Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

51–60 of 502 posts

Re: Technical report on DNC hack [pdf]

#53

'The U.S. Government assesses that information was leaked to the press and publicly disclosed.' Who in US Government? What information was leaked?

I examined the documents with a leaked 0-day steganographic analysis flux capacitor, and it discovered the words "JOINT ANALYSIS REPORT" underneath the DHS and FBI logos. That might be a clue.

Re: Technical report on DNC hack [pdf]

#54
They ought to encourage the use of prepared statements to defend against SQL injections. It's the only way to handle that threat, yet the report does not mention it:

"5. Input Validation - Input validation is a method of sanitizing untrusted user input provided by users of a web application, and may prevent many types of web application security flaws, such as SQLi, XSS, and command injection."

    https://en.wikipedia.org/wiki/Prepared_statement 
    https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet

Re: Technical report on DNC hack [pdf]

#55
post #47
post #41

Earlier quoted context omitted.

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Did they really need to say, "We also have other data about the attack that we're not publishing because it's classified"? Isn't that kind of safe to assume?

I don't think it is safe to assume at all. They laid this at Russia's feet almost immediately and before any investigation was conducted.

Re: Technical report on DNC hack [pdf]

#56
post #47
post #41

Earlier quoted context omitted.

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Did they really need to say, "We also have other data about the attack that we're not publishing because it's classified"? Isn't that kind of safe to assume?

When things like this are used as a pretext to sanction other countries, I will assume nothing and expect data. The bogus weapons of mass destruction in Iraq was enough to convince me that "just trust us" isn't sufficient data.

Re: Technical report on DNC hack [pdf]

#57

It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email. Edit: changed "zero claims" to "zero credible cl…

s/shouldn't discuss them over email./shouldn't.

Re: Technical report on DNC hack [pdf]

#58

Earlier quoted context omitted.

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

Cheney literally made up an intelligence agency to tell him what he wanted, after the CIA said there was no evidence of WMD. If you blame the CIA for that, you very mistaken.

Re: Technical report on DNC hack [pdf]

#59

Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

[deleted]

Re: Technical report on DNC hack [pdf]

#60

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

The Chinese Fighter plane probably was a bigger deal on the merits. I don't know how seriously our national security apparatus takes that versus this attack.

As an attack, though, it didn't rise to a major domestic political issue because there just isn't anything up for debate. It happened, it's clearly bad — where was our response lacking? Maybe it was lacking, but apparently our two parties don't disagree enough to make it an issue.

And that's the issue here. If both parties agreed that it's wrong for foreign governments to hack the DNC's e-mail and air their dirty laundry, there wouldn't be much public debate. But the President elect claims it didn't even happen, and that's making the stakes far larger than the issue itself.

It's like Elian Gonzales: how much does the event itself matter? Not that much. How much do the conflicting political forces arrayed around the event matter? A whole lot.

Post reply on HN