Live data from Hacker News

Dear Obama, from Infosec

blog.erratasec.com

31–40 of 91 posts

Re: Dear Obama, from Infosec

#31
post #29

Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. That, plus, it shouldn't matter who has done it, since (especially if it was Russia) they most likely won't be persecuted for it. What the focus should be put on is making sure this won't happen again - but that the general public isn't very interested in.

> Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about.

There was no "election hacking", a DNC executive failed for a fishing scam, there is absolutely no proof whatsoever that it was the Russians.

It's interesting how liberals became CIA and FBI shills in less that 2 weeks after the election, while ignoring the wide spread corruption in their party. Now maybe Russia did it, it doesn't make the content of the emails less true. There is also an interesting display of anti Russian xenophobia on liberal media, which proves that the party of "progress" is also capable of the worst when it comes to hate speech and warmongering, now labelling anyone who disagree as "traitor".

Re: Dear Obama, from Infosec

#32
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

> were trying to throw the election to Trump (rather than just to sow chaos).

It could be argued that both of those are the same.

I doubt they would be reckless enough to gamble on the former to be honest, when almost everybody thought HRC had it in the bag.

Re: Dear Obama, from Infosec

#33
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

Some attributions of the attack came from private security firms, not from intelligence community. Can their analysis be released or they have ongoing interests too? It would be interesting to know if espionage activities are privatized in USA and "actual humans who will die" work for private corporations.

[deleted]

Re: Dear Obama, from Infosec

#34
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

Some attributions of the attack came from private security firms, not from intelligence community. Can their analysis be released or they have ongoing interests too? It would be interesting to know if espionage activities are privatized in USA and "actual humans who will die" work for private corporations.

Private companies like Crowdstrike would probably love to reveal their analysis however they would be restricted by the actual data owners (e.g. the DNC) and I would guess ongoing government investigations. Plus why blow all of your signatures when they still work?

Outside of that, there's tons of data online already regarding Russian government hacking activity: http://researchcenter.paloaltonetworks.com/2016/06/unit42-ne... https://www.fireeye.com/content/dam/fireeye-www/global/en/cu... https://securelist.com/blog/research/72924/sofacy-apt-hits-h... http://researchcenter.paloaltonetworks.com/2016/09/unit42-so...

Do you think understanding the tools, infrastructure, coding styles, activities, targets of these groups allows them to perform attribution?

Re: Dear Obama, from Infosec

#35
post #31
post #29

Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. That, plus, it shouldn't matter who has done it, since (especially if it was Russia) they most likely won't be persecuted for it. What the focus should be put on is making sure this won't happen again - but that the general public isn't very interested in.

> Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. There was no "election hacking", a DNC executive failed for a fishing scam, there is absolutely no proof whatsoever that it was the Russians. It's interesting how liberals became CIA and FBI shills in less that 2 weeks after the election, while ignoring the wide spread corruption in their party. Now maybe Ru…

> while ignoring the wide spread corruption in their party

Because the crime of breaking in is far more disturbing than what was found, given that even the "victim" brushed it off? If you ask people what the worst part of the emails was, they point to out-of-context blurbs that are either common practices or misleading.

I have legitimate cause for concern when the President to be inaugurated does not believe intelligence about an American adversary.

Re: Dear Obama, from Infosec

#37
First of all this piece should be lauded and it is this type of transparency that ALL administrations should adhere too. Granted without revealing sensitive sources.

Second, the Russians didn't hack the election. As far as we'll all know, no voting machines were compromised. It may have been some email accounts of campaign officials (about which Wikileaks has already publicly stated the leaks didn't come from Russia). So starting off with the propagandist and frankly bullshit headline "Russia hacked the election" is in and of itself already portraying an extremely false narrative. Dangerous. Very dangerous.

Re: Dear Obama, from Infosec

#38
post #31

Earlier quoted context omitted.

> Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. There was no "election hacking", a DNC executive failed for a fishing scam, there is absolutely no proof whatsoever that it was the Russians. It's interesting how liberals became CIA and FBI shills in less that 2 weeks after the election, while ignoring the wide spread corruption in their party. Now maybe Ru…

> while ignoring the wide spread corruption in their party Because the crime of breaking in is far more disturbing than what was found, given that even the "victim" brushed it off? If you ask people what the worst part of the emails was, they point to out-of-context blurbs that are either common practices or misleading. I have legitimate cause for concern when the President to be inaugurated does not believe intellig…

>concern when the President to be inaugurated does not believe intelligence about an American adversary

I dislike Trump for many reasons but, based on the track record of the US intelligence community over the course of the last 10-15 years, if he approaches the intelligence briefings that are fed to him with the same skepticism that he has displayed for climate science, I can only see that as a positive.

Re: Dear Obama, from Infosec

#39

Assange repeatably - and again tonight - said he was sure it wasn't Russia. I think it's worth something to consider the main visible actor opinion.

I have the same level of skepticism towards Assange that I do for the US intelligence community, but for different reasons. If Assange received a email dump from a source, how could he possibly know with absolute certainty that the Russian government didn't have any involvement? The only thing I can think of is if he or one of his very trusted associates executed the attacks themselves. Isn't it possible that the Rus…

> Assange repeatably - and again tonight - said he was sure it wasn't Russia.

The very fact that Assange is has so strenuously denied it was the Russians is itself odd and suspicious. He couldn't possibly know if it is or not and yet he's been adamant since day one. He's either a gov agent, liar, or idiot. And I don't think he's an idiot.

Re: Dear Obama, from Infosec

#40
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

It's simply not true that "the intelligence community will never be able to release enough information to satisfy people".

A few days back, the same author wrote[0]:

> On the other hand, if they've got web server logs from multiple victims where commands from those IP addresses went to this specific web shell, then the attribution would be strong that all these attacks are by the same actor.

All the FBI/DHS have to do is say: Organizations A, B, and C all have server logs showing this IP address deliver the same malware.

That would be enough information to attribute the hacks to the same actor. If the FBI/DHS were lying about Organization B, then Organization B would speak up about it.

The author of this post is right to point out that the attribution given so far is not only incomplete, but is borderline bizarre.

[0] http://blog.erratasec.com/2016/12/some-notes-on-iocs.html

Post reply on HN