Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

321–330 of 502 posts

Re: Technical report on DNC hack [pdf]

#321
post #298

Earlier quoted context omitted.

Except that this is a sort of exclusion of the middle; you say " here's the alternative theory ", but there are other even more likely possibilities. Here's one: 1. The DNC and their members are generally ignorant of good security policy and had an easily hacked system. 2. Some Russian intelligence agency hacked the DNC's email servers. 3. A bunch of other people/hackers/groups hacked the DNC's email servers, as it w…

Point 7 is the one you're supposed to be trying to explain. The FBI, CIA, DHS and NSA have all said, in plain language, no anonymous sources, just regular old press releases, that Russia hacked the DNC. The reasons they might say this are a) they believe it due to some evidence they are not releasing, and b) ???. Theory a) seems pretty believable, and I haven't heard a b) that sounds remotely plausible yet. Whether s…

> b) ???

How about the FBI/CIA/DHS/NSA don't like people who don't play by the accepted rules sticking their nose into their business, so they tell a little white lie to try to avoid that?

The three letter agencies have had plenty of people killed before, so "they'd never do that" isn't going to get you very far.

Re: Technical report on DNC hack [pdf]

#322
post #279

Earlier quoted context omitted.

The report just didn't get into that much detail but they did say: "the code delivers Remote Access Tools (RATs) and evades detection using a range of techniques." A "range of techniques" includes things like rootkits. >No rootkits, The attackers did use stealthy persistence techniques often called 'rootkits". "the SeaDaddy implant developed in Python and compiled with py2exe and another Powershell backdoor with pers…

Can't one just buy a RAT? Also, the WMI think they describe doesn't look like rootkit, more like cron analogue for Windows. I.e. on Unix it would be like installing a command inside crontab. That's not what is usually called a rootkit - a tool that is designed to conceals its presence (and other tools presence) from regular OS tools.

[deleted]

Re: Technical report on DNC hack [pdf]

#323
post #286
post #276

Earlier quoted context omitted.

Seriously. Clapper lied directly to congress under oath on TV. The whole "they know whats best for us and our only choice is blind faith" attitude is really disturbing.

> The whole "they know whats best for us and our only choice is blind faith" attitude is really disturbing. This is so, so insulting. There is no way a fair observer could read the comments here and conclude that the people who find Russia hacking the DNC credible do so because they have blind faith in Clapper or the FBI or anyone else.

> There is no way any a fair observer could read the comments here and conclude that the people who find Russia hacking the DNC credible do so because they have blind faith in Clapper or the FBI or anyone else.

Isn't that what you were more or less saying here: https://news.ycombinator.com/item?id=13281736

Re: Technical report on DNC hack [pdf]

#325

Earlier quoted context omitted.

> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.

I think it's a generational thing. Americans of a certain vocation and certain age and older tend to have no idea about how this whole Internet thing works. No matter what their education level or achievement level. Obama held onto his Blackberry for almost 2 years after SS told him you can't use that thing. I suspect what needs to happen is each branch of government needs to have infosec people assigned to it that s…

It's not necessarily a generational thing. John Podesta was suspicious and sent the phishing email to campaign IT. Clinton campaign IT screwed up and told him to click the link and reset his password. Podesta is in his 60s and the IT people look like hey we're in their 20s.

Re: Technical report on DNC hack [pdf]

#326
post #252
post #199

Earlier quoted context omitted.

The purpose of these "reports" and the retaliation against the Russians is to undermine the legitimacy of the Trump presidency. There's no need for proof, just innuendo and allegation would do. Pretty sick of technology got dragged through the mud for political purpose.

This is the least plausible conspiracy theory I've ever heard. C'mon man. Imagine you're whoever-it-is you think is behind this, and you want to discredit Trump for whatever reason. What would you do? You've got access to all of his tax returns, and all the sealed details of his divorces, and all of his medical records, and all of his business records. You've got a whole squad of spies working for you, you can fabric…

I think the parent of your post was implying there are 2 parties here: the one responsible for the hack, and the people saying the hack was the Russians.

Re: Technical report on DNC hack [pdf]

#327

Ummm what piece of information in the leak caused Clinton to lose? Reality check nothing because there were no bombshells found like James Coomey re-opening the FBI's investigation against that woman. A woman who nationally especially compared to Obama is highly unlikeable with a horrible public image. Though we're stuck with that crazy man... losing game either way!

Considering Clinton only lost by about 80k votes total in 3 states, any negative stories resulting from the linked emails could have been the final straw.

Re: Technical report on DNC hack [pdf]

#328

Earlier quoted context omitted.

True. But the absence of sophistication constitutes evidence neither in favor nor against the "State Actor" hypothesis.

Until a Russian name or IP address is provided, the accusations fail to hold water. An incomplete proof is equivalent to "'cause we said so"

Spoofing ips is absurdly easy.

Re: Technical report on DNC hack [pdf]

#329
post #85

Earlier quoted context omitted.

The "evidence" cited is not the handful of unclassified details included, it's the fact that the FBI and DHS are willing to go on record publicly accusing Russia. There are no asterisks or weasel-words or "allegedly"s. Just a clear "Russia did it." There are only two possible explanations for that: 1) A massive conspiracy in which the leaders of practically the entirety of the US military/intelligence community are w…

If the 1 hypothesis were true, then the conspirator would be betting there will be no "incoming administration", not very soon, i'd say. If the 2 were true, there would be also some conspiration to keep those important infomations classified. Also, I can't help thinking about Snowden and the blown whistle of the NSA spying scheme.

Snowden is a powerful trump card for dismissive claims like "massive conspiracy in which the leaders of practically the entirety of the US military/intelligence community are willing to go on record with a hoax" thaat used to work so well.

We know our security agencies (and high level politicians) are not just dishonest, but actively violating the constitution. That people still mock those who distrust these agencies is so strange.

Post reply on HN