Technical report on DNC hack [pdf]
231–240 of 502 posts
Re: Technical report on DNC hack [pdf]
#232Re: Technical report on DNC hack [pdf]
#233Earlier quoted context omitted.
> Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. The NYT did publish Trump's stolen tax return, and were quite self-congratulatory about having done so... > Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. ...and, the stories about the hacked material were outnumbered probably 100-1 by the simultan…
re: two-party consent, IANAL but there seems to be exceptions where if the parties don't have a reasonable expectation of privacy, consent is not needed. For example, somebody recording you giving a public speech does not need your permission -- the public can go hear you speak with or without the recording. Since Trump was mic'd up on the bus (they were going to film a segment), I think there is a case to be made th…
In any case, it's only a question of how many laws were broken in the process of its being obtained by media outlets, not whether the law was broken.
Re: Technical report on DNC hack [pdf]
#234Re: Technical report on DNC hack [pdf]
#235Jeez people, read the report, it isn't any kind of justification of anything, its just a fairly generic don't do this, like I see 100 times a week at work. The real details were likely shown to congress and the senate (or at least a portion of it). Those are the only people who can say if the actual attack was real or imagined. Do you think the British and Americans were going to publish stories about Enigma back in…
IMO it's crazy not to question at least their competence if not also their motive.
Re: Technical report on DNC hack [pdf]
#236Earlier quoted context omitted.
> I've heard exactly zero claims that the leaked emails were falsified in any way. Podesta and high-ranking Dems have leveled this very charge. The extent of the DKIM signatures all being true makes this very unlikely. RSA1024 and SHA-1 can be beaten, but not easily and not in this volume. It is not E2E from the people authoring the e-mails, so the server maintainer (often Google) could be forging and signing e-mails…
I suppose I should have said that I have heard no credible claims that they were falsified. Most of the denials I've heard were of the "I don't recognize that" variety, which literally means nothing.
http://www.dailymail.co.uk/news/article-3835460/Now-Podesta-...
if the emails are fake, how could a password from the emails dump be used to login into his twitter page.
Re: Technical report on DNC hack [pdf]
#237Earlier quoted context omitted.
The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.
Could you elaborate? Once you have a password shouldn't it be as easy as just downloading all the emails? Any email client should have the functionality built in. edit: seeing some reports they used "sophisticated" SQL injection... okay...I mean for a lay person it seems sophisticated, sure. But for anyone in the industry it's one of the oldest and easiest tricks in the book. I really suspect news sources are knowing…
Re: Technical report on DNC hack [pdf]
#238I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…
That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.
Re: Technical report on DNC hack [pdf]
#239Earlier quoted context omitted.
That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.
The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.
Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration.
The DNC isn't exactly an air-gapped Iranian nuclear centrifuge.
Re: Technical report on DNC hack [pdf]
#240Earlier quoted context omitted.
That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...
Belief in this will likely depend on who someone trusts more, spokespersons for the RNC, or the New York Times and the Washington Post.
From the WaPo: "U.S. officials said the Republican National Committee’s computer systems were also probed and possibly penetrated by hackers tied to Russian intelligence services, but that it remains unclear how much material — if any — was taken from the RNC."
There were a number of significant caveats in the NYT and WaPo reporting of this that people have ignored because it confirms their existing assumptions. Probably by design; it lets the papers push their preferred narratives whilst giving them something to fall back on if it turns out not to be true.