FBI Director Warns Chinese Hackers Aim To 'Wreak Havoc' On US Critical Infrastructure (nbcnews.com) 98
"China's hackers are positioning on American infrastructure in preparation to wreak havoc and cause real-world harm to American citizens and communities, if or when China decides the time has come to strike," said FBI Director Christopher Wray in a prepared testimony before the House Select Committee on the Chinese Communist Party. NBC News reports: Wray also argued that "there has been far too little public focus" that Chinese hackers are targeting critical infrastructure in the U.S. such as water treatment plants, electrical grids, oil and natural gas pipelines, and transportation systems, according to the prepared remarks. "And the risk that poses to every American requires our attention -- now," his prepared testimony said.
As Wray testified, the Justice Department and FBI announced they had disabled a Chinese hacking operation that had infected hundreds of small office and home routers with botnet malware that targeted critical infrastructure. The DOJ said the hackers, known to the private sector as "Volt Typhoon," used privately owned small routers that were infected with "KV botnet" malware to conceal further Chinese hacking activities against U.S. and foreign victims. Wray addressed the malware in his testimony, emphasizing that it targets critical infrastructure in the U.S. [...]
At Wednesday's hearing, the director of the federal Cybersecurity and Infrastructure Security Agency, Jen Easterly, testified that Americans should expect efforts by China to wage influence campaigns online relating to the 2024 election. However, Easterly added that she was confident that voting systems and other election infrastructure are well-defended. "To be very clear, Americans should have confidence in the integrity of our election infrastructure because of the enormous amount of work that's been done by state and local election officials, by the federal government, by vendors, by the private sector since 2016," Easterly said in her testimony.
Wray emphasized in the remarks that the "cyber onslaught" of Chinese hackers "goes way beyond prepositioning for future conflict," saying in the prepared remarks that every day the hackers are "actively attacking" U.S. economic security, engaging in "wholesale theft of our innovation, and our personal and corporate data." "And they don't just hit our security and economy. They target our freedoms, reaching inside our borders, across America, to silence, coerce, and threaten our citizens and residents," the excerpts said.
As Wray testified, the Justice Department and FBI announced they had disabled a Chinese hacking operation that had infected hundreds of small office and home routers with botnet malware that targeted critical infrastructure. The DOJ said the hackers, known to the private sector as "Volt Typhoon," used privately owned small routers that were infected with "KV botnet" malware to conceal further Chinese hacking activities against U.S. and foreign victims. Wray addressed the malware in his testimony, emphasizing that it targets critical infrastructure in the U.S. [...]
At Wednesday's hearing, the director of the federal Cybersecurity and Infrastructure Security Agency, Jen Easterly, testified that Americans should expect efforts by China to wage influence campaigns online relating to the 2024 election. However, Easterly added that she was confident that voting systems and other election infrastructure are well-defended. "To be very clear, Americans should have confidence in the integrity of our election infrastructure because of the enormous amount of work that's been done by state and local election officials, by the federal government, by vendors, by the private sector since 2016," Easterly said in her testimony.
Wray emphasized in the remarks that the "cyber onslaught" of Chinese hackers "goes way beyond prepositioning for future conflict," saying in the prepared remarks that every day the hackers are "actively attacking" U.S. economic security, engaging in "wholesale theft of our innovation, and our personal and corporate data." "And they don't just hit our security and economy. They target our freedoms, reaching inside our borders, across America, to silence, coerce, and threaten our citizens and residents," the excerpts said.
The hackers hacked turtles all the way down (Score:3)
I'm pretty sure US & Taiwan have done similar hacks into China's infrastructure. If Taiwan gets invaded, we can probably kiss modern conveniences goodbye for several weeks at least.
Re: (Score:2)
As in, nationalize all foodstuffs and roll out the National Guard to the distribution centers inconvenient.
Re: (Score:2)
Re: (Score:3)
Re:The hackers hacked turtles all the way down (Score:5, Interesting)
Actually they probably don't, most of their infrastructure is rather new and fairly homogeneous and standardized and penalties for leaving them available to be attacked. Security is an achievable goal in that situation. They don't have the patchwork crazy-quilt of antique analog systems with digital adapters kluged on, the slapped together low-bid SCADA installs illegally connected to the corporate network, or the corporate executives too lazy to VPN into the network who insist on infrastructure connected directly to the Internet so they can review it while sitting in the coffee shop downstairs, or the regulators unable/unwilling to control the companies they're supposed to oversee.
Re: (Score:2, Interesting)
Isn't a bit like MAD theory with nuclear weapons? If both sides have a weapon so powerful, neither side can use it?
I suspect the US has penetrated every bit as deeply as China has, and they both have their hands all over the critical infrastructure (energy, finance, telecoms, IT, etc). There doesn't seem to be much that either side can keep secret if they try (eg. the Shadowbrokers taking out the elite NSA TAO group).
I imagine that we'd see much more strategic disruptions, ones that causes maximum embarrass
Re: (Score:2)
I doubt we (US) are in as deeply as China is to our country.
Its much easier for them to actually physically come over here (spies) in our open society and not stand out, than it is for us to go inside China.
I fear they have much better and nastier capabilities against our society than we do against theirs at this point.
I HOPE that's no
Re: (Score:2)
Re: (Score:2)
> why would you think that the USA has done exactly what Diector Wray suggests that the Chinese have done?
For one example, stuff like this:
https://www.risidata.com/index... [risidata.com]
All you cynics! (Score:4, Funny)
More like, decades. (Score:2)
>> I'm pretty sure US & Taiwan have done similar hacks into China's infrastructure. If Taiwan gets invaded, we can probably kiss modern conveniences goodbye for several weeks at least.
HAHA Weeks.
Nope.
It's more like, decades.
well its not like (Score:2)
Re: (Score:2)
Hacking Pianos (Score:2)
In the UK, it is Pianos getting Hacked.
Voting systems are "well-defended"? (Score:5, Interesting)
That reminds me of a quote:
"The Navy is ready. It is not going to be caught napping." --US Secretary of the Navy Frank Knox, December 4, 1941
Re: (Score:3, Interesting)
Re: (Score:1)
At most, the bomb shortened the war by a couple of weeks. Remember, the U.S. military was already very proficient at wiping cities off the map overnight.
The USA could have shortened the war by years if they had offered to the Japanese what they wanted all along and got in the end anyway: a guarantee that the Emperor would not be harmed.
Re: (Score:3, Interesting)
At most? That bomb saved millions of American lives, and I'm one of them. You may be too. But oh, if we only gave the feudal emperor what he wanted.... I hope you're never in charge of anything. Read a book.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Truman said "thousands and thousands" of young American lives. [millercenter.org] It was only after public sentiment turned against the USA that he changed it to "millions".
Re:Voting systems are "well-defended"? (Score:5, Interesting)
You are picking the nicest fairy-tale solution instead of being objective and realistic to how difficulty it would have been to take Japan via ground assault. It still took a whole year for Germany to surrender after D-day. Japan's population was 'fanatically hostile' and wouldn't just surrender as soon as the first American soldier landed.
Japan was beaten. It had little naval ships, no carriers, small airforce, few big weapons, and very importantly, no oil source to fuel their remaining military. Basically no military except poorly equipped infantry vs American's might, but still were not surrendering. Japanese civilians, especially women and young boys-the ones who had the best chance of causing American solders to let their guard down-were being trained to be kamikaze suicide bombers "For Emperor Hirohito's honor" in preparation for the inevitable invasion of Japan. Japanese men were taught how to Banzai attack in huge numbers.
The atomic bombs shorted the War in the Pacific by years, not months. It saved millions of lives-American, allied, and Japanese. The invasion of Japan could take years and the estimated casualties were 1M to 10M. A very grim prospect.
Re: (Score:2)
Russia was about to invade Japan, but the USA didn't want to share Japan with Russia as they did with Germany. So they dropped the bombs, and when Japan still wouldn't unconditionally surrender, the USA out of desperation finally offered the #1 condition that the Japanese wanted all along: a guarantee that the Emperor would not be harmed.
The Japanese quickly accepted the offer because they knew they wouldn't get the same terms from the Ru
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
Wrecking havoc on X, Facebook and Instagram (Score:2)
What other critical infrastructure is there?
Re: (Score:1)
What other critical infrastructure is there?
Shit which never should've been connected to the internet in the first place. It's like someone watched that late 90s "Hackers" flick and thought it was actually a good idea to implement all the net-connected things Hollywood took artistic license with, for real.
Re: (Score:2)
Re: (Score:2)
Paper ballots (Score:5, Insightful)
Where I am we have paper ballots, which are machine counted, and there's occasional hand recounts. Paper of course is notoriously difficult to hack, they'd also have to get physical access to both the ballots and the electronic record, also the final count is printed out and reported when the polls close, messing with all this would be absurdly difficult, and the several tons of paper they'd need to create and swaparoo won't fit in the pocket and is immune to the internet.
Re: (Score:3)
I think the hackers would pretty much just need to alter the results of the ballot counting in such a way that it isn't likely to trigger any hand recounts. Florida would be an easy state to manipulate because the elections are normally pretty close anyway, so you could easily get whatever result you wanted without it looking too suspicious. Although, for the Chinese there's not much point to messing with our democracy - both of our two major parties have jumped on the China BAD bandwagon.
Re: (Score:2)
They ought to be doing a few hand recounts randomly, and they probably are, that's just basic quality assurance.
Re: (Score:3, Insightful)
There isn't really any reason to need to electronically count. There just isn't.
People did hand counts for decades, using paper ballots. It's not confusing, it's not hard to do, and at least where I am -- members of all parties that wish it, can have a representative watch the count real-time. It's so immensely simple and non-complex. EG, you break them into groups of 10, or 100, or whatever, and then form bricks of votes in those groups. Again, super simple.
But people want to sell new machines, and bl
Re: (Score:2)
how confusing a pencil and an X are
That's actually the one thing the machine does that hand-counting cannot, for about 1-5% of ballots the machine says "Hey dumbass, you put too many Xs, if you like you can void this ballot and try again, instead of guessing maybe use our giant magnifying glass". So fewer spoiled/ambiguous ballots. The machine also provides the various vote counts right when polls close, so probably a very slight increase in security.
Conversely there's the possibility that the machine might be able to tell who voted for who,
How to do it (Score:5, Interesting)
I think the hackers would pretty much just need to alter the results of the ballot counting in such a way that it isn't likely to trigger any hand recounts.
The way to do this is to slowly add fake voter registrations in the weeks leading up to the election, then enter create ballots for all the fake voters. Some of these can be absentee ballots.
The focus on ballot counting machines and process problems during the election night are completely misdirected - you need a way to cheat that would be undiscovered during a hand recount.
Live up-to-the-minute reporting is a big help here. You keep track of which candidate is winning, estimate how much your candidate will lose by, then drop off boxes containing only enough ballots for your candidate to win by a small margin. This minimizes the number of fake ballots entered into the system, and reduces your chance of getting caught.
For extra safety, cook up some reason to pause counting until the next day, then drop the boxes off late at night when everyone's asleep.
Bayesian prior: if this practice were widespread, we should see a large number of elections where candidates win by a thin margin, and not several percentage points.
Bayesian prior: if this practice were widespread, we should see boxes of ballots dropped off late in the process (ie - late at night, after counting has stopped, or after polls close generally).
Re:How to do it (Score:5, Insightful)
That's actually a very good point. The whole voter registration process does seem like a weak spot. Just looking at a few state's Voter Registration sites, basically they are asking for your name, address, and drivers license / state id number. So the real vector could be the DMV.
Though I think (hope) with this new Federal 'RealID' there is less opportunity to screw around with the DMV databases.
And the debates about people who don't have official id not being able to vote...I'm ok with that. Same with people who forgot to register, or waited until after midnight to register...lots of things require you to prove your identity and do stuff on time. Voting is one of them.
Re: (Score:2)
Oh you mean you can lose your right to free speech, or to not be warrantlessly searched, etc if you don't register on time and show ID? Or just voting? You know, we have an affidavit process that allows for filling out a ballot despite having no ID, then proving your ID later. So this nonsense about ID is not about election security, it introduces a security flaw into the election process. Same with registration, if someone deletes the registration of all Rep voters for example should that invalidate them f
Re: (Score:2)
then drop off boxes containing only enough ballots for
Right, you just drop them off, how easy.
For extra safety, cook up some reason to pause counting until the next day, then drop the boxes off late at night when everyone's asleep.
Right, because that will somehow be less suspicious.
Bayesian prior: if this practice were widespread, we should see a large number of elections where candidates win by a thin margin, and not several percentage points.
Bayesian prior: if this practice were only happening in the imaginations of deranged idiots, we should see a large number of elections where candidates win by a thin margin, and not several percentage points.
Bayesian prior: if this practice were widespread, we should see boxes of ballots dropped off late in the process (ie - late at night, after counting has stopped, or after polls close generally).
Bayesian prior: there's idiots who think boxes of ballots can just be "dropped off" and for some reason people would be stupid enough to count them, plus be even less suspicious if there were a break-in, plus thi
Re: (Score:1)
Americans don't want paper ballots, because they can't manipulate them easily.
Their parties play politics like it's a game rather than a duty... and even then not seeming to care about doing it honestly so long as they can get away with it.
Re: (Score:2)
Re: (Score:1)
Ah. A whataboutism, great!
That's a different issue. Yes, elections can be monkeyed with when paper ballots are used. But that's having corrupt elections officials, bribing voters, or disrupting the count process, and on and on, which democracies typically strive to prevent, and has *NOTHING* to do with the ballot type.
However moving from paper -> electronic, means you introduce NEW issues. You cause ADDITIONAL issues, which are well known by everyone.
Re: (Score:3, Interesting)
I confess that way back in the day I was a proponent of electronic voting. In the way that a younger person cringes at any small amount of friction or inconvenience in their life. But maybe sometime after 2000 election but way before all the last 10-12 years of insanity I've done a 180.
Paper ballots, with machine counting is the way to go. It's the correct mix of tamper-resistant and relative expediency. If something looks fishy, or even if it doesn't fire up the hand recount. In the past I would h
Re:Paper ballots (Score:5, Interesting)
In Denmark we have paper ballots and hand counting. Voting places closes at 8 pm and we have a result of how many seats different parties have around midnight.
The day after it is recounted and split into which candidates are actually elected - does it really have to be any faster than that?
Re: (Score:2)
You are probably referring to the process of casting your vote 100% on a computer system, with no paper ballot.
However, I still believe there are still use cases for voting with a compute: using the computer to assist folks in filling out a ballot. This makes support for multiple languages and accommodations for the disabled easier and more flexible.*
I only advocate such a system if the output is a prepared paper ballot (inc
Re: (Score:3)
Re: (Score:2)
Re: (Score:2)
Obligatory XKCD [xkcd.com]
Re: (Score:2)
We could only dream of such a setup in the US.
It's far more difficult to cheat if the data isn't in digital form and / or has a hardcopy receipt to back the digital data up.
( Kinda like trying to steal a few billion dollars when the target has stored the entire thing in $1 bills )
I'll go ahead and make this prediction right now:
If the 2024 election in the US isn't the most honest, transparent and cleanly run election in the history of this country,
mass violence and chaos is going to be the end result. Folk
biggest threat to US Critical Infrastructure (Score:2)
Re: biggest threat to US Critical Infrastructure (Score:3)
There is similar rhetoric from China about US if you read Chinese-language media. Nothing overt, but slowly ratcheting the threat level. Hard to tell which side is driving it. At this point, probably both.
Re: (Score:2)
It would be surprising if one or the other came out and said they didn't think there was any significant threat. The default assumption here is that in the event of an escalation, pretty much everyone is ready to start hacking. We have seen it in Russia and Ukraine, and from North Korea, and of course for profit from numerous outfits all around the world.
Re: (Score:1)
Re: (Score:2)
Sure, China claiming incredibly important international waters that facilitate massive amounts of international shipping along with the territorial waters of many neighboring countries all while not ruling out armed conflict over the claims isnt causing problems that could potentially lead to war at all. It's all the words the US is saying obviously!
Never mind Chinas appalling human rights record that makes us look like saints in comparison.
Don’t look here! Look there! (Score:2)
”If or when” China decides? I’ve heard more valid threats from a fucking 6-year old on the playground. Sounds more like Wray is desperate to put the spotlight on anyone but him right now. Don’t fall for that standard shit to dispel incompetence and/or corruption.
Re: (Score:2)
Is it that time of the year again when the spook agencies are asking for more money again? Maybe they should stop constantly purchasing American private data.
Yeah, or maybe cheap-ass citizens should stop trading their digital soul for a "free" price tag. Root cause, is root cause. They weren't buying data like this 20 years ago, that's for damn sure.
And funding has little to do with being corruptly guilty of bending a political knee and weaponizing the FBI against American citizens. Wray is desperate to point at anything to set on proverbial fire in order to take the heat off him right now. Kind of reminds me when I was sitting on a Military tarmac at 4AM pr
Re:Don’t look here! Look there! (Score:4, Interesting)
For a real world reference (Score:3)
China has been attributed [csoonline.com] by the US government of hacking the OPM database in 2015. That database has every HR detail you can image and then some, on every US Federal government employee with exception to the CIA and military, (if I am not mistaken on that last detail).
Attacking US critical infrastructure via hacks is one of China's best options against the US, and is aimed to make the US think twice about defending Taiwan. Unlike bombs, many levels of hacks don't face reciprocity, like the OPM database theft. By the way, that database OPM used was part of Adobe Coldfusion [arstechnica.com]. Coldfusion got hacked.
FWIW, who knew people still use Coldfusion [adobe.com], or that there's still Coldfusion conferences [adobeevents.com]? Who is using Coldfusion in 2024?
Re: (Score:3)
Having worked in water infrastructure for several years, I wholeheartedly agree. Old computers, old software, and weak security are rampant. Combine that with underfunded municipalities and you get a recipe for easy disruption - and not in a good way.
Re: (Score:2)
Did you hear about the recent Infrastructure Investment and Jobs Act, a $1 trillion infrastructure bill? That seemed like a pretty significant investment to me.
Liar. (Score:1)
Fear mongering Incorporated.
ohh nooo! how did this happen??? (Score:2)
But if you don't prioritize features and speed to market your company loses ou
US elections are won (Score:4, Insightful)
Once, the US government labelled comic-books a risk "to every American".
Nowadays, internal risks are more likely to collapse the USA than international threats: The need to sacrifice specific demographics has spread past US racism and anti-immigration. The US is choosing ideological fanaticism which breeds authoritarianism. The normal result is civil war and a dictator but both are near-impossible in the USA. Instead, the USA will suffer paranoia and mistrust until the normal regulation of society is impossible: That doesn't mean destruction and apocalypse, it means the cost of operating and protecting government will rise exponentially. We're already seeing the first step with the massive spending, propaganda campaigns and partisanship in US elections.
As long as US elections are won by people willing to label some demographics as second-class citizens, this downward spiral will continue.
Re: (Score:2)
So this week it is China again (Score:2)
Next week it will be Russia or North Korea or Iran again.
Or it could be some bored teenagers with an off-the-shelf ransomware package in a bedroom in California like it actually was the last few times, but that doesn't unlock the big budgets.
Re: (Score:2)
Next week it will be Russia or North Korea or Iran again.
Or it could be some bored teenagers with an off-the-shelf ransomware package in a bedroom in California like it actually was the last few times, but that doesn't unlock the big budgets.
At this point I'm convinced that the FBI is just putting Christopher Wray on PR duties to keep him off of real duties where he could be doing serious harm. Given his past announcements (ironically, about China too) he's not got a good history.
Voting Systems (Score:3)
I appreciate the need to increase confidence in our election systems after the 2020 debacle, but, "confident that voting systems and other election infrastructure are well-defended"? What in the entire history of electronic voting machines would lead someone to say something like that?
I'll take "No shit, Sherlock" for $100 please, Art (Score:3)
Our stuffs insecure, so blame China? (Score:2)
Easy Fix.. Block all Chinese CDNs! (Score:2)
Ask Oregon (Score:2)
She pays out fairly regularly for Intel to fuck her with its dirty corporate cock.
Yawn (Score:1)