Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/10/2013
12:04 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

The Dragon In The Room

China, China, China

Everybody's talking China now. The federal government isn't mincing words anymore, either. No more worst-kept secret that Chinese cyberespionage is rampant, but you just can't really come out and say it. The Defense Department flat-out declared this week in a report to Congress that the Chinese government and military are attacking U.S. government networks. Then a bipartisan group of high-profile senators drafted legislation that would create a watch list of nations conducting cyberespionage against the U.S. and call out foreign firms that benefit from intellectual property stolen from the U.S.

Here's the last paragraph of the press release for the bill, called the Deter Cyber Theft Act: "Recent reports indicate that China is by far the largest source of theft attempts against U.S. companies."

The new trend of officially calling out China's cyberespionage machine actually started this past fall when the House Intelligence Committee warned U.S. companies to steer clear of doing business with Chinese telecommunications companies Huawei and ZTE due to their potential ties to the Chinese government and its spying activities. Then came Mandiant's big report on a long-suspected Chinese military link to cyberespionage against U.S. firms.

It's now OK to talk about the elephant -- er, dragon -- in the room.

"The first step toward recovery is to acknowledge our problem," quips Stewart Baker, partner in the Washington office of Steptoe & Johnson LLP and a former Department of Homeland security official. Baker says the U.S. is in "an attribution revolution" period. The intelligence community has known for more than a decade of China's activities, he says, but just hasn't spoken up like the security community has been doing.

"We know a lot about these attackers. We know what their girlfriends look like. It's not as hard as what we thought four years ago," he says. "It's embarrassing for the government because they've known this stuff for 10 to 15 years."

The "reason the debate changed," he added, is because of what security researchers at Mandiant, Trend Labs, and Citizen Labs have done, he says. "They are the only ones who have really given us the goods on the attackers. Frankly, it's a blow to the intell community that they couldn't figure out how to say things people without a security clearance could say," Baker says.

It's unlikely that the bipartisan Deter Cyber Theft Act bill, co-sponsored by Sens. Carl Levin, D-Mich.; John McCain, R-Ariz.; Jay Rockefeller, D-W.Va.; and Tom Coburn, R-Okla., is going anywhere anytime soon, though. Cybersecurity legislation -- well, practically any legislation for that matter -- has fallen flat in Congress lately. Attorney Kristen Verderame says the fact that the sponsors didn't pull in other stakeholders and committees for the bill indicates it was a more symbolic than serious legislative effort. They were basically making a statement, she says.

And for now, making a statement -- or lots of statements -- is at least a way to keep the conversation going. The trouble is that even if the average American is now at least familiar with the idea of Chinese hackers stealing U.S. trade secrets, the full economic impact of IP theft out of China has neither been truly been felt by him or her nor calculated in such a way to illustrate it.

Once that becomes clearer and its impact directly tied to American jobs and the economy, we'll need a lot more than new legislation. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17476
PUBLISHED: 2020-08-10
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
CVE-2020-9525
PUBLISHED: 2020-08-10
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an authentication flaw that allows remote attackers to perform a man-in-the-middle attack, as demonstrated by eavesdropping on user video/audio streams, capturing credentials, and compromising devices.
CVE-2020-9526
PUBLISHED: 2020-08-10
CS2 Network P2P through 3.x, as used in millions of Internet of Things devices, suffers from an information exposure flaw that exposes user session data to supernodes in the network, as demonstrated by passively eavesdropping on user video/audio streams, capturing credentials, and compromising devic...
CVE-2020-9527
PUBLISHED: 2020-08-10
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to execute arbitrary code via ...
CVE-2020-9528
PUBLISHED: 2020-08-10
Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from cryptographic issues that allow remote attackers to access user session data, as demonstrated by eavesdropping on user video/audio strea...