Live data from Hacker News

Critiques of the DHS and FBI’s Grizzly Steppe Report

robertmlee.org

51–60 of 114 posts

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#51
post #26

The poor man's hacking technique worked great. Instead of focusing on the tools, focus on the results. I bet you're one of those people who uses microservices to run his 100 visitors/day blog just because it's the shiniest new paradigm.

The results are that someone got into Podesta's gmail for some few days. The pros use methods that allow them to keep long term access and which keep you from knowing that you have been hacked to begin with. Look at the NSA's TAO catalog for examples of how the pros work. You can wipe your servers and still be hacked. I don't seriously believe that the NSA is out there sending phishing emails. They're too busy using…

The results of getting into "Podesta's gmail for some days" is you take the elections. But no, you think it's smarter getting into some nobody sysadmin's social media accounts. Got it.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#52
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink.

The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government contractor getting software from an individual or a company with nine employees.

You can't use that to force improvements from small entities because they barely even have lawyers to tell them what they have to do, and nobody will actually sue them if they have no money anyway.

What you need isn't for the software vendor to be liable, it's for the company holding all the customer data to be liable to those customers. Then those companies will start caring about actual security instead of "compliance" and figuring out how to pass the buck, and software vendors will still have to make secure software because nobody will buy anything else anymore.

It also forces companies to start treating huge databases as the security liability that they are. And it conveniently applies to the large tech companies that are also data warehousing companies like Yahoo or LinkedIn/Microsoft.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#53
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

The report also disregards various other sources of foreign manipulation on US networks including spam and propaganda which as everyone knows are also forms of hacking. For instance the 'fake news' on Youtube and spam links on Facebook and Instagram which link to phishing sites. Companies must be held accountable for harboring this type of material.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#54
post #37
post #33

Still lacking any evidence that voting machines were hacked or any part of the electoral process was hijacked. The worst damage? Emails related to the actual rigging of the Democrat Party primaries and the collusion of the media with the Democrat party. Its very hard for me to believe that a state actor is behind such seemingly altruistic actions. Voters saw the worst of Trump and Clinton and choose the lessor of two…

How on earth did a leak of DNC emails, but no corresponding RNC leak, help people figure out the lesser of two evils or provide a level playing field? Seems obvious that leaks assisting the pro-Putin candidate were not altruistic.

Assuming Clinton had those dirty secrets and Trump had nothing equivalent, that's what a level playing field looks like.

If you want to assume there were also some dirty Trump secrets that didn't come out then it seems like the only way to "level the playing field" would be for e.g. Venezuela to hack the Republicans and air their dirty laundry too.

And people are running around saying how terrible this is and asking "what if everybody did this?" But it seems like the answer to that question is, then people would know more relevant information about their political candidates. Or politicians would get better at computer security. Which of those is supposed to be bad?

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#55
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government…

"it's an insurance company or government contractor getting software from an individual or a company with nine employees."

The good news is high-assurance systems have been built with smaller teams than that. We also have cases like Bernstein's where one person builds all kinds of stuff with provably better security using a bit of brains and methods that work. We also have tools like SPARK for static systems and Rust/Eiffel for larger ones that can easily eliminate entire classes of attack. Ada & SPARK have been around decades. Eiffel over a decade. Hardly anyone in security-critical space using them.

Most of what you see is easily prevented. Even with small teams. They just don't care or try. A baseline stopping code injection or insecure configurations would knock out a ton of problems. The next thing that would happen, as did with DO-178B regulation & TCSEC, would be reusable components and consulting services designed to meet the standard where the cost & limited expertise is spread among many customers.

It could be done. Even for smaller players to a large degree.

"What you need isn't for the software vendor to be liable, it's for the company holding all the customer data to be liable to those customers."

Doesn't solve the DDOS problem which can also be used for extortion, interfering with government operations, etc. My approach targeting root cause handles that, too.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#56
post #26

Earlier quoted context omitted.

The results are that someone got into Podesta's gmail for some few days. The pros use methods that allow them to keep long term access and which keep you from knowing that you have been hacked to begin with. Look at the NSA's TAO catalog for examples of how the pros work. You can wipe your servers and still be hacked. I don't seriously believe that the NSA is out there sending phishing emails. They're too busy using…

The results of getting into "Podesta's gmail for some days" is you take the elections. But no, you think it's smarter getting into some nobody sysadmin's social media accounts. Got it.

The first statement is not in evidence. It's amazing how many people believe both that nothing was in there, but also that it swung the election. As opposed to, say, the connections between Hillary's top aide, Huma, and the infamous Anthony Wiener coming to light. Or do you know him better as "Carlos Danger"? Did the Russians also make her avoid any campaign stops in the (not so) "blue firewall"? Or what about when Michael Moore put out a speech that could be chopped in half and turned into a Trump ad? Or what about when they insisted that Hillary's health was perfect, then everyone saw this? https://www.youtube.com/watch?v=9zYthqiLs_I

You can say the polls only took a dive in the last week, but if you really look at them, most polls were oversampled in the Democrat's favor the whole time. There were legitimate reasons they did this in expectations of Obama-like results, but in the end the results speak for themselves.

But yes, the sysadmins hold the keys to the kingdom. Why get one lousy email when you can get the email server via the sysadmin? And every other server.

If you just want one person, there are better ways than noisy phishing attacks. Everyone knows that Podesta's email was phished, not many people realize he also lost his cell phone in a DC cab...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#57
post #37

Earlier quoted context omitted.

How on earth did a leak of DNC emails, but no corresponding RNC leak, help people figure out the lesser of two evils or provide a level playing field? Seems obvious that leaks assisting the pro-Putin candidate were not altruistic.

Assuming Clinton had those dirty secrets and Trump had nothing equivalent, that's what a level playing field looks like. If you want to assume there were also some dirty Trump secrets that didn't come out then it seems like the only way to "level the playing field" would be for e.g. Venezuela to hack the Republicans and air their dirty laundry too. And people are running around saying how terrible this is and asking…

> Assuming Clinton had those dirty secrets and Trump had nothing equivalent

Those are two rather incredulous assumptions considering that:

- Clinton released all of her tax returns, whereas Trump didn't release any

- The Clinton Foundation has been audited by at least three well respected, independent, organizations (garnering top ratings from all), whereas we know comparatively little about the Trump Foundation (or whatever it's called), yet it's admitted within the last six months to several inappropriate expenditures or donations, and is likely being investigated for more

- Trump sits atop a network of literally hundreds (if not thousands) of "independent" corporations designed solely to evade disclosure, liability, taxes or some combination thereof

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#58
post #21

So it was just spearfishing, the poor man's hacking technique. The techniques that NSA and MI6 use are far more advanced. Taking advantage of the networking equipment and injecting traffic.

> So it was just spearfishing, the poor man's hacking technique.

Just because someone walked in through an unlocked window does not make them any less an effective burglar.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#59

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

I don't really care that much about this specific event. It's a bunch of liars (Russian government, various US intelligence services, Russian and American politicians) trying to tell me that "the other guy" is a liar and did something bad. My life continues as it does, working against all those listed above because none of them particularly deserve my assistance or respect.

on top of that, the leaks were real. If they were "leaking" phony information, I might have an issue. But this "hack" gives high-ranking politicians a taste of their own medicine. What POTUS calls a "hack", I prefer to call "warrant-less wiretapping".

and it's for "security". I'm 'secure' from hillary clinton's corruption, therefore, violating her right to privacy is ok. same thing they do to each US citizen

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#60
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

It was a spear-phishing attack. The only way to protect against that is to ban email.
Post reply on HN