Live data from Hacker News

Hacker Releases More Democratic Party Documents

nytimes.com

41–50 of 52 posts

Re: Hacker Releases More Democratic Party Documents

#41
post #6

Why does the actual source: https://guccifer2.wordpress.com/2016/08/12/guccifer-2-0-hack... https://news.ycombinator.com/item?id=12279977 get flag-killed immediately where as this somewhat colored article gets on the frontpage?

... was wondering too. The screenshots in the NYT article look like "teaser-advertisements", while the actual sources are a big taboo. Keep in mind that Guccifer2 isn't a lone hacker as initially portrayed. Guccifer2 is a cover for APT-28/APT-29 (GRU). So if anything then this leak has to be considered for what it was: A foreign nation meddling in the elections of another. Current Russian meddling fits seamlessly int…

So if anything then this leak has to be considered for what it was: A foreign nation meddling in the elections of another.

Let's put that into context tho': it happens all the time and no-one bats an eyelid. When Obama came over and said we should vote Bremain, lots of people were annoyed at his presumption, but no-one considered it that big a deal.

Re: Hacker Releases More Democratic Party Documents

#42

Muh Russia... I to my girlfriend- how dare you cheat on me. You are texting Sam since a year. My gf to me: How dare you breach my trust by looking at my phone? This doesn't count.

If you violate multiple laws in looking at this hypothetical person's phone, then yes, you're more in the wrong.

Re: Hacker Releases More Democratic Party Documents

#43
I posted the leak on here yesterday and yeah, it was flagged immediately. Hate to have to say it but when it comes to information critical of a certain candidate this place is an echo chamber, looks like 13 people have now submitted the site and it is no longer flagged. Still concerning about the overall censorship in regards to a topic this site should find interesting no matter your political views https://news.ycombinator.com/item?id=12279977

Re: Hacker Releases More Democratic Party Documents

#44

Earlier quoted context omitted.

"""" CrowdStrike Services Inc., our Incident Response group, was called by the Democratic National Committee (DNC), the formal governing body for the US Democratic Party, to respond to a suspected breach. We deployed our IR team and technology and immediately identified two sophisticated adversaries on the network – COZY BEAR and FANCY BEAR. We’ve had lots of experience with both of these actors attempting to target…

Not an infosec pro but parts of this sounds like hogwash to me: * broadly targeted spearphising attack * both groups were constantly going back into the environment to change out their implants, modify persistent methods, move to new Command & Control channels and perform other tasks to try to stay ahead of being detected.

I'm guessing "broadly targeted spearphishing" means that you're targeting a lot of people, but you know who they are and you're sending them something that's crafted to their interests and social network.

Re: Hacker Releases More Democratic Party Documents

#45

Maybe now Diane Feinstein will see the value of end to end encryption? Doubt it. She'll probably advocate that only for herself and her Senate colleagues.

Nobody disputes the value of end to end encryption. That's not the issue. The problem of encryption is that it changes the relationship between government and individual in a way that has never been seen before. If a person is suspected of committing a crime the police have always had the ability to intercept mail, record calls, search property etc and obtain evidence. They can't do that now. You can argue the pros/c…

Well, technology has changed the status quo in two ways.

The first is, as you say, previously you could intercept a suspect's mail and search their papers; with proper encryption that isn't possible.

The second is in the past the search process wouldn't scale to searching every citizen all the time. With e-mail, web traffic and smartphones, it becomes possible.

We can restore the status quo from 30 years ago for either one of those changes, but not for both.

Re: Hacker Releases More Democratic Party Documents

#46
post #23

Earlier quoted context omitted.

> Guccifer2 is a cover for APT-28/APT-29 (GRU). How do you know? The NYT keeps using the passive voice ("believed to be tied to the Russian intelligence") or saying that some unnamed "American intelligence officials" told them so. Even when they name the officials, they don't say how they determined it.

"""" CrowdStrike Services Inc., our Incident Response group, was called by the Democratic National Committee (DNC), the formal governing body for the US Democratic Party, to respond to a suspected breach. We deployed our IR team and technology and immediately identified two sophisticated adversaries on the network – COZY BEAR and FANCY BEAR. We’ve had lots of experience with both of these actors attempting to target…

Nothing in here provides any evidence it was the Russian gov't, except "because we say so" in the middle of a wall of techno-babble.

Re: Hacker Releases More Democratic Party Documents

#47

Earlier quoted context omitted.

Nobody disputes the value of end to end encryption. That's not the issue. The problem of encryption is that it changes the relationship between government and individual in a way that has never been seen before. If a person is suspected of committing a crime the police have always had the ability to intercept mail, record calls, search property etc and obtain evidence. They can't do that now. You can argue the pros/c…

They can intercept my encrypted emails just like they've always been able to intercept encrypted hand written letters.

This precisely.

Re: Hacker Releases More Democratic Party Documents

#48

Maybe now Diane Feinstein will see the value of end to end encryption? Doubt it. She'll probably advocate that only for herself and her Senate colleagues.

Nobody disputes the value of end to end encryption. That's not the issue. The problem of encryption is that it changes the relationship between government and individual in a way that has never been seen before. If a person is suspected of committing a crime the police have always had the ability to intercept mail, record calls, search property etc and obtain evidence. They can't do that now. You can argue the pros/c…

Police can still intercept communications, including mail, phone calls, etc., with classic investigative techniques like bugging a person's home. Then you can see all their passwords, all their emails, their off-line conversations, and so on. Bugging somebody probably reveals more information than security backdoors.

The one big difference between bugging someone's home vs. encryption backdoor is one of scale, and I don't think citizens should so substantially yield their security so that the state can save money.

I think the natural inclination of voters isn't relevant just yet because privacy and encryption are so far down the list of topics of national salience, or topics to organize voters, that it doesn't register on anyone's political radar. If encryption or security backdoors are mentioned on the national stage, it will be entirely as a subtopic of only terrorism.

Re: Hacker Releases More Democratic Party Documents

#49

Earlier quoted context omitted.

"""" CrowdStrike Services Inc., our Incident Response group, was called by the Democratic National Committee (DNC), the formal governing body for the US Democratic Party, to respond to a suspected breach. We deployed our IR team and technology and immediately identified two sophisticated adversaries on the network – COZY BEAR and FANCY BEAR. We’ve had lots of experience with both of these actors attempting to target…

Nothing in here provides any evidence it was the Russian gov't, except "because we say so" in the middle of a wall of techno-babble.

Very true - also, this being their technical report, I'd personally be surprised if there wasn't some amount of technical jargon present, sufficient to establish the facts of these events. All they do is identify a set of sophisticated actors who have tradecraft and technical expertise to rival a nation state, and then further established a series of similar attacks have been conducted on targets of Russian foreign interests by these same groups. Short of an indictment a la Chinese hackers, or declassification of the information pertaining to the attacks (something that's apparently being prepared), there are not facts present to make a formal attribution.

Re: Hacker Releases More Democratic Party Documents

#50

Is Wikileaks announcement that the recently murdered DNC staff member was the source of the leaks, not Russian hackers, credible? I don't know, and in anycase I consider the source of the leaks to be much less important than the contents of the leaks. When we watch a good magician, they entertain us by using misdirection. Unfortunately, when the deep state and the media they control use misdirection it is not fun or…

If you listen to Assange's interview, he says nothing of substance, just insinuates the connection.
Post reply on HN