".
Once you have found what it is about, you are even more frustrated because you can't do anything about it, except 'strengthen' the security of your account.
But even then, the banner continues to appear. 
Does the 'state-sponsored' agency continues to pip into your emails (and computer)?
Google won't tell you.
And why in India?  
On the subject of 'state-sponsored' actors on June 4, 2012, Republican Senator John McCain testified in front of the Committee on Armed Services of the United State Senate. He said:
I believe that cyber warfare will be the key battlefield of the 21st century, and I am concerned about our ability to fight and win in this new domain. I authored a provision in the bill that requires the commander of U.S. Cyber Command to provide a strategy for the development and deployment of offensive cyber capabilities. I am very concerned that our strategy is too reliant on defensive measures in cyber space, and believe we need to develop the capability to go on the offense as well.
This provision to craft a comprehensive strategy should spur U.S. Cyber Command to develop this offensive capability effectively and at a reasonable cost to the taxpayer.
The question remains why should individual being 'warned' if they don't have the possibility to do anything about it. It is just bad publicity for Google.

Google to Warn Users About Possible 'State-Sponsored' Attacks
Chloe Albanesius
PCMag.com
June 5, 2012
Google has been rather warning-happy lately; from alerts about malware to blocked websites in China. Today, however, the search giant expanded those efforts with security warnings about state-sponsored attacks.
Google said the warnings will appear for a "subset" of users who Google believes "may be the target of state-sponsored attacks." When activated, a pink bar will appear atop various Google services (see below) with a warning that reads: "We believe state-sponsored attackers may be attempting to compromise your account of computer. Protect yourself now." The "protect yourself" text will link to a page with steps you can take to guard against unwanted intrusions.
That includes creating strong passwords, enabling Google's two-step verification, and updating your browser, OS, plugins, and document editors, Eric Grosse, vice president of security engineering at Google, wrote in a blog post.
Grosse warned users about phishing attacks that spoof Google services; be sure that the URL reads "https://accounts.google.com/" before entering your Google password.
"If you see this warning it does not necessarily mean that your account has been hijacked," Grosse said. Nor does it mean that Google's own system has been compromised.
"It just means that we believe you may be a target, of phishing or malware for example, and that you should take immediate steps to secure your account," he said.
How does Google detect these possible attacks? "We can't go into the details without giving away information that would be helpful to these bad actors, but our detailed analysis—as well as victim reports—strongly suggest the involvement of states or groups that are state-sponsored," Grosse wrote.
The news comes several days after Google announced plans to display warnings to Search users in mainland China when their query was likely to result in an error beyond the search giant's control.
Google has had a rather tumultuous relationship with Chinese officials in recent years. In January 2010, Google said there were attempts to hack into the Gmail accounts of Chinese human rights activists. At the time, Google pledged to no longer censor search results in China, even if that meant pulling out of the country entirely, and re-routed all Google.cn traffic to the uncensored Google.com.hk. Unsurprisingly, a Chinese minister warned of "consequences" if Google continued redirecting its results. Finally, the two parties settled on a hybrid solution.
Last month, Google also pledged to warn users whose computers or home routers appear to be infected with the DNSChanger malware. Google first started adding malware warnings to search results last summer after it noticed some unusual activity on its network while conducting routine data center maintenance. Google said last month that that effort resulted in warnings for 1 million of its users.

Friday, December 23, 2011

India should be watchful

The rumor was so persistent that Prime Minister Manmohan Singh had to reassure the Lok Sabha “Our government does not share the view that China plans to attack India,” adding that India’s borders with China “by and large remain peaceful”.
In recent weeks, several senior analysts have predicted a repeat of the 1962 conflict between India and China. The most prominent is Brahma Chellaney of the Centre for Policy Research who wrote: “China’s expanding axis of evil with Pakistan, including a new troop presence in PoK, heightens India’s vulnerability in Jammu and Kashmir, even as India has beefed up its defenses in Arunachal Pradesh.”
In the Parliament, it is the Samajwadi Party Chief Mulayam Singh Yadav who declared that he had information that China was making preparations to attack India and that Beijing had “marked out areas near the borders for this purpose”.
A few weeks earlier, a Senior IDSA Fellow Ali Ahmed had also put oil on the fire by publishing a Brief (‘A Consideration of Sino-Indian Conflict’) in which he spoke of hostilities “confined to a specific section of the border, limited in duration and amenable to a negotiated termination,” a Kargil-type situation.
The main common argument is that India is today not prepared for a war. This is an undisputable fact. A weekly magazine published a cover story arguing: “Fifty years after its only defeat, the Indian Army is still unprepared for a battle with its scheming adversary, China. Low on equipment and lacking in infrastructure, the bloated war machine is in urgent need of an overhaul.”
Though Defence Minister AK Antony affirmed that no infiltration had taken place across the LAC in Arunachal Pradesh, he admitted: "there have been instances of a few Tibetan herb collectors inadvertently crossing over into Indian territory in the last two years." It is common knowledge that the Chinese are masters at testing the ground by sending herders or herb collectors to scout areas that they ‘perceive’ as theirs.
Antony explained: "There is no commonly delineated Line of Actual Control (LAC) between India and China …in a few areas India and China have different perception of the LAC.”
The postponement of the Special Representatives’ talks which was conveniently attributed to the fact that the Dalai Lama was to address a Buddhist Conference in Delhi, was one more sign that Beijing is not interested to clarify these ‘differences of perceptions’.
When Antony mentioned his ministry’s decisions to deploy new radars: “the deployment of radars, including mountain radars, is based on various factors like operational requirement of IAF and security needs of the country”, it send shivers down the public’s spine.
Will 1962 repeat itself?
One can’t deny that it is the perfect time to attack India; in a few years she may be much better prepared.
Take the roads for example: in January 2008, during a visit to Itanagar and Tawang, the Prime Minister announced a Rs 24,000 crores package for the State. The priority was given to the roads (in particular, the construction of a Trans-Arunachal Highway).
With the road being enlarged between the plains of Assam and Tawang (en route to the Tibet border), one finds the messiest imaginable road site which has become the favorite topic of local jokes. It will definitively be different in five years time.
It is however difficult to share the analysts’ pessimism. One of the reasons is that China has its own problems to deal with.
First and foremost there will be a leadership change in 2012. President Hu Jintao, Premier Wen Jiabao and five others of the nine-member Standing Committee of the Politburo, will retire in October next year. China will then witness a period of transition, in other words, a time of instability which could last for a couple of years.
To decide to go to war (with India or any other nation), China needs a stable and strong established leadership or as in 1962, a leader with extraordinary charisma (Mao Zedong); it is not the case today. The main factions of the Communist Youth League Clique (led by Hu Jintao) and the Gang of Princelings (led by Xi Jinping) will have to fight it out to take an ascendant path and impose hard decisions.
Could a new Mao emerge from the Fifth Generation? It is doubtful.
There are other differences between 1962 and 2011: the then foolish Indian leadership did not dare to use the Air Force, it will not be the case today; a full squadron of Sukhoi-30 aircraft have now been deployed at Tezpur air base in Assam (another squadron has been brought to Chabua in Upper Assam). Further, the IAF is planning to open six Advanced Landing Grounds, as well as several helipads in areas close to the border. This may take some time, but the process has started.
Were India attacked today, it will not remain a localized conflict (as predicted by IDSA) like in 1962; any Chinese misadventure would trigger an ‘all-out’ conflict, and India would certainly not hesitate to attack the PLA infrastructure in the Nyingchi Prefecture, north of the McMahon line. Hopefully, the Chinese are aware of this.
It has been in the public domain that two new infantry divisions have been raised and that the Government is looking for a place in the Northeast to set up the headquarters of a Mountain Strike Corps.
Another crucial factor is the support of the local population in Arunachal and Ladakh. In 1962, some villages fully supported the invading Chinese troops. How else could the PLA have built a road from Bumla, the border pass, to Tawang in 18 days? It is not difficult to imagine the amount of accurate intelligence required for this feat.
None of the analysts have gone into the question “What will China gain from such a misadventure, apart from a hypothetical Asian supremacy?”
China perhaps cannot ‘take back’ Tawang militarily; the PLA could at the most occupy a few ‘disputed pockets’ like Samdorong Chu valley, north of Tawang or Demchok in Ladakh, but in the process, Beijing would lose India’s present goodwill and the international respect they earn through their ‘peaceful rise’ policy as well as their integration into  the world scene as a responsible State.
Further, it should not be difficult for India to instigate a 1959-type rebellion in Tibet and support it militarily; at least a civil disobedience could be organised. Let us not forget that an alien PLA has already to deal with a resentful local population on the Tibetan plateau. The recent immolations of monks and nuns in Eastern Tibet are a proof of this.
It is true that China has been rather aggressive on the border issue lately and that India is not fully ready to tackle the Dragon, but India has her own cards to play and hopefully, she will play them well.
The proposed launch of the Agni-V long range missile is one of these cards. It has already made Chinese policy makers ponder. The People's Daily stated that it reflects India's “intention of seeking regional balance of power”. The mouth piece of the Party quoted some Indian and scientists describing Agni-V as a ‘killer for a certain country’.
If Beijing wants again to ‘teach a lesson’ to India, it will indeed be a Himalayan task, and what will Beijing gain in the bargain?
Nevertheless, China can use more asymmetric types of warfare, cyber-warfare is one of them. While India continues to prepare the defence of her borders, she should remain watchful of her interests and not take for granted the profession of friendship by anybody.

Saturday, June 11, 2011

Fighting it out in cyberspace


This article has been published in The Pioneer (yesterday's edition).

In today’s cyber age, missiles, bombs and guns will become increasingly irrelevant as nations hack into each other’s computer servers to rob data.

Sometimes one can see a smile appearing behind the most serious issues. The ease with which hackers can intrude into the privacy of your e-mail accounts or hack your personal computers is one of these serious issues which make individuals and Governments extremely uncomfortable. But not always. At times, it can also bring a smile, as it happened recently when MI6, Britain’s external spy agency, and the Government Communications Headquart-ers managed to penetrate one of Al Qaeda’s websites whose objective was to recruit ‘lone wolf’ agents.
According to a report in The Daily Telegraph, “When Al Qaeda followers tried to download the 67-page colour magazine, instead of instructions about how to ‘Make a bomb in the kitchen of your mom’ by ‘The AQ Chef’ they were greeted with … cupcake recipes.” The British intelligence hackers had removed the original page containing instructions for making a lethal pipe bomb using sugar, match heads and a miniature light bulb attached to a timer and substituted it with a recipe for making cupcakes.
In April 2010, an incident which lasted 18 minutes sent shivers through the Pentagon and the White House. A report of the US-China Economic and Security Review Commission later admitted that the Internet traffic of the US Administration and military was briefly redirected through servers in China. The 18-minute hijack affected about 15 per cent of the world’s online traffic, particularly that of Nasa, the US Senate, the military and the office of the Secretary of Defence.
More recently, Google has again accused China of stealing personal passwords and breaking into sensitive e-mail boxes. The spokesperson for Google said, “We recently uncovered a campaign to collect user passwords, likely through phishing. This campaign, which appears to originate from Jinan, China, affected what seem to be the personal Gmail accounts of hundreds of users including, among others, senior US Government officials, Chinese political activists, officials in several Asian countries (predominantly South Korea), military personnel and journalists.” This was a pointed accusation, as an important signals’ intelligence unit of the PLA is located in Jinan.
Google’s accusation was immediately denied by the Chinese Government. The China Daily spoke of a ‘political farce’: “Google is playing its old tricks at a time when the US Government and the public are making a great whoop on the issue of the Internet. One is led to believe that Google has attempted to play a role in a political farce… Therefore, if Google has really suffered from ‘Chinese hackers’ attacks, it could resort to the judicial cooperation mechanism between China and the US to find solutions.”
A week earlier, the American defence contractor Lockheed Martin admitted that it had also been hacked, though “it managed to stop the ‘tenacious’ attack before any critical data was stolen”. Knowing that Lockheed Martin deals with US defence hardware and software, this news would not have left the Obama Administration indifferent.
What American analysts fear the most is an ‘electronic Pearl Harbour’. The US’s apprehensions are underscored by what Mr James Miller, the Principal Deputy Undersecretary of Defence for Policy, has had to say on this issue: “Over the past decade, we have seen the frequency and sophistication of intrusions into our networks increased. Our networks are scanned thousands of times an hour."
On May 25, China Review News, a publication in Chinese language, reported that the Ministry of National Defence spokesman, Senior Colonel Geng Yansheng, had acknowledged the existence of a professional cyberwarfare unit at Guangzhou Military Region (known as the ‘Online Blue Army’). Col Geng admitted: “China’s network protection is comparatively weak. Enhancing IT capacity and strengthening network security protection are important components of military training for an Army.” He refused to answer whether the objective of the ‘Online Blue Army’ was to attack other countries.
While the Chinese Foreign Ministry has dismissed Google’s allegations, two PLA Senior Colonels, Ye Zheng and Zhao Baoxian, have written an essay for China Youth Daily, arguing that Beijing needs cyberwarfare skills: “Just as nuclear warfare was the strategic war of the industrial era, cyberwarfare has become the strategic war of the information era, and this has become a form of battle that is massively destructive and concerns the life and death of nations.” The PLA is said to have already conducted simulated cyberbattles between a ‘Blue Army’ fighting a ‘Red Team’ using virus and mass spam attacks.
The future is rather depressing. According to The Wall Street Journal the Pentagon is ready to respond to computer sabotage with military force. “The Pentagon has concluded that computer sabotage coming from another country can constitute an act of war, a finding that for the first time opens the door for the US to respond using traditional military force,” the daily said recently. But it is not an easy proposition to decide at what point computer hacking can be construed as an act of war. Apparently the Pentagon has defined some criteria, but are they reliable?
Another issue is how to be sure of the origin of the attack. Further, will missiles solve hacking problems or will they just be a deterrent? Look at the situation in Libya: Despite thousands of missiles being launched, three months into the conflict Colonel Muammar Gaddafi is still going strong. There is clearly no ready-made solutions to cyberwar.
But there is another side to the issue. Kaspersky Security Lab Service recently published a fascinating interview on China’s cybersecurity and the fact that China is itself extremely vulnerable to cyber attacks. A friend commented, “I’m not surprised that China is vulnerable. This is yet another example of why security is asymmetric in nature. It calls for great effort to plug all the holes (defensive action) as opposed to the effort required to find one hole (offensive action).” In the cyberworld, offence is the best defence. This is ‘active defence’.
China’s hackers will probably continue to attack targets abroad. However, the fact remains that China’s servers are possibly not so secure. If Beijing refuses to cooperate, it could also face serious problems with protecting official data.
A Worldwide Cybersecurity Summit was recently held in London with Ministers from the UK, the US, China, India and France gathering to discuss how to combat the threat of cyber-terrorism. Different opinions were shared. France, for example, believes that if nations are able to work together and set up international security standards, national laws are enough to fight this scourge.
For India the situation is different: It sees cyberspace as a borderless world; therefore, a global legal regime is needed to deal with issue. As Mr Kapil Sibal, Minister in charge of IT and communications, says, “The nature of cyberspace is that it is borderless and anonymous and it is not subject to Government territories that have laws,” adding, “There is a fundamental contradiction between Government regulation and the nature of cyberspace.”

Thursday, June 9, 2011

What you need to start a war now is not a trigger, but a mouse

My article What you need to start a war now is not a trigger, but a mouse appeared in today's edition of the DNA. Click on the title to read.

Sunday, May 1, 2011

Chinese Cyber Weakness


The Kaspersky Security Lab Service has just published a fascinating interview about China's cyber security. 
A friend commented: "I'm not surprised that China is vulnerable, this is yet another example of why security is asymmetric in nature. It several orders of magnitude of effort to plug *all* the holes (defense effort) as opposed to the effort required to find *one* hole (attack effort).
So this 'new' finding that might 'surprise US policymakers and Pentagon officials' is rather odd, I don't think it would surprise anyone in the security community assuming the broadest possible definition of security community."
In the previous Chinese White Paper on Defense, the concept of Revolution in Military Affairs (RMA) comes up again and again, so is the idea of ‘active defensive’. 

Practically it means a military strategy in which China does not initiate wars, but engages in war to defend its national sovereignty and territorial integrity: “Strategically, it adheres to the principle of featuring defensive operations, self-defense and striking and getting the better of the enemy only after the enemy has started an attack,” says the WP which also introduces the notion of ‘RMA with Chinese characteristics’.
The WP gives the history of the concept: “Entering the 1990s, the PLA began to vigorously promote RMA with Chinese characteristics. It established the military strategic guideline of active defense for the new era, based on winning local wars in conditions of modern technology, particularly high technology. It began to adopt a strategy of strengthening the military by means of science and technology, and a three-step development strategy in modernizing national defense and the armed forces, and promoted the coordinated development of national defense and economy.”
This gives us an idea of the general direction in which the PLA wants to go in the years to come, but nothing very specific is mentioned.

In the cyber world, the best defense is attack, this is 'active defense'.
The Chinese hackers will probably continue to attack target abroad, however it remains that the Chinese servers are unsecured. 
Beijing will have to tackle this issue in the years to come, if it does not want to face serious drawbacks. 

Glass Dragon: China's Cyber Offense Obscures Woeful Defense
April 27, 2011
Paul Roberts
The official line in Washington D.C. is that there's a new Cold War brewing, with an ascendant China in the place of the old Soviet Union, and cyberspace as the new theater of war. But work done by an independent security researcher suggests that the Chinese government is woefully unprepared to fend off cyber attacks on its own infrastructure.
For the last 18 months, Dillon Beresford, a security researcher with testing firm NSS Labs and divorced father of one, has spent up to seven hours a day of his spare time crawling the networks of China's state and provincial governments, as well as stealthier networks belonging to the PLA and the country's top universities. Armed with free tools like Metasploit and Netcat, as well as Google Translate, he's pulled back the curtains on the state of cyber security in China. What he's discovered may come as a surprise to many U.S. policymakers and Pentagon officials.
Contrary to the image of China as a nearly invincible cyber powerhouse, Beresford says in an interview with Threatpost Editor Paul Roberts, that the fast-growing nation suffers from woeful cyber security practices at home that leave, literally, thousands of networks and databases vulnerable to even trivial, remote attacks. Beresford, who publicized holes in domestic Chinese SCADA systems in September, 2010, said the country's aggressive cyber offense abroad, he said, is in stark contrast to an almost total lack of basic cyber defense at home that has left both classified and unclassified government networks vulnerable to attack and compromise. That should give the Chinese government pause as it ponders the consequences of a global campaign of cyber espionage, and create an opportunity for the U.S. and China to de-escalate what he sees as a growing cyber arms race. Beresford has publicized holes in recent weeks highlighting insecure mail servers and databases he has uncovered. He spoke to Roberts on April 26th, 2011.

Threatpost: Why China? What got you looking at the vulnerability of China's networks?
Dillon Beresford: The best answer to that question is 'curiosity.' I was reading a lot about cyber war  and the capabilities of PRC and PLA. I was hearing a lot about the vulnerability of U.S. critical infrastructure, so I got interested in China and wanted to find out about its infrastructure - map out the flashpoints.

Threatpost: You suggest that China's single party system is actually to blame for some of the poor security practices you discovered. Can you explain?

Dillon Beresford: One of the things I thought about with my research is the issue of transparency. This is an issue in China and, I would guess, other authoritarian regimes. A lot of what is running in China is developed in-house by Chinese firms.  They're not using Western products or open source platforms, because they don't trust them or they're worried that someone might put a back door into them. The down side is that they don't benefit from the whole community of people who are crawling over those platforms and patching bugs and looking for holes.
In China, you see that not a lot of government and private sites are interconnected, as they are in the U.S. That kind of interdependence allows there to be lots of eyes looking at the same network and make it more likely that mistakes will get discovered and reported. But, in China, the government runs everything and there's no clear policy for cyber security.
In Chinese culture, also, its hard to publicly come out and admit mistakes - a fear that people will lose faith in their abilities. So, for example, a journalist who is writing on this got an email from an official in the Office of Foreign Affairs who was worried about losing his job.

Threatpost: It's interesting, because the picture you paint is so different from the one that's presented in the media.
Dillon Beresford: Yes. The media hype in the U.S. is all about cyberwar  and how the Chinese are kicking our ass. I wanted to know how vulnerable are the Chinese, and what I found is that they are just as vulnerable as the U.s. if not more-so. In large part, I think its because of this lack of transparency and openness. I'm hoping that, as a result of my work, they might realize this and maybe tone down their aggressiveness towards U.S. After all, we have the best people and it won't be long before other researchers will do as I have.

Threatpost: Why haven't other security researchers looked at this before you?

Dillon Beresford: I think the language barrier has discouraged people, but with Google's translation tools, that really isn't an issue any more.

Threatpost: How have you managed to navigate these networks and sites?


Dillon Beresford: Rosetta Stone. I've been studying Chinese for a year now, so its getting easier. And I work with people from China, which helps. 

Threatpost: How do you choose your targets?

Dillon Beresford: Its really not hard. In fact, the amount of data I have found that is not intended for public consumption is amazing. I stopped after three terabytes. These systems are not maintained  and are all vulnerable to attacks. HTTP is just one attack vector, but there are many others. For example: there was an LDAP server that was accessible from the Internet and it running a vulnerable version of PHP and, in addition, everything on the server was running as root. I find that a lot - its a bit of laziness by system administrators that makes their job easier. I was able to compromise the the server and then simply enumerate the directory and find other file servers and systems on the network that weren't connected to the Internet. Another example is China's National University of Defense Technology. They had a bunch of Web servers that weren't using SSL or HTTPS, so everyone was logging in using plain HTTP. All you needed to do was compromise one box and you could sniff all the user names and passwords in clear text.

Threatpost: What kinds of vulnerabilities are you finding commonly?

Dillon Beresford: As I mentioned to you before, vulnerable VxWorks installations are very common. I see a lot of Huawei integrated access devices in the private sector there as well, and they all run VxWorks. When Cisco went to vxworks so did Huawei, and they're just out there listening and waiting for a connection, and they haven't been patched or they've got weak passwords that you can brute force. You can just fire up Metasploit and find the vulnerable vxworks installations.  Once you have one vulnerable system, say a switch or router, its very easy to pivot from that to other devices.
I've found lots of appliances - routers, firewalls, IPS. A lot of them have back doors left by the developers. If I find it, I can generally exploit it and get into it. A lot of these devices have Web interfaces that have remote command execution vulnerabilities that allow you to use a function call, say, to log into the device without authenticating. If you have NetCat, you can just fire it up and connect directly to the box. And these publicly exploitable devices are so important, because they're potentially connected to other parts of the network that are even more vulnerable, because it was assumed that they're not public. So, if you find a Web server that's connected to a private LAN (local area network) and the Internet, you can compromise it, then reach out and compromise ever other box on that network.

Threatpost: You've found lots of evidence of weak authentication and passwords, as well?

Dillon Beresford: Yes. I'd estimate that 40% of logins are user name and either all numerical or all lowercase passwords. There are no hash or space characters. They're not complex and there are weak access controls - controls that aren't properly implemented, or there's no password requirement or two factor authentication, which is becoming increasingly common in the West. You don't see any of that in China.

Threatpost: As you talk to officials in China, what sense do you get about the reasons for the widespread problems with insecure IT infrastructure?

Dillon Beresford: I think China is growing very fast and there aren't enough people to maintain the infrastructure. They have more networks and government sites than their own government can even maintain. They don't have the manpower or even the knowledge to maintain them. And, in many ways, China is still playing catch up with the US. They're an aggressor in cyberspace, but their own networks are very weak and poorly designed. I'm not saying that to shed a negative light on China, but there's so much out there that they just can't maintain it all. Beyond that, there's a lack of trust in Western products - even open source products. A fear that people will put back doors in them, which really misunderstands what open source is about, which is: if we have a lot of eyes looking at the code, people will spot problems and fix them.

Threatpost: Have there been any "whoa!" moments where you've come across a hole or exposed data that really surprises you?

Dillon Beresford: That moment was probably the National Institute of Defense Technologies. I mean, when you think about it, they have supercomputers there that they use for cryptography. What's funny is that, if you look, you can't find a Web site for the Ministry of State Security or the Ministry of Cryptography, but most of the projects that the government allocates money for those agencies goes to universities. Its the students who create spy tools, so if you want to find the classified information, you just have to go to the University networks and get it.
Its the same with the People's Liberation Army. Their networks are hidden all throughout China and they're hard to find. But if you can find a vulnerable file server, you can pivot and proxy into a network that may be their equivalent of SIPRNet (the United States' classified information network). Students can make VPN connections into PLA networks. I've seen the client. You have students and cadets who attend university then, when they graduate, go to work for the PLA. In the meantime there's a lot of traffic going between the PLA and the universities.

Threatpost: What do you want to accomplish with this research?


Dillon Beresford: I've been transparent about this research and reported everything to China CERT. I want to create awareness of the problem and raise the bar. I'd like there to be open communications between the U.S. and China. We have to sit down at the same table. If other researchers like myself publish vulnerabilities maybe china will think twice about attacking U.S. companies and acknowledge that they have problems and weaknesses as well.