Critiques of the DHS and FBI’s Grizzly Steppe Report
robertmlee.org
robertmlee.org
If there is one thing the plaintiff's lawyers excel at, it is inflicting extensive expenses and pain on parties who negligently or fraudulently create, fund creation, or use products that injure property or person; thereby creating effective incentives to harden products.
You will know the USGOV is serious about INFOSEC when they stop issuing reports and start legislating, regulating and enforcing meaningful standards, as they already do for automobiles, drugs, machinery, etc.
I’m still not sure what to think of the Sony hack. I instantly rejected the idea that it amounted to “cyber war”, but beyond that, I think governments can take a legitimate interest in digital attacks on private companies, same as law enforcement would get involved in a physical attack on a corporate building.
I think the main response to IT breaches has to be “defensive”; secure code and networks. You can’t find and retaliate towards every hacker. And the benefit is that unlike retaliatory policy responses, good network security is designed to protect against all third parties, whether it’s your own government, random financial criminals, James Bond villains, whatever the entity or motive.
sigh
Several small businesses have been driven out of business by such behavior, and large business have mostly capitulated.
The problem is the organization sizes are the opposite of what works for products liability. It's not Joe Homeowner buying an appliance from Sears or GE, it's an insurance company or government contractor getting software from an individual or a company with nine employees.
You can't use that to force improvements from small entities because they barely even have lawyers to tell them what they have to do, and nobody will actually sue them if they have no money anyway.
What you need isn't for the software vendor to be liable, it's for the company holding all the customer data to be liable to those customers. Then those companies will start caring about actual security instead of "compliance" and figuring out how to pass the buck, and software vendors will still have to make secure software because nobody will buy anything else anymore.
It also forces companies to start treating huge databases as the security liability that they are. And it conveniently applies to the large tech companies that are also data warehousing companies like Yahoo or LinkedIn/Microsoft.
The good news is high-assurance systems have been built with smaller teams than that. We also have cases like Bernstein's where one person builds all kinds of stuff with provably better security using a bit of brains and methods that work. We also have tools like SPARK for static systems and Rust/Eiffel for larger ones that can easily eliminate entire classes of attack. Ada & SPARK have been around decades. Eiffel over a decade. Hardly anyone in security-critical space using them.
Most of what you see is easily prevented. Even with small teams. They just don't care or try. A baseline stopping code injection or insecure configurations would knock out a ton of problems. The next thing that would happen, as did with DO-178B regulation & TCSEC, would be reusable components and consulting services designed to meet the standard where the cost & limited expertise is spread among many customers.
It could be done. Even for smaller players to a large degree.
"What you need isn't for the software vendor to be liable, it's for the company holding all the customer data to be liable to those customers."
Doesn't solve the DDOS problem which can also be used for extortion, interfering with government operations, etc. My approach targeting root cause handles that, too.
> Doesn't solve the DDOS problem which can also be used for extortion, interfering with government operations, etc. My approach targeting root cause handles that, too.
Can you be more specific about your DDOS solution?
The root cause is 0-days in software or bad configuration of mass-market products in most cases. The former can be detected automatically by many tools. The latter can, given the flaws I've seen so far, be spotted in 5 minute review by an amateur consultant. Mandating such things in a regulation or expecting them as "reasonable, professional standard" during a lawsuit would be a start. Prevents many DDOS bots as a side-effect.
My main solution to DDOS mitigation in the interim & part of long-term package is here:
Vulnerabilities are not proportional to software price. That's the whole problem. IBM software is very expensive and complicated but you don't see a lot of CVEs. OpenSSL costs no money and much trouble.
Yet you have projects like OpenSSH that are free, by all accounts have a strong security record, but once or twice a decade there is a serious vulnerability. And because of how and where it's used, liability for that would destroy them.
Meanwhile Adobe would sooner stop distributing Flash Player than fix it, and all this does nothing about the admin who leaves the database server open to the internet with the default password.
This is a public service announcement: if you haven't seen enough information to prove to you, independent of the claims of the White House, CIA & FBI, that Russia was behind this, you should file a Freedom of Information Act Request for sufficient evidence to independently reach that conclusion. Citizens of the US in particular should do this to hold their government accountable -- we can not let it be accepted that because POTUS says something, and maybe has confirmation from "anonymous sources" within the CIA & FBI (e.g. as reported by the NYTimes[1]), that it must be true.
Muckrock[2] makes it dirt-simple to file a FOIA request. Hold the government accountable -- they work for us.
1: http://www.nytimes.com/2016/12/09/us/obama-russia-election-h... 2: https://www.muckrock.com
It's a bunch of liars (Russian government, various US intelligence services, Russian and American politicians) trying to tell me that "the other guy" is a liar and did something bad.
My life continues as it does, working against all those listed above because none of them particularly deserve my assistance or respect.
and it's for "security". I'm 'secure' from hillary clinton's corruption, therefore, violating her right to privacy is ok. same thing they do to each US citizen
Have individuals close to the Kremlin strongly implied they had a role in this and have senior Russian officials stated clearly that they had contact with the Trump campaign during the election? Yes. http://www.haaretz.com/world-news/u-s-election-2016/1.752386
Did Russia even object today on the grounds that the allegations about their role were false? On the contrary, they were practically doing a victory lap.
There are plenty of debates still very worth having about whether the actions taken today are appropriate, whether a hostile stance towards Russia is merited, etc. But I've seen enough to convince me that Russia was engaged in an information operations campaign to cast doubt about the U.S. election and help Trump on the margins.
I would encourage considering applying the same standard that we would apply to a trial by jury. Simply indicating that someone is a repeat offender, and would have reason to commit an offense again, does not itself meet a standard of evidence of actually committing that offense.
1: http://www.politico.com/story/2016/12/kremlin-denies-putin-d...
Covert hacking happens everywhere.
The US openly bribes other nations or sends troops to motivate them to change.
By all means, try, but you're trying to use FOIA to uncover literally the exact kinds of information the law excludes from FOIA.
And there won't be one single source of evidence which points to it, it will be hundreds of small circumstantial points which taken together point to the conclusion.
Those won't ever be released because they will give away sources and techniques.
0: http://www.nytimes.com/2016/12/13/us/politics/russia-hack-el...
Looking at the comments in yesterdays' thread[1], this is absolutely true - many, many people posted some variation of "What? There's no evidence proving Russian involvement in here at all!"
Sooo... still no public evidence that Russia leaked the DNC and Podesta's e-mails?
However, see here for evidence from private sector firms: https://www.reddit.com/r/NeutralPolitics/comments/52uj5c/do_...
Except that's _explicitly_ not what you said. You said:
>still no public evidence that Russia leaked the DNC and Podesta's e-mails?
Your original claim was that there was _no public evidence_. When that claim was challenged, you pretended your claim was about what evidence was provided by the government.
I did read the RPT-APT28 report by FireEye on APT28 (all fifty-something pages, surprise!). It did convince me that APT28 has political motivations. What's the connection between that and DNC/Podesta? I don't know, because there's no public evidence on that (that I know of).
The groups haven't changed; why are we so certain in December of Russian involvement that we're willing to sanction, if we knew everything we needed to know in June? The only evidence that they are associated with the government is a claim by FireEye that they "work during normal Russian business hours" of 8am-8pm, and that their targets (known targets I should say) would be of strategic importance to the Russian government - I bet if you asked any hacker in any country whether they'd like to hack the US government, they would tell you hell yes.
There are two possibilities here: 1, the US government is drawing this conclusion and imposing sanctions based on weak circumstantial evidence or 2, they have actual evidence but won't even hint at what it is. Even during the Iraq WMD debacle (which this ordeal is drawing heavy comparison with) they said they had satellite photos.
[1] http://www.csmonitor.com/World/Passcode/2016/0615/Meet-Fancy...
Seems obvious that leaks assisting the pro-Putin candidate were not altruistic.
If you want to assume there were also some dirty Trump secrets that didn't come out then it seems like the only way to "level the playing field" would be for e.g. Venezuela to hack the Republicans and air their dirty laundry too.
And people are running around saying how terrible this is and asking "what if everybody did this?" But it seems like the answer to that question is, then people would know more relevant information about their political candidates. Or politicians would get better at computer security. Which of those is supposed to be bad?
Those are two rather incredulous assumptions considering that:
- Clinton released all of her tax returns, whereas Trump didn't release any
- The Clinton Foundation has been audited by at least three well respected, independent, organizations (garnering top ratings from all), whereas we know comparatively little about the Trump Foundation (or whatever it's called), yet it's admitted within the last six months to several inappropriate expenditures or donations, and is likely being investigated for more
- Trump sits atop a network of literally hundreds (if not thousands) of "independent" corporations designed solely to evade disclosure, liability, taxes or some combination thereof
https://shorensteincenter.org/pre-primary-news-coverage-2016...
Look at figure 7, Clinton media coverage 84% negative in tone, twice the ratio as Trump's!
Now compare that to the many millions worth of free coverage that Trump got, because he knew how to exploit the media's lust for controversy.
http://mediamatters.org/blog/2016/10/26/study-confirms-netwo...
100 minutes of Clinton emails vs. 32 minutes of policy issues for all candidates combined - who do you think benefits from that, the candidate with realistic policy proposals, or the one who wants solve all problems by building a wall?
Second, how exactly was a level playing field created by leaks that targeted a single party and candidate? Was there some demonstrable advantage HRC and the DNC possessed versus GOP candidates and the RNC, which was neutralized in a fair fashion by the leaks, thus creating an equitable and balanced standing among all the parties and candidates? That seems to require quite a lot of evidence and explaining.
Third, I don't think there has been any stated allegations from the Obama administration or intelligence services regarding hacking voting machines and tallies. I realize some people are suggesting it without any evidence being out there. But the administration doesn't appear to be making those claims from all I've read so far. That's a wholly different issue that would require an incredible amount of organization, effort, and evidence proving it occurred. "Hacking the election" seems to almost be used as a bit of a colloquialism, more akin to "life-hacking", and where administration officials are concerned, specifically focused on the data breaches and leaks in an effort to "life-hack" the election through creative social and political engineering, not manipulating voting tabulations. However, voting machines != electoral process. They are merely the mechanism by which the process culminates in a decision. The machines can be entirely sound, while the process can be hacked and manipulated.
Also, a couple of nitpicks:
- It's the Democratic Party, not Democrat Party. It's members are called Democrats, not the party itself.
- In this instance, you wanted to use "lesser" not "lessor".
In my opinion, the DNC emails and the Trump "grab 'em" tapes are similar -- you can argue that it's private material that should've stayed that way, but you can't argue that the material didn't reveal helpful truths about the candidates.
Finally, a recent poll found 50% of Democrats think that Russia tampered with the vote tallies in the election. This is insane, and the direct result of mainstream media irresponsibly using the phrase "hacked the election" to refer to the (alleged) hacking of DNC emails by Russia.
Fake news.
http://thehill.com/blogs/ballot-box/presidential-races/30386...
>"If Bernie Sanders had been the nominee of the party and the Russians hacked my emails instead of John [Podesta]’s, we'd be reading all these notes between Donna and I and they'd say Donna was cozying up to the Bernie campaign. This is taken out of context. I found her to be a fair arbiter, I think she did a good and honest job."
Turns out they weren't even debate questions:
http://www.nbcnews.com/card/top-sanders-aide-defends-dnc-cha...
Sanders didn't say that. (Read your link. It's an aid running interference.)
Donna did leak debate questions. Here's an email from Donna Brazile. The subject is "From time to time I get the questions in advance".
https://wikileaks.org/podesta-emails/emailid/43962
The email contains the exact text of the question submitted to a CNN producer in advance of the town-hall by a moderator; it is very similar to the final question that ended up being asked.
http://www.politico.com/blogs/on-media/2016/10/roland-martin...
Aide representing Sanders. Distinction not relevant at all.
>town-hall by a moderator
The real question is whether Sanders' camp got the same email. The statements made by his aide suggests they did.
Is there any evidence to suggest that the DNC was singled out for attack? We should be careful not to fall victim to pernicious media spin. The claims laid out in the Grizzly Steppe report are very specific:
1. In summer 2015, an APT29 spearphishing campaign directed emails containing a malicious link ...
2. ...to over 1,000 recipients, including multiple U.S. Government victims.
3. In the course of that campaign, APT29 successfully compromised a U.S. political party.
We know in retrospect that the compromised party was the DNC, but the claims presented do not indicate that the DNC was the only target. Although this is how good boys and girls are supposed to interpret the evidence, since many news media sources are spinning this as "Russia hacked the electoral process for a Trump victory", we can't start from that conclusion and work backward. Claim #2 in particular seems to indicate that the attack was broad and indiscriminate, with government and non-government targets alike.
Consider also what isn't said in this report. If they could say that the hacker groups singled out the DNC for attack, they would say so. That no such claim is made indicates that the authors know otherwise.
Finally, we have this:
4. In spring 2016, APT28 compromised the same political party, again via targeted spearphishing.
This is a separate group from the one in the previous claims. What they do not speak to is the question of who else was attacked or compromised.
Intelligence and counterintelligence is an endless game of cat and mouse that has been played for millenia. Any indication you can glean on who the next leader of the world's #1 power will be is priceless information, so none of us should be the least bit surprised that any of this is going on or that political parties would be the target of hacking attempts in an election year, by Russia, or any other nation.
Russia putting a targeted hit only on the DNC to swing the election specifically in favor of one candidate is an extraordinary claim and this report doesn't clear the bar IMHO. A far more likely hypothesis is that all renowned political organizations are a target for hacking at all times, and the DNC just had shitty security and got compromised. Too bad. Maybe turn on 2FA next time, and stop storing Top Secret material on your home server. (Even my little unknown personal server gets thousands of login attempts from China every day.)
None of the emails on Clinton's email servers were ever compromised, or at least we have no reason to believe they were because no one leaked them.
>Russia putting a targeted hit only on the DNC to swing the election specifically in favor of one candidate is an extraordinary claim and this report doesn't clear the bar IMHO.
This report wasn't meant to provide any evidence of anything.
I didn't say the DNC was singled out for attack. I said the leaks targeted them specifically. It's an intentional and notable distinction.
But they didn't do any of that either. It's amazing how out of control this narrative has gotten. And this is precisely why we can't justify these sorts of intrusions so close to an election, the stories become such distorted pictures of reality which is antithetical to to rational decision making.
They most certainly did. DWS and company actively worked internally to disparage and scuttle the Sanders campaign and push HRC, ultimately resulting in DWS resigning in shame. The DNC leadership's bias was obvious, and the leaked emails that came out before the convention provided sufficient evidence that Sanders' supporters had been right about the DNC not playing fair with the candidates (though still not rigging the primaries). I don't think the narrative about the DNC's pro-Clinton/anti-Sanders bias and internal activity ever got out of control. Seems it stayed pretty level, and it's ultimately a separate matter from the current issue as far as I'm concerned anyway.
Such as? Further, one person leaking emails is a far cry from "the DNC" being against him. You cannot blame the organization for actions of individuals.
>act of writing and discussing the contents of those emails
But it is absurd to be upset by internal discussions that resulted in no action against the Sander's campaign. When I ask for what action the DNC took as an organization, it is in this manner that I am asking the question. Internal emails does not constitute "actively working against the Sanders campaign". Such a characterization is blatant dishonesty.
The techniques that NSA and MI6 use are far more advanced. Taking advantage of the networking equipment and injecting traffic.
Just because someone walked in through an unlocked window does not make them any less an effective burglar.
I don't think this is the best written report, but his conjecture around completely leaving out attribution if it doesn't include evidence seems rooted in playing to the lowest common denominator (ie poor media coverage of what this report entails)
It's quite reasonable to assume the release of this report was intended to create the impression of evidence for attribution, even if it actually contains no such thing. Otherwise why not release it on any other day to avoid confusion? It looks to me like the confusion was quite intentional.
https://www.whitehouse.gov/the-press-office/2016/12/29/fact-...
Attribution is sexy and the media likes to talk about it. I don't believe the confusion was intentional. The White House is pretty bad at PR and 'never ascribe to malice that which can be explained by incompetence'
They have a press secretary whose job is, literally, to manage the media. I'm honestly not sure if your post was intended as satire.
The meat of the report might as well have been copy pasted from OWASP. So if it's not to provide political cover for the yet-to-be-proven claims that Russia did it, they didn't get the message out.
> at least in a vendor report you usually only get 1 page of marketing instead of 8
That was also my reaction when I scrolled down past page 4-5. It almost feels like they could have split this particular report into:
1)public-and-media-facing high level technical overview
2)actionable intelligence information for defenders
With 3) being the attribution and evidence coming at some point down the road.
The whole report, and media coverage, and statements by public officials are so confused and confusing that they are useless in regards to security.
I have to compare this to the FDA's HIPAA regulations which mostly are just instructions on how to correctly secure servers and applications. However, I wish that HIPAA did not have these regs in it because they are susceptible to falling out of date.
Rather, I think the public would be better served by an official security standard that can be updated weekly with new advice and requirements. Then an org like the FDA can have one regulation covering security that says something like "all systems must be secured according to Federal Infosec Guidelines level B3 or higher". The specifics of what B3 might mean and higher levels of securing servers and apps, can be in a single document that would, I am sure, become a core part of the curriculum for developers and system administrators.
Moaning and whining about water under the bridge is a waste of energy and of public funds. This is a fixable problem if only someone in leadership is willing to act. Not grandstand or apportion blame, but act to improve infosecurity for everyone.
A well drafted set of infosec guidelines by industry experts along with a process for keeping it up to date will have incredible multiplier effects throughout industry as well as government, because it makes it much easier for management to order that things be secured, and it makes it much easier to get a consultant to validate that the guidelines have been correctly implemented.
I will say this; the Podesta emails revealed a lot about the internal politics of the DNC. Why are we not treating this type of leak with the same level of respect as the Ellsberg leaks? Or for that matter, the Snowden leaks? Who is really controlling the narrative here?
Randomly dumping personal emails isn't the same as Ellsberg and Snowden working with reporters to blow the whistle on specific transgressions in war and mass surveillance.
Interesting article exploring this issue of exercising discretion and developing new ethics in the age of leaks: http://www.nytimes.com/2016/11/05/opinion/what-were-missing-...
But can't you see the vast amount of corruption? The DNC rigged the primary for one candidate. We need to hold our political parties accountable for their actions.
I'd like to see the RNC's emails now. What kind of dirt do the republicans have? Is it not being released because it's being used to blackmail them?
The big things that came out of the leaks for me is the explicit and cosy relationship with specific members of the media who were instructed to produce and disseminate certain messaging against Bernie Sanders.
They also asked those "media resources" to prop up Trump, Cruz and Carson because they naively believed that Trump would be a push-over, for example.
Clearly there were people within the DNC who preferred clinton, but in what sense did they rig the vote?
Whatever the case was, 126K Brooklyn-based democrats were unable to cast votes in the primary http://www.pbs.org/newshour/rundown/officials-investigating-...
Brooklyn is one of the parts of the NYC area that have ultra liberal demographics, so one could draw the conclusion that Brooklyn's voting power would have tipped the NY primary towards Sanders.
Every time I see someone write something like this my knee jerk reaction is to either assume they're lying or they are clueless. Can you point to the vast amount of corruption you claim is self evident?
I can't tell if people hawking such ridiculous ideas are truly naive or are just following a motivated reasoning to reach some post-hoc justification of their dislike.
http://www.mostdamagingwikileaks.com/
The press never covered most of it because a lot of the leaks are things that make them look bad. For example, Glenn Thrush:
https://wikileaks.org/podesta-emails/emailid/12681
> No worries > Because I have become a hack I will send u the whole section that pertains > to u > Please don't share or tell anyone I did this > Tell me if I fucked up anything
He tried to get out of this by saying he was just fact-checking. But that normally doesn't require a request for secrecy and one would just send specific items they wanted fact checked, not a prerelease copy of the article.
I just randomly picked links and citations. Sorry, but I didn't find any there there. (I skipped the secret email server, mostly because I don't care.)
Just one example, in #6 its clear from context that Bill Ivey's use of "we" refers to society as a whole. Further, he's venting about the decline of civic engagement, an opinion shared by many (such as myself).
My primary reaction is "Hate the game, not the players." Politics sucks. All of it. But why is any one surprised by the corruption? This is the system we designed, or at least accepted. If we hate it so much, they we should support publicly financed campaigns, restoring the fairness doctrine, shortening the political cycle, etc, etc. But we don't. Because Freedom Markets™ booyah!
My secondary reaction is "Wow, this InfoWars stuff makes my head hurt." I can never tell if cherry picking quotes out of context and making wild inferences is intentional obfuscation or just how some people process the world.
Any way, thanks for the link.
PS- The spirit worshipping stuff is hysterical.
Read the PDF on here for more: https://wikileaks.org/clinton-emails/emailid/30324
This is part of what Colin Powell said that I think it especially illustrative of how big of a security risk people like this are when put in power:
Now, the real issue had to do with PDAs, as we called them a few years ago before BlackBerry became a noun. And the issue was DS would not allow them into the secure spaces, especially up your way. When I asked why not they gave me all kinds of nonsense about how they gave out signals that could be read by spies, etc. Same reason they tried to keep mobile phones out of the suite. I had numerous meetings with them. We even opened one up for them to try to explain to me why it was more dangerous than say, a remote control for one of the many tvs in the suite. Or something embedded in my shoe heel. They never satisfied me and NSA/CIA wouldn't back off. So, we just went about our business and stopped asking. I had an ancient version of a PDA and used it. In general, the suite was so sealed that it is hard to get signals in or out wirelessly.
...which is not actually part of the government. I expect political parties to have internal politicking, which is somewhat bad. But ultimately parties are private organizations that are subject to quite different laws and obligations than parts of the government.
a. Democrats and Republicans are guided by very different moral philosophies - the kind of thing that courts eschew dealing with as 'political questions' because which one you plump for depends less on reasoned argument than on which basic premises you adhere to. As inherently political entities, it's irrational to demand they hew to some objective standard of political behavior as if there were a knowable truth of conduct that transcended politics.
b. Fringe parties are always running colorful candidates for high-visibility executive positions and then complaining than the system is exclusionary when they inevitably fail against better funded and organized opponents from parties with long track records (whether or not you approve, at least you sorta know what you're gonna get). This is a crap strategy and the idea that the fringe party should get some sort of help in the next election cycle for having shown in a previous one is mystifying to me.
The path to power in the US is through legislative capture. That's how the Tea Party hijacked the GOP - not spontaneously but as the culmination of a long, focused effort. Conservatives chose to worth within the framework of an existing party. Leftists have attempted to do the same in the Democratic party but frankly they're not that good at entryism as a political tactic, lack a coherent alternative to liberal capitalism, and so end up demanding change while being unable to articulate a plan for how to achieve it. You will see a redoubling and refinement of these effort sin the next few years. but if you don't want to work within an existing party, then the next best thing is a party that focuses on legislative representation like the Working Families Party, whose principles I only partly agree with but whose tactical instincts are excellent.
c. Brokerage (as in back-room political favor-trading and negotiation) is an unavoidable components of representative democracy and wishing it away is like asking it to only rain at night. If you want to change this then you need to think about changing the basis of of the political system itself. For example, one could have election by sortilege, where legislators were chosen involuntarily, like jury service. Or we could move away from producing laws like books authored by committee and adopt Wikiism, such that instead of legislative debates we have edit wars on the legal corpus. The main problem with Wikiism (or Social Coding or Participativism or some similar autology) is that implementation in the real world lacks authoritative grounding or operational consistency, which is probably why you don't see many corporations using this model to carry on business.
Don't get your hopes up. Bruce Schneier drank the Kool-Aid and is completely on board with the "ruskies did it because experts agree" narrative: https://www.schneier.com/blog/archives/2016/08/hacking_the_v...
Look at how he calls whistleblowing "organizational doxing" and he urges a swift and exemplary response to the "national security threat". Somewhere along the way, the respectable security writer became a silly neo-mccarthyist pundit.