Live data from Hacker News

Critiques of the DHS and FBI’s Grizzly Steppe Report

robertmlee.org

61–70 of 114 posts

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#61

Earlier quoted context omitted.

That's right, I was one of those confused people. I assumed this would be the WH presenting what evidence they have. Sooo... still no public evidence that Russia leaked the DNC and Podesta's e-mails?

Read the original CloudStrike report. Not the government report but the private security firm report. The government report is really just a restatement of that report. You don't track hackers for a decade to suddenly be wrong because of a governments political stance.

The CrowdStrike report, and subsequent interview in Christian Science Monitor of CrowdStrike CTO Dmitri Alperovitch [1], stated in June 2016 that they had low to medium confidence that the Russian government was involved with either Russian group detected.

The groups haven't changed; why are we so certain in December of Russian involvement that we're willing to sanction, if we knew everything we needed to know in June? The only evidence that they are associated with the government is a claim by FireEye that they "work during normal Russian business hours" of 8am-8pm, and that their targets (known targets I should say) would be of strategic importance to the Russian government - I bet if you asked any hacker in any country whether they'd like to hack the US government, they would tell you hell yes.

There are two possibilities here: 1, the US government is drawing this conclusion and imposing sanctions based on weak circumstantial evidence or 2, they have actual evidence but won't even hint at what it is. Even during the Iraq WMD debacle (which this ordeal is drawing heavy comparison with) they said they had satellite photos.

[1] http://www.csmonitor.com/World/Passcode/2016/0615/Meet-Fancy...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#62

Earlier quoted context omitted.

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government…

"it's an insurance company or government contractor getting software from an individual or a company with nine employees." The good news is high-assurance systems have been built with smaller teams than that. We also have cases like Bernstein's where one person builds all kinds of stuff with provably better security using a bit of brains and methods that work. We also have tools like SPARK for static systems and Rust…

Oh absolutely, it isn't that small teams can't create secure software, it's that product liability isn't the way to do it. Because when the lawyers come for the bad coders they just turn their pockets inside out and then go back to writing bad code, while all the HMOs carry on using OpenSSL and vulnerable XML parsers.

> Doesn't solve the DDOS problem which can also be used for extortion, interfering with government operations, etc. My approach targeting root cause handles that, too.

Can you be more specific about your DDOS solution?

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#63
post #21

So it was just spearfishing, the poor man's hacking technique. The techniques that NSA and MI6 use are far more advanced. Taking advantage of the networking equipment and injecting traffic.

So this document was written by security professionals. It's intended for an audience of security professionals. We read it and say, "wait a minute, this is basic script kiddie stuff, this is how the Russian intelligence services operate?" - the breathless description of how advanced the basic tactics are is something I would expect from a security firm who trades on fear. Maybe the unspoken message here is "it's just script kiddies." After all, a major political party is a hell of a get, especially with the amount of dirt in there.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#64
post #33

Still lacking any evidence that voting machines were hacked or any part of the electoral process was hijacked. The worst damage? Emails related to the actual rigging of the Democrat Party primaries and the collusion of the media with the Democrat party. Its very hard for me to believe that a state actor is behind such seemingly altruistic actions. Voters saw the worst of Trump and Clinton and choose the lessor of two…

First off, while there was an irrefutable bias in the DNC during the primaries, and shitty moves made against Sanders as a result of that bias, that is not the same thing in any way to rigging the primaries. That's a much stronger allegation with no evidence I've yet seen provided. The DNC was deplorable and idiotic in its rejection of Sanders and active working against his campaign. But the primaries were not rigged…

>leaks that targeted a single party and candidate?

Is there any evidence to suggest that the DNC was singled out for attack? We should be careful not to fall victim to pernicious media spin. The claims laid out in the Grizzly Steppe report are very specific:

1. In summer 2015, an APT29 spearphishing campaign directed emails containing a malicious link ...

2. ...to over 1,000 recipients, including multiple U.S. Government victims.

3. In the course of that campaign, APT29 successfully compromised a U.S. political party.

We know in retrospect that the compromised party was the DNC, but the claims presented do not indicate that the DNC was the only target. Although this is how good boys and girls are supposed to interpret the evidence, since many news media sources are spinning this as "Russia hacked the electoral process for a Trump victory", we can't start from that conclusion and work backward. Claim #2 in particular seems to indicate that the attack was broad and indiscriminate, with government and non-government targets alike.

Consider also what isn't said in this report. If they could say that the hacker groups singled out the DNC for attack, they would say so. That no such claim is made indicates that the authors know otherwise.

Finally, we have this:

4. In spring 2016, APT28 compromised the same political party, again via targeted spearphishing.

This is a separate group from the one in the previous claims. What they do not speak to is the question of who else was attacked or compromised.

Intelligence and counterintelligence is an endless game of cat and mouse that has been played for millenia. Any indication you can glean on who the next leader of the world's #1 power will be is priceless information, so none of us should be the least bit surprised that any of this is going on or that political parties would be the target of hacking attempts in an election year, by Russia, or any other nation.

Russia putting a targeted hit only on the DNC to swing the election specifically in favor of one candidate is an extraordinary claim and this report doesn't clear the bar IMHO. A far more likely hypothesis is that all renowned political organizations are a target for hacking at all times, and the DNC just had shitty security and got compromised. Too bad. Maybe turn on 2FA next time, and stop storing Top Secret material on your home server. (Even my little unknown personal server gets thousands of login attempts from China every day.)

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#65

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

While there's no harm in filing additional FOIA requests, let's also add some deductive reasoning to the mix. Is this consistent with Russia's actions in other countries and contexts (as well as their own)? Yes. http://warontherocks.com/2016/11/trolling-for-trump-how-russ...

Have individuals close to the Kremlin strongly implied they had a role in this and have senior Russian officials stated clearly that they had contact with the Trump campaign during the election? Yes. http://www.haaretz.com/world-news/u-s-election-2016/1.752386

Did Russia even object today on the grounds that the allegations about their role were false? On the contrary, they were practically doing a victory lap.

There are plenty of debates still very worth having about whether the actions taken today are appropriate, whether a hostile stance towards Russia is merited, etc. But I've seen enough to convince me that Russia was engaged in an information operations campaign to cast doubt about the U.S. election and help Trump on the margins.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#66
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government…

For every piece of softare they buy from a 9 person ISV they probably run tens of millions of dollars of software from IBM, Oracle, Microsoft, Adobe, etc. Or custom made software developed by one of the large shops. And that's going to be the vast majority of the attack surface.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#67

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

Much of the evidence you'd be looking for is specifically exempt from FOIA.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#68
post #10

This is theatre. Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use produ…

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government…

[deleted]

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#69

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

This post is from a brand new account, and it only adds FUD to the conversation - it adds no knowledge and has nothing to back up its claims or questions.

It's a pattern that should look familiar by now ...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#70
post #33

Still lacking any evidence that voting machines were hacked or any part of the electoral process was hijacked. The worst damage? Emails related to the actual rigging of the Democrat Party primaries and the collusion of the media with the Democrat party. Its very hard for me to believe that a state actor is behind such seemingly altruistic actions. Voters saw the worst of Trump and Clinton and choose the lessor of two…

First off, while there was an irrefutable bias in the DNC during the primaries, and shitty moves made against Sanders as a result of that bias, that is not the same thing in any way to rigging the primaries. That's a much stronger allegation with no evidence I've yet seen provided. The DNC was deplorable and idiotic in its rejection of Sanders and active working against his campaign. But the primaries were not rigged…

>The DNC was deplorable and idiotic in its rejection of Sanders and active working against his campaign. But the primaries were not rigged.

But they didn't do any of that either. It's amazing how out of control this narrative has gotten. And this is precisely why we can't justify these sorts of intrusions so close to an election, the stories become such distorted pictures of reality which is antithetical to to rational decision making.

Post reply on HN