Skip to content

Comment on How Saudi Arabia Infiltrated Twitter

Comments

I'd also remind that Twitter is surprisingly leaky for Chinese using it, even for people who can get foreign simcards to register an account.

API leak is one hypothesis, another one is that they got a mole there too.

The same goes to Facebook. A number of FB users got detained in China with no better explanation than MSS getting access to FB's internal information like phone ID and IMSI data in user database.

The most probable explanation people have crafted is following:

1. Using internal or external tips, MSS gets user account info of a person of interest

2. Their mole accesses the user database for info on cookies, IMSI, advertising ID and such

3. MSS than cross-references the data with data on the open market, like IMSI databases sold by mobile advertising companies

4. One way ticket to Heilongjiang is issued the next day, once the identity of the person is confirmed using logs of phone companies or ISPs.

Why would a serious government not walk through the open door and take what they needed while their agents collect two salaries? It's just a win-win for foreign intelligence. They would be negligent in their duties to NOT infiltrate US companies with open doors and permissive, trusting internal policies about user data.

Then the company can do the liability minimization dance when the FBI comes and points out that they are running a cheap data service for foreign spies. "We, uh, had no idea..."

Absolutely. It's their job to do this.

But what should large tech companies do? Avoid hiring people from certain countries/heritages? Obviously that's not fair and not a good look. Same for putting extra monitoring on them. This is independent of Twitter apparently trying to downplay this and cover it up, which of course is wrong. It just seems like preventing this is really tough unless you state "we won't hire anyone who's lived in, was born in, or whose parents are from China, Iran, Saudi Arabia, or Russia", which is untenable.

Instead of targeted monitoring monitor everyone who has certain level of access regardless of origin? It's not like it's not scalable, obviously they are capable of widescale automation.

It's really not that easy to monitor for every possible violation/exfiltration, especially at that scale. Of course those need to be monitored for, but they're never perfect. NSA obviously had mechanisms to detect this, but it didn't work for Snowden.

They likely have already had such monitoring in place for years, and are probably augmenting it now. It just didn't work.

LOL @ “a mole.” China has at least a dozen moles inside Twitter. At least a hundred inside Google.

Given that the Chinese government uses coercion (esp. threats to family back home) on foreign workers in the US, every Chinese national working at any company in the US can be a potential mole. Think about that.

"If these contractors can't breach a target, intelligence officers assigned to specific cases come into action. They operate on the ground, near targets, by recruiting company insiders, or even coercing Chinese employees to aide their hacking efforts using blackmail or threats against families living at home." [1]

[1] https://www.zdnet.com/article/fbi-is-investigating-more-than...

Given that the Chinese government uses coercion (esp. threats to family back home) on foreign workers in the US, every Chinese national working at any company in the US can be a potential mole.

They also use money[1] on domestic workers in the US, everyone at any company in the US can be a potential mole. Think about that.

1. https://www.npr.org/2020/02/14/806128410/harvard-professors-...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.