Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

281–290 of 502 posts

Re: Technical report on DNC hack [pdf]

#281

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

Journalists routinely do that - underline that whatever malfeasance is done, the perpetrator is not a usual random criminal but especially heinous one and thus this story is worth your attention.

With computer crime it's especially obvious because most journalists don't know enough to understand what's hard and what's not, so they take the word of law enforcement, and law enforcement has big motivation to make it sound as bad as possible, since it enhances their significance and their success for catching one. "I've caught a sophisticated hacker" sounds better than "I've found a 13-year old kid that sent someone an email saying 'give me your password' and the poor shmoe was silly enough to do just that".

So there won't be a lot of reports about catching unsophisticated hackers. Usually it's always "highly sophisticated" ones.

OTOH, I think the actual (claimed) proof was using of certain bit.ly account etc. not sophistication per se.

Also, it looks like there were at least 3 attacks on the DNC, and phishing was only involved in one. Maybe the whitepapers talked about the other ones.

Re: Technical report on DNC hack [pdf]

#282
post #91
post #82

Earlier quoted context omitted.

Was it any different with Iraq WMD?

Yes. Many, many parts of the intelligence community produced reports contradicting any claims of WMD evidence, and were summarily ignored by a very not-bipartisan administration. There is basically total consensus among every intelligence agency that the evidence points to Russia.

Basic sources on the total consensus?

Re: Technical report on DNC hack [pdf]

#283
post #245

Earlier quoted context omitted.

I have personally written that exact tool while learning Python. A RAT using Twitter for C & C. Uses PGP for encryption and verification. The twitter handles for the C & C change based on a hash of Googles lastest Doodle so you can access it without fear of account deletion. TIL I'm as good as a state level intelligence team. Hey CIA/NSA we know you are reading this, my contact info is in my profile. Hire me.

> TIL I'm as good as a state level intelligence team. Not to totally ignore the pithiness, but I feel like your comment touches on something I see a ton here (and elsewhere): an offhand dismissal of the 'state level' intelligence capacity. At the end of the day, the systems were exploited. That more sophisticated methods went unused should be a measure of efficiency and not necessarily execution. Why break out the tr…

>hat more sophisticated methods went unused should be a measure of efficiency and not necessarily execution. Why break out the trick play if your opponent can't keep from you running it up the middle?

I question how efficient it is to get caught red handed in the cookie jar of the worlds only super power.

Sure Vladimir Putin could invite President Obama to a state dinner and then proceed to blow his head off with an AK-47 but that would lack the subterfuge I expect from "state level actors". If this is indeed the Russians, they are as laughably incompetent as our elected officials in regards to infosec and thus a threat to no one.

Re: Technical report on DNC hack [pdf]

#284
post #239

Earlier quoted context omitted.

Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration. The DNC isn't exactly an air-gapped Irania…

Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Then how is this evidence of a 'state-sponsored actor'? And how did the narrative of this story ever get derailed from what it should have been, which was, "The DNC, and John Podesta in particular who had both his gmail and his Twitter accounts hacked, are incompetent", to "this is…

There are a lot of people who would benefit from the latter conclusion and not a lot of people who would benefit from the former.

Re: Technical report on DNC hack [pdf]

#285
post #246
post #243

Earlier quoted context omitted.

Wasn't the NSA spying on the whole Internet or something? Are you telling me the NSA saw no evidence of Russia hacking the DNC servers? They wouldn't necessarily have to reveal their "methods" that it was the Russians if it was the NSA catching them and not some Kremlin CIA spy. But who knows, maybe they are too busy spying on hundreds of millions of Regular Joes to watch out for all of the Russian attacks.

Haven't the NSA already said they believe it was the Russians? As you suggest, they would be the ones to know.

The NSA doesn't, in general, publicly announce anything. They exist to supply analysis to other branches of government, and only very rarely to the public directly. So the absence of commentary from them in public doesn't indicate that they haven't drawn conclusions and passed them along.

Re: Technical report on DNC hack [pdf]

#286
post #276
post #255

Earlier quoted context omitted.

The FBI has a history of political activism, to put it lightly. Here's a fun one: https://en.m.wikipedia.org/wiki/FBI–King_suicide_letter You're being foolish if you trust a word the FBI says without solid evidence.

Seriously. Clapper lied directly to congress under oath on TV. The whole "they know whats best for us and our only choice is blind faith" attitude is really disturbing.

> The whole "they know whats best for us and our only choice is blind faith" attitude is really disturbing.

This is so, so insulting. There is no way a fair observer could read the comments here and conclude that the people who find Russia hacking the DNC credible do so because they have blind faith in Clapper or the FBI or anyone else.

Re: Technical report on DNC hack [pdf]

#287
post #244

Earlier quoted context omitted.

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

This (complaining about the lack of evidence) just seems ludicrous to me. Does the FBI have a history of declassifying stuff like this so that randos on the internet can independently verify its conclusions? When high-level intelligence people collude to lie to the American people and discredit a president, do they usually do it via press release clearly written by a PIO? The accusation that people who find this cred…

Except that this is a sort of exclusion of the middle; you say "here's the alternative theory", but there are other even more likely possibilities. Here's one:

1. The DNC and their members are generally ignorant of good security policy and had an easily hacked system.

2. Some Russian intelligence agency hacked the DNC's email servers.

3. A bunch of other people/hackers/groups hacked the DNC's email servers, as it was "left out in the open", so to speak, and was a trivial target..

4. One group at least used trivial methods to do so and left behind evidence.

5. The FBI/NSA//DHS/etc found that evidence.

6. One of these hackers passed information to WikiLeaks. WikiLeaks has denied that it was Russians who did this.

7. The FBI/CIA claim that the Russians hacked the DNC servers.

8. The press and political opportunists jump to the conclusion that it was the Russians who released this information to Wikileaks.

9. The FBI/CIA classified what they found and aren't going to put it in a press release.

Re: Technical report on DNC hack [pdf]

#288
post #49

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

> No one is denying that the emails are real. Actually, Donna Brazile, who is inexplicably still the current chair of the DNC, claimed the emails were falsified: https://youtu.be/P_WHsr07cbY?t=458

She's lying.

Re: Technical report on DNC hack [pdf]

#289
post #47
post #41

Earlier quoted context omitted.

Then why did the report attribute any of this to Russia without substantiating those claims? It's one thing to detail mitigations, it's another to call out Russia as the perpetrator without adding contextual value - the majority of the addresses involved aren't Russian.

Did they really need to say, "We also have other data about the attack that we're not publishing because it's classified"? Isn't that kind of safe to assume?

From the downvotes, I guess the FBI doesn't typically keep information to itself, it just releases it on principle. How nice of them!

Re: Technical report on DNC hack [pdf]

#290

Earlier quoted context omitted.

> Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. The NYT did publish Trump's stolen tax return, and were quite self-congratulatory about having done so... > Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. ...and, the stories about the hacked material were outnumbered probably 100-1 by the simultan…

There is no evidence that the NYT stole Trump's tax returns. His ex-wife had copies of those documents and it's widely suspected that she was the one to leak them.

> There is no evidence that the NYT stole[1] Trump's tax returns. His ex-wife had copies of those documents and it's widely suspected that she was the one to leak them.

There's no evidence[2] that Russia hacked the DNC. It's "widely suspected" that murdered DNC staffer Seth Rich leaked the emails.[3]

Even if Marla Maples herself provided the returns to the NYT (and the NYT claims they were sent from Trump Tower), I strongly suspect it would've been in that case a violation of their divorce settlement.[4]

[1] Obviously the NYT themselves didn't steal Trump's tax returns, but their source almost certainly did.

[2] That we've seen.

[3] That theory is IMO ridiculous; my point is that it's also evidence-free speculation.

[4] If it were Marla, and it didn't violate the divorce settlement, why the anonymity?

Post reply on HN