Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

461–470 of 502 posts

Re: Technical report on DNC hack [pdf]

#461
post #450
post #373

Earlier quoted context omitted.

No. I believe the official version (that the reason the intelligence agencies are accusing Russia of hacking the DNC is because believe it did) because the alternative is less plausible and there's no evidence for it. That's pure Occam's Razor, no faith involved. The FBI has lied and will lie again, getting me to believe they lied about something is not hard, but they don't generally do it in big, obvious ways that a…

That's not how Occam's razor works. You don't pick the most likely single outcome and then just assume that to be true with 100% confidence. Occam's razor is just an informal statement of the fact that you should assign a higher a priori probability to simpler hypotheses. It doesn't mean you should ignore any marginally less likely hypothesis.

Please stop accusing people of being 100% confident. It's such a weak, insulting tactic. What is the alternate hypothesis that's "marginally less likely"?

(Please remember what question we're trying to answer. It is not "Who hacked the DNC?". We are not in a position to know; hell, we don't even know there was a hack. It is also not "Is the FBI trustworthy?" Of course they're not. It is "Why are US intelligence agencies saying they have proof that Russia hacked the DNC?" The base hypothesis is "Because they do." The alternate hypothesis is what you're supplying.)

Re: Technical report on DNC hack [pdf]

#462
Nonsense. I'm doing cybersecurity analysis for a Navy program this very day. To the person that says "The attackers did use stealthy persistence techniques often called 'rootkits'" -- you know exactly nothing about what you're talking about.

A rootkit is the means to obtain "root" permissions which is an exclusive feature of UNIX/Linux operating systems. Powershell is a Windows product... these systems are Windows based. No rootkit. Period.

Re: Technical report on DNC hack [pdf]

#463
post #461
post #450

Earlier quoted context omitted.

That's not how Occam's razor works. You don't pick the most likely single outcome and then just assume that to be true with 100% confidence. Occam's razor is just an informal statement of the fact that you should assign a higher a priori probability to simpler hypotheses. It doesn't mean you should ignore any marginally less likely hypothesis.

Please stop accusing people of being 100% confident. It's such a weak, insulting tactic. What is the alternate hypothesis that's "marginally less likely"? (Please remember what question we're trying to answer. It is not "Who hacked the DNC?". We are not in a position to know; hell, we don't even know there was a hack. It is also not "Is the FBI trustworthy?" Of course they're not. It is "Why are US intelligence agenc…

> Please stop accusing people of being 100% confident.

To quote you:

> No. I believe the official version

> What is the alternate hypothesis that's "marginally less likely"?

That Russia didn't hack the DNC. I think it's actually marginally more likely than that Russia didn't hack the DNC than that they did, but I was humoring you.

Re: Technical report on DNC hack [pdf]

#464
post #31

Earlier quoted context omitted.

I guess the real question is, why should these IP addresses from those countries make this attack attributable to Russia? Unless you can answer that, yours doesn't really make much sense.

>why should these IP addresses from those countries make this attack attributable to Russia? "DHS has released a Joint Analysis Report (JAR) attributing those compromises to Russian malicious cyber activity, designated as GRIZZLY STEPPE. " This is one of the 'GRIZZLY STEPPE Indicators' . Am i reading this wrong ?

Yes. I can't imagine how you could possibly come to the conclusion that there's supposed to be anything attribution related here.

They explicitly stated this is just indicators of compromise that network administrators should look for.

>DHS recommends that network administrators review the Security Publication for more information and implement the recommendations provided.

not

>DHS recommends that everyone review the irrefutable proof that communists hacked DNC

Re: Technical report on DNC hack [pdf]

#465
post #443

Earlier quoted context omitted.

Hackers have been targeting boring government docs for as long as there's been hacking, sometimes just for laughs, bragging rights, etc. If all the docs are boring, isn't that all the more reason to think that a nation state had nothing to do with this? The NSA would've intercepted your new router in the mail with a backdoor and could've used a TEMPEST van to read your screens from miles away. I have to believe those…

Why bother when it wasn't needed? They have the motive to do it, as much or more than anyone else and certainly the capacity. They are tied to a disinformation campaigns [1] that seem to have the goal of sowing suspicion between allies who oppose them and have everything to gain by swaying our political process. That isn't enough evidence of course, but I'm surprised by the suspicion here and I can only chock it up t…

Because an attack like that gives you short term access which isn't particularly valuable to a nation state. It was quickly found out and stopped.

Re: Technical report on DNC hack [pdf]

#466

Earlier quoted context omitted.

The sophistication is not evidence of government involvement, the lack of sophistication is not evidence that a government was not involved. Certainly malware which costs serious resources to develop, like stuxnet, says something about the capabilities of the attacker. Given that at the high end of the resource spectrum it is mostly governments, resources required are suggestive of a government, but resources are not…

Apparently John McAfee disagrees with you: https://www.youtube.com/watch?v=aDTKKmBjlwE#t=5m40s

Watched, didn't hear anything that contradicts what I wrote. Can you be more specific?

The closest I can find is when McAfee says: "If it looks like the Russians it isn't the Russians." I said "It looks like the Russians." These statements don't contradict each other.

We do disagree on attribution, but I haven't discussed that in this thread. He is radically skeptical about ever attributing any state sponsored hacking, although in the same interview he does attribute Stuxnet to the US/Israel and the OPM hack to China.

Re: Technical report on DNC hack [pdf]

#467
post #368

Earlier quoted context omitted.

I'm referring to parent of this whole thread, which (briefly) is a press release that says, "Here are some ways you can protect yourself from the kind of attack the Russians did on the DNC" and then goes on to describe spear-phishing. The reason this is unusual is because the intelligence agencies are being so matter-of-fact about this. They're not trying to convince anyone, like they did with Iraq's WMDs. They're no…

Absolutely any state that would enjoy the benefits of the distractions that comes with an escalated political conflict, Israel, China, Saudi Arabia. Think about how quickly Erdogan switched from being US ally to being best chums with Russians and helping with the peace negotiations with Iran after the attempted coup. Was it Russia, was it US, what was the motive, does one have motive to frame the other? It's not thei…

You're suggesting that a foreign country supplied the FBI with forged evidence, and the FBI said, "Well, this doesn't match our own investigation, but I guess we'll just assume it's true anyway, now let's announce it to the world on our official letterhead"? Does that sound likely to you?

Re: Technical report on DNC hack [pdf]

#468
post #361

Earlier quoted context omitted.

Think this through. Multiple people in the FBI, CIA, DHS, and NSA all decided this? Together? Did they have meetings? And no one is spilling the beans, even though there are maybe dozens or hundreds of people in on it? Not one of them has more to gain by revealing the conspiracy than by keeping silent? And they're all so confident that no one will squeal that they're having press releases now? And the point of this w…

Haha, I know, it does sound rather crazy. However, once again I will play the Snowden card: all of that was called crazy conspiracy talk, because there would be too many people involved who so thinking that is just crazy. It's certainly not crazy to not trust these people. Deceit is their job .

[deleted]

Re: Technical report on DNC hack [pdf]

#469

Earlier quoted context omitted.

That's the real absurdity of this debacle to me. Many of the whitepapers that I read about the DNC hack listed the attack's "sophistication" as proof that it came from a state actor, yet it was the most routine, simple attack conceivable. No rootkits, no 0 days, just simple phishing and social engineering.

The report just didn't get into that much detail but they did say: "the code delivers Remote Access Tools (RATs) and evades detection using a range of techniques." A "range of techniques" includes things like rootkits. >No rootkits, The attackers did use stealthy persistence techniques often called 'rootkits". "the SeaDaddy implant developed in Python and compiled with py2exe and another Powershell backdoor with pers…

Just to add to this, Crowdstrike is on the DNC's payroll. Any conclusions they provide should either be met with skepticism or discredited to a degree.

Re: Technical report on DNC hack [pdf]

#470
post #463
post #461

Earlier quoted context omitted.

Please stop accusing people of being 100% confident. It's such a weak, insulting tactic. What is the alternate hypothesis that's "marginally less likely"? (Please remember what question we're trying to answer. It is not "Who hacked the DNC?". We are not in a position to know; hell, we don't even know there was a hack. It is also not "Is the FBI trustworthy?" Of course they're not. It is "Why are US intelligence agenc…

> Please stop accusing people of being 100% confident. To quote you: > No. I believe the official version > What is the alternate hypothesis that's "marginally less likely"? That Russia didn't hack the DNC. I think it's actually marginally more likely than that Russia didn't hack the DNC than that they did, but I was humoring you.

I repeat:

> "Why are US intelligence agencies saying they have proof that Russia hacked the DNC?" The base hypothesis is "Because they do." The alternate hypothesis is what you're supplying.

Post reply on HN