public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Adam Carter <adamcarter3@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Google Inc. Could Be Compliant to the Chinese Government in Beijing, People's Republic of China (PRC)
Date: Tue, 21 Sep 2010 18:32:14 +1000	[thread overview]
Message-ID: <AANLkTinqoQCmu80z6vRKJrOouptp2D_dRx7+3U3mv3ac@mail.gmail.com> (raw)
In-Reply-To: <4C97FEF2.6000305@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 1748 bytes --]

On Tue, Sep 21, 2010 at 10:40 AM, "Mr. Teo En Ming (Zhang Enming) 张恩鸣 of
Singapore" <space.time.universe@gmail.com> wrote:

> Article: Google Warns of China Exit Over Hacking
> Link: http://online.wsj.com/article/SB126333757451026659.html
>
>
Nice to be back in January and OT ;)


> I don't think it is that easy to hack if you are using SSL connections and
> very strong passwords. How long would it take supercomputers to perform a
> brute force attack if you are using a strong password with at least 20
> characters, and a combination of upper case and lower case letters, numbers,
> and symbols?
>

In TFA they said the attack against google was sophisticated and IP was also
stolen, so if that's true it wasnt a brute force against gmail accounts
which isnt sophisticated or would reveal any of google's IP.

Also an easier way to attack gmail passwords would be via a MITM with a
dodgy certificate. x509 authentication is as weak as the weakest CA in a web
browsers trusted certificate store.... Remember the the dodgy mozilla cert
from last year?


>
> I am wondering if Chinese government officials could have secretly
> approached specific Google China employees for direct access to the Google
> GMail email accounts of human rights activists in China? It would have been
> far simpler to do it that way. What is the size of China's sovereign wealth
> fund?
>

Or they could get their agents to apply for jobs at google and get in that
way.

This would be OnT at securityfocus.com Security Basics list.You'd probably
get an answer about the password cracking time there, but you'd need to
specify the conditions (online or offline, and if offline what format the
passwords are stored in)

[-- Attachment #2: Type: text/html, Size: 2473 bytes --]

      reply	other threads:[~2010-09-21  9:06 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-09-21  0:40 [gentoo-user] Google Inc. Could Be Compliant to the Chinese Government in Beijing, People's Republic of China (PRC) "Mr. Teo En Ming (Zhang Enming) 张恩鸣 of Singapore"
2010-09-21  8:32 ` Adam Carter [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=AANLkTinqoQCmu80z6vRKJrOouptp2D_dRx7+3U3mv3ac@mail.gmail.com \
    --to=adamcarter3@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox