
閱讀時間約 18 分鐘




Chinese hackers suspected in attack on The Post’s computers◎Washington Post(2013.02.02)


By Craig Timberg and Ellen Nakashima, Saturday, February 2, 10:25 AM

A sophisticated cyberattack targeted The Washington Post in an operation that resembled intrusions against other major American news organizations and that company officials suspect was the work of Chinese hackers, people familiar with the incident said.

Post company officials confirmed the broad outlines of the infiltration, which was discovered in 2011 and first reported by an independent cybersecurity blog on Friday.  But they did not elaborate on the circumstances, the duration of the intrusion or its apparent origin.

“Like other companies in the news recently, we face cybersecurity threats,” Post spokeswoman Kris Coratti said.  “In this case, we worked with [security company] Mandiant to detect, investigate, and remediate the situation promptly at the end of 2011.  We have a number of security measures in place to guard against cyberattacks on an ongoing basis.”

The New York Times and the Wall Street Journal reported this week on major hacking campaigns they said likely originated in China.

The Times and The Post used the same Alexandria-based security company, Mandiant, to secure their systems.  Grady Summers, a vice president at Mandiant, declined to comment on the intrusion at The Post but said that in general, Chinese government hackers “want to know who the sources are, who in China is talking to the media. . . . They want to understand how the media is portraying them — what they’re planning and what’s coming.”

The Chinese Embassy in Washington and officials in Beijing did not respond to calls for comment.  When questioned by The Post on Thursday about cyberattacks on media organizations, China’s Defense Ministry said, “The Chinese military has never supported any hack attacks.  Cyberattacks have transnational and anonymous characteristics.  It is unprofessional and groundless to accuse the Chinese military of launching cyberattacks without any conclusive evidence.

The cyberattack targeted The Post’s main information technology server and several other computers, said people familiar with the incident who spoke on the condition of anonymity to describe details the company did not release publicly.

These people said that sensitive administrative passwords likely were compromised, giving hackers potentially wide-ranging access to The Post’s systems before the computers were taken offline and enhanced monitoring was put in place to prevent a recurrence.  It was not clear what information, if any, was stolen by the hackers.

The intruders gained access as early as 2008 or 2009, according to these accounts.  In 2011, Mandiant neutralized the malicious software, which had been sending a signal to an Internet command-and-control server associated with a Chinese hacking group.

This description tracks in general terms with one posted Friday on the blog “Krebs on Security,” authored by former Washington Post reporter Brian Krebs. He quoted an unidentified former information technology employee at the company.

Krebs’s report included the assertion that The Post turned over one of its servers to the National Security Agency and the Defense Department for analysis.  That would be an unusual step for a news organization that traditionally has carefully guarded the security of its e-mail and other information from government intrusion.

“We are confident that did not happen,” Coratti said.  Other Post officials speaking on condition of anonymity said the company would investigate the claim.

The National Security Agency and the Defense Department declined to comment.

Though U.S. news organizations and other companies frequently are the target of cyber-espionage, the extent of the Post intrusion appears to have been unusual and was kept secret from most company employees.

After the report by Krebs on Friday, some Post journalists grumbled about not being alerted to the intrusion and expressed concern that outside hackers may have had access to their e-mails or documents kept on their computers. Reporting that dealt with dissidents or political issues in China would have been especially sensitive.

“Nobody told me a word.  Wish they had,” said longtime Post foreign correspondent Keith B. Richburg, who was acting bureau chief in Beijing at the time of the cyberattack and is leaving the company for a job at Harvard University.

He said that correspondents based in China assumed they were being monitored by the government there and took measures to protect sources and evade spying — especially while working in offices owned by the government or while reporting by e-mail. “We always joked that if the toilet didn’t flush, we could stand in the middle of the room and say, ‘Can’t they fix the toilet?’ ”

Security experts regard the Chinese government as the most aggressive hackers of Western companies and government agencies.

“What we’re seeing now is the end of a decade-long drive toward complete visibility into all computer networks of interest,” said Steven Chabinsky, a former senior FBI cyber-official who now works for the security company CrowdStrike.

China’s cyber-espionage assists the government’s broader efforts to quell internal dissent by identifying activists and dissidents and tracking them through their e-mail.  China has been accused of hacking the servers of Google to obtain dissidents’ e-mail and of targeting nonprofit groups and think tanks that study China.

Some analysts say that more transparency is needed to address the issue.  Google in January 2010 became the first company to disclose voluntarily it had been hacked through an intrusion originating in China.  It also disclosed that its investigations had turned up dozens of other companies that had similarly been penetrated by China in hopes that some of them would also disclose the hacking.  None did, though Intel later disclosed in a regulatory filing it had been targeted.

“If every company reported when it was hacked and who it was hacked by, it would be harder [for China] to get away with it,” said one industry official, speaking on condition of anonymity because he was not authorized by his company to speak on the record.

Chabinsky agreed. “It’s easy to dismiss one or two companies,” he said. “It’s harder if 100 companies come together and say, we’ve analyzed where it’s coming from and it’s you, and it has to stop.”

James A. Lewis, a cybersecurity expert at the Center for Strategic and International Studies, said that the U.S. government must be more forthcoming, too.  “If the U.S. were to publish the intelligence it has, it would show a massive coordinated espionage effort by China that dwarfs what we see from other countries.  This would make it very difficult to continue to pretend that things are going along in a normal fashion.”

William Wan contributed to this report from Beijing.

Sign up today to receive #thecircuit, a daily roundup of the latest tech policy news from Washington and how it is shaping business, entertainment and science.



    Google News 追蹤
    這個秋,Chill 嗨嗨!穿搭美美去賞楓,裝備款款去露營⋯⋯你的秋天怎麼過?秋日 To Do List 等你分享! 秋季全站徵文,我們準備了五個創作主題,參賽還有機會獲得「火烤兩用鍋」,一起來看看如何參加吧~
    Faker昨天真的太扯了,中國主播王多多點評的話更是精妙,分享給各位 王多多的點評 「Faker是我們的處境,他是LPL永遠繞不開的一個人和話題,所以我們特別渴望在決賽跟他相遇,去直面我們的處境。 我們曾經稱他為最高的山,最長的河,以為山海就是盡頭,可是Faker用他28歲的年齡...
    有別於試圖直接從數據中找出洞察,商業分析的精髓在於先思考 so what——從定義目標開始,做出商業決策的雛形後,才用數據去支持假說。這篇文章介紹 A/B 測試的技巧,以及摘櫻桃的應用,解說數據篩選的操作、摘櫻桃的好處,以及企業案例:數位轉型後的報社,亞馬遜CEO貝佐斯改造百年郵報。
    位於四川新都的中國著名古剎寶光寺於 九月二十九日為雲高大法王上師的弟子王篤川居士舉行毗荼大典,火化後拾得225顆堅固子。 王篤川居士夫婦都是大學教授,他們在退休以後,得以拜雲高大師為師學習佛法,虔誠精進。在雲高大師離開成都以後,王教授夫婦主動要求留守壇場。
    聖海倫火山是一座活火山,在歷史上噴發多次且造成嚴重損失與死傷,屬於Cascade Range的一份子,也是環太平洋地震帶的其中一塊。聖海倫火山發生在1980年5月18日的噴發十分知名,是美國歷史上死傷人數最多、經濟損失最大的火山爆發,因此美國後續對於火山的相關研究,常常會以聖海倫火山來做為比較基準。
    華盛頓特區國家美術館(National Gallery of Art in Washington, DC)在最新10月8日開幕的維梅爾特展「Vermeer’s Secrets」中,公佈了該館最新發現!
    在杰基·罗宾逊 (Jackie Robinson) 作为职业比赛的主要黑暗球员首次亮相美国职业棒球大联盟 (MLB) 75 年后,道奇队促成了 2022 年的选秀大会。 罗宾逊在道奇队度过了他的整个 MLB 职业生涯,当时他们位于布鲁克林而不是洛杉矶。 https://lu.ma/3v4fkikn
    今日公推美國職棒MLB,重注推薦私訊詢問 LINE ID:crazy17168 點擊連結➔https://line.me/ti/p/uPsX3SuXjk 9/26公推巨人VS落磯山正如分析文所說巨人先發Anthony DeSclafani表現不錯落磯山直到第五局才拿下第一分,最後巨人以6比2獲勝
    Photo by Clem Onojeghuo on Unsplash 今年一月,一部名為「The Post」的電影在美國上映了。 電影內容圍繞在華盛頓郵報參與當時轟動全球的「Pentagon Papers」,也就是所謂的五角大廈機密文件解密,包括當時美國參與越戰時許多見不得光的美越關係報告(這
    這個秋,Chill 嗨嗨!穿搭美美去賞楓,裝備款款去露營⋯⋯你的秋天怎麼過?秋日 To Do List 等你分享! 秋季全站徵文,我們準備了五個創作主題,參賽還有機會獲得「火烤兩用鍋」,一起來看看如何參加吧~
    Faker昨天真的太扯了,中國主播王多多點評的話更是精妙,分享給各位 王多多的點評 「Faker是我們的處境,他是LPL永遠繞不開的一個人和話題,所以我們特別渴望在決賽跟他相遇,去直面我們的處境。 我們曾經稱他為最高的山,最長的河,以為山海就是盡頭,可是Faker用他28歲的年齡...
    有別於試圖直接從數據中找出洞察,商業分析的精髓在於先思考 so what——從定義目標開始,做出商業決策的雛形後,才用數據去支持假說。這篇文章介紹 A/B 測試的技巧,以及摘櫻桃的應用,解說數據篩選的操作、摘櫻桃的好處,以及企業案例:數位轉型後的報社,亞馬遜CEO貝佐斯改造百年郵報。
    位於四川新都的中國著名古剎寶光寺於 九月二十九日為雲高大法王上師的弟子王篤川居士舉行毗荼大典,火化後拾得225顆堅固子。 王篤川居士夫婦都是大學教授,他們在退休以後,得以拜雲高大師為師學習佛法,虔誠精進。在雲高大師離開成都以後,王教授夫婦主動要求留守壇場。
    聖海倫火山是一座活火山,在歷史上噴發多次且造成嚴重損失與死傷,屬於Cascade Range的一份子,也是環太平洋地震帶的其中一塊。聖海倫火山發生在1980年5月18日的噴發十分知名,是美國歷史上死傷人數最多、經濟損失最大的火山爆發,因此美國後續對於火山的相關研究,常常會以聖海倫火山來做為比較基準。
    華盛頓特區國家美術館(National Gallery of Art in Washington, DC)在最新10月8日開幕的維梅爾特展「Vermeer’s Secrets」中,公佈了該館最新發現!
    在杰基·罗宾逊 (Jackie Robinson) 作为职业比赛的主要黑暗球员首次亮相美国职业棒球大联盟 (MLB) 75 年后,道奇队促成了 2022 年的选秀大会。 罗宾逊在道奇队度过了他的整个 MLB 职业生涯,当时他们位于布鲁克林而不是洛杉矶。 https://lu.ma/3v4fkikn
    今日公推美國職棒MLB,重注推薦私訊詢問 LINE ID:crazy17168 點擊連結➔https://line.me/ti/p/uPsX3SuXjk 9/26公推巨人VS落磯山正如分析文所說巨人先發Anthony DeSclafani表現不錯落磯山直到第五局才拿下第一分,最後巨人以6比2獲勝
    Photo by Clem Onojeghuo on Unsplash 今年一月,一部名為「The Post」的電影在美國上映了。 電影內容圍繞在華盛頓郵報參與當時轟動全球的「Pentagon Papers」,也就是所謂的五角大廈機密文件解密,包括當時美國參與越戰時許多見不得光的美越關係報告(這