But I do have something to say about the attribution here:
A very common sentiment on HN is that the US intelligence community has decided that Russia has a motive to hack the US, and spends money on offensive security, ergo "it was probably Russia".
That is not how attribution works. Officials (and the firms they hire) are working with vastly more specific fact patterns than the news stories about these incidents convey. They are matching Russian means, motive, and opportunity at a far more precise level of detail than is commonly reported.
The major attribution firms --- FireEye/Mandiant, Crowdstrike, &c --- have for years prior to these breaches been collecting huge volumes of information from a pretty significant fraction of the Global 2000, who deploy their tools as part of their anti-malware strategy. That's the entire idea behind Crowdstrike†: you deploy their agents, and they hoover up IOCs and malware samples from around the world and analyze them. These firms have been involved in thousands of compromises we've never heard of, and have staffed large teams of experts (both FireEye and Crowdstrike have gold-plated reputations in the infosec community) to analyze and develop signatures from that information.
The DNC compromise is analyzed in terms of IOCs --- network traces of command and control channels, captured backdoor and malware samples, vulnerabilities employed, IP addresses of staging servers --- and those IOCs are matched to previous compromises. When DHS says they're working with a "high degree of certainty" about who's behind the compromise, they're saying that they've matched the compromise to a set of IOCs --- many of which are not public --- that are tied to previous known Russian compromises.
That doesn't mean everyone involved here --- multiple departments of the US Government, the executive branch of the government at the very highest level, and several of the largest security firms in the US --- couldn't be lying. It could all be a conspiracy. If it was, it would be the largest conspiracy ever carried out by the US government. But I guess that could be what happened!
† Crowdstrike, by the way, is run by a conservative Republican.