Five Eyes intel chiefs warn China's IP theft program now at 'unprecedented' levels
- Reference: 1697623206
- News link: https://www.theregister.co.uk/2023/10/18/five_eyes_china_espionage/
- Source link:
The five from the US, UK, Canada, Australia, and New Zealand all appeared together on stage for the first time ever at a [1]summit hosted by Stanford University's Hoover Institution, a public policy think tank. The discussion, hosted by former US Secretary of State Condoleezza Rice, centered on emerging technology and securing innovation.
Will Chinese giants defy US sanctions on Russia? We asked a ZTE whistleblower [2]READ MORE
"There is no greater threat to innovation than the Chinese government," said FBI Director Christopher Wray.
This threat goes well beyond the traditional nation-state spies stealing government secrets from other counties, added Australian Security Intelligence Organisation Director-General Mike Burgess.
"The threat is that we have the Chinese government engaged in the most sustained, scaled, and sophisticated theft of intellectual property and acquisition of expertise that is unprecedented in human history," Burgess said.
[3]
This is challenging in its "scale and breadth," said Wray, citing the PRC's hacking program, which he has [4]repeatedly said is bigger than that of every other nation's combined.
[5]
[6]
"Combine that with human intelligence operations," Wray said, noting that this includes not just "traditional spies" stealing trade secrets from private-sector businesses and research institutions.
Chinese President Xi Jinping's cyber squads also recruit non-traditional spies such as business insiders and use "seemingly innocuous joint ventures investments," Wray added. "So part of what makes it challenging is all of those tools deployed in tandem at a scale that the likes of which the world has never seen."
Zeroing in on emerging tech
Increasingly, Chinese government IP thieves are focusing on emerging technologies – AI, quantum computing, biotechnology, robotics, and automation. The especially worrisome part of those efforts, according to the Five Eyes, is that China and other adversarial nations like Russia and Iran don't consult laws or safeguards when deploying such technologies.
Using AI as an example, Wray said: "Right now, where it's most dangerous is essentially taking junior varsity bad actors and bringing them to the varsity level. But in fairly short order, we're going to be seeing AI taking the varsity level athletes to a whole other level of dangerousness."
[7]China caught – again – with its malware in another nation's power grid
[8]Five Eyes nations detail dirty dozen most exploited vulnerabilities
[9]US Navy sailor admits selling secret military blueprints to China for $15K
[10]US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster
AI can be used to scan for vulnerabilities to exploit, and to write code to exploit those vulnerabilities, according to Wray.
The Register observes that AI's ability to write malware is disputed by private security researchers. The consensus seems to be that AI can help experienced coders save time and has the potential to write exploit code by itself. But at this point, AI still [11]requires human intelligence to create malware.
[12]
Wray said that miscreants are also using AI to pull off more sophisticated [13]spear-phishing attacks . AI is also good at producing content for disinformation campaigns, including [14]deepfake audio and images , and China is already taking full advantage of this capability, he added.
"AI [can] enhance things like [15]virtual kidnappings , where parents get a call and they think their child's been kidnapped," Wray said. "But now AI can mimic your child's voice, so it sounds even more credible."
AI's nastier applications means that government spies, and not just those from China, are interested in stealing data from and recruiting insiders at startups, universities, and other organizations developing these emerging technologies.
[16]
"If you are working at the cutting edge of technology today, you might not be interested in geopolitics, but geopolitics is certainly interested in you," said MI5 Director General Ken McCallum. "Lots of people who, perfectly understandably, may not previously have thought that national security had anything to do with them do need to think about this in a new way."
To this end, Tuesday's summit also included discussions between the Five Eyes intelligence leaders and business execs about expanding private-public partnerships to better protect innovation and national security.
These "Five Principles," as the intel chiefs called them, will "better inform innovators around the types of threats we face and what they can do about it," said Andrew Hampton, Director-General of the New Zealand Security Intelligence Service. ®
Get our [17]Tech Resources
[1] https://livestream.com/accounts/1973198/events/10982851
[2] https://www.theregister.com/2022/03/28/ashley_yablon_zte_whistleblower_interview/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTABLwKMdSD8Vr8M8XM5iAAAAow&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2023/05/01/fbi_director_wray_china_testimony/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTABLwKMdSD8Vr8M8XM5iAAAAow&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTABLwKMdSD8Vr8M8XM5iAAAAow&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/09/12/china_malware_grid/
[8] https://www.theregister.com/2023/08/07/in_brief_security/
[9] https://www.theregister.com/2023/10/11/us_navy_china_spy/
[10] https://www.theregister.com/2023/04/12/us_chatgpt_threat/
[11] https://www.theregister.com/2023/08/18/ai_malware_truth/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTABLwKMdSD8Vr8M8XM5iAAAAow&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://www.theregister.com/2023/01/11/gpt3_phishing_emails/
[14] https://www.theregister.com/2023/01/27/google_tag_dragonbridge_takedown/
[15] https://amp-cnn-com.cdn.ampproject.org/c/s/amp.cnn.com/cnn/2023/04/29/us/ai-scam-calls-kidnapping-cec/index.html
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTABLwKMdSD8Vr8M8XM5iAAAAow&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://whitepapers.theregister.com/
Hey if Ronnie Biggs tells you that your train is vulnerable to theft.....
You think that ?
Great matter. Intel on six years new category product line they are in quasi equal graph tech stuff than AMD -ATI in 30 years tech life !!
Re: You think that ?
How's your Gran for soap?
Decouple
I believe we should decouple from the internet or make a separate internet which can't be accessed from non-Western states. The internet initially started out that way in the early '70's. With internet and digital storage it has become too easy to steal secrets and intellectual property.
Re: Decouple
I understand the point you're trying to make, but it wouldn't really work. Take Apple for example, which still relies heavily on China for most of the manufacturing of its products -- even if they are slowly shifting more and more of it to Vietnam. It wouldn't really be very practical for them to have workers in the US using Internet A, while workers in China were using Internet B. At some point, someone would need to be using both and then that gives Chinese hackers a potential way in to Internet A.
To make it work, you'd have to start bringing manufacturing back to other nations which would drive up costs significantly because we have regulations that make sure the air we breathe is generally safe, same with the water, and that we pay people at least a certain amount. The sad reality is, people will tend to always buy what is cheapest. Say you have a new release movie on BD. You go to a local retail store and there are two versions sitting side by side. One was made in the US or England, the other China. Let's say the difference in price is 1 dollar/pound. I will pretty much guarantee the cheaper Chinese one will sell at a significantly higher rate. Even if you said that the US/English made one had a lifetime warranty and they'd replace it for free even if you accidentally ran it over with your car or damaged it in some other equally ridiculous way.
Re: Decouple
I'll be the first to admit that I don't have all the answers, but short of going back to paper and pencil this is the only way of preventing China from nabbing all of our tech. If someone has a better idea I'd like to hear it.
Fact is, security is way down the list of priorities of most companies, including high-tech companies with valuable IP.
Re: Decouple
Fair enough, my friend. I'm not trying to dump all over your idea or anything. Frankly, anyone on these here interwebs who can admit that they don't know everything automatically earns a certain level of respect from me. I am all for "reshoring" a lot of jobs, be they in the US, Blighty, or anywhere else. While your idea, as-is, probably is unworkable, there might be a nugget of something useful that someone could take and run with.
Makes me think of a job I had a few years ago at a large multi-national company. China was basically the only market left with any significant growth potential, but because of fears regarding IP theft and the like, the company would only sell products a couple generations old in China. They even had people get specially configured laptops if they were going to travel to China. Didn't stop the employees in China from routinely sending emails wanting to know why this or that value in SAP was set the way it was for a specific material, and I'm guessing they were caught accessing design documents because the company made a big to-do about upgrading their SAP instance to a version that included a new feature which allowed them to restrict access based on region.
And in a bit of an ironic twist, I grew up in farm country in the US, and so still sometimes see news reports about someone working at a college in, or near, my home state being deported because they were trying to steal secrets of some new agriculture technology. Sort of like how Thomas Jefferson stole seeds from Italy when he was the Ambassador. Seeds that were considered a state secret at the time. That theft essentially bootstrapped the American economy in the early days.
So they restricted SAP usage to China, driving them to madness and bankruptcy?
No idea. I wasn't really involved in those particulars, I just was peripherally aware of them. I wasn't the person who had to deal with the incessant questions from the China employees either, but it sounded like it was multiple emails a day, all asking oddly specific questions that really had absolutely nothing to do with their job. So, pretty sure they were politely, but firmly, told to STFU and stay in their lane. When China sends their industrial spies, they aren't sending their best. They are incompetent. They blow their own covers. Some, I assume, are at least semi-competent.
The one funny story about it was that one time the person who handled those requests went on vacation, so someone else was covering for them. The spies would ask their questions and then wanted to know where "Ngoc" was. I guess that name is more typically masculine, but in this case it was a woman. So, the person covering responds back to one of the spies misgendering the person with something like, "No, Ngoc is a woman. A very beautiful woman." After which, the spies were all like, "That's OK, we'll wait for her to get back!"
Meanwhile we're still happy to bank roll Poo Bear by buying (literally) boat loads of his cheap tat. It all adds up to a huge transfer of wealth. Ill-gotten in the first instance perhaps but handing it over to an idealistically hostile regime won't undo that. And the cheap tat is becoming less cheap with the likes of BYD and MG flooding our markets so the rate of transfer ramps up.
Translate into Chinese please, lest in English it be thought Worthless and Nonsensical Double Dutch.
"If you are working at the cutting edge of technology today, you might not be interested in geopolitics, but geopolitics is certainly interested in you," said MI5 Director General Ken McCallum. "Lots of people who, perfectly understandably, may not previously have thought that national security had anything to do with them do need to think about this in a new way."
Methinks it is Five Eyes wonks who need to think about national, international and internetional security in a completely different way and which does not have them prime time leading with cutting edge technologies, but rather more following and supporting others elsewhere fully aware of the geopolitical implications of second and third party interest in their development and deployment of emerging and inscrutable and almighty powerful programs in Premium JOINT AIDVentures* Such is where all the next waves of great fortunes and future live action for NEUKlearer HyperRadioProACTive IT Systems Administrations is at.
They [Five Eyes nationals] might like to realise, for it very likely is the present true actual case, they are themselves not fit to lead, with not a great enough understanding of that which is required for their intelligence services to provide new cutting-edge technologies in order that they can both prosper and grow ever stronger together, with such an intellectual property deficit having them vainly struggling forever and never able to take full advantage of all that can be made virtually available at no great extra cost by others foreign and alien to them .... and with JOINT AIDVentures* ...... JOINT Operations Internetworking Novel Technologies in Advanced IntelAIgently Designed Ventures ...... being one such present true actual case proving the point valid.
And of course, Five Eyes would never themselves do any of that spying and snooping and phishing and stealing or purchasing of sensitive secrets from others, would they? :-) If you believe that, you gotta get out more lest you forever are condemned to remain an ignorant blunt tool of a fool.
"Five Eyes," "Hoover Institution," "Condoleezza Rice..."
Say no more!