WADA Confirms Attack by Russian Cyber Espionage Group
wada-ama.org
wada-ama.org
Seems like they imply the Russian state is behind this but they don't explicitly say it, probably because they have no proof, as always. What trust do I have in WADA when they clearly have a bias against Russia?
APT28 is pretty obviously Russia, due to character encodings in the files, timestamps, etc. etc. etc. If I'm not mistaken, the attacks almost always also leak the location of a particular Russian government building. The technical evidence for their previous attacks is so extensive it seems they want to be caught.
They're who the Russian government sends when they want to make it obvious it was them to other governments, but don't want to start an open conflict.
“WADA has been informed by law enforcement authorities that these attacks are originating out of Russia,”
A quick google search of Fancy Bears (the name the hackers have used on their release page) links them to APT28:
"APT28, as it's known by FireEye/Mandiant, is also called Tsar Team by iSIGHT Partners, Sednit by Eset, Fancy Bear by CrowdStrike, and Operation Pawn Storm by Trend Micro. This attack group goes after NATO, Eastern European government and military agencies, defense, and Russian adversaries, the report notes."
WADA didnt investigate, the investigation is done by competent security analysts, and whilst I am aware that anything is this sphere is possibly misinformation/propaganda from both sides, it would seem evident that after Russia were sanctioned for doping, then hackers release data on suspected US doping that there is an easy link to make. And there is very little to be gained by another adversary trying to make trouble between the US and Russia with such an attack.
If anything WADA and the IOC have been far too lenient with Russia given the extent of evidence.
The quote from the article:
"WADA has been informed by law enforcement authorities that these attacks are originating out of Russia,” he continued."
1) Focus on US athletes
2) Bear mentioned in name of hackers
3) Focus on sports doping (which Russia was recently found guilty of)
Now I know that many hacks and hackers will obfuscate the trail to them as much as possible but this is a fairly basic attack with little in the way of real impact as a result of the releases. It was obvious even to a non-security professional that the most likely culprits were russian nationalist hackers.
For instance: the HRC/DNC attribution started with CrowdStrike (whose executive team is not exactly HRC-friendly), and concurrences were later released by some of CrowdStrike's competitors.
Attribution is obviously deeply imperfect. But it's not as simple as "this sure seems like Russian and there's some Cyrillic so let's call it a day".
Attack tools are deployed cliquishly, and different groups have different tradecraft; they leave fingerprints.
To do this kind of fingerprinting one needs to be able to inspect a large chunk of traffic of the whole Internet. I thought that was not really possible for private companies (except maybe a few).
How do you fingerprint malicious executables if the traffic is encrypted?
I suppose attempts to cover your tracks and to impersonate other groups are common. Are they feasible?
By the time something like Crowdstrike or FireEye is seeing an executable, it's already been decrypted.
It's totally possible to impersonate another hacking group, but you have to know a lot about their tradecraft to do so with any fidelity.
Compartmentalization is one of the strongest defense tools we have. For example, with the icloud leaks an attacker was able to gain access to all the data in a single strike. If it's true that Apple can no longer decrypt user's icloud data, an attacker now needs to hack people one-by-one. Hacking takes time and effort, and a one-by-one payoff may make it that hacking icloud is no longer worth the effort. Users are safer, even though they are still theoretically vulnerable.
A lot of people are stepping up to the plate to offer stronger security on digital systems. (Qubes, for example. Let's Encrypt, for example). If choose to take security seriously, hacking will become harder, the rewards will plummet, and the world will be safer.
...security will become less of a concern, hacking will become easier, the rewards will rise, security will be taken more seriously...
There was an issue with allowing brute force attacks which was fixed. But all the publicised hacks were to do with individual accounts being compromised.
I think in one case the "secret questions" used to reset accounts was actually asked during a media junket by a fake reporter.
No, they likely wouldn't fire someone unless they specifically had controls in place for that (eg. security clearance area). People "tailgate" at companies all the time.
http://www.pacifict.com/Story/
In addition, the "value" of these records shot up dramatically once Russia was banned. The security was not stepped up to match.
The real problem is the fact that managers DO request passwords, access control changes, etc. via email, and they do it more often than people get phished. So, people learn to give out information rather than protect it.
I think a more constructive reaction would be to say that phishing training is important and should be implemented or revised. In addition technical solutions should be investigated. Perhaps some of the infallible people who never fall for phishing attacks can automate part of their brilliance for the mere mortals.
What has leaked since 2012 that we won't know about until 2020?
I don't think it's necessary a problem that more current leaks are state sponsored.
Firstly, that's their job.
Secondly they're open about what they[1] are doing and are on a recruitment drive.
Thirdly, the more leaks that are obviously state-sponsored suggests sites are better protected against johnny hacker and his downloaded scripts.
[1] By "they" I mean the agencies who frequently pop up here with articles about how they're recruiting because of an ongoing cyber-war. (And yes, the word cyber is cringeworthy but it's the word used.)
the game is to sell the data to any nation that bids the highest
http://www.lse.co.uk/AllNews.asp?code=kwdwehme&headline=Russ...
It's amazing that people are still being phished successfully.
What's up with hackers and their English grammar? Shouldn't it be doping American athletes? This reminds of the adjective-word-order rule and Tolkien's "green great dragons" story. [1]
More coverage over on the NYTimes: http://www.nytimes.com/2016/09/14/sports/simone-biles-serena...
We see that athletes are allowed to take some very strong and beneficial drugs and its not doping.
I had always pictured that "clean" athletes were not eating OxyContin or required vast amounts of asthma medication to make it through the day. (This last part if from a different disclosure).
I think an adjustment to the current regiment would be that each athlete disclose exactly what type of drugs they are consuming.
What is doping and what is not is not arbitrary but it certainly changes over time.
As far as sports drugs, I honestly don't care about it, not being someone who watches or participates in any of them. But I strongly suspect that we'll see the "ok"/"not ok" lines being drawn towards maximizing viewers, perhaps with a sop towards athlete-health down the list somewhere.
I also predict that conversations about doping will sometime soon indirectly put enough pressure on the US NFL to cause it serious problems about player brain injury. It is hard to worry about player health regarding drugs and ignore the people broken by other aspects of the games.
Yes, I'm Russian. Yes, I live in Russia. And Yes, I like my country.
You are likely on solid ground accusing the US government of using Russia as an excuse.
When you accuse WADA of being "pro-US"; however, you lose all your credibility.
There is documents, that WADA allowed Serena Williams to take oxycodone and hydromorphone (opioids), prednisone, prednisolone, and methylprednisolone. Her sister Venus Williams was allowed to take prednisone, prednisolone, triamcinolone and formoterol. This is very strong grungs, they should lay in hostpital if they need then for living (owning some of this drugs will cause a 14 years sentence in EU). There is also info about Simone Biles and Elena Delle Donne and they promise more :)
In addition many attacks have been attributed to China in the period you have mentioned.
It is incredibly likely that US based hackers have attacked both Russian and Chinese targets however both these governments would cover up these through control of state media to prevent what they would see as embarassment. Western media will report on hacks regardless of which government had done them if they were aware of the hack occuring.
No problems with liking your country but blindly believing everything put out by state controlled media does not have to be part of that.
Also, that's how media works these days. One press release to Reuters, and all the newspapers publish the same "facts".
That being said, I think it's fairly plausible that some actor with relations to Russia would publish documents like these.
Several years ago I used to support eastern position in all situation in Russia. But after accusation against Russia with no proves started to appear I become quite disappointed in the US...
http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-...
Especially page 60 onwards is useful.