Live data from Hacker News

Critiques of the DHS and FBI’s Grizzly Steppe Report

robertmlee.org

81–90 of 114 posts

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#81
post #21

So it was just spearfishing, the poor man's hacking technique. The techniques that NSA and MI6 use are far more advanced. Taking advantage of the networking equipment and injecting traffic.

The NSA used spearphishing to compromise the North Korean networks prior to Sony hack. See http://securityaffairs.co/wordpress/32592/intelligence/nsa-c...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#82
post #26

The poor man's hacking technique worked great. Instead of focusing on the tools, focus on the results. I bet you're one of those people who uses microservices to run his 100 visitors/day blog just because it's the shiniest new paradigm.

The results are that someone got into Podesta's gmail for some few days. The pros use methods that allow them to keep long term access and which keep you from knowing that you have been hacked to begin with. Look at the NSA's TAO catalog for examples of how the pros work. You can wipe your servers and still be hacked. I don't seriously believe that the NSA is out there sending phishing emails. They're too busy using…

The NSA spearphished North Korea http://securityaffairs.co/wordpress/32592/intelligence/nsa-c...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#83
post #50

Earlier quoted context omitted.

I agree not rigged, but giving Hillary debate questions in advance comes pretty close. In my opinion, the DNC emails and the Trump "grab 'em" tapes are similar -- you can argue that it's private material that should've stayed that way, but you can't argue that the material didn't reveal helpful truths about the candidates. Finally, a recent poll found 50% of Democrats think that Russia tampered with the vote tallies…

I guess you conveniently forget where Sanders said his emails would have the same sorts of messages from Donna? http://thehill.com/blogs/ballot-box/presidential-races/30386... >"If Bernie Sanders had been the nominee of the party and the Russians hacked my emails instead of John [Podesta]’s, we'd be reading all these notes between Donna and I and they'd say Donna was cozying up to the Bernie campaign. This is taken o…

Both your statements are untrue.

Sanders didn't say that. (Read your link. It's an aid running interference.)

Donna did leak debate questions. Here's an email from Donna Brazile. The subject is "From time to time I get the questions in advance".

https://wikileaks.org/podesta-emails/emailid/43962

The email contains the exact text of the question submitted to a CNN producer in advance of the town-hall by a moderator; it is very similar to the final question that ended up being asked.

http://www.politico.com/blogs/on-media/2016/10/roland-martin...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#84
post #82
post #26

Earlier quoted context omitted.

The results are that someone got into Podesta's gmail for some few days. The pros use methods that allow them to keep long term access and which keep you from knowing that you have been hacked to begin with. Look at the NSA's TAO catalog for examples of how the pros work. You can wipe your servers and still be hacked. I don't seriously believe that the NSA is out there sending phishing emails. They're too busy using…

The NSA spearphished North Korea http://securityaffairs.co/wordpress/32592/intelligence/nsa-c...

That was an email with a malicious attachment that appeared legit which did nothing obvious to compromise the system.

Podesta got an email saying that "someone has your password" and pointing at the IP Address: 134.249.139.239, allegedly in the Ukraine[1].

I can see your point, but one attack is a lot quieter than the other. The usual goal is that they don't know they've been compromised so you retain access over a long period of time, rather than triggering all the alarms.

[1] https://wikileaks.org/podesta-emails/emailid/34899

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#85
post #84
post #82

Earlier quoted context omitted.

The NSA spearphished North Korea http://securityaffairs.co/wordpress/32592/intelligence/nsa-c...

That was an email with a malicious attachment that appeared legit which did nothing obvious to compromise the system. Podesta got an email saying that "someone has your password" and pointing at the IP Address: 134.249.139.239, allegedly in the Ukraine[1]. I can see your point, but one attack is a lot quieter than the other. The usual goal is that they don't know they've been compromised so you retain access over a l…

Sure, there different levels of phishing, depending on the sophistication of the opposition.

The GCHQ attacks on Belgacom[1] had a phishing component, but I suspect most people here would have fallen for them too.

[1] https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#86

Earlier quoted context omitted.

>But can't you see the vast amount of corruption? Every time I see someone write something like this my knee jerk reaction is to either assume they're lying or they are clueless. Can you point to the vast amount of corruption you claim is self evident?

1) Selling ambassdor positions to the donors (check the xlsx file which has higher paying donors getting 'better' countries) 2) Co-ordinating with Super PAC https://twitter.com/wikileaks/status/807308520546848769

1) This doesn't make it right, but it's a common practice for a President to give a percentage of ambassadorships (typically 30%-40%) to donors and friends. Obama, Clinton, and both Bush's all engaged in this practice. It's unusual though to extend this practice to the Cabinet, as Trump has done.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#87
post #83

Earlier quoted context omitted.

I guess you conveniently forget where Sanders said his emails would have the same sorts of messages from Donna? http://thehill.com/blogs/ballot-box/presidential-races/30386... >"If Bernie Sanders had been the nominee of the party and the Russians hacked my emails instead of John [Podesta]’s, we'd be reading all these notes between Donna and I and they'd say Donna was cozying up to the Bernie campaign. This is taken o…

Both your statements are untrue. Sanders didn't say that. (Read your link. It's an aid running interference.) Donna did leak debate questions. Here's an email from Donna Brazile. The subject is "From time to time I get the questions in advance". https://wikileaks.org/podesta-emails/emailid/43962 The email contains the exact text of the question submitted to a CNN producer in advance of the town-hall by a moderator; i…

>Sanders didn't say that. (Read your link. It's an aid running interference.)

Aide representing Sanders. Distinction not relevant at all.

>town-hall by a moderator

The real question is whether Sanders' camp got the same email. The statements made by his aide suggests they did.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#88

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

Sure, you can go ahead and file a FOIA request. But according to the NYT article you linked to, 'the forensic evidence was accompanied by “human and technical” sources in Russia, which appears to mean that the United States’ implants or taps in Russian computer and phone networks helped confirm the country’s role.' [0] CIA will not give you information about its secret agents in the Kremlin just because you ask nicely.

0: http://www.nytimes.com/2016/12/13/us/politics/russia-hack-el...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#89
Seems to me that the DNC had really sloppy security and that many groups could have compromised their servers. If the government has proof that Russian actors did so, they do not appear to have any proof that the info was used maliciously.

The whole report, and media coverage, and statements by public officials are so confused and confusing that they are useless in regards to security.

I have to compare this to the FDA's HIPAA regulations which mostly are just instructions on how to correctly secure servers and applications. However, I wish that HIPAA did not have these regs in it because they are susceptible to falling out of date.

Rather, I think the public would be better served by an official security standard that can be updated weekly with new advice and requirements. Then an org like the FDA can have one regulation covering security that says something like "all systems must be secured according to Federal Infosec Guidelines level B3 or higher". The specifics of what B3 might mean and higher levels of securing servers and apps, can be in a single document that would, I am sure, become a core part of the curriculum for developers and system administrators.

Moaning and whining about water under the bridge is a waste of energy and of public funds. This is a fixable problem if only someone in leadership is willing to act. Not grandstand or apportion blame, but act to improve infosecurity for everyone.

A well drafted set of infosec guidelines by industry experts along with a process for keeping it up to date will have incredible multiplier effects throughout industry as well as government, because it makes it much easier for management to order that things be secured, and it makes it much easier to get a consultant to validate that the guidelines have been correctly implemented.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#90
post #32
post #9

Earlier quoted context omitted.

What was the public interest in his lobster recipe? Or creating a paranoid frenzy that got shots fired at a Pizza place? Randomly dumping personal emails isn't the same as Ellsberg and Snowden working with reporters to blow the whistle on specific transgressions in war and mass surveillance. Interesting article exploring this issue of exercising discretion and developing new ethics in the age of leaks: http://www.nyt…

There's a long list of stuff here: http://www.mostdamagingwikileaks.com/ The press never covered most of it because a lot of the leaks are things that make them look bad. For example, Glenn Thrush: https://wikileaks.org/podesta-emails/emailid/12681 > No worries > Because I have become a hack I will send u the whole section that pertains > to u > Please don't share or tell anyone I did this > Tell me if I fucked up an…

Upvote for link. I had ignored the wikileaks stuff, like I ignored most of the election cycle, because I ignore most current events. But it was time to take a peek to see what everyone got excited about.

I just randomly picked links and citations. Sorry, but I didn't find any there there. (I skipped the secret email server, mostly because I don't care.)

Just one example, in #6 its clear from context that Bill Ivey's use of "we" refers to society as a whole. Further, he's venting about the decline of civic engagement, an opinion shared by many (such as myself).

My primary reaction is "Hate the game, not the players." Politics sucks. All of it. But why is any one surprised by the corruption? This is the system we designed, or at least accepted. If we hate it so much, they we should support publicly financed campaigns, restoring the fairness doctrine, shortening the political cycle, etc, etc. But we don't. Because Freedom Markets™ booyah!

My secondary reaction is "Wow, this InfoWars stuff makes my head hurt." I can never tell if cherry picking quotes out of context and making wild inferences is intentional obfuscation or just how some people process the world.

Any way, thanks for the link.

PS- The spirit worshipping stuff is hysterical.

Post reply on HN