Live data from Hacker News

Critiques of the DHS and FBI’s Grizzly Steppe Report

robertmlee.org

71–80 of 114 posts

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#71
post #50

Earlier quoted context omitted.

First off, while there was an irrefutable bias in the DNC during the primaries, and shitty moves made against Sanders as a result of that bias, that is not the same thing in any way to rigging the primaries. That's a much stronger allegation with no evidence I've yet seen provided. The DNC was deplorable and idiotic in its rejection of Sanders and active working against his campaign. But the primaries were not rigged…

I agree not rigged, but giving Hillary debate questions in advance comes pretty close. In my opinion, the DNC emails and the Trump "grab 'em" tapes are similar -- you can argue that it's private material that should've stayed that way, but you can't argue that the material didn't reveal helpful truths about the candidates. Finally, a recent poll found 50% of Democrats think that Russia tampered with the vote tallies…

I guess you conveniently forget where Sanders said his emails would have the same sorts of messages from Donna?

http://thehill.com/blogs/ballot-box/presidential-races/30386...

>"If Bernie Sanders had been the nominee of the party and the Russians hacked my emails instead of John [Podesta]’s, we'd be reading all these notes between Donna and I and they'd say Donna was cozying up to the Bernie campaign. This is taken out of context. I found her to be a fair arbiter, I think she did a good and honest job."

Turns out they weren't even debate questions:

http://www.nbcnews.com/card/top-sanders-aide-defends-dnc-cha...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#72
post #37
post #33

Still lacking any evidence that voting machines were hacked or any part of the electoral process was hijacked. The worst damage? Emails related to the actual rigging of the Democrat Party primaries and the collusion of the media with the Democrat party. Its very hard for me to believe that a state actor is behind such seemingly altruistic actions. Voters saw the worst of Trump and Clinton and choose the lessor of two…

How on earth did a leak of DNC emails, but no corresponding RNC leak, help people figure out the lesser of two evils or provide a level playing field? Seems obvious that leaks assisting the pro-Putin candidate were not altruistic.

Level is relative here. But remember DNC candidate had 6 or more multibillion dollar mass media corps actively supporting their candidate, POTUS was campaigning for them, had a top strategy team, support from tech giants, Wall St., huge contributions from countries like Saudi Arabia and so on. A few emails leaked I would say still wasn't a level playing field but it was close?

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#73

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

This post is from a brand new account, and it only adds FUD to the conversation - it adds no knowledge and has nothing to back up its claims or questions. It's a pattern that should look familiar by now ...

I'm not perpetuating any particular agenda other than that people should request enough information to form their own opinions. Throwaway accounts for political conversations are an occupational necessity for my line of work.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#74
post #12

Earlier quoted context omitted.

I question the importance of attribution on this issue. The Office of Personnel Management hack seems far worse than this report's conclusions, but there was a fraction of the outrage. Sadly, the problem is not confined to one state actor. INFOSEC is systemically broken and although the solution is starring Congress in the face, I suspect software/hardware lobbyists will prevent meaningful legislation.

What is the solution?

Tort reform that extend products liability to sodtware and hardware developers and their partners. The problem is too complex for corporate or individual end users to manage. This plus retooling NSA through SBA conduit to provide protections to small businesses, law firms, health providers.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#75
post #67

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

Much of the evidence you'd be looking for is specifically exempt from FOIA.

Yes, there are specific exemptions, but a properly worded FOIA request should be able to maneuver around them. For example, Exemption 7[1] would protect "from disclosure information which would reveal techniques and procedures for law enforcement investigations or prosecutions or that would disclose guidelines for law enforcement investigations or prosecutions if disclosure of the information could reasonably be expected to risk circumvention of the law," but a properly worded request would seek the information that those techniques uncovered, not the techniques themselves.

1: http://www.foiadvocates.com/exemptions.html

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#76

Throwaway because I work in a related field. This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government acco…

While there's no harm in filing additional FOIA requests, let's also add some deductive reasoning to the mix. Is this consistent with Russia's actions in other countries and contexts (as well as their own)? Yes. http://warontherocks.com/2016/11/trolling-for-trump-how-russ... Have individuals close to the Kremlin strongly implied they had a role in this and have senior Russian officials stated clearly that they had co…

Russia has denied involvement with this incident in the past[1].

I would encourage considering applying the same standard that we would apply to a trial by jury. Simply indicating that someone is a repeat offender, and would have reason to commit an offense again, does not itself meet a standard of evidence of actually committing that offense.

1: http://www.politico.com/story/2016/12/kremlin-denies-putin-d...

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#77
post #67

Earlier quoted context omitted.

Much of the evidence you'd be looking for is specifically exempt from FOIA.

Yes, there are specific exemptions, but a properly worded FOIA request should be able to maneuver around them. For example, Exemption 7[1] would protect "from disclosure information which would reveal techniques and procedures for law enforcement investigations or prosecutions or that would disclose guidelines for law enforcement investigations or prosecutions if disclosure of the information could reasonably be expe…

You are not going to be able to use FOIA to discover national security secrets, no matter how carefully you word the requests.

By all means, try, but you're trying to use FOIA to uncover literally the exact kinds of information the law excludes from FOIA.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#78

Earlier quoted context omitted.

> Were Congress to expand tort law to mandate standards and consequences similar to products liability regulations for other products, then the attack surface available to state and non-state actors would meaningfully shrink. The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government…

For every piece of softare they buy from a 9 person ISV they probably run tens of millions of dollars of software from IBM, Oracle, Microsoft, Adobe, etc. Or custom made software developed by one of the large shops. And that's going to be the vast majority of the attack surface.

> For every piece of softare they buy from a 9 person ISV they probably run tens of millions of dollars of software from IBM, Oracle, Microsoft, Adobe, etc. Or custom made software developed by one of the large shops. And that's going to be the vast majority of the attack surface.

Vulnerabilities are not proportional to software price. That's the whole problem. IBM software is very expensive and complicated but you don't see a lot of CVEs. OpenSSL costs no money and much trouble.

Yet you have projects like OpenSSH that are free, by all accounts have a strong security record, but once or twice a decade there is a serious vulnerability. And because of how and where it's used, liability for that would destroy them.

Meanwhile Adobe would sooner stop distributing Flash Player than fix it, and all this does nothing about the admin who leaves the database server open to the internet with the default password.

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#79
post #77

Earlier quoted context omitted.

Yes, there are specific exemptions, but a properly worded FOIA request should be able to maneuver around them. For example, Exemption 7[1] would protect "from disclosure information which would reveal techniques and procedures for law enforcement investigations or prosecutions or that would disclose guidelines for law enforcement investigations or prosecutions if disclosure of the information could reasonably be expe…

You are not going to be able to use FOIA to discover national security secrets, no matter how carefully you word the requests. By all means, try, but you're trying to use FOIA to uncover literally the exact kinds of information the law excludes from FOIA.

This is predicated on the evidence, should it exist, of a Russia-backed security incursion being classified a national security secret. While such a hypothetical claim would have questionable value, would it be worth classifying a bit of information, say, like "the attack ingress point was IP address x.x.x.x, which is owned by Russian military?"

Re: Critiques of the DHS and FBI’s Grizzly Steppe Report

#80
post #77

Earlier quoted context omitted.

You are not going to be able to use FOIA to discover national security secrets, no matter how carefully you word the requests. By all means, try, but you're trying to use FOIA to uncover literally the exact kinds of information the law excludes from FOIA.

This is predicated on the evidence, should it exist, of a Russia-backed security incursion being classified a national security secret. While such a hypothetical claim would have questionable value, would it be worth classifying a bit of information, say, like "the attack ingress point was IP address x.x.x.x, which is owned by Russian military?"

Of course it is classified. And of course no state backed actor is going to use a military owned IP.

And there won't be one single source of evidence which points to it, it will be hundreds of small circumstantial points which taken together point to the conclusion.

Those won't ever be released because they will give away sources and techniques.

Post reply on HN