Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

41–50 of 502 posts

Re: Technical report on DNC hack [pdf]

#41
post #32

This report is a joke. I didn't find any reasoning about attribution. Here is the only valuable part: " rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "

Did you read the first page? This report has nothing to do with detailing or justifying attribution

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Re: Technical report on DNC hack [pdf]

#42

Earlier quoted context omitted.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

Why trust them in the first place, look at the evidence and if you disagree with a conclusion, be able to say why. This is the whole problem we're dealing with right now - people just decide they do or do not trust something. Don't agree with a fact check? Just call it bogus and move on, even though it might be a 50 point case they make why bother finding a flaw in their reasoning and using that to refute their concl…

The basic flaws I'd mention are:

- Multiple state actors (or well-funded non-state actors) likely compromised the emails.

- A state actor could also have faked the "trail" that points to Russia.

- The rest of the evidence is circumstantial.

Sure, if we pretend we live in a pre-stuxnet, script kiddie sort of world, this was likely a high level state sponsored attack, but it seems preposterous that a state actor would be so sloppy:

If you were Putin wishing to try to use spearfishing to get access to specific accounts, you would not source that work to groups that were known to work with your government. You'd set up a fake Nigerian operation so that if found it would look like the email address had been randomly chosen from a list of many used by some Nigerian person to try to scam a few thousand dollars.

This is not akin to thinking three or four moves ahead, it's simply thinking one move ahead.

Re: Technical report on DNC hack [pdf]

#43

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

It was the timing of the exposure that could have interfered with the results of the Presidential election which is a major news event in the US that many people perceive to have a higher impact on their lives vs. a quietly disclosed hack/coincidence (F-35 example).

Plus in some people's minds a private defense contractor being "hacked" is more along the lines of industrial espionage instead of a major political party being "hacked" during an election. Even worse, certain news outlets reporting that the election itself(!) was hacked which is misleading and could make people think that voting machines were actually hacked by a foreign power instead of the PsyOps which allegedly took place.

Re: Technical report on DNC hack [pdf]

#44
post #29

Earlier quoted context omitted.

It seems notable that many of these comments are jumping on this for not providing proof that it was Russia, when that was not the intention of the report. The first page states- >This JAR provides technical indicators related to many of these operations, recommended mitigations, suggested actions to take in response to the indicators provided, and information on how to report such incidents to the U.S. Government.

The bloomberg article I read ( http://archive.is/j5wRd ) presented it as evidence. Maybe other publications are doing the same. >As part of the administration’s response, the FBI and Homeland Security Department also released a report with technical evidence intended to prove Russia’s military and civilian intelligence services were behind the hacking and to expose some of their most sensitive hacking infrastructure.

> presented it as evidence

Quite predictable, since they also considered the wild accusations of various politicians of a high level Russian conspiracy to be evidence.

Re: Technical report on DNC hack [pdf]

#45

Earlier quoted context omitted.

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

It's certainly possible that intelligence agencies are mistaken or deliberately lying. We can't possibly know if that's the best interpretation of the evidence they may or may not have. They have been correct in the past as well.

The best and only thing the average citizen can really do is try to put people in office who can intelligently parse classified information and evidence from intelligence agencies.

Re: Technical report on DNC hack [pdf]

#46
It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email.

Edit: changed "zero claims" to "zero credible claims"

Re: Technical report on DNC hack [pdf]

#47
post #41
post #32

Earlier quoted context omitted.

Did you read the first page? This report has nothing to do with detailing or justifying attribution

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Did they really need to say, "We also have other data about the attack that we're not publishing because it's classified"? Isn't that kind of safe to assume?

Re: Technical report on DNC hack [pdf]

#48
post #16

~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|grep -f exits -c 191 ~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|wc -l 876 At least 191 of the IOC IPs are (probably random) Tor exit nodes :) The actual number may very well be higher, I just grabbed current exit node list from https://check.torproject.org/exit-addresses Here's the PHP backdoor the YARA rule…

Wow, this should be the top comment.

Re: Technical report on DNC hack [pdf]

#49

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

> No one is denying that the emails are real.

Actually, Donna Brazile, who is inexplicably still the current chair of the DNC, claimed the emails were falsified: https://youtu.be/P_WHsr07cbY?t=458

Re: Technical report on DNC hack [pdf]

#50
post #41
post #32

Earlier quoted context omitted.

Did you read the first page? This report has nothing to do with detailing or justifying attribution

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Then why did the report attribute any of this to Russia without substantiating those claims?

If my boss drops a request on me to write a report on the "technical details regarding the tools and infrastructure used by the X to do Y", I don't spend time in the report explaining that X did Y. That's not the point of the report I was asked to make. That's a different report.

Post reply on HN