{"id":2022,"date":"2016-09-25T13:55:09","date_gmt":"2016-09-25T12:55:09","guid":{"rendered":"https:\/\/www.ofcourseimright.com\/?p=2022"},"modified":"2016-09-26T17:28:45","modified_gmt":"2016-09-26T16:28:45","slug":"whats-a-state-sponsored-actor","status":"publish","type":"post","link":"https:\/\/ofcourseimright.com\/?p=2022","title":{"rendered":"What\u2019s a \u201cState-Sponsored Actor\u201d?"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-2005\" src=\"https:\/\/www.ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo-300x103.jpg\" alt=\"Yahoo!\" width=\"253\" height=\"87\" srcset=\"https:\/\/ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo-300x103.jpg 300w, https:\/\/ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo-768x263.jpg 768w, https:\/\/ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo-1024x351.jpg 1024w, https:\/\/ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo-1200x412.jpg 1200w, https:\/\/ofcourseimright.com\/blog\/wp-content\/uploads\/2016\/09\/Yahoo.jpg 1280w\" sizes=\"auto, (max-width: 253px) 85vw, 253px\" \/>[Updated thanks to an old friend.]<\/p>\n<p>In Yahoo!\u2019s <a href=\"https:\/\/yahoo.tumblr.com\/post\/150781911849\/an-important-message-about-yahoo-user-security\">announcement<\/a> of the theft of 500 million accounts, the Chief Information Security Officer Bob Lord wrote that the company believes a \u201cstate-sponsored actor\u201d was behind the attack.\u00a0 What does that mean and how would Yahoo! come to this conclusion?<\/p>\n<p>The term \u201cstate-sponsored\u201d is vague.\u00a0 It could means someone who works for a government, or it could mean someone who has in effect been contracted out by a government.\u00a0 Both Russia and China have been accused of this sort of behavior in the past.\u00a0 In the case of Russia, there are two well known hacking organizations, Cozy Bear and Fancy Bear that the Washington Post <a href=\"https:\/\/www.washingtonpost.com\/world\/national-security\/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump\/2016\/06\/14\/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html\">previously reported<\/a> were involved in the cyberattack against the Democratic National Committee\u2019s systems.\u00a0 In the case of China, the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Operation_Aurora\">Elderwood Group<\/a> was accused of taking part in a successful phishing attack against His Holiness, the Dalai Lama.<\/p>\n<p>But why does Yahoo! believe that the culprit is one of these groups and not any other hacker?\u00a0 There are several possibilities:<\/p>\n<ul>\n<li>Perhaps the botnet systems used used to gain access to the Yahoo! passwords were the same as those used in an earlier attack in which a state-sponsored actor was known to be involved; or<\/li>\n<li>The code used to break into Yahoo!\u2019s internal network was the same or similar to code used in an earlier attack that is known to be from one of these groups; or<\/li>\n<li>The investigation has been able to determine where the control systems of an attack are and who is accessing them.<\/li>\n<li>As my friend points out, governments aren&#8217;t in this for the money but for some other purpose.\u00a0 That means that stolen information isn&#8217;t likely to hit the black market anytime soon.\u00a0 In this case, by the time Yahoo! discovered the problem, the breach was two years old.<\/li>\n<\/ul>\n<p>Finding proof beyond a reasonable doubt will be difficult.\u00a0 Consider this: it is possible for the Chinese to make use of a botnet run in Russia or America, or for America to operate a botnet in China to attack systems in Russia, just to lend the appearance as to who the source is, without revealing who the actual source is.<\/p>\n<p>The only fundamental solution to this sort of attack is better end system security.\u00a0 Only when botnets have dried up can we establish the true source of attacks.\u00a0 Maybe in my lifetime this will happen.\u00a0 Maybe.\u00a0 But that means a lot of people have to do a lot of work.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Updated thanks to an old friend.] In Yahoo!\u2019s announcement of the theft of 500 million accounts, the Chief Information Security Officer Bob Lord wrote that the company believes a \u201cstate-sponsored actor\u201d was behind the attack.\u00a0 What does that mean and how would Yahoo! come to this conclusion? The term \u201cstate-sponsored\u201d is vague.\u00a0 It could means &hellip; <a href=\"https:\/\/ofcourseimright.com\/?p=2022\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;What\u2019s a \u201cState-Sponsored Actor\u201d?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":172,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[87,9],"tags":[534,32,362,496,535],"class_list":["post-2022","post","type-post","status-publish","format-standard","hentry","category-internet","category-security","tag-cyberattack","tag-cybercrime","tag-cybersecurity","tag-security","tag-state-sponsored"],"_links":{"self":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts\/2022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/users\/172"}],"replies":[{"embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2022"}],"version-history":[{"count":4,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts\/2022\/revisions"}],"predecessor-version":[{"id":2042,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts\/2022\/revisions\/2042"}],"wp:attachment":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}