Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

181–190 of 502 posts

Re: Technical report on DNC hack [pdf]

#181

Earlier quoted context omitted.

> By the way iOS is the only popular operating system I know that doesn't allow to execute files downloaded from web or emails. Windows 8, 8.1, and 10 don't allow it either. SmartScreen will block unsigned executables by default[0]. Enterprise customers should be using AppLocker which does a lot of what SmartScreen does, but with more flexibility and control. The issue arises when [bad] System Administrators disable…

"If Microsoft forced either SmartScreen OR AppLocker" Meh, just add a button or clickable link that allows the sysadmin to swiftly disable such warnings. Just make sure to put a scary-enough disclaimer that doing so can expose you to very bad, malicious stuff, from ill-intentioned people. It might get more application publishers to implement signing, just as Vista and 7 got rid of the "run everything as administrator…

I think there should be a separate UI for installing or running a downloaded program (with a huge red warning) so the users cannot accidentally run anything.

Re: Technical report on DNC hack [pdf]

#182

Earlier quoted context omitted.

The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.

Could you elaborate? Once you have a password shouldn't it be as easy as just downloading all the emails? Any email client should have the functionality built in. edit: seeing some reports they used "sophisticated" SQL injection... okay...I mean for a lay person it seems sophisticated, sure. But for anyone in the industry it's one of the oldest and easiest tricks in the book. I really suspect news sources are knowing…

You can read about the backdoors they used here:

https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...

The summary: One used Powershell modules and Windows Scheduler to run scripts. Another used a combination of Twitter and public sites like Github/Dropbox for command and control.

In my opinion, neither is impressively sophisticated, and a skilled application developer could whip up something similar in a week or two. Using popular sites like Twitter/Dropbox for C&C has been common for years, and you can purchase similar backdoors/RATs for less than $100.

edit: Another interesting point from the link above: the two exploits stole exactly the same info once inside the DNC network. This would obviously be a big no-no for a sophisticated state actor as it doubles your chance of being compromised, but the author explains it away by claiming that Russia's intelligence agencies are disorganized and adversarial.

Re: Technical report on DNC hack [pdf]

#183

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

This report merely points the finger at Russia; it does not purport to substantiate that allegation.

   Previous JARs have not attributed malicious cyber activity to specific 
   countries or threat actors. However, public attribution of these activities 
   to RIS is supported by technical indicators from the U.S. Intelligence 
   Community, DHS, FBI, the private sector, and other entities.
The report then discusses when the attackers did and mitigation strategies.

Re: Technical report on DNC hack [pdf]

#184
post #161

Earlier quoted context omitted.

The RNC was hacked as well, although they similarly circumvented the same security procedures.

That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...

Belief in this will likely depend on who someone trusts more, spokespersons for the RNC, or the New York Times and the Washington Post.

Re: Technical report on DNC hack [pdf]

#185
post #161

Earlier quoted context omitted.

The RNC was hacked as well, although they similarly circumvented the same security procedures.

That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...

[deleted]

Re: Technical report on DNC hack [pdf]

#186
post #179

Earlier quoted context omitted.

> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.

Can confirm. I did tech at the DNC in 2012. We pushed to get senior staff using 2FA and ran internal phishing drills. Obviously didn't take.

That's super annoying. The 100 person startup I'm at uses 2 factor authentication! It's so easy these days there is no technical excuse anymore.

Re: Technical report on DNC hack [pdf]

#188

Earlier quoted context omitted.

It's rather naive to think these things didn't have an effect. The problem isn't the truth of the claims, it's that the illicitly gained information was strategically released to disrupt one specific campaign, effectively destabilizing our election. Much like Comey's last minute email announcement revealed nothing new, yet allowed the email narrative to renew its currency in the last days of the campaign. Imagine if…

> Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. The NYT did publish Trump's stolen tax return, and were quite self-congratulatory about having done so... > Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. ...and, the stories about the hacked material were outnumbered probably 100-1 by the simultan…

re: two-party consent, IANAL but there seems to be exceptions where if the parties don't have a reasonable expectation of privacy, consent is not needed. For example, somebody recording you giving a public speech does not need your permission -- the public can go hear you speak with or without the recording.

Since Trump was mic'd up on the bus (they were going to film a segment), I think there is a case to be made that he couldn't realistically make the case he didn't know he was being recorded or could be recorded. I think it'd be a hard sell that this was an illegally recorded conversation.

Re: Technical report on DNC hack [pdf]

#189

It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email. Edit: changed "zero claims" to "zero credible cl…

In terms of illegally obtained content, the Democrats had no problem claiming higher ethical ground in releasing a tapped cell phone conversation of Newt Gingrich http://www.daviddfriedman.com/CCP_97/Gingrich%252fMartin%252...

And if you want to focus on foreign (illegal) involvement in U.S. elections, look no further than the alleged Chinese involvement in the 1996 presidential election https://en.wikipedia.org/wiki/1996_United_States_campaign_fi...

My point being, this is almost entirely political. It changes no ones mind.

Re: Technical report on DNC hack [pdf]

#190
post #183

Earlier quoted context omitted.

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

This report merely points the finger at Russia; it does not purport to substantiate that allegation. Previous JARs have not attributed malicious cyber activity to specific countries or threat actors. However, public attribution of these activities to RIS is supported by technical indicators from the U.S. Intelligence Community, DHS, FBI, the private sector, and other entities. The report then discusses when the attac…

>This report merely points the finger at Russia; it does not purport to substantiate that allegation.

That's the point, its just another completely baseless, unsubstantiated accusation. This report contains nothing that suggests that the Russians were any more likely to be the source of the hack then countless other entities. The problem is that these baseless claims are being presented as evidence and being consumed uncritically as such. Take for example the headline in PcMag:

>Hacking Evidence in Hand, Obama Sanctions Russia

http://www.pcmag.com/news/350675/hacking-evidence-in-hand-ob...

Post reply on HN