Live data from Hacker News

Dear Obama, from Infosec

blog.erratasec.com

51–60 of 91 posts

Re: Dear Obama, from Infosec

#51
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

How can they not convince Congress, apparently both parties don't trust the claim? If you cannot convince another branch of government, in particular one that can fund and write laws to assist in continued action against, then you have an apparatus that is more politically oriented than public oriented.

Re: Dear Obama, from Infosec

#53
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

[deleted]

Re: Dear Obama, from Infosec

#54
post #12

Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…

> It's much more interesting to discuss the shared conclusion was formed that "the Russians" were trying to throw the election to Trump And it's why we need proof. Guessing a password or phising it can be a one man operation.

I appreciate the sentiment that anyone can phish or password guess, but even a cursory glance at infosec reports shows there was an operation targeting the DNC that was far more sophisticated than a one man job.

Firstly we know that that Podesta's account was targeted by a phishing email with a bit.ly link [0]. We have proof the bit.ly phishing link in this email was clicked twice in March [1], and his wikileaks dump stops two days after that. The bitly link uses the TTP of base64 encoded strings targeting a google account. We know DNC staffers whose information was leaked by DC Leaks, like Rinehart, were targeted the same way [2] and that the same infrastructure hosted the Rinehart and Podesta phishing pages, along with plenty of other phishing sites [3]. You can verify the bitly links if you like.

We have reports long before Wikleaks released Podesta's information, and before DC leaks had released most of their information, that the same TTP of bitly links with base64 encoded strings that targeted Podesta, Rinehart etc. were targeting other high profile targets in Clinton's campaign [4] as well as Russians, Ukranians etc. [5]. According to security firms these were all using the same two bitly accounts.

Those attacks were attributed to APT 28 by private companies long before Wikileaks released any Podesta information.

We also have proof the same infrastructure that hosted dcleaks [6] hosted domains targeting Syrian human rights groups, Ukranians, Turks, Google accounts, Microsoft accounts etc. or that other IPs used were also used in attacks against the German Parliament, Tv5 etc. That's definitely circumstantial, but a one man job would be terribly unlucky to use a private Romanian server seen used in previous attacks attributed to a state actor.

Sure this could all be circumstantial, it definitely doesn't prove Russia did anything, but the suggestion that this is a one man operation is ludicrous - almost 4,000 people were targeted by the group that targeted the Clinton campaign. In relation to your other comment below, Assange has less credibility than the DHS report unless he comes out with some sort proof.

[0] https://wikileaks.org/podesta-emails/emailid/34899 [1] https://bitly.com/1PibSU0+ [2] http://www.thesmokinggun.com/documents/investigation/trackin... [3] https://www.passivetotal.org/search/80.255.12.237 [4] https://www.secureworks.com/research/threat-group-4127-targe... [5] https://www.secureworks.com/research/threat-group-4127-targe... [6] https://www.threatconnect.com/blog/does-a-bear-leak-in-the-w... and indeed this entire series.

Re: Dear Obama, from Infosec

#55
post #45
post #42

Earlier quoted context omitted.

I think he's saying between the lines that his source is a insider, and it's either a leak or an internal hack. That's the only way he could have any reliable information at all about the source.

Assange strongly implied that the emails were leaked by Seth Rich. Not sure if I believe that though, since it seems that Assange would have proved it by now if it were true. Maybe he's withholding the proof as leverage, or maybe he's lying. I do trust Assange much more than the CIA though.

>I do trust Assange much more than the CIA though.

But do you trust Assange more than the 17 US intelligence agencies? And the actual president? And members of congress (including many Republicans who would directly benefit from any intelligence pointing another way)?

At this point it's getting close to Assange vs the world. Even Trump won't directly say the Russians weren't involved anymore, he's just muddying the water with "can you really ever prove anything" talk.

Re: Dear Obama, from Infosec

#56
post #31
post #29

Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. That, plus, it shouldn't matter who has done it, since (especially if it was Russia) they most likely won't be persecuted for it. What the focus should be put on is making sure this won't happen again - but that the general public isn't very interested in.

> Pardon my ignorance, but as a non-American, I still have no bloody clue what the election hacking was about. There was no "election hacking", a DNC executive failed for a fishing scam, there is absolutely no proof whatsoever that it was the Russians. It's interesting how liberals became CIA and FBI shills in less that 2 weeks after the election, while ignoring the wide spread corruption in their party. Now maybe Ru…

Now maybe Russia did it, it doesn't make the content of the emails less true.

This is the part I don't get. It is easily discarded because it is attributed to bad guys. Ad hominem / guilt by association.

Re: Dear Obama, from Infosec

#57
post #47
post #43

Earlier quoted context omitted.

The one that's spelled 'none'. WikiLeaks claimed many times Russia wasn't involved, NYT admitted they faked the story. It's nothing more than liberal tears who can't deal with losing elections in a system they were creating and shaping for years.

Last sentence was a bit caustic. Should WikiLeaks even be considered as a reliable source after Assange demonstrated his political bias against Hillary? Also, can you provide a link to NYT admitting to publishing a fake story? Thanks.

DKIM verification shows that everything from the Podesta leaks is real.

Re: Dear Obama, from Infosec

#58
post #23
post #17

Earlier quoted context omitted.

This Russians hacked the election narrative is just like Saddam has WMDs back ten years ago, only more dangerous. So unless any hard evidence comes to light, we can safely dismiss it as propaganda and not get too excited about it.

It's not "just like" that because people in the Bush administration were pressuring the CIA to say the thinnest of evidence proved he had WMDs and was trying to get nukes then repeated the claim again and again. Cut to 2016 where none of the intelligence branches claim Russians "hacked the election," they claim they hacked the DNC and other political organizations for political ends. There's no evidence that anyone i…

It's being used as a shield for the DNC leaks (eg, make the issue that the leak happened, rather than e.g. that the government deliberately played down the Benghazi attacks, DNC had already chosen Hillary as the nominee and was working to undermine Sanders), and to delegitamise the new administration, in the same way Iraq WMD was being used as an excuse to build the US's position in the Middle East.

Re: Dear Obama, from Infosec

#60

Earlier quoted context omitted.

Some attributions of the attack came from private security firms, not from intelligence community. Can their analysis be released or they have ongoing interests too? It would be interesting to know if espionage activities are privatized in USA and "actual humans who will die" work for private corporations.

Private companies like Crowdstrike would probably love to reveal their analysis however they would be restricted by the actual data owners (e.g. the DNC) and I would guess ongoing government investigations. Plus why blow all of your signatures when they still work? Outside of that, there's tons of data online already regarding Russian government hacking activity: http://researchcenter.paloaltonetworks.com/2016/06/uni…

> Do you think understanding the tools, infrastructure, coding styles, activities, targets of these groups allows them to perform attribution?

No. First they ignored all the other intruders on the DNC network because they didn't fit the Russian narrative, then they took a Chinese tool of choice like X-Tunnel and claimed it's some custom Russian tool, then they forgot to tell us that the actual email exfiltration had nothing to do with the internal intruders - it was just phishing, done from the outside.

These private digital forensics companies act more like PR companies, so trusting them with something you can't verify is silly.

Post reply on HN