Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

61–70 of 502 posts

Re: Technical report on DNC hack [pdf]

#61
post #29

Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

It seems notable that many of these comments are jumping on this for not providing proof that it was Russia, when that was not the intention of the report. The first page states- >This JAR provides technical indicators related to many of these operations, recommended mitigations, suggested actions to take in response to the indicators provided, and information on how to report such incidents to the U.S. Government.

Agreed - this is meant to present the evidence or at least the public part of.

If this is all there is; then the skepticism coming from the incoming administration is warranted.

Re: Technical report on DNC hack [pdf]

#62

Earlier quoted context omitted.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

You clearly don't understand the intelligence process if this is your critique. First, the people making the DNC hack report are not the same as the analysts who worked on Iraq. The IC is not a monolith. Second, the Bush White House saw the intelligence they wanted to see. Third, burning sources and methods is a very real concern in intelligence gathering. That reality can't be ignored no matter how much you want inf…

>Second, the Bush White House saw the intelligence they wanted to see.

And the Obama administration is not doing the exact same thing here? I'm sorry but a py2exe agent dropped from phishing, some random IP addresses, and some publicly known persistence techniques do not an APT make. This is horse shit

Re: Technical report on DNC hack [pdf]

#63

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

It was the timing of the exposure that could have interfered with the results of the Presidential election which is a major news event in the US that many people perceive to have a higher impact on their lives vs. a quietly disclosed hack/coincidence (F-35 example). Plus in some people's minds a private defense contractor being "hacked" is more along the lines of industrial espionage instead of a major political part…

There was barely any coverage when the Office of Personnel Management was hacked and the personal data of millions of people holding security clearances was taken. The hue and cry about the social engineering hack of the email of a political party campaign manager seems far in excess of the response for that...

Re: Technical report on DNC hack [pdf]

#65
post #49

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

> No one is denying that the emails are real. Actually, Donna Brazile, who is inexplicably still the current chair of the DNC, claimed the emails were falsified: https://youtu.be/P_WHsr07cbY?t=458

[deleted]

Re: Technical report on DNC hack [pdf]

#66
post #49

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

> No one is denying that the emails are real. Actually, Donna Brazile, who is inexplicably still the current chair of the DNC, claimed the emails were falsified: https://youtu.be/P_WHsr07cbY?t=458

And if someone wasn't aware emails are DKIM verified for authenticity.

Re: Technical report on DNC hack [pdf]

#68
post #58

Earlier quoted context omitted.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

Cheney literally made up an intelligence agency to tell him what he wanted, after the CIA said there was no evidence of WMD. If you blame the CIA for that, you very mistaken.

Do you mean the https://en.wikipedia.org/wiki/Office_of_Special_Plans ?

Re: Technical report on DNC hack [pdf]

#69
Great. Password expiration.

Cue everyone recycling a set of 10 unique passwords among devices and/or writing passwords on Post-It notes on work computers at the office.

Only bit of truth in here was the phishing campaign. That could be anyone, however. This is barely more advanced than the Nigerian bank scam e-mails.

Yet the POTUS says it's a sign of the highest levels of Russian government.

We've already been fed lies about e-mails being altered (DKIM signatures disprove this) and now this PDF ignores the insider element in the DNC/Wasserman-Schultz leaks.

What a joke. NIST, NSA, FBI, CIA et alia should be discredited almost entirely at this point.

Re: Technical report on DNC hack [pdf]

#70
Great. Password expiration.

Cue everyone recycling a set of 10 unique passwords among devices and/or writing passwords on Post-It notes on work computers at the office.

Only bit of truth in here was the phishing campaign. That could be anyone, however. This is barely more advanced than the Nigerian bank scam e-mails.

Yet the POTUS says it's a sign of the highest levels of Russian government.

We've already been fed lies about e-mails being altered (DKIM signatures disprove this) and now this PDF ignores the insider element in the DNC/Wasserman-Schultz leaks.

What a joke. NIST, NSA, FBI, CIA et alia should be discredited almost entirely at this point.

Post reply on HN