Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

231–240 of 502 posts

Re: Technical report on DNC hack [pdf]

#233

Earlier quoted context omitted.

> Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. The NYT did publish Trump's stolen tax return, and were quite self-congratulatory about having done so... > Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. ...and, the stories about the hacked material were outnumbered probably 100-1 by the simultan…

re: two-party consent, IANAL but there seems to be exceptions where if the parties don't have a reasonable expectation of privacy, consent is not needed. For example, somebody recording you giving a public speech does not need your permission -- the public can go hear you speak with or without the recording. Since Trump was mic'd up on the bus (they were going to film a segment), I think there is a case to be made th…

He (and Billy Bush) had a reasonable expectation that he was not being recorded by whichever person was doing the recording.

In any case, it's only a question of how many laws were broken in the process of its being obtained by media outlets, not whether the law was broken.

Re: Technical report on DNC hack [pdf]

#234
It's clear that this is being done to validate their lies about the Russian's hacking. The US-CERT report came out today on this. I understand all this content and it is very limited scope. It does not provide any validation that Russia was involved in any kind of hacking against the US. They described what is probably the most common form of spear-phish hacking, put Russia's name on it, and listed a bunch of other hacking tools which are made by hackers who actually claim to be part of ISIS (probably CIA assets, looks to me like they are trying to false flag this) https://en.wikipedia.org/w/index.php?title=Fancy_Bear&oldid=...

Re: Technical report on DNC hack [pdf]

#235

Jeez people, read the report, it isn't any kind of justification of anything, its just a fairly generic don't do this, like I see 100 times a week at work. The real details were likely shown to congress and the senate (or at least a portion of it). Those are the only people who can say if the actual attack was real or imagined. Do you think the British and Americans were going to publish stories about Enigma back in…

Being cynical about a government that's consistently shown disregard for individual privacy makes us nutty conspiracy theorists?

IMO it's crazy not to question at least their competence if not also their motive.

Re: Technical report on DNC hack [pdf]

#236

Earlier quoted context omitted.

> I've heard exactly zero claims that the leaked emails were falsified in any way. Podesta and high-ranking Dems have leveled this very charge. The extent of the DKIM signatures all being true makes this very unlikely. RSA1024 and SHA-1 can be beaten, but not easily and not in this volume. It is not E2E from the people authoring the e-mails, so the server maintainer (often Google) could be forging and signing e-mails…

I suppose I should have said that I have heard no credible claims that they were falsified. Most of the denials I've heard were of the "I don't recognize that" variety, which literally means nothing.

There was that twitter post from John podesta "i've switched sides hi /pol/" post from his verified twitter page.

http://www.dailymail.co.uk/news/article-3835460/Now-Podesta-...

if the emails are fake, how could a password from the emails dump be used to login into his twitter page.

Re: Technical report on DNC hack [pdf]

#237

Earlier quoted context omitted.

The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.

Could you elaborate? Once you have a password shouldn't it be as easy as just downloading all the emails? Any email client should have the functionality built in. edit: seeing some reports they used "sophisticated" SQL injection... okay...I mean for a lay person it seems sophisticated, sure. But for anyone in the industry it's one of the oldest and easiest tricks in the book. I really suspect news sources are knowing…

RNC got hacked but nothing was leaked.

Re: Technical report on DNC hack [pdf]

#238

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

[deleted]

Re: Technical report on DNC hack [pdf]

#239

Earlier quoted context omitted.

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

The sophistication cited by CrowdStrike was the actions taken on the DNC servers, not the initial penetration.

Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface?

Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration.

The DNC isn't exactly an air-gapped Iranian nuclear centrifuge.

Re: Technical report on DNC hack [pdf]

#240
post #184

Earlier quoted context omitted.

That the RNC was also hacked seems to be a popular, but probably false, meme. http://www.cnn.com/2016/12/10/politics/smerconish-spicer-hac...

Belief in this will likely depend on who someone trusts more, spokespersons for the RNC, or the New York Times and the Washington Post.

From the New York Times article: "One senior government official, who had been briefed on an F.B.I. investigation into the matter, said that while there were attempts to penetrate the Republican committee’s systems, they were not successful."

From the WaPo: "U.S. officials said the Republican National Committee’s computer systems were also probed and possibly penetrated by hackers tied to Russian intelligence services, but that it remains unclear how much material — if any — was taken from the RNC."

There were a number of significant caveats in the NYT and WaPo reporting of this that people have ignored because it confirms their existing assumptions. Probably by design; it lets the papers push their preferred narratives whilst giving them something to fall back on if it turns out not to be true.

Post reply on HN