Further, why is there no backlash against the DNC or the government themselves for failing to secure their systems.
This entire election cycle just seems like everyone has been acting irrationally.
Further, why is there no backlash against the DNC or the government themselves for failing to secure their systems.
This entire election cycle just seems like everyone has been acting irrationally.
Cloudstrike https://www.crowdstrike.com/blog/bears-midst-intrusion-democ...
Security firm Mandiant https://www.washingtonpost.com/world/national-security/cyber...
Fidelis Cybersecurity http://www.computerworld.com/article/3086314/security/russia...
SecureWorks Evidence https://www.secureworks.com/research/threat-group-4127-targe...
Threatconnect https://www.threatconnect.com/blog/guccifer-2-all-roads-lead...
FireEye https://www.fireeye.com/blog/threat-research/2014/10/apt28-a...
I found the SecureWorks article had excellent detail but even they only had 'moderate confidence' that the attacks were sponsored by the Russian Government.
Regardless, I find it interesting that the rhetoric is that a 'nation state was influencing the election', rather than our own security practices are so weak that our political organizations were infiltrated repeatedly.
If not, which mean either bad passwords, bad support practice or known vulnerable software, then the nation state angle is just an incentive issue that describe who has an incentive to spread the hacked data.
Just a few months ago, a large mmorpg gaming company had a developer account hacked through spear fishing. The attacker went in, danced around a bit, and gave out free items. Not really the behavior of a nation-state actor. The company, contrary to most other, admitted the fault and that security practices (and basic sense to not ask in the office why the "developer" needed to reset the password) had not been followed in this case, and that human error resulted in the breach. They did not claim that the attack was some complex hacking trick for which can't be defended and thus they be faulted for. It raised my respect for them, and it is something I hope more victims of social engineering would do.
After the US conducted its own cyberattacks, they've been beating the drum on cyber security (I've personally seen one presentation from a high level official on beefing up security). Is it not reasonable to expect that the government and two official political parties have a minimum security requirement to protect against common attacks?
I suppose I'm just surprised that the rhetoric is 'boo Russia they interfered with our election' as opposed to 'wake up America, our cyber security is weak'.
You seem to have a prejudice that you are not willing to challenge.
TreatConnect:
>This discovery strengthens our ongoing assessment that Guccifer 2.0 is a Russian propaganda effort and not an independent actor.
> a Russian propaganda effort and not an independent actor
Let's unpack that statement.
Yes, this was clearly propaganda, hack originated in Russia, so sure Russian propaganda. Not an independent actor, ok, so a hacking group then, or a hacker plus wikileaks? I'm not seeing where they connected the dots to the Russian government.
Look, the US created Stuxnet and destroyed industrial equipment. Meanwhile internal emails are published using phishing attacks and we suddenly call this meddling and are incensed that someone would dare do this to us?
As it stands, the public evidence I've seen is
1) The attacks originating from servers owned by Russian companies
2) Pseudo-admission/gloating by low-level officials
3) Wikileaks and Assange's increasingly close relationship with Russia
4) The behavior of the Trump campaign, taking an exceptionally pro-Russian tack. Indeed, the only change they demanded be made to the Republican platform was to take out some anti-Russian commitments.
True, this is all circumstantial. The NSA certainly has more. If the NSA released it, the people who disbelieve the NSA would rightly point out that any really hard evidence could have been planted by the NSA anyway, so it can't be taken as certain that the NSA didn't plant it.
So why should the NSA sacrifice any assets to satisfy them?
The solution is for the NSA to share their evidence to a third party and the third party to come forward saying, "yup, I've seen the evidence and it is clear and irrefutable". I believe congress/senate are usually that third party, but for something technical like this I think they would benefit from inviting someone like Bruce Schneier to those sessions.
Will it happen. No. But, should it happen? Yes. Especially if there are to be escalations.
But I agree wholeheartedly: the first and foremost purpose of the NSA should be securing the USA's IT infrastructure.
1) if you wanted to launch an attack, how better than to buy a few VPSes in Russia. This is like saying that an attack that originated in AWS US-EAST was undertaken by the US Government. Truly bizarre.
2) The person who did that is apparently more of a pundit than an official.
3) Not sure what evidence you'd point to for this. Assange did an interview for hire than was run on RT, but surely he would happily do interviews with American TV networks if they offered.
4) Trump made a PR stunt remark about respecting Putin and the next thing we all know he's a Russian stooge. Not sure how old you are but during the cold war it was a big relief when Reagan and Gorbachev sat down for talks and everyone calmed down. In light of the frantic anti-Russian rhetoric coming from HRC's political campaign, I view any sort of moderation as a breath of fresh air and sign of maturity.
I think the disturbing issue is that we don't have enough transparency into the DOJ, the FBI or the NSA to have any clue what might be going on. There was pretty much zero reaction/reform after the Snowden revelations. I would not have thought this possible.
I'm not bringing this point up to start a side tangent argument, but just pointing out that in this election cycle, a lot of people held pre-existing beliefs and would justify them in any way they could (i.e. cognitive dissonance).
This doesn't even hint that there might be Russian involvement. It's utterly irrelevant. Anyone doing something like this will most likely be hosting either in Russia or the Netherlands.
>2) Pseudo-admission/gloating by low-level officials
Low-level officials probably aren't in positions to confirm intelligence operations such as these, and even if they were, such behaviour would hardly be unexpected from an entirely unrelated party.
>3) Wikileaks and Assange's increasingly close relationship with Russia
Would you like to back that up somehow? Not all of us share your security clearance so we can't read the emails between Assange and Putin.
>4) The behavior of the Trump campaign, taking an exceptionally pro-Russian tack. Indeed, the only change they demanded be made to the Republican platform was to take out some anti-Russian commitments.
The pro-Russian tack only stands out if you ignore the rest of their politics... In which case literally anything would stand out, no?
>True, this is all circumstantial
This is all bullshit. There exists significantly better technical evidence of Russian involvement available to the public.
> we can't read the emails between Assange and Putin.
Perhaps some person or organization that believes in radical transparency will leak them.Could you share?
I'm not sure why it would matter. The perception of the world and a relative place in it, affects voting. That's inherent. China warned against electing Trump, early on, iirc. That's not an issue because it was anti-trump. Transparent political attacks against an ideology, is not news.
Generally, intelligence agencies do not provide evidence or any other indication of their sources or tools. Law enforcement is different.