Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.
You're ignoring the political context in which it was released. 1. Released the same day as the announcement of formal Russian Sanctions 2. Released the same day US made 35 "diplomats" (aka. known Human Intelligence Officers) Persona Non Grata. Which is a big deal. This type of document is not intended to "make the case" because we don't do that. Making a case for something by definition, would reveal sources and met…
Technical report on DNC hack [pdf]
101–110 of 502 posts
Re: Technical report on DNC hack [pdf]
#102Earlier quoted context omitted.
You clearly don't understand the intelligence process if this is your critique. First, the people making the DNC hack report are not the same as the analysts who worked on Iraq. The IC is not a monolith. Second, the Bush White House saw the intelligence they wanted to see. Third, burning sources and methods is a very real concern in intelligence gathering. That reality can't be ignored no matter how much you want inf…
>Second, the Bush White House saw the intelligence they wanted to see. And the Obama administration is not doing the exact same thing here? I'm sorry but a py2exe agent dropped from phishing, some random IP addresses, and some publicly known persistence techniques do not an APT make. This is horse shit
The latter part of my comment was meant to provide some context as to why that type of information hasn't been publicly released. If the IC reveals sources and methods, Russia or similar actors will change their behaviors in order to avoid detection/attribution.
Re: Technical report on DNC hack [pdf]
#103Earlier quoted context omitted.
The bloomberg article I read ( http://archive.is/j5wRd ) presented it as evidence. Maybe other publications are doing the same. >As part of the administration’s response, the FBI and Homeland Security Department also released a report with technical evidence intended to prove Russia’s military and civilian intelligence services were behind the hacking and to expose some of their most sensitive hacking infrastructure.
The "evidence" cited is not the handful of unclassified details included, it's the fact that the FBI and DHS are willing to go on record publicly accusing Russia. There are no asterisks or weasel-words or "allegedly"s. Just a clear "Russia did it." There are only two possible explanations for that: 1) A massive conspiracy in which the leaders of practically the entirety of the US military/intelligence community are w…
If they had damning evidence it'd be in their interest to release it.
Re: Technical report on DNC hack [pdf]
#104Earlier quoted context omitted.
State-sponsored actions intended to undermine the basis of our political institutions is a "distraction"? What qualifies as "news" by your standards?
If you believe this proves that claim I have some WMD's in Iraq to sell you.
Re: Technical report on DNC hack [pdf]
#105Re: Technical report on DNC hack [pdf]
#106It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email. Edit: changed "zero claims" to "zero credible cl…
> I've heard exactly zero claims that the leaked emails were falsified in any way. Podesta and high-ranking Dems have leveled this very charge. The extent of the DKIM signatures all being true makes this very unlikely. RSA1024 and SHA-1 can be beaten, but not easily and not in this volume. It is not E2E from the people authoring the e-mails, so the server maintainer (often Google) could be forging and signing e-mails…
Re: Technical report on DNC hack [pdf]
#107tl;dr - "ultra advanced cyber persistent cyber threat cyber actors" are sending phishing emails and people are still clicking on them.
Why spend weeks/months searching for 0-days and hoping they will remain viable when you can spin up a fake login page and a bit.ly, find the people to target and send the targeted emails in a couple of days, max?
Re: Technical report on DNC hack [pdf]
#108This is a magic report. Over the next 24 hours, it will transform a huge number of people into experts on intelligence reporting requirements, hacking, sources and methods, and diplomacy.
Plot twist: there was no attack, the RNC and DNC invented it as a way to teach America's political blowhards what spear-phishing is and how to avoid it.
Re: Technical report on DNC hack [pdf]
#109Re: Technical report on DNC hack [pdf]
#110First step to prevent "Russian hackers": Don't make your password "p@ssw0rd" https://wikileaks.org/podesta-emails/emailid/22335
From: Eryn Sepp To: john.podesta@gmail.com
Though CAP is still having issues with my email and computer, yours is good to go.=20
jpodesta
p@ssw0rd
It looks like it was a temporary password assigned by the sys admin (or tech savvy friend).Also, It is not clear how this was hacked since it seems a gmail to gmail communication.