Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

261–270 of 502 posts

Re: Technical report on DNC hack [pdf]

#261
post #78

Earlier quoted context omitted.

If I recally correctly, NIST recently issued guidelines specifically against password expiration/recycling and against forced limits on what characters you can have in your password.

Yep. All the more infuriating. They know better. NGOs, private industry and the US government at most levels there has been a movement away from password length limits and password expiration and SMS as a second factor. (Even OTP and hashes may be replaced by U2F keys someday.) Then we get this recommendation for password expirations. Two steps forward, one back -- as always.

What? The old suggestion which government/enterprise followed was quarterly password changes/rotation. This is no longer recommended by NIST though. How is that bad?

Re: Technical report on DNC hack [pdf]

#262
post #245

Earlier quoted context omitted.

I have personally written that exact tool while learning Python. A RAT using Twitter for C & C. Uses PGP for encryption and verification. The twitter handles for the C & C change based on a hash of Googles lastest Doodle so you can access it without fear of account deletion. TIL I'm as good as a state level intelligence team. Hey CIA/NSA we know you are reading this, my contact info is in my profile. Hire me.

> TIL I'm as good as a state level intelligence team. Not to totally ignore the pithiness, but I feel like your comment touches on something I see a ton here (and elsewhere): an offhand dismissal of the 'state level' intelligence capacity. At the end of the day, the systems were exploited. That more sophisticated methods went unused should be a measure of efficiency and not necessarily execution. Why break out the tr…

True. But the absence of sophistication constitutes evidence neither in favor nor against the "State Actor" hypothesis.

Re: Technical report on DNC hack [pdf]

#263
post #85

Earlier quoted context omitted.

The bloomberg article I read ( http://archive.is/j5wRd ) presented it as evidence. Maybe other publications are doing the same. >As part of the administration’s response, the FBI and Homeland Security Department also released a report with technical evidence intended to prove Russia’s military and civilian intelligence services were behind the hacking and to expose some of their most sensitive hacking infrastructure.

The "evidence" cited is not the handful of unclassified details included, it's the fact that the FBI and DHS are willing to go on record publicly accusing Russia. There are no asterisks or weasel-words or "allegedly"s. Just a clear "Russia did it." There are only two possible explanations for that: 1) A massive conspiracy in which the leaders of practically the entirety of the US military/intelligence community are w…

>1) A massive conspiracy in which the leaders of practically the entirety of the US military/intelligence community are willing to go on record with a hoax that will easily be unraveled by the incoming administration in a few months

Unless the actual perpetrators were the US intelligence community and/or the incoming administration. Then they could both hide their tracks or have no reason to unravel this. But why suspect the group with the most to gain or the community with the most experience doing this? It's not like there's any other examples of a Republican politician breaking into the DNC to tap their communications, using the intelligence agencies to help cover it up...

Re: Technical report on DNC hack [pdf]

#264
post #250
post #149

Earlier quoted context omitted.

I understand why that might superficially decrease you trust in the claims, but consider the perspective of the totalitarian trying to spin up a chemical weapons program. Wouldn't leveraging existing expertise and contractors be a good way to get the weapons you wanted? Why wouldn't a dictator hire outsiders to build weapons? Having his experts check them for traps after the construction sounds much cheaper than buil…

We knew that Iraq had WMDs because a number of western countries sold them some a few decades ago to drop on Iran on our behalf. That's not a secret, and if I recall correctly they were tightly secured and probably degraded to the point of ineffectiveness by that point. The claim that justified invasion was that they had new chemical weapons programs, and that seems to be categorically untrue and without evidence.

It's not that simple. Saddam was trying to make it look to his neighbors (especially Iran) that he had WMDs. Recall that this is very shortly after the end of the decade-long Iran-Iraq war. He wanted to be very convincing, so as to make his neighbors unwilling to oppose him.

At the same time, he was telling the US, "Who, me? I don't have any WMDs." Which made him look like a two-faced liar. The "evidence" that he wanted his neighbors to see convinced Washington.

Re: Technical report on DNC hack [pdf]

#265
post #257

Earlier quoted context omitted.

The actual evidence is probably closer to 'we have moles in the kremlin and taps on their phones' but they're not exactly going to publish that are they.

If they're not going to publish their (hypothetical, ostensible, theoretical, possibly entirely imaginary) evidence, then why would we put much faith into their claim? It's not like all major US intelligence agencies haven't led deception campaigns against the public before.

There is a fair amount of public evidence lying around tying the hacks to Russia or at minimum Russians, including CrowdStrike's recent report about Ukrainian artillery. Considering that, it seems more likely that US intelligence has their own evidence, as they claim, than that they're simply making things up (at the risk of substantial embarrassment).

Re: Technical report on DNC hack [pdf]

#266

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

Do you have any evidence to back up your utterly ridiculous claims?

And yes, claiming that's all the evidence that exists is complete bullshit.

Re: Technical report on DNC hack [pdf]

#267
post #252
post #199

Earlier quoted context omitted.

The purpose of these "reports" and the retaliation against the Russians is to undermine the legitimacy of the Trump presidency. There's no need for proof, just innuendo and allegation would do. Pretty sick of technology got dragged through the mud for political purpose.

This is the least plausible conspiracy theory I've ever heard. C'mon man. Imagine you're whoever-it-is you think is behind this, and you want to discredit Trump for whatever reason. What would you do? You've got access to all of his tax returns, and all the sealed details of his divorces, and all of his medical records, and all of his business records. You've got a whole squad of spies working for you, you can fabric…

The Democrats (of whom I am one since birth) are using "The Reds did it!" as a tried and true excuse to explain the utter failure of their muddled, ineffective ideology on the national stage.

It's face saving through and through. And it makes a better story than "Trump beat us because we half-assed this election."

Re: Technical report on DNC hack [pdf]

#268
post #252
post #199

Earlier quoted context omitted.

The purpose of these "reports" and the retaliation against the Russians is to undermine the legitimacy of the Trump presidency. There's no need for proof, just innuendo and allegation would do. Pretty sick of technology got dragged through the mud for political purpose.

This is the least plausible conspiracy theory I've ever heard. C'mon man. Imagine you're whoever-it-is you think is behind this, and you want to discredit Trump for whatever reason. What would you do? You've got access to all of his tax returns, and all the sealed details of his divorces, and all of his medical records, and all of his business records. You've got a whole squad of spies working for you, you can fabric…

Double points for banging war drums?

Re: Technical report on DNC hack [pdf]

#269
Ummm what piece of information in the leak caused Clinton to lose?

Reality check nothing because there were no bombshells found like James Coomey re-opening the FBI's investigation against that woman. A woman who nationally especially compared to Obama is highly unlikeable with a horrible public image. Though we're stuck with that crazy man... losing game either way!

Re: Technical report on DNC hack [pdf]

#270

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

The report just didn't get into that much detail but they did say:

"the code delivers Remote Access Tools (RATs) and evades detection using a range of techniques."

A "range of techniques" includes things like rootkits.

>No rootkits,

The attackers did use stealthy persistence techniques often called 'rootkits".

"the SeaDaddy implant developed in Python and compiled with py2exe and another Powershell backdoor with persistence accomplished via Windows Management Instrumentation (WMI) system,[..] The Powershell backdoor is ingenious in its simplicity and power" [0]

>no 0 days

The same group used six 0-days in 2015. Either they didn't need to use them in this attack or they used them and deleted the evidence. Senit is APT28 see quote below:

"One of the striking characteristics of the Sednit group is its ability to come up with brand-new 0-day vulnerabilities regularly. In 2015, the group exploited no fewer than six 0-day vulnerabilities" [1]

>yet it was the most routine, simple attack conceivable.

The attack involved multiple pieces of custom written software and carefully researched spearfishing, the attackers spent time and effort to hide their tracks, maintain persistence and exfil data without detection. This level of effort and time does not qualify as routine, some intelligence agencies can't even write their own RATs.

[0]: https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...

[1]: http://www.welivesecurity.com/wp-content/uploads/2016/10/ese...

Post reply on HN