I am under the impression that attribution is a very difficult and often impossible process. If that is true, what is the point of including "Russian" in this headline? I would guess the most probable response would be something involving "fulfilling a narrative." Even if that is true, what makes "Russian" hackers more exciting then just "Hackers?" I am not trying to pose some profound question. I am genuinely confus…
> what makes "Russian" hackers more exciting then just "Hackers?" It's all about what ultimately happens to the information harvested. If it's some kids in mom's basement doing it for lulz, that's not very concerning. But, presumably, Russian hackers, even if not actual Russian government employees, would pass on useful information to their government. Even if non-classified, that could be very damaging to national s…
Russian Hackers Read Obama’s Unclassified Emails, Officials Say
31–40 of 46 posts
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#32I am under the impression that attribution is a very difficult and often impossible process. If that is true, what is the point of including "Russian" in this headline? I would guess the most probable response would be something involving "fulfilling a narrative." Even if that is true, what makes "Russian" hackers more exciting then just "Hackers?" I am not trying to pose some profound question. I am genuinely confus…
Did you ever think the government knows more than it can tell you?
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#33This unfortunate announcement is one of those things lawmakers love to use to justify exploitative and unethical policies.
Let's hope that's not the case
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#34Sounds perfectly alright to me. Remember that there are levels of classification. Unclassified (the lowest level) could be running through Gmail in plain text for all anyone at the White House cares. Anything of even minute importance will get a classification status. (Also, Re: the NSA—they do the government's COMSEC , securing the classified data. OPSEC, the risk/reward policies regarding what data should be classi…
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#35Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#36Just quoting some of the comments on NYTimes: > Am I the ONLY one who has a hard time believing that these hackers ONLY got "unclassified" stuff? Riiiiiiiiight. They just don't want us to know how deeply in these folks got. Why would they just get "unclassified" stuff? > Only unclassified emails. Right. Do people even read articles these days?
I know what you said is a little bit tongue-in-cheek, but as someone running a news startup there are two types of news consumers:
1. People looking to understand what's happening 2. People looking for ammunition to reinforce their already-unstoppable notion as to how the world works.
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#37Somebody on Computerworld said that the State Dept was spearphished, and that POTUS's system was breached from there.
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#38I always wonder how these hackers know which IP range to attack. Is it just like a hit and miss kinda thing? Or do they have insiders who leak those info to them.
If you wanted to figure it out starting with something like whitehouse.gov is a bad place to begin. That's a public facing media engine at best, not really used for "government" per se. In fact, it's likely not even homed on a DoD or GOV network. Many of the media engine type sites in the government are outsourced to third party hosting.
You'd want to find something more specific, like perhaps a protected access web system, like a Sharepoint portal or website, or even a mail relay conveniently pointed out by an MX record. Trace that system back and you likely will find either its reverse proxy, a front end system, or an SMTP entry point. This gives you the parameter subnet (DMZ) that you can probe from there. Then, using available DNS records, you could start mapping out the parameter looking for proxies, mail relays, and web servers. If you had access to web traffic logs you could use them as well to look for egress points from networks. If you had e-mail traffic to look at you'd likely see leaked internal subnets as well in the headers. However, this would only work for services they have blessed for access to the public internet.
It is absolutely no different than how you'd map any other network.
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#39Earlier quoted context omitted.
Fun fact: hackers are never American citizens somehow. It's 'cuz Americans are all model patriots. Obviously.
Well to be fair, America is one of the few countries really really good at catching hackers. So I doubt many citizens ever bother. Case in point: when was the last time you heard Russia/China arresting a hacker?
Re: Russian Hackers Read Obama’s Unclassified Emails, Officials Say
#40Hello, National Security Agency: Preventing this sort of thing is your job. Once you're done snarfing up my personal data, perhaps you could attend to it.
These networks would be under the white house communications agency, a subset of the defense information systems agency which is not affiliated with NSA. Supposedly his blackberry is run through NSA (See, e.g., the fishbowl project), and was not implicated in this breach.
It's not that it's the President's email that's vulnerable. It's that _all_ people's email is vulnerable.
Some of those people are key to national security, many aren't. But they all deserve privacy and protection.
And yes, one of NSA's mandates is to secure U.S. communications:
"The Information Assurance mission confronts the formidable challenge of preventing foreign adversaries from gaining access to sensitive or classified national security information. "
https://www.nsa.gov/about/mission/index.shtml
It's not just the President the NSA are failing.