Earlier quoted context omitted.
Some attributions of the attack came from private security firms, not from intelligence community. Can their analysis be released or they have ongoing interests too? It would be interesting to know if espionage activities are privatized in USA and "actual humans who will die" work for private corporations.
Private companies like Crowdstrike would probably love to reveal their analysis however they would be restricted by the actual data owners (e.g. the DNC) and I would guess ongoing government investigations. Plus why blow all of your signatures when they still work? Outside of that, there's tons of data online already regarding Russian government hacking activity: http://researchcenter.paloaltonetworks.com/2016/06/uni…
Dear Obama, from Infosec
71–80 of 91 posts
Re: Dear Obama, from Infosec
#72Re: Dear Obama, from Infosec
#73Earlier quoted context omitted.
Did that private security publish any proof?
What sort of proof are you looking for? If you're looking for firewall logs or hard drives with definitive proof that malware on certain machines was linking back to particular servers then you're out of luck. However Crowdstrike, the firm that the DNC used to investigate the intrusion, published a report that shows some of the code used and other IOCs from the attack [0]. A security firm like Crowdstrike would have…
Re: Dear Obama, from Infosec
#74And realistically, the public is not likely to be surprised by it either. It's barely 3 years since we found out the NSA spied on the United Nations, its own allies, and the Pope. And every day the news is full of western governments wanting to legislate back doors into our iPhones so they can read all our emails. Did anyone think notorious bad guy Putin would have his spy agencies twiddling their thumbs thinking "no, we mustn't - it'd be wrong"?
"Foreign government tried to influence our election" has probably lost a lot of its sting too, since Obama weighed in on the Brexit referendum, and every world politician and their dog weighed in on what they thought of Trump.
Honestly, I don't think much of the public cares how Podesta's emails got released, any more than they care how Trump's open-mike tape got released. And embarrassment aside, I doubt the public thinks any of the leaks had much impact on the result. I imagine much of the public muttering "Trump's a letch, the Democrat higher-ups and parts of the media have a love-in, and politicians think of the public as a mixture of easily-led minions and ignoramuses. Yup, we'd pretty much guessed that already..."
I think the "news" in this is why a famously competent, articulate, and measured president (Obama) is being a bit ham-fisted in his response, suddenly upping the reaction quite late in the day.
If I can theorise for a mo -
The Democrats, and parts of the Republican party, are still coming to terms with the surprise that they didn't win, and therefore believe that surely they will be back in power in four years' time. So they want to make it as hard as possible for Trump to deviate from longstanding policy in the meantime.
Moving to taking a hard diplomatic line on China and a soft line on Russia (rather than the other way around) would be a huge strategic shift from past policy, that would be quite hard to unpick. For nearly 40 years, the US strategic position has been to reach out to China, and that the US's chief strategic opponent has been Russia.
I wonder if the Democrats and GOP are starting to come to grips with where Trump's views really are a bit of a departure from the recent past:
- he's decided many of the things the US and Russia compete on these days aren't especially important to the US's interests, so it's not worth considering them the US's biggest opponent
- he's decided that the way to argue/posture with China on points of difference is to use the economy (eg, threat of tariffs) and more belligerent diplomacy (eg, threat of recognising Taiwain), rather than the military (eg, Freedom of navigation operations)
- he's decided the US should stop trying to act as an altruistic international arbiter, and instead attach unswerving value to being the US's friend (eg, moving embassy in Israel to Jerusalem)
And of course, he seems to think the US is in a position where it can be a bit of a dick about things if it wants to. For most of us, we have to be nice people to work with or people won't work with us. But I guess if you're the US it's quite hard for people to say "well I won't work with the world's biggest economy then".
Re: Dear Obama, from Infosec
#75Earlier quoted context omitted.
> It's much more interesting to discuss the shared conclusion was formed that "the Russians" were trying to throw the election to Trump And it's why we need proof. Guessing a password or phising it can be a one man operation.
I appreciate the sentiment that anyone can phish or password guess, but even a cursory glance at infosec reports shows there was an operation targeting the DNC that was far more sophisticated than a one man job. Firstly we know that that Podesta's account was targeted by a phishing email with a bit.ly link [0]. We have proof the bit.ly phishing link in this email was clicked twice in March [1], and his wikileaks dump…
Re: Dear Obama, from Infosec
#76It's so bizarre to me how big this story has become only now when the DNC hacks themselves were done back in June. It's certainly hit a fever pitch since Trump's election, but I can't tell if that's from his tweeting and provocation, or from the Democrats angst at losing the election and trying to save face.
Regardless, compared to China hacking us and stealing our fighter jet plans or the data breach of 18 million personnel records from OPM, compromising the DNC and releasing some authentic but mildly embarrassing emails seems so... minor, I guess. Every time people say "hacking the election" it makes me so frustrated since it minimizes the very real fear of actual election hacking the more we're moving to electronic voting machines, that Bruce Schneier talks about. It's also no surprise that half[0] of Clinton voters believe "hacking the election" means that Russia actually fucking tampered with the vote tallies now.
Surely any impact of the DNC email release months ago was minor compared to say, Comey re-opening the Clinton case right before the election. And I dunno, does an article in the BBC or The Economist count as foreign influence? What about the Snowden leaks to The Guardian?
The evidence that APT28/29 were in the DNC servers is moderately compelling, I think. I can't find the data on the connection between APT28/29 and GRU/FSB, though. In any case, it's clear Russia could have not left a trace if they were so inclined. Maybe they didn't think it was such a big deal so they were a little sloppy? Certainly, a priori, it's hard to imagine the amount of attention releasing DNC and Podesta emails would have gotten.
[0] https://today.yougov.com/news/2016/12/27/belief-conspiracies...
Re: Dear Obama, from Infosec
#77Earlier quoted context omitted.
Assange strongly implied that the emails were leaked by Seth Rich. Not sure if I believe that though, since it seems that Assange would have proved it by now if it were true. Maybe he's withholding the proof as leverage, or maybe he's lying. I do trust Assange much more than the CIA though.
>I do trust Assange much more than the CIA though. But do you trust Assange more than the 17 US intelligence agencies? And the actual president? And members of congress (including many Republicans who would directly benefit from any intelligence pointing another way)? At this point it's getting close to Assange vs the world. Even Trump won't directly say the Russians weren't involved anymore, he's just muddying the w…
Yes. Does that really surprise you?
Re: Dear Obama, from Infosec
#78Earlier quoted context omitted.
I think he's saying between the lines that his source is a insider, and it's either a leak or an internal hack. That's the only way he could have any reliable information at all about the source.
Assange strongly implied that the emails were leaked by Seth Rich. Not sure if I believe that though, since it seems that Assange would have proved it by now if it were true. Maybe he's withholding the proof as leverage, or maybe he's lying. I do trust Assange much more than the CIA though.
My money's on Charles Delavan. Nobody's that stupid: https://wikileaks.org/podesta-emails/emailid/34899
Re: Dear Obama, from Infosec
#79Earlier quoted context omitted.
What sort of proof are you looking for? If you're looking for firewall logs or hard drives with definitive proof that malware on certain machines was linking back to particular servers then you're out of luck. However Crowdstrike, the firm that the DNC used to investigate the intrusion, published a report that shows some of the code used and other IOCs from the attack [0]. A security firm like Crowdstrike would have…
Proof of any damage or an apparently hostile action that could cause damage, that was confirmed to be done by Russian state actors. Crowdstrike report shows only signs of intrusion, but you would not expel 35 diplomats for a radar touching your airplanes, right?
I'm not sure I get your analogy, but no, I wouldn't expel anyone for "radar touching my planes", but in this case that's the equivalent of browsing the DNC website. If someone had broken into my airforce base, stolen security badges to get into other airforce bases, was photographing planes and stealing and leaking blueprints then you better believe I'd take action
Re: Dear Obama, from Infosec
#80Bloody Hell. I find it very frustrating that intelligent people don't seem to follow through their thought process here. The intelligence community will never be able to release enough information to satisfy people. The information will either be so non-specific as to be useless ("we had spies who told us" - would anyone here believe that anymore than they do now?), or so specific it will damage ongoing interests ("W…
It's simply not true that "the intelligence community will never be able to release enough information to satisfy people". A few days back, the same author wrote[0]: > On the other hand, if they've got web server logs from multiple victims where commands from those IP addresses went to this specific web shell, then the attribution would be strong that all these attacks are by the same actor. All the FBI/DHS have to d…
The attribution issue was whether it was "the Russians".