Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

91–100 of 502 posts

Re: Technical report on DNC hack [pdf]

#91
post #82
post #77

Earlier quoted context omitted.

If you rephrase your hysterical wording as "major bipartisan concern across every intelligence agency and nearly all ranking members of both houses of Congress, including the heads of both Intelligence Committees," then I'm not really sure what more evidence you or I could hope for from such an obviously sensitive, active topic for the time being.

Was it any different with Iraq WMD?

Yes. Many, many parts of the intelligence community produced reports contradicting any claims of WMD evidence, and were summarily ignored by a very not-bipartisan administration. There is basically total consensus among every intelligence agency that the evidence points to Russia.

Re: Technical report on DNC hack [pdf]

#92
post #78

Great. Password expiration. Cue everyone recycling a set of 10 unique passwords among devices and/or writing passwords on Post-It notes on work computers at the office. Only bit of truth in here was the phishing campaign. That could be anyone, however. This is barely more advanced than the Nigerian bank scam e-mails. Yet the POTUS says it's a sign of the highest levels of Russian government. We've already been fed li…

If I recally correctly, NIST recently issued guidelines specifically against password expiration/recycling and against forced limits on what characters you can have in your password.

Yep. All the more infuriating. They know better.

NGOs, private industry and the US government at most levels there has been a movement away from password length limits and password expiration and SMS as a second factor. (Even OTP and hashes may be replaced by U2F keys someday.)

Then we get this recommendation for password expirations.

Two steps forward, one back -- as always.

Re: Technical report on DNC hack [pdf]

#93

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

The entire thing has been a politicized distraction and propaganda campaign ... the level of discourse in America is now at a terrifying and dangerous quality; we used to mock the propaganda of the Soviets, China, etc. but we are descending into their grade.

I spy with my little eye....a trump supporter

Re: Technical report on DNC hack [pdf]

#94
post #16

~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|grep -f exits -c 191 ~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|wc -l 876 At least 191 of the IOC IPs are (probably random) Tor exit nodes :) The actual number may very well be higher, I just grabbed current exit node list from https://check.torproject.org/exit-addresses Here's the PHP backdoor the YARA rule…

Wow, this should be the top comment.

[deleted]

Re: Technical report on DNC hack [pdf]

#95
post #89

Even if Wikileaks never published anything, She would have still lost. She had the greatest help, money and collusion from government, media, international community elites and her party and still lost against the most unpopular and unfit candidate of all time who got more than 300 electoral votes. That's how loser and corrupt she is. Just get over it.

That is unfortunately something we will never get to know. Trump's election is tainted by both the Russian DNC hack and the FBI letter released immediately before the election. It is impossible to know what would have happened without these two events

Re: Technical report on DNC hack [pdf]

#96

Earlier quoted context omitted.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

Why trust them in the first place, look at the evidence and if you disagree with a conclusion, be able to say why. This is the whole problem we're dealing with right now - people just decide they do or do not trust something. Don't agree with a fact check? Just call it bogus and move on, even though it might be a 50 point case they make why bother finding a flaw in their reasoning and using that to refute their concl…

> Why trust them in the first place, look at the evidence and if you disagree with a conclusion, be able to say why.

They never even claim that the evidence they show would lead to the conclusions they assert. What they claim is that there's other information that they can't tell you that would lead to their conclusions, and then they release documents like this so interests who have an interest in supporting their conclusions have something to cite.

They're explicitly asking you to trust them, and offering no evidence.

When climate change scientists who operate within an opaque government agency start telling me that the evidence for climate change is too secret for me to see, I'll become a climate change skeptic, too.

Re: Technical report on DNC hack [pdf]

#97
post #80

Earlier quoted context omitted.

The entire thing has been a politicized distraction and propaganda campaign ... the level of discourse in America is now at a terrifying and dangerous quality; we used to mock the propaganda of the Soviets, China, etc. but we are descending into their grade.

State-sponsored actions intended to undermine the basis of our political institutions is a "distraction"? What qualifies as "news" by your standards?

If you believe this proves that claim I have some WMD's in Iraq to sell you.

Re: Technical report on DNC hack [pdf]

#98
post #89

Even if Wikileaks never published anything, She would have still lost. She had the greatest help, money and collusion from government, media, international community elites and her party and still lost against the most unpopular and unfit candidate of all time who got more than 300 electoral votes. That's how loser and corrupt she is. Just get over it.

This stopped being about Hilary Clinton over a month ago. This is extremely important regardless of who is President.

Re: Technical report on DNC hack [pdf]

#99
post #90

Earlier quoted context omitted.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

I'm an ex Army bomb technician, let me help you. You know WMDs were found in Iraq right? ..Unless we're not calling stockpiled chemical weapons WMDs anymore. http://www.nytimes.com/interactive/2014/10/14/world/middleea...

This does not increase my confidence or trust in abstract assurances from intelligence agencies.

> In five of six incidents in which troops were wounded by chemical agents, the munitions appeared to have been designed in the United States, manufactured in Europe and filled in chemical agent production lines built in Iraq by Western companies.

Re: Technical report on DNC hack [pdf]

#100
post #81

tl;dr - "ultra advanced cyber persistent cyber threat cyber actors" are sending phishing emails and people are still clicking on them.

Not just clicking on them. They are entering their details.

I can excuse (sort of) clicking on infected files. Honestly, how many of us are checking unsigned e-mails' headers in the source code? At the very least we should confirm if the displayed From and Reply-to match the originating server.

But we usually don't. And we may be on webmail(!) on someone else's computer. That PDF could have malicious software.

*

Clicking on a suspicious link is one thing. Doing something on that linked site is worse. (instead of re-typing the URL -- I hate internationalized URL domains for making this hard.)

Not checking the URL or even looking for the green padlock or using common sense and then typing in your password??? No excuse.

Would a bank ever send you a postcard asking you write down your PIN and bank balance on the postcard and send it back to them? No. Of course not. For starters, they don't need that information.

Clicking on phishing links and entering personal information is stupidity on a whole new level.

Post reply on HN