Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

121–130 of 502 posts

Re: Technical report on DNC hack [pdf]

#121

Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

The report itself seems to claim it provides attribution. Am I misunderstanding?

> Previous JARs have not attributed malicious cyber activity to specific countries or threat actors. However, public attribution of these activities to RIS is supported by technical indicators from the U.S. Intelligence Community, DHS, FBI, the private sector, and other entities. This determination expands upon the Joint Statement released October 7, 2016, from the Department of Homeland Security and the Director of National Intelligence on Election Security.

Re: Technical report on DNC hack [pdf]

#122
post #84

Earlier quoted context omitted.

By mentioning that they are "ranking members" you make an argument from authority that is predicated on the legitimacy of the government alone, effectively saying "kneel and take whatever they say at face value". In my view, they are all self-serving career politicians and none have shown any particular reason they should be trusted or respected. They were the ones who urged the knee-jerk reaction in Iraq which has c…

Fine. But (assuming you extend this attitude to "the mainstream media" as well) you've created for yourself an ontology of the world in which it is impossible to claim any knowledge of anything outside your direct field of view. I'm not really sure how you intend us to accomplish much of anything without _some_ ability to trust _someone_ else. And bipartisan agreement from bitter enemies who have little or nothing to…

Politicians stand to gain government expansion when they scare the population.

So it's not nearly as low of a bar as you think. It's like you're claiming we must trust pharmaceutical representatives from competing companies when they both agree that we all need more pills.

Re: Technical report on DNC hack [pdf]

#123

The Sony hack had more evidence than this... Someone explain to me why this is such an issue? There have been many proven hacks from many states that are far worse (the Chinese Fighter plane that looks almost identical to the F35 come to mind) than exposing the DNC's dirty laundry. No one is denying that the emails are real. This seems like some sort of distraction.

> The Sony hack had more evidence than this...

Where? The FBI handled the investigation and didn't cite its sources.

https://www.fbi.gov/news/pressrel/press-releases/update-on-s...

> "While the need to protect sensitive sources and methods precludes us from sharing all of this information, our conclusion is based, in part, on the following"

Re: Technical report on DNC hack [pdf]

#124

It seems unlikely that email hacking will stop in the future. If the leaked emails actually influenced the elections, it was because of their content. I've heard exactly zero credible claims that the leaked emails were falsified in any way. Perhaps if political candidates/party executives are going to do unethical/illegal things, they shouldn't discuss them over email. Edit: changed "zero claims" to "zero credible cl…

It's rather naive to think these things didn't have an effect.

The problem isn't the truth of the claims, it's that the illicitly gained information was strategically released to disrupt one specific campaign, effectively destabilizing our election. Much like Comey's last minute email announcement revealed nothing new, yet allowed the email narrative to renew its currency in the last days of the campaign.

Imagine if the IRS "accidentally" released Trump's tax returns or been hacked to allow this data to come out. Or if the alleged tapes went public of Donald Trump making openly racist remarks on his TV shows outtakes. Even if these simply revealed things many people already expect to be true, it would have had mesurable impact on the election.

Re: Technical report on DNC hack [pdf]

#125
post #77

Earlier quoted context omitted.

If you rephrase your hysterical wording as "major bipartisan concern across every intelligence agency and nearly all ranking members of both houses of Congress, including the heads of both Intelligence Committees," then I'm not really sure what more evidence you or I could hope for from such an obviously sensitive, active topic for the time being.

By mentioning that they are "ranking members" you make an argument from authority that is predicated on the legitimacy of the government alone, effectively saying "kneel and take whatever they say at face value". In my view, they are all self-serving career politicians and none have shown any particular reason they should be trusted or respected. They were the ones who urged the knee-jerk reaction in Iraq which has c…

That's not what "ranking members" communicates; rather, it suggests that the conclusion transcends partisan politics. That doesn't mean it doesn't succumb to other biases (though I don't think so), but it is a meaningful statement to make.

Re: Technical report on DNC hack [pdf]

#126
post #84

Earlier quoted context omitted.

Fine. But (assuming you extend this attitude to "the mainstream media" as well) you've created for yourself an ontology of the world in which it is impossible to claim any knowledge of anything outside your direct field of view. I'm not really sure how you intend us to accomplish much of anything without _some_ ability to trust _someone_ else. And bipartisan agreement from bitter enemies who have little or nothing to…

Politicians stand to gain government expansion when they scare the population. So it's not nearly as low of a bar as you think. It's like you're claiming we must trust pharmaceutical representatives from competing companies when they both agree that we all need more pills.

Who's expanding what part of government here?

Re: Technical report on DNC hack [pdf]

#127
I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website.

As I understand from report the main methods used were:

- sendind emails with executable files that victims for some reason executed

- phishing

So, they used script kiddie level tools anyone could use (and they are cheap; you don't have to buy expensive zero-day exploits on a black market). But of course this could be done intentionally so it looks amateur-ish.

This attacks could be easily mitigated. First, OS and applications should not run unknown files from Internet (because some people got used to double click on everything they get in email), second, we should start using physical cryptographic keys instead of passwords. Common people cannot handle passwords, they either make easily guessed passwords or enter them everywhere without thinking. I hate passwords too because they are hard to remember (and please don't suggest that I should download some software and upload my passwords to a "cloud" in NSA-controlled country).

By the way iOS is the only popular operating system I know that doesn't allow to execute files downloaded from web or emails. Apple did it the right way.

The report also contains a pretty useless firewall rule named "PAS TOOL PHP WEB KIT FOUND" that can be used to search malware in PHP files. It is interesting that they have replaced digits in 'base64_decode' function name with regexp as if there were any other similar functions.

Re: Technical report on DNC hack [pdf]

#128

Earlier quoted context omitted.

The entire thing has been a politicized distraction and propaganda campaign ... the level of discourse in America is now at a terrifying and dangerous quality; we used to mock the propaganda of the Soviets, China, etc. but we are descending into their grade.

Exactly. Obama just created a National Anti-Propaganda Center to keep watch over American news organizations. An elaborate surveillance/police state combined with a propaganda system is scary indeed, no matter which president or political party controls it.

>National Anti-Propaganda Center to keep watch over American news organizations.

I googled this term and all I got were conspiracy theory websites.

Here's the actual law: https://www.congress.gov/bill/114th-congress/senate-bill/327...

Re: Technical report on DNC hack [pdf]

#129

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

>I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website.

https://news.ycombinator.com/item?id=13280068

Look again, they handed you more than enough information.

>The report also contains a pretty useless firewall rule named "PAS TOOL PHP WEB KIT FOUND" that can be used to search malware in PHP files. It is interesting that they have replaced digits in 'base64_decode' function name with regexp as if there were any other similar functions.

  root@:~/super_secret_govt_malware_samples# grep * -e bas|tail -n2
  D285115E97C02063836F1CF8F91669C114052727C39BF4BD3C062AD5B3509E38:
Why is everyone trying so desperately to attack and discredit this report?

Re: Technical report on DNC hack [pdf]

#130
At least some of the DNC users who had VPN access (which, presumably terminated "behind the firewall") had local Administrator rights on the PCs they used [1]. Getting one of those people to load malware and piggybacking on their VPN connection (letting them enter 2FA if there even was any) was likely a cinch.

There's nothing that I've read anywhere that makes me think the DNC was any kind of difficult target to compromise. Likely their information security posture was on par industry norms for small office networks-- absolutely terrible.

[1] https://wikileaks.org/dnc-emails/emailid/8763

Post reply on HN