Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

411–420 of 502 posts

Re: Technical report on DNC hack [pdf]

#411
post #299
post #293

Earlier quoted context omitted.

> not a lot of people There are many Republicans.

Republicans as such don't have a lot of motivation to prove DNC incompetence by them being hacked, now that Republicans won the election - that would be much larger claim that DNC is less than competent than being hacked.

Your assertion does not persuade me.

Re: Technical report on DNC hack [pdf]

#412

Earlier quoted context omitted.

There is no evidence that the NYT stole Trump's tax returns. His ex-wife had copies of those documents and it's widely suspected that she was the one to leak them.

> There is no evidence that the NYT stole[1] Trump's tax returns. His ex-wife had copies of those documents and it's widely suspected that she was the one to leak them. There's no evidence[2] that Russia hacked the DNC. It's "widely suspected" that murdered DNC staffer Seth Rich leaked the emails.[3] Even if Marla Maples herself provided the returns to the NYT (and the NYT claims they were sent from Trump Tower), I s…

Wow! Do Trump's exes also live in Trump Tower? That has the potential to really ruin an elevator ride...

Re: Technical report on DNC hack [pdf]

#413
post #353

Earlier quoted context omitted.

Basic sources on the total consensus?

https://www.dhs.gov/news/2016/10/07/joint-statement-departme... > The U.S. Intelligence Community (USIC) is confident that the Russian Government directed the recent compromises of e-mails from US persons and institutions, including from US political organizations. This is an official joint statement from the USIC, which is an official body composed of 16 different intelligence organizations: https://en.wikipedia.org…

That report presents no evidence, comes from political appointees, and generally only says that it might be consistent with something Russia would like to do without explaining why.

Also, not sure how the agency count helps anything. Exactly what did agencies like the NRO and Coast Guard contribute here?

Re: Technical report on DNC hack [pdf]

#414

Earlier quoted context omitted.

You can buy RATs. The several RATs used in this campaign were never for sale. For example the RAT named X-Agent was one of several used in the DNC hack. It has never been put up for sale and it was used in previous Russian intelligence operations (for example tracking Ukraine artillery[0]). >That's not what is usually called a rootkit It doesn't appear that anyone has reverse engineered the PC version of X-Agent but…

So essentially someone hacked the DNC, and it's "advanced" because some custom software was written just for this particular target ? I've written custom software (which was a lot harder to find than some python WMI hooks) for hacking a lot lower profile organisations. I've consulted for organisations that were hacked by Chinese hackers for bitcoin ransom that had custom software written too. I mean, high profile tar…

Let's keep the discussion to the technical aspects of the attack. The democrat vs republican antagonism doesn't belong on hacker news.

Re: Technical report on DNC hack [pdf]

#415
post #22

'The U.S. Government assesses that information was leaked to the press and publicly disclosed.' Who in US Government? What information was leaked?

Are you under the impression that different parts of the US government typically "speak" with difference voices? This was an official government publication, that means "Who" is "The US Government", period.

Yes, I am under that distinct impression. Most noteworthy political and legal matters amount to precisely that.

Re: Technical report on DNC hack [pdf]

#416

Earlier quoted context omitted.

The "evidence" boils down to: The Hackers drove a truck. Russians drive trucks. The Russians did the hacking. While its insulting that our government would try to pass off this drivel as "evidence", I'm much more dismayed that so many of my fellow Americans will uncritically accept it as such.

This is not evidence, and it is unlikely evidence would be released. The Administration (as is usually the case for any US executive on any issue unless they are seeking action that requires legislation or a court verdict or something similar by some formal body outside of the executive branch) is not engaging in an effort to prove anything to anyone. This is an analysis report with information (including most signif…

I think the discussion of sources will be very interesting. There is a strong national interest in restoring faith in our electoral process. This is why so many were appalled at certain accusations that the election was "rigged".

Re: Technical report on DNC hack [pdf]

#417

I have looked through the report. The only useful information was brief description of attack methods, everything else looks like a list of general recommendations one can find on the OWASP website. As I understand from report the main methods used were: - sendind emails with executable files that victims for some reason executed - phishing So, they used script kiddie level tools anyone could use (and they are cheap;…

> This attacks could be easily mitigated. [...] second, we should start using physical cryptographic keys instead of passwords Man--I like the way you think, I really do, but this is not "easy". Technical simplicity and social ease are vastly different, and it's usually the humans who are getting hacked.

I honestly think politicians have stopped using email. This leak was so inconvenient that it has changed behaviors.

Re: Technical report on DNC hack [pdf]

#418

Earlier quoted context omitted.

You don't think they might be a bit concerned a loose cannon like Trump might be a little more curious than normal candidates what sorts of interesting things they get up to, and where they spend their significant budgets? > but I need something That's how a lot of people feel about this whole "Russians rigged the election" thing, we'd like some evidence a little more substantial than "trust us", or at least we'd lik…

...they might be a bit concerned a loose cannon like Trump might be a little more curious than normal candidates what sorts of interesting things they get up to, and where they spend their significant budgets? It is perhaps significant that the "further analysis" leakfest started after Trump had already disappointed the spooks by bagging their special briefings, rather than back when all of the actual underlying fact…

Ya, who knows....I do think he is very different than your typical politician, but exactly how no one really knows. You might be right that they thought they had the goods on him with things like the sex talk tape, but when he basically shrugs his shoulders and it slides right off his back, I could see how that might be worrying to someone who is also in the influence game.

I agree on Obama, I think something must happen in the first few days where the new President is sat down and gets told how things really work. I would think that is what happened to many of Obama's promises. I doubt anyone would look forward to having that talk with Donald Trump.

Re: Technical report on DNC hack [pdf]

#419
The report released by the US govt only contains a birds-eye view of the hacking incident and not much technical details. But they do reference APT28 and APT29 which are described in reports from FireEye in 2014 and 2015:

   http://www2.fireeye.com/rs/fireye/images/rpt-apt28.pdf
   https://www2.fireeye.com/rs/848-DID-242/images/rpt-apt29-hammertoss.pdf
The evidence is circumstantial, but there is so much of it that I think you can confidently say that Russia is behind it. For example, compile times pointing towards office workers in Moscow, Russian language settings and so on.

Read the reports and make up your own minds!

Re: Technical report on DNC hack [pdf]

#420
ok i think i know what happened: Obama forced FBI to produce the report, but they got nothing, so they filled it mostly with irrelevant slightly-more complicated mumbo jumbo than Obama can understand to slide under his scrutiny, and then he pushes it out to the public without first consulting an actual security professional.
Post reply on HN