[新聞] WSJ:BABA高層因阿里雲洩密案被調查

看板Stock作者 (賽非茵)時間1年前 (2022/07/14 23:50), 編輯推噓6(607)
留言13則, 9人參與, 1年前最新討論串1/1
原文標題: Alibaba Executives Called In by China Authorities as It Investigates Historic Data Heist 原文連結:https://ibit.ly/xBWI 發布時間:July 14, 2022 11:33 am ET 記者署名:Karen Hao 原文內容: HONG KONG—Executives from Alibaba Group Holding Ltd.’s BABA -4.86%▼ cloud division have been called in for talks by Shanghai authorities in connection with the theft of a vast police database, according to people familiar with the matter, adding urgency to an internal investigation by the Chinese tech giant into how one of history’s largest data heists was allowed to happen. The investigation revolves around a cache of sensitive Shanghai police data on an estimated nearly one billion Chinese citizens, which was offered for sale online for the equivalent of roughly $200,000 in late June. Cybersecurity researchers said a dashboard for managing the database had been left open on the public internet without a password for more than a year, making it easy to pilfer and erase its contents. Based on scans of the database, the researchers concluded that it was hosted on Alibaba’s cloud platform. Company employees also confirmed the relationship. Senior managers from Alibaba and its cloud unit gathered virtually to formulate an emergency response on July 1, after an anonymous seller posted an advertisement for the data and provided a sample of it in a cybercrime forum, according to people briefed on the meeting. Executives called in for meetings with the Shanghai authorities include Alibaba Cloud Vice President Chen Xuesong, who was recently hired to lead the unit’s digital public-security business, according to people familiar with the matter. Mr. Chen couldn’t be reached for comment. Alibaba and the Shanghai government didn’t immediately respond to requests for comment. Since the theft was discovered, Alibaba engineers have temporarily disabled all access to the breached database and have begun inspecting related code, some employees familiar with the response said. The reasons for the breach haven’t yet been determined, they said. Two cybersecurity companies told The Wall Street Journal the stolen data had been stored on Alibaba’s cloud using technology that was several years outdated and lacked basic security features, according to an analysis of the database’s metadata—part of a pattern they detected with more than a dozen other databases hosted by the company. Alibaba didn’t respond to a request for comment on the companies’ findings. Based on samples provided by the seller, the stolen data is believed to contain the names, government ID numbers and phone numbers of the vast majority of Chinese citizens, including minors, as well as records of crimes reported to the Shanghai police and other sensitive information. Though it’s common around the globe for databases to be left unsecured, cybersecurity researchers have said they were shocked to see such a huge volume of this level of sensitive information set out for the taking. The breach has highlighted the volumes of data Chinese authorities are collecting through the country’s nationwide digital surveillance system, as well as the difficulty the government faces in keeping that data secure. A report published by China’s state-sponsored National Academy of Governance in November warned that a paucity of professionals capable of handling digital systems and a lack of coordination with tech suppliers were undermining the government’s effort to use technology to more efficiently manage society. Mr. Chen, the Alibaba Cloud executive called in by Shanghai authorities, formerly worked as a government-funded engineer in public security and information technology, according to employees familiar with his background. It couldn’t be determined what was discussed in their meeting. As the investigation continued, Alibaba Cloud ordered staff to review details such as the database architecture and configurations in contracts with key clients, especially those with dedicated private cloud resources such as government agencies and financial institutions, according to employees familiar with the matter and a cloud customer. 心得/評論: 盤中突然崩崩 查了一下發現這新聞 對岸網友還說:別讓馬雲跑了XD 不說這個,十億洩密看來真的很傷,這樣誰敢用阿里雲阿? 無怪乎會被調查了. -- ※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 118.160.70.94 (臺灣) ※ 文章網址: https://www.ptt.cc/bbs/Stock/M.1657813841.A.7DA.html

07/14 23:55, 1年前 , 1F
4%在美股算崩嗎?
07/14 23:55, 1F

07/14 23:59, 1年前 , 2F
4%還好吧
07/14 23:59, 2F

07/14 23:59, 1年前 , 3F
你去看分k阿 不過也有人說財經記者和空方串通好了
07/14 23:59, 3F

07/14 23:59, 1年前 , 4F
之前誤傳馬雲被黨控制 馬上跌了9%
07/14 23:59, 4F

07/15 00:09, 1年前 , 5F
今天很多阿里的壞消息~如解散三組團隊之類的
07/15 00:09, 5F

07/15 00:15, 1年前 , 6F
可能最近漲太多 所以大家瘋狂空它
07/15 00:15, 6F

07/15 01:24, 1年前 , 7F
十億資料夠本島詐騙集團玩好幾輪
07/15 01:24, 7F

07/15 01:24, 1年前 , 8F
07/15 01:24, 8F

07/15 01:30, 1年前 , 9F
新手嗎?沒有這資料 你知道隨便花小錢都能"開盒"?
07/15 01:30, 9F

07/15 01:30, 1年前 , 10F
電梯向上?下?
07/15 01:30, 10F

07/15 01:30, 1年前 , 11F
TG 社工庫隨便找一堆 要什麼有什麼
07/15 01:30, 11F

07/15 01:37, 1年前 , 12F
洗把韭菜怎麼了?
07/15 01:37, 12F

07/15 08:21, 1年前 , 13F
他的手可以穿過我的 baba
07/15 08:21, 13F
文章代碼(AID): #1Yq3jHVQ (Stock)