Live data from Hacker News

Email from FBI Looks Odd

old.reddit.com

71–80 of 172 posts

Re: Email from FBI Looks Odd

#71
post #51
post #25

The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain. Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration…

It could be the Russians trying to make the FBI look incompetent and make people trust the government less.

[deleted]

Re: Email from FBI Looks Odd

#72
This Newsweek article has a pretty good breakdown:

"The Federal Bureau of Investigation (FBI) email system had reportedly suffered a hack on Saturday morning amid several reports of messages sent from the agency's email infrastructure purporting to be a warning from the Department of Homeland Security (DHS) about a cyberattack." [1]

"The Spamhaus Project, an international nonprofit organization based in Andorra and Switzerland that tracks spam, reported on Twitter that its analysis had shown the unusual emails are being sent from accounts "scraped" from the American Registry for Internet Numbers (ARIN) database." [1]

"Our telemetry indicates that there were two 'spam' waves, one shortly before 5 AM (UTC) [12.am. E.T.] and another one shortly after 7 AM (UTC) [2a.m. E.T.]. The FBI has been getting many calls about it. We are therefore refraining from further actions against the sending IP addresses." [1]

[1] https://www.newsweek.com/fbi-email-system-reportedly-hacked-...

Re: Email from FBI Looks Odd

#75
post #61

I still don't quite understand hackers: doing such high-profile hacking and writing lame texts even wihout much fact checking (about agency divisions in this case). Being written in more professional way, this attack could be way more effective. Also, is it a thing among "hackers" to write with tons of mistakes? A part of culture maybe? Or to scare the bricks out of people? )

I'd have guessed that it should be possible to get a reasonable amount of $ for selling access to FBI email servers but maybe the person(s) behind the attack don't care much about money.

Re: Email from FBI Looks Odd

#76

Earlier quoted context omitted.

Oh no! Best check under the bed and in the closet for those dang ruskies /s

What's the point of comments like this? Do you honestly not believe that Russia enlists hackers to poke at the seams in the US?

Not the OP, but, well, just as it could've been Russians, it could be North Koreans, Chinese, or anyone else. As a Russian, the comment just seemed unnecessary, though I'm obviously biased.

Re: Email from FBI Looks Odd

#77
post #61

I still don't quite understand hackers: doing such high-profile hacking and writing lame texts even wihout much fact checking (about agency divisions in this case). Being written in more professional way, this attack could be way more effective. Also, is it a thing among "hackers" to write with tons of mistakes? A part of culture maybe? Or to scare the bricks out of people? )

According to the phishing training I was mandated to take at work if you are stupid enough to overlook the mistakes you are the right target. According to them the misspellings filter out the smart enough people they don’t want talking to. But that could also be nonsense.

Yeah, I buy this theory in general, but I'm not sure that's the highest-leverage way to use this access.

Re: Email from FBI Looks Odd

#78
post #61

I still don't quite understand hackers: doing such high-profile hacking and writing lame texts even wihout much fact checking (about agency divisions in this case). Being written in more professional way, this attack could be way more effective. Also, is it a thing among "hackers" to write with tons of mistakes? A part of culture maybe? Or to scare the bricks out of people? )

I'm guessing they are either testing their approach or doing it just for fun without a real objective.

Re: Email from FBI Looks Odd

#80
post #25

The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain. Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration…

Awesome. A guide written in 2019 from the FBI that suggests Internet Explorer.

I would assume they're recommending Edge now. We switched from IE to Edge around that time; and our company is very security conscious because of our clients.
Post reply on HN