Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

441–450 of 502 posts

Re: Technical report on DNC hack [pdf]

#441
post #2

>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…

Earlier news reports said they came to that conclusion by comparing the RAT artifacts on the compromised machines. ETA : Also, the bit.ly URLs used in the phishing attacks indicated sharing of resources with other APT28 hacks. http://motherboard.vice.com/read/how-hackers-broke-into-john...

It's not the bit.ly URLs, but allegedly the domain they pointed to, though they don't show us any other links to it.

For reference, this is the Podesta phishing email: https://wikileaks.org/podesta-emails/emailid/34899

And this is the stats page for the bit.ly link in that email: https://bitly.com/1PibSU0+

Re: Technical report on DNC hack [pdf]

#442

Nothing about this supports a Russian attribution.

What would you expect as a proof?

Look at the NSA's TAO tools for the kind of thing I expect from a nation state.

They're using backdoored hardware & TEMPEST, not pitiful phishing scams.

Re: Technical report on DNC hack [pdf]

#443

Earlier quoted context omitted.

It appears to confirm what we knew: the DNC's failure to adhere to basic security protocols, which would be enforced in any corporation with more than a couple dozen employees (edit: or not, see eropple's comment below), allowed its systems to be compromised by script kiddies (for political reasons, the USG insists these script kiddies are sponsored by the Russian government, and insists we take them at their word).…

While the methods used were very simple, I have an opinion why this could be done for some government or political party. The emails and data from a political party are probably very boring stuff, so a typical hacker would not bother to spend a lot of time sending thousands of phishing emails to get access to them. And later he would have to read through them to find some facts the mass media would be interested in.…

Hackers have been targeting boring government docs for as long as there's been hacking, sometimes just for laughs, bragging rights, etc.

If all the docs are boring, isn't that all the more reason to think that a nation state had nothing to do with this?

The NSA would've intercepted your new router in the mail with a backdoor and could've used a TEMPEST van to read your screens from miles away. I have to believe those mighty Russian hackers have figured out comparable tricks by now and aren't reliant on people falling for idiotic phishing scams to get their information.

I mean, they have Snowden, who showed us the NSA's TAO programs... right?

Re: Technical report on DNC hack [pdf]

#444

Earlier quoted context omitted.

You can buy RATs. The several RATs used in this campaign were never for sale. For example the RAT named X-Agent was one of several used in the DNC hack. It has never been put up for sale and it was used in previous Russian intelligence operations (for example tracking Ukraine artillery[0]). >That's not what is usually called a rootkit It doesn't appear that anyone has reverse engineered the PC version of X-Agent but…

So essentially someone hacked the DNC, and it's "advanced" because some custom software was written just for this particular target ? I've written custom software (which was a lot harder to find than some python WMI hooks) for hacking a lot lower profile organisations. I've consulted for organisations that were hacked by Chinese hackers for bitcoin ransom that had custom software written too. I mean, high profile tar…

The sophistication is not evidence of government involvement, the lack of sophistication is not evidence that a government was not involved.

Certainly malware which costs serious resources to develop, like stuxnet, says something about the capabilities of the attacker. Given that at the high end of the resource spectrum it is mostly governments, resources required are suggestive of a government, but resources are not conclusive in and of themselves.

The attribution of the DNC hack to APT28 and APT29 was not based on its sophistication but on the similarity to the methods used, tradecraft fingerprints, and the sharing of C&C servers to past attacks.

Re: Technical report on DNC hack [pdf]

#445

Earlier quoted context omitted.

I have no doubt that Hillary Clinton would have won the primary regardless of the DNC "meddling" in the primary, but I do feel that they would have a more unified DNC had there not been news of the DNC backing HRC before the primaries had even finished.

What "meddling" did the DNC do in the primary? How were they were backing her before the primaries finished?

> In a May 2016 email chain, the DNC chief financial officer (CFO) Brad Marshall told the DNC chief executive officer, Amy Dacy, that they should have someone from the media ask Sanders if he is an atheist prior to the West Virginia primary.[46][47]

> high-ranking DNC officials discussed the possibility of making Sanders' religion a campaign issue in southern states

Did they do so? If so, thats clear meddling. If not, its shows intent of meddling.

> Paustenbach suggested that a past incident could be used to promote a "narrative for a story, which is that Bernie never had his act together, that his campaign was a mess."

Again, suggestion to do acts of meddling but not clear if they went through with it.

> Wasserman Schultz resigned as DNC chair after the leak, and was replaced by Donna Brazile and the Democratic National Committee issued an apology to Sanders.[52] Speaking on CNN, Sanders responded to the email leak: "...it is an outrage and sad that you would have people in important positions in the DNC trying to undermine my campaign.

Regardless if the intended meddling happed or not, it is clear that even the party itself know that they were in the wrong.

Re: Technical report on DNC hack [pdf]

#446
post #89

Even if Wikileaks never published anything, She would have still lost. She had the greatest help, money and collusion from government, media, international community elites and her party and still lost against the most unpopular and unfit candidate of all time who got more than 300 electoral votes. That's how loser and corrupt she is. Just get over it.

That is unfortunately something we will never get to know. Trump's election is tainted by both the Russian DNC hack and the FBI letter released immediately before the election. It is impossible to know what would have happened without these two events

We can make about as good guessed about the outcome as if the leaked tapes and anonymous sex allegations never was published.

As a thought experiment, how would US political landscape look like if it was illegal for news paper to publish articles that imply past criminal behavior in candidates during elections? HC would not have the mail server scandal, and trump would not have the sexual assault scandal. Which side would have benefited more?

Re: Technical report on DNC hack [pdf]

#447
post #317

Earlier quoted context omitted.

Er, the parent was replying to a poster who implied he did not believe "point 7." >Frankly, I find the suggestion that telling voters more about their candidate constitutes 'interference' to be repugnant Really? By this argument, I take it you believe political candidates' email (or cough tax returns) should automatically be made public? Much as I agree with transparency, I think we need to recognize that everyone--i…

>Much as I agree with transparency, I think we need to recognize that everyone--including political candidates--has some right to private communications. No, they don't, unless you see the need for them to act against our interests without our knowleddge because markets or something, or see some sort of right for them to rule others.

So you believe that all email communication from all elected officials and candidates should be made public?

What about non-email communication? Face-to-face conversations should all be public? Does this extend to classified briefings? Should, for example, discussions of "Olympic Games" have been public before it was executed?

Re: Technical report on DNC hack [pdf]

#448

Earlier quoted context omitted.

Valid point, but I should clarify my original comment: I don't find either aspect of the attack--the entry or the payload--to be particularly sophisticated. Everything I've read indicates the bulk of work was done by Powershell scripts, along with a backdoor process running in the open. If you told me that the backdoor was a kernel level rootkit or something similar then I could get onboard, but as it stands I don't…

The main arguments might be not technical. The political emails are pretty boring stuff for an outsider so it should be some government or politician bothering to get them. I also remember that some gmail accounts of people from DNC staff were hacked. Gmail probably has logged what IP addresses were used when logging in with stolen passwords and they could be used as a hint too (though most probably they point to che…

nobody except complete amateurs is using its own computer to do hacking. there are thousands if not millions of compromized computers in aws cloud and similar hosting services that in turn work as robot-hackers to compromise other sites. it is like a self building hacking network where each cell works to infect other cells. so atack, if it was any atack (as document does not have any evidence that it was one) was unlikely be runnig from a real IP but from a random AWS instance registered by some junior software developer from India who bought it to deploy a pet project that was hacked without him even knowing this weeks ago before the event.

Re: Technical report on DNC hack [pdf]

#449

Earlier quoted context omitted.

Biased? Yes, the DNC would obviously prefer a Democrat to an independent. Rigged? There was no evidence of any rigging outside of fake news.

Here you're using a common everyday definition of the verb "rig". Observe that this definition excludes e.g. publicizing a political candidate's banal episodes of tawdriness to the scrutiny of voters, so it's not the definition in wide use in USA news media over the last month or so.

I'm using rig in a broad sense. The DNC didn't publicize banal episodes of tawdriness to the scrutiny of voters. If you're talking about the NGP VAN data access, that hit the news on 12/17/2015 when Michael Briggs (Sanders's communications aide) talked about it to BuzzFeed, and the story blew up on 12/18 when the Sanders campaign filed a lawsuit against the DNC over temporarily shutting down their access to the system until they could show that they had deleted any copies they might have had of the Clinton campaign's data.

Re: Technical report on DNC hack [pdf]

#450
post #373

Earlier quoted context omitted.

> There is no way any a fair observer could read the comments here and conclude that the people who find Russia hacking the DNC credible do so because they have blind faith in Clapper or the FBI or anyone else. Isn't that what you were more or less saying here: https://news.ycombinator.com/item?id=13281736

No. I believe the official version (that the reason the intelligence agencies are accusing Russia of hacking the DNC is because believe it did) because the alternative is less plausible and there's no evidence for it. That's pure Occam's Razor, no faith involved. The FBI has lied and will lie again, getting me to believe they lied about something is not hard, but they don't generally do it in big, obvious ways that a…

That's not how Occam's razor works. You don't pick the most likely single outcome and then just assume that to be true with 100% confidence. Occam's razor is just an informal statement of the fact that you should assign a higher a priori probability to simpler hypotheses. It doesn't mean you should ignore any marginally less likely hypothesis.
Post reply on HN