Russian government hackers penetrated DNC, stole opposition research on Trump
washingtonpost.com
washingtonpost.com
Is there anyone here who really believes that every major campaign organization since, say, 2004 hasn't been completely owned up? What, you think the people that build the software and IT environments for campaigns --- sites that by design have millions of users with persistent accounts, and thousands of staff members at varying levels of privilege --- are the creme de la creme of software security talent?
Because, sure, I mean, everyone I know in software security and pentesting tells me "my first career choice is to go work in IT for the DNC and the GOP", but somehow along the way Google manages after a mighty struggle to outbid the 70k/year cost-center IT organizations offer for security talent.
If there was any interesting "oppo research" on McCain in the DNC servers during the '08 election, I will bet all the money in my pocket versus all the money in yours that the Chinese read all of it long before everyone on the official CC list did.
No, but I've always considered the competence of the IT people to likely fluctuate wildly from person to person, as I assumed many were politically motivated and donating at least some of their expected compensation level. I think the bigger problem would be in an organization with lots of volunteers, at least at the lower levels, and that gets at least partially rebuilt every few years, operational security is probably very hard to enforce for multiple reasons.
If this was somebody's health records, the organization responsible for the disclosure would be under serious investigation (HIPPA), and throwing down retainers to every law firm in town.
Thomas, is it your opinion that those responsible for securing this data shouldn't be held responsible?
But, more importantly: I meant what I said. The only interesting thing about this story is that whoever hacked the DNC got attributed. You think the GOP isn't owned up?
Security is hard, but I wonder if it's P VS NP?
I'd actually say security research firms have pretty high quality security people, however, and not just the tech giants.
1. http://www.iphoneincanada.ca/news/1password-open-letter-bank...
Sure, the ones you mentioned have the biggest paychecks. But they won't give you indemnity and extended resources to find weaknesses in critical infrastructure. Some people like breaking bigger toys.
I'm really not liking the cream comparison for a couple reasons. One is that I like cream.
Further, that private email servers for public function should never be again. The damage wasn't that a classified email was read; it was that any information was read before it was deemed safe for the rest of the world to read.
It's astounding to me that NSA and DHS hasn't been all over this for years. Although I suppose if all those systems were secure it would be harder for NSA to spy on their owners.
That said, the CIA & NSA probably owned them all up well before, and whomever has them in their pocket will have an upper hand as well. It's not like blackhats and foreign states are the only interested parties.
Insecure online voting would be icing on the cake
If you can't be bothered to vote in person, which I will argue needs to have fewer obstacles in its' own right, then I don't care about your vote.
At various times (Mongols, US Navy vs pirates etc) governments stepped in and provided that protection (for a lesser price) and trade grew.
I'm not too sure how governments can provide protection in the online realm. Perhaps by providing minimal standards of security? (I know the standards exists but enforcing them?)
However, now my iPhone is FBI-resistant, and public keys are fairly easy to share, it seems that secure peer to peer communication is feasible.
So the shape of a more secure, bandit free internet is clearer - hardened mobile devices, and much much stricter standards that are enforced, but it seems an odd new world.
For example, filtering out some important emails, with a goal of hamstringing the organization.
Also... The older I get, the more I realize that adults are just kids with very fancy tree houses. MY treehouse doesn't have rats. Get your leaders from here, not from there.
We have the info about how long were they inside of the network, we have some basic idea about how they are discovered to be connected to Russia (basically groups were previously linked to Russia, and now they were probably discovered by analyzing the code style and/or by re-using some of the code), we got to know how the incident response went, we discovered that they used 0 days targeting Windows, that they masked their traffic as legit Windows services, that they have created some kind of pattern analyzing tool that analyzes the code they got on every machine so they could detect if the attackers try breaching into the system again...
I'd say that this is a pretty hefty amount of information we got from a single article when it's not really a post mortem by the company, but an article on Washington Post.
Or in other words: 说话像一个男人谁不说第二语言
I think democracies are more at risk at this kind of thing because they have real elections and the data mined during elections is important. Its managed by a non-profit political party and as such usually has lax security.