Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer
thedailybeast.com
thedailybeast.com
> [An intelligence researcher] led an investigation at ThreatConnect that tried to track down Guccifer from the metadata in his emails. But the trail always ended at the same data center in France. Ehmke eventually uncovered that Guccifer was connecting through an anonymizing service called Elite VPN, a virtual private networking service that had an exit point in France but was headquartered in Russia.
> But on one occasion, The Daily Beast has learned, Guccifer failed to activate the VPN client before logging on. As a result, he left a real, Moscow-based Internet Protocol address in the server logs of an American social media company, according to a source familiar with the government’s Guccifer investigation. Twitter and WordPress were Guccifer 2.0’s favored outlets. Neither company would comment for this story, and Guccifer did not respond to a direct message on Twitter.
> Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow. (The Daily Beast’s sources did not disclose which particular officer worked as Guccifer.)
There are better ways to hide. From experience (I work in security), the ones I would use are (individually or combined):
- Have the VPN set up in my router using OpenWRT (the R7000 is great for that) and drop all connections when VPN disconnects (with a script).
- Rent a VPS on a botnet friendly host that accepts Bitcoins (i.e Hostsailor).
- Then do all my shady stuff from the VPS or even better, configure Tor and proxychains on the VPS then use proxychains when doing anything on a remote host.
I think the guy was just lazy and preferred convenience.
Having a separate browser that jumps through all the well-audited crypto hoops you want doesn't really help you if you have a native Safari window sitting next to it where you read your gmail.
Opsec is hard. Technology can only solve so much, the weak link will always be the wet spongy tissue.
Edit: you could even configure Little Snitch to ask for permission for every app and domain your Mac wants to connect to. That way you would even catch yourself accidentally surfing to the wrong URL or using the wrong browser.
That totally says "false trail" rather than "fuck up" to me. /sarcasm
Instead of phone number, think port on the phone company’s switch or a specific pair of wires. That’s hard to spoof.
It’s much easier to spoof a MAC address, which can identify specific hardware associated with the IP address, but that doesn’t make the IP any more difficult to identify.
Depends on the occasion, no? There's a difference between "the target account once used phrasing more typical of a Russian speaker than a Romanian speaker" and "the target connected to the server from inside GRU headquarters".
> it's also definitely easy to throw investigations off course
Connecting to a server from GRU headquarters isn't something I'd call "definitely easy". If the claim is true, Occam's Razor suggests that the GRU was involved in some fashion. What's the alternative? That the DNC compromised the network of a Russian intelligence agency?
(How much faith to put in an anonymously sourced claim about what was in the logs of an unnamed social network is a separate question, of course.)
> U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow.
Parent already addressed this. Unless you have evidence to the contrary the "what if" game does not take us very far.
Tell me; how did The Daily Beast, an org that has Chelsea Clinton on their board, get the external IP addresses of the Russian Intellegence headquarters?
It wasn't the DailyBeast conducting the investigation, they are just reporting on it
[0]: https://abcnews.go.com/Technology/story?id=119423&page=1
Right, the fact someone could compromise a random government agency in the 90s clearly means someone else could compromise Russian military intelligence in 2016, because NASA's IT security in the 90s is totally comparable to the GRU today, absolutely.
> possibly backed by a nation state
Which nation state, exactly?
There is no public video recording to substantiate their claim. You'd think this entire debate would be settled if on YouTube we could all just watch visual proof of Russians hacking the US.
They also claimed that the video feed came from a university building in Moscow's Red Square. I challenge you to find such a building on a map of the Red Square.
Because such hacks don't happen today?
>Which nation state, exactly?
Well, which nation state likes false flags and BS excuses like WMDs for their target du jour?
The most infamous (and heinous) oft sighted example...
https://en.wikipedia.org/wiki/Russian_apartment_bombings
And there are plenty of more recent allegations such as the framing of North Korea for the attempts to disrupt the Winter Olympics:
https://www.wired.com/story/russia-false-flag-hacks/
Parkland shootings etc etc
http://www.politifact.com/truth-o-meter/article/2018/feb/22/...
https://www.washingtonpost.com/opinions/after-the-parkland-s...
As words, phrases and fads spreads on the press, so they do on the internet.
It generally only takes one occasion of a videotape catching you stealing and an eyewitness corroboration for you to be believed the thief as well.
It's surprising that RT published those. I thought it was an entity controlled by the Russian government. Why would it be publishing the names of its own officers when supposedly the said officers went out of their way to appear Romanian and not Russian.
and please note the careful wording: "Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer working out of the agency’s headquarters on Grizodubovoy Street in Moscow. "
interpretation 1: The guy accessed the device from his GRU office
Interpretation 2: The IP belongs to a guy (maybe his residential connection), and he happens (from other sources) to work at the GRU office. Assuming the GRU device is relatively secure, is it possible that other devices on his home have malware on them? If the latter, all the devices would appear as coming from that same residential IP address.
I work in this field and false attribution happens all the time. Evidence is really easy to fake.
Don't confuse the ease of installing tools that let you maintain access once you have gained access with the ease of gaining access in the first place.
https://www.cyberscoop.com/winter-olympics-hack-attribution-...
https://krebsonsecurity.com/2017/08/blowing-the-whistle-on-b...
https://blog.trendmicro.com/trendlabs-security-intelligence/...
https://blog.talosintelligence.com/2018/02/who-wasnt-respons...
But that has nothing to do with a watering hole attack - are you claiming that successful watering hole attacks against GRU personnel are commonplace?
OK - show us. Doesn't need to be GRU - I'd settle for an NSA or Mossad ip address instead. Go on, install a RAT and make a connection...
That means that if it it wasn't Russia then it must be some "deep state" conspiracy. Which so far hasn't been backed up by any decent evidence.
Lets see what Jonathan Haidt has to say on the matter:
"“With UMBRAGE and related projects the CIA cannot only increase its total number of attack types, but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from,” Wikileaks said in a statement."
https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia...
and for remote control:
"In April this year, WikiLeaks disclosed a brief information about Project Hive, revealing that the project is an advanced command-and-control server (malware control system) that communicates with malware to send commands to execute specific tasks on the targets and receive exfiltrated information from the target machines. Hive is a multi-user all-in-one system that can be used by multiple CIA operators to remotely control multiple malware implants used in different operations."
https://thehackernews.com/2017/11/cia-hive-malware-code.html
How would either be relevant?
Except the Russians haven't worked very hard to try to deny it.
And - more importantly - everything else they do aligns with this same goal.
It's like during WW2 finding a person spying in London, finding they were passing information on English plans to attack German air defenses to someone in Berlin and saying "Well.. they might have been American, because the US and the UK were rivals during the Washington Naval treaty process during the 1920s". Yes.. they might. But there's a lot of evidence pointing the other way, and German actions indicate it was the kind of thing they would like.
Same here.
Doing something shady from a regular workstation is either a mark of noobiness, or it's someone trying to disguise as someone else. Relying on manually launching a commercial VPN each time when you want anonymity? It's not really opsec per se.
These are not amateurs. They should know better.
"If you have a STU-III secure telephone, use it, but remember that even the STU-III depends upon strict telephone security discipline. A defector from one of the foreign intelligence services that monitor U.S. communications reports that STU-III encryption is fairly secure. However, he also advised that the chitchat that occurs before the STU-III is switched to secure mode and after it is switched off of secure mode is a bonanza of valuable information. Communications monitors can identify STU-III lines, so these phone numbers are obvious targets. Therefore, a STU-III line being used in non-secure mode may be more likely to be monitored than another line that never carries encrypted communications. Maintaining strict telephone security discipline is critical." (my emphasis added)
I'll also note that stopping these accidental leaks was part of the motivation for the Compartmented Mode Workstations that weren't secure enough at B1 class to stop well-funded attacks that B3 or A1 might. Risks ranged from cut/paste to classified docs making it onto unclassified networks. The systems' security kernels would look at the labels to catch that. The kinds of leaks they addressed still happen to both innocent users and criminals.
Yeah, in every field there are lots of cases where people end up saying this because professionals who should know better don't. Or cut corners because of resource constraints. Or, just screw up something they actually do know. Or...
They are just regular people. It's not a world of super spies. I am sure GRU is not that much different. Even the top folks eat corn flakes like everyone else.
People make mistakes all the time.
This might be bullshit but just saying so is hardly a compelling argument. I will wait for more evidence one way or another myself, with the obvious disclaimer that anything could be bullshit.
“We found an IP address in a log which lets us tie Guccifer 2.0 to a specific GRU agent” is laughable on the face of it. But with the absolute shitshow that the investigation has been to-date I personally am way past caring, and way past beleiving anything at all to do with the Russia narrative.
Indeed, Trump has already said something like that:
“Somebody did say if he did do it, you won’t have found out about it. Which is a very interesting point.”
Yes.
"He has cautioned in the past of a plan to create a North American Union with a single currency for the United States, Mexico and Canada, and a stealth United Nations campaign to confiscate civilian handguns. He has repeatedly referred to the “tyranny” of the federal government."
He's a strong libertarian which is, by definition, wackjob territory.
At this point, if you don't want to see to the myriad of evidence that the Trump campaign was either working with or willfully used by Russia its just because you don't want to see it.
http://time.com/5155810/russian-meddling-2018-elections/
https://www.nytimes.com/2018/02/13/us/politics/russia-sees-m...
https://www.cnn.com/2018/02/13/politics/intelligence-chiefs-...
The only thing I know is this -- no one is right, no one is good, no one is clean, and there's enough corruption on all sides of this to make anyone sick. You can pick whichever specific aspects of it support one side or another, but I personally think the things we do have hard evidence of point to;
1) An incredibly fucked up situation at the top of the FBI and Justice Department
2) A media which has largely lost the ability to separate reporting from editorial
3) A little trolling by Russian during the election to stir the pot
4) A very close election which was won by the "wrong" person, and a large percentage of Americans who are desperate to unseat him by any means possible
And why he insists on breaking all protocols to do this, such as meeting without his own translator? For so many reasons this is a terrible idea.
Why would Trump meet with the Russian ambassador and tell him Comey is taken care of? And do this secretly? Why would Trump have an insult for every US ally and not a single bad word about Russia?
I challenge you right now to find me a single bad word Trump has said about Russia.
What makes these indictments more political than every other time the FBI prosecuted alleged spies?
Wait for more evidence to come out.
The DNC leaks were pretty bad for the campaign, but ultimately of their own doing.
Edit: downvoted I assume for not specifying technical evidence, like this garbage news story about dns traffic:
http://www.slate.com/articles/news_and_politics/cover_story/...
Moreover, note the weasel wording. For all we know, "familiar with the government's investigation" just means "the guy who brings in the water bottles overheard some office gossip."
I would take this story with a grain of salt.
Recommended reading for understanding attribution: https://www.lawfareblog.com/how-read-news-story-about-invest...
I did want to point out the sourcing either way, though. It's really distressing to me the way anonymous sourcing has really taken off lately, and that most people appear to be entirely credulous despite the lessons we learned back during the Bush administration. It rarely even gets questioned, though even the past year in particular has served up frequent and egregious object lessons of why anonymous government sources cannot simply be taken at their word. The sad fact of the matter is that the vast majority of anonymous sources are not leaking information to edify the American people. They are leaking information because they have an agenda.
That doesn't mean that we can simply ignore them. Sometimes the information is false, sometimes critical context is left out, but sometimes it is true and extremely important. It means we have to consider what they say very carefully and why they might be saying it.
Columbia Journalism Review publishes insightful articles on these and other problems.
With the modern need to push fast headlines for outrage clicks, I don’t see the standards rising anytime soon.
You know, trying to convince specifically knowledgeable audience isn't something you can do easily .
This is a pipe dream and I'm not sure this is even possible, but I think the best outcome of this is to pass legislation to try and ensure that:
1. Political campaigns don't engage in the type of behaviour in the first place, and
2. Make communications more public in general - official campaigns of people running for public office must operate under the light of greater public scrutiny
Democracy is only possible if accurate information is available, and the biggest takeaway for me in the last elections was just how many secrets all political players have.
The Clinton campaign raised and spent much more money than the Trump campaign: https://www.bloomberg.com/politics/graphics/2016-presidentia...
The U.S. desperately needs campaign finance reform.
To the extent that this is true, campaign finance laws couldn't have stopped it. If anything, restricting the ability of Americans to express their opinions makes foreign propaganda even stronger.
Again, the investigation is still underway and the full extent of the assistance is still unknown, meaning you can't assert that until the findings are released.
This problem goes well beyond any single political candidate.
You need to think about these things in nuance rather than just looking at hard numbers.
People say Sanders got crushed by Clinton, ignoring the media blackout on his campaign for the first half of the primary and the fact that he started in the low single digits for name ID and ended with 45% of the votes.
Context matters.
Yes, that's part of my point. Suppose you overcome the many Constitutional and logistical problems and pass campaign finance laws that limit candidates to spending a fixed amount of money and prohibit third party spending. This would give an even bigger advantage to candidates who are already well known, political insiders, and those the media chooses to give attention to.
People say Sanders got crushed by Clinton, ignoring the media blackout on his campaign for the first half of the primary and the fact that he started in the low single digits for name ID and ended with 45% of the votes.
And the DNC blatantly putting their thumb on the scale. Sanders did as well as he did largely because ordinary people were able to contribute to his campaign and help get his message out.
My own opinion is that asking politicians who take "Big Money" to pass legislation to put a stop to that is unrealistic. It will never, ever, happen.
What is realistic is to personally pledge and publicly announce that you will stop voting for any politician who takes or uses Big Money and urge others to do the same.
When you get enough representatives elected who don't take that Big Money, and defeat enough who do, passing that legislation will be possible. But not before then.
This is happening right now. People are beginning to do this. We all need to do this.
So the government gets to decide which political parties can run candidates? That sounds a little too much like certain 'democratic' dictatorships. I don't think we want to (or can) put that much power in the hands of the government.
Stronger anti-nepotism laws, restraints on the ability to pardon, and ending the electoral college also all seem helpful and would have bipartisan support.
If ending the electoral college had any meaningful bipartisan support, it would already be dead as a system, as changing that is overwhelmingly supported by Democrats.
http://news.gallup.com/poll/2305/americans-long-questioned-e...
Recent and past presidential candidates who supported direct election of the President in the form of a constitutional amendment, before the National Popular Vote bill was introduced: George H.W. Bush (R-TX-1969), Bob Dole (R-KS-1969), Gerald Ford (R-MI-1969), Richard Nixon (R-CA-1969), Michael Dukakis (D-MA), Jimmy Carter (D-GA-1977), and Hillary Clinton (D-NY-2001).
Recent and past presidential candidates with a public record of support, before November 2016, for the National Popular Vote bill that would guarantee the majority of Electoral College votes and the presidency to the candidate with the most national popular votes: Bob Barr (Libertarian- GA), U.S. House Speaker Newt Gingrich (R–GA), Congressman Tom Tancredo (R-CO), and Senator Fred Thompson (R–TN), Senator and Vice President Al Gore (D-TN), Ralph Nader, Governor Martin O’Malley (D-MD), Jill Stein (Green), Senator Birch Bayh (D-IN), Senator and Governor Lincoln Chafee (R-I-D, -RI), Governor and former Democratic National Committee Chair Howard Dean (D–VT), Congressmen John Anderson (R, I –ILL).
[1] https://en.wikipedia.org/wiki/Assault_Weapons_Ban_of_2013
Each party would adjust their platform as a result, so there is fundamental advantage to either that I see. It would certainly save a lot of time spent campaigning in the middle battleground states, and result in a lot more pork barrel projects in cities.
It changes state winner-take-all laws (not mentioned in the U.S. Constitution, but later enacted by 48 states), without changing anything in the Constitution, using the built-in method that the Constitution provides for states to make changes.
Support for a national popular vote for President has been strong among Republicans, Democrats, and Independent voters, as well as every demographic group in every state surveyed. In the 41 red, blue, and purple states surveyed, overall support has been in the 67-81% range - in rural states, in small states, in Southern and border states, in big states, and in other states polled.
Most Americans don't ultimately care whether their presidential candidate wins or loses in their state or district. Voters want to know, that no matter where they live, even if they were on the losing side, their vote actually was equally counted and mattered to their candidate. Most Americans think it is wrong that the candidate with the most popular votes can lose. We don't allow this in any other election in our representative republic.
The National Popular Vote bill in 2017 passed the New Mexico Senate and Oregon House. It was approved in 2016 by a unanimous bipartisan House committee vote in both Georgia (16 electoral votes) and Missouri (10). Since 2006, the bill has passed 35 state legislative chambers in 23 rural, small, medium, large, Democratic, Republican and purple states with 261 electoral votes, including one house in Arizona (11), Arkansas (6), Maine (4), Michigan (16), Nevada (6), North Carolina (15), and Oklahoma (7), and both houses in Colorado (9) and New Mexico (5). The bill has been enacted by 11 small, medium, and large jurisdictions with 165 electoral votes – 61% of the way to guaranteeing the majority of Electoral College votes and the presidency to the candidate with the most national popular votes.
It changes state winner-take-all laws (not mentioned in the U.S. Constitution, but later enacted by 48 states), without changing anything in the Constitution, using the built-in method that the Constitution provides for states to make changes.
You seem to be implying it's a foregone conclusion that the Trump campaign colluded with the Russian government to do this, but that certainly hasn't been proven.
At best, this reveals a clearer link in the DNC emails being hacked from Russia. These were then sent to Wikileaks. If they came from Russia, then it was likely to influence our election, and it likely benefited Trump. But that (in no way) implies any behavior on the part of the Trump campaign. You're making a big leap here.
No one has been executed for treason against the federal government. Yet.
>"So many 'slip-ups' pointing to Russia from this guy.. you could be forgiven for thinking he's not Russian, and was in fact created by the DNC.
>He CHOSE to name his computer account after the founder of the Soviet Secret Police.
>He CHOSE to create/open and then save documents so the Russian name was written to metadata.
>He CHOSE to use a Russian VPN service to cloak his IP address.
>He CHOSE to use public web-based email services that would forward his cloaked IP.
>He CHOSE to use the above to contact various media outlets on the same day.
>Odd behaviour for an elite hacker.
>Also, still today, none of his claims of hacking can be verified."
https://www.reddit.com/r/worldnews/comments/86gglv/lone_dnc_...
It's very similar to Russia's choice to poison Litvienko with Polonium–an unnatural radioactive element that can easily be traced back to the reactor where it originated. And, similarly, the very recent chemical weapons attack in the UK, using a nerve agent only ever produced by Russia.
If the DNC were responsible for their own 'hack':
They CHOSE to release embarrassing and damaging information right before a major election, in case they lost, so they would have an excuse if it happened?
And the DNC is so competent at information security that they were able to deceive 17 (or whatever the number is) government agencies and several independent researchers?
WL announces it's going to publish DNC emails. This alerts DNC to leak/hack. DNC decides to get in front of it by playing the whole thing as a Russian op, especially potent as Trump is campaigning on softening stance with Russia. Notice that the first thing G2.0 leaked from the DNC was oppo on Trump.
By the time Wikileaks publishes (without all these Russian fingerprints), "Guccifer" has already carried out the misdirection.
Whole op could be a gambit by the DNC to set the discourse before the content of the emails gets picked up.
Just a few months ago Russians send a government airplane (like Secret Service government) to pick up a load of cocaine in Argentina.
A few years ago they've send an AA to Ukraine and downed MH-17.
They're definitely not superheroes.
http://www.newsweek.com/russian-hacker-stealing-clintons-ema...
---
Konstantin Kozlovsky, a Russian citizen working for a hacker group called Lurk, confessed to hacking Clinton’s emails during a hearing about his arrest in August. An audio recording and minutes from the hearing were posted on Kozlovsky’s Facebook page, and their authenticity was reportedly confirmed by The Bell.
---
He allegedly worked with someone from FSB:
---
Kozlovsky identified his FSB handler as Dmitry Dokuchaev, a cybersecurity expert who worked as a hacker before joining the FSB.
Dokuchaev, who used the moniker “Forb,” has been linked to a group of hackers called Shaltai Boltai, or Humpty Dumpty,
---
Perhaps the DNC was hacked by both? It was a pretty large target and multiple state actors gave it a try.
Coincidentally, this also solves the problem of DNS leaks.
1. The hacker mistakenly sign in from Russia once.
2. The hacker intentionally sign in from Russia once.
I really have no bias towards all this issue and don't really care, but I do care about media making interpretations that mislead the public, which is why I draw this question.
One widely used hacking technique is to intentionally leave a trail that leads investigators down the wrong track, not just for hacking but for all crimes.
I'm just having hard time understanding how people are taking for granted that a competent hacker is more likely to leave a trail by mistake instead of leaving one intentionally, because in most cases it's the latter.
1. The hacker actually worked for GRU, which was already known to engage in such activities, and slipped up once?
2. Somebody hacked into a GRU office so they could connect from there one time and hope somebody would notice?
Governmental incompetence is all a great charade meant to make their flawlessly-executed deceptions and conspiracies more believable.
Was it the latter, but still goofed by good old human fallibility?
It's obvious that the troll factory people and Guccifer 2.0 were acting on behalf of Russia with the direct approval from Putin. Why bother indicting individuals?
Russian agents used isotopes and nerve gas in GCHQ’s backyard. The sitting US President might have received their help to win the election. Russia just made the only major territory annexation by a superpower since WWII (iirc).
Obviously we didn’t start the fire, as Billy Joel would say, but we certainly live in interesting times.
Exactly. I think the US Govt failed to appreciate that Putin has been waging Cold War 2.0 for some time now. The scary thing is that he is clearly not playing by the old rules and is willing to push far beyond old boundaries.
The fact that he would so brazenly use a nerve agent in an assassination means we're well and truly in uncharted territory.
So has the US. Encroaching NATO in Russia's sphere of influence after the US had agreed they wouldn't. Bush at some point just went "actually, we're not going to honour our word any more."
At the same time, sloppiness has come into play on multiple occasions. They want to project an image of strength but there is a vein of ineptness running through their military and sometimes their intelligence ops. This is why the West needs to slap Putin down rather than appease his aggression. He is a puffed up bully who is trying to push the envelope beyond what he is capable of backing up.
I don't see that. The raid on Osama was pretty inept too, as it was arming and training any random anti-Iranian person in the region and ending up with IS/Daesh.
It's just that direct action is inevitably brazen and unsubtle, and will often have unpredictable repercussions. You give state-of-the-art anti-aircraft weaponry to Ukrainian biker gangs and they shoot down a civilian plane; you support anti-Ghaddafi groups and they end up burning down your own embassy. You just cannot predict which way the grass will bend under your feet. Any direct action will have its fair share of fumbles, it's just that the world is now so well-connected that they will be ruthlessly exposed pretty much all the time.
Personally, I wouldn't underestimate Putin - like all fascist regimes, his rule has likely cultivated a cohort of inept yes-men, but he's also reinvigorated what was a tremendously dangerous military apparatus that is still capable of triggering a nuclear holocaust. I think our approach should be a bit subtler than "slapping down a bully".
Putin's tactics used in Crimea are quite the same ones used by Stalin's Russia after WW2 in Eastern Europe. You can find all of them in decassified CIA reports. The only difference is the lack of insignia on troops, clearly designed to support the claim that the forces that siezed Crimea were rebels as opposed to Russian military.
I disagree, Putin doesn't need to be slapped down, for this is too risky and could trigger a war. Nato (US) presence in Eastern (Romania) and Northern Europe (Poland, Eastonia, Letonia, Latvia), military and economic cooperation with these states is sufficient to deter his bulying ambitions. Hungary and Bulgaria have been ruled out for being too cosy with Russia.
Unless Trump made a deal with them to do so, this looks like business as usual to me.
Your comment doesn't pass a basic test of moral decency, which is that there is no reason to point fingers. Actions should be judged based on their own merits, not what others are doing. That is just deflection.
I doubt you meant it that way, but that is how it came across.
And of course it is a very big deal and not at all palatable to interfere with the internal politics of another country to destabilize it, regardless of how often it has been done, the roles of its internal members, or their cooperation with you.
Edit: I also don't think just any improvement would morally justify interference in another country's sovereignty. There must be a significant evil that must be overcome so that the interference becomes the lesser evil - a hard test to pass.
I don't think this is a clear moral line in international politics.
If your primary motivation is to improve the life of those within your own country, it can be justifiable to get involved in another country's politics. And that's what is done. Ostensibly to prevent war, enhance regional stability, etc.
Even just looking from Russia's perspective. If the world's leading country is so weak that a few phishing attacks can swing the election away from a less favorable candidate, is it really morally wrong to do that to benefit your people?
There is no such thing as "a little phishing" in another election. It is the equivalent of calling something a little hand gesture without mentioning you shoved your hand into someone's vagina first.
The autarky of self-governance is sacred, and should be respected as such. The modern world has completely lost its moral compass on these issues, and I have previously denounced harder lines by the EU and the US interfering in smaller countries elections / forcing laws down their throats (Eastern European and Balkan) countries). But as I alluded to in the beginning of this thread: Just because everyone's doing something does not make it right.
I do suspect we only disagree on the degree of influence.
You are quite possibly correct. Much of "sanctions, embargoes, tariffs, and the promise of lifting those measures for the preferred candidate/party" would fall under what I meant by "openly setting out the country's position", and is qualitatively different from the (alleged) Russian interference and how the US (and others) have historically influenced elections.
I think much of the difference comes down to attributability (giving the country/government's opinion and how they will deal with any particular winner is fine; making claims that appear to come from other/in-country sources, or misleading the population of that country is not) and whether you are directly taking actions within the country/working with a particular political party (what is a small amount of money to the US could very easily skew the election massively in some countries, and lead to the US de facto deciding the result).
Actions shouldn't be considered within the context of what's normal? That sounds a bit like.....deflection.
This is called speech. I personally have zero problem with speech, no matter who is engaging in it. And I support the market place of ideas.
Everyone should have the right to engage in speech. Yes, even political speech.
This is especially true in America, where the founding fathers put in protections for speech in the constitution. (ESPECIALLY for political speech).
If you don't like the speech or airguns that someone else is making, then you should make better arguments yourself.
There's a big difference between 'influencing' an election and committing a concerted campaign of espionage, propaganda, disinformation, hacking, and potentially extortion in an effort to subvert the the government of another nation. The scope and aggressiveness of Russia's actions are quite a different animal than normal statecraft.
The fact that several members of the Trump campaign have been indicted and made plea deals indicates that there is a lot of criminal activity there to unpack. Most definitely not business as usual.
It was most definitely business as usual. DC is dirty at every corner and most administrations are overflowing with it, including the Bill Clinton and George W. Bush administrations. Obama's was cleaner than both of those, based on what we know so far.
You also need to look at what those Trump campaign members were indicted for: absolutely nothing to do with colluding with Russia to rig the election. They got them on rather routine political corruption charges, which you can probably get half of DC for given the way it operates, if you look. It's the Xi premise of cleaning up China's corruption: they're all doing it, you can get any of them if you want to investigate closely enough.
This is false.
How many members of Clinton and Bush's campaign staff or senior national security staff were ever accused of collusion with or corruption involving hostile/iffy foreign governments? Because there's nothing comparable to NSA Flynn plotting to execute an extraordinary rendition on US soil on behalf of a foreign power (Turkey), or campaign manager Manafort indicted for financial crimes involving hiding money received from a foreign government under active sanctions, or deputy campaign manager pleading guilty to similar charges.
> absolutely nothing to do with colluding with Russia to rig the election
Reminder: Paul Manafort was indicated for being a paid agent of and conspiring with the Russian government and 13 Russian nationals have been indicted for interfering with the 2016 elections.
The closest you get to this is Iran-Contra in 1987 and the rumored 1980 "October Surprise", where George HW Bush -- allegedly -- negotiated with Iran to delay releasing American hostages until after Reagan defeated Carter. (They were released on Inauguration day 1981.) However, I would argue that nothing in modern US history comes close to this. No American president has been credibly accused or even remotely tied to foreign government attempts to manipulate the US electorate the way the Trump campaign and White House have been.
Doesn't change the fact that it is very much not business as usual for Russia to attempt to subvert the US Govt like this. They've crossed several lines in the sand, which is why expulsions, Interpol warrants, and sanctions have been levied against Russia and individuals involved.
One can make the argument that this is just Cold War stuff again, but the tactics being employed are in several ways a step above the old Cold War in aggressiveness.
To me this and the trade war with China suggest that the US is losing it's status as pre-eminent super power. The crown is slipping and the vultures circle.
Worrying times really.
I'm sure they're 95% genuine, we just don't know which 95% all we have is some KGB guy's word on it
Given access to almost anyone’s email, it’s not a difficult task to selectively pick out emails to paint an unflattering picture.
If you are a political party, I am not going to give you the benfit of the doubt. If you POINT to something and say "specifically this email is untrue", then I'll believe you.
But if you stay silent, then I am just going to assume that you believe everything is true.
Innocent until proven guilty is for the court system.
Political parties do not get that benefit from me. All they have to do is counter claim (about a SPECIFIC, point of fact, email, ect) , and I'll listen to them.
If you think that American politicians are more corrupt than Russian spies then you probably too biased to rationally discuss the issue anyway.
Right now they're just rolling up the smaller players so they can build a case against the bigger fish. All those plea deals being cut are not because Mueller has a weak hand.
Has he made any statement or indication he’s close to something significant yet? Any special counsel looking for crimes in DC is going to find plenty, but I don’t see where Trump is implicated in any of these. The leaks from the FBI have been so voluminous and the Democrat incentive to leak them I doubt they are keeping secret evidence under wraps at this point.
Yes, the very first charge made public, the charge against, and guilty plea and statement of the offense by George Papadopolous are specifically about lying to investigators about his collusion and attempted collusion with Russians connected with, and whom he believed to be connected with, the Russian government, on behalf of the Trump campaign and with ongoing coordination with higher campaign officials.
Nope, but I wouldn't expect that because "collusion" isn't a crime on the books.
> Any special counsel looking for crimes in DC is going to find plenty
Ken Starr spent a lot of time looking for real estate investment crimes and only turned up with an extramarital affair.
> The leaks from the FBI have been so voluminous and the Democrat incentive to leak them I doubt they are keeping secret evidence under wraps at this point.
There have been zero leaks from the SP, which is distinct from the FBI. No one, not Congress, not the President, not the FBI knows what he has.
Sure we don't have proof right now as it would be Top Secret if it exists, but I'm sure we will find out in due time.
I will reserve my final judgement until the special counsel investigation is completed, but it certainly seems to point towards collusion to me, or Trump has something just as big to hide (RICO).
With that ballot we were going to get 4-8 years of this garbage news pandering either way. Obama was an outlier, far cleaner than average.
The problem is, the camp of people willing to reserve judgement until we have verifiable evidence is a very exclusive club.
Is the DNC computer network not on US turf?
We can't be.
Have some vodka, American friend.
https://theforensicator.wordpress.com/guccifer-2-ngp-van-met...
And today Trump ejects his sane national security advisor, H.R. McMaster, in favor of the hawk who was one of the four architects of the Iraq war, John Bolton.
John Bolton penned the WSJ article The Legal Case for Striking North Korea First published Feb 28 2018.
https://lawandcrime.com/high-profile/bombshell-nsa-experts-s...
or just ask Wikileaks or Kim Dotcom.
More like nobody at the NYT or WP willing to tarnish their reputation with this crap. Which is pretty bad given what they will publish.
In 2013, Ackerman was forced to take down one of his Wired stories on what he claimed was a "North Korean propaganda video", after it was revealed the film was a satire video by British travel writer Alun Hill.[16]
https://twitter.com/attackerman/status/311868261945978881
To remind everyone where the plot is, I was responding to this phrase:
> Yeah, I am sure The Daily Beast got this story because they are such a well respected journalistic outlet.
None of his sourced reporting has ever been called into question. The original commenter was way off base with this insinuation.
IOW, they don't have jack shit, which is why the stuff I quoted above is buried towards the end of the article. How does one tie an IP address to a street address? Or to a specific person? And what does "working off" an IP address even mean? And why would he be running this from the GRU headquarters rather than from some obscure Russian bunker?
I smell massive quantities of clickbait manure.
If anything this whole event should prove how hard it is to really pull off this kind of shady conspiracy without leaving a real trail of evidence, something the 9/11 truthers, the moon landing loons, or the false flag school shooting assholes have never been able to find because it's not there.
Please point to any "significant criminal conspiracy" which was exposed, and which laws it was in violation of, if possible.
And for bonus points, please tell us why Trump hasn't thrown Hillary into prison yet, as promised.
The law broken is the court order telling them to hand over all the emails.
The reason for no prosecution is because of politics. That's how the world works, shrug.
Some of the hacked emails in question, could have been some of the ones that were illegally deleted in the first place.
So they were in effect, undeleting emails that were illegally deleted.
The deleted emails were on Hillary Clinton's private server, which she used during her tenure as Secretary of State, 2009-2013.
There is no connection between the two sets of email whatsoever. Remember when Donald Trump responded to the DNC leaks by asking the Russians to leak Hillary's deleted emails? Yeah. That's because they're not the same thing.
> And for bonus points, please tell us why Trump hasn't thrown Hillary into prison yet, as promised.
Because they play golf at the same country clubs, and their IRL actions aren't bound by the marketing characters they play? It would be kind of like shooting someone after you beat them in chess - totally uncool.
But I don't see how this is relevant, unless you assume that by criticizing one ignorance club I must be a cheerleader for its twin?
What election fraud? What is "subverting the will of the people and the authorized government" supposed to refer to?
I'm not assuming anything, but bold and unsubstantiated assertions of conspiracy are just noise in threads like this.
> The Washington Post reported: "Many of the most damaging emails suggest the committee was actively trying to undermine Bernie Sanders's presidential campaign. Basically, all of these examples came late in the primary - after Hillary Clinton was clearly headed for victory - but they belie the national party committee's stated neutrality in the race even at that late stage."
> Noun 1. election fraud - misrepresentation or alteration of the true results of an election
Yes, the DNC was in the bag for Clinton. That's hardly election fraud and doubtful would rise to the level of criminal activity, however distasteful.
The apparent presence of Bernie Sanders in the race definitely induced people to vote in the Democratic primary who otherwise wouldn't have. Otherwise, they could have either voted in a different primary or stayed home and registered their lack of support for the entire process.
One thing that does not appear in the emails anywhere is any hint that the DNC tried to manipulate the outcome of primaries or caucuses. That's what "election fraud" means.
Not a network whizz but doesn't that sound unlikely? They would have to have 1. Static IPs 2. Deep enough penetration of their systems to have IP/Officer mapping -> in which case they would have known this was going on anyways?
Seems necessary to edit:
I understand the NSA is the most powerful player and likely had penetrated their systems. My point is that if their networks were penetrated anyways, why are receiving this reasoning about the accident with the VPN? The only plausible explanation I can see is what another commenter put out which is the Officer had also used the non-VPNd connection to something personal. Now this would be a big fuck up
Saying they could identify an individual officer from an IP leads you to assume they had penetrated the network. In which case, why not disclose that? That would be the assumption from the other side.
The IP address could have led to GRU HQ (specifically identified as where he was working out of), and other information could have narrowed it down from there to a particular officer.
A comment downthread suggests that he logged into a real-name service from the same IP without a VPN. This too is possible, but I find it at least somewhat surprising that an intelligence service doesn't prohibit logging in to real-name services from State computers.
For example, some civilian employers prohibit this, even when they provably have nothing to hide.
It just strikes me as very sloppy epistemology, and sort of insulting to my abilities to draw my own conclusions.
He forgot to use the VPN that was masking him.
"Hey, maybe even knowing this much means the government knows more?"
No. You just come in with the: "This doesn't seem right. Isn't the NSA basically on college 101 level?"
Dude, they did it. Dutch intel even pwn3d their networks and video cameras.
* Agent embedded in the office - they might not know about the operation beforehand if it's well compartmentalised, but may be able to find out more now they have that initial information, or rule out enough people to narrow it down
* Breach the internal network, knowing that access will be short-lived and discovered, but for long enough to get the information you need
* A further slip-up that, e.g., includes a name or some other identifying piece of information (e.g. cookie to a non-HTTP site), or accessing GRU systems that the US have previously breached or are otherwise improperly secured from the same machine
* Forge the VPN set up so that the user connects to NSA-controlled servers -- doesn't seem out of the realm of the NAS's capabilities; or
* Work with Elite VPN (unlikely--they appear to be a Russian company) or breach their systems (I imagine their security is less than GRU's, especially if they have servers in France which would likely allow the NSA or their French counterparts to compel physical access) to gain access to the VPN traffic. Once you have that, insert a zero-day into the traffic to gain access to the GRU machine
* Use a QUANTUM-style attack to embed a zero-day into non-VPN requests made over that connection
It's unlikely that you could immediately go from IP address to GRU officer, but working from that IP address you certainly have options that could lead you to an individual. I think it's quite clear why NSA would not want to reveal which technique(s) they used, particularly as it could lead GRU's countermeasures to be specifically targeted against useful methods.
I'm also not particularly sure it matters all that much. It's quite possibly the work of a team (even if the actual postings come from an individual) and will at least (presumably) have command authorisation. The article notes "[s]ometime after its hasty launch, the Guccifer persona was handed off to a more experienced GRU officer". Attributing it to an individual, rather than just the GRU, doesn't seem to make much difference.
[1] I find it possible that traffic analysis was used to uncover this -- find that Guccifer 2.0 is posting via Elite VPN, then correlate traffic in to Elite with possible sources. I'm surprised that GRU wouldn't use a machine that is forced to connect to a VPN for this, particularly if the machine's public IP points back to GRU/Russia, so it being something more that "agent forgot to enable VPN" would not be shocking.
Edit: fix list formatting
You forget this story is aimed at people who mostly get their news from Faux Television ..