There are a lot of ballistic missiles being shown off this week, starting with the Chinese displaying 16 of the mobile DF 31AG which is mounted on an all-terrain vehicle that will allow it to go almost anywhere. It has a range of 6200 miles and has multiple warheads. Apparently, they were doing some testing over the weekend and letting everyone know what the targets were going to be - missile silos and F-22 fighters. Good luck with that. There is a nice picture of a test the Chinese did in July in The Aviationist. A commercial airline pilot just happened to be in the right place at the right time and took a good shot.
North Korea would have been missing something if it had not launched another missile over towards Japan but on a very high arc not seen very often. It reportedly came down a few miles short of a commercial airliner passing by. Another thing for the flying public to worry about.
The US fired off a THAAD interceptor and also launched a Minuteman III, which it does regularly to prove those missiles in the ground still work, but it went 4200 miles landing near Kwajalein where we used to do all of our defensive missile testing. They don't really have to fly that far to prove the point that they are working, but why not? Since we are having so much fun, it seems appropriate.
People outside the defense community are probably yawning through all of this, but this is not just a fun time for everyone to enjoy. Everybody is trying to prove something and most of the things they are doing have something to do with lethality and survivability - something North Korea has seemed to miss. Being able to heft a warhead 6000 miles is a neat trick and not as easy as it sounds. Doing it from a missile silo or a mobile launcher is a lot trickier and much harder. Yes, the North might be able to launch a warhead that far, but it is sitting on a very exposed platform just minutes before it is launched. If they think we would let them load it up and just sit there watching, they might think about that a little.
Wednesday, August 2, 2017
Tuesday, August 1, 2017
Code-Signing Certificates Revisited
I went back to look at what Symantec had published on code signing cert. A couple of things: (1) not many other security groups seem to be interested in how hacker groups and state actors use code signing as a way to mask the illegal use of their software and (2) the attack groups seem to use code signing to hide the introduction of legitimate code and their own malware. So, they steal code signing certs to verify that legitimate code is verifiable by the host. That makes sense, if you think about it. Since so many systems require signed software, they have to get a valid signature from somewhere.
But what China is doing is slightly different than that, at one level. The Chinese do not just hack and collect information. They are building their own domains with their own software (no doubt stolen in those "security reviews" they are doing) and inviting users in. Everything in a domain is not stolen, but some of it is. Some of it has been modified to do collection and penetration for intelligence purposes. Some of it is censored by the same software used in China on its own citizens. Once a user is inside one of those domains, they become infected with all kinds of tools that can trace what networks they use, where they go on them, and what they are reading or writing about. While they criticize the US for doing the same kinds of things, they quietly go about their business. There needs to be more reserach into how big some of these networks have become and how we recognize them for what they are. Toronto University has a good start on it by examining what Chinese browsers are collecting, but that doesn't go far enough to take in the whole of it.
China wants to control the Internet, from China out. In their minds, they are controlling what is good for Chinese citizens and they can justify anything that is done for that reason. If intelligence collection is done for the same reason, so be it. That will be good for them too. They can manage content of other people's networks by filtering the sources of data from the inside out. They can control what you see about China, and what China sees from you.
China doesn't claim to be a democracy. Its citizens have no privacy and have no free speech. That worked well enough that they think the rest of the world could benefit from their experience, and find the joy of a China-controlled Internet. That is arrogance of the highest order.
But what China is doing is slightly different than that, at one level. The Chinese do not just hack and collect information. They are building their own domains with their own software (no doubt stolen in those "security reviews" they are doing) and inviting users in. Everything in a domain is not stolen, but some of it is. Some of it has been modified to do collection and penetration for intelligence purposes. Some of it is censored by the same software used in China on its own citizens. Once a user is inside one of those domains, they become infected with all kinds of tools that can trace what networks they use, where they go on them, and what they are reading or writing about. While they criticize the US for doing the same kinds of things, they quietly go about their business. There needs to be more reserach into how big some of these networks have become and how we recognize them for what they are. Toronto University has a good start on it by examining what Chinese browsers are collecting, but that doesn't go far enough to take in the whole of it.
China wants to control the Internet, from China out. In their minds, they are controlling what is good for Chinese citizens and they can justify anything that is done for that reason. If intelligence collection is done for the same reason, so be it. That will be good for them too. They can manage content of other people's networks by filtering the sources of data from the inside out. They can control what you see about China, and what China sees from you.
China doesn't claim to be a democracy. Its citizens have no privacy and have no free speech. That worked well enough that they think the rest of the world could benefit from their experience, and find the joy of a China-controlled Internet. That is arrogance of the highest order.
THAAD Passes the Test
When the U.S. Successfully tested another THAAD anti-missile system against a ballistic target, it was telling China something it needs to hear. You can ignore North Korea and play the blame game all you want, but if the North continues to threaten the United States, like it has for the past 15 years, the defensive missiles can make that threat seem less credible. That was a good step to take.
As we saw yesterday in the U.N. China has decided the US was remiss in not bringing up a complaint about the latest missile firing by the North. In fact, even worse, the US has gone off on its own to impose sanctions which are not backed by the UN. China says it is offended by this lack of adherence to protocols of the UN, which it only follows when the subject of "One China" comes up, or it wants to tamp down the heat from North Korea doing something again. They have played this game so long, even they think it is the only game in town.
The US has ignored the UN using the repeated reasoning that the UN hasn't done anything lately, and China routinely violates the sanctions it imposes. So, everyone gets warm and fuzzy by passing a UN resolution, then they ignore the provisions and do what they want. This is a game the US got tired of playing, as we all heard Nikki Haley say last week.
But, THAAD is a different thing than a UN sanction. It is s real-world interceptor that looks like it works pretty well. It would be nice to test it on one of those missiles fired off by the North. Japan could do that, since they have THAAD, and probably more countries as time goes on. China tries to discourage the world buying THAAD, using the paper-thin argument that it might peer into China to look at its military. In case they forgot to look, that radar is a ground based radar pointing up at the sky where it is needed. Even China doesn't believe what it says about THAAD's radar. But it does know it works, and is a great equalizer to the insane asylums in North Korea's leadership.
China claims this is a problem for the US and the North to work out. They have been getting away with that for a long time, when it is really a problem China created to get reactions from the US and others on how they are going to deal with nuclear threats. If the North does fire off a nuclear loaded rocket, China knows what will happen. They are going to have a bunch of North Koreans getting in line to jump the border to seek asylum, or get away from the destruction. You saw Xi running around in fatigues last week pretending to be the guy running the military and getting ready to repel an attack - from somewhere. We are pretty tired of that game too.
Let's try to remember the Korean War. Do we think the UN is not going to fight on the side of the South? Is China going to push down all the way to the southern tip of the the South, then retreat back to the North and sue for peace? I don't think so. China, though its control of the South China Sea, is going to make it very hard for anyone to set foot on South Korean soil. They will own the South in no time and they won't be retreating. The North won't be a problem after that.
As we saw yesterday in the U.N. China has decided the US was remiss in not bringing up a complaint about the latest missile firing by the North. In fact, even worse, the US has gone off on its own to impose sanctions which are not backed by the UN. China says it is offended by this lack of adherence to protocols of the UN, which it only follows when the subject of "One China" comes up, or it wants to tamp down the heat from North Korea doing something again. They have played this game so long, even they think it is the only game in town.
The US has ignored the UN using the repeated reasoning that the UN hasn't done anything lately, and China routinely violates the sanctions it imposes. So, everyone gets warm and fuzzy by passing a UN resolution, then they ignore the provisions and do what they want. This is a game the US got tired of playing, as we all heard Nikki Haley say last week.
But, THAAD is a different thing than a UN sanction. It is s real-world interceptor that looks like it works pretty well. It would be nice to test it on one of those missiles fired off by the North. Japan could do that, since they have THAAD, and probably more countries as time goes on. China tries to discourage the world buying THAAD, using the paper-thin argument that it might peer into China to look at its military. In case they forgot to look, that radar is a ground based radar pointing up at the sky where it is needed. Even China doesn't believe what it says about THAAD's radar. But it does know it works, and is a great equalizer to the insane asylums in North Korea's leadership.
China claims this is a problem for the US and the North to work out. They have been getting away with that for a long time, when it is really a problem China created to get reactions from the US and others on how they are going to deal with nuclear threats. If the North does fire off a nuclear loaded rocket, China knows what will happen. They are going to have a bunch of North Koreans getting in line to jump the border to seek asylum, or get away from the destruction. You saw Xi running around in fatigues last week pretending to be the guy running the military and getting ready to repel an attack - from somewhere. We are pretty tired of that game too.
Let's try to remember the Korean War. Do we think the UN is not going to fight on the side of the South? Is China going to push down all the way to the southern tip of the the South, then retreat back to the North and sue for peace? I don't think so. China, though its control of the South China Sea, is going to make it very hard for anyone to set foot on South Korean soil. They will own the South in no time and they won't be retreating. The North won't be a problem after that.
Subscribe to:
Posts (Atom)