Live data from Hacker News

Critiques of the DHS and FBI’s Grizzly Steppe Report

robertmlee.org

11–20 of 114 posts

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#11
post #4

> But why is this so bad? Because it does not follow the intent laid out by the White House and confuses readers to think that this report is about attribution and not the intended purpose of helping network defenders. Looking at the comments in yesterdays' thread[1], this is absolutely true - many, many people posted some variation of "What? There's no evidence proving Russian involvement in here at all!" 1. https:/…

That's right, I was one of those confused people. I assumed this would be the WH presenting what evidence they have. Sooo... still no public evidence that Russia leaked the DNC and Podesta's e-mails?

Read the original CloudStrike report. Not the government report but the private security firm report. The government report is really just a restatement of that report. You don't track hackers for a decade to suddenly be wrong because of a governments political stance.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#12
post #3

The white house and the document itself never list attribution as the goal. Robert M Lee seems to think because it refers to the attackers as Russia, it is confusing readers. The summary at the beginning makes it clear to me that the document is presupposing the attacker is Russia as to be consistent with all future public reports. I don't think this is the best written report, but his conjecture around completely le…

I question the importance of attribution on this issue. The Office of Personnel Management hack seems far worse than this report's conclusions, but there was a fraction of the outrage. Sadly, the problem is not confined to one state actor. INFOSEC is systemically broken and although the solution is starring Congress in the face, I suspect software/hardware lobbyists will prevent meaningful legislation.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#13
post #9
post #7

Has Scheiner written anything on this report? I will say this; the Podesta emails revealed a lot about the internal politics of the DNC. Why are we not treating this type of leak with the same level of respect as the Ellsberg leaks? Or for that matter, the Snowden leaks? Who is really controlling the narrative here?

What was the public interest in his lobster recipe? Or creating a paranoid frenzy that got shots fired at a Pizza place? Randomly dumping personal emails isn't the same as Ellsberg and Snowden working with reporters to blow the whistle on specific transgressions in war and mass surveillance. Interesting article exploring this issue of exercising discretion and developing new ethics in the age of leaks: http://www.nyt…

Obviously the pizzagate stuff is stupid and unfounded. It does a great disservice to people that were victims of real sexual abuse.

But can't you see the vast amount of corruption? The DNC rigged the primary for one candidate. We need to hold our political parties accountable for their actions.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#14
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

Agreed. I wrote this on FB last year when people were calling hacks 'cyberwar':

I’m still not sure what to think of the Sony hack. I instantly rejected the idea that it amounted to “cyber war”, but beyond that, I think governments can take a legitimate interest in digital attacks on private companies, same as law enforcement would get involved in a physical attack on a corporate building.

I think the main response to IT breaches has to be “defensive”; secure code and networks. You can’t find and retaliate towards every hacker. And the benefit is that unlike retaliatory policy responses, good network security is designed to protect against all third parties, whether it’s your own government, random financial criminals, James Bond villains, whatever the entity or motive.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#15
post #8
post #3

The white house and the document itself never list attribution as the goal. Robert M Lee seems to think because it refers to the attackers as Russia, it is confusing readers. The summary at the beginning makes it clear to me that the document is presupposing the attacker is Russia as to be consistent with all future public reports. I don't think this is the best written report, but his conjecture around completely le…

The timing of the release of this document, at the same time as the announcement of sanctions on Russia for the hacking, can't be overlooked. It's quite reasonable to assume the release of this report was intended to create the impression of evidence for attribution, even if it actually contains no such thing. Otherwise why not release it on any other day to avoid confusion? It looks to me like the confusion was quit…

It also can be seen as a meaningful signal of attribution capability to certain parties. Think of the form - an official document intended for public consumption - as not really being intended for consumption by the general public.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#16

Earlier quoted context omitted.

That's right, I was one of those confused people. I assumed this would be the WH presenting what evidence they have. Sooo... still no public evidence that Russia leaked the DNC and Podesta's e-mails?

Read the original CloudStrike report. Not the government report but the private security firm report. The government report is really just a restatement of that report. You don't track hackers for a decade to suddenly be wrong because of a governments political stance.

No idea why you're bringing politics into this. All I said was no evidence has been made public by the government.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#17
post #14
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

Agreed. I wrote this on FB last year when people were calling hacks 'cyberwar': I’m still not sure what to think of the Sony hack. I instantly rejected the idea that it amounted to “cyber war”, but beyond that, I think governments can take a legitimate interest in digital attacks on private companies, same as law enforcement would get involved in a physical attack on a corporate building. I think the main response to…

The Sony hack is a great example. The shareholders, employees and other stakeholders should have enjoyed legal remedies that could have rocked the corporate world into enacting meaningful INFOSEC practices. Instead I've seen reports they paid only $8m USD in a class action settlement. Its not enough to serve the public policy need.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#18
post #8
post #3

The white house and the document itself never list attribution as the goal. Robert M Lee seems to think because it refers to the attackers as Russia, it is confusing readers. The summary at the beginning makes it clear to me that the document is presupposing the attacker is Russia as to be consistent with all future public reports. I don't think this is the best written report, but his conjecture around completely le…

The timing of the release of this document, at the same time as the announcement of sanctions on Russia for the hacking, can't be overlooked. It's quite reasonable to assume the release of this report was intended to create the impression of evidence for attribution, even if it actually contains no such thing. Otherwise why not release it on any other day to avoid confusion? It looks to me like the confusion was quit…

White House stated pretty clearly why the Grizzly Steppe report went out: "to better help network defenders in the United States and abroad identify, detect, and disrupt Russia’s global campaign of malicious cyber activities."

https://www.whitehouse.gov/the-press-office/2016/12/29/fact-...

Attribution is sexy and the media likes to talk about it. I don't believe the confusion was intentional. The White House is pretty bad at PR and 'never ascribe to malice that which can be explained by incompetence'

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#19
post #13
post #9

Earlier quoted context omitted.

What was the public interest in his lobster recipe? Or creating a paranoid frenzy that got shots fired at a Pizza place? Randomly dumping personal emails isn't the same as Ellsberg and Snowden working with reporters to blow the whistle on specific transgressions in war and mass surveillance. Interesting article exploring this issue of exercising discretion and developing new ethics in the age of leaks: http://www.nyt…

Obviously the pizzagate stuff is stupid and unfounded. It does a great disservice to people that were victims of real sexual abuse. But can't you see the vast amount of corruption? The DNC rigged the primary for one candidate. We need to hold our political parties accountable for their actions.

They preferred a candidate, but 'rigging' implies fraudulently manipulating the votes, which didn't happen.

I'd like to see the RNC's emails now. What kind of dirt do the republicans have? Is it not being released because it's being used to blackmail them?

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#20
post #13
post #9

Earlier quoted context omitted.

What was the public interest in his lobster recipe? Or creating a paranoid frenzy that got shots fired at a Pizza place? Randomly dumping personal emails isn't the same as Ellsberg and Snowden working with reporters to blow the whistle on specific transgressions in war and mass surveillance. Interesting article exploring this issue of exercising discretion and developing new ethics in the age of leaks: http://www.nyt…

Obviously the pizzagate stuff is stupid and unfounded. It does a great disservice to people that were victims of real sexual abuse. But can't you see the vast amount of corruption? The DNC rigged the primary for one candidate. We need to hold our political parties accountable for their actions.

>The DNC rigged the primary for one candidate.

Clearly there were people within the DNC who preferred clinton, but in what sense did they rig the vote?

See: http://electionado.com/canvas/1478880826459

Post reply on HN