
latimes.com
Just as U.S. companies are coming to grips with the threats to their computer networks emanating from cyber spies based in China, a noted expert is highlighting what he says is an even more pernicious vulnerability in smartphones.

dailyherald.comPacking for business in China? Bring your passport and business cards, but maybe not that laptop loaded with contacts and corporate memos.
China’s massive market beckons to American businesses — the nation is the United States’ second-largest trading partner — but many are increasingly concerned about working amid electronic surveillance that is sophisticated and pervasive.
Security experts also warn about Russia, Israel and even France, which in the 1990s reportedly bugged first-class airplane cabins to capture business travelers’ conversations. Many other countries, including the United States, spy on one another for national security purposes.
But China’s brazen use of cyber-espionage stands out because the focus is often corporate, part of a broader government strategy to help develop the country’s economy, according to experts who advise American businesses and government agencies.
“I’ve been told that if you use an iPhone or BlackBerry, everything on it — contacts, calendar, emails — can be downloaded in a second. All it takes is someone sitting near you on a subway waiting for you to turn it on, and they’ve got it,” said Kenneth Lieberthal, a former senior White House official for Asia who is at the Brookings Institution.
cbc.caWhen many people think of espionage, the image that readily comes to mind is of the furtive spy, clad in black, taking photographs of secret dossiers with a camera disguised as a cigarette lighter. It's an image that seems quaint and dated, especially since the end of the Cold War. But the recent controversy surrounding Conservative MP Bob Dechert's flirtatious email exchanges with a Chinese journalist remind Canadians that the threat of international espionage did not vanish with the fall of the Iron Curtain.
If anything, the threat to Canadian secrets has strengthened in recent years and is something the federal government is fighting on a daily basis.
Christian Leuprecht, an associate professor of political science at the Royal Military College of Canada in Kingston, says the Dechert case represents a textbook example of international espionage.
"It is an active, long-standing intelligence tradition to use journalists, because it's easy to place them on temporary assignment somewhere for a period of time," he said. Journalists ask questions, meet people, learn things. "There seems to be something more to the story than meets the eye." But although they are still used, the need for such field operatives is declining in the online age.
More...
theepochtimes.com
washingtontimes.comA U.S. supercomputer laboratory engaged in classified military research concluded a recent dealinvolving Chinese-made components that is raising concerns in Congress about potential electronic espionage.
The concerns are based on a contract reached this summer between a computer-technology firm and the National Center for Computational Engineering at the University of Tennessee, whose supercomputers simulate flight tests for next-generation U.S. military aircraft and spacecraft, and simulate submarine warfare for the Navy.
The storage system for the contract calls for using software from U.S. cybersecurity firm Symantec installed over devices made by Huawei Technologies, a Chinese telecommunications giant that U.S. officials have said has close ties to China’s military. Huawei and Symantec formed a joint venture in 2008, with Huawei owning 51 percent of the shares of the enterprise.
More...
cnn.com London (CNN) -- U.S. government agencies, the United Nations, defense contractors and Olympic bodies have all been targeted by a single intruder in an "unprecedented" campaign of cyberspying, says a new report by a computer-security firm. The operation, which targeted agencies and groups in 14 countries, bears the hallmarks of state-sponsored espionage, according to the report by security company McAfee. Other cybersecurity experts downplayed the report's findings, however.
McAfee said the attacks, which it calls Operation Shady RAT, have allowed hackers potentially to gain access to military and industrial secrets from 72 targets, most of them in the United States, over a five-year period.
McAfee did not name all the targets but said the sheer scope of victims, including 14 U.S. government bodies; the governments of Canada, India, South Korea and Taiwan; defense contractors; the International Olympic Committee; and even a cybersecurity company, indicates no one is safe.
Dmitri Alperovitch, McAfee's vice president of threat research, said attacks on political nonprofit groups indicated a "state actor" could be behind the operation. He declined to name a specific country, but media reports have pointed a finger at China.
When contacted by CNN, an official at the Chinese embassy said that the allegations were unwarranted, irresponsible and an attempt to vilify China. The official added that China, too, has been a victim of hacking and that the country wants to work with other countries to end the problem.
More...
Beijing is allegedly using audio spying devices on dual-plate Chinese-Hong Kong vehicles to gather information.
Apple Daily reports the eavesdropping devices were originally installed under the name "inspection and quarantine cards” back in July 2007. The Shenzhen Inspection and Quarantine Bureau installed the devices free of charge to thousands of vehicles across Hong Kong. The devices are about the size of a PDA, screwed into the car’s front window.People in Hong Kong, in particular criminals, began to notice something was awry when the authorities were able to pick out cars carrying illegal goods across borders without problem or hesitation.
"For every ten cars we ran we only had [smuggled goods] in three or four to reduce the risk, but the border agents caught all of them. The accuracy was unreal!" one smuggler told Apple Daily.
scmagazineus.comGoogle has identified and disrupted a campaign operating out of eastern China meant to hijack and monitor the Gmail accounts belonging to hundreds of users, the technology giant revealed Wednesday.
Victims included U.S. and Asian government officials -- mostly from South Korea, military members, journalists and Chinese political activists, said Eric Grosse, engineering director of the Google's security team, in a blog post.
The campaign appears to trace back to Jinan, China and involves the theft of user's Gmail passwords, likely through phishing, he said. Google was able to disrupt the campaign, secure the affected accounts and notify the targeted individuals.
"The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Grosse wrote. "Google enables you to forward your emails automatically, as well as grant others access to your account."
More...
channelinsider.comBrett Kingstone’s 80-person fiber-optic lighting company, Super Vision, was targeted by a Chinese government shell company which bribed one of Kingstone’s key employees to steal designs and process secrets. The Chinese then set up a company to duplicate Super Vision’s products and offer them at low prices, since the cost of stealing was a fraction of the cost of Super Vision’s research and development.
In his book, The Real War Against America (Specialty Publishing Company, 2005) Kingstone describes how he was challenged by his distributors when they found his company’s products being offered for much lower prices. Kingstone was confused until he was able to get samples, which matched Super Vision’s products in every way. Through a spy-thriller ordeal that included bribes, threats, shredded evidence, stolen equipment, fraudulent bankruptcy filings, an FBI investigation, and private investigators posing as Arab sheiks, Kingstone was able to get a $33.1 million civil judgment even though the culprits avoided criminal prosecution.
More...
ca.reuters.comPARIS (Reuters) - France's intelligence services have unearthed a case of suspected industrial espionage at an engine subsidiary of French aerospace and defense firm Safran, Le Monde newspaper said in its weekend edition.
A Safran spokeswoman declined to comment on Sunday when contacted by Reuters about the report, which spoke of a Chinese link.
The newspaper said investigators had placed about 10 people in custody as they dig for information about a 2010 attack on the computer networks of Safran subsidiary Turbomeca, which makes helicopter engines.
It said hackers broke into the computer networks and gained access to sensitive information about propeller systems at Turbomeca, as well as Safran documents containing information about billing and the cost of various company projects.
The computer break-ins took place during the first eight months of 2010 and may have involved help from company insiders, Le Monde reported it was told by an unnamed judicial source.
More...
Berlin - Industrial espionage by China and Russia is becoming easier thanks to computer hacking, officials warned German business leaders on Thursday, adding that police need data logs to track computer break-ins.
A conference heard that the annual cost to German companies of data theft was at least 20 billion euros (nearly 30 billion dollars).
However it is often easier to simply buy corporate secrets from disloyal employees.
Ole Schroeder, a senior Interior Ministry official, said that in 70 per cent of known cases, staff who hated their employer or were angry that they were likely to lose their jobs were behind the leaks.