China's attack on Google explained
China's attack on Google explained
6:51

China's attack on Google explained

Tech Industry
[ Music ] ^M00:00:04 >> Google shocked the tech community this past week by not only announcing that they were considering pulling out of China but the reason why was targeted attacks against them from within China. Now, there has been a lot of confusion and speculation about whether it's the government at fault, what these attacks were, what kind of information they got away with. And to help us make a little bit clearer picture on what's happening in China's attacks on Google, we have Elinor Mills from CNET News. Thanks for joining us, Elinor. >>Elinor: Sure. >> Let's start with what happened. What did Google know and when did they know it? >>Elinor: Google this week said that in mid-December they noticed that there had been a network intrusion on its corporate network. It said that it was highly sophisticated and it was investigating. And it said that, at the time that it noticed, intellectual property was stolen. >> Okay. So this is an attack on Google, trying to steal stuff. Do we know what they tried to steal? What kind of intellectual property? >>Elinor: No. They won't say, but other sources who are familiar with the investigation said that the attacks were directed at source code. >> Okay. So that would make sense. That's the kind of intellectual property someone might be after. >>Elinor: Also, someone was able to go through the Google network somehow, get in there, and access Juno accounts from two users and see some account information, like when it was created, but they were not able to read the contents. >> Okay. So they didn't get in and read the email? >>Elinor: No. >> They got into the Google network and found some account information about them. >>Elinor: Right. >> Those were internal. Now, there were also some external attacks, not on Google but against Google properties, right? >>Elinor: Against Google users, specifically other Gmail users who had their computers infected separately, not associated with Google. >> So this wasn't an attack against the Google network. This is an attack against home computers and then getting in and reading people's Gmail. >>Elinor: Exactly. >> And why were they targeting Gmail at all? >>Elinor: The link between these Gmail users was that they were human rights activists or somehow involved in human rights. >> Okay. So we have two types of attacks; we have two targets. One was intellectual property, and the other was going after dissidents. How were these attacks executed? >>Elinor: Microsoft said yesterday that there was a newly discovered vulnerability in Internet Explorer that was used in the attacks. >> Okay. So all versions of Internet Explorer? >>Elinor: Six. They said IE6 was used. >> Okay. Seven and eight doesn't have to worry? >>Elinor: Seven and eight also are vulnerable. >> But wasn't used in the attacks. >>Elinor: So it's to the exploit. But, in the attacks, they specifically said IE6. >> And they've got a patch coming for that? >>Elinor: Yes. >> Okay. So maybe a PDF file, definitely an Internet Explorer vulnerability. >>Elinor: Yeah, definitely. >> And where did these attacks come from? What do we know about that? >>Elinor: Google specifically said they originated in China. They did not blatantly come out and say that they think the Chinese government is behind it. They said they're going to stop censoring their [inaudible]. >> They've implied it through their actions, essentially. >>Elinor: Absolutely. >> But there are some other researchers who've said, "Yeah. I think we know this is China." How did they -- how did they come to that determination? >>Elinor: Yeah. Tracing it to servers that were found to be hosting the data that were in Taiwan; and, then, also, servers that were found to be in Texas and Illinois. >> Okay. So when they were looking at -- and I understand they call it Project Aurora as sort of a code name. >>Elinor: McAfee's calling it -- >> -- is it from what McAfee's calling the vulnerability or the code? >>Elinor: Yeah. >> It was communicating to servers in Texas, Illinois, and Taiwan. >>Elinor: There are links to IP addresses that were similar to attacks that previously had been done on US corporations similar to this that were linked to the Chinese state. >> So it fit the profile, in other words. >>Elinor: It fit the profile. >> Okay. So we know what happened, we know how it happened, we know from where it came, sort of. Who else did it affect? Because I know others, besides Google, were under attack, as well. >>Elinor: The same day that Google made their announcement, on Tuesday, shortly thereafter Adobe came out and said, "Our network was attacked." Now, they didn't link it specifically to Google; but that's the implication is that Google had said at least twenty other companies were part of these attacks. >> And then Adobe announced an attack that was similar, so we can assume it must be part of the same? >>Elinor: Right. Yeah. That it's a similar attack. They didn't give any details. They said they are still investigating. >> Who else? >>Elinor: Since then, researchers listed Yahoo, Symantec, Northrop Grumman, Dow Chemical, and Juniper networks. Yahoo, Symantec, Grumman, and Dow have all either declined to comment or have declined to say whether it -- you know, confirm it or deny it. Juniper has said they are investigating attacks. Now, whether, you know, they didn't say specifically attacks on our network or what, so. >> And Juniper does investigate attacks as part of their business. >>Elinor: Yes. >> Yeah. So they are obfuscating a little bit there, as well. >>Elinor: Absolutely. >> How many total companies? Is it just twenty or do we think it's more? >>Elinor: Okay. So, no. The number has been pegged at 34 from iDefense and others. >> Okay. So we think -- >>Elinor: 34 total, including Google. >> 34 companies and all after the same sort of thing? Human rights and intellectual property, or do we even know? >>Elinor: Actually, for these companies, it would be the intellectual property. >> Now, before we wrap up, that seems to kind of encapsulate it. But we had one interesting incident later on at -- these attacks all started in December, ended around January 4th, right? >>Elinor: Right. Because one of the servers or more of the servers were cut down then. >> And we don't know why they were cut down. >>Elinor: We don't know. >> But, after they went down, something else happened. >>Elinor: Okay. Yeah. So a law firm in LA, Gipson, Hoffman and Pancione reported that it, too, had had a similar type of attack on its employees. And, again, they say that there is the China connection based on the way the attacks were done and the timing. Now, the firm is alleging in the lawsuit that China stole code from that US product to use in its Green Dam software that it's using to -- >> Filter. >>Elinor: To filter and block citizens from accessing internet sites. >> Okay. So they -- there's a case for retaliation there -- >>Elinor: Absolutely. >> -- that you could see and understand. One last question. All of this seems very clear. Thank you for helping to explain it. Things are still developing. Are there any other issues that we think might crop up that we should keep an eye on? >>Elinor: Yeah. The investigations continue on all the -- the attacks on all the companies, and information is trickling out. One -- a couple of sources have said that Google is most definitely probably looking at insider -- an insider threat. >> So someone infiltrated Google? >>Elinor: Or -- yes. An employee maybe with connections to China. >> That's serious. That's something to keep our eyes on. All right. Thank you so much, Elinor. We appreciate the walk-through. We are going to keep following the story. Look for Elinor and Tom Krazit's work at news .com, and we'll keep you up to date. [ Music ] ^M00:06:51

Up Next

The Big Vision Behind These iOS, WatchOS Updates
231207-vision-pro-mindset-v03-b

Up Next

The Big Vision Behind These iOS, WatchOS Updates

What I Learned Using Apple's Journal App
231129-site-apples-latest-app-to-fix-you-v2

What I Learned Using Apple's Journal App

Apple Products We're Expecting in 2024
231121-site-whats-coming-in-2024-apples-leftovers-v3

Apple Products We're Expecting in 2024

Exploring Spatial Video: What It's Like to View, Shoot 3D iPhone Videos
231116-site-what-to-know-about-spatial-video-v2

Exploring Spatial Video: What It's Like to View, Shoot 3D iPhone Videos

Apple Watch Double Tap Early Impressions
231109-site-double-tap-commentary

Apple Watch Double Tap Early Impressions

Apple's M3 Sparks a New Era of Mac vs. PC Battles
231102-site-the-return-of-mac-vs-pc

Apple's M3 Sparks a New Era of Mac vs. PC Battles

Apple Unveils 14-Inch, 16-Inch MacBook Pros With M3 Processors
pic

Apple Unveils 14-Inch, 16-Inch MacBook Pros With M3 Processors

Apple Debuts 24-Inch iMac With M3 Chips
apple-unveils-new-24-inch-imac-with-m3-processor-mp4-00-00-08-12-still001

Apple Debuts 24-Inch iMac With M3 Chips

Trick or Treat? Apple's 'Scary Fast' Mac Event Makes Us Jumpy
scary-fast-apple-event-clean

Trick or Treat? Apple's 'Scary Fast' Mac Event Makes Us Jumpy

I Upgraded to the iPhone 15 Pro Max: Was It Worth It?
thmbcnet

I Upgraded to the iPhone 15 Pro Max: Was It Worth It?

Tech Shows

The Apple Core
apple-core-w

The Apple Core

Alphabet City
alphabet-city-w

Alphabet City

CNET Top 5
cnet-top-5-w

CNET Top 5

The Daily Charge
dc-site-1color-logo.png

The Daily Charge

What the Future
what-the-future-w

What the Future

Tech Today
tech-today-w

Tech Today

Latest News All latest news

Creating the World's Most Efficient Solar Electric Car
cruiser-class

Creating the World's Most Efficient Solar Electric Car

The Big Vision Behind These iOS, WatchOS Updates
231207-vision-pro-mindset-v03-b

The Big Vision Behind These iOS, WatchOS Updates

First Impressions of Gemini: Google's Newest Major AI Upgrade
gemini-sb-v2-copy-01-00-01-19-02-still003.png

First Impressions of Gemini: Google's Newest Major AI Upgrade

These Are the Best Wireless Earbuds for 2023
broll-00-02-39-17-still001.png

These Are the Best Wireless Earbuds for 2023

AMD's AI Chip Event: Everything Revealed in 8 Minutes
amd-ai-event-clean

AMD's AI Chip Event: Everything Revealed in 8 Minutes

Can the Samsung Gaming Hub Replace An Xbox?
p1005566

Can the Samsung Gaming Hub Replace An Xbox?

Most Popular All most popular

The PlayStation 5 Slim: Hands-On
p1019822

The PlayStation 5 Slim: Hands-On

Lomi Makes Composting Faster and Cleaner at Home
lomi-thumb-site

Lomi Makes Composting Faster and Cleaner at Home

These Are the Best Wireless Noise-Canceling Headphones for 2023
broll-00-00-58-10-still001.png

These Are the Best Wireless Noise-Canceling Headphones for 2023

LG's latest soundbars promise more realistic voices
soundbar-thumb

LG's latest soundbars promise more realistic voices

Can the Samsung Gaming Hub Replace An Xbox?
p1005566

Can the Samsung Gaming Hub Replace An Xbox?

Sony Pulse Explore Earbuds: Setup and Hands-On
cnet

Sony Pulse Explore Earbuds: Setup and Hands-On

Latest Products All latest products

Sony Pulse Explore Earbuds: Setup and Hands-On
cnet

Sony Pulse Explore Earbuds: Setup and Hands-On

The PlayStation 5 Slim: Hands-On
p1019822

The PlayStation 5 Slim: Hands-On

CNET Editor Reacts to Vision Pro Spatial Video
04-viewing-spatial-videos-in-apple-vision-pro

CNET Editor Reacts to Vision Pro Spatial Video

Samsung's 98-inch 8K TV Is Big, Bright and Really Expensive
samsung98in-2

Samsung's 98-inch 8K TV Is Big, Bright and Really Expensive

300-Mile Honda Prologue EV Hits the Road Next Year
hondapic2

300-Mile Honda Prologue EV Hits the Road Next Year

Meta's Ray-Bans, Hands-On: These Glasses Now Stream to Instagram
raybanglassescnet

Meta's Ray-Bans, Hands-On: These Glasses Now Stream to Instagram

Latest How To All how to videos

Tips and Tricks for the Galaxy Watch 6
231120-site-tips-tricks-and-hidden-features-v2

Tips and Tricks for the Galaxy Watch 6

How to Use ChatGPT's New Voice Conversations
how-to-use-chatgpt-voice-chat-00-03-01-13-still003

How to Use ChatGPT's New Voice Conversations

How to Add Multiple Accounts and Set Up a Parent-Supervised Account on the Quest 3
add-accounts-on-quest-3-00-02-59-11-still005

How to Add Multiple Accounts and Set Up a Parent-Supervised Account on the Quest 3

How to Take Screenshots in Windows 11
p1022383-00-00-00-06-still003

How to Take Screenshots in Windows 11

10 Must-Try Hidden iOS 17 Features on Your iPhone
230921-site-ios-17-hidden-features

10 Must-Try Hidden iOS 17 Features on Your iPhone

How to Record Your Screen in Windows 11
how-to-record-your-screen-in-windows-11-00-00-48-13-still002

How to Record Your Screen in Windows 11