Earlier quoted context omitted.
It's rather naive to think these things didn't have an effect. The problem isn't the truth of the claims, it's that the illicitly gained information was strategically released to disrupt one specific campaign, effectively destabilizing our election. Much like Comey's last minute email announcement revealed nothing new, yet allowed the email narrative to renew its currency in the last days of the campaign. Imagine if…
The 10 year old tape of Trump making crude sexual comments was leaked obviously to disrupt Trump's campaign. A lot of people believed it would destroy his chances. Unflattering leaks are part and parcel of Presidential campaigns, on both sides. It's why candidates get "vetted", meaning digging up as much dirt as possible in advance to see if it can be dealt with or if it disqualifies the candidate.
Technical report on DNC hack [pdf]
291–300 of 502 posts
Re: Technical report on DNC hack [pdf]
#292Earlier quoted context omitted.
Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Sure, HDD firmware hacks are cool, but in terms of R&D time far less efficient if you're willing to spam attempts to get in the front door. And I'd say they chose the appropriate level of sophistication given the success of the penetration. The DNC isn't exactly an air-gapped Irania…
Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Then how is this evidence of a 'state-sponsored actor'? And how did the narrative of this story ever get derailed from what it should have been, which was, "The DNC, and John Podesta in particular who had both his gmail and his Twitter accounts hacked, are incompetent", to "this is…
The news is why that particular person was targeted.
Re: Technical report on DNC hack [pdf]
#293Earlier quoted context omitted.
Exactly, why burn zero-days when you're targeting a technologically unsophisticated adversary with a huge organizational attack surface? Then how is this evidence of a 'state-sponsored actor'? And how did the narrative of this story ever get derailed from what it should have been, which was, "The DNC, and John Podesta in particular who had both his gmail and his Twitter accounts hacked, are incompetent", to "this is…
There are a lot of people who would benefit from the latter conclusion and not a lot of people who would benefit from the former.
There are many Republicans.
Re: Technical report on DNC hack [pdf]
#294Re: Technical report on DNC hack [pdf]
#295Earlier quoted context omitted.
The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.
The actual evidence is probably closer to 'we have moles in the kremlin and taps on their phones' but they're not exactly going to publish that are they.
Re: Technical report on DNC hack [pdf]
#296Earlier quoted context omitted.
Who else could have forced the DNC to rig the primaries? It's very clear from the collusion between CNN and the Hillary campaign that state level actors were involved.
Please don't spread fake news about primary rigging, even if tongue-in-cheek. Stick to discussing the article.
Re: Technical report on DNC hack [pdf]
#297Earlier quoted context omitted.
> TIL I'm as good as a state level intelligence team. Not to totally ignore the pithiness, but I feel like your comment touches on something I see a ton here (and elsewhere): an offhand dismissal of the 'state level' intelligence capacity. At the end of the day, the systems were exploited. That more sophisticated methods went unused should be a measure of efficiency and not necessarily execution. Why break out the tr…
True. But the absence of sophistication constitutes evidence neither in favor nor against the "State Actor" hypothesis.
Re: Technical report on DNC hack [pdf]
#298Earlier quoted context omitted.
This (complaining about the lack of evidence) just seems ludicrous to me. Does the FBI have a history of declassifying stuff like this so that randos on the internet can independently verify its conclusions? When high-level intelligence people collude to lie to the American people and discredit a president, do they usually do it via press release clearly written by a PIO? The accusation that people who find this cred…
Except that this is a sort of exclusion of the middle; you say " here's the alternative theory ", but there are other even more likely possibilities. Here's one: 1. The DNC and their members are generally ignorant of good security policy and had an easily hacked system. 2. Some Russian intelligence agency hacked the DNC's email servers. 3. A bunch of other people/hackers/groups hacked the DNC's email servers, as it w…
Whether someone else also hacked the DNC would be interesting to know, but it doesn't really impinge on the question of whether there is or is not a vast-but-also-ham-handed-and-kind-of-contradictory conspiracy pushing theory a.
Re: Technical report on DNC hack [pdf]
#299Earlier quoted context omitted.
There are a lot of people who would benefit from the latter conclusion and not a lot of people who would benefit from the former.
> not a lot of people There are many Republicans.
Re: Technical report on DNC hack [pdf]
#300Earlier quoted context omitted.
The report just didn't get into that much detail but they did say: "the code delivers Remote Access Tools (RATs) and evades detection using a range of techniques." A "range of techniques" includes things like rootkits. >No rootkits, The attackers did use stealthy persistence techniques often called 'rootkits". "the SeaDaddy implant developed in Python and compiled with py2exe and another Powershell backdoor with pers…
Can't one just buy a RAT? Also, the WMI think they describe doesn't look like rootkit, more like cron analogue for Windows. I.e. on Unix it would be like installing a command inside crontab. That's not what is usually called a rootkit - a tool that is designed to conceals its presence (and other tools presence) from regular OS tools.
For example the RAT named X-Agent was one of several used in the DNC hack. It has never been put up for sale and it was used in previous Russian intelligence operations (for example tracking Ukraine artillery[0]).
>That's not what is usually called a rootkit
It doesn't appear that anyone has reverse engineered the PC version of X-Agent but the android variant (which may be very different from the one used in the DNC hack) does take some steps to hide itself. Granted nothing suggests anything like kernel syscall hooking but those sorts of rootkit techniques are overrated because they leave obvious and detectable patterns of compromise.
[0]: https://blog.trendmicro.com/trendlabs-security-intelligence/...