And Bitly links ain't it.
And Bitly links ain't it.
It started with the WashPo story[0] on the DNC hack and the CrowdStrike attribution (there were some good rebuttal stories at that time, I think they have changed their minds) and now you have 10-15 different sources kicking this story further down the road each day.
That's how journalism is changing - rather than having 2-3 investigative reporters at one newspaper do a one year investigation then publish their in-depth series (pass go, collect pulitzer etc.) the large stories are now often broken down piecemeal and worked on in public over time.
It means many more experts can work on it and the stories are better for it - but the downside is that they're very difficult to keep track of (the only way is Twitter or reddit, IMO - and the netsec reddit is horrible with approving stories). If you come into it part way you can feel lost because the writers assume you've been following along (which is a mistake)
I've honestly probably read 100+ stories on this thread, likely more. At this stage you need to bring the thread back together yourself with Google or starting with the Wikipedia pages[2][3]
[0] https://www.washingtonpost.com/world/national-security/russi...
[1] https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...
[2] https://en.wikipedia.org/wiki/Democratic_National_Committee_...
[3] https://en.wikipedia.org/wiki/2016_Democratic_National_Commi...
My personal favorite part of the article, couple paragraphs after that quote:
"We are approaching the point in this case where there are only two reasons for why people say there’s no good evidence,” Rid told me. “The first reason is because they don’t understand the evidence—because the don’t have the necessary technical knowledge. The second reason is they don’t want to understand the evidence.”
Conversely, there are ample reasons for the intelligence community to pin it on their historic enemy, rather than the more likely Murder on the Orient Express scenario where absolutely everyone paying attention hacked every grotesquely unsecured setup, or the insider-threat scenario.
Hey, whatever happened to Seth Rich?
And if the "intelligence community" isn't actively targeting insiders at least as a pure pen-testing contingency, why aren't they?
Well, what if that evidence was gathered via extra-legal means?
I feel like given the amount of info necessary for security clearance & the fact most politicians live and die with their phones means the intelligence agencies have them all pretty much dead to rights.
What if the source is an actual human asset within the malicious organization?
What if the source is a compromised server of the Russian organization?
What if the source is a legal wiretap on a bad actor?
That's why eg in World War II, the allies only acted on Enigma intercepts if there was a plausible alternate source.
So my inference is that they're lying about having sufficient evidence to definitively point at the rooskies, or they're being reckless with sourcing.
"US government took the rare step of publicly pointing the finger at the Russian government, accusing it of directing the recent string of hacks and data breaches. The intelligence community declined to explain how they reached their conclusion, and it’s fair to assume they have data no one else can see."
So, if the evidence exists (and I personally believe it does, though I also understand those who disagree) it hasn't been made public.
Not to sound arrogant, I really like to know some reasoning behind it. I'm even more curious to understand if you are an American citizen.
With the lack of any publicly available evidence, I guess the reasoning behind it largely comes down to trust. You either trust the government on this or you don't. On this issue, I do, but again, I wouldn't fault you for disagreeing. If I had to elaborate, I'd say:
The cost of being caught in a lie is sufficiently damaging to the organization that makes the claim. What benefit do they gain by making such a claim? does the risk of getting caught in a lie outweigh the benefit? I just don't see the lie as being a risk worth taking.
There have been many times in the past where 'blaming it on Russia' could have been politically convenient. If you do it too often, you become the boy-who-cries-wolf. Would the risk of reputation loss outweigh the benefits gained by telling the lie? again, I don't see the lie as being worth the risk.
Not losing the most important general election of this first half-century?
This might actually explain KGB/FSB's apparent preference for Trump: the enemy of one's enemy...
I only intended to point out that various agencies do have interests in the outcome of elections.
Before the first debate Trump was down by 1 point (but trending upward) according to the RealClearPolitics average. That's within the margin of error on even the largest polls, meaning he was basically tied with Hillary. Then the Alicia Machado story broke at the end of the first debate, and his poll numbers went down to about -4. Then the bus tape came out, and he's now at roughly -7. That's well outside the margin of error. In fact, his poll numbers are now at the point where no one has ever won the presidency while being this far down so close to the election. He might still pull it off, but he's got a steep road ahead of him.
So he's gone from basically tied, to the point where he'd need something huge to happen in order to win. The biggest stories in that period of time were Alicia Machado and the bus tape. Most of the polls give detailed demographic breakdowns. He's dropped a little with men, but most of the damage was with women, where he's seen a double-digit loss of support in some polls.
What do you mean if?
Perhaps my original comment was unclear, but I believe the statements made in the article imply the latter.
Many people do not agree, believing that their government (as defined by what they think it should do) is on their side.
It is a matter of trust or distrust by default. Personally, I believe the spirit of the US Constitution is to distrust those in charge.
I for one would really like to see this evidence and I'm very reluctant to just assume these people have it right as they have had it wrong so many times.
Anyway, the sheer fact that a phishing attempt at a personal email accout yielded anything already points to gross incompetence in the government. The miasma of email scandals around Clinton and her friends just keeps on spreading...
I'm not American so I have no skin in the game, but I'm surprised that Trump keeps banging on about the email server. If that (and that someone in her organisation got phished) is the worst you've got on Clinton, I'm glad that you're going to have such a clean president.
Not sure why you feel a risotto recipe is supposed to be critically important to the American public.
I mean, don't we already know to add the broth in a little at a time? Are there really people that dump the entire broth in at once?
Non-partisan outrage and country-before-party are necessary reguardless of the names or affiliations.
We have only a very general statement that does not say anything is actually 'confirmed'. It is speculative, so you could say the intelligence isn't convinced this time either. However, politicians are already spinning it for their agenda. https://www.dni.gov/index.php/newsroom/press-releases/215-pr...
If there actually is evidence, it's not public.
In my opinion, the "RUSSIANS WILL KILL US ALL AND TRUMP IS BEST FRIENDS WITH PUTIN" meme is nothing but a scare tactic to influence older voters who were around during the cold war. Obviously, I could be completely wrong. That's just my cynical opinion.
"Those who are not hopeful, who do not believe in a better future, are not paying attention." --me
Same amount of authority.
"None of this new data constitutes a smoking gun that can clearly frame Russia as the culprit"
The scam was so generic I'm confused why it has to be Russian government vs individuals, but it doesn't matter much IMO.
I think HRC wins this easily, but these scandals won't just go away. There's enough meat in them to fuel 1-2 years of republican attacks. I fear she'll be the most ineffective President of my time.
https://www.reddit.com/r/The_Donald/comments/58j7jn/gentleme...
based on dates in the message, they're likely referring to the hearing on 10/22/15.
Messages are hashed and signed by a private key in the exclusive possesion of the email system, such as gmail. The public keys are published in DNS. This allows anyone to verify the messages are unaltered using widely available tools. It seems this system may have been in place on one of the Exchange servers as well, though the integrity of that key is questionable.
Yes, which is why I consider the keys for the Exchange server questionable, as there is no way to disprove intrusion into those systems.
My claim surrounds gmail.com and the set of emails that passed through gmail.com. I am not aware of an intrusion into Google's systems that would have obtained highly protected keys. This also limits the number of actors who could forge the complete collection of messages obtained from a gmail.com account.
(i.e. the only thing obtained was a password, not system level access.)
If the attachments are BASE64 encoded and part of the MIME source, they should also be protected by the DKIM signature.
As far as any documents obtained from blogspot, I have no assertion to make reguarding the integrity of those message contents. The use a specific cracked version of Office may explain the document summary information not matching the proclaimed nationality of the publisher of the documents on blogspot.
I object to the (sometimes deliberate) conflating of the multiple collections and sources and the attendant implied discrediting of all be ine.
This is a forum that I hope values technical explainations and inquiry, many forums have their own version of reality.
May the truth be known, whoever is damned or praised.
EDIT: some fundraising callers pretty much hang up on me in anger, but a lot are also sympathetic. Not hard evidence, but I have heard a convincing "I understand" often enough to think that a lot of rank and file Democrates are Fed. Up.
One could hope ...
So when people say things like "anyone could have carried out this attack" or "these systems are so insecure it could have been anybody who did it", they're not actually addressing the argument.
Whole thing makes me really wonder if using insecure email in government is a good idea...
Unfortunately it has the strongest network effect at the moment, and no one's come up with a way to get everyone to use encryption/cryptographic signatures yet.
http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.454...
Almost all older or modern ones build email processing capabilities onto guards optionally with a proxy on client's side to integrate with common, mail client. Here's an article describing what a guard is along with some examples government uses today:
https://en.wikipedia.org/wiki/Guard_(information_security)
Firewalls are knockoffs of guards that were created after businesses and much of government rejected high-assurance systems since they didn't have development pace and [insecure] features of low-security competition. Firewalls were cheap, fast, constantly added features, and totally left off the whole "design it to be nearly unhackable" aspect of guards. Even the guards themselves have lowered their assurance at the TCB and guard software over the years as neither military nor commercial market really care outside a small niche of customers. Remaining ones like Boeing SNS Server and BAE's XTS-400 go for $100,000+ a unit due to limited market + high development & certification costs.
So, that's that. Medium-assurance solutions like Nexor's and General Dynamics continue being developed and adopted. They'll get smashed, though, since they're all adopting Linux-based cores & other COTS tech. Such are the market incentives.
0. FireEye identifies a threat group known as APT28 (active since 2007) as having Russian origin, based upon political identities of targets, language markers, timezone data, and compiler settings. This analysis is from 2014. [EDIT: added this step later on to solidify Russian attribution] Sources:
- https://www.fireeye.com/blog/threat-research/2014/10/apt28-a... (blog)
- https://www.fireeye.com/content/dam/fireeye-www/global/en/cu... (long-form report PDF)
1. CrowdStrike & SecureWorks identifying the DNC breaches originating from the well-known Russian state threat actor APT28. Sources:
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...
- https://www.secureworks.com/research/threat-group-4127-targe...
2. This Motherboard article revealing the custom bitly links used in the Podesta phishing email. Sources:
- [OP] http://motherboard.vice.com/read/how-hackers-broke-into-john...
3. Politico confirming with SecureWorks that the Podesta spoofed phishing domain from step 2 has previously been used by threat actor APT28: "'The Google-spoofing domain in the Motherboard article is one we observed used by Fancy Bear,' SecureWorks researcher Tom Finney told POLITICO in an email." Sources:
- http://www.politico.com/story/2016/10/russia-responsible-pod...
This Politico article is the better summary. It also links to 2 other quality corroborating stories from ThreatConnect and Esquire. The Motherboard one is key but doesn't tie the whole story together. Sorry to disappoint parent commenter but the evidence does involve bitly custom domains! I'm not 100% clear whether this was simply a decently-executed vanilla phishing attack or if there were some advanced techniques used, but none of the evidence above hinges on that.
Personally, I would consider that a somewhat extraordinary claim. Is there anyone familiar with this sector who can comment on this?
I think very few people on HN understand how Crowdstrike works. Know how every Fortune-1000 company in the world has McAfee or Norton Antivirus installed (or at least used to)? Crowdstrike is like that, except they hoover up all the malware detection stuff they do on endpoints to a central data center and correlate it across customers.
More seriously, anything not phoning home with traffic patterns for things that 'might be attacks'.
It's fine to explain how malware works and turn it into a PR piece with fancy pictures of minified JavaScript, but none of that is proof of some Russian connection. Neither are professional sounding statements like "we have medium confidence the attackers are Russian actors" or similar baloney.
All there is is Stratfor style analysis along the lines of "we think NATO countries X, Y, Z got exploited so it must be Russia" when in reality that's probably just because all their customers are NATO countries X, Y, Z.
I believe that the industry's identification of APT28 (active since 2007) as a Russian group is based on both the political identities of their targets, and language and timezone indicators leaked in their work. Here is one such analysis from 2014 from a different security company:
https://www.fireeye.com/blog/threat-research/2014/10/apt28-a...
Here's the report for how you might detect APT28 in your network.
What would evidence look like, to you? Do you want to see the PCAPs? The executables themselves?
And why aren't they? Too damning I presume.
At no point in the official statement [0] is Russia EVER blamed for the DNC hack and subsequent leaks. This statement has given the media carte blanche to make the accusation themselves.
When previously posted, numerous people have said it does accuse the Russians of this. I would urge you to read the statement extremely carefully. The amount of intelligence and man-hours that go into crafting something like this is huge. There is a reason why at no point, is any current official coming out and explicitly accusing Russia of the DNC hack. Note that at no point has POTUS, Earnest during press briefings of Clinton ever accused the Russians of the DNC hack. Every time they refer to the matter they take great time and care to get their wording right.
[0] https://www.dhs.gov/node/23199
edit: What I am saying is not far-fetched or crazy. For those down-voting I hope you get a lawyer before signing any important legal document.
Do not forgot Bill Clinton during his trial at the Grand Jury :"It depends upon what your definition of is is."
> The U.S. Intelligence Community (USIC) is confident that the Russian Government directed the recent compromises of e-mails from US persons and institutions, including from US political organizations.
which recent compromises are they referring to?
Each statement can be proved to be correct individually. They do not have to refer to each other from a legal standpoint.
"are consistent with the methods and motivations of Russian-directed efforts"
The methods can be anything referring to hacking. Anyone who hacked the DNC would have been using methods (hacking) consistent with previous Russian hacking attempts.
Motivations? Motivations can be defined as someone wanting to take private information and making it public.
Read it like a lawyer. There is a reason why these statements are carefully crafter.
Additionally, why are you bringing in all this courtroom talk? This, and the many other statements by officials, have been directed to the general public. If the matter ever made it to court it would be the layperson's interpretation that would be key.
I fear you may not be well-versed in this area and I think it's really dangerous to be spreading such egregious misinformation.
"[The hack] has come from the highest levels of the Russian government, clearly from Putin himself, in an effort – as 17 of our intelligence agencies have confirmed – to influence our election."
At no point in the official statement [0] is Russia EVER
blamed for the DNC hack and subsequent leaks
(click) We believe, based on the scope and sensitivity of these
efforts, that only Russia's senior-most officials could
have authorized these activities.
Hmm."Such activity is not new to Moscow—the Russians have used similar tactics and techniques across Europe and Eurasia, for example, to influence public opinion there"